Report is below.
Also noticed this forum has just started viewing weird in firefox for me the last 10 minutes. Screenshot to explain it better - the blue colour and whole forum table etc seem missing:
RootRepeal report:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Time: 2009/07/03 03:07
Program Version: Version 1.3.0.0
Windows Version: Windows Vista SP1
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8EFA9000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8EF9E000 Size: 45056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xA283E000 Size: 49152 File Visible: No Signed: -
Status: -
Name: UACxvmylbqnbcxkisi.sys
Image Path: C:\Windows\system32\drivers\UACxvmylbqnbcxkisi.sys
Address: 0x807E0000 Size: 81920 File Visible: - Signed: -
Status: Hidden from Windows API!
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\program files\microsoft windows onecare live\winsssvc_log.bin
Status: Allocation size mismatch (API: 983040, Raw: 458752)
Path: C:\Windows\System32\uacinit.dll
Status: Invisible to the Windows API!
Path: C:\Windows\System32\UACmyeiicusnvwuaet.dll
Status: Invisible to the Windows API!
Path: C:\Windows\System32\UACpwfxombeippvtpo.dll
Status: Invisible to the Windows API!
Path: C:\Windows\System32\UACryrerbwqibfktwr.dll
Status: Invisible to the Windows API!
Path: C:\Windows\System32\UACvugysntfoxrqfpp.dll
Status: Invisible to the Windows API!
Path: C:\Windows\System32\UACvvpeufduseqmsov.dat
Status: Invisible to the Windows API!
Path: C:\Windows\Temp\UAC2fb6.tmp
Status: Invisible to the Windows API!
Path: c:\program files\enigma software group\spyhunter\processguard.dll
Status: Allocation size mismatch (API: 786432, Raw: 0)
Path: C:\Program Files\Windows Media Player\Network Sharing\RENDER~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\Microsoft.NET\Framework\NETFXS~1.HKF
Status: Locked to the Windows API!
Path: C:\Windows\System32\drivers\UACxvmylbqnbcxkisi.sys
Status: Invisible to the Windows API!
Path: C:\Windows\System32\wbem\PORTAB~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\System32\wbem\PORTAB~2.MOF
Status: Locked to the Windows API!
Path: C:\Windows\System32\wbem\PORTAB~3.MOF
Status: Locked to the Windows API!
Path: C:\Windows\System32\wbem\PRINTF~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_abac38a907ee8801.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_10b3ea459bfee365.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d218504d2.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_91949b06671d08ae.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c2866332652.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16789_none_09360999522be962\RENDER~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.20976_none_09c777586b441e5d\RENDER~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18185_none_0b1847174f5614f7\RENDER~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22331_none_0bd3f43c684ec0d7\RENDER~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6000.16830_none_29a6eeebde589a97\PRINTF~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6000.21023_none_2a3e34a2f76b9db7\PRINTF~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6001.18226_none_2b9dff39db71a7a1\PRINTF~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6001.22389_none_2be9bd5af4bd3b16\PRINTF~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.16767_none_48e0ac03ef0db56a\PORTAB~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.16767_none_48e0ac03ef0db56a\PORTAB~2.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.16767_none_48e0ac03ef0db56a\PORTAB~3.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.20941_none_4979e8d10820826f\PORTAB~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.20941_none_4979e8d10820826f\PORTAB~2.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.20941_none_4979e8d10820826f\PORTAB~3.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.18160_none_4abfe8a3ec3a94fa\PORTAB~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.18160_none_4abfe8a3ec3a94fa\PORTAB~2.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.18160_none_4abfe8a3ec3a94fa\PORTAB~3.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.22292_none_4b2b163f056ebb45\PORTAB~1.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.22292_none_4b2b163f056ebb45\PORTAB~2.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.22292_none_4b2b163f056ebb45\PORTAB~3.MOF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.16720_none_9b31bbe79077558b\GROUPE~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6000.16720_none_a54ef540d05f91fc\ASPNET~1.UNI
