GMER-1.log 2 got hung up and system froze.
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-07-24 08:49:47
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
Code 858556DE ZwEnumerateKey
Code 859635BE ZwFlushInstructionCache
Code 85856C35 IofCallDriver
Code 853513ED IofCompleteRequest
Code 8587BDED ZwSaveKey
Code 8565A735 ZwSaveKeyEx
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\kungsfiwtgxiif.sys (*** hidden *** ) [SYSTEM] kungsffifukier <-- ROOTKIT !!!
Service C:\WINDOWS\system32\drivers\SKYNETnypymufx.sys (*** hidden *** ) [SYSTEM] SKYNETxmkxidjr <-- ROOTKIT !!!
Service C:\WINDOWS\system32\drivers\UACdojdvjiyey.sys (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
---------------------------------------------
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 796
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 848
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 872
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 920
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 932
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1108
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1196
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1260
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1328
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1564
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 1580
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 1888
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 2008
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 148
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 284
Hidden: No
Window Visible: No
Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 340
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jqs.exe
PID: 500
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PID: 548
Hidden: No
Window Visible: No
Name: C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PID: 588
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\nvsvc32.exe
PID: 692
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 844
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wdfmgr.exe
PID: 1688
Hidden: No
Window Visible: No
Name: C:\WINDOWS\msa.exe
PID: 1488
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 2144
Hidden: No
Window Visible: No
Name: C:\Program Files\Vongo\VongoService.exe
PID: 2272
Hidden: No
Window Visible: No
Name: C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PID: 2316
Hidden: No
Window Visible: No
Name: C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
PID: 2424
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\alg.exe
PID: 2720
Hidden: No
Window Visible: No
Name: C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
PID: 2812
Hidden: No
Window Visible: No
Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 2840
Hidden: No
Window Visible: No
Name: C:\Program Files\Hp\QuickPlay\QPService.exe
PID: 2848
Hidden: No
Window Visible: No
Name: C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
PID: 2868
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PID: 2928
Hidden: No
Window Visible: No
Name: C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
PID: 2976
Hidden: No
Window Visible: No
Name: C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PID: 3064
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jusched.exe
PID: 3104
Hidden: No
Window Visible: No
Name: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PID: 3212
Hidden: No
Window Visible: No
Name: C:\Program Files\PeerGuardian2\pg2.exe
PID: 3256
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\wmiprvse.exe
PID: 3312
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\wmiprvse.exe
PID: 3680
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
PID: 2668
Hidden: No
Window Visible: No
Name: C:\Program Files\Internet Explorer\iexplore.exe
PID: 3752
Hidden: No
Window Visible: No
Name: C:\Program Files\Internet Explorer\iexplore.exe
PID: 3792
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wuauclt.exe
PID: 1960
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\me.PC608619932964\Desktop\Unused Desktop Shortcuts\SysProt\SysProt\SysProt.exe
PID: 3100
Hidden: No
Window Visible: Yes
Name: C:\WINDOWS\system32\wuauclt.exe
PID: 2388
Hidden: No
Window Visible: No
Name: C:\DOCUME~1\MEA40B~1.PC6\LOCALS~1\Temp\b.exe
PID: 2176
Hidden: No
Window Visible: No
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: C:\WINDOWS\system32\drivers\kungsfiwtgxiif.sys
Service Name: kungsffifukier
Module Base: ---
Module End: ---
Hidden: Yes
Module Name: \systemroot\system32\drivers\SKYNETnypymufx.sys
Service Name: SKYNETxmkxidjr
Module Base: ---
Module End: ---
Hidden: Yes
Module Name: \systemroot\system32\drivers\UACdojdvjiyey.sys
Service Name: UACd.sys
Module Base: ---
Module End: ---
Hidden: Yes
Module Name: \??\C:\Documents and Settings\me.PC608619932964\Desktop\Unused Desktop Shortcuts\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: B85A0000
Module End: B85AB000
Hidden: No
Module Name: \WINDOWS\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 804D7000
Module End: 806E2000
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806E2000
Module End: 80702C80
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F7A70000
Module End: F7A72000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F7980000
Module End: F7983000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F7441000
Module End: F746F000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F7A72000
Module End: F7A74000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F7430000
Module End: F7441000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F7570000
Module End: F7579000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ohci1394.sys
Service Name: ohci1394
Module Base: F7580000
Module End: F758F000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: F7590000
Module End: F759D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\compbatt.sys
Service Name: Compbatt
Module Base: F7984000
Module End: F7987000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\BATTC.SYS
Service Name: BattC
Module Base: F7988000
Module End: F798C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F7B38000
Module End: F7B39000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F77F0000
Module End: F77F7000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\intelide.sys
Service Name: IntelIde
Module Base: F7A74000
Module End: F7A76000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\viaide.sys
Service Name: ViaIde
Module Base: F7A76000
Module End: F7A78000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\aliide.sys
Service Name: AliIde
Module Base: F7A78000
Module End: F7A7A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pcmcia.sys
Service Name: Pcmcia
Module Base: F7412000
Module End: F7430000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F75A0000
Module End: F75AB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F73F3000
Module End: F7412000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPIEC.sys
Service Name: ACPIEC
Module Base: F798C000
Module End: F798F000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
Service Name: ---
Module Base: F7B39000
Module End: F7B3A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F77F8000
Module End: F77FD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F75B0000
Module End: F75BD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F73DB000
Module End: F73F3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\nvata.sys
Service Name: nvata
Module Base: F73C2000
Module End: F73DB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F75C0000
Module End: F75C9000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F75D0000
Module End: F75DD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltMgr.sys
Service Name: FltMgr
Module Base: F73A3000
Module End: F73C2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F7391000
Module End: F73A3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F7800000
Module End: F7805000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F737A000
Module End: F7391000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F72ED000
Module End: F737A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F72C0000
Module End: F72ED000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Serial.sys
Service Name: Serial
Module Base: F75E0000
Module End: F75F0000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F72A5000
Module End: F72C0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\nic1394.sys
Service Name: NIC1394
Module Base: F75F0000
Module End: F7600000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\AmdK8.sys
Service Name: AmdK8
Module Base: F7620000
Module End: F762E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
Service Name: HBtnKey
Module Base: F6A35000
Module End: F6A38000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: F7630000
Module End: F7639000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: F78F0000
Module End: F78F7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
Service Name: WmiAcpi
Module Base: F6A31000
Module End: F6A34000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
Service Name: BCM43XX
Module Base: F5CAC000
Module End: F5D14000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
Service Name: nv
Module Base: F592E000
Module End: F5CAC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F591A000
Module End: F592E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\nvsmu.sys
Service Name: nvsmu
Module Base: F6A1D000
Module End: F6A20000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Service Name: usbohci
Module Base: F78F8000
Module End: F78FD000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F58F7000
Module End: F591A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F7900000
Module End: F7907000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F7640000
Module End: F764B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F7650000
Module End: F765D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F7660000
Module End: F766E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: F58D4000
Module End: F58F7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
Service Name: GEARAspiWDM
Module Base: F7670000
Module End: F767A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\sdbus.sys
Service Name: sdbus
Module Base: F58C3000
Module End: F58D4000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
Service Name: rimmptsk
Module Base: F7908000
Module End: F7910000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
Service Name: rimsptsk
Module Base: F7680000
Module End: F768D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
Service Name: rismxdp
Module Base: F5877000
Module End: F58C3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: F5852000
Module End: F5877000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
Service Name: nvnetbus
Module Base: F7A1C000
Module End: F7A20000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\NVNRM.SYS
Service Name: ---
Module Base: F5807000
Module End: F5852000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\NVSNPU.SYS
Service Name: ---
Module Base: F57D0000
Module End: F5807000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F7690000
Module End: F769D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F7910000
Module End: F7916000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\SynTP.sys
Service Name: SynTP
Module Base: F57A0000
Module End: F57D0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F7AAE000
Module End: F7AB0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F7918000
Module End: F791E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\CmBatt.sys
Service Name: CmBatt
Module Base: F7A20000
Module End: F7A24000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7C16000
Module End: F7C17000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F6470000
Module End: F647D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F7A24000
Module End: F7A27000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F5789000
Module End: F57A0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F6460000
Module End: F646B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F6450000
Module End: F645C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F7920000
Module End: F7925000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys
Service Name: PSched
Module Base: F5750000
Module End: F5761000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F6440000
Module End: F6449000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F7928000
Module End: F792D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F7930000
Module End: F7935000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F6430000
Module End: F643A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F7AB0000
Module End: F7AB2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\update.sys
Service Name: Update
Module Base: F571C000
Module End: F5750000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F7A30000
Module End: F7A34000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: F7A38000
Module End: F7A3C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F6420000
Module End: F642A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: EEF83000
Module End: EEF92000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
Service Name: NVENETFD
Module Base: EEF73000
Module End: EEF7C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\CHDAud.sys
Service Name: HdAudAddService
Module Base: ED348000
Module End: ED3DD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: ED324000
Module End: ED348000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: EEF63000
Module End: EEF72000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
Service Name: HSFHWAZL
Module Base: ED2F1000
Module End: ED324000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
Service Name: HSF_DPV
Module Base: ED1FD000
Module End: ED2F1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
Service Name: winachsf
Module Base: ED14B000
Module End: ED1FD000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: EEE70000
Module End: EEE78000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\i2omgmt.SYS
Service Name: i2omgmt
Module Base: F1348000
Module End: F134A000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F1346000
Module End: F1348000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: EDC04000
Module End: EDC05000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F1344000
Module End: F1346000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: EDE2B000
Module End: EDE31000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F1342000
Module End: F1344000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F1340000
Module End: F1342000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: EDE23000
Module End: EDE28000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: EDE1B000
Module End: EDE23000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Service Name: HidUsb
Module Base: EED4E000
Module End: EED51000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Service Name: usbccgp
Module Base: EDDEB000
Module End: EDDF3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: EDB60000
Module End: EDB63000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: ECE62000
Module End: ECE75000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: ECE0A000
Module End: ECE62000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: ECDE2000
Module End: ECE0A000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: ECDC0000
Module End: ECDE2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: ED4B0000
Module End: ED4B9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\eabfiltr.sys
Service Name: eabfiltr
Module Base: EFC15000
Module End: EFC17000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: ECD94000
Module End: ECDC0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: ECD25000
Module End: ECD94000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: ED490000
Module End: ED499000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: ECD04000
Module End: ECD25000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: ED470000
Module End: ED479000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\arp1394.sys
Service Name: Arp1394
Module Base: EDE83000
Module End: EDE92000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
Service Name: NuidFltr
Module Base: F78B0000
Module End: F78B7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\WDFLDR.SYS
Service Name: ---
Module Base: F7600000
Module End: F760D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
Service Name: Wdf01000
Module Base: EE561000
Module End: EE5DC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: F2E12000
Module End: F2E15000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\usbvideo.sys
Service Name: usbvideo
Module Base: EFA6B000
Module End: EFA7F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: ECCE1000
Module End: ECD04000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_nvata.sys
Service Name: ---
Module Base: ECCC8000
Module End: ECCE1000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7ADC000
Module End: F7ADE000
Hidden: Yes
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: EFFF1000
Module End: EFFF4000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: F1022000
Module End: F1027000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: ED53F000
Module End: ED540000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: F00E9000
Module End: F00ED000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: B92AD000
Module End: B92DA000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: B9248000
Module End: B925D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: EDE73000
Module End: EDE82000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys
Service Name: Srv
Module Base: B9061000
Module End: B90B3000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\mbam.sys
Service Name: MBAMProtector
Module Base: B91D7000
Module End: B91DA000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
Service Name: mdmxsdk
Module Base: B928D000
Module End: B9291000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\symlcbrd.sys
Service Name: symlcbrd
Module Base: EFC69000
Module End: EFC6F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: B8BE8000
Module End: B8C29000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: EDEA3000
Module End: EDEB3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
Service Name: IpFilterDriver
Module Base: B8B68000
Module End: B8B71000
Hidden: No
Module Name: \??\C:\Program Files\PeerGuardian2\pgfilter.sys
Service Name: pgfilter
Module Base: F7830000
Module End: F7836000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: B8556000
Module End: B8580000
Hidden: No
******************************************************************************************
******************************************************************************************
No SSDT Hooks found
******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: ZwFlushInstructionCache
At Address: 805B5642
Jump To: 8567C112
Module Name: _unknown_
Hooked Function: ZwEnumerateKey
At Address: 80622DE0
Jump To: 8567BBFA
Module Name: _unknown_
Hooked Function: IofCompleteRequest
At Address: 804EF230
Jump To: 854ABC6A
Module Name: _unknown_
Hooked Function: IofCallDriver
At Address: 804EF1A0
Jump To: 8567BA62
Module Name: _unknown_
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: PC608619932964.NO.COX.NET:1245
Remote Address: AD1.P2.VIP.RM.SP1.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1240
Remote Address: MAP-C.PIPELANE.NET:HTTP
Type: TCP
Process: C:\WINDOWS\msa.exe
State: ESTABLISHED
Local Address: PC608619932964.NO.COX.NET:1239
Remote Address: DAL-AGG-N48.PANTHERCDN.COM:HTTP
Type: TCP
Process: C:\WINDOWS\msa.exe
State: ESTABLISHED
Local Address: PC608619932964.NO.COX.NET:1238
Remote Address: DAL-AGG-N48.PANTHERCDN.COM:HTTP
Type: TCP
Process: C:\WINDOWS\msa.exe
State: CLOSE_WAIT
Local Address: PC608619932964.NO.COX.NET:1235
Remote Address: 216.178.33.50:HTTP
Type: TCP
Process: C:\WINDOWS\msa.exe
State: ESTABLISHED
Local Address: PC608619932964.NO.COX.NET:1230
Remote Address: AD1.P2.VIP.RM.SP1.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1207
Remote Address: BWCLICKB.LAS.MARCHEX.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1203
Remote Address: IP70-167-151-135.AT.AT.COX.NET:HTTP
Type: TCP
Process: C:\WINDOWS\msa.exe
State: ESTABLISHED
Local Address: PC608619932964.NO.COX.NET:1200
