Hijackthis Log Looking at a Hijackthis log
#16
Posted 02 May 2011 - 08:44 AM
Here are the results from ESET's online scan:
C:\QooBox\Quarantine\C\WINDOWS\system32\akkukstk.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\cdfneivb.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\dpwgvohf.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\dsoileua.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\efwnlybl.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\fcejmrkp.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\fuikionb.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\fwiuvdrh.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\geeivwbk.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\gsxnvabc.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\jwxekhqt.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\kuqiegur.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\kxwjpuku.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\olahedri.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\ottontqs.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\plglqrrl.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\pugdpncu.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\qqajrdpm.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\sabcdhgy.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\sitqfuwc.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\tgdudeuu.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\uefctbyc.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\vngppwxn.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\vqtxrmub.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\vvmylvsv.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\xpbvlldv.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\xybsrpod.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\ycekdnyc.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
C:\QooBox\Quarantine\C\WINDOWS\system32\ygmtbxwh.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
Here are the results from the Blue Screen View:
==================================================
Dump File : Mini041811-01.dmp
Crash Time : 4/18/2011 10:34:05 PM
Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x000000d1
Parameter 1 : 0x00030040
Parameter 2 : 0x00000002
Parameter 3 : 0x00000000
Parameter 4 : 0xb9f18af2
Caused By Driver : atapi.sys
Caused By Address : atapi.sys+5af2
File Description : IDE/ATAPI Port Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini041811-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 65,536
==================================================
What should I do now?
#17
Posted 02 May 2011 - 04:09 PM
atapi.sys caused that blue screen. That suggests a particular rootkit. Let's run TDSS Killer
Also, how is your computer running at this point?
- Download TDSSKiller.exe and save it to your desktop.
- Double-click TDSSKiller.exe to run it.
- Under "Objects to scan" ensure both "Services and Drivers" and "Boot Sectors" are checked.
- Click Start scan and allow it to scan for Malicious objects.
- If malicious objects are found, the default action will be Cure, ensure Cure is selected then click Continue.
- If suspicious objects are detected, the default action will be Skip, ensure Skip is selected then click Continue.
- It may ask you to reboot the computer to complete the process. Click on Reboot Now and allow the computer to reboot.
- A log will be created on your root (usually C:) drive. The log is like UtilityName.Version_Date_Time_log.txt.
for example, C:\TDSSKiller.2.4.1.2_20.04.2010_15.31.43_log.txt - If no reboot is required, click on Report. A log file should appear.
- Please post the contents of the logfile in your next reply
etavares
This post has been edited by etavares: 02 May 2011 - 04:10 PM
If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.


Unified Network of Instructors and Trusted Eliminators
#18
Posted 03 May 2011 - 07:51 AM
Here is the log report:
2011/05/02 18:53:26.0343 4000 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/05/02 18:53:27.0031 4000 ================================================================================
2011/05/02 18:53:27.0031 4000 SystemInfo:
2011/05/02 18:53:27.0031 4000
2011/05/02 18:53:27.0031 4000 OS Version: 5.1.2600 ServicePack: 3.0
2011/05/02 18:53:27.0031 4000 Product type: Workstation
2011/05/02 18:53:27.0031 4000 ComputerName: GABE
2011/05/02 18:53:27.0031 4000 UserName: Gabriel Smith
2011/05/02 18:53:27.0031 4000 Windows directory: C:\WINDOWS
2011/05/02 18:53:27.0031 4000 System windows directory: C:\WINDOWS
2011/05/02 18:53:27.0031 4000 Processor architecture: Intel x86
2011/05/02 18:53:27.0031 4000 Number of processors: 1
2011/05/02 18:53:27.0031 4000 Page size: 0x1000
2011/05/02 18:53:27.0031 4000 Boot type: Normal boot
2011/05/02 18:53:27.0031 4000 ================================================================================
2011/05/02 18:53:29.0984 4000 Initialize success
2011/05/02 18:54:10.0890 0464 ================================================================================
2011/05/02 18:54:10.0890 0464 Scan started
2011/05/02 18:54:10.0890 0464 Mode: Manual;
2011/05/02 18:54:10.0890 0464 ================================================================================
2011/05/02 18:54:13.0359 0464 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
2011/05/02 18:54:13.0453 0464 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/05/02 18:54:13.0546 0464 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/05/02 18:54:13.0625 0464 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
2011/05/02 18:54:13.0687 0464 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/05/02 18:54:14.0109 0464 AegisP (076394a345ee5e9e3911fc0f058f4f38) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/05/02 18:54:14.0218 0464 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys
2011/05/02 18:54:14.0296 0464 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/05/02 18:54:14.0343 0464 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
2011/05/02 18:54:14.0406 0464 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
2011/05/02 18:54:14.0484 0464 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
2011/05/02 18:54:15.0078 0464 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
2011/05/02 18:54:15.0125 0464 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/05/02 18:54:15.0218 0464 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
2011/05/02 18:54:15.0281 0464 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
2011/05/02 18:54:15.0343 0464 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
2011/05/02 18:54:15.0406 0464 ApfiltrService (aeb775a2bae0f392ba6adc0bb706233a) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2011/05/02 18:54:15.0843 0464 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
2011/05/02 18:54:15.0953 0464 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
2011/05/02 18:54:16.0015 0464 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
2011/05/02 18:54:16.0062 0464 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
2011/05/02 18:54:16.0203 0464 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/05/02 18:54:16.0640 0464 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/05/02 18:54:16.0843 0464 ati2mtag (2a6c99cfdc23c9c26d0e30b1c99748d4) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2011/05/02 18:54:17.0375 0464 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/05/02 18:54:17.0453 0464 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/05/02 18:54:17.0531 0464 b57w2k (2acf06176b9d011567d7f25b83ddd066) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
2011/05/02 18:54:17.0609 0464 BANTExt (5d7be7b19e827125e016325334e58ff1) C:\WINDOWS\System32\Drivers\BANTExt.sys
2011/05/02 18:54:17.0687 0464 BASFND (3d87b0484be1093c6614062701f375c5) C:\WINDOWS\system32\Drivers\BASFND.sys
2011/05/02 18:54:17.0734 0464 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/05/02 18:54:18.0296 0464 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
2011/05/02 18:54:18.0328 0464 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/05/02 18:54:18.0406 0464 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/05/02 18:54:18.0468 0464 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
2011/05/02 18:54:18.0531 0464 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/05/02 18:54:18.0625 0464 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/05/02 18:54:19.0609 0464 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/05/02 18:54:19.0859 0464 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys
2011/05/02 18:54:20.0234 0464 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/05/02 18:54:20.0484 0464 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
2011/05/02 18:54:20.0687 0464 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/05/02 18:54:20.0750 0464 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
2011/05/02 18:54:20.0859 0464 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
2011/05/02 18:54:20.0953 0464 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
2011/05/02 18:54:21.0125 0464 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/05/02 18:54:21.0546 0464 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/05/02 18:54:21.0703 0464 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/05/02 18:54:21.0765 0464 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/05/02 18:54:22.0125 0464 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/05/02 18:54:22.0234 0464 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
2011/05/02 18:54:22.0281 0464 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/05/02 18:54:22.0375 0464 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
2011/05/02 18:54:22.0484 0464 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
2011/05/02 18:54:22.0625 0464 DUMeterDrv (24f97aca2946fbaa46e38babdef766c0) C:\Program Files\DU Meter\DUM_XP32.SYS
2011/05/02 18:54:23.0000 0464 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/05/02 18:54:23.0109 0464 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/05/02 18:54:23.0171 0464 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/05/02 18:54:23.0234 0464 FilterService (f9183d35ad38f093d5e1aa8ba072d51b) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
2011/05/02 18:54:23.0343 0464 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/05/02 18:54:23.0406 0464 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/05/02 18:54:23.0484 0464 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/05/02 18:54:23.0640 0464 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/05/02 18:54:23.0984 0464 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/05/02 18:54:24.0078 0464 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/05/02 18:54:24.0171 0464 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/05/02 18:54:24.0281 0464 GTIPCI21 (7d074058804ad398f93ca0a08af83ff2) C:\WINDOWS\system32\DRIVERS\gtipci21.sys
2011/05/02 18:54:24.0359 0464 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/05/02 18:54:24.0437 0464 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
2011/05/02 18:54:24.0828 0464 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2011/05/02 18:54:24.0890 0464 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2011/05/02 18:54:24.0968 0464 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2011/05/02 18:54:25.0125 0464 HSFHWICH (140ba850417896b6b3322048de280368) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
2011/05/02 18:54:25.0265 0464 HSF_DP (b2dfc168d6f7512faea085253c5a37ad) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
2011/05/02 18:54:25.0718 0464 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/05/02 18:54:25.0796 0464 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
2011/05/02 18:54:25.0859 0464 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
2011/05/02 18:54:25.0906 0464 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/05/02 18:54:25.0968 0464 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/05/02 18:54:26.0046 0464 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
2011/05/02 18:54:26.0125 0464 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/05/02 18:54:26.0187 0464 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/05/02 18:54:26.0578 0464 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/05/02 18:54:26.0671 0464 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/05/02 18:54:26.0750 0464 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/05/02 18:54:26.0828 0464 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/05/02 18:54:26.0906 0464 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/05/02 18:54:26.0984 0464 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/05/02 18:54:27.0609 0464 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/05/02 18:54:27.0671 0464 IWCA (872d090ca5c306f62d1982bce6302376) C:\WINDOWS\system32\DRIVERS\iwca.sys
