OTS File
I'd also like to add that access was denied to the Hosts file according to HijackThis, but this is what I got:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:41:12 PM, on 8/14/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\sttray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Users\A.XiN\Desktop\HiJackThis.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - (no file)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O13 - Gopher Prefix:
O15 - ESC Trusted Zone:
http://*.update.microsoft.com
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} (Diagnostics ActiveX WebControl) -
http://support.micro...gWebControl.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: getPlusŪ Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Auto Shutdown Service (ShutdownService) - Unknown owner - C:\Program Files\Auto Shutdown Genius\ShutdownSvr.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 12686 bytes
SysportLog:
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\Windows\System32\smss.exe
PID: 424
Hidden: No
Window Visible: No
Name: C:\Windows\System32\csrss.exe
PID: 552
Hidden: No
Window Visible: No
Name: C:\Windows\System32\wininit.exe
PID: 604
Hidden: No
Window Visible: No
Name: C:\Windows\System32\csrss.exe
PID: 616
Hidden: No
Window Visible: No
Name: C:\Windows\System32\services.exe
PID: 648
Hidden: No
Window Visible: No
Name: C:\Windows\System32\lsass.exe
PID: 676
Hidden: No
Window Visible: No
Name: C:\Windows\System32\lsm.exe
PID: 684
Hidden: No
Window Visible: No
Name: C:\Windows\System32\winlogon.exe
PID: 836
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 864
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 932
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 968
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 1052
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 1124
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 1148
Hidden: No
Window Visible: No
Name: C:\Windows\System32\audiodg.exe
PID: 1232
Hidden: No
Window Visible: No
Name: C:\Windows\System32\SLsvc.exe
PID: 1268
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 1308
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 1448
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PID: 1552
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
PID: 1644
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PID: 1712
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\ashServ.exe
PID: 1728
Hidden: No
Window Visible: No
Name: C:\Windows\System32\spoolsv.exe
PID: 1412
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 1464
Hidden: No
Window Visible: No
Name: C:\Windows\System32\taskeng.exe
PID: 2144
Hidden: No
Window Visible: No
Name: C:\Windows\System32\dwm.exe
PID: 2192
Hidden: No
Window Visible: No
Name: C:\Windows\explorer.exe
PID: 2260
Hidden: No
Window Visible: No
Name: C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PID: 2428
Hidden: No
Window Visible: No
Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 2468
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
PID: 2484
Hidden: No
Window Visible: No
Name: C:\Windows\System32\CTSVCCDA.EXE
PID: 2508
Hidden: No
Window Visible: No
Name: C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PID: 2552
Hidden: No
Window Visible: No
Name: C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
PID: 2712
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 2776
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
PID: 2808
Hidden: No
Window Visible: No
Name: C:\Program Files\Auto Shutdown Genius\ShutdownSvr.exe
PID: 2940
Hidden: No
Window Visible: No
Name: C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PID: 2960
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 2972
Hidden: No
Window Visible: No
Name: C:\Program Files\Viewpoint\Common\ViewpointService.exe
PID: 3004
Hidden: No
Window Visible: No
Name: C:\Windows\System32\svchost.exe
PID: 3024
Hidden: No
Window Visible: No
Name: C:\Windows\System32\SearchIndexer.exe
PID: 3052
Hidden: No
Window Visible: No
Name: C:\Windows\System32\drivers\XAudio.exe
PID: 3112
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PID: 3248
Hidden: No
Window Visible: No
Name: C:\Windows\System32\WUDFHost.exe
PID: 3304
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PID: 3312
Hidden: No
Window Visible: No
Name: C:\Windows\System32\mobsync.exe
PID: 3840
Hidden: No
Window Visible: No
Name: C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
PID: 3940
Hidden: No
Window Visible: No
Name: C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
PID: 3960
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PID: 3984
Hidden: No
Window Visible: No
Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 4020
Hidden: No
Window Visible: Yes
Name: C:\Program Files\Java\jre6\bin\jusched.exe
PID: 4064
Hidden: No
Window Visible: No
Name: C:\Windows\sttray.exe
PID: 2072
Hidden: No
Window Visible: No
Name: C:\Program Files\QuickTime\QTTask.exe
PID: 416
Hidden: No
Window Visible: No
Name: C:\Program Files\Dell\MediaDirect\PCMService.exe
PID: 2648
Hidden: No
Window Visible: No
Name: C:\Windows\System32\rundll32.exe
PID: 3036
Hidden: No
Window Visible: No
Name: C:\Windows\System32\rundll32.exe
PID: 3120
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
PID: 892
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PID: 556
Hidden: No
Window Visible: No
Name: C:\Windows\System32\rundll32.exe
PID: 1072
Hidden: No
Window Visible: No
Name: C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PID: 3972
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 4032
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PID: 2216
Hidden: No
Window Visible: No
Name: C:\Program Files\AIM6\aim6.exe
PID: 2884
Hidden: No
Window Visible: Yes
Name: C:\Program Files\Windows Media Player\wmpnscfg.exe
PID: 2084
Hidden: No
Window Visible: No
Name: C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PID: 2864
Hidden: No
Window Visible: No
Name: C:\Program Files\Windows Sidebar\sidebar.exe
PID: 2728
Hidden: No
Window Visible: Yes
Name: C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PID: 2040
Hidden: No
Window Visible: No
Name: C:\Program Files\DellSupport\DSAgnt.exe
PID: 1720
Hidden: No
Window Visible: No
Name: C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
PID: 3480
Hidden: No
Window Visible: Yes
Name: C:\Program Files\Digital Line Detect\DLG.exe
PID: 3268
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
PID: 656
Hidden: No
Window Visible: No
Name: C:\Program Files\Logitech\SetPoint\SetPoint.exe
PID: 4036
Hidden: No
Window Visible: No
Name: C:\Windows\System32\wbem\WmiPrvSE.exe
PID: 4204
Hidden: No
Window Visible: No
Name: C:\Program Files\Windows Media Player\wmpnetwk.exe
PID: 4236
Hidden: No
Window Visible: No
Name: C:\Program Files\Mozilla Firefox\firefox.exe
PID: 4640
Hidden: No
Window Visible: No
Name: C:\Windows\System32\taskeng.exe
PID: 4848
Hidden: No
Window Visible: No
Name: C:\Program Files\Windows Sidebar\sidebar.exe
PID: 5324
Hidden: No
Window Visible: Yes
Name: C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
PID: 4156
Hidden: No
Window Visible: No
Name: C:\Program Files\AIM6\aolsoftware.exe
PID: 5148
Hidden: No
Window Visible: No
Name: C:\Windows\System32\SearchProtocolHost.exe
PID: 5060
Hidden: No
Window Visible: No
Name: C:\Windows\System32\SearchFilterHost.exe
PID: 4016
Hidden: No
Window Visible: No
Name: C:\Users\A.XiN\Desktop\SysProt\SysProt.exe
PID: 4724
Hidden: No
Window Visible: Yes
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Users\A.XiN\Desktop\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: A4706000
Module End: A4711000
Hidden: No
Module Name: C:\Windows\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 81E1C000
Module End: 821D5000
Hidden: No
Module Name: C:\Windows\system32\hal.dll
Service Name: ---
Module Base: 821D5000
Module End: 82208000
Hidden: No
Module Name: C:\Windows\system32\kdcom.dll
Service Name: ---
Module Base: 80402000
Module End: 8040A000
Hidden: No
Module Name: C:\Windows\system32\mcupdate_GenuineIntel.dll
Service Name: ---
Module Base: 8040A000
Module End: 8046A000
Hidden: No
Module Name: C:\Windows\system32\PSHED.dll
Service Name: ---
Module Base: 8046A000
Module End: 8047B000
Hidden: No
Module Name: C:\Windows\system32\BOOTVID.dll
Service Name: ---
Module Base: 8047B000
Module End: 80483000
Hidden: No
Module Name: C:\Windows\system32\CLFS.SYS
Service Name: CLFS
Module Base: 80483000
Module End: 804C4000
Hidden: No
Module Name: C:\Windows\system32\CI.dll
Service Name: ---
Module Base: 804C4000
Module End: 805A4000
Hidden: No
