BleepingComputer.com: Infected with TDSS and google keeps redirecting

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

Infected with TDSS and google keeps redirecting Tried rootkit removers but still cant get rid of it.

#16 User is offline   etavares 

  • Bleepin' Remover
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 10,743
  • Joined: 16-August 08
  • Gender:Male

Posted 26 September 2011 - 07:41 PM

Hello, cyberjunkie.

That's often due to TDL/TDSS...there's a good chance you're still infected. Let's run TDSS Killer.

  • Download TDSSKiller.exe and save it to your desktop.
  • Double-click TDSSKiller.exe to run it.
  • Under "Objects to scan" ensure both "Services and Drivers" and "Boot Sectors" are checked.
  • Click Start scan and allow it to scan for Malicious objects.
  • If malicious objects are found, the default action will be Cure, ensure Cure is selected then click Continue.
  • If suspicious objects are detected, the default action will be Skip, ensure Skip is selected then click Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now and allow the computer to reboot.
  • A log will be created on your root (usually C:) drive. The log is like UtilityName.Version_Date_Time_log.txt.
    for example, C:\TDSSKiller.2.4.1.2_20.04.2010_15.31.43_log.txt
  • If no reboot is required, click on Report. A log file should appear.
  • Please post the contents of the logfile in your next reply


etavares

If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Posted Image
Unified Network of Instructors and Trusted Eliminators


#17 User is offline   cyberjunkie 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 47
  • Joined: 27-October 07
  • Gender:Male
  • Location:Amsterdam, Holland

Posted 27 September 2011 - 12:40 PM

I found out that the lag with internet sites wasn't only this PC its all the computers. I talked to my service provider and he explained their having problems connecting to the ADSL network. It should be fixed within the next 72 hours. Once its fixed the internet will load normal, and the TDSS Killer didn't find anything the log is below.


20:00:26.0718 1056 TDSS rootkit removing tool 2.6.2.0 Sep 26 2011 18:56:43
20:00:26.0843 1056 ============================================================
20:00:26.0843 1056 Current date / time: 2011/09/27 20:00:26.0843
20:00:26.0843 1056 SystemInfo:
20:00:26.0843 1056
20:00:26.0843 1056 OS Version: 5.1.2600 ServicePack: 3.0
20:00:26.0843 1056 Product type: Workstation
20:00:26.0843 1056 ComputerName: PPP-D7D51CFE4DA
20:00:26.0843 1056 UserName: ljb.3
20:00:26.0843 1056 Windows directory: C:\WINDOWS
20:00:26.0843 1056 System windows directory: C:\WINDOWS
20:00:26.0843 1056 Processor architecture: Intel x86
20:00:26.0843 1056 Number of processors: 2
20:00:26.0843 1056 Page size: 0x1000
20:00:26.0843 1056 Boot type: Normal boot
20:00:26.0843 1056 ============================================================
20:00:28.0015 1056 Initialize success
20:00:36.0406 1724 ============================================================
20:00:36.0406 1724 Scan started
20:00:36.0406 1724 Mode: Manual;
20:00:36.0406 1724 ============================================================
20:00:37.0796 1724 Abiosdsk - ok
20:00:37.0953 1724 abp480n5 - ok
20:00:38.0000 1724 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:00:38.0000 1724 ACPI - ok
20:00:38.0031 1724 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
20:00:38.0031 1724 ACPIEC - ok
20:00:38.0062 1724 adfs (73685e15ef8b0bd9c30f1af413f13d49) C:\WINDOWS\system32\drivers\adfs.sys
20:00:38.0062 1724 adfs - ok
20:00:38.0078 1724 adpu160m - ok
20:00:38.0109 1724 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
20:00:38.0109 1724 aec - ok
20:00:38.0156 1724 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
20:00:38.0156 1724 AFD - ok
20:00:38.0156 1724 Aha154x - ok
20:00:38.0171 1724 aic78u2 - ok
20:00:38.0187 1724 aic78xx - ok
20:00:38.0187 1724 AliIde - ok
20:00:38.0203 1724 amsint - ok
20:00:38.0203 1724 asc - ok
20:00:38.0218 1724 asc3350p - ok
20:00:38.0234 1724 asc3550 - ok
20:00:38.0250 1724 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:00:38.0250 1724 AsyncMac - ok
20:00:38.0265 1724 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
20:00:38.0265 1724 atapi - ok
20:00:38.0265 1724 Atdisk - ok
20:00:38.0359 1724 ati2mtag (9a6bfd014090c96a2f3708d98e5a3f40) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
20:00:38.0375 1724 ati2mtag - ok
20:00:38.0406 1724 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:00:38.0406 1724 Atmarpc - ok
20:00:38.0437 1724 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
20:00:38.0437 1724 audstub - ok
20:00:38.0484 1724 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
20:00:38.0500 1724 Beep - ok
20:00:38.0656 1724 catchme - ok
20:00:38.0671 1724 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
20:00:38.0687 1724 cbidf2k - ok
20:00:38.0718 1724 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
20:00:38.0718 1724 CCDECODE - ok
20:00:38.0718 1724 cd20xrnt - ok
20:00:38.0734 1724 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
20:00:38.0734 1724 Cdaudio - ok
20:00:38.0750 1724 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
20:00:38.0750 1724 Cdfs - ok
20:00:38.0750 1724 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:00:38.0765 1724 Cdrom - ok
20:00:38.0765 1724 Changer - ok
20:00:38.0781 1724 CmdIde - ok
20:00:38.0796 1724 Cpqarray - ok
20:00:38.0812 1724 dac2w2k - ok
20:00:38.0812 1724 dac960nt - ok
20:00:38.0828 1724 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
20:00:38.0828 1724 Disk - ok
20:00:38.0875 1724 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
20:00:38.0875 1724 dmboot - ok
20:00:38.0906 1724 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
20:00:38.0921 1724 dmio - ok
20:00:38.0937 1724 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
20:00:38.0937 1724 dmload - ok
20:00:38.0968 1724 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
20:00:38.0968 1724 DMusic - ok
20:00:38.0984 1724 dpti2o - ok
20:00:39.0015 1724 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
20:00:39.0015 1724 drmkaud - ok
20:00:39.0046 1724 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
20:00:39.0046 1724 Fastfat - ok
20:00:39.0062 1724 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
20:00:39.0062 1724 Fdc - ok
20:00:39.0062 1724 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
20:00:39.0062 1724 Fips - ok
20:00:39.0093 1724 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:00:39.0093 1724 Flpydisk - ok
20:00:39.0109 1724 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
20:00:39.0109 1724 FltMgr - ok
20:00:39.0109 1724 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:00:39.0125 1724 Fs_Rec - ok
20:00:39.0125 1724 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:00:39.0140 1724 Ftdisk - ok
20:00:39.0140 1724 FXDrv32 - ok
20:00:39.0156 1724 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:00:39.0156 1724 Gpc - ok
20:00:39.0156 1724 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:00:39.0171 1724 HDAudBus - ok
20:00:39.0171 1724 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:00:39.0171 1724 hidusb - ok
20:00:39.0187 1724 hpn - ok
20:00:39.0218 1724 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
20:00:39.0234 1724 HTTP - ok
20:00:39.0234 1724 i2omgmt - ok
20:00:39.0250 1724 i2omp - ok
20:00:39.0250 1724 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\drivers\i8042prt.sys
20:00:39.0265 1724 i8042prt - ok
20:00:39.0265 1724 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
20:00:39.0281 1724 Imapi - ok
20:00:39.0281 1724 ini910u - ok
20:00:39.0390 1724 IntcAzAudAddService (8f924588c272fdaa28cf31a9bbc21a72) C:\WINDOWS\system32\drivers\RtkHDAud.sys
20:00:39.0421 1724 IntcAzAudAddService - ok
20:00:39.0437 1724 IntelIde - ok
20:00:39.0468 1724 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
20:00:39.0468 1724 Ip6Fw - ok
20:00:39.0500 1724 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:00:39.0515 1724 IpFilterDriver - ok
20:00:39.0546 1724 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:00:39.0546 1724 IpInIp - ok
20:00:39.0546 1724 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:00:39.0562 1724 IpNat - ok
20:00:39.0562 1724 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:00:39.0562 1724 IPSec - ok
20:00:39.0578 1724 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
20:00:39.0593 1724 IRENUM - ok
20:00:39.0609 1724 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:00:39.0609 1724 isapnp - ok
20:00:39.0656 1724 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:00:39.0656 1724 Kbdclass - ok
20:00:39.0656 1724 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:00:39.0656 1724 kbdhid - ok
20:00:39.0687 1724 KL1 (94d67d49bd9503bb1d838405d80f2058) C:\WINDOWS\system32\DRIVERS\kl1.sys
20:00:39.0703 1724 KL1 - ok
20:00:39.0703 1724 kl2 (713576569667ac9e0f8556076004a96b) C:\WINDOWS\system32\DRIVERS\kl2.sys
20:00:39.0703 1724 kl2 - ok
20:00:39.0734 1724 KLIF (44ec6b3dbe167c7fa818f9918d2cbf22) C:\WINDOWS\system32\DRIVERS\klif.sys
20:00:39.0750 1724 KLIF - ok
20:00:39.0765 1724 klim5 (8d6e11bfa9927978d25b1b8029554f07) C:\WINDOWS\system32\DRIVERS\klim5.sys
20:00:39.0765 1724 klim5 - ok
20:00:39.0796 1724 klmouflt (3959530f69e19da56f1f24f2c89f1e2c) C:\WINDOWS\system32\DRIVERS\klmouflt.sys
20:00:39.0796 1724 klmouflt - ok
20:00:39.0812 1724 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
20:00:39.0812 1724 kmixer - ok
20:00:39.0812 1724 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
20:00:39.0828 1724 KSecDD - ok
20:00:39.0859 1724 L6UX2 (27207f289cbf01d46e4f5f7a261aa4ac) C:\WINDOWS\system32\Drivers\L6UX2.sys
20:00:39.0875 1724 L6UX2 - ok
20:00:39.0890 1724 lbrtfdc - ok
20:00:39.0937 1724 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
20:00:39.0937 1724 LVPr2Mon - ok
20:00:39.0953 1724 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
20:00:39.0953 1724 mnmdd - ok
20:00:40.0000 1724 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
20:00:40.0000 1724 Modem - ok
20:00:40.0000 1724 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:00:40.0000 1724 Mouclass - ok
20:00:40.0015 1724 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:00:40.0015 1724 mouhid - ok
20:00:40.0031 1724 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
20:00:40.0031 1724 MountMgr - ok
20:00:40.0031 1724 mraid35x - ok
20:00:40.0046 1724 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:00:40.0046 1724 MRxDAV - ok
20:00:40.0093 1724 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:00:40.0093 1724 MRxSmb - ok
20:00:40.0109 1724 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
20:00:40.0109 1724 Msfs - ok
20:00:40.0140 1724 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:00:40.0140 1724 MSKSSRV - ok
20:00:40.0156 1724 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:00:40.0156 1724 MSPCLOCK - ok
20:00:40.0171 1724 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
20:00:40.0171 1724 MSPQM - ok
20:00:40.0187 1724 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:00:40.0187 1724 mssmbios - ok
20:00:40.0203 1724 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
20:00:40.0218 1724 MSTEE - ok
20:00:40.0234 1724 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
20:00:40.0234 1724 Mup - ok
20:00:40.0250 1724 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
20:00:40.0250 1724 NABTSFEC - ok
20:00:40.0265 1724 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
20:00:40.0265 1724 NDIS - ok
20:00:40.0296 1724 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
20:00:40.0296 1724 NdisIP - ok
20:00:40.0312 1724 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:00:40.0312 1724 NdisTapi - ok
20:00:40.0343 1724 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:00:40.0343 1724 Ndisuio - ok
20:00:40.0343 1724 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:00:40.0343 1724 NdisWan - ok
20:00:40.0375 1724 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
20:00:40.0375 1724 NDProxy - ok
20:00:40.0390 1724 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
20:00:40.0390 1724 NetBIOS - ok
20:00:40.0390 1724 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
20:00:40.0406 1724 NetBT - ok
20:00:40.0421 1724 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
20:00:40.0421 1724 Npfs - ok
20:00:40.0453 1724 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
20:00:40.0468 1724 Ntfs - ok
20:00:40.0468 1724 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
20:00:40.0484 1724 Null - ok
20:00:40.0500 1724 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:00:40.0515 1724 NwlnkFlt - ok
20:00:40.0515 1724 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:00:40.0515 1724 NwlnkFwd - ok
20:00:40.0562 1724 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
20:00:40.0562 1724 Parport - ok
20:00:40.0562 1724 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
20:00:40.0562 1724 PartMgr - ok
20:00:40.0609 1724 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
20:00:40.0609 1724 ParVdm - ok
20:00:40.0625 1724 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
20:00:40.0625 1724 PCI - ok
20:00:40.0625 1724 PCIDump - ok
20:00:40.0656 1724 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
20:00:40.0656 1724 PCIIde - ok
20:00:40.0687 1724 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
20:00:40.0687 1724 Pcmcia - ok
20:00:40.0703 1724 PDCOMP - ok
20:00:40.0703 1724 PDFRAME - ok
