Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Whistler rootkit - how to remove


  • This topic is locked This topic is locked
18 replies to this topic

#1 swinka

swinka

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 01 November 2011 - 05:53 AM

Hi

I got some major problems with removing Boo/whistler rootkit. Tried everything ans still no help.

Heres the deal. Avira free says that there is Boo/Whistler virus. I tried everything and still no use. Strange is, that TDsskiller doesn't find anything.
Maybe it's false alarm

Heres my mbrcheck and tdsskiller logs

MBR

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: System manufacturer
System Product Name: System Product Name
Logical Drives Mask: 0x0000003c

Kernel Drivers (total 167):
0x02C06000 \SystemRoot\system32\ntoskrnl.exe
0x031E3000 \SystemRoot\system32\hal.dll
0x00BA0000 \SystemRoot\system32\kdcom.dll
0x00CA9000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x00CB6000 \SystemRoot\system32\PSHED.dll
0x00CCA000 \SystemRoot\system32\CLFS.SYS
0x00D28000 \SystemRoot\system32\CI.dll
0x00C00000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00DE8000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00E2E000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00E85000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00E8E000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00E98000 \SystemRoot\system32\DRIVERS\pci.sys
0x00ECB000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00ED8000 \SystemRoot\System32\drivers\partmgr.sys
0x00EED000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00F02000 \SystemRoot\System32\drivers\volmgrx.sys
0x00F5E000 \SystemRoot\system32\DRIVERS\pciide.sys
0x00F65000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00F75000 \SystemRoot\System32\drivers\mountmgr.sys
0x00F8F000 \SystemRoot\system32\DRIVERS\atapi.sys
0x00F98000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x00FC2000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x010FA000 \SystemRoot\system32\drivers\fltmgr.sys
0x01146000 \SystemRoot\system32\drivers\fileinfo.sys
0x01209000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0115A000 \SystemRoot\System32\Drivers\msrpc.sys
0x013AC000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01000000 \SystemRoot\System32\Drivers\cng.sys
0x013C6000 \SystemRoot\System32\drivers\pcw.sys
0x013D7000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x014E3000 \SystemRoot\system32\drivers\ndis.sys
0x01400000 \SystemRoot\system32\drivers\NETIO.SYS
0x01460000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01603000 \SystemRoot\System32\drivers\tcpip.sys
0x0148B000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01073000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x014D5000 \SystemRoot\System32\Drivers\spldr.sys
0x010BF000 \SystemRoot\System32\drivers\rdyboost.sys
0x015D5000 \SystemRoot\System32\Drivers\mup.sys
0x015E7000 \SystemRoot\System32\drivers\hwpolicy.sys
0x011B8000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x013E1000 \SystemRoot\system32\DRIVERS\disk.sys
0x00FCD000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x015F0000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
0x015F8000 \SystemRoot\System32\DRIVERS\cmderd.sys
0x02A5B000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02A85000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x02B1D000 \SystemRoot\System32\DRIVERS\cmdguard.sys
0x02BAD000 \SystemRoot\System32\Drivers\Null.SYS
0x02BB6000 \SystemRoot\System32\Drivers\Beep.SYS
0x02BBD000 \SystemRoot\System32\drivers\vga.sys
0x02BCB000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x02BF0000 \SystemRoot\System32\drivers\watchdog.sys
0x02A00000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x02A09000 \SystemRoot\system32\drivers\rdpencdd.sys
0x02A12000 \SystemRoot\system32\drivers\rdprefmp.sys
0x02A1B000 \SystemRoot\System32\Drivers\Msfs.SYS
0x02A26000 \SystemRoot\System32\Drivers\Npfs.SYS
0x02A37000 \SystemRoot\system32\DRIVERS\tdx.sys
0x00E1F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x03CA6000 \SystemRoot\System32\DRIVERS\cmdhlp.sys
0x03CB2000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x03CC4000 \SystemRoot\system32\drivers\afd.sys
0x03D4E000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x03D5B000 \SystemRoot\System32\DRIVERS\netbt.sys
0x03DA0000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x03DA9000 \SystemRoot\system32\DRIVERS\pacer.sys
0x03DCF000 \SystemRoot\system32\DRIVERS\inspect.sys
0x03DE7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x03C00000 \SystemRoot\system32\DRIVERS\serial.sys
0x03C1D000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x03C38000 \SystemRoot\system32\DRIVERS\termdd.sys
0x03C4C000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x03E00000 \SystemRoot\system32\drivers\nsiproxy.sys
0x03E0C000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x03E17000 \SystemRoot\System32\drivers\discache.sys
0x03E26000 \SystemRoot\System32\Drivers\dfsc.sys
0x03E44000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x03E55000 \SystemRoot\System32\Drivers\aswSP.SYS
0x03EA5000 \SystemRoot\SysWow64\drivers\AsIO.sys
0x03EAB000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x03ED1000 \SystemRoot\system32\DRIVERS\amdppm.sys
0x03EE6000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x04644000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x05052000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x05146000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0518C000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x051B0000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x051E0000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x051E2000 \SystemRoot\system32\DRIVERS\usbfilter.sys
0x051EF000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x03F37000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04600000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x04611000 \SystemRoot\system32\DRIVERS\serenum.sys
0x0461D000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0x04625000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x03F8D000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x03F9C000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x03FEF000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x040E7000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x040F7000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x0410D000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04131000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x0413D000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x0416C000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04187000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x041A8000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x041C2000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x041D1000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04000000 \SystemRoot\system32\DRIVERS\ks.sys
0x04043000 \SystemRoot\system32\DRIVERS\amdiox64.sys
0x04057000 \SystemRoot\system32\DRIVERS\umbus.sys
0x04069000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x04081000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x041D3000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x06433000 \SystemRoot\system32\drivers\AtihdW76.sys
0x06471000 \SystemRoot\system32\drivers\portcls.sys
0x064AE000 \SystemRoot\system32\drivers\drmk.sys
0x064D0000 \SystemRoot\system32\drivers\ksthunk.sys
0x06605000 \SystemRoot\system32\drivers\viahduaa.sys
0x067B6000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x067C4000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x067DD000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x067E6000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x064D6000 \SystemRoot\System32\Drivers\crashdmp.sys
0x067F3000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x064E4000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x064ED000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x00090000 \SystemRoot\System32\win32k.sys
0x06500000 \SystemRoot\System32\drivers\Dxapi.sys
0x0650C000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00540000 \SystemRoot\System32\TSDDD.dll
0x00610000 \SystemRoot\System32\cdd.dll
0x0651A000 \SystemRoot\system32\drivers\luafv.sys
0x0653D000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x06577000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x06580000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x06595000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x06884000 \SystemRoot\system32\drivers\HTTP.sys
0x0694C000 \SystemRoot\system32\DRIVERS\bowser.sys
0x0696A000 \SystemRoot\System32\drivers\mpsdrv.sys
0x06982000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x069AE000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x06800000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x06823000 \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
0x078F0000 \SystemRoot\system32\drivers\peauth.sys
0x07996000 \SystemRoot\System32\Drivers\secdrv.SYS
0x079A1000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x079CE000 \SystemRoot\System32\drivers\tcpipreg.sys
0x07800000 \SystemRoot\System32\DRIVERS\srv2.sys
0x086EC000 \SystemRoot\System32\DRIVERS\srv.sys
0x779C0000 \Windows\System32\ntdll.dll
0x48260000 \Windows\System32\smss.exe
0xFFCE0000 \Windows\System32\apisetschema.dll
0xFFBE0000 \Windows\System32\autochk.exe
0xFFC30000 \Windows\System32\msvcrt.dll
0xFFA50000 \Windows\System32\setupapi.dll
0x77B90000 \Windows\System32\normaliz.dll
0xFF970000 \Windows\System32\advapi32.dll
0xFF920000 \Windows\System32\Wldap32.dll
0xFF840000 \Windows\System32\oleaut32.dll
0x77B80000 \Windows\System32\psapi.dll
0xFF7D0000 \Windows\System32\gdi32.dll
0xFF6A0000 \Windows\System32\wininet.dll
0xFE910000 \Windows\System32\shell32.dll
0xFE870000 \Windows\System32\comdlg32.dll