Remote Address: CLICK.LAS.MARCHEX.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1199
Remote Address: 66.116.125.43:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1185
Remote Address: AD1.P1.VIP.RM.SP1.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1174
Remote Address: SERVER-216-137-43-241.DFW3.CLOUDFRONT.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1165
Remote Address: AD1.P1.VIP.RM.SP1.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1163
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1158
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1157
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1155
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1154
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1151
Remote Address: 4.23.45.126:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1150
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1146
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1143
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1141
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1137
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1136
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1135
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1134
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1133
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1126
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1125
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1124
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1121
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1119
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1118
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1116
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1114
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1113
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1112
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1111
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1110
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:KPOP
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1108
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1107
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1106
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1105
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1100
Remote Address: GEEK15.GEEKSTOGO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1095
Remote Address: 8.19.18.47:HTTP
Type: TCP
Process: C:\WINDOWS\msa.exe
State: ESTABLISHED
Local Address: PC608619932964.NO.COX.NET:1086
Remote Address: MAIL1.KOENIG-SOLUTIONS.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1084
Remote Address: IP70-167-151-171.AT.AT.COX.NET:HTTP
Type: TCP
Process: C:\WINDOWS\msa.exe
State: ESTABLISHED
Local Address: PC608619932964.NO.COX.NET:1079
Remote Address: 213-133-110-21.CLIENTS.YOUR-SERVER.DE:HTTPS
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: CLOSE_WAIT
Local Address: PC608619932964.NO.COX.NET:1077
Remote Address: STATIC.91.213.46.78.CLIENTS.YOUR-SERVER.DE:HTTPS
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: CLOSE_WAIT
Local Address: PC608619932964.NO.COX.NET:1059
Remote Address: COOKEX1.CL1.ADS.ADX.VIP.AC4.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1054
Remote Address: PERFORA.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1052
Remote Address: OOL-457C89D8.DYN.OPTONLINE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1051
Remote Address: PROJECTS.SOURCEFORGE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1048
Remote Address: 212.100.242.237:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1046
Remote Address: OOL-457C89D8.DYN.OPTONLINE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1045
Remote Address: OOL-457C89D8.DYN.OPTONLINE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1044
Remote Address: PROJECTS.SOURCEFORGE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1043
Remote Address: PROJECTS.SOURCEFORGE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1042
Remote Address: PROJECTS.SOURCEFORGE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1041
Remote Address: PROJECTS.SOURCEFORGE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1040
Remote Address: PROJECTS.SOURCEFORGE.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:1028
Remote Address: 64.27.1.205:HTTP
Type: TCP
Process: 688 (PID)
State: FIN_WAIT1
Local Address: PC608619932964.NO.COX.NET:1027
Remote Address: A72-246-90-10.DEPLOY.AKAMAITECHNOLOGIES.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PC608619932964.NO.COX.NET:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: PC608619932964:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING
Local Address: PC608619932964:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING
Local Address: PC608619932964:5152
Remote Address: LOCALHOST:1089
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: CLOSE_WAIT
Local Address: PC608619932964:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: PC608619932964:1089
Remote Address: LOCALHOST:5152
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: FIN_WAIT2
Local Address: PC608619932964:1030
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING
Local Address: PC608619932964:2005
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Vongo\VongoService.exe
State: LISTENING
Local Address: PC608619932964:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: PC608619932964:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: PC608619932964.NO.COX.NET:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: PC608619932964.NO.COX.NET:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: PC608619932964.NO.COX.NET:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: PC608619932964.NO.COX.NET:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: PC608619932964.NO.COX.NET:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: PC608619932964:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: PC608619932964:1087
Remote Address: NA
Type: UDP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: NA
Local Address: PC608619932964:1026
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\msa.exe
State: NA
Local Address: PC608619932964:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: PC608619932964:58277
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: PC608619932964:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: PC608619932964:1025
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: PC608619932964:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: PC608619932964:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}
Status: Access denied
Object: C:\WINDOWS\system32\drivers\SKYNETnypymufx.sys
Status: Hidden
Object: C:\WINDOWS\system32\drivers\UACdojdvjiyey.sys
Status: Hidden