Module Name: C:\Windows\system32\drivers\Wdf01000.sys
Service Name: Wdf01000
Module Base: 8060A000
Module End: 80686000
Hidden: No
Module Name: C:\Windows\system32\drivers\WDFLDR.SYS
Service Name: ---
Module Base: 80686000
Module End: 80693000
Hidden: No
Module Name: C:\Windows\system32\drivers\acpi.sys
Service Name: ACPI
Module Base: 80693000
Module End: 806D9000
Hidden: No
Module Name: C:\Windows\system32\drivers\WMILIB.SYS
Service Name: ---
Module Base: 806D9000
Module End: 806E2000
Hidden: No
Module Name: C:\Windows\system32\drivers\msisadrv.sys
Service Name: msisadrv
Module Base: 806E2000
Module End: 806EA000
Hidden: No
Module Name: C:\Windows\system32\drivers\pci.sys
Service Name: pci
Module Base: 806EA000
Module End: 80711000
Hidden: No
Module Name: C:\Windows\System32\drivers\partmgr.sys
Service Name: partmgr
Module Base: 80711000
Module End: 80720000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\compbatt.sys
Service Name: Compbatt
Module Base: 80720000
Module End: 80723000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\BATTC.SYS
Service Name: BattC
Module Base: 80723000
Module End: 8072D000
Hidden: No
Module Name: C:\Windows\system32\drivers\volmgr.sys
Service Name: volmgr
Module Base: 8072D000
Module End: 8073C000
Hidden: No
Module Name: C:\Windows\System32\drivers\volmgrx.sys
Service Name: volmgrx
Module Base: 8073C000
Module End: 80786000
Hidden: No
Module Name: C:\Windows\system32\drivers\intelide.sys
Service Name: intelide
Module Base: 80786000
Module End: 8078D000
Hidden: No
Module Name: C:\Windows\system32\drivers\PCIIDEX.SYS
Service Name: ---
Module Base: 8078D000
Module End: 8079B000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\pciide.sys
Service Name: pciide
Module Base: 8079B000
Module End: 807A2000
Hidden: No
Module Name: C:\Windows\System32\drivers\mountmgr.sys
Service Name: MountMgr
Module Base: 807A2000
Module End: 807B2000
Hidden: No
Module Name: C:\Windows\system32\drivers\atapi.sys
Service Name: atapi
Module Base: 807B2000
Module End: 807BA000
Hidden: No
Module Name: C:\Windows\system32\drivers\ataport.SYS
Service Name: ---
Module Base: 807BA000
Module End: 807D8000
Hidden: No
Module Name: C:\Windows\System32\Drivers\AFS.sys
Service Name: AFS
Module Base: 807D8000
Module End: 807E5000
Hidden: No
Module Name: C:\Windows\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: 805A4000
Module End: 805D6000
Hidden: No
Module Name: C:\Windows\system32\drivers\fileinfo.sys
Service Name: FileInfo
Module Base: 807E5000
Module End: 807F5000
Hidden: No
Module Name: C:\Windows\System32\Drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: 807F5000
Module End: 807FE000
Hidden: No
Module Name: C:\Windows\System32\Drivers\ksecdd.sys
Service Name: KSecDD
Module Base: 8280C000
Module End: 8287D000
Hidden: No
Module Name: C:\Windows\system32\drivers\ndis.sys
Service Name: NDIS
Module Base: 8287D000
Module End: 82988000
Hidden: No
Module Name: C:\Windows\system32\drivers\msrpc.sys
Service Name: MsRPC
Module Base: 82988000
Module End: 829B3000
Hidden: No
Module Name: C:\Windows\system32\drivers\NETIO.SYS
Service Name: ---
Module Base: 829B3000
Module End: 829ED000
Hidden: No
Module Name: C:\Windows\System32\drivers\tcpip.sys
Service Name: Tcpip
Module Base: 82A04000
Module End: 82AEB000
Hidden: No
Module Name: C:\Windows\System32\drivers\fwpkclnt.sys
Service Name: ---
Module Base: 82AEB000
Module End: 82B06000
Hidden: No
Module Name: C:\Windows\System32\Drivers\Ntfs.sys
Service Name: Ntfs
Module Base: 87C06000
Module End: 87D15000
Hidden: No
Module Name: C:\Windows\system32\drivers\volsnap.sys
Service Name: volsnap
Module Base: 87D15000
Module End: 87D4E000
Hidden: No
Module Name: C:\Windows\System32\Drivers\spldr.sys
Service Name: spldr
Module Base: 87D4E000
Module End: 87D56000
Hidden: No
Module Name: C:\Windows\System32\Drivers\mup.sys
Service Name: Mup
Module Base: 87D56000
Module End: 87D65000
Hidden: No
Module Name: C:\Windows\System32\drivers\ecache.sys
Service Name: Ecache
Module Base: 87D65000
Module End: 87D8C000
Hidden: No
Module Name: C:\Windows\system32\drivers\disk.sys
Service Name: disk
Module Base: 87D8C000
Module End: 87D9D000
Hidden: No
Module Name: C:\Windows\system32\drivers\CLASSPNP.SYS
Service Name: ---
Module Base: 87D9D000
Module End: 87DBE000
Hidden: No
