__________
rkill log:
__________
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/22/2011 at 10:50:19.
Operating System: Windows Vista ™ Home Premium
Processes terminated by Rkill or while it was running:
Rkill completed on 03/22/2011 at 10:50:37.
******************************************************************
DDS.txt
_________
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:55:57.20 on Tue 03/22/2011
Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_22
Microsoft® Windows Vista™ Home Premium
6.0.6002.2.1252.1.1033.18.3061.1366 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-
47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-
7CA8AE10B9B5}
SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339-
560EB3387C28}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-
DA132C1ACF46}
FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-
C449366C71EE}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0
\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device
Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
C:\Toshiba\IVP\ISM\pinger.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\system32\UTSCSI.EXE
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows
Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows
Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
C:\Program Files\CyberLink\PowerCinema for
TOSHIBA\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common
Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\ehome\ehmsas.exe
C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\Microsoft
Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe
C:\Windows\System32\notepad.exe
C:\Program Files\Cisco Systems\VPN Client\ipseclog.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\explorer.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\explorer.exe
C:\Users\AdilSabah\Desktop\wtt forums\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uWindow Title = Sabah's Internet Explorer
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-
784b7d6be0b3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer:
{3049c3e9-b461-4bc5-8870-4c09146192ca} -
c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrec
ordplugin.dll
BHO: BHOManager Class: {474264bc-9571-47c1-85b9-780f756dc9ce} -
c:\windows\system32\BHOManager.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5
-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-
206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-
5164760863c6} - c:\program files\common files\microsoft
shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7}
- c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} -
c:\program files\skype\toolbars\internet
explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-
ce66b5ad205d} - c:\program
files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-
42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-
9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} -
c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [TOSCDSPD] TOSCDSPD.EXE
uRun: [MsnMsgr] "c:\program files\windows
live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search &
destroy\TeaTimer.exe
uRun: [swg] "c:\program
files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ISUSPM] "c:\program files\common
files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [Google Update]
"c:\users\adilsabah\appdata\local\google\update\GoogleUpdate.exe"
/c
uRun: [DW6] "c:\program files\the weather channel
fw\desktop\DesktopWeather.exe"
uRun: [cdloader]
"c:\users\adilsabah\appdata\roaming\mjusbsp\cdloader2.exe"
MAGICJACK
uRunOnce: [FlashPlayerUpdate] c:\windows\system32
\macromed\flash\FlashUtil10k_Plugin.exe -update plugin
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [SmoothView] %ProgramFiles%
\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [Windows Defender] %ProgramFiles%\Windows
Defender\MSASCui.exe -hide
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba
Stack\ItSecMng.exe /START
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [PCMAgent] "c:\program files\cyberlink\powercinema for
toshiba\PCMAgent.exe"
mRun: [CLMLServer] "c:\program files\cyberlink\powercinema for
toshiba\kernel\clml\CLMLSvc.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common
files\java\java update\jusched.exe"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader
8.0\reader\Reader_sl.exe"
mRun: [avast5] "c:\program files\alwil software\avast5
\avastUI.exe" /nogui
mRun: [TkBellExe] "c:\program files\common
files\real\update_ob\realsched.exe" -osboot
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -
atboottime
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe
-hide
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo
internet security\cfp.exe" -h
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [Picasa Media Detector] c:\program files\picasa2
\PicasaMediaDetector.exe
StartupFolder: c:\users\adilsa~1\appdata\roaming\micros~1
\windows\startm~1\programs\startup\spywar~1.lnk - c:\program
files\spywareguard\sgmain.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1
\programs\startup\vpncli~1.lnk - c:\windows\installer\{ccbaa1f7-
e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
IE: Add to Google Photos Screensa&ver; - c:\windows\system32
\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office14
\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google
toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll
/cmsidewiki.html
IE: Se&nd; to OneNote - c:\progra~1\mi1933~1\office14
\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-
98DB-E99415F33AEC} - c:\program files\windows
live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-
914C-F5F514E3486C} - c:\program files\microsoft office\office14
\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-
AB38-5D6374584B52} - c:\program files\microsoft office\office14
\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-
8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet
explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-
2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: magicjack.com\my
Trusted Zone: netflix.com\www
Trusted Zone: talk4free.com\reg
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
hxxp://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} -
hxxp://picasaweb.google.com/s/v/56.25/uploader2.cab