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6000.20883_none_8e870be4ea01d6ef\ASPNET~1.UNI
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6001.18111_none_a529d9f6d0b19e9d\ASPNET~1.UNI
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6001.22230_none_8e5e4a92ea5717b0\ASPNET~1.UNI
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.20883_none_8469d28baa199a7e\GROUPE~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_defwsdlhlpgen_b03f5f7f11d50a3a_6.0.6000.16720_none_38b929534b68462d\DEFAUL~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_defwsdlhlpgen_b03f5f7f11d50a3a_6.0.6000.20883_none_21f13ff7650a8b20\DEFAUL~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_defwsdlhlpgen_b03f5f7f11d50a3a_6.0.6001.18111_none_38940e094bba52ce\DEFAUL~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_defwsdlhlpgen_b03f5f7f11d50a3a_6.0.6001.22230_none_21c87ea5655fcbe1\DEFAUL~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6000.16720_none_48d018cce81ec9cb\INSTAL~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6000.16720_none_48d018cce81ec9cb\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6000.20883_none_32082f7101c10ebe\INSTAL~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6000.20883_none_32082f7101c10ebe\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6001.18111_none_48aafd82e870d66c\INSTAL~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6001.18111_none_48aafd82e870d66c\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6001.22230_none_31df6e1f02164f7f\INSTAL~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_personalization_sql_b03f5f7f11d50a3a_6.0.6001.22230_none_31df6e1f02164f7f\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_pg_persnlization_sql_b03f5f7f11d50a3a_6.0.6000.16720_none_b898612ecd927be5\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_pg_persnlization_sql_b03f5f7f11d50a3a_6.0.6000.20883_none_a1d077d2e734c0d8\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_pg_persnlization_sql_b03f5f7f11d50a3a_6.0.6001.18111_none_b87345e4cde48886\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_pg_persnlization_sql_b03f5f7f11d50a3a_6.0.6001.22230_none_a1a7b680e78a0199\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.16720_none_7b4eba45cecd6936\IEEXEC~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.20883_none_6486d0e9e86fae29\IEEXEC~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.18111_none_7b299efbcf1f75d7\IEEXEC~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.22230_none_645e0f97e8c4eeea\IEEXEC~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.16720_none_0bca521ee450d037\NETFXS~1.HKF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.20883_none_0c16103ffd9c63ac\NETFXS~1.HKF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.18111_none_0dbc60fae16e5e8e\NETFXS~1.HKF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.22230_none_0e2f5da3fa9d1ce3\NETFXS~1.HKF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_membership_sql_b03f5f7f11d50a3a_6.0.6000.16720_none_6d8c18ba50aebc1f\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_membership_sql_b03f5f7f11d50a3a_6.0.6000.20883_none_56c42f5e6a510112\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_membership_sql_b03f5f7f11d50a3a_6.0.6001.18111_none_6d66fd705100c8c0\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_membership_sql_b03f5f7f11d50a3a_6.0.6001.22230_none_569b6e0c6aa641d3\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6001.18111_none_9b0ca09d90c9622c\GROUPE~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6001.22230_none_84411139aa6edb3f\GROUPE~1.XML
Status: Locked to the Windows API!
Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\ASPNET~1.UNI
Status: Locked to the Windows API!
Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\SYSTEM~1.DLL
Status: Locked to the Windows API!
Path: c:\windows\system32\logfiles\scm\scm.evm
Status: Allocation size mismatch (API: 491520, Raw: 229376)
Path: C:\Users\Kev\AppData\Local\Temp\UAC6e43.tmp
Status: Invisible to the Windows API!
Path: c:\users\kev\appdata\local\temp\etilqs_s5byauchwwsoghwypkde
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: C:\Users\Kev\AppData\Local\Temp\~DF5392.tmp
Status: Invisible to the Windows API!
Path: C:\Users\Kev\AppData\Roaming\Sports Interactive\Installer Launcher
Status: Locked to the Windows API!