Module Name: C:\Windows\system32\drivers\crcdisk.sys
Service Name: crcdisk
Module Base: 87DBE000
Module End: 87DC7000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\tunnel.sys
Service Name: tunnel
Module Base: 87DE7000
Module End: 87DF2000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\tunmp.sys
Service Name: tunmp
Module Base: 87DF2000
Module End: 87DFB000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: 82B06000
Module End: 82B15000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\wmiacpi.sys
Service Name: WmiAcpi
Module Base: 82B15000
Module End: 82B1E000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\CmBatt.sys
Service Name: CmBatt
Module Base: 87DFB000
Module End: 87DFF000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\nvlddmkm.sys
Service Name: nvlddmkm
Module Base: 8B80B000
Module End: 8BF52000
Hidden: No
Module Name: C:\Windows\System32\drivers\dxgkrnl.sys
Service Name: DXGKrnl
Module Base: 8BF52000
Module End: 8BFF1000
Hidden: No
Module Name: C:\Windows\System32\drivers\watchdog.sys
Service Name: ---
Module Base: 8BFF1000
Module End: 8BFFE000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: 82B1E000
Module End: 82B30000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\NETw4v32.sys
Service Name: NETw4v32
Module Base: 8C002000
Module End: 8C231000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: 8C231000
Module End: 8C23C000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: 8C23C000
Module End: 8C27A000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: 8C27A000
Module End: 8C289000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\bcm4sbxp.sys
Service Name: bcm4sbxp
Module Base: 8C289000
Module End: 8C29A000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\ohci1394.sys
Service Name: ohci1394
Module Base: 8C29A000
Module End: 8C2AA000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: 8C2AA000
Module End: 8C2B8000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\sdbus.sys
Service Name: sdbus
Module Base: 8C2B8000
Module End: 8C2D2000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\rimmptsk.sys
Service Name: rimmptsk
Module Base: 8C2D2000
Module End: 8C2E0000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\rimsptsk.sys
Service Name: rimsptsk
Module Base: 8C2E0000
Module End: 8C2F4000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\rixdptsk.sys
Service Name: rismxdp
Module Base: 8C2F4000
Module End: 8C345000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: 8C345000
Module End: 8C358000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\SynTP.sys
Service Name: SynTP
Module Base: 8C358000
Module End: 8C383000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: 8C383000
Module End: 8C385000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\mouclass.sys
Service Name: mouclass
Module Base: 8C385000
Module End: 8C390000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\kbdclass.sys
Service Name: kbdclass
Module Base: 8C390000
Module End: 8C39B000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\cdrom.sys
Service Name: cdrom
Module Base: 8C39B000
Module End: 8C3B3000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\msiscsi.sys
Service Name: iScsiPrt
Module Base: 8C3B3000
Module End: 8C3E1000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\storport.sys
Service Name: ---
Module Base: 82B30000
Module End: 82B71000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: 8C3E1000
Module End: 8C3EC000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: 82B71000
Module End: 82B88000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: 8C3EC000
Module End: 8C3F7000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: 82B88000
Module End: 82BAB000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: 82BAB000
Module End: 82BBA000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: 82BBA000
Module End: 82BCE000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\rassstp.sys
Service Name: RasSstp
Module Base: 82BCE000
Module End: 82BE3000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: 82BE3000
Module End: 82BF3000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: 8C3F7000
Module End: 8C3F9000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: 805D6000
Module End: 80600000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: 8B800000
