Dear shinybeast:
I am posting my reply again as I do not see it.
I have deleted old Java, downloaded new Java, disabled Windows Defender. I am still trying to figure out how to disable Norton's automatic updates.
Here is the SYSPROT LOG:
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 4
Hidden: Yes
Window Visible: No
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: SYMDS.SYS
Service Name: SymDS
Module Base: F82B7000
Module End: F830D000
Hidden: Yes
Module Name: SYMEFA.SYS
Service Name: SymEFA
Module Base: F8279000
Module End: F82A5000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: F5D69000
Module End: F5D81000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F8A48000
Module End: F8A4A000
Hidden: Yes
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwAlertResumeThread
Address: 82F2D230
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAlertThread
Address: 82F85A60
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAllocateVirtualMemory
Address: 82F825D8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwAssignProcessToJobObject
Address: 82F31AC8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwConnectPort
Address: 82F7AE30
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateKey
Address: F6246210
Driver Base: F6230000
Driver End: F6255000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwCreateMutant
Address: 83134E78
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateSymbolicLinkObject
Address: 83182468
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwCreateThread
Address: 82F82828
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDebugActiveProcess
Address: 82F31BA8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDeleteKey
Address: F6246490
Driver Base: F6230000
Driver End: F6255000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwDeleteValueKey
Address: F62469F0
Driver Base: F6230000
Driver End: F6255000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwDuplicateObject
Address: 82F89528
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwEnumerateKey
Address: F83C1A92
Driver Base: F83BB000
Driver End: F8495000
Driver Name: sptd.sys
Function Name: ZwEnumerateValueKey
Address: F83C1E20
Driver Base: F83BB000
Driver End: F8495000
Driver Name: sptd.sys
Function Name: ZwFreeVirtualMemory
Address: 830F14E0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwImpersonateAnonymousToken
Address: 8306D518
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwImpersonateThread
Address: 83230C80
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwLoadDriver
Address: 830C93D8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwMapViewOfSection
Address: 83085008
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenEvent
Address: 82FFCE68
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenKey
Address: F62467A0
Driver Base: F6230000
Driver End: F6255000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwOpenProcess
Address: 82F94280
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenProcessToken
Address: 82F97248
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenSection
Address: 82FF76A0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwOpenThread
Address: 831AA660
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwProtectVirtualMemory
Address: 83182558
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwQueryKey
Address: F83C1EF8
Driver Base: F83BB000
Driver End: F8495000
Driver Name: sptd.sys
Function Name: ZwQueryValueKey
Address: F83C1D78
Driver Base: F83BB000
Driver End: F8495000
Driver Name: sptd.sys
Function Name: ZwResumeThread
Address: 82F8AA60
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetContextThread
Address: 82F8C5F0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetInformationProcess
Address: 82F8A5E0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetSystemInformation
Address: 82F403D0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSetValueKey
Address: F6246C40
Driver Base: F6230000
Driver End: F6255000
Driver Name: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Function Name: ZwSuspendProcess
Address: 82FF7780
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwSuspendThread
Address: 82F8D928
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwTerminateProcess
Address: 831158F0
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwTerminateThread
Address: 82F88840
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwUnmapViewOfSection
Address: 82FA6A18
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwWriteVirtualMemory
Address: 82F76590
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
IRP Hooks:
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_CREATE
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_CLOSE
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_READ
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_WRITE
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_SET_EA
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_CLEANUP
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_POWER
Jump To: F83CADB8
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F83E5344
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: \Driver\PCI_NTPNP0094
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: F83E8F18
Hooking Module: C:\WINDOWS\system32\drivers\sptd.sys