Path: C:\Windows\assembly\GAC_32\Policy.1.2.Microsoft.Interop.Security.AzRoles\6.0.6000.16386__31bf3856ad364e35\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!
Path: C:\Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\SYSTEM~1.DLL
Status: Locked to the Windows API!
Path: C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PRESEN~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Locked to the Windows API!
Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Locked to the Windows API!
Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Locked to the Windows API!
Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Locked to the Windows API!
Path: c:\programdata\microsoft\search\data\applications\windows\gatherlogs\systemindex\systemindex.229.crwl
Status: Allocation size mismatch (API: 280, Raw: 8)
Path: c:\programdata\microsoft\search\data\applications\windows\gatherlogs\systemindex\systemindex.229.gthr
Status: Allocation size mismatch (API: 16384, Raw: 288)
Path: c:\users\kev\appdata\local\mozilla\firefox\profiles\1jl9dx14.default\xul.mfl
Status: Allocation size mismatch (API: 2097152, Raw: 0)
Path: C:\Users\Kev\AppData\Local\Mozilla\Firefox\Profiles\1jl9dx14.default\Cache\A8FBC0DBd01
Status: Visible to the Windows API, but not on disk.
Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1268 Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: wininit.exe (PID: 528) Address: 0x009f0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: wininit.exe (PID: 528) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: services.exe (PID: 576) Address: 0x01850000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: services.exe (PID: 576) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: lsass.exe (PID: 588) Address: 0x01870000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: lsass.exe (PID: 588) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: lsm.exe (PID: 604) Address: 0x00e00000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: lsm.exe (PID: 604) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: winlogon.exe (PID: 640) Address: 0x00520000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: winlogon.exe (PID: 640) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 780) Address: 0x008c0000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 780) Address: 0x00990000 Size: 49152
Object: Hidden Module [Name: UACryrerbwqibfktwr.dll]
Process: svchost.exe (PID: 780) Address: 0x00dd0000 Size: 73728
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 780) Address: 0x01dc0000 Size: 45056
Object: Hidden Module [Name: UACpwfxombeippvtpo.dll]
Process: svchost.exe (PID: 780) Address: 0x01fc0000 Size: 200704
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 780) Address: 0x021c0000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 780) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: nvvsvc.exe (PID: 844) Address: 0x00ed0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: nvvsvc.exe (PID: 844) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 908) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 908) Address: 0x006e0000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 908) Address: 0x00de0000 Size: 49152
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: MsMpEng.exe (PID: 1004) Address: 0x00f60000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: MsMpEng.exe (PID: 1004) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 1128) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 1128) Address: 0x00190000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 1128) Address: 0x00a50000 Size: 49152
Object: Hidden Module [Name: WinMgmtR.dll]
Process: svchost.exe (PID: 1128) Address: 0x01bf0000 Size: 8192
Object: Hidden Module [Name: winlogon.exe]
Process: svchost.exe (PID: 1128) Address: 0x02df0000 Size: 323584
Object: Hidden Module [Name: winlogon.exe]
Process: svchost.exe (PID: 1128) Address: 0x02f00000 Size: 323584
Object: Hidden Module [Name: WinMgmtR.dll]
Process: svchost.exe (PID: 1128) Address: 0x6ff40000 Size: 8192
Object: Hidden Module [Name: adtschema.dll]
Process: svchost.exe (PID: 1128) Address: 0x69f40000 Size: 606208
Object: Hidden Module [Name: ci.dll]
Process: svchost.exe (PID: 1128) Address: 0x32f10000 Size: 913408
Object: Hidden Module [Name: wuaueng.dll]
Process: svchost.exe (PID: 1128) Address: 0x6a080000 Size: 1814528
Object: Hidden Module [Name: tquery.dll]
Process: svchost.exe (PID: 1128) Address: 0x700c0000 Size: 1589248
Object: Hidden Module [Name: schedsvc.dll]
Process: svchost.exe (PID: 1128) Address: 0x73130000 Size: 606208
Object: Hidden Module [Name: profsvc.dll]
Process: svchost.exe (PID: 1128) Address: 0x73c60000 Size: 163840
Object: Hidden Module [Name: wevtapi.dll]
Process: svchost.exe (PID: 1128) Address: 0x75620000 Size: 258048
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 1160) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 1160) Address: 0x00650000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 1160) Address: 0x00950000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 1192) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 1192) Address: 0x00640000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 1192) Address: 0x00de0000 Size: 49152