Module End: 8B80A000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\umbus.sys
Service Name: umbus
Module Base: 82BF3000
Module End: 82C00000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: 8D200000
Module End: 8D234000
Hidden: No
Module Name: C:\Windows\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: 8D234000
Module End: 8D245000
Hidden: No
Module Name: C:\Windows\system32\drivers\stwrt.sys
Service Name: STHDA
Module Base: 8D245000
Module End: 8D2E8000
Hidden: No
Module Name: C:\Windows\system32\drivers\portcls.sys
Service Name: ---
Module Base: 8D2E8000
Module End: 8D315000
Hidden: No
Module Name: C:\Windows\system32\drivers\drmk.sys
Service Name: ---
Module Base: 8D315000
Module End: 8D33A000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\HSXHWAZL.sys
Service Name: HSXHWAZL
Module Base: 8D33A000
Module End: 8D377000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\HSX_DPV.sys
Service Name: HSF_DPV
Module Base: 8D80F000
Module End: 8D912000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\HSX_CNXT.sys
Service Name: winachsf
Module Base: 8D912000
Module End: 8D9C6000
Hidden: No
Module Name: C:\Windows\system32\drivers\modem.sys
Service Name: Modem
Module Base: 8D9C6000
Module End: 8D9D3000
Hidden: No
Module Name: C:\Windows\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: 8D9D3000
Module End: 8D9DC000
Hidden: No
Module Name: C:\Windows\System32\Drivers\Null.SYS
Service Name: Null
Module Base: 8D9DC000
Module End: 8D9E3000
Hidden: No
Module Name: C:\Windows\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: 8D9E3000
Module End: 8D9EA000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: 8D9F3000
Module End: 8D9FA000
Hidden: No
Module Name: C:\Windows\System32\drivers\vga.sys
Service Name: vga
Module Base: 8D800000
Module End: 8D80C000
Hidden: No
Module Name: C:\Windows\System32\drivers\VIDEOPRT.SYS
Service Name: ---
Module Base: 8D377000
Module End: 8D398000
Hidden: No
Module Name: C:\Windows\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: 8D9EA000
Module End: 8D9F2000
Hidden: No
Module Name: C:\Windows\system32\drivers\rdpencdd.sys
Service Name: RDPENCDD
Module Base: 8D398000
Module End: 8D3A0000
Hidden: No
Module Name: C:\Windows\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: 8D3A0000
Module End: 8D3AB000
Hidden: No
Module Name: C:\Windows\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: 8D3AB000
Module End: 8D3B9000
Hidden: No
Module Name: C:\Windows\System32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: 8D3B9000
Module End: 8D3C2000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\tdx.sys
Service Name: tdx
Module Base: 8D3C2000
Module End: 8D3D8000
Hidden: No
Module Name: C:\Windows\System32\Drivers\aswTdi.SYS
Service Name: aswTdi
Module Base: 8D3D8000
Module End: 8D3E3000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\smb.sys
Service Name: Smb
Module Base: 8D3E3000
Module End: 8D3F7000
Hidden: No
Module Name: C:\Windows\system32\drivers\afd.sys
Service Name: AFD
Module Base: 8DA02000
Module End: 8DA4A000
Hidden: No
Module Name: C:\Windows\System32\Drivers\aswRdr.SYS
Service Name: aswRdr
Module Base: 8DA4A000
Module End: 8DA4E000
Hidden: No
Module Name: C:\Windows\System32\DRIVERS\netbt.sys
Service Name: netbt
Module Base: 8DA4E000
Module End: 8DA80000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\pacer.sys
Service Name: PSched
Module Base: 8DA80000
Module End: 8DA96000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: 8DA96000
Module End: 8DAA4000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: 8DAA4000
Module End: 8DAB7000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SYMTDI.SYS
Service Name: SYMTDI
Module Base: 8DAB7000
Module End: 8DAE3000
Hidden: No
Module Name: \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
Service Name: SymEvent
Module Base: 8DAE3000
Module End: 8DB08000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SYMREDRV.SYS
Service Name: SYMREDRV
Module Base: 8DB08000
Module End: 8DB0E000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SYMDNS.SYS
Service Name: SYMDNS
Module Base: 8DB0E000
Module End: 8DB10000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SYMNDISV.SYS
Service Name: SYMNDISV
Module Base: 8DB10000