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 833D41E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 833D41E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 833D41E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: FEFB14B8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 833D41E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 833D41E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 831EF1E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 831EF1E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 831EF1E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 831EF1E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 831EF1E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 831EF1E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_READ
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 833691E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 83088610
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 83088610
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 83088610
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 83088610
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 83088610
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_READ
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 831BC980
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 831F31E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 831F31E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 831F31E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 831F31E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 831F31E8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 831F31E8
Hooking Module: _unknown_
******************************************************************************************
******************************************************************************************
Ports:
Local Address: DOWNSTAIRS:8999
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
State: LISTENING
Local Address: DOWNSTAIRS:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: DOWNSTAIRS:1028
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING
Local Address: DOWNSTAIRS:1027
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe
State: LISTENING
Local Address: DOWNSTAIRS:65533
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\services.exe
State: LISTENING
Local Address: DOWNSTAIRS:8367
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\services.exe
State: LISTENING
Local Address: DOWNSTAIRS:3389
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: DOWNSTAIRS:2479
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\services.exe
State: LISTENING
Local Address: DOWNSTAIRS:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: DOWNSTAIRS:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: DOWNSTAIRS:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: DOWNSTAIRS:1094
Remote Address: NA
Type: UDP
Process: C:\Program Files\Windows Live\Contacts\wlcomm.exe
State: NA
Local Address: DOWNSTAIRS:1081
Remote Address: NA
Type: UDP
Process: C:\Program Files\Windows Live\Mail\wlmail.exe
State: NA
Local Address: DOWNSTAIRS:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: DOWNSTAIRS:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: DOWNSTAIRS:MS-SQL-M
Remote Address: NA
Type: UDP
Process: C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
State: NA
Local Address: DOWNSTAIRS:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: DOWNSTAIRS:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
******************************************************************************************
******************************************************************************************
No hidden files/folders found
Here is the RSIT log.txt:
Run by Marie Johnson at 2010-01-13 17:40:23
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 94 GB (72%) free of 131 GB
Total RAM: 511 MB (25% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:40:38 PM, on 1/13/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Belkin\F5D8053v4\BelkinWCUI.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Marie Johnson\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Marie Johnson.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&gbh=1R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.100:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Belkin Wireless Networking Utility.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) -
http://www.alternatiff.com/install/00/alttiff.cabO16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) -
http://webiq005.webiqonline.com/WebIQ/D ... tion&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cabO16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) -
http://workingmom.coupons.smartsource.c ... scmv5X.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resour ... se6662.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/Shar ... /cabsa.cabO16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
https://webdl.symantec.com/activex/symdlmgr.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftup ... 3674339687O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2.hp.com/ediags/dex/s ... DEXAXO.cabO16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} -
http://h20270.www2.hp.com/ediags/gmn2/i ... ction2.cabO16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) -
http://offers.e-centives.com/cif/downlo ... ctxcab.cabO16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} -
http://h20264.www2.hp.com/ediags/dd/ins ... csxp2k.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton Internet Security. (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 10643 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1251834635.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Marie Johnson.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{B8E2009F-5D9A-4246-92C7-AB4E566AEAB1}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll [2009-10-28 392560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\IPSBHO.DLL [2009-10-01 79224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-13 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-13 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll [2009-10-28 392560]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"RemoteControl"=C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2003-12-08 32768]
"nwiz"=nwiz.exe /install []
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2003-10-06 5058560]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"InCD"=C:\Program Files\Ahead\InCD\InCD.exe [2005-07-08 1397760]
"diagent"=C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe [2002-04-03 135264]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-11-07 111936]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [2007-03-09 63712]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-22 68856]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-06-02 1957888]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Belkin Wireless Networking Utility.lnk - C:\Program Files\Belkin\F5D8053v4\BelkinWCUI.exe
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-02-15 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-04 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
scecli
scecli
scecli
scecli
scecli
scecli
scecli
scecli
scecli
scecli
scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe"="C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe:*:Enabled:Acrobat Reader 5.0"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.0.0.125\uiStub.exe"="C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.0.0.125\uiStub.exe:*:Enabled:Norton Internet Security"
"C:\Program Files\Adobe\Acrobat.com\Acrobat.com.exe"="C:\Program Files\Adobe\Acrobat.com\Acrobat.com.exe:*:Enabled:Acrobat.com"
"C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe"="C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:*:Disabled:PandoRest Application Name"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN\MSNCoreFiles\msn6.exe"="C:\Program Files\MSN\MSNCoreFiles\msn6.exe:*:Enabled:MSN Explorer"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 3 months======
2010-01-13 17:40:23 ----D---- C:\rsit
2010-01-13 16:29:40 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-01-13 16:27:36 ----A---- C:\WINDOWS\system32\javaws.exe
2010-01-13 16:27:36 ----A---- C:\WINDOWS\system32\javaw.exe
2010-01-13 16:27:35 ----A---- C:\WINDOWS\system32\java.exe
2010-01-06 11:03:16 ----A---- C:\Spiderevmpatch.exe
2010-01-05 19:42:44 ----D---- C:\Program Files\Trend Micro
2010-01-05 17:27:23 ----D---- C:\Documents and Settings\Marie Johnson\Application Data\Malwarebytes
2010-01-05 17:27:02 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-01-05 17:27:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-05 15:58:55 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-05 13:44:28 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-01-05 13:42:43 ----D---- C:\Program Files\Windows Defender
2010-01-05 13:32:02 ----D---- C:\Program Files\Microsoft Silverlight
2010-01-01 12:30:09 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-12-09 23:25:33 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2009-12-09 23:25:19 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-09 23:24:16 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-09 23:23:00 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-09 23:22:46 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2009-11-25 23:19:40 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-11-25 23:19:27 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-11-11 11:34:11 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-10-31 13:22:25 ----SHD---- C:\WINDOWS\ftpcache
2009-10-16 08:07:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-10-16 08:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-10-16 08:03:57 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-10-16 08:02:35 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-10-16 08:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-10-16 08:00:26 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-10-16 07:57:36 ----D---- C:\WINDOWS\SQLTools9_KB970892_ENU
2009-10-16 07:54:14 ----D---- C:\WINDOWS\SQL9_KB970892_ENU
2009-10-16 07:49:07 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-10-16 07:45:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-10-16 07:43:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
======List of files/folders modified in the last 3 months======
2010-01-13 17:39:50 ----D---- C:\WINDOWS\Prefetch
2010-01-13 17:39:22 ----D---- C:\WINDOWS\Temp
2010-01-13 16:37:57 ----SD---- C:\WINDOWS\Tasks
2010-01-13 16:33:43 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-13 16:31:54 ----SHD---- C:\System Volume Information
2010-01-13 16:31:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-13 16:29:39 ----SHD---- C:\WINDOWS\Installer
2010-01-13 16:29:38 ----D---- C:\Program Files\Common Files\Java
2010-01-13 16:27:36 ----D---- C:\WINDOWS\system32
2010-01-13 16:27:06 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-01-13 15:45:33 ----D---- C:\Program Files\Java
2010-01-13 15:42:28 ----D---- C:\WINDOWS
2010-01-13 15:42:27 ----D---- C:\Program Files\Coupons
2010-01-07 10:57:45 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
2010-01-06 14:48:57 ----D---- C:\Program Files\Symantec
2010-01-06 14:48:43 ----A---- C:\WINDOWS\system32\S32EVNT1.DLL
2010-01-06 10:43:17 ----D---- C:\DELL
2010-01-06 10:06:56 ----D---- C:\WINDOWS\Minidump
2010-01-05 19:42:44 ----RD---- C:\Program Files
2010-01-05 17:27:06 ----D---- C:\WINDOWS\system32\drivers
2010-01-05 16:05:02 ----D---- C:\WINDOWS\AppPatch
2010-01-05 15:59:09 ----HD---- C:\WINDOWS\inf
2010-01-05 15:59:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-05 15:58:04 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-05 13:42:43 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-01-05 11:05:09 ----D---- C:\WINDOWS\Help
2010-01-02 12:31:38 ----D---- C:\WINDOWS\system32\CatRoot_bak
2010-01-02 12:31:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-02 12:31:20 ----D---- C:\Program Files\Google
2010-01-01 18:02:26 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-01 17:46:02 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2010-01-01 17:45:13 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-01 17:26:51 ----D---- C:\Documents and Settings
2010-01-01 17:24:17 ----D---- C:\Program Files\Mozilla Firefox
2010-01-01 13:38:29 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-01-01 12:34:07 ----D---- C:\Program Files\Common Files\Adobe
2010-01-01 12:30:09 ----D---- C:\Program Files\Common Files
2009-12-20 14:23:02 ----D---- C:\WINDOWS\network diagnostic
2009-12-10 10:52:38 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-09 23:25:45 ----A---- C:\WINDOWS\imsins.BAK
2009-12-09 23:23:43 ----D---- C:\WINDOWS\system32\en-US
2009-12-09 23:23:42 ----D---- C:\Program Files\Internet Explorer
2009-12-01 14:06:19 ----A---- C:\WINDOWS\system32\MRT.exe
2009-11-25 23:18:20 ----D---- C:\WINDOWS\WinSxS
2009-11-23 13:00:17 ----A---- C:\WINDOWS\NeroDigital.ini
2009-10-29 01:46:59 ----A---- C:\WINDOWS\system32\wininet.dll
2009-10-29 01:46:59 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-10-29 01:46:58 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-10-29 01:46:58 ----A---- C:\WINDOWS\system32\url.dll
2009-10-29 01:46:58 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-10-29 01:46:58 ----A---- C:\WINDOWS\system32\occache.dll
2009-10-29 01:46:58 ----A---- C:\WINDOWS\system32\mstime.dll
2009-10-29 01:46:58 ----A---- C:\WINDOWS\system32\msrating.dll
2009-10-29 01:46:57 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-10-29 01:46:57 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-10-29 01:46:55 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-10-29 01:46:55 ----A---- C:\WINDOWS\system32\msfeeds.dll
2009-10-29 01:46:55 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-10-29 01:46:54 ----A---- C:\WINDOWS\system32\iertutil.dll
2009-10-29 01:46:54 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-10-29 01:46:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-10-29 01:46:52 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-10-29 01:46:52 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-10-29 01:46:51 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2009-10-29 01:46:51 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-10-29 01:46:51 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-10-29 01:46:51 ----A---- C:\WINDOWS\system32\icardie.dll
2009-10-29 01:46:51 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-10-29 01:46:51 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-10-29 01:46:50 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-10-29 01:46:50 ----A---- C:\WINDOWS\system32\corpol.dll
2009-10-29 01:46:50 ----A---- C:\WINDOWS\system32\advpack.dll
2009-10-28 09:07:15 ----A---- C:\WINDOWS\system32\tzchange.exe
2009-10-28 08:36:11 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-10-28 08:36:11 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-10-28 00:52:46 ----A---- C:\WINDOWS\system32\ieakui.dll
2009-10-21 00:00:55 ----A---- C:\WINDOWS\system32\strmfilt.dll
2009-10-21 00:00:55 ----A---- C:\WINDOWS\system32\httpapi.dll
2009-10-16 08:30:13 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-16 08:30:03 ----RSD---- C:\WINDOWS\assembly
2009-10-16 08:00:59 ----D---- C:\WINDOWS\ie7updates
2009-10-16 07:58:26 ----D---- C:\Program Files\Microsoft SQL Server
2009-10-16 07:58:08 ----D---- C:\WINDOWS\Registration
2009-10-16 07:48:13 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2004-10-07 35840]
R1 BHDrvx86;BHDrvx86; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx86.sys []
