SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 560
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 636
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 660
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 704
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 716
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 868
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 948
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1044
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1104
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1252
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PID: 1400
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\ashServ.exe
PID: 1460
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 1740
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 436
Hidden: No
Window Visible: No
Name: C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PID: 552
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jqs.exe
PID: 640
Hidden: No
Window Visible: No
Name: C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PID: 1348
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
PID: 1760
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1992
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wdfmgr.exe
PID: 220
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Java\Java Update\jusched.exe
PID: 476
Hidden: No
Window Visible: No
Name: C:\Program Files\ICQ7.1\ICQ.exe
PID: 572
Hidden: No
Window Visible: Yes
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 1396
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PID: 212
Hidden: No
Window Visible: No
Name: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PID: 772
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wscntfy.exe
PID: 2528
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\alg.exe
PID: 2504
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 3072
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 1988
Hidden: No
Window Visible: No
Name: C:\Program Files\Mozilla Firefox\firefox.exe
PID: 3192
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\Verka\Dokumenty\Stažené soubory\SysProt\SysProt\SysProt.exe
PID: 1068
Hidden: No
Window Visible: Yes
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\Verka\Dokumenty\Stažené soubory\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: EF80E000
Module End: EF819000
Hidden: No
Module Name: \WINDOWS\system32\ntoskrnl.exe
Service Name: ---
Module Base: 804D7000
Module End: 806EBE00
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806EC000
Module End: 8070C380
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F8A42000
Module End: F8A44000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F8952000
Module End: F8955000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F84F3000
Module End: F8521000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F8A44000
Module End: F8A46000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F84E2000
Module End: F84F3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F8542000
Module End: F854B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PCIIde.sys
Service Name: PCIIde
Module Base: F8B0A000
Module End: F8B0B000
Hidden: No
Module Name: \WINDOWS\System32\Drivers\PCIIDEX.SYS
Service Name: ---
Module Base: F87C2000
Module End: F87C9000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\intelide.sys
Service Name: IntelIde
Module Base: F8A46000
Module End: F8A48000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F8552000
Module End: F855D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F84C3000
Module End: F84E2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: F8A48000
Module End: F8A4A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: F849D000
Module End: F84C3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F87CA000
Module End: F87CF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F8562000
Module End: F856F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F8485000
Module End: F849D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F8572000
Module End: F857B000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F8582000
Module End: F858F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltMgr.sys
Service Name: FltMgr
Module Base: F8466000
Module End: F8485000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F8454000
Module End: F8466000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F8592000
Module End: F859B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F843D000
Module End: F8454000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F83B0000
Module End: F843D000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F8383000
Module End: F83B0000
Hidden: No
Module Name: Combo-Fix.sys
Service Name: ---
Module Base: F85A2000
Module End: F85B1000
Hidden: Yes
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F8368000
Module End: F8383000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F8622000
Module End: F862C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
Service Name: ialm
Module Base: F8309000
Module End: F8320000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F82F5000
Module End: F8309000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F87EA000
Module End: F87EF000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F82D2000
Module End: F82F5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F87F2000
Module End: F87F9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\e100b325.sys
Service Name: E100B
Module Base: F82AE000
Module End: F82D2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F8632000
Module End: F863F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F87FA000
Module End: F8800000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\serial.sys
Service Name: Serial
Module Base: F8642000
Module End: F8652000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\serenum.sys
Service Name: Serenum
Module Base: F89DA000
Module End: F89DE000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F8652000
Module End: F865F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F8662000
Module End: F8671000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: F828B000
Module End: F82AE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\smwdm.sys
Service Name: smwdm
Module Base: F8207000
Module End: F828B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: F81E3000
Module End: F8207000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: F8672000
Module End: F8681000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\aeaudio.sys
Service Name: aeaudio
Module Base: F8A4C000
Module End: F8A4E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F8B7E000
Module End: F8B7F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F8682000
Module End: F868F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F89E2000
Module End: F89E5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F81CC000
Module End: F81E3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F8692000
Module End: F869D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F86A2000
Module End: F86AE000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F880A000
Module End: F880F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys
Service Name: PSched
Module Base: F81BB000
Module End: F81CC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F86B2000
Module End: F86BB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F8812000
Module End: F8817000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F881A000
Module End: F881F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: F818A000
Module End: F81BB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F86C2000
Module End: F86CC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F8822000
Module End: F8828000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F8A4E000
Module End: F8A50000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\update.sys
Service Name: Update
