Here's the latest log
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
No Hidden Processes found
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: F45E0000
Module End: F45F8000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7A93000
Module End: F7A95000
Hidden: Yes
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwCreateKey
Address: F74586AE
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwCreateProcess
Address: F7436A96
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwCreateProcessEx
Address: F7436D5E
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwDeleteKey
Address: F745904C
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwDeleteValueKey
Address: F74593D6
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwOpenKey
Address: F74578EC
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwOpenProcess
Address: F32FC6C0
Driver Base: F32FA000
Driver End: F3304000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
Function Name: ZwRenameKey
Address: F745991A
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwSetValueKey
Address: F7458A50
Driver Base: F7429000
Driver End: F7466000
Driver Name: PCTCore.sys
Function Name: ZwTerminateProcess
Address: F32FC770
Driver Base: F32FA000
Driver End: F3304000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
Function Name: ZwTerminateThread
Address: F32FC810
Driver Base: F32FA000
Driver End: F3304000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
Function Name: ZwWriteVirtualMemory
Address: F32FC8B0
Driver Base: F32FA000
Driver End: F3304000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{BA5F9362-B794-BB7F-C945-12392C889AD9}\01\10-{BA5F9362-B794-BB7F-C945-12392C889AD9}-v1-{48
Status: Hidden
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{BA5F9362-B794-BB7F-C945-12392C889AD9}\13\13-{A3198939-C9B9-435D-98CF-AB2BC92BE533}-v13-{A
Status: Hidden
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{BA5F9362-B794-BB7F-C945-12392C889AD9}\13\13-{A7A505AF-E478-4F4D-8F6A-D79C6FC14BAE}-v13-{A
Status: Hidden
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{BA5F9362-B794-BB7F-C945-12392C889AD9}\14\14-{A3198939-C9B9-435D-98CF-AB2BC92BE533}-v14-{A
Status: Hidden
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{BA5F9362-B794-BB7F-C945-12392C889AD9}\16\16-{A3198939-C9B9-435D-98CF-AB2BC92BE533}-v16-{A
Status: Hidden
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{BA5F9362-B794-BB7F-C945-12392C889AD9}\17\17-{A3198939-C9B9-435D-98CF-AB2BC92BE533}-v17-{A
Status: Hidden
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{BA5F9362-B794-BB7F-C945-12392C889AD9}\18\18-{A3198939-C9B9-435D-98CF-AB2BC92BE533}-v18-{A
Status: Hidden
Object: C:\Documents and Settings\DENNIS\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{68E73B71-4EA2-A14A-5BF5-C5F9C066BB5F}\01\11-{68E73B71-4EA2-A14A-5BF5-C5F9C066BB5F}-v1-{4812
Status: Hidden
Object: C:\Program Files\IObit\IObit SmartDefrag\language\Lietuviu.lng
Status: Hidden
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied
Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied