1
Tech Clinic / No TaskMan/ Starting to slow down
« on: November 03, 2009, 09:18:58 PM »
I couldn't get the ESET Scanner to work, it would just hang up half way through the load, but here is the SysProt Log
[quote name=\'SysProt\']SysProt AntiRootkit v1.0.1.0
by swatkat
********************************************************************************
**********
********************************************************************************
**********
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 1020
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 1092
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 1128
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 1172
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 1184
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 1336
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1372
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1464
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1508
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 1572
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1652
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1728
Hidden: No
Window Visible: No
Name: C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PID: 1920
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 364
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 856
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\WgaTray.exe
PID: 980
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
PID: 1084
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 1100
Hidden: No
Window Visible: No
Name: C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PID: 1408
Hidden: No
Window Visible: No
Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 1748
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jqs.exe
PID: 1860
Hidden: No
Window Visible: No
Name: C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
PID: 528
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\HPZipm12.exe
PID: 616
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 692
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PID: 2216
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
PID: 2260
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\searchindexer.exe
PID: 2836
Hidden: No
Window Visible: No
Name: C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
PID: 3520
Hidden: No
Window Visible: No
Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 736
Hidden: No
Window Visible: No
Name: C:\WINDOWS\sm56hlpr.exe
PID: 2352
Hidden: No
Window Visible: No
Name: C:\Program Files\Trillian\trillian.exe
PID: 2456
Hidden: No
Window Visible: No
Name: C:\WINDOWS\RTHDCPL.exe
PID: 2512
Hidden: No
Window Visible: No
Name: C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PID: 2528
Hidden: No
Window Visible: No
Name: C:\Program Files\Trillian\trillian.exe
PID: 2532
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
PID: 2568
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
PID: 2820
Hidden: No
Window Visible: No
Name: C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
PID: 2852
Hidden: No
Window Visible: No
Name: C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
PID: 2864
Hidden: No
Window Visible: No
Name: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PID: 2908
Hidden: No
Window Visible: No
Name: C:\Program Files\PureEdge\Viewer 6.5\masqform.exe
PID: 3036
Hidden: No
Window Visible: No
Name: C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
PID: 3060
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
PID: 1720
Hidden: No
Window Visible: No
Name: C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PID: 3156
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jusched.exe
PID: 3180
Hidden: No
Window Visible: No
Name: C:\Program Files\iTunes\iTunesHelper.exe
PID: 3228
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
PID: 3252
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 3260
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\Acrobat_sl.exe
PID: 3992
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PID: 4056
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
PID: 4092
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\SetPoint\SetPoint.exe
PID: 2324
Hidden: No
Window Visible: No
Name: C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PID: 256
Hidden: No
Window Visible: No
Name: C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PID: 628
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\Connor\Desktop\SysProt\SysProt\SysProt.exe
PID: 3360
Hidden: No
Window Visible: Yes
Name: C:\WINDOWS\system32\wuauclt.exe
PID: 3460
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
PID: 3852
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\unsecapp.exe
PID: 3588
Hidden: No
Window Visible: No
Name: C:\Program Files\iPod\bin\iPodService.exe
PID: 3688
Hidden: No
Window Visible: No
********************************************************************************
**********
********************************************************************************
**********
Kernel Modules:
Module Name: \??\C:\Documents and Settings\Connor\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: A9FA4000
Module End: A9FAF000
Hidden: No
Module Name: \WINDOWS\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 804D7000
Module End: 806E4000
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806E4000
Module End: 80704D00
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F7A12000
Module End: F7A14000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F7922000
Module End: F7925000
Hidden: No
Module Name: spkl.sys
Service Name: ---
Module Base: F7314000
Module End: F7411000
Hidden: Yes
Module Name: \WINDOWS\System32\Drivers\WMILIB.SYS
Service Name: ---
Module Base: F7A14000
Module End: F7A16000
Hidden: No
Module Name: \WINDOWS\System32\Drivers\SCSIPORT.SYS
Service Name: ScsiPort
Module Base: F72FC000
Module End: F7314000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F72CE000
Module End: F72FC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F72BD000
Module End: F72CE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ohci1394.sys
Service Name: ohci1394
Module Base: F7512000
Module End: F7522000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: F7522000
Module End: F7530000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F7532000
Module End: F753C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\compbatt.sys
Service Name: Compbatt
Module Base: F7926000
Module End: F7929000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\BATTC.SYS
Service Name: BattC
Module Base: F792A000
Module End: F792E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F7ADA000
Module End: F7ADB000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F7792000
Module End: F7799000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F7542000
Module End: F754D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F729E000
Module End: F72BD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: F7A16000
Module End: F7A18000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: F7278000
Module End: F729E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPIEC.sys
Service Name: ACPIEC
Module Base: F792E000
Module End: F7931000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
Service Name: ---
Module Base: F7ADB000
Module End: F7ADC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F779A000
Module End: F779F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F7552000
Module End: F755F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\iviVD.sys
Service Name: iviVD
Module Base: F7562000
Module End: F756D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F7260000
Module End: F7278000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\viamraid.sys
Service Name: viamraid
Module Base: F7572000
Module End: F7581000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F7582000
Module End: F758B000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F7592000
Module End: F759F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: F7240000
Module End: F7260000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F722E000
Module End: F7240000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Lbd.sys
Service Name: Lbd
Module Base: F75A2000
Module End: F75B1000
Hidden: No
Module Name: SYMEFA.SYS
Service Name: SymEFA
Module Base: F71DF000
Module End: F722E000
Hidden: Yes
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F71C8000
Module End: F71DF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F713B000
Module End: F71C8000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F710E000
Module End: F713B000
Hidden: No
Module Name: C:\WINDOWS\system32\speedfan.sys
Service Name: speedfan
Module Base: F7A18000
Module End: F7A1A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F70F4000
Module End: F710E000
Hidden: No
Module Name: C:\WINDOWS\system32\giveio.sys
Service Name: giveio
Module Base: F7ADC000
Module End: F7ADD000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tunmp.sys
Service Name: tunmp
Module Base: F6836000
Module End: F6839000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F7622000
Module End: F762B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\CmBatt.sys
Service Name: CmBatt
Module Base: F682A000
Module End: F682E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
Service Name: ati2mtag
Module Base: F631D000
Module End: F6608000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F6309000
Module End: F631D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
Service Name: WmiAcpi
Module Base: F6826000
Module End: F6829000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: F62E1000
Module End: F6309000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\NETw3x32.sys
Service Name: NETw3x32
Module Base: F613F000
Module End: F62E1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F790A000
Module End: F7910000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F611B000
Module End: F613F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F7912000
Module End: F791A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F7632000
Module End: F763F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F791A000
Module End: F7920000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\SynTP.sys
Service Name: SynTP
Module Base: F60EC000
Module End: F611B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F7AA0000
Module End: F7AA2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F77AA000
Module End: F77B0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F693A000
Module End: F6945000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F692A000
Module End: F693A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F691A000
Module End: F6929000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: F60C9000
Module End: F60EC000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\InCDPass.sys
Service Name: InCDPass
Module Base: F77B2000
Module End: F77BA000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\incdrm.SYS
Service Name: incdrm
Module Base: F77EA000
Module End: F77F1000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys
Service Name: GEARAspiWDM
Module Base: F77FA000
Module End: F7800000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Service Name: ---
Module Base: F6020000
Module End: F6085000
Hidden: Yes
Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7BC0000
Module End: F7BC1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F68CA000
Module End: F68D7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F70B4000
Module End: F70B7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F5F51000
Module End: F5F68000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F68BA000
Module End: F68C5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F7612000
Module End: F761E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F78AA000
Module End: F78AF000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys
Service Name: PSched
Module Base: F5F40000
Module End: F5F51000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F68AA000
Module End: F68B3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F4B76000
Module End: F4B7B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F4B6E000
Module End: F4B73000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: F3F09000
Module End: F3F39000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F54D0000
Module End: F54DA000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\SymIM.sys
Service Name: SymIM
Module Base: F4B66000
Module End: F4B6E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F7A1C000
Module End: F7A1E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\update.sys
Service Name: Update
Module Base: F3E4F000
Module End: F3EAD000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F79EA000
Module End: F79EE000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F690A000
Module End: F6914000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\smserial.sys
Service Name: smserial
Module Base: AE6A2000
Module End: AE771000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F4214000
Module End: F421C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\RtkHDAud.sys
Service Name: IntcAzAudAddService
Module Base: AE270000
Module End: AE6A2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: AE24C000
Module End: AE270000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: F4379000
Module End: F4388000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F4349000
Module End: F4358000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SRTSP.SYS
Service Name: SRTSP
Module Base: AE1F9000
Module End: AE24C000
Hidden: No
Module Name: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091103.007\NAVEX15.SYS
Service Name: NAVEX15
Module Base: AE0B7000
Module End: AE1F9000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Service Name: SymEvent
Module Base: AE092000
Module End: AE0B7000
Hidden: No
Module Name: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091103.007\NAVENG.SYS
Service Name: NAVENG
Module Base: AE07E000
Module End: AE092000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Service Name: usbstor
Module Base: F7832000
Module End: F7839000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\usbaapl.sys
Service Name: USBAAPL
Module Base: F75F2000
Module End: F7600000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Service Name: usbccgp
Module Base: F7842000
Module End: F784A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\usbaudio.sys
Service Name: usbaudio
Module Base: F7602000
Module End: F7611000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NIS\1007020.00B\SRTSPX.SYS
Service Name: SRTSPX
Module Base: F3FB9000
Module End: F3FC3000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F7A70000
Module End: F7A72000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F7C5B000
Module End: F7C5C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F7A74000
Module End: F7A76000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: F41F4000
Module End: F41FB000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F78C2000
Module End: F78C8000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F7A88000
Module End: F7A8A000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F7A8A000
Module End: F7A8C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\InCDrec.SYS
Service Name: InCDrec
Module Base: F4757000
Module End: F475A000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\InCDfs.SYS
Service Name: InCDfs
Module Base: AE045000
Module End: AE05E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F7862000
Module End: F7867000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F4B8E000
Module End: F4B96000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: F79D6000
Module End: F79D9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: AE032000
Module End: AE045000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: ADFD9000
Module End: AE032000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMTDI.SYS
Service Name: SYMTDI
Module Base: ADFA5000
Module End: ADFD9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: ADF7F000
Module End: ADFA5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F75C2000
Module End: F75CB000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMNDIS.SYS
Service Name: SYMNDIS
Module Base: F78BA000
Module End: F78C2000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMFW.SYS
Service Name: SYMFW
Module Base: ADF6A000
Module End: ADF7F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMIDS.SYS
Service Name: SYMIDS
Module Base: F78CA000
Module End: F78D1000
Hidden: No
Module Name: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20091102.002\IDSxpx86.sys
Service Name: IDSxpx86
Module Base: ADF16000
Module End: ADF6A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: ADEEE000
Module End: ADF16000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip6.sys
Service Name: Tcpip6
Module Base: ADEB6000
Module End: ADEEE000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: ADE94000
Module End: ADEB6000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ip6fw.sys
Service Name: Ip6Fw
Module Base: F4359000
Module End: F4362000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: F3F79000
Module End: F3F82000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SCDEmu.SYS
Service Name: SCDEmu
Module Base: F421C000
Module End: F4224000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: ADE41000
Module End: ADE6C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: ADDD1000
Module End: ADE41000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Service Name: HidUsb
Module Base: F381B000
Module End: F381E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: F5540000
Module End: F5549000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: F7742000
Module End: F774D000
Hidden: No
Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
Service Name: eeCtrl
Module Base: ADD73000
Module End: ADDD1000
Hidden: No
Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
Service Name: EraserUtilRebootDrv
Module Base: ADD56000
Module End: ADD73000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\ccHPx86.sys
Service Name: ccHP
Module Base: ADCDB000
Module End: ADD56000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\BHDrvx86.sys
Service Name: BHDrvx86
Module Base: ADC99000
Module End: ADCDB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: F7087000
Module End: F708B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
Service Name: LHidKe
Module Base: F78DA000
Module End: F78E1000
Hidden: No
Module Name: \??\C:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys
Service Name: atitray
Module Base: F708B000
Module End: F708F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: F7077000
Module End: F707A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
Service Name: LMouKE
Module Base: ADC60000
Module End: ADC71000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: ADC3C000
Module End: ADC60000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_diskdump.sys
Service Name: ---
Module Base: F7097000
Module End: F709B000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_viamraid.sys
Service Name: ---
Module Base: F7772000
Module End: F7781000
Hidden: Yes
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: ADE70000
Module End: ADE73000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: F7852000
Module End: F7857000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: F7B1F000
Module End: F7B20000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: AB95C000
Module End: AB960000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: AB6DF000
Module End: AB6F4000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: AB73C000
Module End: AB74B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\secdrv.sys
Service Name: Secdrv
Module Base: F3F99000
Module End: F3FA3000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\symlcbrd.sys
Service Name: symlcbrd
Module Base: F780A000
Module End: F7810000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: AB79C000
Module End: AB7AC000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\TDTCP.SYS
Service Name: TDTCP
Module Base: F789A000
Module End: F78A0000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\RDPWD.SYS
Service Name: RDPWD
Module Base: AADC3000
Module End: AADE6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys
Service Name: Srv
Module Base: AAB91000
Module End: AABE3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: AA774000
Module End: AA79F000
Hidden: No
********************************************************************************
**********
********************************************************************************
**********
SSDT:
Function Name: ZwAlertResumeThread
Address: 85C9A790
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAlertThread
Address: 85C9A870
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAllocateVirtualMemory
Address: 85DB2778
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAssignProcessToJobObject
Address: 8521CD48
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwConnectPort
Address: 87130620
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateKey
Address: AE0A8130
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwCreateMutant
Address: 85C9A300
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateSymbolicLinkObject
Address: 8521CB68
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateThread
Address: 86C4F4D8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDebugActiveProcess
Address: 8521CE28
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDeleteKey
Address: AE0A83B0
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwDeleteValueKey
Address: AE0A8910
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwDuplicateObject
Address: 85DB3370
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwEnumerateKey
Address: F7332CA2
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwEnumerateValueKey
Address: F7333030
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwFreeVirtualMemory
Address: 85DB25D8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwImpersonateAnonymousToken
Address: 85C9A3F0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwImpersonateThread
Address: 85C9A4D0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwLoadDriver
Address: 8712A268
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwMapViewOfSection
Address: 852A0348
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenEvent
Address: 85C9A220