Module End: 8DB1B000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SYMFW.SYS
Service Name: SYMFW
Module Base: 8DB1B000
Module End: 8DB3D000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SYMIDS.SYS
Service Name: SYMIDS
Module Base: 8DB3D000
Module End: 8DB46000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SRTSPX.SYS
Service Name: SRTSPX
Module Base: 8DB46000
Module End: 8DB50000
Hidden: No
Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Service Name: SASKUTIL
Module Base: 8DB50000
Module End: 8DB75000
Hidden: No
Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Service Name: SASDIFSV
Module Base: 8DB75000
Module End: 8DB7B000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\rdbss.sys
Service Name: rdbss
Module Base: 8DB7B000
Module End: 8DBB7000
Hidden: No
Module Name: C:\Windows\system32\drivers\nsiproxy.sys
Service Name: nsiproxy
Module Base: 8DBB7000
Module End: 8DBC1000
Hidden: No
Module Name: \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20070628.003\IDSvix86.sys
Service Name: IDSvix86
Module Base: 8DBC1000
Module End: 8DBF7000
Hidden: No
Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
Service Name: eeCtrl
Module Base: 8EC09000
Module End: 8EC6B000
Hidden: No
Module Name: C:\Windows\System32\Drivers\dfsc.sys
Service Name: DfsC
Module Base: 8EC6B000
Module End: 8EC82000
Hidden: No
Module Name: C:\Windows\System32\Drivers\aswSP.SYS
Service Name: aswSP
Module Base: 8EC82000
Module End: 8ECA3000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\USBSTOR.SYS
Service Name: USBSTOR
Module Base: 8ECA3000
Module End: 8ECB5000
Hidden: No
Module Name: C:\Windows\System32\Drivers\fastfat.SYS
Service Name: fastfat
Module Base: 8ECB5000
Module End: 8ECDD000
Hidden: No
Module Name: C:\Windows\System32\Drivers\crashdmp.sys
Service Name: ---
Module Base: 8ECDD000
Module End: 8ECEA000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
Service Name: ---
Module Base: 8ECEA000
Module End: 8ECF5000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: 8ECF5000
Module End: 8ECFD000
Hidden: Yes
Module Name: C:\Windows\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: 8ECFD000
Module End: 8ED07000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\monitor.sys
Service Name: monitor
Module Base: 8ED07000
Module End: 8ED16000
Hidden: No
Module Name: C:\Windows\system32\drivers\luafv.sys
Service Name: luafv
Module Base: 8ED16000
Module End: 8ED31000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\aswMonFlt.sys
Service Name: aswMonFlt
Module Base: 8ED31000
Module End: 8ED48000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\aswFsBlk.sys
Service Name: aswFsBlk
Module Base: 8ED48000
Module End: 8ED50000
Hidden: No
Module Name: C:\Windows\system32\drivers\spsys.sys
Service Name: ---
Module Base: 9BE0D000
Module End: 9BEBC000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\lltdio.sys
Service Name: lltdio
Module Base: 9BEBC000
Module End: 9BECC000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\nwifi.sys
Service Name: NativeWifiP
Module Base: 9BECC000
Module End: 9BEF6000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: 9BEF6000
Module End: 9BF00000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\rspndr.sys
Service Name: rspndr
Module Base: 9BF00000
Module End: 9BF13000
Hidden: No
Module Name: C:\Windows\system32\drivers\HTTP.sys
Service Name: HTTP
Module Base: 9BF13000
Module End: 9BF7E000
Hidden: No
Module Name: C:\Windows\System32\DRIVERS\srvnet.sys
Service Name: srvnet
Module Base: 9BF7E000
Module End: 9BF9B000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\bowser.sys
Service Name: bowser
Module Base: 9BF9B000
Module End: 9BFB4000
Hidden: No
Module Name: C:\Windows\System32\drivers\mpsdrv.sys
Service Name: mpsdrv
Module Base: 9BFB4000
Module End: 9BFC9000
Hidden: No
Module Name: C:\Windows\system32\drivers\mrxdav.sys
Service Name: MRxDAV
Module Base: 9BFC9000
Module End: 9BFE9000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\mrxsmb.sys
Service Name: mrxsmb
Module Base: 8ED58000
Module End: 8ED77000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\mrxsmb10.sys
Service Name: mrxsmb10
Module Base: 8ED77000
Module End: 8EDB0000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\mrxsmb20.sys
Service Name: mrxsmb20
Module Base: 8EDB0000
Module End: 8EDC8000
Hidden: No
Module Name: C:\Windows\System32\DRIVERS\srv2.sys
Service Name: srv2
Module Base: 8EDC8000
Module End: 8EDEF000
Hidden: No
Module Name: C:\Windows\System32\DRIVERS\srv.sys
Service Name: srv
Module Base: 9EA0A000
Module End: 9EA56000
Hidden: No
Module Name: \??\C:\Program Files\DellSupport\Drivers\dsunidrv.sys
Service Name: dsunidrv
Module Base: 9EA56000
Module End: 9EA58000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\mdmxsdk.sys
Service Name: mdmxsdk
Module Base: 9EA58000
Module End: 9EA5C000
Hidden: No
Module Name: \??\C:\Program Files\Nexxon\MapleStory\npkcrypt.sys
Service Name: npkcrypt
Module Base: 9EA5C000
Module End: 9EA62000
Hidden: No
Module Name: C:\Windows\system32\drivers\peauth.sys
Service Name: PEAUTH
Module Base: 9EA62000
Module End: 9EB40000
Hidden: No
Module Name: C:\Windows\System32\Drivers\secdrv.SYS
Service Name: secdrv
Module Base: 9EB40000
Module End: 9EB4A000
Hidden: No
Module Name: C:\Windows\System32\drivers\tcpipreg.sys
Service Name: tcpipreg
Module Base: 9EB4A000
Module End: 9EB56000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\xaudio.sys
Service Name: XAudio
Module Base: 9EB56000
Module End: 9EB5E000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\WUDFRd.sys
Service Name: WUDFRd
Module Base: 9EB5E000
Module End: 9EB73000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\WUDFPf.sys
Service Name: ---
Module Base: 9EB73000
Module End: 9EB85000
Hidden: No
Module Name: C:\Windows\System32\Drivers\SRTSP.SYS
Service Name: SRTSP
Module Base: 9EB85000
Module End: 9EBCE000
Hidden: No
Module Name: \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070706.017\NAVEX15.SYS
Service Name: NAVEX15
Module Base: A4608000
Module End: A46D7000
Hidden: No
Module Name: \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070706.017\NAVENG.SYS
Service Name: NAVENG
Module Base: A46D7000
Module End: A46E9000
Hidden: No
Module Name: C:\Windows\system32\DRIVERS\cdfs.sys
Service Name: cdfs
Module Base: A46E9000
Module End: A46FF000
Hidden: No
Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Service Name: SASENUM
Module Base: A46FF000
Module End: A4704000
Hidden: No
Module Name: \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
Service Name: DSproct
Module Base: A4704000
Module End: A4706000
Hidden: No
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwConnectPort
Address: 8D44A968
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwTerminateProcess
Address: 8DB590B0
Driver Base: 8DB50000
Driver End: 8DB75000
Driver Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49330
Remote Address: 65.55.17.39:HTTP
Type: TCP
Process: C:\Program Files\Windows Sidebar\sidebar.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49326
Remote Address: QW-IN-F137.GOOGLE.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49323
Remote Address: VW-IN-F100.GOOGLE.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49321
Remote Address: QW-IN-F103.GOOGLE.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49320
Remote Address: QW-IN-F103.GOOGLE.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49317
Remote Address: VW-IN-F113.GOOGLE.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49305
Remote Address: CPE-24-29-138-32.NYC.RES.RR.COM:HTTP
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jusched.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49304
Remote Address: 72.5.124.55:HTTP
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jusched.exe
State: CLOSE_WAIT
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49228
Remote Address: 216.246.75.105:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49226
Remote Address: QY-IN-F113.GOOGLE.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49192
Remote Address: OAM-D06A.BLUE.AOL.COM:HTTPS
Type: TCP
Process: C:\Program Files\AIM6\aim6.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:49187
Remote Address: BOS-M006B-SDR4.BLUE.AOL.COM:HTTPS
Type: TCP
Process: C:\Program Files\AIM6\aim6.exe
State: ESTABLISHED
Local Address: AXIN-PC.MYHOME.WESTELL.COM:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: AXIN-PC:49325
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49322
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49319
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49318
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49316