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} -
hxxp://picasaweb.google.com/s/v/54.16/uploader2.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
hxxp://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUplden-us.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} -
hxxp://messenger.zone.msn.com/EN-IN/a-UNO1/GAME_UNO1.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} -
hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCt
rl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-
i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear
/ultrashim.cab
DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} -
hxxp://www.idesitv.com/livetv.ocx
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -
hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab569
07.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-
i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-
i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-
i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-
i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} -
hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: {98098E6A-0CE9-43A8-892C-28940937E7FA} =
156.154.70.22,156.154.71.22
TCP: {C26356AB-0B17-4DD2-B7F7-24F7CE13D609} =
156.154.70.22,156.154.71.22
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} -
c:\program files\common files\microsoft shared\office14
\MSOXMLMF.DLL
Handler: HTLFP - {03B7A5D4-96B0-4316-95F8-072D326A58F1} -
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-
07617B9B86A8} - c:\program files\skype\toolbars\internet
explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: vfsp - {E4CB5121-E242-11D4-8ED6-00010219EB22} -
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
c:\program files\windows live\photo
gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll
c:\windows\system32\guard32.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910}
- c:\program files\spywareguard\spywareguard.dll
SEH: ShHook Class: {a5949e07-8536-4625-a3d0-2dd83f559990} -
c:\windows\system32\ShellHook.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\adilsa~1
\appdata\roaming\mozilla\firefox\profiles\kf2i0fbv.laddu\
FF - component:
c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\com
ponents\nprpffbrowserrecordext.dll
FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\update\1.2.183.39
\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6
\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\web platform
installer\NPWPIDetector.dll
FF - plugin: c:\program files\picasa2\npPicasa3.dll
FF - plugin: c:\program files\windows live\photo
gallery\NPWLPG.dll
FF - plugin:
c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\
nprphtml5videoshim.dll
FF - plugin:
c:\users\adilsabah\appdata\local\google\update\1.2.183.39
\npGoogleOneClick8.dll
FF - plugin:
c:\users\adilsabah\appdata\roaming\mozilla\plugins\npgoogletalk.dl
l
FF - plugin:
c:\users\adilsabah\appdata\roaming\mozilla\plugins\npgtpo3dautoplu
gin.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} -
c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-
a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-
0006-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} -
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-
0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-
0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} -
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-
0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} -
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-
0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed
-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5
\windows presentation foundation\DotNetAssistantExtension
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-
88E6-365A6E755758} -
c:\programdata\real\realplayer\browserrecordplugin\firefox\Ext
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed
-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-
80e3-08825760534b}
.
============= SERVICES / DRIVERS ===============
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-6-26
294608]
R1 cmdGuard;COMODO Internet Security Sandbox
Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-9-11 236600]
R1 cmdHlp;COMODO Internet Security Helper
Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-9-11 34744]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys
[2008-6-26 17744]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys
[2008-6-26 51280]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil
software\avast5\AvastSvc.exe [2010-10-31 40384]
R2 ConfigFree Service;ConfigFree Service;c:\program
files\toshiba\configfree\CFSvcs.exe [2007-12-25 40960]
R2 FontCache;Windows Font Cache Service;c:\windows\system32
\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 paldrv;paldrv;c:\windows\system32\pal_drv.sys [2010-4-17 11107]
R2 SBSDWSCService;SBSD Security Center Service;c:\program
files\spybot - search & destroy\SDWinSec.exe [2008-6-26 1153368]
R2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5
\TeamViewer_Service.exe [2010-3-18 172328]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program
files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008
-2-12 7168]
R3 osppsvc;Office Software Protection Platform;c:\program
files\common files\microsoft
shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9
4640000]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32
\drivers\teamviewervpn.sys [2010-3-11 25088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN
v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319
\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1c9dfab9a16ffd0;Google Update Service
(gupdate1c9dfab9a16ffd0);c:\program
files\google\update\GoogleUpdate.exe [2009-5-28 133104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager
5.9.1005.12335;c:\program files\google\google desktop
search\GoogleDesktop.exe [2008-2-12 30192]
S3 McComponentHostService;McAfee Security Scan Component Host
Service;"c:\program files\mcafee security scan\2.0.181
\mcchsvc.exe" –> c:\program files\mcafee security scan\2.0.181
\McCHSvc.exe [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache
4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319
\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 AutoSyncService;Memeo AutoSync ;c:\program
files\memeo\autosync\MemeoService.exe [2007-7-6 31768]
.