Processes (total 56):
0 System Idle Process
4 System
364 C:\Windows\System32\smss.exe
468 csrss.exe
544 C:\Windows\System32\wininit.exe
568 csrss.exe
616 C:\Windows\System32\services.exe
636 C:\Windows\System32\lsass.exe
644 C:\Windows\System32\lsm.exe
720 C:\Windows\System32\winlogon.exe
820 C:\Windows\System32\svchost.exe
900 C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
928 C:\Windows\System32\svchost.exe
1004 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
460 C:\Windows\System32\svchost.exe
572 C:\Windows\System32\atiesrxx.exe
732 C:\Windows\System32\svchost.exe
1032 C:\Windows\System32\svchost.exe
1072 C:\Windows\System32\svchost.exe
1136 C:\Windows\System32\audiodg.exe
1176 C:\Windows\System32\svchost.exe
1320 C:\Windows\System32\atieclxx.exe
1340 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1468 C:\Windows\System32\dwm.exe
1492 C:\Windows\explorer.exe
1820 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
1892 C:\Windows\System32\spoolsv.exe
1904 C:\Windows\System32\taskhost.exe
1940 C:\Windows\System32\svchost.exe
1236 C:\Windows\System32\taskeng.exe
1580 C:\Program Files (x86)\Gadu-Gadu 10\gg.exe
1252 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
2052 C:\Windows\DAODx.exe
2064 C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
2368 C:\Windows\SysWOW64\PnkBstrA.exe
2392 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2448 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2708 C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
2808 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
3000 C:\Windows\System32\svchost.exe
2188 C:\Windows\System32\SearchIndexer.exe
2704 C:\Windows\System32\svchost.exe
3208 C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
3360 C:\Program Files (x86)\ASUS\EPU\EPU.exe
3368 C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
3376 C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe
3408 C:\Program Files\AVAST Software\Avast\AvastUI.exe
3580 WmiPrvSE.exe
3688 C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
3696 C:\Program Files\COMODO\COMODO GeekBuddy\CLPS.exe
3724 C:\Program Files\COMODO\COMODO GeekBuddy\Cpa_VA.exe
3856 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
1440 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
3536 C:\Users\Hateful\Desktop\MBRCheck.exe
2400 C:\Windows\System32\conhost.exe
2076 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: --> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x0000000d`6d900000 (NTFS)

PhysicalDrive0 Model Number: ST3250620AS, Rev: 3.AAE
PhysicalDrive1 Model Number: ST3160811AS, Rev: 3.AAE

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
149 GB \\.\PhysicalDrive1 Unknown MBR code
SHA1: 2112DEB97137CBCC5710EFED18ADC8F308731CFF


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!


TDSS
09:05:34.0462 0800 TDSS rootkit removing tool 2.6.14.0 Oct 28 2011 11:11:01
09:05:34.0875 0800 ============================================================
09:05:34.0875 0800 Current date / time: 2011/10/31 09:05:34.0875
09:05:34.0875 0800 SystemInfo:
09:05:34.0875 0800
09:05:34.0875 0800 OS Version: 6.1.7600 ServicePack: 0.0
09:05:34.0875 0800 Product type: Workstation
09:05:34.0875 0800 ComputerName: DOM
09:05:34.0876 0800 UserName: Hateful
09:05:34.0876 0800 Windows directory: C:\Windows
09:05:34.0876 0800 System windows directory: C:\Windows
09:05:34.0876 0800 Running under WOW64
09:05:34.0876 0800 Processor architecture: Intel x64
09:05:34.0876 0800 Number of processors: 4
09:05:34.0876 0800 Page size: 0x1000
09:05:34.0876 0800 Boot type: Normal boot
09:05:34.0876 0800 ============================================================
09:05:35.0574 0800 Initialize success
09:05:38.0286 0700 ============================================================
09:05:38.0286 0700 Scan started
09:05:38.0286 0700 Mode: Manual;
09:05:38.0286 0700 ============================================================
09:05:38.0846 0700 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
09:05:38.0850 0700 1394ohci - ok
09:05:39.0139 0700 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
09:05:39.0145 0700 ACPI - ok
09:05:39.0452 0700 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
09:05:39.0454 0700 AcpiPmi - ok
09:05:39.0746 0700 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
09:05:39.0754 0700 adp94xx - ok
09:05:40.0045 0700 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
09:05:40.0051 0700 adpahci - ok
09:05:40.0330 0700 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
09:05:40.0334 0700 adpu320 - ok
09:05:40.0946 0700 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
09:05:40.0955 0700 AFD - ok
09:05:41.0311 0700 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
09:05:41.0313 0700 agp440 - ok
09:05:41.0586 0700 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
09:05:41.0587 0700 aliide - ok
09:05:41.0878 0700 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
09:05:41.0879 0700 amdide - ok
09:05:42.0145 0700 amdiox64 (6a2eeb0c4133b20773bb3dd0b7b377b4) C:\Windows\system32\DRIVERS\amdiox64.sys
09:05:42.0147 0700 amdiox64 - ok
09:05:42.0422 0700 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
09:05:42.0424 0700 AmdK8 - ok
09:05:42.0935 0700 amdkmdag (446a1aad34191665a8df6092bd8eb5a8) C:\Windows\system32\DRIVERS\atikmdag.sys
09:05:42.0982 0700 amdkmdag - ok
09:05:43.0313 0700 amdkmdap (f8f8a908fdb005a65ddf7238c814eea5) C:\Windows\system32\DRIVERS\atikmpag.sys
09:05:43.0318 0700 amdkmdap - ok
09:05:43.0598 0700 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
09:05:43.0600 0700 AmdPPM - ok
09:05:43.0884 0700 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
09:05:43.0887 0700 amdsata - ok
09:05:44.0184 0700 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
09:05:44.0188 0700 amdsbs - ok
09:05:44.0474 0700 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
09:05:44.0476 0700 amdxata - ok
09:05:44.0553 0700 AODDriver4.0 (f312fad7dbd49ed21a194ac71b497832) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
09:05:44.0555 0700 AODDriver4.0 - ok
09:05:44.0570 0700 AODDriver4.01 (f312fad7dbd49ed21a194ac71b497832) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
09:05:44.0572 0700 AODDriver4.01 - ok
09:05:44.0893 0700 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
09:05:44.0895 0700 AppID - ok
09:05:45.0203 0700 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
09:05:45.0205 0700 arc - ok
09:05:45.0490 0700 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
09:05:45.0492 0700 arcsas - ok
09:05:45.0505 0700 AsIO - ok
09:05:45.0777 0700 aswFsBlk (5a68b880c16ad5a6aa20b49a47ffff24) C:\Windows\system32\drivers\aswFsBlk.sys
09:05:45.0779 0700 aswFsBlk - ok
09:05:46.0070 0700 aswMonFlt (230613be2d3da8053879be5ed2848f2d) C:\Windows\system32\drivers\aswMonFlt.sys
09:05:46.0073 0700 aswMonFlt - ok
09:05:46.0359 0700 aswRdr (0dc1996ae4178d7d14744ef6b3082313) C:\Windows\system32\drivers\aswRdr.sys
09:05:46.0361 0700 aswRdr - ok
09:05:46.0650 0700 aswSnx (b6ff911c23775cdfdd49612d92637af4) C:\Windows\system32\drivers\aswSnx.sys
09:05:46.0660 0700 aswSnx - ok
09:05:46.0945 0700 aswSP (5a590d8516376aed1829fc07d3bdaa4b) C:\Windows\system32\drivers\aswSP.sys
09:05:46.0951 0700 aswSP - ok
09:05:47.0223 0700 aswTdi (3239c0082fb0c1c4ee323730b85690a5) C:\Windows\system32\drivers\aswTdi.sys
09:05:47.0225 0700 aswTdi - ok
09:05:47.0497 0700 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
09:05:47.0499 0700 AsyncMac - ok
09:05:47.0772 0700 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
09:05:47.0774 0700 atapi - ok
09:05:48.0062 0700 AtiHDAudioService (dbb487d09f56c674430ac454fd8bcab9) C:\Windows\system32\drivers\AtihdW76.sys
09:05:48.0067 0700 AtiHDAudioService - ok
09:05:48.0353 0700 AtiPcie (7c5d273e29dcc5505469b299c6f29163) C:\Windows\system32\DRIVERS\AtiPcie.sys
09:05:48.0355 0700 AtiPcie - ok
09:05:48.0666 0700 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
09:05:48.0670 0700 b06bdrv - ok
09:05:48.0953 0700 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
09:05:48.0958 0700 b57nd60a - ok
09:05:49.0275 0700 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
09:05:49.0276 0700 Beep - ok
09:05:49.0560 0700 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
09:05:49.0562 0700 blbdrive - ok
09:05:49.0828 0700 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys
09:05:49.0831 0700 bowser - ok
09:05:50.0094 0700 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
09:05:50.0096 0700 BrFiltLo - ok
09:05:50.0352 0700 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
09:05:50.0354 0700 BrFiltUp - ok
09:05:50.0624 0700 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
09:05:50.0629 0700 Brserid - ok
09:05:50.0907 0700 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
09:05:50.0909 0700 BrSerWdm - ok
09:05:51.0182 0700 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
09:05:51.0183 0700 BrUsbMdm - ok
09:05:51.0440 0700 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
09:05:51.0442 0700 BrUsbSer - ok
09:05:51.0693 0700 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
09:05:51.0695 0700 BTHMODEM - ok
09:05:51.0973 0700 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
09:05:51.0976 0700 cdfs - ok
09:05:52.0262 0700 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
09:05:52.0265 0700 cdrom - ok
09:05:52.0545 0700 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
09:05:52.0547 0700 circlass - ok
09:05:52.0757 0700 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
09:05:52.0764 0700 CLFS - ok
09:05:53.0072 0700 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
09:05:53.0074 0700 CmBatt - ok
09:05:53.0356 0700 cmderd (67c7a415e487dfb26d029838f568ef80) C:\Windows\system32\DRIVERS\cmderd.sys
09:05:53.0358 0700 cmderd - ok
09:05:53.0637 0700 cmdGuard (f81457b43f083e0ff8eacae720f0537b) C:\Windows\system32\DRIVERS\cmdguard.sys
09:05:53.0646 0700 cmdGuard - ok
09:05:53.0906 0700 cmdHlp (0091563e864c5d750771919ea8900763) C:\Windows\system32\DRIVERS\cmdhlp.sys
09:05:53.0908 0700 cmdHlp - ok
09:05:54.0247 0700 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
09:05:54.0248 0700 cmdide - ok
09:05:54.0648 0700 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
09:05:54.0656 0700 CNG - ok
09:05:54.0927 0700 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
09:05:54.0929 0700 Compbatt - ok
09:05:55.0203 0700 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
09:05:55.0205 0700 CompositeBus - ok
09:05:55.0504 0700 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
09:05:55.0505 0700 crcdisk - ok
09:05:55.0823 0700 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
09:05:55.0826 0700 DfsC - ok
09:05:56.0607 0700 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
09:05:56.0609 0700 discache - ok
09:05:56.0893 0700 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
09:05:56.0896 0700 Disk - ok
09:05:57.0376 0700 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
09:05:57.0377 0700 drmkaud - ok