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49243
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49225
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49178
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
State: LISTENING
Local Address: AXIN-PC:49173
Remote Address: LOCALHOST:49172
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49172
Remote Address: LOCALHOST:49173
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49169
Remote Address: LOCALHOST:49168
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:49168
Remote Address: LOCALHOST:49169
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: AXIN-PC:12143
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: AXIN-PC:12119
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: AXIN-PC:12110
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: AXIN-PC:12080
Remote Address: LOCALHOST:49325
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC:12080
Remote Address: LOCALHOST:49322
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC:12080
Remote Address: LOCALHOST:49319
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC:12080
Remote Address: LOCALHOST:49318
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC:12080
Remote Address: LOCALHOST:49316
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC:12080
Remote Address: LOCALHOST:49243
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC:12080
Remote Address: LOCALHOST:49225
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: AXIN-PC:12080
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: LISTENING
Local Address: AXIN-PC:12025
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: AXIN-PC:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING
Local Address: AXIN-PC:49158
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\services.exe
State: LISTENING
Local Address: AXIN-PC:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING
Local Address: AXIN-PC:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\lsass.exe
State: LISTENING
Local Address: AXIN-PC:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING
Local Address: AXIN-PC:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\wininit.exe
State: LISTENING
Local Address: AXIN-PC:5357
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: AXIN-PC:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: AXIN-PC:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING
Local Address: AXIN-PC.MYHOME.WESTELL.COM:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: AXIN-PC.MYHOME.WESTELL.COM:SSDP
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: AXIN-PC.MYHOME.WESTELL.COM:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: AXIN-PC.MYHOME.WESTELL.COM:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: AXIN-PC:65407
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: AXIN-PC:64001
Remote Address: NA
Type: UDP
Process: C:\Program Files\Windows Sidebar\sidebar.exe
State: NA
Local Address: AXIN-PC:55433
Remote Address: NA
Type: UDP
Process: C:\Program Files\AIM6\aim6.exe
State: NA
Local Address: AXIN-PC:53891
Remote Address: NA
Type: UDP
Process: C:\Program Files\Windows Media Player\wmpnetwk.exe
State: NA
Local Address: AXIN-PC:52025
Remote Address: NA
Type: UDP
Process: C:\Program Files\Windows Sidebar\sidebar.exe
State: NA
Local Address: AXIN-PC:SSDP
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: AXIN-PC:60021
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: AXIN-PC:9370
Remote Address: NA
Type: UDP
Process: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
State: NA
Local Address: AXIN-PC:LLMNR
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: AXIN-PC:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: AXIN-PC:500
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: AXIN-PC:123
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
******************************************************************************************
******************************************************************************************
No hidden files/folders found
I'd also like to note that the icon isn't present in normal mode, it's only on my taskbar in safe mode. Also, my internet only works in normal mode.
Attached File(s)
-
OTS.Txt (196.18K)
Number of downloads: 105