=============== Created Last 30 ================
.
2011-03-22 15:24:22 5943120 —-a-w- c:\progra~2
\microsoft\windows defender\definition updates\{f432af65-fca3-
465a-aee5-dff8b3ee82c1}\mpengine.dll
2011-03-12 03:49:11 429056 —-a-w-
c:\windows\system32\EncDec.dll
2011-03-12 03:49:11 322560 —-a-w-
c:\windows\system32\sbe.dll
2011-03-12 03:49:11 177664 —-a-w-
c:\windows\system32\mpg2splt.ax
2011-03-12 03:49:11 153088 —-a-w-
c:\windows\system32\sbeio.dll
2011-03-12 03:48:49 677888 —-a-w-
c:\windows\system32\mstsc.exe
2011-03-12 03:48:49 2067968 —-a-w-
c:\windows\system32\mstscax.dll
2011-02-23 17:26:55 ——– d—–w-
c:\users\adilsa~1\appdata\local\Microsoft Games
.
==================== Find3M ====================
.
2011-02-15 18:33:54 285480 —-a-w-
c:\windows\system32\guard32.dll
2011-02-02 23:11:20 222080 ——w-
c:\windows\system32\MpSigStub.exe
2011-01-20 16:08:16 478720 —-a-w-
c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w-
c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w-
c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w-
c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w-
c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w-
c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w-
c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w-
c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w-
c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w-
c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w-
c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w-
c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w-
c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w-
c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w-
c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w-
c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 —-a-w-
c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 —-a-w-
c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w-
c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w-
c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w-
c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w-
c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w-
c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w-
c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w-
c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 —-a-w-
c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 —-a-w-
c:\windows\system32\FntCache.dll
2011-01-13 08:47:35 38848 —-a-w-
c:\windows\avastSS.scr
2011-01-08 08:47:50 34304 —-a-w-
c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w-
c:\windows\system32\atmfd.dll
2010-12-31 13:57:01 2039808 —-a-w-
c:\windows\system32\win32k.sys
2010-12-31 01:26:37 6275960 -c–a-w- c:\program
files\Silverlight.exe
2010-12-28 15:55:03 413696 —-a-w-
c:\windows\system32\odbc32.dll
2008-05-31 03:16:51 13288968 -c–a-w- c:\program
files\RealPlayer11GOLD.exe
.
============= FINISH: 10:58:00.12 ===============
*************************************************************************
rootkitunhooker report:
___________________
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6002 (Service Pack 2)
Number of processors #2
==============================================
>Drivers
==============================================
0x8F40E000 C:\Windows\system32\DRIVERS\igdkmd32.sys 6516736 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x82E02000 C:\Windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System)
0x82E02000 PnpManager 3907584 bytes
0x82E02000 RAW 3907584 bytes
0x82E02000 WMIxWDM 3907584 bytes
0x8FE0D000 C:\Windows\system32\DRIVERS\NETw4v32.sys 2289664 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver)
0x9B030000 Win32k 2109440 bytes
0x9B030000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x90600000 C:\Windows\system32\drivers\RTKVHDA.sys 2052096 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver)
0x90800000 C:\Windows\system32\DRIVERS\AGRSM.sys 1163264 bytes (Agere Systems, SoftModem Device Driver)
0x8B807000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver)
0x8B477000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x80694000 PCI_PNP3389 1048576 bytes
0x80694000 C:\Windows\System32\Drivers\spku.sys 1048576 bytes
0x80694000 sptd 1048576 bytes
0x8B607000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)
0x804E0000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)
0xB4003000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x8F200000 C:\Windows\System32\Drivers\dump_iaStor.sys 819200 bytes
0x8B313000 C:\Windows\system32\DRIVERS\iaStor.sys 819200 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)
0xAEE0D000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)
0x8FA45000 C:\Windows\System32\drivers\dxgkrnl.sys 655360 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0xB20EB000 C:\Windows\system32\Drivers\CVPNDRVA.sys 589824 bytes (Cisco Systems, Inc., Cisco Systems VPN Client IPSec Driver)
0x8FB49000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x8060B000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)
0x8B406000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x80416000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)
0xAEF14000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x90097000 C:\Windows\system32\DRIVERS\rixdptsk.sys 331776 bytes (REDC, RICOH XD SM Driver)
0xB2099000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x8B955000 C:\Windows\system32\DRIVERS\tos_sps32.sys 307200 bytes (TOSHIBA Corporation, tos_sps2)
0x8B2A4000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x90C00000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x90D32000 C:\Windows\System32\Drivers\aswSP.SYS 290816 bytes (AVAST Software, avast! self protection module)
0x8B204000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)
0x8049F000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x8F2F9000 C:\Windows\system32\DRIVERS\Rtlh86.sys 266240 bytes (Realtek , Realtek 8136/8168/8169 NDIS6 32-bit Driver )
0x901BC000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x8FAFC000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x90929000 C:\Windows\System32\DRIVERS\cmdguard.sys 249856 bytes (COMODO, COMODO Internet Security Sandbox Driver)
0x90CD5000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x8B5AD000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)
0xB2020000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x8B917000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x90DBA000 C:\Windows\system32\drivers\aswMonFlt.sys 225280 bytes (AVAST Software, avast! File System Minifilter for Windows 2003/Vista)
0x8B73A000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x831BC000 ACPI_HAL 208896 bytes
0x831BC000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x805C0000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x90C4D000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x90106000 C:\Windows\system32\DRIVERS\SynTP.sys 196608 bytes (Synaptics, Inc., Synaptics Touchpad Driver)
0x9018D000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x8B76F000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x8B582000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8F3A5000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0xAEECD000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0xB4170000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver)
0xB2071000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x8B9B7000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0x8B252000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0x8079D000 C:\Windows\System32\Drivers\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver)
0x8B79C000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x8F33A000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x8B70C000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0xAEFCC000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x9098B000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0xB2001000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x807C3000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)
0x9016F000 C:\Windows\system32\DRIVERS\dne2000.sys 122880 bytes (Deterministic Networks, Inc., Deterministic Network Enhancer)
0xAEF81000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x8B6F1000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x90D9F000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0x9005A000 C:\Windows\system32\DRIVERS\sdbus.sys 106496 bytes (Microsoft Corporation, SecureDigital Bus Driver)
0xAEF9E000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x90147000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xB2059000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x90D1B000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x8FBD6000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xB40FC000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0x90C9E000 C:\Windows\system32\DRIVERS\inspect.sys 90112 bytes (COMODO, COMODO Internet Security Firewall Driver)