2011/05/02 18:54:27.0734 0464 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/05/02 18:54:27.0828 0464 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/05/02 18:54:28.0015 0464 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/05/02 18:54:28.0156 0464 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/05/02 18:54:28.0453 0464 lvpopflt (f61a8ff029614e403e9d001a6741981f) C:\WINDOWS\system32\DRIVERS\lvpopflt.sys
2011/05/02 18:54:28.0531 0464 LVPr2Mon (8be71d7edb8c7494913722059f760dd0) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
2011/05/02 18:54:28.0765 0464 LVRS (f01fc94eb8f39f7d6e5f5b367473381e) C:\WINDOWS\system32\DRIVERS\lvrs.sys
2011/05/02 18:54:29.0453 0464 LVUVC (caffd79278b3d8fe75fdfe1b66c2565f) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
2011/05/02 18:54:30.0265 0464 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/05/02 18:54:30.0437 0464 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/05/02 18:54:30.0531 0464 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/05/02 18:54:30.0578 0464 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/05/02 18:54:31.0015 0464 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/05/02 18:54:31.0062 0464 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/05/02 18:54:31.0140 0464 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
2011/05/02 18:54:31.0187 0464 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/05/02 18:54:31.0312 0464 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/05/02 18:54:31.0765 0464 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/05/02 18:54:31.0828 0464 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/05/02 18:54:31.0875 0464 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/05/02 18:54:31.0937 0464 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/05/02 18:54:32.0000 0464 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/05/02 18:54:32.0062 0464 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/05/02 18:54:32.0156 0464 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/05/02 18:54:32.0281 0464 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/05/02 18:54:32.0703 0464 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/05/02 18:54:32.0765 0464 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/05/02 18:54:32.0859 0464 Ndisprot (a3b80c6e0774815c362aeb5ed5ac047d) C:\WINDOWS\system32\drivers\Ndisprot.sys
2011/05/02 18:54:32.0906 0464 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/05/02 18:54:32.0953 0464 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/05/02 18:54:33.0031 0464 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/05/02 18:54:33.0109 0464 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/05/02 18:54:33.0656 0464 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/05/02 18:54:33.0718 0464 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/05/02 18:54:33.0859 0464 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/05/02 18:54:34.0515 0464 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/05/02 18:54:35.0015 0464 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
2011/05/02 18:54:35.0062 0464 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/05/02 18:54:35.0218 0464 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/05/02 18:54:35.0390 0464 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/05/02 18:54:35.0750 0464 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/05/02 18:54:35.0828 0464 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
2011/05/02 18:54:35.0937 0464 ovt519 (4cdadec3dc1300ee1d313ea5494e6472) C:\WINDOWS\system32\Drivers\ov519vid.sys
2011/05/02 18:54:36.0015 0464 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/05/02 18:54:36.0109 0464 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/05/02 18:54:36.0187 0464 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/05/02 18:54:36.0718 0464 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/05/02 18:54:36.0859 0464 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/05/02 18:54:36.0937 0464 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/05/02 18:54:37.0171 0464 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
2011/05/02 18:54:37.0296 0464 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
2011/05/02 18:54:37.0718 0464 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/05/02 18:54:37.0984 0464 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/05/02 18:54:38.0093 0464 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/05/02 18:54:38.0203 0464 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/05/02 18:54:38.0703 0464 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
2011/05/02 18:54:38.0781 0464 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
2011/05/02 18:54:38.0890 0464 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
2011/05/02 18:54:38.0953 0464 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
2011/05/02 18:54:39.0000 0464 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
2011/05/02 18:54:39.0062 0464 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/05/02 18:54:39.0265 0464 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/05/02 18:54:39.0546 0464 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/05/02 18:54:39.0593 0464 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/05/02 18:54:39.0640 0464 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/05/02 18:54:39.0687 0464 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/05/02 18:54:39.0750 0464 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/05/02 18:54:39.0875 0464 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/05/02 18:54:40.0062 0464 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/05/02 18:54:40.0468 0464 RimUsb (92d33f76769a028ddc54a863eb7de4a2) C:\WINDOWS\system32\Drivers\RimUsb.sys
2011/05/02 18:54:40.0546 0464 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
2011/05/02 18:54:40.0656 0464 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/05/02 18:54:40.0781 0464 s24trans (81aa6f0d6a2be1c550f814b036215888) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/05/02 18:54:40.0953 0464 SCDEmu (16b1abe7f3e35f21dac57592b6c5d464) C:\WINDOWS\system32\drivers\SCDEmu.sys
2011/05/02 18:54:41.0453 0464 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/05/02 18:54:41.0609 0464 Sentinel (b3c1b187fefc941f63ce0df93d02eb9f) C:\WINDOWS\System32\Drivers\SENTINEL.SYS
2011/05/02 18:54:41.0781 0464 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/05/02 18:54:42.0078 0464 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/05/02 18:54:42.0140 0464 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/05/02 18:54:42.0250 0464 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
2011/05/02 18:54:42.0343 0464 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/05/02 18:54:42.0484 0464 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/05/02 18:54:42.0609 0464 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/05/02 18:54:42.0968 0464 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
2011/05/02 18:54:42.0968 0464 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/05/02 18:54:42.0984 0464 sptd - detected Locked file (1)
2011/05/02 18:54:43.0140 0464 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/05/02 18:54:43.0328 0464 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/05/02 18:54:43.0671 0464 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
2011/05/02 18:54:43.0750 0464 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
2011/05/02 18:54:43.0843 0464 STAC97 (305cc42945a713347f978d78566113f3) C:\WINDOWS\system32\drivers\STAC97.sys
2011/05/02 18:54:44.0046 0464 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/05/02 18:54:44.0640 0464 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/05/02 18:54:44.0984 0464 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/05/02 18:54:45.0109 0464 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
2011/05/02 18:54:45.0296 0464 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
2011/05/02 18:54:45.0343 0464 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
2011/05/02 18:54:45.0406 0464 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
2011/05/02 18:54:45.0750 0464 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/05/02 18:54:45.0906 0464 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/05/02 18:54:46.0062 0464 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/05/02 18:54:46.0093 0464 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/05/02 18:54:46.0453 0464 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/05/02 18:54:46.0625 0464 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys
2011/05/02 18:54:46.0687 0464 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys
2011/05/02 18:54:46.0734 0464 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys
2011/05/02 18:54:46.0906 0464 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys
2011/05/02 18:54:46.0984 0464 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys
2011/05/02 18:54:47.0312 0464 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys
2011/05/02 18:54:47.0500 0464 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys
2011/05/02 18:54:47.0593 0464 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys
2011/05/02 18:54:47.0656 0464 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys
2011/05/02 18:54:47.0859 0464 TIEHDUSB (a1124ebc672aa3ae1b327096c1dcc346) C:\WINDOWS\system32\drivers\tiehdusb.sys
2011/05/02 18:54:48.0125 0464 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
2011/05/02 18:54:48.0578 0464 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/05/02 18:54:48.0859 0464 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
2011/05/02 18:54:48.0953 0464 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/05/02 18:54:49.0062 0464 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys
2011/05/02 18:54:49.0140 0464 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/05/02 18:54:49.0375 0464 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/05/02 18:54:49.0671 0464 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/05/02 18:54:49.0734 0464 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/05/02 18:54:49.0796 0464 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/05/02 18:54:49.0843 0464 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/05/02 18:54:49.0906 0464 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/05/02 18:54:49.0968 0464 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/05/02 18:54:50.0046 0464 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
2011/05/02 18:54:50.0328 0464 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/05/02 18:54:50.0609 0464 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
2011/05/02 18:54:50.0671 0464 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/05/02 18:54:50.0750 0464 VirtualAudioCable (b0e2cc9d642e51632438200c0654673c) C:\WINDOWS\system32\drivers\vackmd.sys
2011/05/02 18:54:50.0796 0464 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/05/02 18:54:51.0156 0464 w29n51 (f0f902220910c4fbe42a51964bd33599) C:\WINDOWS\system32\DRIVERS\w29n51.sys
2011/05/02 18:54:51.0625 0464 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/05/02 18:54:51.0796 0464 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
2011/05/02 18:54:51.0921 0464 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/05/02 18:54:52.0000 0464 winachsf (2dc7c0b6175a0a8ed84a4f70199c93b5) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/05/02 18:54:52.0531 0464 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/05/02 18:54:52.0718 0464 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/05/02 18:54:52.0812 0464 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/05/02 18:54:52.0890 0464 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/05/02 18:54:53.0265 0464 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/05/02 18:54:58.0015 0464 ================================================================================
2011/05/02 18:54:58.0015 0464 Scan finished
2011/05/02 18:54:58.0015 0464 ================================================================================
2011/05/02 18:54:58.0046 1652 Detected object count: 1
2011/05/02 18:55:10.0125 1652 Locked file(sptd) - User select action: Skip
What would you like me to do now?
#19
Posted 03 May 2011 - 05:13 PM
If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.


Unified Network of Instructors and Trusted Eliminators
#21
Posted 03 May 2011 - 06:05 PM
Try this please. You will need a USB drive.
Download http://unetbootin.sourceforge.net/unetbootin-xpud-windows-latest.exe & http://noahdfear.net/downloads/bootable/xPUD/xpud-0.9.2.iso to the desktop of your clean computer
- Insert your USB drive
- Press Start > My Computer > right click your USB drive > choose Format > Quick format
- Double click the unetbootin-xpud-windows-387.exe that you just downloaded
- Press Run then OK
- Select the DiskImage option then click the browse button located on the right side of the textbox field.
- Browse to and select the xpud-0.9.2.iso file you downloaded
- Verify the correct drive letter is selected for your USB device then click OK
- It will install a little bootable OS on your USB device
- Once the files have been written to the device you will be prompted to reboot ~ do not reboot and instead just Exit the UNetbootin interface
- After it has completed do not choose to reboot the clean computer simply close the installer
- Next download http://noahdfear.net/downloads/driver.sh to your USB
- Remove the USB and insert it in the sick computer
- Boot the Sick computer
- Press F12 and choose to boot from the USB
- Follow the prompts
- A Welcome to xPUD screen will appear
- Press File
- Expand mnt
- sda1,2...usually corresponds to your HDD
- sdb1 is likely your USB
- Click on the folder that represents your USB drive (sdb1 ?)
- Confirm that you see driver.sh that you downloaded there
- Press Tool at the top
- Choose Open Terminal
- Type bash driver.sh
- Press Enter
- After it has finished a report will be located on your USB drive named report.txt
- Remove the USB drive and insert back in your working computer and navigate to report.txt
Please note - all text entries are case sensitive
etavares
If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.


Unified Network of Instructors and Trusted Eliminators
#22
Posted 04 May 2011 - 07:59 AM
I did all the usb stuff and here is the report:
Tue May 3 23:22:51 UTC 2011
Driver report for /mnt/sda2/WINDOWS/system32/drivers
5d7be7b19e827125e016325334e58ff1 BANTExt.sys has NO Company Name!
b0e2cc9d642e51632438200c0654673c vackmd.sys has NO Company Name!
6abb91494fe6c59089b9336452ab2ea3 abp480n5.sys
Microsoft Corporation
9859c0f6936e723e4892d7141b1327d5 acpiec.sys
Microsoft Corporation
8fd99680a539792a30e97944fdaecf17 acpi.sys
Microsoft Corporation
9a11864873da202c996558b2106b0bbc adpu160m.sys
Microsoft Corporation
8bed39e3c35d6a489438b8141717a557 aec.sys
Microsoft Corporation
076394a345ee5e9e3911fc0f058f4f38 AegisP.sys
Meetinghouse Data Communications
7618d5218f2a614672ec61a80d854a37 afd.sys
Microsoft Corporation
08fd04aa961bdc77fb983f328334e3d7 agp440.sys
Microsoft Corporation
03a7e0922acfe1b07d5db2eeb0773063 agpcpq.sys
Microsoft Corporation
c23ea9b5f46c7f7910db3eab648ff013 aha154x.sys
Microsoft Corporation
19dd0fb48b0c18892f70e2e7d61a1529 aic78u2.sys
Microsoft Corporation
b7fe594a7468aa0132deb03fb8e34326 aic78xx.sys
Microsoft Corporation
1140ab9938809700b46bb88e46d72a96 aliide.sys
Acer Laboratories
cb08aed0de2dd889a8a820cd8082d83c alim1541.sys
Microsoft Corporation
95b4fb835e28aa1336ceeb07fd5b9398 amdagp.sys
Advanced Micro Devices
d7701d7e72243286cc88c9973d891057 amdk6.sys
Microsoft Corporation
8fce268cdbdd83b23419d1f35f42c7b1 amdk7.sys
Microsoft Corporation
79f5add8d24bd6893f2903a3e2f3fad6 amsint.sys
Microsoft Corporation
aeb775a2bae0f392ba6adc0bb706233a Apfiltr.sys
Alps Electric
ec94e05b76d033b74394e7b2175103cf APPDRV.SYS
Dell
b5b8a80875c1dededa8b02765642c32f arp1394.sys
Microsoft Corporation
69eb0cc7714b32896ccbfd5edcbea447 asc3350p.sys
Microsoft Corporation
5d8de112aa0254b907861e9e9c31d597 asc3550.sys
Advanced System Products
62d318e9a0c8fc9b780008e724283707 asc.sys
Advanced System Products
b153affac761e7f5fcfa822b9c4e97bc asyncmac.sys
Microsoft Corporation
9f3a2f5aa6875c72bf062c712cfa2674 atapi.sys
Microsoft Corporation
d649c57da6fa762c64013747e5d7d2d6 ati1btxx.sys
ATI Technologies
60b6aa2dc1521da343f781b70eb7895a ati1mdxx.sys
ATI Technologies
6fdc61e8e8e17f6ecc2d9a10fa8df347 ati1pdxx.sys
ATI Technologies
9d318099bf3876a4af4bc75966d27603 ati1raxx.sys
ATI Technologies
bcaf267b10620f8c93f6e87ab726e145 ati1rvxx.sys
ATI Technologies
dac7d785cf62f5bd41441e9d6f5a6efe ati1snxx.sys
ATI Technologies
f7706dae7d101f1b19ce552d772ebfce ati1ttxx.sys
ATI Technologies
6f714b4720dd80ffa9f8d2731594ea4c ati1tuxx.sys
ATI Technologies
67ffbc158dd4d27ba3fc92c6acd87f73 ati1xbxx.sys
ATI Technologies
0d8cab1f08f7d3c4de228b49e12e596a ati1xsxx.sys
ATI Technologies
2d030c2f6b036ca0bc243e1b16d924d1 ati2mtaa.sys
ATI Technologies
2a6c99cfdc23c9c26d0e30b1c99748d4 ati2mtag.sys
ATI Technologies
993e7bd6438fe989e328c6b4bca246a9 atinbtxx.sys
ATI Technologies
ed4c2bf8403f4437987c0ba09cf48716 atinmdxx.sys
ATI Technologies
e90ac2b14e98f1a4372e5891b4278784 atinpdxx.sys
ATI Technologies
da36687d701c833430605a298731410b atinraxx.sys
ATI Technologies
a7a01b907db63898d40b0a14248ff9a2 atinrvxx.sys
ATI Technologies
ceddee2e0591894d19654d458fd3b9be atinsnxx.sys
ATI Technologies
d80a8f6c0a717446496c3a06d33b0d9c atinttxx.sys
ATI Technologies
edd66332608d27f4fd5069bcd0bc5164 atintuxx.sys
ATI Technologies
3e7d485cbd0b0d9f6ea2ad9442411831 atinxbxx.sys
ATI Technologies
77b575d7aab35d5908ae6ce681608d62 atinxsxx.sys
ATI Technologies
9916c1225104ba14794209cfa8012159 atmarpc.sys
Microsoft Corporation
39a0a59180f19946374275745b21aeba atmepvc.sys
Microsoft Corporation
ae76348a2605fb197fa8ff1d6f547836 atmlane.sys
Microsoft Corporation
e7ef69b38d17ba01f914ae8f66216a38 atmuni.sys
Microsoft Corporation
d9f724aa26c010a217c97606b160ed68 audstub.sys
Microsoft Corporation
ec018602809b28520caa132cd616bb2a AWRTPD.sys
Lavasoft
10d3f81b955cd10d6464b1b922e5ac68 AWRTRD.sys
Lavasoft
2acf06176b9d011567d7f25b83ddd066 b57xp32.sys
