Hi Super Dave,
Here are the logs for Security Check and SysProt
Security Check screen317 Results of screen317's Security Check version 0.99.7
Windows XP Service Pack 2
Out of date service pack!! Internet Explorer 7
Out of date! ``````````````````````````````
Antivirus/Firewall Check: Windows Firewall Enabled!
avast! Free Antivirus
Online Armor 4.0
```````````````````````````````
Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware
CCleaner
Java(TM) 6 Update 22
Adobe Flash Player 10.1.102.64
Adobe Reader 9.3
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.13)
````````````````````````````````
Process Check:
objlist.exe by Laurent Tall Emu Online Armor OAcat.exe
Alwil Software Avast5 AvastSvc.exe
Alwil Software Avast5 avastUI.exe
``````````End of Log```````````` ====
SysProt AntiRootkitSysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 500
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 552
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 576
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 620
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 632
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 796
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 844
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 912
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 980
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1056
Hidden: No
Window Visible: No
Name: C:\Program Files\Emsisoft\Online Armor\oacat.exe
PID: 1104
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PID: 1388
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 1768
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 196
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1988
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\alg.exe
PID: 1812
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 3396
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PID: 3916
Hidden: No
Window Visible: No
Name: C:\Program Files\ICQ7.2\ICQ.exe
PID: 1608
Hidden: No
Window Visible: Yes
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 2156
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wuauclt.exe
PID: 2388
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\Yahoo!\Messenger\Ymsgr_tray.exe
PID: 1596
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\NewUser\Desktop\SysProt\SysProt.exe
PID: 1284
Hidden: No
Window Visible: Yes
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\NewUser\Desktop\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: B131F000
Module End: B132A000
Hidden: No
Module Name: \WINDOWS\system32\ntoskrnl.exe
Service Name: ---
Module Base: 804D7000
Module End: 806FD000
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806FD000
Module End: 8071DD00
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F7987000
Module End: F7989000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F7897000
Module End: F789A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F75A8000
Module End: F75D6000
Hidden: No
Module Name: \WINDOWS\System32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F7989000
Module End: F798B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F7597000
Module End: F75A8000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F75F7000
Module End: F7600000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ohci1394.sys
Service Name: ohci1394
Module Base: F7607000
Module End: F7616000
Hidden: No
Module Name: \WINDOWS\System32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: F7617000
Module End: F7624000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F7A4F000
Module End: F7A50000
Hidden: No
Module Name: \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F7707000
Module End: F770E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F7627000
Module End: F7632000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F74D8000
Module End: F74F7000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F770F000
Module End: F7714000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F7637000
Module End: F7644000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F74C0000
Module End: F74D8000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F7647000
Module End: F7650000
Hidden: No
Module Name: \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F7657000
Module End: F7664000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: F74A0000
Module End: F74C0000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F748E000
Module End: F74A0000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F7667000
Module End: F7671000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F7860000
Module End: F7877000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F7B52000
Module End: F7BDF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F7833000
Module End: F7860000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F796C000
Module End: F7987000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\agp440.sys
Service Name: agp440
Module Base: F7677000
Module End: F7682000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\nic1394.sys
Service Name: NIC1394
Module Base: F76A7000
Module End: F76B7000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F76D7000
Module End: F76E0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
Service Name: nv
Module Base: B66C4000
Module End: B7091000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: B66B0000
Module End: B66C4000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F774F000
Module End: F7754000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: B668D000
Module End: B66B0000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F7757000
Module End: F775E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ctaud2k.sys
Service Name: ctaud2k
Module Base: B6633000
Module End: B668D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: B660F000
Module End: B6633000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: F76E7000
Module End: F76F6000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ks.sys
Service Name: ---
Module Base: B65EC000
Module End: B660F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ctoss2k.sys
Service Name: ossrv
Module Base: B65C0000
Module End: B65EC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ctprxy2k.sys
Service Name: ctprxy2k
Module Base: F79B9000
Module End: F79BB000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\IntelC53.sys
Service Name: IntelC53
Module Base: F76F7000
Module End: F7703000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\IntelC51.sys
Service Name: IntelC51
Module Base: B64BF000
Module End: B65C0000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\IntelC52.sys
Service Name: IntelC52
Module Base: B6451000
Module End: B64BF000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mohfilt.sys
Service Name: mohfilt
Module Base: F775F000
Module End: F7764000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F7767000
Module End: F776F000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\e100b325.sys