09:05:57.0819 0700 DXGKrnl (7cb7d2b73813ce05c7bc0f5f95d27cec) C:\Windows\System32\drivers\dxgkrnl.sys
09:05:57.0827 0700 DXGKrnl - ok
09:05:58.0288 0700 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
09:05:58.0307 0700 ebdrv - ok
09:05:58.0623 0700 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
09:05:58.0632 0700 elxstor - ok
09:05:58.0908 0700 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
09:05:58.0910 0700 ErrDev - ok
09:05:59.0224 0700 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
09:05:59.0228 0700 exfat - ok
09:05:59.0530 0700 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
09:05:59.0534 0700 fastfat - ok
09:05:59.0829 0700 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
09:05:59.0831 0700 fdc - ok
09:06:00.0131 0700 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
09:06:00.0134 0700 FileInfo - ok
09:06:00.0398 0700 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
09:06:00.0400 0700 Filetrace - ok
09:06:00.0665 0700 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
09:06:00.0667 0700 flpydisk - ok
09:06:00.0951 0700 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
09:06:00.0956 0700 FltMgr - ok
09:06:01.0232 0700 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
09:06:01.0235 0700 FsDepends - ok
09:06:01.0499 0700 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
09:06:01.0501 0700 Fs_Rec - ok
09:06:01.0796 0700 fvevol (b8b2a6e1558f8f5de5ce431c5b2c7b09) C:\Windows\system32\DRIVERS\fvevol.sys
09:06:01.0800 0700 fvevol - ok
09:06:02.0070 0700 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
09:06:02.0072 0700 gagp30kx - ok
09:06:02.0462 0700 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
09:06:02.0464 0700 hcw85cir - ok
09:06:02.0956 0700 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
09:06:02.0963 0700 HdAudAddService - ok
09:06:03.0242 0700 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
09:06:03.0245 0700 HDAudBus - ok
09:06:03.0532 0700 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
09:06:03.0534 0700 HidBatt - ok
09:06:03.0802 0700 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
09:06:03.0806 0700 HidBth - ok
09:06:04.0071 0700 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
09:06:04.0073 0700 HidIr - ok
09:06:04.0365 0700 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
09:06:04.0367 0700 HidUsb - ok
09:06:04.0668 0700 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
09:06:04.0670 0700 HpSAMD - ok
09:06:04.0961 0700 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
09:06:04.0973 0700 HTTP - ok
09:06:05.0243 0700 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
09:06:05.0245 0700 hwpolicy - ok
09:06:05.0538 0700 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
09:06:05.0542 0700 i8042prt - ok
09:06:05.0828 0700 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
09:06:05.0835 0700 iaStorV - ok
09:06:06.0115 0700 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
09:06:06.0117 0700 iirsp - ok
09:06:06.0401 0700 inspect (db2ce341c290292f60c6bb13b7a1d84e) C:\Windows\system32\DRIVERS\inspect.sys
09:06:06.0404 0700 inspect - ok
09:06:06.0674 0700 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
09:06:06.0676 0700 intelide - ok
09:06:06.0961 0700 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
09:06:06.0963 0700 intelppm - ok
09:06:07.0245 0700 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
09:06:07.0248 0700 IpFilterDriver - ok
09:06:07.0513 0700 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
09:06:07.0516 0700 IPMIDRV - ok
09:06:07.0798 0700 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
09:06:07.0802 0700 IPNAT - ok
09:06:08.0082 0700 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
09:06:08.0084 0700 IRENUM - ok
09:06:08.0383 0700 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
09:06:08.0385 0700 isapnp - ok
09:06:08.0660 0700 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
09:06:08.0662 0700 iScsiPrt - ok
09:06:08.0674 0700 Scan interrupted by user!
09:06:08.0674 0700 Scan interrupted by user!
09:06:08.0674 0700 Scan interrupted by user!
09:06:08.0674 0700 ============================================================
09:06:08.0674 0700 Scan finished
09:06:08.0674 0700 ============================================================
09:06:08.0687 4588 Detected object count: 0
09:06:08.0687 4588 Actual detected object count: 0
09:06:12.0501 2156 ============================================================
09:06:12.0501 2156 Scan started
09:06:12.0501 2156 Mode: Manual;
09:06:12.0502 2156 ============================================================
09:06:12.0915 2156 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
09:06:12.0920 2156 1394ohci - ok
09:06:13.0200 2156 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
09:06:13.0206 2156 ACPI - ok
09:06:13.0463 2156 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
09:06:13.0465 2156 AcpiPmi - ok
09:06:13.0907 2156 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
09:06:13.0915 2156 adp94xx - ok
09:06:14.0197 2156 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
09:06:14.0203 2156 adpahci - ok
09:06:14.0483 2156 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
09:06:14.0487 2156 adpu320 - ok
09:06:14.0771 2156 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
09:06:14.0775 2156 AFD - ok
09:06:15.0038 2156 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
09:06:15.0039 2156 agp440 - ok
09:06:15.0305 2156 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
09:06:15.0306 2156 aliide - ok
09:06:15.0580 2156 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
09:06:15.0582 2156 amdide - ok
09:06:15.0855 2156 amdiox64 (6a2eeb0c4133b20773bb3dd0b7b377b4) C:\Windows\system32\DRIVERS\amdiox64.sys
09:06:15.0857 2156 amdiox64 - ok
09:06:16.0115 2156 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
09:06:16.0117 2156 AmdK8 - ok
09:06:16.0626 2156 amdkmdag (446a1aad34191665a8df6092bd8eb5a8) C:\Windows\system32\DRIVERS\atikmdag.sys
09:06:16.0679 2156 amdkmdag - ok
09:06:17.0132 2156 amdkmdap (f8f8a908fdb005a65ddf7238c814eea5) C:\Windows\system32\DRIVERS\atikmpag.sys
09:06:17.0137 2156 amdkmdap - ok
09:06:17.0483 2156 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
09:06:17.0484 2156 AmdPPM - ok
09:06:17.0753 2156 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
09:06:17.0756 2156 amdsata - ok
09:06:18.0036 2156 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
09:06:18.0038 2156 amdsbs - ok
09:06:18.0318 2156 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
09:06:18.0320 2156 amdxata - ok
09:06:18.0397 2156 AODDriver4.0 (f312fad7dbd49ed21a194ac71b497832) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
09:06:18.0399 2156 AODDriver4.0 - ok
09:06:18.0409 2156 AODDriver4.01 (f312fad7dbd49ed21a194ac71b497832) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
09:06:18.0411 2156 AODDriver4.01 - ok
09:06:18.0695 2156 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
09:06:18.0697 2156 AppID - ok
09:06:19.0031 2156 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
09:06:19.0033 2156 arc - ok
09:06:19.0292 2156 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
09:06:19.0295 2156 arcsas - ok
09:06:19.0299 2156 AsIO - ok
09:06:19.0580 2156 aswFsBlk (5a68b880c16ad5a6aa20b49a47ffff24) C:\Windows\system32\drivers\aswFsBlk.sys
09:06:19.0581 2156 aswFsBlk - ok
09:06:19.0856 2156 aswMonFlt (230613be2d3da8053879be5ed2848f2d) C:\Windows\system32\drivers\aswMonFlt.sys
09:06:19.0858 2156 aswMonFlt - ok
09:06:20.0128 2156 aswRdr (0dc1996ae4178d7d14744ef6b3082313) C:\Windows\system32\drivers\aswRdr.sys
09:06:20.0130 2156 aswRdr - ok
09:06:20.0411 2156 aswSnx (b6ff911c23775cdfdd49612d92637af4) C:\Windows\system32\drivers\aswSnx.sys
09:06:20.0421 2156 aswSnx - ok
09:06:20.0723 2156 aswSP (5a590d8516376aed1829fc07d3bdaa4b) C:\Windows\system32\drivers\aswSP.sys
09:06:20.0728 2156 aswSP - ok
09:06:21.0017 2156 aswTdi (3239c0082fb0c1c4ee323730b85690a5) C:\Windows\system32\drivers\aswTdi.sys
09:06:21.0020 2156 aswTdi - ok
09:06:21.0299 2156 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
09:06:21.0301 2156 AsyncMac - ok
09:06:21.0558 2156 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