R1 ccHP;Symantec Hash Provider; C:\WINDOWS\system32\drivers\NIS\1101000.013\ccHPx86.sys [2009-10-20 501888]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 InCDPass;InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [2005-07-08 29696]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-03 36096]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 SRTSP;Symantec Real Time Storage Protection; C:\WINDOWS\System32\Drivers\NIS\1101000.013\SRTSP.SYS [2009-10-08 325168]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\WINDOWS\system32\drivers\NIS\1101000.013\SRTSPX.SYS [2009-10-08 43696]
R1 SymIRON;Symantec Iron Driver; C:\WINDOWS\system32\drivers\NIS\1101000.013\Ironx86.SYS [2009-10-08 114736]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\WINDOWS\system32\drivers\NIS\1101000.013\SYMTDI.SYS [2009-10-14 361520]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-07-20 21361]
R2 Fallback;Fallback; C:\WINDOWS\system32\DRIVERS\fallback.sys [2001-07-18 310899]
R2 Fsks;Fsks; C:\WINDOWS\system32\DRIVERS\fsksnt.sys [2001-07-18 127405]
R2 K56;K56; C:\WINDOWS\system32\DRIVERS\k56nt.sys [2001-07-18 426783]
R2 MCSTRM;MCSTRM; C:\WINDOWS\system32\drivers\MCSTRM.sys [2007-08-28 8413]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 PfModNT;PfModNT; \??\C:\WINDOWS\System32\PfModNT.sys []
R2 SoftFax;SoftFax; C:\WINDOWS\system32\DRIVERS\faxnt.sys [2001-07-18 217019]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\system32\DRIVERS\spkpnt.sys [2001-07-18 80449]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\System32\drivers\symlcbrd.sys []
R2 Tones;Tones; C:\WINDOWS\system32\DRIVERS\tonesnt.sys [2001-07-18 56607]
R2 V124;V124; C:\WINDOWS\system32\DRIVERS\v124nt.sys [2001-07-18 534125]
R3 basic2;basic2; C:\WINDOWS\system32\DRIVERS\basic2.sys [2001-07-18 77426]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2002-04-30 139776]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 IDSxpx86;IDSxpx86; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\IPSDefs\20100106.001\IDSxpx86.sys []
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 NAVENG;NAVENG; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\VirusDefs\20100113.009\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\VirusDefs\20100113.009\NAVEX15.SYS []
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2003-10-06 1550043]
R3 P16X;Creative SB Live! Series (WDM); C:\WINDOWS\system32\drivers\P16X.sys [2002-08-30 1293440]
R3 Rksample;Rksample; C:\WINDOWS\system32\DRIVERS\rksample.sys [2001-07-18 67654]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt2870.sys [2007-07-29 517632]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2009-08-18 36400]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2001-07-25 584336]
R4 InCDfs;InCD File System; C:\WINDOWS\system32\drivers\InCDfs.sys [2005-07-08 99584]
S1 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys []
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys []
S1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys []
S1 incdrm;InCD Reader; C:\WINDOWS\system32\drivers\incdrm.sys [2005-07-08 28672]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2003-09-22 130192]
S3 FVNETusb;Linksys Wireless-B USB Network Adapter v2.8 Driver; C:\WINDOWS\System32\DRIVERS\vnet58lx.sys [2004-03-26 122112]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2007-05-23 26056]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-03-09 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-03-09 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-03-09 21456]
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera; C:\WINDOWS\system32\DRIVERS\mr97310v.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 NMSCFG;NIC Management Service Configuration Driver; \??\C:\WINDOWS\System32\drivers\NMSCFG.SYS []
S3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2003-09-22 178672]
S3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMDNS.SYS []
S3 SYMFW;Symantec Network Filter Driver; C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMFW.SYS []
S3 SYMIDS;Symantec Network Filter Driver; C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMIDS.SYS []
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2009-08-18 36400]
S3 SYMNDIS;Symantec Network Filter Driver; C:\WINDOWS\System32\Drivers\NIS\1007020.00B\SYMNDIS.SYS []
S3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMREDRV.SYS []
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\System32\CTsvcCDA.exe [1999-12-13 44032]
R2 InCDsrv;InCD Helper; C:\Program Files\Ahead\InCD\InCDsrv.exe [2005-07-08 871424]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-01-13 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-20 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 NIS;Norton Internet Security.; C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe [2009-10-20 126392]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2003-10-06 81920]
R2 OpenCASE Media Agent;OpenCASE Media Agent; C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-05 835208]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\System32\MsPMSPSv.exe [2000-06-26 53520]
S2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-28 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMSSvc;Intel(R) NMS; C:\WINDOWS\System32\NMSSvc.exe [2002-05-03 1118208]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2003-03-09 65795]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
I am sending the rest the the info required in a separate reply as I have gone over the 100000 maximum character