Service Name: E100B
Module Base: B642D000
Module End: B6451000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\serial.sys
Service Name: Serial
Module Base: F7587000
Module End: F7597000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\serenum.sys
Service Name: serenum
Module Base: B87E0000
Module End: B87E4000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\parport.sys
Service Name: Parport
Module Base: B6419000
Module End: B642D000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F7577000
Module End: F7582000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F7567000
Module End: F7574000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F7557000
Module End: F7566000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\pwd_2k.SYS
Service Name: pwd_2k
Module Base: B63FC000
Module End: B6419000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7AB9000
Module End: F7ABA000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F7547000
Module End: F7554000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: B87D4000
Module End: B87D7000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: B63E5000
Module End: B63FC000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F7537000
Module End: F7542000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F7527000
Module End: F7533000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F7777000
Module End: F777C000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F777F000
Module End: F7784000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F7787000
Module End: F778C000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F7517000
Module End: F7521000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F778F000
Module End: F7795000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: B70D9000
Module End: B70DF000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F79BB000
Module End: F79BD000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\update.sys
Service Name: Update
Module Base: B63B1000
Module End: B63E5000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\WmBEnum.sys
Service Name: WmBEnum
Module Base: B87C8000
Module End: B87CB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\WmXlCore.sys
Service Name: WmXlCore
Module Base: F7507000
Module End: F7512000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: B87C4000
Module End: B87C8000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\dvd_2K.SYS
Service Name: dvd_2K
Module Base: B70C1000
Module End: B70C7000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F746E000
Module End: F7478000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F745E000
Module End: F746D000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F79CB000
Module End: F79CD000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\hap16v2k.sys
Service Name: hap16v2k
Module Base: B393B000
Module End: B3960000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ha10kx2k.sys
Service Name: ha10kx2k
Module Base: B385E000
Module End: B393B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\emupia2k.sys
Service Name: emupia
Module Base: B383C000
Module End: B385E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ctsfm2k.sys
Service Name: ctsfm2k
Module Base: B381C000
Module End: B383C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ctac32k.sys
Service Name: ctac32k
Module Base: B377E000
Module End: B381C000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Service Name: Flpydisk
Module Base: B70B9000
Module End: B70BE000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS
Service Name: Cdr4_xp
Module Base: F7A5B000
Module End: F7A5C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdralw2k.SYS
Service Name: Cdralw2k
Module Base: F7A5D000
Module End: F7A5E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F79D1000
Module End: F79D3000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F7A62000
Module End: F7A63000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F79D3000
Module End: F79D5000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: B70A1000
Module End: B70A8000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: B7099000
Module End: B709F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F79D5000
Module End: F79D7000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F79D7000
Module End: F79D9000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\cdudf_xp.SYS
Service Name: cdudf_xp
Module Base: B36F6000
Module End: B3736000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\DVDVRRdr_xp.SYS
Service Name: DVDVRRdr_xp
Module Base: B36C0000
Module End: B36E4000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: B7091000
Module End: B7096000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F7797000
Module End: F779F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\UdfReadr_xp.SYS
Service Name: UdfReadr_xp
Module Base: B3601000
Module End: B3636000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: B3978000
Module End: B397B000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\OAnet.sys
Service Name: OAnet
Module Base: F741E000
Module End: F7427000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: B35B4000
Module End: B35C7000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F740E000
Module End: F7417000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: B355C000
Module End: B35B4000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\OAmon.sys
Service Name: OAmon
Module Base: F779F000
Module End: F77A7000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: B353B000
Module End: B355C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswTdi.SYS
Service Name: aswTdi
Module Base: F7887000
Module End: F7891000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F7877000
Module End: F7880000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: B3513000
Module End: B353B000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\arp1394.sys
Service Name: Arp1394
Module Base: B81A1000
Module End: B81B0000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswRdr.SYS
Service Name: aswRdr
Module Base: F77A7000
Module End: F77AC000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: B34F1000
Module End: B3513000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: B8191000
Module End: B819A000
Hidden: No
Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
Service Name: SASKUTIL
Module Base: B34CF000
Module End: B34F1000
Hidden: No
Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Service Name: SASDIFSV
Module Base: F77AF000
Module End: F77B5000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: B34A4000
Module End: B34CF000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Service Name: OADevice
Module Base: B3456000
Module End: B34A4000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: B33E7000
Module End: B3456000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: B8171000
Module End: B817A000
Hidden: No
Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