0x90C88000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x909DE000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0xAEFB7000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8F380000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8F36C000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x90083000 C:\Windows\system32\DRIVERS\rimsptsk.sys 81920 bytes (REDC, RICOH MS Driver)
0x8B5E8000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x900E8000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)
0xAEF01000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x90CC2000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x8B9DE000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x8F3E7000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x80486000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x8B3ED000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0xAEEBD000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x8B303000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x9003C000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0x8F395000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x9015F000 C:\Windows\System32\Drivers\tosrfcom.sys 65536 bytes (TOSHIBA Corporation, Bluetooth RFCOMM Driver)
0x8F2E6000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0x90D90000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x8B9A8000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x8B279000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x8F35D000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x90074000 C:\Windows\system32\DRIVERS\rimmptsk.sys 61440 bytes (REDC, RICOH SD Driver)
0x8FB3A000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x8B295000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x9004C000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0x9B300000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x90CB4000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x909C7000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x8B2F5000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x90D79000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x9091C000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)
0x8F3CF000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x80687000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)
0xB40EB000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x9097F000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x8FAE5000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)
0x907F5000 C:\Windows\System32\DRIVERS\cmdhlp.sys 45056 bytes (COMODO, COMODO Internet Security Helper Driver)
0x900FB000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)
0x90138000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)
0x909BC000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x8FBED000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x8FE00000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x8F3DC000 C:\Windows\system32\DRIVERS\tosporte.sys 45056 bytes (TOSHIBA Corporation, TOSHIBA Bluetooth Port Emulation Driver)
0x8FAF1000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x8F2CA000 C:\Windows\System32\Drivers\aswTdi.SYS 40960 bytes (AVAST Software, avast! TDI Filter Driver)
0x8B28B000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x90D86000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x8B3E3000 C:\Windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x8F400000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0xAEEF7000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x90D11000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x807E1000 C:\Windows\System32\Drivers\PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xB40E1000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0xB4198000 C:\Windows\system32\DRIVERS\asyncmac.sys 36864 bytes (Microsoft Corporation, MS Remote Access serial network driver)
0x8B9EF000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x90968000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0xB41CB000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x909D5000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x9B250000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8F2D5000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x80794000 C:\Windows\System32\Drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x90C7F000 C:\Windows\system32\drivers\ws2ifsl.sys 36864 bytes (Microsoft Corporation, Winsock2 IFS Layer)
0x8B3DB000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x80497000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x8F2DE000 C:\Windows\system32\DRIVERS\FwLnk.sys 32768 bytes (TOSHIBA Corporation, TOSHIBA Firmware Linkage 32-bit Driver)
0x8B24A000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x909AC000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x909B4000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8B9A0000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x90978000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0xB4169000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x8B2EE000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0x8040F000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xB41C4000 C:\Users\ADILSA~1\AppData\Local\Temp\mbr.sys 28672 bytes
0x90971000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8FBF8000 C:\Windows\system32\DRIVERS\teamviewervpn.sys 28672 bytes (TeamViewer GmbH, TeamViewerVPN Network Adapter)
0x90C48000 C:\Windows\System32\Drivers\aswRdr.SYS 20480 bytes (AVAST Software, avast! TDI RDR Driver)
0xB40F7000 C:\Windows\system32\DRIVERS\LVPr2Mon.sys 20480 bytes (-, -)
0x8B950000 C:\Windows\system32\DRIVERS\TVALZ_O.SYS 20480 bytes (TOSHIBA Corporation, TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver)
0xB20E7000 C:\Windows\System32\Drivers\Aspi32.SYS 16384 bytes (Adaptec, ASPI for WIN32 Kernel Driver)
0x8F2F5000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x90143000 C:\Windows\system32\DRIVERS\tdcmdpst.sys 16384 bytes (TOSHIBA Corporation., Toshiba ODD Writing Driver For x86.)