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: SLsvc.exe (PID: 1324) Address: 0x00f70000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: SLsvc.exe (PID: 1324) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 1424) Address: 0x00530000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 1424) Address: 0x00600000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 1424) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: rundll32.exe (PID: 1460) Address: 0x00b10000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: rundll32.exe (PID: 1460) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 1572) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 1572) Address: 0x00520000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 1572) Address: 0x005d0000 Size: 49152
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: spoolsv.exe (PID: 1788) Address: 0x007a0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: spoolsv.exe (PID: 1788) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 1828) Address: 0x001c0000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 1828) Address: 0x00de0000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 1828) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: taskeng.exe (PID: 1032) Address: 0x009d0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: taskeng.exe (PID: 1032) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: Dwm.exe (PID: 1504) Address: 0x00430000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: Dwm.exe (PID: 1504) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: Explorer.EXE (PID: 1720) Address: 0x01ba0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: Explorer.EXE (PID: 1720) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: AppleMobileDeviceService.exe (PID: 1412) Address: 0x009f0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: AppleMobileDeviceService.exe (PID: 1412) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: guard.exe (PID: 1252) Address: 0x00340000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: guard.exe (PID: 1252) Address: 0x00ac0000 Size: 49152
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: mDNSResponder.exe (PID: 1808) Address: 0x00af0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: mDNSResponder.exe (PID: 1808) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 2112) Address: 0x00570000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 2112) Address: 0x00610000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 2112) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: taskeng.exe (PID: 2144) Address: 0x00a50000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: taskeng.exe (PID: 2144) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: OcHealthMon.exe (PID: 2196) Address: 0x00fa0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: OcHealthMon.exe (PID: 2196) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 2464) Address: 0x00240000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 2464) Address: 0x004a0000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 2464) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 2508) Address: 0x007e0000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 2508) Address: 0x01820000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 2508) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: svchost.exe (PID: 2580) Address: 0x004a0000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: svchost.exe (PID: 2580) Address: 0x005c0000 Size: 49152
Object: Hidden Module [Name: UAC2fb6.tmpombeippvtpo.dll]
Process: svchost.exe (PID: 2580) Address: 0x10000000 Size: 200704
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: SearchIndexer.exe (PID: 2688) Address: 0x00e80000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: SearchIndexer.exe (PID: 2688) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: msfwsvc.exe (PID: 2860) Address: 0x009e0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: msfwsvc.exe (PID: 2860) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: winss.exe (PID: 2936) Address: 0x00fc0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: winss.exe (PID: 2936) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: WUDFHost.exe (PID: 3512) Address: 0x00e40000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: WUDFHost.exe (PID: 3512) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: mobsync.exe (PID: 3520) Address: 0x008b0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: mobsync.exe (PID: 3520) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: wmiprvse.exe (PID: 2408) Address: 0x009d0000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: wmiprvse.exe (PID: 2408) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: RtHDVCpl.exe (PID: 2392) Address: 0x01f30000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: RtHDVCpl.exe (PID: 2392) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: winssnotify.exe (PID: 2680) Address: 0x01850000 Size: 49152
Object: Hidden Module [Name: UACvugysntfoxrqfpp.dll]
Process: winssnotify.exe (PID: 2680) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmyeiicusnvwuaet.dll]
Process: rundll32.exe (PID: 864) Address: 0x00e80000 Size: 49152
Object: Hidden Module [NameHidden Services
-------------------
Service Name: UACd.sys
Image Path: C:\Windows\system32\drivers\UACxvmylbqnbcxkisi.sys
==EOF==