Ok...I have completed all of that. I have included all the logs. Once again, thank you very much for all your help.
Combo-fix Log
ComboFix 09-08-20.07 - HP_Administrator 08/21/2009 7:48.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.513 [GMT -5:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\c31f316.msp
c:\windows\Installer\c31f329.msp
c:\windows\Installer\c31f331.msp
c:\windows\system32\drivers\Sonyhcp.dll
c:\windows\system32\drivers\UACemmyqyrdqj.sys
c:\windows\system32\UAChnywkvlsxw.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACklnxnvrlae.dll
c:\windows\system32\UACotqluqqrfb.dll
c:\windows\system32\UACpxkjqeuwrb.dll
c:\windows\system32\UACtwvabvdtpb.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-21 to 2009-08-21 )))))))))))))))))))))))))))))))
.
2009-08-21 04:46 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-21 04:46 . 2009-08-21 05:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-21 04:46 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-20 21:57 . 2009-08-20 21:57 0 ----a-w- c:\windows\nsreg.dat
2009-08-20 21:57 . 2009-08-20 21:57 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Mozilla
2009-08-12 02:20 . 2009-08-18 21:27 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-12 02:20 . 2009-08-18 21:25 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-02 22:03 . 2009-08-21 10:10 -------- d--h--w- C:\$AVG8.VAULT$
2009-08-02 21:56 . 2009-08-02 21:56 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-02 21:56 . 2009-08-02 21:56 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-02 21:56 . 2009-08-02 21:56 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-02 21:56 . 2009-08-02 21:56 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-02 21:55 . 2009-08-12 01:30 -------- d-----w- c:\windows\system32\drivers\Avg
2009-08-02 21:55 . 2009-08-02 21:55 -------- d-----w- c:\program files\AVG
2009-08-02 21:55 . 2009-08-02 21:55 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-08-02 21:16 . 2009-08-02 21:16 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\AVG8
2009-08-02 17:18 . 2009-08-02 17:18 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-02 17:06 . 2009-08-02 17:06 0 ----a-w- c:\windows\system32\cmpwrap.dat
2009-07-28 18:52 . 2009-07-28 18:52 -------- d-----w- c:\program files\Linksys
2009-07-28 18:52 . 2008-12-12 23:05 23984 ----a-w- c:\windows\system32\drivers\pnarp.sys
2009-07-28 18:52 . 2008-12-12 23:05 25264 ----a-w- c:\windows\system32\drivers\purendis.sys
2009-07-28 18:51 . 2009-07-28 18:51 -------- d-----w- c:\program files\Common Files\Pure Networks Shared
2009-07-28 18:51 . 2009-07-28 18:51 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Pure Networks
2009-07-28 18:50 . 2008-12-04 13:17 627072 ----a-r- c:\windows\system32\drivers\WUSB54GCv3.sys
2009-07-28 18:50 . 2008-12-04 13:17 221184 ----a-w- c:\windows\system32\RaCoInst.dll
2009-07-28 18:50 . 2008-12-04 13:17 15312 ----a-r- c:\windows\system32\RaCoInst.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-12 03:14 . 2006-06-05 13:40 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Yahoo!
2009-08-12 03:14 . 2006-04-26 17:49 -------- d-----w- c:\program files\Yahoo!
2009-08-12 03:14 . 2007-05-05 20:46 -------- d--h--r- c:\documents and settings\HP_Administrator\Application Data\yahoo!
2009-08-02 22:25 . 2005-05-05 15:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-02 22:25 . 2006-05-30 21:54 -------- d-----w- c:\program files\Verizon
2009-07-14 18:44 . 2005-06-23 03:10 55048 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-12 00:06 . 2005-05-05 16:02 -------- d-----w- c:\program files\Google
2009-07-11 23:54 . 2005-05-05 15:26 -------- d-----w- c:\program files\HP
2009-07-11 23:54 . 2005-05-05 15:26 -------- d-----w- c:\program files\Hewlett-Packard
2009-07-11 23:53 . 2009-07-11 23:53 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\HP Product Assistant
2009-07-11 23:49 . 2003-05-19 22:01 139264 ----a-w- c:\windows\system32\hpzjrd01.dll
2009-07-11 23:36 . 2009-07-11 23:36 -------- d-----w- c:\program files\MSBuild
2009-07-11 23:35 . 2009-07-11 23:35 -------- d-----w- c:\program files\Reference Assemblies
2009-07-11 16:14 . 2006-09-05 12:39 -------- d-----w- c:\program files\fsupport
2009-07-11 14:51 . 2009-07-11 14:50 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Lavasoft
2009-07-11 14:51 . 2009-07-11 14:51 -------- dc-h--w- c:\docume~1\ALLUSE~1\APPLIC~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-11 14:50 . 2006-02-15 19:59 -------- d-----w- c:\program files\Lavasoft
2009-07-03 17:09 . 2004-08-10 04:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-03 14:49 . 2009-07-11 14:51 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-03 14:49 . 2009-07-11 16:14 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-16 14:36 . 2004-08-10 04:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-10 04:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2004-08-10 04:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2005-07-17 20:00 . 2005-07-17 20:00 251 ----a-w- c:\program files\wt3d.ini
2005-07-20 15:45 . 2005-07-20 15:45 22 --sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-08-19_03.20.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-21 12:46 . 2009-08-21 12:46 16384 c:\windows\temp\Perflib_Perfdata_3a8.dat
+ 2005-01-28 02:47 . 2009-08-20 21:45 73100 c:\windows\system32\perfc009.dat
- 2005-01-28 02:47 . 2009-07-28 18:51 73100 c:\windows\system32\perfc009.dat
- 2009-07-11 16:14 . 2009-08-19 03:18 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-11 16:14 . 2009-08-21 06:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-01-27 18:29 . 2009-08-21 06:04 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-01-27 18:29 . 2009-08-19 03:18 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-08-02 17:18 . 2009-08-20 21:17 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-08-02 17:18 . 2009-08-19 03:18 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2005-01-27 18:29 . 2009-08-19 03:18 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-01-27 18:29 . 2009-08-21 06:04 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2005-01-28 02:47 . 2009-07-28 18:51 446338 c:\windows\system32\perfh009.dat
+ 2005-01-28 02:47 . 2009-08-20 21:45 446338 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 245760]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-02 339968]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-02-16 1358384]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-02 2000152]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-09-22 14854144]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-03-04 88209]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-23 39264]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2005-5-5 45056]
WG111v2 Smart Wizard Wireless Setting.lnk - c:\program files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2008-9-18 745472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-02 21:56 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/11/2009 9:51 AM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/2/2009 4:56 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/2/2009 4:56 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/2/2009 4:55 PM 297752]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [9/18/2008 8:27 PM 66048]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [7/28/2009 1:50 PM 627072]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [9/18/2008 8:27 PM 167808]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search -
http://kl.bar.need2find.com/KL/menusearch.html?p=KLIE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: kaspersky.nl\www
FF - ProfilePath - c:\docume~1\HP_ADM~1\APPLIC~1\Mozilla\Firefox\Profiles\azhv9w8e.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-21 07:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(916)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-08-21 8:01
ComboFix-quarantined-files.txt 2009-08-21 13:01
ComboFix2.txt 2009-08-19 03:25
Pre-Run: 195,689,365,504 bytes free
Post-Run: 195,670,073,344 bytes free
241 --- E O F --- 2009-08-12 02:01
SysProt LOG
SysProt AntiRootkit v1.0.1.0
by swatkat
********************************************************************************
**********
********************************************************************************
**********
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 796
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 888
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 916
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 960
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 972
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 1120
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1152
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1248
Hidden: No
Window Visible: No
Name: C:\Program Files\Windows Defender\MsMpEng.exe
PID: 1308
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1348
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1664
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1756
Hidden: No
Window Visible: No
Name: C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PID: 1972
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 212
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 416
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 548
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PID: 632
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 644
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
PID: 664
Hidden: No
Window Visible: No
Name: C:\WINDOWS\ehome\ehrecvr.exe
PID: 704
Hidden: No
Window Visible: No
Name: C:\WINDOWS\ehome\ehSched.exe
PID: 736
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 876
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jqs.exe
PID: 936
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PID: 1452
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PID: 1500
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\HPZipm12.exe
PID: 1540
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1596
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1624
Hidden: No
Window Visible: No
Name: C:\WINDOWS\ehome\mcrdsvc.exe
PID: 1748
Hidden: No
Window Visible: No
Name: C:\Program Files\AVG\AVG8\avgrsx.exe
PID: 1832
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\AVG\AVG8\avgnsx.exe
PID: 1840
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PID: 696
Hidden: No
Window Visible: No
Name: C:\Program Files\Windows Media Player\wmpnetwk.exe
PID: 2148
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\dllhost.exe
PID: 3520
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\unsecapp.exe
PID: 3536
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\alg.exe
PID: 3752
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\wmiprvse.exe
PID: 3968
Hidden: No
Window Visible: No
Name: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PID: 508
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\notepad.exe
PID: 2204
Hidden: No
Window Visible: Yes
Name: C:\WINDOWS\explorer.exe
PID: 1788
Hidden: No