0x90DF1000 C:\Windows\System32\Drivers\aswFsBlk.SYS 12288 bytes (AVAST Software, avast! File System Access Blocking Driver)
0x8B288000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0xB217B000 C:\Windows\system32\pal_drv.sys 12288 bytes (Mercury Interactive Corp., Astra)
0x8FE0B000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x90136000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0x865171F8 unknown_irp_handler 3592 bytes
0xD7ACB1F8 unknown_irp_handler 3592 bytes
0x865151F8 unknown_irp_handler 3592 bytes
0x87F7C1F8 unknown_irp_handler 3592 bytes
0x89ED51F8 unknown_irp_handler 3592 bytes
0x89F091F8 unknown_irp_handler 3592 bytes
0x8807C1F8 unknown_irp_handler 3592 bytes
0x865121F8 unknown_irp_handler 3592 bytes
0x87EC51F8 unknown_irp_handler 3592 bytes
0x865161F8 unknown_irp_handler 3592 bytes
0x87EEF1F8 unknown_irp_handler 3592 bytes
0x87ECD500 unknown_irp_handler 2816 bytes
0x85E7D500 unknown_irp_handler 2816 bytes
==============================================
>Stealth
==============================================
WARNING: File locked for read access [C:\Windows\system32\drivers\sptd.sys]
0xB41DA130 Unknown thread object [ ETHREAD 0xDE4A7730 ] , 600 bytes
0x909F5130 Unknown thread object [ ETHREAD 0x89F95020 ] , 600 bytes
0xB412A130 Unknown thread object [ ETHREAD 0x87F00688 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x8A22E9A0 ] , 600 bytes
0xB41A2130 Unknown thread object [ ETHREAD 0x85D35470 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x8A29FAC0 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x81371CA0 ] , 600 bytes
0xB4154130 Unknown thread object [ ETHREAD 0x85F3A5B8 ] , 600 bytes
0xB4113130 Unknown thread object [ ETHREAD 0xAF4C2290 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0xD7A17A90 ] , 600 bytes
0xF41E1130 Unknown thread object [ ETHREAD 0xE18CBAC0 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0x8214A290 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x85FD45F0 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x85E8F3B8 ] , 600 bytes
0xF41B7130 Unknown thread object [ ETHREAD 0x925A23F8 ] , 600 bytes
0xF4130130 Unknown thread object [ ETHREAD 0x925DB370 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0xDE4472C0 ] , 600 bytes
0xB41B9130 Unknown thread object [ ETHREAD 0x82809020 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0x86487AA8 ] , 600 bytes
0xB41E3130 Unknown thread object [ ETHREAD 0x8A2AA020 ] , 600 bytes
0xB415F130 Unknown thread object [ ETHREAD 0xAFFE4D78 ] , 600 bytes
0xF4139130 Unknown thread object [ ETHREAD 0x94067D78 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x860950F0 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x924CBD78 ] , 600 bytes
0xB41F1130 Unknown thread object [ ETHREAD 0x92B682E8 ] , 600 bytes
0xF4102130 Unknown thread object [ ETHREAD 0x9256CB08 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0x874C4858 ] , 600 bytes
0xB41AB130 Unknown thread object [ ETHREAD 0x81C11B08 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0x81C22290 ] , 600 bytes
0xF4163130 Unknown thread object [ ETHREAD 0x92AD0480 ] , 600 bytes
0xDF6E9130 Unknown thread object [ ETHREAD 0xAC9CD170 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0xD8A0BD78 ] , 600 bytes
0xF415A130 Unknown thread object [ ETHREAD 0x940585C8 ] , 600 bytes
0xB41BE130 Unknown thread object [ ETHREAD 0x8213A898 ] , 600 bytes
0xB41DA130 Unknown thread object [ ETHREAD 0x925DE298 ] , 600 bytes
0xB41D5130 Unknown thread object [ ETHREAD 0x875CC910 ] , 600 bytes
0xF410F130 Unknown thread object [ ETHREAD 0x8AF97930 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0x92AA22B8 ] , 600 bytes
0xF40E1130 Unknown thread object [ ETHREAD 0xF4820D78 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0x92BFF820 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0xBC98A278 ] , 600 bytes
0xB41A2130 Unknown thread object [ ETHREAD 0x8F18ED78 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0x8A39C020 ] , 600 bytes
0xB41E3130 Unknown thread object [ ETHREAD 0xCD6A72C8 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0xC4AF03F8 ] , 600 bytes
0xB414B130 Unknown thread object [ ETHREAD 0xDD247298 ] , 600 bytes
0xF418D130 Unknown thread object [ ETHREAD 0x94119A90 ] , 600 bytes