09:06:21.0560 2156 atapi - ok
09:06:21.0840 2156 AtiHDAudioService (dbb487d09f56c674430ac454fd8bcab9) C:\Windows\system32\drivers\AtihdW76.sys
09:06:21.0844 2156 AtiHDAudioService - ok
09:06:22.0114 2156 AtiPcie (7c5d273e29dcc5505469b299c6f29163) C:\Windows\system32\DRIVERS\AtiPcie.sys
09:06:22.0116 2156 AtiPcie - ok
09:06:22.0421 2156 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
09:06:22.0429 2156 b06bdrv - ok
09:06:22.0697 2156 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
09:06:22.0702 2156 b57nd60a - ok
09:06:22.0969 2156 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
09:06:22.0971 2156 Beep - ok
09:06:23.0246 2156 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
09:06:23.0248 2156 blbdrive - ok
09:06:23.0505 2156 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys
09:06:23.0508 2156 bowser - ok
09:06:23.0780 2156 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
09:06:23.0782 2156 BrFiltLo - ok
09:06:24.0047 2156 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
09:06:24.0048 2156 BrFiltUp - ok
09:06:24.0326 2156 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
09:06:24.0332 2156 Brserid - ok
09:06:24.0593 2156 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
09:06:24.0595 2156 BrSerWdm - ok
09:06:24.0859 2156 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
09:06:24.0861 2156 BrUsbMdm - ok
09:06:25.0134 2156 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
09:06:25.0136 2156 BrUsbSer - ok
09:06:25.0395 2156 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
09:06:25.0397 2156 BTHMODEM - ok
09:06:25.0676 2156 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
09:06:25.0679 2156 cdfs - ok
09:06:25.0948 2156 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
09:06:25.0951 2156 cdrom - ok
09:06:26.0231 2156 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
09:06:26.0233 2156 circlass - ok
09:06:26.0443 2156 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
09:06:26.0451 2156 CLFS - ok
09:06:26.0733 2156 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
09:06:26.0735 2156 CmBatt - ok
09:06:27.0025 2156 cmderd (67c7a415e487dfb26d029838f568ef80) C:\Windows\system32\DRIVERS\cmderd.sys
09:06:27.0027 2156 cmderd - ok
09:06:27.0306 2156 cmdGuard (f81457b43f083e0ff8eacae720f0537b) C:\Windows\system32\DRIVERS\cmdguard.sys
09:06:27.0316 2156 cmdGuard - ok
09:06:27.0584 2156 cmdHlp (0091563e864c5d750771919ea8900763) C:\Windows\system32\DRIVERS\cmdhlp.sys
09:06:27.0586 2156 cmdHlp - ok
09:06:27.0858 2156 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
09:06:27.0859 2156 cmdide - ok
09:06:28.0209 2156 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
09:06:28.0217 2156 CNG - ok
09:06:28.0904 2156 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
09:06:28.0906 2156 Compbatt - ok
09:06:29.0189 2156 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
09:06:29.0191 2156 CompositeBus - ok
09:06:29.0481 2156 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
09:06:29.0483 2156 crcdisk - ok
09:06:29.0793 2156 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
09:06:29.0795 2156 DfsC - ok
09:06:30.0076 2156 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
09:06:30.0078 2156 discache - ok
09:06:30.0338 2156 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
09:06:30.0340 2156 Disk - ok
09:06:30.0620 2156 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
09:06:30.0622 2156 drmkaud - ok
09:06:30.0909 2156 DXGKrnl (7cb7d2b73813ce05c7bc0f5f95d27cec) C:\Windows\System32\drivers\dxgkrnl.sys
09:06:30.0925 2156 DXGKrnl - ok
09:06:31.0380 2156 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
09:06:31.0407 2156 ebdrv - ok
09:06:31.0701 2156 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
09:06:31.0710 2156 elxstor - ok
09:06:31.0986 2156 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
09:06:31.0986 2156 ErrDev - ok
09:06:32.0260 2156 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
09:06:32.0264 2156 exfat - ok
09:06:32.0549 2156 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
09:06:32.0554 2156 fastfat - ok
09:06:32.0823 2156 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
09:06:32.0825 2156 fdc - ok
09:06:33.0116 2156 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
09:06:33.0119 2156 FileInfo - ok
09:06:33.0391 2156 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
09:06:33.0392 2156 Filetrace - ok
09:06:33.0658 2156 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
09:06:33.0660 2156 flpydisk - ok
09:06:33.0944 2156 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
09:06:33.0950 2156 FltMgr - ok
09:06:34.0218 2156 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
09:06:34.0220 2156 FsDepends - ok
09:06:34.0484 2156 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
09:06:34.0486 2156 Fs_Rec - ok
09:06:34.0748 2156 fvevol (b8b2a6e1558f8f5de5ce431c5b2c7b09) C:\Windows\system32\DRIVERS\fvevol.sys
09:06:34.0753 2156 fvevol - ok
09:06:35.0014 2156 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
09:06:35.0017 2156 gagp30kx - ok
09:06:35.0281 2156 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
09:06:35.0283 2156 hcw85cir - ok
09:06:35.0568 2156 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
09:06:35.0574 2156 HdAudAddService - ok
09:06:35.0836 2156 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
09:06:35.0839 2156 HDAudBus - ok
09:06:36.0102 2156 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
09:06:36.0104 2156 HidBatt - ok
09:06:36.0372 2156 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
09:06:36.0375 2156 HidBth - ok
09:06:36.0807 2156 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
09:06:36.0809 2156 HidIr - ok
09:06:37.0076 2156 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
09:06:37.0078 2156 HidUsb - ok
09:06:37.0362 2156 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
09:06:37.0365 2156 HpSAMD - ok
09:06:37.0655 2156 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
09:06:37.0662 2156 HTTP - ok
09:06:37.0938 2156 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
09:06:37.0940 2156 hwpolicy - ok
09:06:38.0225 2156 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
09:06:38.0228 2156 i8042prt - ok
09:06:38.0522 2156 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
09:06:38.0530 2156 iaStorV - ok
09:06:38.0802 2156 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
09:06:38.0804 2156 iirsp - ok
09:06:39.0088 2156 inspect (db2ce341c290292f60c6bb13b7a1d84e) C:\Windows\system32\DRIVERS\inspect.sys
09:06:39.0090 2156 inspect - ok
09:06:39.0360 2156 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
09:06:39.0362 2156 intelide - ok
09:06:39.0647 2156 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
09:06:39.0649 2156 intelppm - ok
09:06:39.0948 2156 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
09:06:39.0951 2156 IpFilterDriver - ok
09:06:40.0225 2156 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
09:06:40.0228 2156 IPMIDRV - ok
09:06:40.0493 2156 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
09:06:40.0496 2156 IPNAT - ok
09:06:40.0768 2156 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
09:06:40.0771 2156 IRENUM - ok
09:06:41.0052 2156 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
09:06:41.0054 2156 isapnp - ok
09:06:41.0331 2156 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
09:06:41.0335 2156 iScsiPrt - ok
09:06:41.0605 2156 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
09:06:41.0607 2156 kbdclass - ok
09:06:42.0064 2156 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
09:06:42.0066 2156 kbdhid - ok
09:06:42.0348 2156 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
09:06:42.0351 2156 KSecDD - ok
09:06:42.0611 2156 KSecPkg (bbe1bf6d9b661c354d4857d5fadb943b) C:\Windows\system32\Drivers\ksecpkg.sys
09:06:42.0615 2156 KSecPkg - ok
09:06:42.0909 2156 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
09:06:42.0912 2156 ksthunk - ok
09:06:43.0244 2156 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
09:06:43.0246 2156 lltdio - ok
09:06:43.0557 2156 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
09:06:43.0560 2156 LSI_FC - ok
09:06:43.0842 2156 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
09:06:43.0845 2156 LSI_SAS - ok
09:06:44.0135 2156 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
09:06:44.0137 2156 LSI_SAS2 - ok
09:06:44.0413 2156 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
09:06:44.0416 2156 LSI_SCSI - ok
09:06:44.0700 2156 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
09:06:44.0703 2156 luafv - ok
09:06:45.0000 2156 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
09:06:45.0002 2156 megasas - ok
09:06:45.0275 2156 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
09:06:45.0278 2156 MegaSR - ok
09:06:45.0558 2156 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
09:06:45.0561 2156 Modem - ok
09:06:45.0851 2156 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
09:06:45.0853 2156 monitor - ok
09:06:46.0136 2156 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
09:06:46.0138 2156 mouclass - ok
09:06:46.0428 2156 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
09:06:46.0430 2156 mouhid - ok
09:06:46.0714 2156 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
09:06:46.0717 2156 mountmgr - ok
09:06:46.0994 2156 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
09:06:46.0998 2156 mpio - ok
09:06:47.0270 2156 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
09:06:47.0273 2156 mpsdrv - ok
09:06:47.0547 2156 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
09:06:47.0551 2156 MRxDAV - ok
09:06:47.0819 2156 mrxsmb (cfdcd8ca87c2a657debc150ac35b5e08) C:\Windows\system32\DRIVERS\mrxsmb.sys
09:06:47.0823 2156 mrxsmb - ok
09:06:48.0099 2156 mrxsmb10 (1bee517b220b7f024f411aec1571dd5a) C:\Windows\system32\DRIVERS\mrxsmb10.sys
09:06:48.0104 2156 mrxsmb10 - ok
09:06:48.0373 2156 mrxsmb20 (6b2d5fef385828b6e485c1c90afb8195) C:\Windows\system32\DRIVERS\mrxsmb20.sys
09:06:48.0377 2156 mrxsmb20 - ok
09:06:48.0656 2156 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
09:06:48.0658 2156 msahci - ok
09:06:48.0953 2156 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
09:06:48.0957 2156 msdsm - ok
09:06:49.0219 2156 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
09:06:49.0221 2156 Msfs - ok
09:06:49.0485 2156 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
09:06:49.0488 2156 mshidkmdf - ok
09:06:49.0752 2156 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
09:06:49.0754 2156 msisadrv - ok
09:06:50.0049 2156 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
09:06:50.0051 2156 MSKSSRV - ok
09:06:50.0324 2156 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
09:06:50.0326 2156 MSPCLOCK - ok
09:06:50.0599 2156 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
09:06:50.0601 2156 MSPQM - ok
09:06:50.0872 2156 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
09:06:50.0879 2156 MsRPC - ok
09:06:51.0153 2156 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
09:06:51.0155 2156 mssmbios - ok
09:06:51.0436 2156 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
09:06:51.0438 2156 MSTEE - ok
09:06:51.0711 2156 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
09:06:51.0713 2156 MTConfig - ok
09:06:52.0001 2156 MTsensor (19b006b181e3875fd254f7b67acf1e7c) C:\Windows\system32\DRIVERS\ASACPI.sys
09:06:52.0002 2156 MTsensor - ok
09:06:52.0289 2156 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
09:06:52.0292 2156 Mup - ok
09:06:52.0606 2156 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
09:06:52.0612 2156 NativeWifiP - ok
09:06:52.0915 2156 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
09:06:52.0931 2156 NDIS - ok
09:06:53.0221 2156 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
09:06:53.0223 2156 NdisCap - ok
09:06:53.0496 2156 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
09:06:53.0499 2156 NdisTapi - ok
09:06:53.0774 2156 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
09:06:53.0776 2156 Ndisuio - ok
09:06:54.0062 2156 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
09:06:54.0066 2156 NdisWan - ok
09:06:54.0337 2156 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
09:06:54.0340 2156 NDProxy - ok
09:06:54.0613 2156 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
09:06:54.0615 2156 NetBIOS - ok
09:06:54.0897 2156 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
09:06:54.0903 2156 NetBT - ok
09:06:55.0214 2156 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
09:06:55.0217 2156 nfrd960 - ok
09:06:55.0498 2156 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
09:06:55.0501 2156 Npfs - ok
09:06:55.0799 2156 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
09:06:55.0801 2156 nsiproxy - ok
09:06:56.0121 2156 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
09:06:56.0140 2156 Ntfs - ok
09:06:56.0401 2156 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
09:06:56.0403 2156 Null - ok
09:06:56.0691 2156 nusb3hub (285acec1b13a15ba520aae06bacb9cff) C:\Windows\system32\DRIVERS\nusb3hub.sys
09:06:56.0694 2156 nusb3hub - ok
09:06:56.0961 2156 nusb3xhc (f6d625ff7b56bb6ea063f0d3a5bbc996) C:\Windows\system32\DRIVERS\nusb3xhc.sys
09:06:56.0965 2156 nusb3xhc - ok
09:06:57.0239 2156 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
09:06:57.0243 2156 nvraid - ok
09:06:57.0527 2156 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
09:06:57.0531 2156 nvstor - ok
09:06:57.0821 2156 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
09:06:57.0825 2156 nv_agp - ok
09:06:58.0102 2156 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
09:06:58.0105 2156 ohci1394 - ok
09:06:58.0416 2156 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
09:06:58.0419 2156 Parport - ok
09:06:58.0952 2156 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
09:06:58.0955 2156 partmgr - ok
09:06:59.0249 2156 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
09:06:59.0253 2156 pci - ok
09:06:59.0547 2156 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
09:06:59.0549 2156 pciide - ok
09:06:59.0824 2156 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
09:06:59.0828 2156 pcmcia - ok
09:07:00.0098 2156 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
09:07:00.0100 2156 pcw - ok
09:07:00.0388 2156 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
09:07:00.0399 2156 PEAUTH - ok
09:07:00.0754 2156 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
09:07:00.0758 2156 PptpMiniport - ok
09:07:01.0032 2156 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
09:07:01.0035 2156 Processor - ok
09:07:01.0396 2156 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
09:07:01.0400 2156 Psched - ok
09:07:01.0731 2156 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
09:07:01.0750 2156 ql2300 - ok
09:07:02.0027 2156 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
09:07:02.0031 2156 ql40xx - ok
09:07:02.0301 2156 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
09:07:02.0304 2156 QWAVEdrv - ok
09:07:02.0568 2156 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
09:07:02.0570 2156 RasAcd - ok
09:07:02.0841 2156 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
09:07:02.0843 2156 RasAgileVpn - ok
09:07:03.0156 2156 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
09:07:03.0159 2156 Rasl2tp - ok
09:07:03.0449 2156 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
09:07:03.0452 2156 RasPppoe - ok
09:07:03.0728 2156 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
09:07:03.0731 2156 RasSstp - ok
09:07:04.0006 2156 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
09:07:04.0012 2156 rdbss - ok
09:07:04.0278 2156 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
09:07:04.0280 2156 rdpbus - ok
09:07:04.0553 2156 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
09:07:04.0555 2156 RDPCDD - ok
09:07:04.0853 2156 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
09:07:04.0855 2156 RDPENCDD - ok
09:07:05.0128 2156 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
09:07:05.0130 2156 RDPREFMP - ok
09:07:05.0399 2156 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
09:07:05.0404 2156 RDPWD - ok
09:07:05.0718 2156 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
09:07:05.0723 2156 rdyboost - ok
09:07:06.0023 2156 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
09:07:06.0026 2156 rspndr - ok
09:07:06.0310 2156 RTL8167 (20a466b9ea2bd828c0ec723f99b8cfe7) C:\Windows\system32\DRIVERS\Rt64win7.sys
09:07:06.0313 2156 RTL8167 - ok
09:07:06.0575 2156 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
09:07:06.0579 2156 sbp2port - ok
09:07:06.0875 2156 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
09:07:06.0878 2156 scfilter - ok
09:07:07.0172 2156 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
09:07:07.0174 2156 secdrv - ok
09:07:07.0489 2156 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
09:07:07.0491 2156 Serenum - ok
09:07:07.0775 2156 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
09:07:07.0779 2156 Serial - ok
09:07:08.0050 2156 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
09:07:08.0052 2156 sermouse - ok
09:07:08.0342 2156 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
09:07:08.0344 2156 sffdisk - ok
09:07:08.0617 2156 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
09:07:08.0619 2156 sffp_mmc - ok
09:07:08.0885 2156 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
09:07:08.0888 2156 sffp_sd - ok
09:07:09.0169 2156 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
09:07:09.0171 2156 sfloppy - ok
09:07:09.0470 2156 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
09:07:09.0473 2156 SiSRaid2 - ok
09:07:09.0757 2156 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
09:07:09.0760 2156 SiSRaid4 - ok
09:07:10.0051 2156 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
09:07:10.0054 2156 Smb - ok
09:07:10.0342 2156 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
09:07:10.0344 2156 spldr - ok
09:07:10.0640 2156 srv (ec8f67289105bf270498095f14963464) C:\Windows\system32\DRIVERS\srv.sys
09:07:10.0648 2156 srv - ok
09:07:10.0945 2156 srv2 (f773d2ed090b7baa1c1a034f3ca476c8) C:\Windows\system32\DRIVERS\srv2.sys
09:07:10.0953 2156 srv2 - ok
09:07:11.0235 2156 srvnet (26e84d3649019c3244622e654dfcd75b) C:\Windows\system32\DRIVERS\srvnet.sys
09:07:11.0239 2156 srvnet - ok
09:07:11.0584 2156 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
09:07:11.0587 2156 stexstor - ok
09:07:11.0879 2156 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
09:07:11.0881 2156 swenum - ok
09:07:12.0245 2156 Tcpip (912107716bab424c7870e8e6af5e07e1) C:\Windows\system32\drivers\tcpip.sys
09:07:12.0259 2156 Tcpip - ok
09:07:12.0586 2156 TCPIP6 (912107716bab424c7870e8e6af5e07e1) C:\Windows\system32\DRIVERS\tcpip.sys
09:07:12.0610 2156 TCPIP6 - ok
09:07:12.0881 2156 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
09:07:12.0884 2156 tcpipreg - ok
09:07:13.0190 2156 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
09:07:13.0192 2156 TDPIPE - ok
09:07:13.0457 2156 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
09:07:13.0459 2156 TDTCP - ok
09:07:13.0735 2156 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
09:07:13.0738 2156 tdx - ok
09:07:14.0019 2156 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
09:07:14.0022 2156 TermDD - ok
09:07:14.0336 2156 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
09:07:14.0339 2156 tssecsrv - ok
09:07:14.0624 2156 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
09:07:14.0628 2156 tunnel - ok
09:07:14.0908 2156 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
09:07:14.0911 2156 uagp35 - ok
09:07:15.0187 2156 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
09:07:15.0193 2156 udfs - ok
09:07:15.0502 2156 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
09:07:15.0505 2156 uliagpkx - ok
09:07:15.0802 2156 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
09:07:15.0805 2156 umbus - ok
09:07:16.0085 2156 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
09:07:16.0088 2156 UmPass - ok
09:07:16.0364 2156 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
09:07:16.0365 2156 usbccgp - ok
09:07:16.0651 2156 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
09:07:16.0655 2156 usbcir - ok
09:07:16.0943 2156 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
09:07:16.0946 2156 usbehci - ok
09:07:17.0221 2156 usbfilter (2c780746dc44a28fe67004dc58173f05) C:\Windows\system32\DRIVERS\usbfilter.sys
09:07:17.0224 2156 usbfilter - ok
09:07:17.0514 2156 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
09:07:17.0521 2156 usbhub - ok
09:07:17.0803 2156 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
09:07:17.0805 2156 usbohci - ok
09:07:18.0095 2156 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
09:07:18.0098 2156 usbprint - ok
09:07:18.0373 2156 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
09:07:18.0374 2156 USBSTOR - ok
09:07:18.0648 2156 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
09:07:18.0651 2156 usbuhci - ok
09:07:18.0941 2156 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
09:07:18.0943 2156 vdrvroot - ok
09:07:19.0235 2156 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
09:07:19.0237 2156 vga - ok
09:07:19.0526 2156 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
09:07:19.0528 2156 VgaSave - ok
09:07:19.0809 2156 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
09:07:19.0814 2156 vhdmp - ok
09:07:20.0126 2156 VIAHdAudAddService (dfdf7f9caa50ee72a633ea4bbd65a557) C:\Windows\system32\drivers\viahduaa.sys
09:07:20.0141 2156 VIAHdAudAddService - ok
09:07:20.0423 2156 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
09:07:20.0425 2156 viaide - ok
09:07:20.0696 2156 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
09:07:20.0699 2156 volmgr - ok
09:07:20.0984 2156 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
09:07:20.0991 2156 volmgrx - ok
09:07:21.0283 2156 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
09:07:21.0289 2156 volsnap - ok
09:07:21.0560 2156 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
09:07:21.0564 2156 vsmraid - ok
09:07:21.0836 2156 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
09:07:21.0839 2156 vwifibus - ok
09:07:22.0127 2156 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
09:07:22.0129 2156 WacomPen - ok
09:07:22.0431 2156 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
09:07:22.0434 2156 WANARP - ok
09:07:22.0453 2156 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
09:07:22.0455 2156 Wanarpv6 - ok
09:07:22.0739 2156 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
09:07:22.0742 2156 Wd - ok
09:07:23.0064 2156 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
09:07:23.0076 2156 Wdf01000 - ok
09:07:23.0398 2156 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
09:07:23.0401 2156 WfpLwf - ok
09:07:23.0665 2156 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
09:07:23.0668 2156 WIMMount - ok
09:07:24.0024 2156 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
09:07:24.0026 2156 WmiAcpi - ok
09:07:24.0366 2156 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
09:07:24.0369 2156 ws2ifsl - ok
09:07:24.0685 2156 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
09:07:24.0689 2156 WudfPf - ok
09:07:24.0742 2156 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
09:07:24.0756 2156 \Device\Harddisk0\DR0 - ok
09:07:24.0781 2156 MBR (0x1B8) (9c603bc3977968c891de319283e1e7af) \Device\Harddisk1\DR1
09:07:24.0869 2156 \Device\Harddisk1\DR1 - ok
09:07:24.0880 2156 Boot (0x1200) (791c73f1b97e834a8edfa2a266760ee6) \Device\Harddisk0\DR0\Partition0
09:07:24.0881 2156 \Device\Harddisk0\DR0\Partition0 - ok
09:07:24.0892 2156 Boot (0x1200) (0854796db90916c149887f4fdebbda05) \Device\Harddisk0\DR0\Partition1
09:07:24.0892 2156 \Device\Harddisk0\DR0\Partition1 - ok
09:07:24.0909 2156 Boot (0x1200) (9c803390d55e257f7d768a6641353d85) \Device\Harddisk0\DR0\Partition2
09:07:24.0910 2156 \Device\Harddisk0\DR0\Partition2 - ok
09:07:24.0945 2156 Boot (0x1200) (abe6a925aab3dd57269e4a7c8da7a4d1) \Device\Harddisk1\DR1\Partition0
09:07:24.0945 2156 \Device\Harddisk1\DR1\Partition0 - ok
09:07:24.0946 2156 ============================================================
09:07:24.0946 2156 Scan finished
09:07:24.0946 2156 ============================================================
09:07:24.0958 1524 Detected object count: 0
09:07:24.0958 1524 Actual detected object count: 0