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenKey
Address: F73150C0
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwOpenProcess
Address: 85C9D300
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenProcessToken
Address: 85DB32F0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenSection
Address: 85C9A060
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenThread
Address: 85DB3440
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwProtectVirtualMemory
Address: 8521CC58
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwQueryKey
Address: F7333108
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwQueryValueKey
Address: F7332F88
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwResumeThread
Address: 85DA7E38
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetContextThread
Address: 85DB2300
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetInformationProcess
Address: 85DB23C0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetSystemInformation
Address: 8521CF08
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetValueKey
Address: AE0A8B60
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwSuspendProcess
Address: 85C9A140
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSuspendThread
Address: 85C9A930
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwTerminateProcess
Address: 85DC56C0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwTerminateThread
Address: 85C9AF90
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwUnmapViewOfSection
Address: 85DB2490
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwWriteVirtualMemory
Address: 85DB26A8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
********************************************************************************
**********
********************************************************************************
**********
No Kernel Hooks found
********************************************************************************
**********
********************************************************************************
**********
IRP Hooks:
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_CREATE
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_POWER
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLOSE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_READ
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_WRITE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_EA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLEANUP
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_POWER
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_READ
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_CREATE
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_READ
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_WRITE
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_POWER
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_READ
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_READ
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CREATE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CLOSE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_READ
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_WRITE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_EA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CLEANUP
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_POWER
Jump To: F731CE1C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F7330514
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86EA0500
Hooking Module: _unknown_
********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: CONNOR:50701
Remote Address: LOCALHOST:1032
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
State: ESTABLISHED
Local Address: CONNOR:50701
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
State: LISTENING
Local Address: CONNOR:27015
Remote Address: LOCALHOST:1036
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED
Local Address: CONNOR:27015
Remote Address: LOCALHOST:1034
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED
Local Address: CONNOR:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING
Local Address: CONNOR:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING
Local Address: CONNOR:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: CONNOR:1036
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED
Local Address: CONNOR:1034
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED
Local Address: CONNOR:1032
Remote Address: LOCALHOST:50701
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: ESTABLISHED
Local Address: CONNOR:1031
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
State: LISTENING
Local Address: CONNOR:1044
Remote Address: 63.251.254.131:HTTP
Type: TCP
Process: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
State: SYN_SENT
Local Address: CONNOR:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: CONNOR:3703
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: LISTENING
Local Address: CONNOR:3389
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: CONNOR:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: CONNOR:427
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: LISTENING
Local Address: CONNOR:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: CONNOR:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: CONNOR:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: NA
Local Address: CONNOR:1039
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: CONNOR:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: CONNOR:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:52329
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: CONNOR:9370
Remote Address: NA
Type: UDP
Process: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
State: NA
Local Address: CONNOR:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: CONNOR:3703
Remote Address: NA
Type: UDP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: NA
Local Address: CONNOR:3544
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:1029
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\spoolsv.exe
State: NA
Local Address: CONNOR:1025
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: CONNOR:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: CONNOR:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: CONNOR:427
Remote Address: NA
Type: UDP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: NA
********************************************************************************
**********
********************************************************************************
**********
Hidden files/folders:
Object: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\34EB0A60.TMP
Status: Access denied
Object: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\68A5962A.TMP
Status: Access denied
Object: C:\System Volume Information\EfaData
Status: Access denied
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\_restore{029932C0-D74E-4292-AF45-3DA84248588C}
Status: Access denied[/quote]
[quote name=\'SysProt\']SysProt AntiRootkit v1.0.1.0
by swatkat
********************************************************************************
**********
********************************************************************************
**********
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 1020
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 1092
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 1128
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 1172
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 1184
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 1336
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1372
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1464
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1508
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 1572
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1652
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1728
Hidden: No
Window Visible: No
Name: C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PID: 1920
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 364
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 856
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\WgaTray.exe
PID: 980
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
PID: 1084
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 1100
Hidden: No
Window Visible: No
Name: C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PID: 1408
Hidden: No
Window Visible: No
Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 1748
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jqs.exe
PID: 1860
Hidden: No
Window Visible: No
Name: C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
PID: 528
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\HPZipm12.exe
PID: 616
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 692
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PID: 2216
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
PID: 2260
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\searchindexer.exe
PID: 2836
Hidden: No
Window Visible: No
Name: C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
PID: 3520
Hidden: No
Window Visible: No
Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 736
Hidden: No
Window Visible: No
Name: C:\WINDOWS\sm56hlpr.exe
PID: 2352
Hidden: No
Window Visible: No
Name: C:\Program Files\Trillian\trillian.exe
PID: 2456
Hidden: No
Window Visible: No
Name: C:\WINDOWS\RTHDCPL.exe
PID: 2512
Hidden: No
Window Visible: No
Name: C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PID: 2528
Hidden: No
Window Visible: No
Name: C:\Program Files\Trillian\trillian.exe
PID: 2532
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
PID: 2568
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
PID: 2820
Hidden: No
Window Visible: No
Name: C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
PID: 2852
Hidden: No
Window Visible: No
Name: C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
PID: 2864
Hidden: No
Window Visible: No
Name: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PID: 2908
Hidden: No
Window Visible: No
Name: C:\Program Files\PureEdge\Viewer 6.5\masqform.exe
PID: 3036
Hidden: No
Window Visible: No
Name: C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
PID: 3060
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
PID: 1720
Hidden: No
Window Visible: No
Name: C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PID: 3156
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jusched.exe
PID: 3180
Hidden: No
Window Visible: No
Name: C:\Program Files\iTunes\iTunesHelper.exe
PID: 3228
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
PID: 3252
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 3260
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\Acrobat_sl.exe
PID: 3992
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PID: 4056
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
PID: 4092
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\SetPoint\SetPoint.exe
PID: 2324
Hidden: No
Window Visible: No
Name: C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PID: 256
Hidden: No
Window Visible: No
Name: C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PID: 628
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\Connor\Desktop\SysProt\SysProt\SysProt.exe
PID: 3360
Hidden: No
Window Visible: Yes
Name: C:\WINDOWS\system32\wuauclt.exe
PID: 3460
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
PID: 3852
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\unsecapp.exe
PID: 3588
Hidden: No
Window Visible: No
Name: C:\Program Files\iPod\bin\iPodService.exe
PID: 3688
Hidden: No
Window Visible: No
********************************************************************************
**********
********************************************************************************
**********
Kernel Modules:
Module Name: \??\C:\Documents and Settings\Connor\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: A9FA4000
Module End: A9FAF000
Hidden: No
Module Name: \WINDOWS\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 804D7000
Module End: 806E4000
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806E4000
Module End: 80704D00
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F7A12000
Module End: F7A14000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F7922000
Module End: F7925000
Hidden: No
Module Name: spkl.sys
Service Name: ---
Module Base: F7314000
Module End: F7411000
Hidden: Yes
Module Name: \WINDOWS\System32\Drivers\WMILIB.SYS
Service Name: ---
Module Base: F7A14000
Module End: F7A16000
Hidden: No
Module Name: \WINDOWS\System32\Drivers\SCSIPORT.SYS
Service Name: ScsiPort
Module Base: F72FC000
Module End: F7314000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F72CE000
Module End: F72FC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F72BD000
Module End: F72CE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ohci1394.sys
Service Name: ohci1394
Module Base: F7512000
Module End: F7522000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: F7522000
Module End: F7530000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F7532000
Module End: F753C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\compbatt.sys
Service Name: Compbatt
Module Base: F7926000
Module End: F7929000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\BATTC.SYS
Service Name: BattC
Module Base: F792A000
Module End: F792E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F7ADA000
Module End: F7ADB000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F7792000
Module End: F7799000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F7542000
Module End: F754D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F729E000
Module End: F72BD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: F7A16000
Module End: F7A18000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: F7278000
Module End: F729E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPIEC.sys
Service Name: ACPIEC
Module Base: F792E000
Module End: F7931000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
Service Name: ---
Module Base: F7ADB000
Module End: F7ADC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F779A000
Module End: F779F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F7552000
Module End: F755F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\iviVD.sys
Service Name: iviVD
Module Base: F7562000
Module End: F756D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F7260000
Module End: F7278000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\viamraid.sys
Service Name: viamraid
Module Base: F7572000
Module End: F7581000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F7582000
Module End: F758B000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F7592000
Module End: F759F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: F7240000
Module End: F7260000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F722E000
Module End: F7240000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Lbd.sys