Window Visible: No
Name: C:\Program Files\Mozilla Firefox\firefox.exe
PID: 1316
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\HP_Administrator\Desktop\SysProt\SysProt\SysProt.exe
PID: 2872
Hidden: No
Window Visible: Yes
********************************************************************************
**********
********************************************************************************
**********
Kernel Modules:
Module Name: \??\C:\Documents and Settings\HP_Administrator\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: B8127000
Module End: B8132000
Hidden: No
Module Name: \WINDOWS\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 804D7000
Module End: 806E4000
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806E4000
Module End: 80704D00
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F7A90000
Module End: F7A92000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F79A0000
Module End: F79A3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F7461000
Module End: F748F000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F7A92000
Module End: F7A94000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F7450000
Module End: F7461000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F7590000
Module End: F759A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F7B58000
Module End: F7B59000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F7810000
Module End: F7817000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F75A0000
Module End: F75AB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F7431000
Module End: F7450000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: F7A94000
Module End: F7A96000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: F740B000
Module End: F7431000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F7818000
Module End: F781D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F75B0000
Module End: F75BD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F73F3000
Module End: F740B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fasttx2k.sys
Service Name: fasttx2k
Module Base: F73D0000
Module End: F73F3000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
Service Name: ScsiPort
Module Base: F73B8000
Module End: F73D0000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F75C0000
Module End: F75C9000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F75D0000
Module End: F75DD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: F7398000
Module End: F73B8000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F7386000
Module End: F7398000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Lbd.sys
Service Name: Lbd
Module Base: F75E0000
Module End: F75EF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F7820000
Module End: F7825000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F736F000
Module End: F7386000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F72E2000
Module End: F736F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F72B5000
Module End: F72E2000
Hidden: No
Module Name: Combo-Fix.sys
Service Name: ---
Module Base: F75F0000
Module End: F75FF000
Hidden: Yes
Module Name: C:\WINDOWS\system32\drivers\ohci1394.sys
Service Name: ohci1394
Module Base: F7600000
Module End: F7610000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: F7610000
Module End: F761E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F729B000
Module End: F72B5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\nic1394.sys
Service Name: NIC1394
Module Base: F7640000
Module End: F7650000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F7670000
Module End: F7679000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
Service Name: ati2mtag
Module Base: F6F0D000
Module End: F7002000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F6EF9000
Module End: F6F0D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: F6ED1000
Module End: F6EF9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F7968000
Module End: F796E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F6EAD000
Module End: F6ED1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F7970000
Module End: F7978000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hcwPP2.sys
Service Name: hcwPP2
Module Base: F6E88000
Module End: F6EAD000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: F6E65000
Module End: F6E88000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\AGRSM.sys
Service Name: AgereSoftModem
Module Base: F6D60000
Module End: F6E65000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F7978000
Module End: F7980000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\e100b325.sys
Service Name: E100B
Module Base: F6D3A000
Module End: F6D60000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\parport.sys
Service Name: Parport
Module Base: F6D26000
Module End: F6D3A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F7680000
Module End: F768D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F7980000
Module End: F7986000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\PS2.sys
Service Name: Ps2
Module Base: F7988000
Module End: F798D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F7990000
Module End: F7996000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F7690000
Module End: F769B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F76A0000
Module End: F76B0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F76B0000
Module End: F76BF000
Hidden: No
Module Name: C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys
Service Name: GEARAspiWDM
Module Base: F7A74000
Module End: F7A77000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7BB0000
Module End: F7BB1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F76C0000
Module End: F76CD000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F7A80000
Module End: F7A83000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F6CE7000
Module End: F6CFE000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F76D0000
Module End: F76DB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F76E0000
Module End: F76EC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F7998000
Module End: F799D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys
Service Name: PSched
Module Base: F6CD6000
Module End: F6CE7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F76F0000
Module End: F76F9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F7830000
Module End: F7835000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F7860000
Module End: F7865000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: F6CA6000
Module End: F6CD6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F7700000
Module End: F770A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F7ABA000
Module End: F7ABC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\update.sys
Service Name: Update
Module Base: F6C48000
Module End: F6CA6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F726B000
Module End: F726F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F7710000
Module End: F771A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\RtkHDAud.sys
Service Name: IntcAzAudAddService
Module Base: EE81B000
Module End: EEC00000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: EE7F7000
Module End: EE81B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: F7082000
Module End: F7091000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F7072000
Module End: F7081000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F7ABE000
Module End: F7AC0000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F7AC0000
Module End: F7AC2000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F7CCD000
Module End: F7CCE000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F7AC2000
Module End: F7AC4000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: F7888000