Object: C:\WINDOWS\system32\SKYNETahjsciay.dat
Status: Hidden
Object: C:\WINDOWS\system32\SKYNETciasxbat.dat
Status: Hidden
Object: C:\WINDOWS\system32\SKYNETrvobvvix.dll
Status: Hidden
Object: C:\WINDOWS\system32\SKYNETwyvdfcag.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACafcoxrqmat.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACaxjydlssst.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACayuefvebnr.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACclybadlboh.dat
Status: Hidden
Object: C:\WINDOWS\system32\UACifkmqheaiv.db
Status: Hidden
Object: C:\WINDOWS\system32\uacinit.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACobwjcjvipk.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACwcohlsqalp.dll
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETacamtrgtlq.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETadlbvpvbux.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETajdqfegdst.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETaljgynfmqv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETaokaojmsgb.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETarbjtoevnf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETaungupnafd.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETavqfvkcpfl.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETaxlrmanlss.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbatytaxcdg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbjnugvmilo.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbmgjmituqn.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbpcjwxpkla.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbqycimceth.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbwnuaanubj.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbwxprkpnjm.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbxtlonyjas.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETbyuboxlkdh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETchcvendrbj.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETchmngvxfer.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETcrrwiumais.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETcsurixloli.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETcuucuxdefy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETcvbdmxnywq.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETcwhpehycjt.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETcxugkjbvhf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETdctuwydmri.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETderlnvvdlt.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETdliwjhncxg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETdooriudget.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETdtlesfsmrx.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETdwdxhjpfoy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETeckgxujfqk.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETefirhpeahf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETehhtgykops.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETescvxdrivt.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETesxkhumwye.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETetblchafss.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETfccieylncm.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETfddknrtytd.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETfdyjkawemt.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETfkofdriawm.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETfmqdncnlas.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETftxgflyjsq.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETgbrqskquux.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETgkwojmguyr.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETgmehorruvn.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETgopogoelcb.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETgypvwfxoya.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEThbvlxqvhkv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEThcvibalkud.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEThmqowpnhje.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEThnfcnstsga.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEThoylhdwpse.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEThqbjlbpkhk.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETicxbpqlsbe.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETidfiturbgs.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETighkssqfoy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETihqlunosfu.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETiqcsvfncja.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETiqjismnwmn.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETirtshneyaw.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjaupadlqtg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjccrymqceh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjfrcmgexvl.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjftapbdivx.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjfyvvygbft.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjmmbraaaar.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjnnkutxdce.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjsppyfdmxv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETjsvqyxfvid.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETkhqirrnqkb.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETkokccstaql.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETkpfxjppxmk.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETkpltfibdsy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETktxqfajmsi.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETkxdjnubpts.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETkxxrekdctf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlbrmgdoauv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlbsyeiesls.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlcsrjsqvek.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETldrgalvtmc.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlerpllqwlw.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlmsxuuqrnm.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlpyciokwaf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlpyprvcdrs.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlsyoisgbxm.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETltptwmvoal.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlvpxdicsix.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlvuinptjdr.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETlyqrsydklq.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETmpdmxbhoan.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETmuutpkqpbx.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETmvejjdgodw.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETmyqvvnboqy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnfnnsncjjs.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnghpnxjnoa.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnkatifivfn.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnkjchrajey.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnmstovmyes.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnognukfnmf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnrcbewvqwv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnvqbkewyss.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnvydoeyamd.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnwjxhutqre.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETnxtaucctpj.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETobckxcwnnu.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETocrlequeyy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEToeqwnbnwjo.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETogajypkgtc.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETohuqfrmbgi.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEToijbwitfny.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETolokmstopn.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETopidgemryl.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETopxucxxhnh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEToukfmgdyep.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETouxnwdaype.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETowhogxfjyg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEToxhcrcjpac.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNEToyprvmbfhk.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpcdkovwtwc.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpdqtquqxwj.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpieqkgghcg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpmlnhaepqg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETppcjlcvqwh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpsyrmqnqlh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpuusiowslr.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpwbwmrvfiy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpwcpvxnidg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETpwkrtyiiaw.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqbjwiqolbn.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqbqajlktba.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqbyhfmmmvu.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqeltehghgr.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqfpgfvdqcm.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqoiskavxgx.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqqfganoiig.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETqxsbvejiuh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETraeeuydumt.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETrdihtkxbsb.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETrkdihhqxqg.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETrlghpymals.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETrnjvkqlloo.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETromqescigo.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETrsobaeckcq.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETrvmibwwqsu.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETryixyaigcq.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETsevrfdlhnx.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETsfonrymham.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETslocquudoi.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETsohevhnqcr.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETsqsrhcwelf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETswptxbmblk.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtdegnilbeo.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtguduqweat.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtiuinfqhfe.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtmeqqccodj.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtmoxmacrma.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtpxtswqcce.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETttsinuxxkf.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtxbiesmcyv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETtxudteyneo.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETucnacwehhl.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETucsayeiosl.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETuhebhebmam.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETuiiunlrncy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETuumlpuwjxt.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETvbpynwbsbh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETvctijmrvqv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETveujvydhjw.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETvgqoncrkck.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETvkljuqhxcm.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETvyackinfuv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwcfrnmmpse.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwfcvjuemht.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwfteunuraj.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwfvlkjsuyl.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwhvrwvifsy.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwkedcdfnie.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwkmrdlkeup.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwnrgteesay.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwryaevofkn.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwtqaewaotb.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwuypbvtbtb.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETwxeiuaciqu.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETxcqdpeaeun.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETxeriysgqhd.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETxgojouoobi.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETxjmvmmetgh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETxoyclawqmd.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETxulxdqtcbr.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETydjusexoyv.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETyhrtcsxait.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETykasayhvsh.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETyndwbauqri.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETyqvxssyvtu.tmp
Status: Hidden
Object: C:\WINDOWS\temp\SKYNETyripgycwxb.tmp
Status: Hidden
Object: C:\WINDOWS\temp\UACc3f.tmp
Status: Hidden
Object: C:\WINDOWS\temp\UACdb86.tmp
Status: Hidden
--------------------------