Broadcom Corporation
5d7be7b19e827125e016325334e58ff1 BANTExt.sys
3d87b0484be1093c6614062701f375c5 BASFND.sys
Broadcom Corporation
0d93976f7801b7fcd8135cc77257bbd0 battc.sys
Microsoft Corporation
13b22e449af69f79ad83ce7a66096d5d bdfndisf.sys
tH#VS_VERSION_INFOrv?bStringFileInfoB@CompanyNameBitDefenderSRLx(FileDescriptionBitDefenderFirewallNDISFilterDrivertFileVersion...:rInternalNamebdfndisf.sys`LegalCopyrightCopyright©BitDefenderSRLBrOriginalFilenamebdfndisf.sys>ProductNameBitDefendernProductVersion...DVarFileInfo$Translation
da1f27d85e0d1525f6621372e7b685e9 beep.sys
Microsoft Corporation
f934d1b230f84e1d19dd00ac5a7a83ed bridge.sys
Microsoft Corporation
b279426e3c0c344893ed78a613a73bde bthenum.sys
Microsoft Corporation
fca6f069597b62d42495191ace3fc6c1 bthmodem.sys
Microsoft Corporation
80602b8746d3738f5886ce3d67ef06b6 bthpan.sys
Microsoft Corporation
662bfd909447dd9cc15b1a1c366583b4 bthport.sys
Microsoft Corporation
bb68cebffd181e18a26112d1b9f90f3d bthprint.sys
Microsoft Corporation
61364cd71ef63b0f038b7e9df00f1efa bthusb.sys
Microsoft Corporation
90a673fc8e12a79afbed2576f6a7aaf9 cbidf2k.sys
Microsoft Corporation
0be5aef125be881c4f854c554f2b025c CCDECODE.sys
Microsoft Corporation
f3ec03299634490e97bbce94cd2954c7 cd20xrnt.sys
Microsoft Corporation
c1b486a7658353d33a10cc15211a873b cdaudio.sys
Microsoft Corporation
c885b02847f5d2fd45a24e219ed93b32 cdfs.sys
Microsoft Corporation
837eef65af62d4e8a37c41d3879f7274 cdr4_xp.sys
Sonic Solutions
579da2f9f5401f55dae2cf8779d61dfc cdralw2k.sys
Sonic Solutions
1f4260cc5b42272d71f79e570a27a4fe cdrom.sys
Microsoft Corporation
84853b3fd012251690570e9e7e43343f cercsr6.sys
Adaptec
b562592b7f5759c99e179ca467ecfb4c cinemst2.sys
Ravisent Technologies
fe47dd8fe6d7768ff94ebec6c74b2719 classpnp.sys
Microsoft Corporation
0f6c187d38d98f8df904589a5f94d411 cmbatt.sys
Microsoft Corporation
e5dcb56c533014ecbc556a8357c929d5 cmdide.sys
CMD Technology
6e4c9f21f0fae8940661144f41b13203 compbatt.sys
Microsoft Corporation
3ee529119eed34cd212a215e8c40d4b6 cpqarray.sys
Microsoft Corporation
9624293e55ad405415862b504ca95b73 cpqdap01.sys
Compaq Computer Corp
f50d9bdbb25cce075e514dc07472a22f crusoe.sys
Microsoft Corporation
e550e7418984b65a78299d248f0a7f36 dac2w2k.sys
Mylex Corporation
683789caa3864eb46125ae86ff677d34 dac960nt.sys
Microsoft Corporation
e65e2353a5d74ea89971cb918eeeb2f6 diskdump.sys
Microsoft Corporation
044452051f3e02e7963599fc8f4f3e25 disk.sys
Microsoft Corporation
d992fe1274bde0f84ad826acae022a41 dmboot.sys
Microsoft Corp
7c824cf7bbde77d95c08005717a95f6f dmio.sys
Microsoft Corp
e9317282a63ca4d188c0df5e09c6ac5f dmload.sys
Microsoft Corp
8a208dfcf89792a484e76c40e5f50b45 dmusic.sys
Microsoft Corporation
40f3b93b4e5b0126f2f5c0a7a5e22660 dpti2o.sys
Microsoft Corporation
8f5fcff8e8848afac920905fbd9d33c8 drmkaud.sys
Microsoft Corporation
6cb08593487f5701d2d2254e693eafce drmk.sys
Microsoft Corporation
e814854e6b246ccf498874839ab64d77 drvmcdb.sys
Sonic Solutions
ee83a4ebae70bc93cf14879d062f548b drvnddm.sys
Sonic Solutions
fe97d0343acfdebdd578fc67cc91fa87 dxapi.sys
Microsoft Corporation
ac7280566a7bb85cb3291f04ddc1198e dxg.sys
Microsoft Corporation
a73f5d6705b1d820c19b18782e176efd dxgthk.sys
Microsoft Corporation
3fca03cbca11269f973b70fa483c88ef e100b325.sys
Intel Corporation
d3aaf1c7c8fe9d82ada6d3acc6e32ef6 FADXP32.sys
Broadcom Corporation
38d332a6d56af32635675f132548343e fastfat.sys
Microsoft Corporation
92cdd60b6730b9f50f6a1a0c1f8cdc81 fdc.sys
Microsoft Corporation
d45926117eb9fa946a6af572fbe1caa3 fips.sys
Microsoft Corporation
9d27e7b80bfcdf1cdd9b555862d5e7f0 flpydisk.sys
Microsoft Corporation
b2cf4b0786f8212cb92ed2b50c6db6b0 fltmgr.sys
Microsoft Corporation
3e1e2bd4f39b0e2b7dc4f4d2bcc2779a fs_rec.sys
Microsoft Corporation
455f778ee14368468560bd7cb8c854d0 fsvga.sys
Microsoft Corporation
6ac26732762483366c3969c9e4d2259d ftdisk.sys
Microsoft Corporation
3a74c423cf6bcca6982715878f450a3b gagp30kx.sys
Microsoft Corporation
8182ff89c65e4d38b2de4bb0fb18564e GEARAspiWDM.sys
GEAR Software
7d074058804ad398f93ca0a08af83ff2 gtipci21.sys
Texas Instruments
573c7d0a32852b48f3058cfd8026f511 hdaudbus.sys
Windows Server DDK provider
7bd2de4c85eb4241eed57672b16a7d8d hidbth.sys
Microsoft Corporation
1af592532532a402ed7c060f6954004f hidclass.sys
Microsoft Corporation
bb1a6fb7d35a91e599973fa74a619056 hidir.sys
Microsoft Corporation
96eccf28fdbf1b2cc12725818a63628d hidparse.sys
Microsoft Corporation
ccf82c5ec8a7326c3066de870c06daf1 hidusb.sys
Microsoft Corporation
b028377dea0546a5fcfba928a8aefae0 hpn.sys
Microsoft Corporation
d03d10f7ded688fecf50f8fbf1ea9b8a HPZid412.sys
HP
89f41658929393487b6b7d13c8528ce3 HPZipr12.sys
HP
abcb05ccdbf03000354b9553820e39f8 HPZius12.sys
HP
970178e8e003eb1481293830069624b9 hsfbs2s2.sys
Conexant
2dc7c0b6175a0a8ed84a4f70199c93b5 HSF_CNXT.sys
Conexant
1225ebea76aac3c84df6c54fe5e5d8be hsfcxts2.sys
Conexant
ebb354438a4c5a3327fb97306260714a hsfdpsp2.sys
Conexant
b2dfc168d6f7512faea085253c5a37ad HSF_DP.sys
Conexant
140ba850417896b6b3322048de280368 HSFHWICH.sys
Conexant
f80a415ef82cd06ffaf0d971528ead38 http.sys
Microsoft Corporation
9368670bd426ebea5e8b18a62416ec28 i2omgmt.sys
Microsoft Corporation
f10863bf1ccc290babd1a09188ae49e0 i2omp.sys
Microsoft Corporation
4a0b06aa8943c1e332520f7440c0aa30 i8042prt.sys
Microsoft Corporation
083a052659f5310dd8b6a6cb05edcf8e imapi.sys
Microsoft Corporation
4a40e045faee58631fd8d91afc620719 ini910u.sys
Microsoft Corporation
b5466a9250342a7aa0cd1fba13420678 intelide.sys
Microsoft Corporation
8c953733d8f36eb2133f5bb58808b66b intelppm.sys
Microsoft Corporation
3bb22519a194418d5fec05d800a19ad0 ip6fw.sys
Microsoft Corporation
731f22ba402ee4b62748adaf6363c182 ipfltdrv.sys
Microsoft Corporation
b87ab476dcf76e72010632b5550955f5 ipinip.sys
Microsoft Corporation
cc748ea12c6effde940ee98098bf96bb ipnat.sys
Microsoft Corporation
23c74d75e36e7158768dd63d92789a91 ipsec.sys
Microsoft Corporation
b43b36b382aea10861f7c7a37f9d4ae2 irbus.sys
Microsoft Corporation