Service Name: eeCtrl
Module Base: B3389000
Module End: B33E7000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Service Name: aswSP
Module Base: B32A2000
Module End: B32E9000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Aavmker4.SYS
Service Name: Aavmker4
Module Base: F77C7000
Module End: F77CD000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\hidusb.sys
Service Name: HidUsb
Module Base: B376A000
Module End: B376D000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: B8151000
Module End: B815A000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: B375E000
Module End: B3761000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: B3756000
Module End: B375A000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: B2DA1000
Module End: B2DB1000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: B1B58000
Module End: B1B70000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: B1BD8000
Module End: B1BDA000
Hidden: Yes
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: B1BA6000
Module End: B1BA9000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: B2A12000
Module End: B2A17000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: B2CA0000
Module End: B2CA1000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswFsBlk.SYS
Service Name: aswFsBlk
Module Base: B329A000
Module End: B329D000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: B2EFF000
Module End: B2F03000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswMon2.SYS
Service Name: aswMon2
Module Base: B18D0000
Module End: B18E7000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: B1673000
Module End: B16A0000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Service Name: ParVdm
Module Base: B2BE2000
Module End: B2BE4000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\aksfridge.sys
Service Name: aksfridge
Module Base: B15F1000
Module End: B164B000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\hardlock.sys
Service Name: Hardlock
Module Base: B1561000
Module End: B15F1000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: B153E000
Module End: B1561000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\secdrv.sys
Service Name: Secdrv
Module Base: B14EE000
Module End: B1516000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\srv.sys
Service Name: Srv
Module Base: B1497000
Module End: B14EE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: B11B2000
Module End: B11C7000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: B1738000
Module End: B1747000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: B1164000
Module End: B118F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: B0F13000
Module End: B0F54000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\fdc.sys
Service Name: Fdc
Module Base: F776F000
Module End: F7776000
Hidden: No
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwAllocateVirtualMemory
Address: B32AB728
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwAssignProcessToJobObject
Address: B3475700
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwClose
Address: B32B27EA
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwConnectPort
Address: B3472DA0
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateFile
Address: B34829C0
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreatePort
Address: B34728E0
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateProcess
Address: B346F620
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateProcessEx
Address: B346FA30
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateSection
Address: B346EEF0
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateThread
Address: B3470F20
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwDebugActiveProcess
Address: B3471B90
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwDeleteKey
Address: B32B2CA8
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwDeleteValueKey
Address: B32B2BBE
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwDuplicateObject
Address: B32B2276
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwFreeVirtualMemory
Address: B32AB7D8
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwLoadDriver
Address: B3474490
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwOpenFile
Address: B3483040
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwOpenProcess
Address: B32B21B2
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwOpenSection
Address: B346F310
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwOpenThread
Address: B32B2218
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwProtectVirtualMemory
Address: B32AB870
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwQueryDirectoryFile
Address: B3474A70
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwQueryValueKey
Address: B32B28C2
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwQueueApcThread
Address: B34758A0
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwRenameKey
Address: B32B2D76
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwRequestPort
Address: B34739A0
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwRequestWaitReplyPort
Address: B3473F90
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwRestoreKey
Address: B32B2880
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwResumeThread
Address: B3472340
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSecureConnectPort
Address: B3473190
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSetContextThread
Address: B3471970
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSetSystemInformation
Address: B3471D30
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSetValueKey
Address: B32B2A04
Driver Base: B32A2000
Driver End: B32E9000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwShutdownSystem
Address: B3474370
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSuspendProcess
Address: B3472520
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSuspendThread
Address: B3472130
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSystemDebugControl
Address: B3471F40
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwTerminateProcess
Address: B3470C80
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwTerminateThread
Address: B3471760
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwUnloadDriver
Address: B3474780
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwWriteVirtualMemory
Address: B3475520
Driver Base: B3456000
Driver End: B34A4000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: ObMakeTemporaryObject
At Address: 805A80B6
Jump To: B32BB1EE
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Hooked Function: ObInsertObject
At Address: 8056CBBF
Jump To: B32BCC88
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Hooked Function: ObDereferenceSecurityDescriptor
At Address: 8056CBBF
Jump To: B32BCC88
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied
Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied
Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied