great tool!
but now a question. what in hell are these?
C:\security\ModGrepper\modGREPER-0.2-bin>modgreper -h
modGREPER 0.2, written by Joanna Rutkowska (June 2005)
http://invisiblethings.org
searching phase 1 completed.
searching phase 2 completed.
? f7dd6000 - f7dd8000 : \SystemRoot\System32\Drivers\dump_WMILIB.SYS
? ee94a000 - ee962000 : \SystemRoot\System32\Drivers\dump_atapi.sys
THERE ARE 2 SUSPECTED MODULE(S)!!!
i go to the folder and cant find them and the computer is set to view all files including system files.
OK, sorry to ask this question before i did any research. i just got nervous.
ump_wmilib.sys
dump_WMILIB.SYS is a part of Microsoft Windows Operation system.
dump_WMILIB.SYS is the WMI driver.
so why cant i find them. they aren't even found in the registry