c93c9ff7b04d772627a3646d89f7bf89 irenum.sys
Microsoft Corporation
05a299ec56e52649b1cf2fc52d20f2d7 isapnp.sys
Microsoft Corporation
872d090ca5c306f62d1982bce6302376 iwca.sys
Intel Corporation
463c1ec80cd17420a542b7f36a36f128 kbdclass.sys
Microsoft Corporation
9ef487a186dea361aa06913a75b3fa99 kbdhid.sys
Microsoft Corporation
692bcf44383d056aed41b045a323d378 kmixer.sys
Microsoft Corporation
b467646c54cc746128904e1654c750c1 ksecdd.sys
Microsoft Corporation
0753515f78df7f271a5e61c20bcd36a1 ks.sys
Microsoft Corporation
f61a8ff029614e403e9d001a6741981f lvpopflt.sys
Logitech
?StringFileInfoBFCompanyNameLogicoolCo.,Ltd.v'FileDescriptionLogicoolAudioProcessingFilterDriver:rFileVersion...:rInternalNameLVPopflt.sys.LegalCopyright©-Logicool.Allrightsreserved.BrOriginalFilenameLVPopflt.sysRProductNameLogicoolWebcamSoftware>rProductVersion...DVarFileInfo$Translation*
8be71d7edb8c7494913722059f760dd0 LVPr2Mon.sys
Logitech
?StringFileInfoBFCompanyNameLogicoolCo.,Ltd.XFileDescriptionLogicoolProcMonDriver:rFileVersion...:rInternalNameLVPrMon.sys.LegalCopyright©-Logicool.Allrightsreserved.BrOriginalFilenameLVPrMon.sysRProductNameLogicoolWebcamSoftware>rProductVersion...DVarFileInfo$Translation&
f01fc94eb8f39f7d6e5f5b367473381e lvrs.sys
Logitech
?StringFileInfoBFCompanyNameLogicoolCo.,Ltd.FileDescriptionLogicoolKernelAudioImprovementFilterDriver:rFileVersion...tInternalNameLVRS.sys.LegalCopyright©-Logicool.Allrightsreserved.:tOriginalFilenameLVRS.sysRProductNameLogicoolWebcamSoftware>rProductVersion...DVarFileInfo$Translation*
f9183d35ad38f093d5e1aa8ba072d51b lvuvcflt.sys
Logitech
?StringFileInfoBFCompanyNameLogicoolCo.,Ltd.v'FileDescriptionLogicoolUSBVideoClassFilterDriver:rFileVersion...:rInternalNamelvuvcflt.sys.LegalCopyright©-Logicool.Allrightsreserved.BrOriginalFilenamelvuvcflt.sysRProductNameLogicoolWebcamSoftware>rProductVersion...DVarFileInfo$Translation*
caffd79278b3d8fe75fdfe1b66c2565f lvuvc.sys
Logitech
?StringFileInfoBFCompanyNameLogicoolCo.,Ltd.hFileDescriptionLogicoolUSBVideoClassDriver:rFileVersion...nInternalNamelvuvc.sys.LegalCopyright©-Logicool.Allrightsreserved.<nOriginalFilenamelvuvc.sysRProductNameLogicoolWebcamSoftware>rProductVersion...DVarFileInfo$Translation%
d68e165c3123aba3b1282eddb4213bd8 mbamswissarmy.sys
Malwarebytes Corporation
836e0e09ca9869be7eb39ef2cf3602c7 mbam.sys
Malwarebytes Corporation
d1f8be91ed4ddb671d42e473e3fe71ab mcd.sys
Microsoft Corporation
3c318b9cd391371bed62126581ee9961 mdmxsdk.sys
Conexant
a7da20ab18a1bdae28b0f349e57da0d1 mf.sys
Microsoft Corporation
4ae068242760a1fb6e1a44bf4e16afa6 mnmdd.sys
Microsoft Corporation
dfcbad3cec1c5f964962ae10e0bcc8e1 modem.sys
Microsoft Corporation
35c9e97194c8cfb8430125f8dbc34d04 mouclass.sys
Microsoft Corporation
b1c303e17fb9d46e87a98e4ba6769685 mouhid.sys
Microsoft Corporation
a80b9a0bad1b73637dbcbba7df72d3fd mountmgr.sys
Microsoft Corporation
70c14f5cca5cf73f8a645c73a01d8726 mqac.sys
Microsoft Corporation
3f4bb95e5a44f3be34824e8e7caf0737 mraid35x.sys
American Megatrends
11d42bb6206f33fbb3ba0288d3ef81bd mrxdav.sys
Microsoft Corporation
0ea4d8ed179b75f8afa7998ba22285ca mrxsmb.sys
Microsoft Corporation
c941ea2454ba8350021d774daf0f1027 msfs.sys
Microsoft Corporation
0a02c63c8b144bd8c86b103dee7c86a2 msgpc.sys
Microsoft Corporation
d1575e71568f4d9e14ca56b7b0453bf1 mskssrv.sys
Microsoft Corporation
325bb26842fc7ccc1fcce2c457317f3e mspclock.sys
Microsoft Corporation
bad59648ba099da4a17680b39730cb3d mspqm.sys
Microsoft Corporation
af5f4f3f14a8ea2c26de30f7a1e17136 mssmbios.sys
Microsoft Corporation
e53736a9e30c45fa9e7b5eac55056d1d MSTEE.sys
Microsoft Corporation
c53775780148884ac87c455489a0c070 mtlmnt5.sys
Smart Link
54886a652bf5685192141df304e923fd mtlstrm.sys
Smart Link
6dda78a0be692b61b668fab860f276cf mtxparhm.sys
Matrox Graphics
2f625d11385b1a94360bfc70aaefdee1 mup.sys
Microsoft Corporation
b538dcd9816ea35fa4f637cfc261aaa8 mutohpen.sys
Microsoft Corporation
5b50f1b2a2ed47d560577b221da734db NABTSFEC.sys
Microsoft Corporation
7ff1f1fd8609c149aa432f95a8163d97 NdisIP.sys
Microsoft Corporation
a3b80c6e0774815c362aeb5ed5ac047d ndisprot.sys
?b*StringFileInfoBv+CompanyNameWindows®CodenameLonghornDDKprovider`FileDescriptionArcNetNDISProtocolDriver`FileVersion...builtby:WinDDK:rInternalNameNDISPROT.SYS.LegalCopyrightMicrosoftCorporation.Allrightsreserved.BrOriginalFilenameNDISPROT.SYSr)ProductNameWindows®CodenameLonghornDDKdriverBProductVersion...DVarFileInfo$Translationt*
1df7f42665c94b825322fae71721130d ndis.sys
Microsoft Corporation
1ab3d00c991ab086e69db84b6c0ed78f ndistapi.sys
Microsoft Corporation
f927a4434c5028758a842943ef1a3849 ndisuio.sys
Microsoft Corporation
edc1531a49c80614b2cfda43ca8659ab ndiswan.sys
Microsoft Corporation
9282bd12dfb069d3889eb3fcc1000a9b ndproxy.sys
Microsoft Corporation
5d81cf9a2f1a3a756b66cf684911cdf0 netbios.sys
Microsoft Corporation
74b2b2f5bea5e9a3dc021d685551bd3d netbt.sys
Microsoft Corporation
98f3abc312bc0c660ba3f3b47782455e NETMD031.sys
Sony Corporation
417334447945c9e111ffd881f7bf4d08 NETMD033.sys
Sony Corporation
986acdece933131288f1957dc359865f NETMDUSB.sys
Sony Corporation
e9e47cfb2d461fa0fc75b7a74c6383ea nic1394.sys
Microsoft Corporation
be984d604d91c217355cdd3737aad25d nikedrv.sys
Diamond Multimedia Systems
1e421a6bcf2203cc61b821ada9de878b nmnt.sys
Microsoft Corporation
3182d64ae053d6fb034f44b6def8034a npfs.sys
Microsoft Corporation
05bdd706a847bbfa9fd5948cd636eb1a NSDriver.sys
Lavasoft
78a08dd6a8d65e697c18e1db01c5cdca ntfs.sys
Microsoft Corporation
576b34ceae5b7e5d9fd2775e93b3db53 ntmtlfax.sys
Smart Link
cf7e041663119e09d2e118521ada9300 nuidfltr.sys
Microsoft Corporation
73c1e1f395918bc2c6dd67af7591a3ad null.sys
Microsoft Corporation
2b298519edbfcf451d43e0f1e8f1006d nv4_mini.sys
NVIDIA Corporation
a1f88223528aadbb6374132becbbdcc1 NvAtaBus.sys
NVIDIA Corporation
30dd670c6ffa1e0ef51955c08a7fe5bf nvraid.sys
NVIDIA Corporation
b305f3fad35083837ef46a0bbce2fc57 nwlnkflt.sys
Microsoft Corporation
c99b3415198d1aab7227f2c88fd664b9 nwlnkfwd.sys
Microsoft Corporation
8b8b1be2dba4025da6786c645f77f123 nwlnkipx.sys
Microsoft Corporation
56d34a67c05e94e16377c60609741ff8 nwlnknb.sys
Microsoft Corporation
c0bb7d1615e1acbdc99757f6ceaf8cf0 nwlnkspx.sys
Microsoft Corporation
36b9b950e3d2e100970a48d8bad86740 nwrdr.sys
Microsoft Corporation
4aea5ad49cc6f35292ac0239d36a0ed4 NWWMUSB.sys
Sony Corporation
b17228142cec9b3c222239fd935a37ca omci.sys
Dell
4bb30ddc53ebc76895e38694580cdfe9 oprghdlr.sys
Microsoft Corporation
578101d3a57f00b78d6e176c712f1713 ov519cmd.sys
tH@T((VS_VERSION_INFO)n?StringFileInfodbCommentsZCompanyNameOmniVisionTechnologiesInc.=FileDescriptionDualModeUSBCameraUniversalSerialBusCameraDriver:rFileVersion...:rInternalNameovcmd.sysLegalCopyrightCopyrightOmniVisionTechnologiesInc..,.(LegalTrademarksBrOriginalFilenameovcmd.sysPrivateBuildRProductNameDualModeUSBCamerabProductVersion..SpecialBuildDVarFileInfo$Translationtlje|
4cdadec3dc1300ee1d313ea5494e6472 ov519vid.sys
tH`kVS_VERSION_INFO.n?xStringFileInfoTbCommentsCompanyNameOmniVisionTechnologies,Inc.FileDescriptionDualModeUSBCameraStreamClassMiniDrivervFileVersion...:rInternalNameovvid.sysLegalCopyrightCopyrightOmnivisionTechnologies,Inc.,-(LegalTrademarksBrOriginalFilenameovvid.sysPrivateBuildRProductNameDualModeUSBCameranProductVersion...SpecialBuildDVarFileInfo$TranslationtpW
f06d9977a75213888804eaa9ceb8598b ozscr.sys
H]VS_VERSION_INFO?(dStringFileInfo@bzCommentsOMicroSmartCardBusReaderDriver-BsupportbCompanyNameOMicroFileDescriptionOZSCRvFileVersion,,,,InternalNameOZSCRTLegalCopyrightCopyright©-hLegalTrademarksOMicroSmartCardBusReader©<nOriginalFilenameOZSCR.SYS(PrivateBuildN/A`ProductNameOMicro©SmartCardBusReader:vProductVersion,,,(SpecialBuildN/ADVarFileInfo$Translationt(h
c90018bafdc7098619a4a95b046b30f3 p3.sys
Microsoft Corporation
5575faf8f97ce5e713d108c2a58d7c7c parport.sys
Microsoft Corporation
beb3ba25197665d82ec7065b724171c6 partmgr.sys
Microsoft Corporation
70e98b3fd8e963a6a46a2e6247e0bea1 parvdm.sys
Microsoft Corporation
ccf5f451bb1a5a2a522a76e670000ff0 pciide.sys
Microsoft Corporation
52e60f29221d0d1ac16737e8dbf7c3e9 pciidex.sys
Microsoft Corporation
a219903ccf74233761d92bef471a07b1 pci.sys
Microsoft Corporation
9e89ef60e9ee05e3f2eef2da7397f1c1 pcmcia.sys
Microsoft Corporation
f50f7c27f131afe7beba13e14a3b9416 perc2hib.sys
Microsoft Corporation
6c14b9c19ba84f73d3a86dba11133101 perc2.sys
Microsoft Corporation
e82a496c3961efc6828b508c310ce98f portcls.sys
Microsoft Corporation
a32bebaf723557681bfc6bd93e98bd26 processr.sys
Microsoft Corporation
09298ec810b07e5d582cb3a3f9255424 psched.sys
Microsoft Corporation
80d317bd1c3dbc5d4fe7b1678c60cadd ptilink.sys
Parallel Technologies
e42e3433dbb4cffe8fdd91eab29aea8e pxhelp20.sys
Sonic Solutions
0a63fb54039eb5662433caba3b26dba7 ql1080.sys
QLogic Corporation
6503449e1d43a0ff0201ad5cb1b8c706 ql10wnt.sys
Microsoft Corporation
156ed0ef20c15114ca097a34a30d8a01 ql12160.sys
QLogic Corporation
70f016bebde6d29e864c1230a07cc5e6 ql1240.sys
Microsoft Corporation
907f0aeea6bc451011611e732bd31fcf ql1280.sys
QLogic Corporation
fe0d99d6f31e4fad8159f690d68ded9c rasacd.sys
Microsoft Corporation
11b4a627bc9614b885c4969bfa5ff8a6 rasl2tp.sys
Microsoft Corporation
5bc962f2654137c9909c3d4603587dee raspppoe.sys
Microsoft Corporation
efeec01b1d3cf84f16ddd24d9d9d8f99 raspptp.sys
Microsoft Corporation
fdbb1d60066fcfbb7452fd8f9829b242 raspti.sys
Microsoft Corporation
01524cd237223b18adbb48f70083f101 rawwan.sys
Microsoft Corporation
7ad224ad1a1437fe28d89cf22b17780a rdbss.sys
Microsoft Corporation
4912d5b403614ce99c28420f75353332 rdpcdd.sys
Microsoft Corporation
15cabd0f7c00c47c70124907916af3f1 rdpdr.sys
Microsoft Corporation
6728e45b66f93c08f11de2e316fc70dd rdpwd.sys
Microsoft Corporation
e9aaa0092d74a9d371659c4c38882e12 recagent.sys
Smart Link
f828dd7e1419b6653894a8f97a0094c5 redbook.sys
Microsoft Corporation
851c30df2807fcfa21e4c681a7d6440e rfcomm.sys
Microsoft Corporation
2c4fb2e9f039287767c384e46ee91030 RimSerial.sys
Research in Motion
92d33f76769a028ddc54a863eb7de4a2 RimUsb.sys
tH``VS_VERSION_INFOnn?StringFileInfobVCompanyNameResearchInMotionLimitedZFileDescriptionBlackBerryDeviceDrivertFileVersion....aInternalNameRimUsbx*LegalCopyrightCopyrightResearchInMotionLimited(LegalTrademarks<nOriginalFilenameRimUsb.rcRProductNameBlackBerryDeviceDrivertProductVersion...DVarFileInfo$Translationt*
a56fe08ec7473e8580a390bb1081cdd7 rio8drv.sys
Diamond Multimedia Systems
0a854df84c77a0be205bfeab2ae4f0ec riodrv.sys
Diamond Multimedia Systems
96f7a9a7bf0c9c0440a967440065d33c rmcast.sys
Microsoft Corporation
601844cbcf617ff8c868130ca5b2039d rndismp.sys
Microsoft Corporation
726548542afeca56257ff01eb13bb6d7 rndismpx.sys
Microsoft Corporation
d8b0b4ade32574b2d9c5cc34dc0dbbe7 rootmdm.sys
Microsoft Corporation
81aa6f0d6a2be1c550f814b036215888 s24trans.sys
Intel Corporation
0dbcc071a268e0340a2ba6bdd98bace4 s3gnbm.sys
SGraphics
16b1abe7f3e35f21dac57592b6c5d464 scdemu.sys
tHVS_VERSION_INFO?StringFileInfobHCommentshttp://www.poweriso.comRCompanyNamePowerISOComputing,Inc.VFileDescriptionPowerISOVirtualDrivevFileVersion,,,.aInternalNameSCDEMUTLegalCopyrightCopyright©-(LegalTrademarks>vOriginalFilenamescdemu.sysPrivateBuild.aProductNamescdemu:vProductVersion,,,SpecialBuildDVarFileInfo$Translationt
76c465f570e90c28942d52ccb2580a10 scsiport.sys
Microsoft Corporation
8d04819a3ce51b9eb47e5689b44d43c4 sdbus.sys
Microsoft Corporation
90a3935d05b494a5a39d37e71f09a677 secdrv.sys
Macrovision Corporation
b3c1b187fefc941f63ce0df93d02eb9f sentinel.sys
tH`>``VS_VERSION_INFOaa?vStringFileInfoB<CompanyNameSafeNet,Inc.,FileDescriptionSentinelSystemDriver(NTParalleldriver)tFileVersionSSD..x,InternalNameSentinelSystemDriver(NTParalleldriver)XLegalCopyrightSafeNet,Inc.-:iLegalTrademarksSentinelNProductNameSentinelSystemDrivertProductVersionSSD..DVarFileInfo$Translationt
0f29512ccd6bead730039fb4bd2c85ce serenum.sys
Microsoft Corporation
cca207a8896d4c6a0c9ce29a4ae411a7 serial.sys
Microsoft Corporation
0fa803c64df0914b41f807ea276bf2a6 sffdisk.sys
Microsoft Corporation
d66d22d76878bf3483a6be30183fb648 sffp_mmc.sys
Microsoft Corporation
c17c331e435ed8737525c86a7557b3ac sffp_sd.sys
Microsoft Corporation
8e6b8c671615d126fdc553d1e2de5562 sfloppy.sys
Microsoft Corporation
392834adb35deb199b03ae6a6caab23a SilvrLnk.sys
Texas Instruments
6b33d0ebd30db32e27d1d78fe946a754 sisagp.sys
Silicon Integrated Systems
866d538ebe33709a5c9f5c62b73b7d14 SLIP.sys
Microsoft Corporation
d9673011648a71ed1e1f77b831bc85e6 slnt7554.sys
Smart Link
2c1779c0feb1f4a6033600305eba623a slntamr.sys
Smart Link
f9b8e30e82ee95cf3e1d3e495599b99c slnthal.sys
Smart Link
db56bb2c55723815cf549d7fc50cfceb slwdmsup.sys
Smart Link
895be38a993b9bd5abbe570d63d88a2e smbali.sys
Microsoft Corporation
017daecf0ed3aa731313433601ec40fa smclib.sys
Microsoft Corporation
489703624dac94ed943c2abda022a1cd sonydcam.sys
Microsoft Corporation
83c0f71f86d3bdaf915685f3d568b20e sparrow.sys
Adaptec
ab8b92451ecb048a4d1de7c3ffcb4a9f splitter.sys
Microsoft Corporation
cdddec541bc3c96f91ecb48759673505 sptd.sys
Duplex Secure
76bb022c2fb6902fd5bdd4f78fc13a5d sr.sys
Microsoft Corporation
47ddfc2f003f7f9f0592c6874962a2e7 srv.sys
Microsoft Corporation
d7968049be0adbb6a57cee3960320911 sscdbhk5.sys
Sonic Solutions
c3ffd65abfb6441e7606cf74f1155273 ssrtln.sys
Sonic Solutions
305cc42945a713347f978d78566113f3 STAC97.sys
SigmaTel
77813007ba6265c4b6098187e6ed79d2 StreamIP.sys
Microsoft Corporation
3e5d89099ded9e86e5639f411693218f stream.sys
Microsoft Corporation
3941d127aef12e93addf6fe6ee027e0f swenum.sys
Microsoft Corporation
8ce882bcc6cf8a62f2b2323d95cb3d01 swmidi.sys
Microsoft Corporation
1ff3217614018630d0a6758630fc698c symc810.sys
Symbios Logic
070e001d95cf725186ef8b20335f933c symc8xx.sys
LSI Logic
80ac1c4abbe2df3b738bf15517a51f2c sym_hi.sys
LSI Logic
bf4fab949a382a8e105f46ebb4937058 sym_u3.sys
LSI Logic
8b83f3ed0f1688b4958f77cd6d2bf290 sysaudio.sys
Microsoft Corporation
fd6093e3decd925f1cffc8a0dd539d72 tape.sys
Microsoft Corporation
4e53bbcc4be37d7a4bd6ef1098c89ff7 tcpip6.sys
Microsoft Corporation
9aefa14bd6b182d61e3119fa5f436d3d tcpip.sys
Microsoft Corporation
0539d5e53587f82d1b4fd74c5be205cf tdi.sys
Microsoft Corporation
6471a66807f5e104e4885f5b67349397 tdpipe.sys
Microsoft Corporation
c56b6d0402371cf3700eb322ef3aaf61 tdtcp.sys
Microsoft Corporation
88155247177638048422893737429d9e termdd.sys
Microsoft Corporation
a1124ebc672aa3ae1b327096c1dcc346 tiehdusb.sys
Texas Instruments
699450901c5ccfd82357cbc531cedd23 tosdvd.sys
Microsoft Corporation
f2790f6af01321b172aa62f8e1e187d9 toside.sys
Microsoft Corporation
d74a8ec75305f1d3cfde7c7fc1bd62a9 tsbvcap.sys
Toshiba Corporation
8f861eda21c05857eb8197300a92501c tunmp.sys
Microsoft Corporation
d85938f272d1bcf3db3a31fc0a048928 uagp35.sys
Microsoft Corporation
5787b80c2e3c5e2f56c2a233d91fa2c9 udfs.sys
Microsoft Corporation
1b698a51cd528d8da4ffaed66dfc51b9 ultra.sys
Promise Technology
Promise Technology
Promise Technology
Promise Technology
Promise Technology
402ddc88356b1bac0ee3dd1580c76a31 update.sys
Microsoft Corporation
bee793d4a059caea55d6ac20e19b3a8f usb8023.sys
Microsoft Corporation
b6cc50279d6cd28e090a5d33244adc9a usb8023x.sys
Microsoft Corporation
d4fb6ecc60a428564ba8768b0e23c0fc usbaapl.sys
Apple
e919708db44ed8543a7c017953148330 USBAUDIO.sys
Microsoft Corporation
ce97845d2e3f0d274b8bac1ed07c6149 usbcamd2.sys
Microsoft Corporation
1c1a47b40c23358245aa8d0443b6935e usbcamd.sys
Microsoft Corporation
173f317ce0db8e21322e71b7e60a27e8 usbccgp.sys
Microsoft Corporation
596eb39b50d6ebd9b734dc4ae0544693 usbd.sys
Microsoft Corporation
65dcf09d0e37d4c6b11b5b0b76d470a7 usbehci.sys
Microsoft Corporation
1ab3cdde553b6e064d2e754efe20285c usbhub.sys
Microsoft Corporation
290913dc4f1125e5a82de52579a44c43 usbintel.sys
Microsoft Corporation
791912e524cc2cc6f50b5f2b52d1eb71 usbport.sys
Microsoft Corporation
a717c8721046828520c9edf31288fc00 usbprint.sys
Microsoft Corporation
a0b8cf9deb1184fbdd20784a58fa75d4 usbscan.sys
Microsoft Corporation
a32426d9b14a089eaa1d922e0c5801a9 usbstor.sys
Microsoft Corporation
26496f9dee2d787fc3e61ad54821ffe6 usbuhci.sys
Microsoft Corporation
63bbfca7f390f4c49ed4b96bfb1633e0 usbvideo.sys
Microsoft Corporation
b0e2cc9d642e51632438200c0654673c vackmd.sys
55e01061c74a8cefff58dc36114a8d3f vdmindvd.sys
Ravisent Technologies
0d3a8fafceacd8b7625cd549757a7df1 vga.sys
Microsoft Corporation
754292ce5848b3738281b4f3607eaef4 viaagp.sys
Microsoft Corporation
3b3efcda263b8ac14fdf9cbdd0791b2e viaide.sys
Microsoft Corporation
e28726b72c46821a28830e077d39a55b videoprt.sys
Microsoft Corporation
2121b9843e7682db7612f3bef50d590e VMCUSB.sys
Sony Corporation
4c8fcb5cc53aab716d810740fe59d025 volsnap.sys
Microsoft Corporation
f0f902220910c4fbe42a51964bd33599 w29n51.sys
Intel Corporation
aced8c149b30f8496c237bcba3727b48 wacompen.sys
Microsoft Corporation
0308aef61941e4af478fa1a0f83812f5 wadv07nt.sys
Intel Corporation
714038a8aa5de08e12062202cd7eaeb5 wadv08nt.sys
Intel Corporation
7bb3aa595e4507a788de1cdc63f4c8c4 wadv09nt.sys
Intel Corporation
36e6c405b6143d09687f4056fd9a0d10 wadv11nt.sys
Intel Corporation
e20b95baedb550f32dd489265c1da1f6 wanarp.sys
Microsoft Corporation
352fa0e98bc461ce1ce5d41f64db558d watv06nt.sys
Intel Corporation
791cc45de6e50445be72e8ad6401ff45 watv10nt.sys
Intel Corporation
d918617b46457b9ac28027722e30f647 wdf01000.sys
Microsoft Corporation
399c974dda25fd3e59f22bab787f662b wdfldr.sys
Microsoft Corporation
6768acf64b18196494413695f0c3a00f wdmaud.sys
Microsoft Corporation
2f31b7f954bed437f2c75026c65caf7b wmilib.sys
Microsoft Corporation
cf4def1bf66f06964dc0d91844239104 wpdusb.sys
Microsoft Corporation
6abe6e225adb5a751622a9cc3bc19ce8 ws2ifsl.sys
Microsoft Corporation
c98b39829c2bbd34e454150633c62c78 WSTCODEC.SYS
Microsoft Corporation
f15feafffbb3644ccc80c5da584e6311 WudfPf.sys
Microsoft Corporation
28b524262bce6de1f7ef9f510ba3985b WudfRd.sys
Microsoft Corporation
Thoughts? What should I do now? And what exactly did I do when I ran the usb? Thanks!