Service Name: Lbd
Module Base: F75A2000
Module End: F75B1000
Hidden: No
Module Name: SYMEFA.SYS
Service Name: SymEFA
Module Base: F71DF000
Module End: F722E000
Hidden: Yes
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F71C8000
Module End: F71DF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F713B000
Module End: F71C8000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F710E000
Module End: F713B000
Hidden: No
Module Name: C:\WINDOWS\system32\speedfan.sys
Service Name: speedfan
Module Base: F7A18000
Module End: F7A1A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F70F4000
Module End: F710E000
Hidden: No
Module Name: C:\WINDOWS\system32\giveio.sys
Service Name: giveio
Module Base: F7ADC000
Module End: F7ADD000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tunmp.sys
Service Name: tunmp
Module Base: F6836000
Module End: F6839000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F7622000
Module End: F762B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\CmBatt.sys
Service Name: CmBatt
Module Base: F682A000
Module End: F682E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
Service Name: ati2mtag
Module Base: F631D000
Module End: F6608000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F6309000
Module End: F631D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
Service Name: WmiAcpi
Module Base: F6826000
Module End: F6829000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: F62E1000
Module End: F6309000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\NETw3x32.sys
Service Name: NETw3x32
Module Base: F613F000
Module End: F62E1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F790A000
Module End: F7910000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F611B000
Module End: F613F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F7912000
Module End: F791A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F7632000
Module End: F763F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F791A000
Module End: F7920000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\SynTP.sys
Service Name: SynTP
Module Base: F60EC000
Module End: F611B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F7AA0000
Module End: F7AA2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F77AA000
Module End: F77B0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F693A000
Module End: F6945000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F692A000
Module End: F693A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F691A000
Module End: F6929000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: F60C9000
Module End: F60EC000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\InCDPass.sys
Service Name: InCDPass
Module Base: F77B2000
Module End: F77BA000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\incdrm.SYS
Service Name: incdrm
Module Base: F77EA000
Module End: F77F1000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys
Service Name: GEARAspiWDM
Module Base: F77FA000
Module End: F7800000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Service Name: ---
Module Base: F6020000
Module End: F6085000
Hidden: Yes
Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7BC0000
Module End: F7BC1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F68CA000
Module End: F68D7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F70B4000
Module End: F70B7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F5F51000
Module End: F5F68000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F68BA000
Module End: F68C5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F7612000
Module End: F761E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F78AA000
Module End: F78AF000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys
Service Name: PSched
Module Base: F5F40000
Module End: F5F51000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F68AA000
Module End: F68B3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F4B76000
Module End: F4B7B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F4B6E000
Module End: F4B73000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: F3F09000
Module End: F3F39000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F54D0000
Module End: F54DA000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\SymIM.sys
Service Name: SymIM
Module Base: F4B66000
Module End: F4B6E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F7A1C000
Module End: F7A1E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\update.sys
Service Name: Update
Module Base: F3E4F000
Module End: F3EAD000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F79EA000
Module End: F79EE000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F690A000
Module End: F6914000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\smserial.sys
Service Name: smserial
Module Base: AE6A2000
Module End: AE771000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F4214000
Module End: F421C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\RtkHDAud.sys
Service Name: IntcAzAudAddService
Module Base: AE270000
Module End: AE6A2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: AE24C000
Module End: AE270000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: F4379000
Module End: F4388000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F4349000
Module End: F4358000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SRTSP.SYS
Service Name: SRTSP
Module Base: AE1F9000
Module End: AE24C000
Hidden: No
Module Name: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091103.007\NAVEX15.SYS
Service Name: NAVEX15
Module Base: AE0B7000
Module End: AE1F9000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Service Name: SymEvent
Module Base: AE092000
Module End: AE0B7000
Hidden: No
Module Name: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091103.007\NAVENG.SYS
Service Name: NAVENG
Module Base: AE07E000
Module End: AE092000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Service Name: usbstor
Module Base: F7832000
Module End: F7839000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\usbaapl.sys
Service Name: USBAAPL
Module Base: F75F2000
Module End: F7600000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Service Name: usbccgp
Module Base: F7842000
Module End: F784A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\usbaudio.sys
Service Name: usbaudio
Module Base: F7602000
Module End: F7611000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NIS\1007020.00B\SRTSPX.SYS
Service Name: SRTSPX
Module Base: F3FB9000
Module End: F3FC3000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F7A70000
Module End: F7A72000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F7C5B000
Module End: F7C5C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F7A74000
Module End: F7A76000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: F41F4000
Module End: F41FB000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F78C2000
Module End: F78C8000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F7A88000
Module End: F7A8A000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F7A8A000
Module End: F7A8C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\InCDrec.SYS
Service Name: InCDrec
Module Base: F4757000
Module End: F475A000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\InCDfs.SYS
Service Name: InCDfs
Module Base: AE045000
Module End: AE05E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F7862000
Module End: F7867000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F4B8E000
Module End: F4B96000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: F79D6000
Module End: F79D9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: AE032000
Module End: AE045000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: ADFD9000
Module End: AE032000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMTDI.SYS
Service Name: SYMTDI
Module Base: ADFA5000
Module End: ADFD9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: ADF7F000
Module End: ADFA5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F75C2000
Module End: F75CB000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMNDIS.SYS
Service Name: SYMNDIS
Module Base: F78BA000
Module End: F78C2000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMFW.SYS
Service Name: SYMFW
Module Base: ADF6A000
Module End: ADF7F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMIDS.SYS
Service Name: SYMIDS
Module Base: F78CA000
Module End: F78D1000
Hidden: No
Module Name: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20091102.002\IDSxpx86.sys
Service Name: IDSxpx86
Module Base: ADF16000
Module End: ADF6A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: ADEEE000
Module End: ADF16000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip6.sys
Service Name: Tcpip6
Module Base: ADEB6000
Module End: ADEEE000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: ADE94000
Module End: ADEB6000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ip6fw.sys
Service Name: Ip6Fw
Module Base: F4359000
Module End: F4362000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: F3F79000
Module End: F3F82000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SCDEmu.SYS
Service Name: SCDEmu
Module Base: F421C000
Module End: F4224000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: ADE41000
Module End: ADE6C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: ADDD1000
Module End: ADE41000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Service Name: HidUsb
Module Base: F381B000
Module End: F381E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: F5540000
Module End: F5549000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: F7742000
Module End: F774D000
Hidden: No
Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
Service Name: eeCtrl
Module Base: ADD73000
Module End: ADDD1000
Hidden: No
Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
Service Name: EraserUtilRebootDrv
Module Base: ADD56000
Module End: ADD73000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\ccHPx86.sys
Service Name: ccHP
Module Base: ADCDB000
Module End: ADD56000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NIS\1007020.00B\BHDrvx86.sys
Service Name: BHDrvx86
Module Base: ADC99000
Module End: ADCDB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: F7087000
Module End: F708B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
Service Name: LHidKe
Module Base: F78DA000
Module End: F78E1000
Hidden: No
Module Name: \??\C:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys
Service Name: atitray
Module Base: F708B000
Module End: F708F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: F7077000
Module End: F707A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
Service Name: LMouKE
Module Base: ADC60000
Module End: ADC71000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: ADC3C000
Module End: ADC60000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_diskdump.sys
Service Name: ---
Module Base: F7097000
Module End: F709B000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_viamraid.sys
Service Name: ---
Module Base: F7772000
Module End: F7781000
Hidden: Yes
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: ADE70000
Module End: ADE73000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: F7852000
Module End: F7857000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: F7B1F000
Module End: F7B20000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: AB95C000
Module End: AB960000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: AB6DF000
Module End: AB6F4000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: AB73C000
Module End: AB74B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\secdrv.sys
Service Name: Secdrv
Module Base: F3F99000
Module End: F3FA3000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\symlcbrd.sys
Service Name: symlcbrd
Module Base: F780A000
Module End: F7810000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: AB79C000
Module End: AB7AC000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\TDTCP.SYS
Service Name: TDTCP
Module Base: F789A000
Module End: F78A0000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\RDPWD.SYS
Service Name: RDPWD
Module Base: AADC3000
Module End: AADE6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys
Service Name: Srv
Module Base: AAB91000
Module End: AABE3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: AA774000
Module End: AA79F000
Hidden: No
********************************************************************************
**********
********************************************************************************
**********
SSDT:
Function Name: ZwAlertResumeThread
Address: 85C9A790
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAlertThread
Address: 85C9A870
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAllocateVirtualMemory
Address: 85DB2778
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAssignProcessToJobObject
Address: 8521CD48
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwConnectPort
Address: 87130620
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateKey
Address: AE0A8130
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwCreateMutant
Address: 85C9A300
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateSymbolicLinkObject
Address: 8521CB68
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateThread
Address: 86C4F4D8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDebugActiveProcess
Address: 8521CE28
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDeleteKey
Address: AE0A83B0
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwDeleteValueKey
Address: AE0A8910
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwDuplicateObject
Address: 85DB3370
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwEnumerateKey
Address: F7332CA2
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwEnumerateValueKey
Address: F7333030
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwFreeVirtualMemory
Address: 85DB25D8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwImpersonateAnonymousToken
Address: 85C9A3F0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwImpersonateThread
Address: 85C9A4D0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwLoadDriver
Address: 8712A268
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwMapViewOfSection
Address: 852A0348
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenEvent
Address: 85C9A220
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenKey
Address: F73150C0
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwOpenProcess
Address: 85C9D300
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenProcessToken
Address: 85DB32F0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenSection
Address: 85C9A060
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenThread
Address: 85DB3440
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwProtectVirtualMemory
Address: 8521CC58
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwQueryKey
Address: F7333108
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwQueryValueKey
Address: F7332F88
Driver Base: F7314000
Driver End: F7411000
Driver Name: spkl.sys
Function Name: ZwResumeThread
Address: 85DA7E38
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetContextThread
Address: 85DB2300
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetInformationProcess
Address: 85DB23C0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetSystemInformation
Address: 8521CF08
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetValueKey
Address: AE0A8B60
Driver Base: AE092000
Driver End: AE0B7000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwSuspendProcess
Address: 85C9A140
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSuspendThread
Address: 85C9A930
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwTerminateProcess
Address: 85DC56C0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwTerminateThread
Address: 85C9AF90
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwUnmapViewOfSection
Address: 85DB2490
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwWriteVirtualMemory
Address: 85DB26A8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
********************************************************************************
**********
********************************************************************************
**********
No Kernel Hooks found
********************************************************************************
**********
********************************************************************************
**********
IRP Hooks:
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\iviVD.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871641F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_CREATE
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_POWER
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\a4cza4bo.SYS
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86C801F8
Hooking Module: _unknown_
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLOSE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_READ
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_WRITE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_EA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLEANUP
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_POWER
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: F7315000
Hooking Module: spkl.sys
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_READ
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871D51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_CREATE
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_READ
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_WRITE
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_POWER
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86F02500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86CC01F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_READ
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871651F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\viamraid.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 871631F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 86F24500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_READ
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86C821F8
Hooking Module: _unknown_
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CREATE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CLOSE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_READ
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_WRITE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_EA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CLEANUP
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_POWER
Jump To: F731CE1C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F7330514
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: \Driver\PCI_PNP0416
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: F7356B0C
Hooking Module: spkl.sys
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 86EA0500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 86EA0500
Hooking Module: _unknown_
********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: CONNOR:50701
Remote Address: LOCALHOST:1032
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
State: ESTABLISHED
Local Address: CONNOR:50701
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
State: LISTENING
Local Address: CONNOR:27015
Remote Address: LOCALHOST:1036
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED
Local Address: CONNOR:27015
Remote Address: LOCALHOST:1034
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED
Local Address: CONNOR:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING
Local Address: CONNOR:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING
Local Address: CONNOR:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: CONNOR:1036
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED
Local Address: CONNOR:1034
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED
Local Address: CONNOR:1032
Remote Address: LOCALHOST:50701
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: ESTABLISHED
Local Address: CONNOR:1031
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
State: LISTENING
Local Address: CONNOR:1044
Remote Address: 63.251.254.131:HTTP
Type: TCP
Process: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
State: SYN_SENT
Local Address: CONNOR:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: CONNOR:3703
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: LISTENING
Local Address: CONNOR:3389
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: CONNOR:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: CONNOR:427
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: LISTENING
Local Address: CONNOR:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: CONNOR:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: CONNOR:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: NA
Local Address: CONNOR:1039
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: CONNOR:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: CONNOR:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:52329
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: CONNOR:9370
Remote Address: NA
Type: UDP
Process: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
State: NA
Local Address: CONNOR:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: CONNOR:3703
Remote Address: NA
Type: UDP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: NA
Local Address: CONNOR:3544
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: CONNOR:1029
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\spoolsv.exe
State: NA
Local Address: CONNOR:1025
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: CONNOR:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: CONNOR:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: CONNOR:427
Remote Address: NA
Type: UDP
Process: C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
State: NA
********************************************************************************
**********
********************************************************************************
**********
Hidden files/folders:
Object: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\34EB0A60.TMP
Status: Access denied
Object: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\68A5962A.TMP
Status: Access denied
Object: C:\System Volume Information\EfaData
Status: Access denied
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\_restore{029932C0-D74E-4292-AF45-3DA84248588C}
Status: Access denied[/quote]