Module End: F788F000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F7890000
Module End: F7896000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F7AC4000
Module End: F7AC6000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F7AC6000
Module End: F7AC8000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F7898000
Module End: F789D000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F78A0000
Module End: F78A8000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: F7A64000
Module End: F7A67000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: EDF7C000
Module End: EDF8F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: EDF23000
Module End: EDF7C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\avgtdix.sys
Service Name: AvgTdiX
Module Base: EDF0A000
Module End: EDF23000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: EDEE4000
Module End: EDF0A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F7052000
Module End: F705B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: EDEBC000
Module End: EDEE4000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: EDE9A000
Module End: EDEBC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: F7042000
Module End: F704B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: EDE6F000
Module End: EDE9A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: EDDD7000
Module End: EDE47000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: F7032000
Module End: F703D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\arp1394.sys
Service Name: Arp1394
Module Base: F7022000
Module End: F7031000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Service Name: USBSTOR
Module Base: F78A8000
Module End: F78AF000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\WUSB54GCv3.sys
Service Name: WUSB54GCv3
Module Base: EDC9D000
Module End: EDD37000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\BANTExt.sys
Service Name: BANTExt
Module Base: F7BA1000
Module End: F7BA2000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\avgmfx86.sys
Service Name: AvgMfx86
Module Base: F78B0000
Module End: F78B6000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\avgldx86.sys
Service Name: AvgLdx86
Module Base: EDC4C000
Module End: EDC9D000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: EDC28000
Module End: EDC4C000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: EDC10000
Module End: EDC28000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7B00000
Module End: F7B02000
Hidden: Yes
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: EDFC7000
Module End: EDFCA000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: F78F0000
Module End: F78F5000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: F7C8D000
Module End: F7C8E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\EAPPkt.sys
Service Name: EAPPkt
Module Base: B8DBF000
Module End: B8DD0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: B8F30000
Module End: B8F34000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\pnarp.sys
Service Name: pnarp
Module Base: F7930000
Module End: F7935000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\purendis.sys
Service Name: purendis
Module Base: F7940000
Module End: F7945000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: B8B3A000
Module End: B8B67000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: B8B25000
Module End: B8B3A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: B8CBF000
Module End: B8CCE000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: B89D1000
Module End: B8A12000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys
Service Name: Srv
Module Base: B865F000
Module End: B86B1000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\TDTCP.SYS
Service Name: TDTCP
Module Base: F78D8000
Module End: F78DE000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\RDPWD.SYS
Service Name: RDPWD
Module Base: B7F5C000
Module End: B7F7F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MSPQM.sys
Service Name: MSPQM
Module Base: F7AFC000
Module End: F7AFE000
Hidden: No
Module Name: \??\C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\catchme.sys
Service Name: catchme
Module Base: F78C0000
Module End: F78C8000
Hidden: Yes
Module Name: \??\C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Service Name: ---
Module Base: F7B2A000
Module End: F7B2C000
Hidden: Yes
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: B7E43000
Module End: B7E6E000
Hidden: No
********************************************************************************
**********
********************************************************************************
**********
SSDT:
Function Name: ZwCreateKey
Address: F75E087E
Driver Base: F75E0000
Driver End: F75EF000
Driver Name: Lbd.sys
Function Name: ZwSetValueKey
Address: F75E0BFE
Driver Base: F75E0000
Driver End: F75EF000
Driver Name: Lbd.sys
********************************************************************************
**********
********************************************************************************
**********
No Kernel Hooks found
********************************************************************************
**********
********************************************************************************
**********
No IRP Hooks found
********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: HPMCE2005:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: HPMCE2005:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING
Local Address: HPMCE2005:18080
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe
State: LISTENING
Local Address: HPMCE2005:13128
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe
State: LISTENING
Local Address: HPMCE2005:10080
Remote Address: LOCALHOST:1441
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: HPMCE2005:10080
Remote Address: LOCALHOST:1439
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: HPMCE2005:10080
Remote Address: LOCALHOST:1437
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: HPMCE2005:10080
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe
State: LISTENING
Local Address: HPMCE2005:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: HPMCE2005:1256
Remote Address: LOCALHOST:1255
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: HPMCE2005:1255
Remote Address: LOCALHOST:1256
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: HPMCE2005:1252
Remote Address: LOCALHOST:1251
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: HPMCE2005:1251
Remote Address: LOCALHOST:1252
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: HPMCE2005:1031
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING
Local Address: HPMCE2005:3389
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: HPMCE2005:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: HPMCE2005:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: HPMCE2005:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HPMCE2005:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: HPMCE2005:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: HPMCE2005:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HPMCE2005:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HPMCE2005:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HPMCE2005:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: HPMCE2005:3776
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\ehome\mcrdsvc.exe
State: NA
Local Address: HPMCE2005:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: HPMCE2005:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
********************************************************************************
**********
********************************************************************************
**********
Hidden files/folders:
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}
Status: Access denied