Module Base: F8156000
Module End: F818A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F89FE000
Module End: F8A02000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F86D2000
Module End: F86DC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ialmkchw.sys
Service Name: {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}
Module Base: EFFFA000
Module End: F000E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ialmsbw.sys
Service Name: {6080A529-897E-4629-A488-ABA0C29B635E}
Module Base: EFFDE000
Module End: EFFFA000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F86F2000
Module End: F8701000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F8A50000
Module End: F8A52000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\flpydisk.sys
Service Name: Flpydisk
Module Base: F882A000
Module End: F882F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F8A52000
Module End: F8A54000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F8BFE000
Module End: F8BFF000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F8A54000
Module End: F8A56000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: F883A000
Module End: F8841000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F8842000
Module End: F8848000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F8A56000
Module End: F8A58000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F8A58000
Module End: F8A5A000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F884A000
Module End: F884F000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F8852000
Module End: F885A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: F8A36000
Module End: F8A39000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: EFF83000
Module End: EFF96000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: EFF2B000
Module End: EFF83000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswTdi.SYS
Service Name: aswTdi
Module Base: F8712000
Module End: F871C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: EFF0A000
Module End: EFF2B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F8722000
Module End: F872B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: EFEE2000
Module End: EFF0A000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: EFEC0000
Module End: EFEE2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: F8732000
Module End: F873B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: EFE94000
Module End: EFEC0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: EFE25000
Module End: EFE94000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: F8752000
Module End: F875B000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Service Name: aswSP
Module Base: EFE04000
Module End: EFE25000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Aavmker4.SYS
Service Name: Aavmker4
Module Base: F886A000
Module End: F886F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Service Name: hidusb
Module Base: F8324000
Module End: F8327000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: F8772000
Module End: F877B000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: F8320000
Module End: F8323000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: EFDB9000
Module End: EFDDC000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: EFDA1000
Module End: EFDB9000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F8A62000
Module End: F8A64000
Hidden: Yes
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: F814E000
Module End: F8151000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: F8872000
Module End: F8877000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: F8BD7000
Module End: F8BD8000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
Service Name: aswFsBlk
Module Base: F8882000
Module End: F888A000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: EFCA9000
Module End: EFCAD000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswMon2.SYS
Service Name: aswMon2
Module Base: EFB0B000
Module End: EFB21000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: EF89E000
Module End: EF8B3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: F8792000
Module End: F87A1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: EF614000
Module End: EF641000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys
Service Name: Srv
Module Base: EF536000
Module End: EF588000
Hidden: No
Module Name: \??\C:\DOCUME~1\Verka\LOCALS~1\Temp\mbr.sys
Service Name: mbr
Module Base: F88B2000
Module End: F88B8000
Hidden: Yes
Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: EF10D000
Module End: EF14E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswRdr.SYS
Service Name: aswRdr
Module Base: EF34A000
Module End: EF34E000
Hidden: No
Module Name: \??\C:\ComboFix\catchme.sys
Service Name: catchme
Module Base: F88BA000
Module End: F88C2000
Hidden: Yes
Module Name: \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
Service Name: ---
Module Base: F8A8A000
Module End: F8A8C000
Hidden: Yes
Module Name: C:\WINDOWS\system32\DRIVERS\fdc.sys
Service Name: Fdc
Module Base: F8802000
Module End: F8809000
Hidden: No
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwClose
Address: EFE0C6B8
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwCreateKey
Address: EFE0C574
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwDeleteValueKey
Address: EFE0CA52
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwDuplicateObject
Address: EFE0C14C
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwOpenKey
Address: EFE0C64E
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwOpenProcess
Address: EFE0C08C
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwOpenThread
Address: EFE0C0F0
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwQueryValueKey
Address: EFE0C76E
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwRestoreKey
Address: EFE0C72E
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwSetValueKey
Address: EFE0C8AE
Driver Base: EFE04000
Driver End: EFE25000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: ZwLoadDriver
At Address: 805A410A
Jump To: EFE157B0
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Hooked Function: ZwCreateSection
At Address: 8056469B
Jump To: EFE1567C
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Hooked Function: ZwCreateProcessEx
At Address: 80581F0E
Jump To: EFE15832
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: VĚRKY:1569
Remote Address: PAGEAD2.GOOGLESYNDICATION.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1568
Remote Address: FILES.NETSHELTER.NET:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1566
Remote Address: PAGEAD2.GOOGLESYNDICATION.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1564
Remote Address: IMG.TRADEPUB.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: CLOSE_WAIT
Local Address: VĚRKY:1561
Remote Address: FPDOWNLOAD2.MACROMEDIA.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1558
Remote Address:
WWW.GOOGLE:HTTPType: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1556
Remote Address: GOOGLEADS.G.DOUBLECLICK.NET:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1553
Remote Address: GOOGLEADS.G.DOUBLECLICK.NET:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1551
Remote Address: GOOGLEADS.G.DOUBLECLICK.NET:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1549
Remote Address: GOOGLEADS.G.DOUBLECLICK.NET:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1548
Remote Address: GOOGLEADS.G.DOUBLECLICK.NET:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1545
Remote Address: TRACK.NETSHELTER.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1531
Remote Address: IMAGES.BETANEWS.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1530
Remote Address: IMAGES.BETANEWS.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1528
Remote Address: IMAGES.BETANEWS.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1526
Remote Address: IMAGES.BETANEWS.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:INGRESLOCK
Remote Address: IMAGES.BETANEWS.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1522
Remote Address: IMAGES.BETANEWS.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1516
Remote Address:
WWW.GOOGLE.COM:HTTPType: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1508
Remote Address: GOOGLEADS.G.DOUBLECLICK.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1489
Remote Address: IDCS.INTERCLICK.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1486
Remote Address:
WWW.SYMANTEC.COM:HTTPType: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1485
Remote Address:
WWW.SYMANTEC.COM:HTTPType: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1483
Remote Address: WELCOME.ICQ.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1481
Remote Address: WELCOME.ICQ.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1479
Remote Address: WELCOME.ICQ.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1477
Remote Address: WELCOME.ICQ.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1476
Remote Address: WELCOME.ICQ.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1472
Remote Address: WELCOME.ICQ.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1443
Remote Address: IMAGES.INTELLITXT.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1442
Remote Address: IMAGES.INTELLITXT.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1440
Remote Address: IMAGES.INTELLITXT.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1438
Remote Address: IMAGES.INTELLITXT.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1436
Remote Address: IMAGES.INTELLITXT.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:MS-SQL-M
Remote Address: IMAGES.INTELLITXT.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1421
Remote Address: CDN5.TRIBALFUSION.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1415
Remote Address: STATIC.AK.FACEBOOK.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1390
Remote Address:
WWW.GOOGLE.COM:HTTPType: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1278
Remote Address:
WWW.GOOGLE:HTTPType: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1191
Remote Address: C.ICQ.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1083
Remote Address: C.ICQ.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:1054
Remote Address: BOS-D043A-RDR2.BLUE.AOL.COM:HTTPS
Type: TCP
Process: C:\Program Files\ICQ7.1\ICQ.exe
State: ESTABLISHED
Local Address: VĚRKY:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: VĚRKY:12143
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: VĚRKY:12119
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: VĚRKY:12110
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1567
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1565
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1563
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1562
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1559
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1555
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1554
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1552
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1550
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1547
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1546
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1541
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1515
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1387
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1110
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: LOCALHOST:1082
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: VĚRKY:12080
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: LISTENING
Local Address: VĚRKY:12025
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: VĚRKY:5152
Remote Address: LOCALHOST:1517
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: CLOSE_WAIT
Local Address: VĚRKY:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: VĚRKY:1574
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1572
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1570
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1567
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1565
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1563
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1562
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1559
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1557
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1555
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1554
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1552
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1550
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1547
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1546
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1532
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1518
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1517
Remote Address: LOCALHOST:5152
Type: TCP
Process: 1204 (PID)
State: FIN_WAIT2
Local Address: VĚRKY:1515
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1513
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1470
Remote Address: LOCALHOST:5152
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: VĚRKY:1387
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1259
Remote Address: LOCALHOST:1258
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1258
Remote Address: LOCALHOST:1259
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1254
Remote Address: LOCALHOST:1253
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1253
Remote Address: LOCALHOST:1254
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: VĚRKY:1110
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\ICQ7.1\ICQ.exe
State: ESTABLISHED
Local Address: VĚRKY:1082
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\ICQ7.1\ICQ.exe
State: ESTABLISHED
Local Address: VĚRKY:1026
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING
Local Address: VĚRKY:2869
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: VĚRKY:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: VĚRKY:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: VĚRKY:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: VĚRKY:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: VĚRKY:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: VĚRKY:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: VĚRKY:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: VĚRKY:1045
Remote Address: NA
Type: UDP
Process: C:\Program Files\ICQ7.1\ICQ.exe
State: NA
Local Address: VĚRKY:1036
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: VĚRKY:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: VĚRKY:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: VĚRKY:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: VĚRKY:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: D:\Program Files\Windows NT\poíslušenství
Status: Hidden
Object: D:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: D:\System Volume Information\tracking.log
Status: Access denied
Object: D:\System Volume Information\_restore{503E6C49-67A3-449D-8B7C-19CCA0F06703}
Status: Access denied
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\adventnA_Ä?as.pps.LNK
Status: Hidden
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\Báseo_Charles_R._Swindoll.pps.LNK
Status: Hidden
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\Dovolená_pro_mu3e.pps.LNK
Status: Hidden
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\Erotika_a_uminí_....pps.LNK
Status: Hidden
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\Jak_u3ívat_3ivota.pps.LNK
Status: Hidden
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\Kuoecí_buchta_1.ppt.LNK
Status: Hidden
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\Mrtvé_Mooe_Izrael.pps.LNK
Status: Hidden
Object: C:\Documents and Settings\Verka\Data aplikací\Microsoft\Office\Naposledy otevřené\Noení_Praha.pps.LNK
Status: Hidden