#23
Posted 04 May 2011 - 05:45 PM
Let's look for a newer variety of rootkit that is difficult to detect.
Please download aswMBR ( 511KB ) to your desktop.
- Double click the aswMBR.exe icon to run it
- Click the Scan button to start the scan
- On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
In addition, please also run BlueScreenView as before and post the resulting log so we can see if it's the same issue or something different.
This post has been edited by etavares: 04 May 2011 - 05:46 PM
If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.


Unified Network of Instructors and Trusted Eliminators
#24
Posted 04 May 2011 - 06:27 PM
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-04 19:22:01
-----------------------------
19:22:01.388 OS Version: Windows 5.1.2600 Service Pack 3
19:22:01.388 Number of processors: 1 586 0xD08
19:22:01.388 ComputerName: GABE UserName:
19:22:03.122 Initialize success
19:22:19.919 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:22:19.919 Disk 0 Vendor: Hitachi_HTS541080G9AT00 MB4OA61A Size: 76319MB BusType: 3
19:22:19.935 Disk 0 MBR read error 0
19:22:19.935 Disk 0 MBR scan
19:22:19.935 Disk 0 unknown MBR code
19:22:19.935 MBR BIOS signature not found 0
19:22:19.951 Disk 0 scanning sectors +156280320
19:22:19.951 Disk 0 scanning C:\WINDOWS\system32\drivers
19:22:33.107 Service scanning
19:22:37.388 Disk 0 trace - called modules:
19:22:37.435 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys spuc.sys hal.dll >>UNKNOWN [0x8a60d938]<<
19:22:37.435 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a62bab8]
19:22:37.451 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a56ed98]
19:22:37.451 Scan finished successfully
19:22:55.185 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Gabriel Smith\Desktop\MBR.dat"
19:22:55.185 The log file has been saved successfully to "C:\Documents and Settings\Gabriel Smith\Desktop\aswMBR.txt"
Here is the Blue Screen log as requested:
==================================================
Dump File : Mini041811-01.dmp
Crash Time : 4/18/2011 10:34:05 PM
Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x000000d1
Parameter 1 : 0x00030040
Parameter 2 : 0x00000002
Parameter 3 : 0x00000000
Parameter 4 : 0xb9f18af2
Caused By Driver : atapi.sys
Caused By Address : atapi.sys+5af2
File Description : IDE/ATAPI Port Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini041811-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 65,536
==================================================
What should I do now?
#25
Posted 05 May 2011 - 05:35 PM
EDIT: That's the same BSOD dump as before. Have you had a blue screen since then? If so, we need to turn on your minidumps. Please do this:
- go to the Control Panel
- Double-click the System icon
- Go to the Advanced tab
- Under Startup and Recoveryclick Settings
- Enable Write an Event to the system log
- Disable Automatically Restart
- Select the following debugging information:
- Small memory dump (64 Kb)
- Small Dump Directory : %SystemRoot%\Minidump
- Small memory dump (64 Kb)
- Confirm all and restart the computer.
This post has been edited by etavares: 05 May 2011 - 05:38 PM
If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.


Unified Network of Instructors and Trusted Eliminators
#26
Posted 06 May 2011 - 06:31 PM
I have been getting the BSOD, but I am going to restart the comp after making those changes you requested and let you know what happens.
#27
Posted 07 May 2011 - 06:29 AM
Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help
The re-run aswMBR as before and post the resulting log. If you have another BSOD, please post the Blue Screen View of the latest error.
If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.


Unified Network of Instructors and Trusted Eliminators
#28
Posted 07 May 2011 - 12:43 PM
Here is the log for the Defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 13:25 on 07/05/2011 (Gabriel Smith)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
Unable to read sptd.sys
SPTD -> Disabled (Service running -> reboot required)
-=E.O.F=-
Here is the log for aswMBR:
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-07 13:37:54
-----------------------------
13:37:54.281 OS Version: Windows 5.1.2600 Service Pack 3
13:37:54.281 Number of processors: 1 586 0xD08
13:37:54.281 ComputerName: GABE UserName:
13:37:55.562 Initialize success
13:37:57.781 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
13:37:57.796 Disk 0 Vendor: Hitachi_HTS541080G9AT00 MB4OA61A Size: 76319MB BusType: 3
13:37:59.812 Disk 0 MBR read successfully
13:37:59.812 Disk 0 MBR scan
13:37:59.812 Disk 0 unknown MBR code
13:38:01.828 Disk 0 scanning sectors +156280320
13:38:01.859 Disk 0 scanning C:\WINDOWS\system32\drivers
13:38:12.921 Service scanning
13:38:15.859 Disk 0 trace - called modules:
13:38:15.890 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
13:38:15.890 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a59c588]
13:38:15.890 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a59e940]
13:38:15.906 Scan finished successfully
13:38:27.562 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Gabriel Smith\Desktop\MBR.dat"
13:38:27.578 The log file has been saved successfully to "C:\Documents and Settings\Gabriel Smith\Desktop\aswMBR2.txt"
What should I do now?
#29
Posted 08 May 2011 - 07:12 AM
OK, that is legitimate. Please follow the instructions here to reenable your emulator.
We'll update a few security holes on your system at this point. Let me know if you're getting that BSOD again.
Step 1
Next, we need to update Java.
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
- Download the latest version of Java Runtime Environment (JRE) Version 25..
- Save it to your desktop.
- Close any programs you may have running - especially your web browser.
- Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
- Check (highlight) any item with Java Runtime Environment (JRE or J2SE) or Java in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove each Java version(s) shown below:
Java 6 Update 24 - Reboot your computer once all Java components are removed.
- Then from your desktop double-click on jre-6u25-windows-i586-s.exe to install the newest version.
Step 2
Your Firefox is really out of date. You're running 3.6.3 but the latest version is 3.6.16 or something around there. Please launch Firefox, and go to Help --> Check for Updates and let it install the latest update. It fixes some known security holes.
etavares
If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.


Unified Network of Instructors and Trusted Eliminators
#30
Posted 09 May 2011 - 11:50 AM

Help
This topic is locked

Back to top