BC AdBot (Login to Remove)

 


#2 B-boy/StyLe/

B-boy/StyLe/

    Bleeping Freestyler


  • Malware Response Team
  • 6,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:23 PM

Posted 01 November 2011 - 10:36 AM

Hello swinka ! Welcome to BleepingComputer Forums! :welcome:

My name is Georgi and and I will be helping you with your computer problems.

Before we begin, please note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.




We need to get the mbr dump for analysis.

Make sure TDSSKiller.exe is on the Desktop itself, not within a folder on the desktop.

Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

"%userprofile%\Desktop\TDSSKiller.exe" -qmbr

A folder will apper called TDSSKiller_Quarantine in the C:\ drive.

Please zip up that folder and attach it to your next reply.



Regards,
Georgi
qnfKk.jpg
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - paypal.gif

#3 swinka

swinka
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 01 November 2011 - 03:40 PM

Nice to meet you Georgi, im happy that someone is willing to help me with this problem :)

Ok, I have done as you told. A new folder got created on C drive. It also opened TDSS killer, so I did a scan and Im also adding the log from it.
Hope it helps!

Attached Files


Edited by swinka, 01 November 2011 - 03:43 PM.


#4 B-boy/StyLe/

B-boy/StyLe/

    Bleeping Freestyler


  • Malware Response Team
  • 6,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:23 PM

Posted 01 November 2011 - 04:17 PM

Hello,


Thank you for the folder.
I'm pretty sure there is still a rootkit lurking on the computer and that wasn't a false positive regarding the VirusTotal results.


I need some time for additional research. It may take awhile, so please be patient with me.


Some extra notes: :)

Also do you have windows 7 installation DVD ? If not please verify that you can access the Recovery Environment.
To do so, restart your computer and begin tapping the F8 key to enable the Advanced Start menu.
If the option 'Repair your computer' is available please hard reboot your computer and report to me your success. Do not proceed!!!

Posted Image


Regards,
Georgi
qnfKk.jpg
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - paypal.gif

#5 swinka

swinka
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 01 November 2011 - 04:29 PM

I tried to access the Recovery Environment, but I failed. I was tapping f8, and I had the option to choose a drive I want to operate on. My options were 2 hard drives and DVD drive.
But when I try to enter one of the drives or the DVD drive, the cpu just starts windows.
When I try to open the other drive, I only see a black screen and nothing happens.

#6 B-boy/StyLe/

B-boy/StyLe/

    Bleeping Freestyler


  • Malware Response Team
  • 6,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:23 PM

Posted 02 November 2011 - 08:45 AM

Hi,


Please download aswMBR.exe to your desktop.

  • Double click the aswMBR.exe icon to run it.
  • The program will offers to download the latest antivirus definitions from Avast servers. Click YES to agree.
  • When it's done in the AV Scan drop down options choose C:\
    Posted Image
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
Note - do NOT attempt any Fix or FixMBR yet.


Regards,
Georgi
qnfKk.jpg
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - paypal.gif

#7 swinka

swinka
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 02 November 2011 - 11:19 AM

Hello,

Im adding the log of the scan, As you said, I did not try to fix anything.

Attached Files



#8 B-boy/StyLe/

B-boy/StyLe/

    Bleeping Freestyler


  • Malware Response Team
  • 6,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:23 PM

Posted 02 November 2011 - 07:59 PM

Hi swinka, :)



Please download ComboFix from the link below:

ComboFix

Save it to your Desktop, but do not run it yet <-- Important!!!

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Please refer to this link for instructions.
  • Double click it & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    Notes: Skip the Recovery Console part as you're running Vista. You can use the Windows DVD to boot into the Vista Recovery Environment if something goes awry.
  • Click on Yes, to continue scanning for malware.
  • If you receive a UAC prompt asking if you want to continue running the program, you should press the Continue button.
  • When finished, it will produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.
  • Note: After running Combofix, you may receive an error about "illegal operation on a registry key that has been marked for deletion." If you receive this error, please reboot and it should disappear.
  • If you no longer have access to your Internet connection after running ComboFix, please reboot to restore it. If that does not restore the connection, then follow the instructions for Manually restoring the Internet connection provided in the "How to Guide" you printed out earlier.



-- Do not touch your mouse/keyboard until the ComboFix scan has completed, as this may cause the process to stall or the computer to lock.




Regards,
Georgi
qnfKk.jpg
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - paypal.gif

#9 swinka

swinka
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 03 November 2011 - 10:33 AM

Hi,

I did the scan with Combo fix without any errors or internet connection loss.
I upload the log.

Attached Files



#10 B-boy/StyLe/

B-boy/StyLe/

    Bleeping Freestyler


  • Malware Response Team
  • 6,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:23 PM

Posted 03 November 2011 - 01:40 PM

Hi swinka,



STEP 1



It looks like you have an infection in the Master Boot Record(MBR) on your hard disk drive.
Let's do a backup before fixing it. (this is in case something goes wrong). You will need a USB drive.



Please go to this site and download MBRFix.exe.

Scroll down to locate mbrfix.exe, and in the lower right corner of the tool info, you'll see the Download link. Save it directly to the C:\ drive and extract all files there.

Windows Vista/7 do not display the Run line on the Start menu in the default setting but the Run line can be accessed in all current versiions of Windows by pressing the keyboard combination Windows key + R.

Copy/paste the following into the Run box and click OK:

cmd /c MbrFix /drive 0 savembr C:\Backup_MBR_0.bin

You should now see the C:\Backup_MBR_0.bin on your C:\ drive.

Repeat these steps using the following command:

cmd /c MbrFix /drive 1 savembr C:\Backup_MBR_1.bin

You should now see the C:\Backup_MBR_1.bin on your C:\ drive.

Please zip these files and attach them in your next reply.



Please note - all text entries are case sensitive



Please make sure you copy the files Backup_MBR_0.bin and Backup_MBR_1.bin to your USB drive as well. <-- IMPORTANT



Make sure that you have done backups of important data before you proceed. <-- IMPORTANT
Of course the backups should be on an external media - like CD/DVD.



STEP 2



Kaspersky has silently updated their TDSSKiller.exe to 2.6.15.0...

Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

Please delete your copy of TDSSKiller and download the latest version from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application.
  • Click the Start Scan button.

    Posted Image
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    Posted Image
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.

    Posted Image
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.


Regards,
Georgi
qnfKk.jpg
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - paypal.gif

#11 swinka

swinka
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 03 November 2011 - 03:17 PM

Hello,

Im stuck at Step 1. This is what I've done:
-dowloaded the mbrfix.exe on /C
-I extracted it also on /C (I did not run it, because you did not write that I should)
-I pasted the Run line You gave me and pressed OK. I saw a dialog window just flash for a second. I searched the /C drive, but no C:\Backup_MBR_0.bin got created there.

Im stuck at this point.

#12 B-boy/StyLe/

B-boy/StyLe/

    Bleeping Freestyler


  • Malware Response Team
  • 6,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:23 PM

Posted 03 November 2011 - 08:19 PM

Hi,

Try this instead:

Press the keyboard combination Windows key + R and type in cmd to open the command window.

A black windows will appear on the screen where you must enter the commands.

Type in the following and press Enter:

cd c:\

next type

MbrFix64.exe /drive 0 savembr C:\Backup_MBR_0.bin

and press Enter

There should be C:\Backup_MBR_0.bin on the C:\ drive. Zip it up and attach it in your next reply.

Repeat the procedure typing the following command:

MbrFix64.exe /drive 1 savembr C:\Backup_MBR_1.bin

There should be C:\Backup_MBR_1.bin on the C:\ drive. Zip it up and attach it in your next reply.

Please make sure you copy the files Backup_MBR_0.bin and Backup_MBR_1.bin to your USB drive as well. <-- IMPORTANT


Next proceed with TDSSKiller.


Regards,
Georgi
qnfKk.jpg
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - paypal.gif

#13 swinka

swinka
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 04 November 2011 - 03:09 PM

Hi,

I think that it is done :) But please check my logs to make that info possitive.
Thanks :)

Attached Files



#14 B-boy/StyLe/

B-boy/StyLe/

    Bleeping Freestyler


  • Malware Response Team
  • 6,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:23 PM

Posted 04 November 2011 - 03:29 PM

Hi,


Please re-run TDSSKiller and post its log in your next reply. :)



Regards,
Georgi
qnfKk.jpg
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - paypal.gif

#15 swinka

swinka
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 05 November 2011 - 09:26 AM

Hello,

So here is my final log ( I hope :)).

Attached Files

  • Attached File  TDSS.txt   36.65KB   4 downloads





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users