20:00:40.0718 1724 PDRELI - ok
20:00:40.0718 1724 PDRFRAME - ok
20:00:40.0734 1724 perc2 - ok
20:00:40.0734 1724 perc2hib - ok
20:00:40.0781 1724 pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys
20:00:40.0796 1724 pfc - ok
20:00:40.0828 1724 PID_0928 (d2d2fa02b722336960eeae0ae7107891) C:\WINDOWS\system32\DRIVERS\LV561AV.SYS
20:00:40.0843 1724 PID_0928 - ok
20:00:40.0859 1724 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:00:40.0859 1724 PptpMiniport - ok
20:00:40.0875 1724 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
20:00:40.0875 1724 Processor - ok
20:00:40.0921 1724 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
20:00:40.0921 1724 PSched - ok
20:00:40.0921 1724 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:00:40.0937 1724 Ptilink - ok
20:00:40.0937 1724 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
20:00:40.0953 1724 PxHelp20 - ok
20:00:40.0953 1724 ql1080 - ok
20:00:40.0968 1724 Ql10wnt - ok
20:00:40.0968 1724 ql12160 - ok
20:00:40.0984 1724 ql1240 - ok
20:00:40.0984 1724 ql1280 - ok
20:00:41.0000 1724 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:00:41.0000 1724 RasAcd - ok
20:00:41.0015 1724 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:00:41.0015 1724 Rasl2tp - ok
20:00:41.0031 1724 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:00:41.0031 1724 RasPppoe - ok
20:00:41.0031 1724 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
20:00:41.0046 1724 Raspti - ok
20:00:41.0046 1724 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:00:41.0046 1724 Rdbss - ok
20:00:41.0062 1724 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:00:41.0062 1724 RDPCDD - ok
20:00:41.0078 1724 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
20:00:41.0093 1724 RDPWD - ok
20:00:41.0093 1724 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
20:00:41.0093 1724 redbook - ok
20:00:41.0125 1724 RimUsb - ok
20:00:41.0140 1724 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
20:00:41.0140 1724 RimVSerPort - ok
20:00:41.0156 1724 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
20:00:41.0171 1724 ROOTMODEM - ok
20:00:41.0203 1724 RTLE8023xp (3400495f5b219d5153c770a95499579c) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
20:00:41.0203 1724 RTLE8023xp - ok
20:00:41.0250 1724 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:00:41.0250 1724 Secdrv - ok
20:00:41.0265 1724 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
20:00:41.0265 1724 serenum - ok
20:00:41.0281 1724 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
20:00:41.0281 1724 Serial - ok
20:00:41.0312 1724 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
20:00:41.0312 1724 Sfloppy - ok
20:00:41.0312 1724 Simbad - ok
20:00:41.0343 1724 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
20:00:41.0359 1724 SLIP - ok
20:00:41.0390 1724 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
20:00:41.0390 1724 SONYPVU1 - ok
20:00:41.0390 1724 Sparrow - ok
20:00:41.0421 1724 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
20:00:41.0421 1724 splitter - ok
20:00:41.0421 1724 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
20:00:41.0421 1724 sr - ok
20:00:41.0453 1724 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
20:00:41.0468 1724 Srv - ok
20:00:41.0484 1724 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
20:00:41.0500 1724 streamip - ok
20:00:41.0531 1724 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
20:00:41.0531 1724 swenum - ok
20:00:41.0546 1724 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
20:00:41.0546 1724 swmidi - ok
20:00:41.0562 1724 symc810 - ok
20:00:41.0562 1724 symc8xx - ok
20:00:41.0578 1724 sym_hi - ok
20:00:41.0578 1724 sym_u3 - ok
20:00:41.0609 1724 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
20:00:41.0609 1724 sysaudio - ok
20:00:41.0625 1724 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:00:41.0640 1724 Tcpip - ok
20:00:41.0656 1724 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
20:00:41.0656 1724 TDPIPE - ok
20:00:41.0671 1724 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
20:00:41.0671 1724 TDTCP - ok
20:00:41.0687 1724 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
20:00:41.0687 1724 TermDD - ok
20:00:41.0703 1724 TosIde - ok
20:00:41.0718 1724 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
20:00:41.0718 1724 Udfs - ok
20:00:41.0734 1724 ultra - ok
20:00:41.0750 1724 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
20:00:41.0750 1724 Update - ok
20:00:41.0796 1724 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
20:00:41.0796 1724 usbaudio - ok
20:00:41.0812 1724 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:00:41.0812 1724 usbccgp - ok
20:00:41.0843 1724 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:00:41.0843 1724 usbehci - ok
20:00:41.0859 1724 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:00:41.0859 1724 usbhub - ok
20:00:41.0875 1724 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
20:00:41.0875 1724 usbohci - ok
20:00:41.0906 1724 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
20:00:41.0921 1724 usbprint - ok
20:00:41.0953 1724 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:00:41.0953 1724 usbscan - ok
20:00:41.0968 1724 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:00:41.0968 1724 USBSTOR - ok
20:00:42.0000 1724 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
20:00:42.0000 1724 VgaSave - ok
20:00:42.0000 1724 ViaIde - ok
20:00:42.0015 1724 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
20:00:42.0015 1724 VolSnap - ok
20:00:42.0031 1724 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:00:42.0031 1724 Wanarp - ok
20:00:42.0031 1724 WDICA - ok
20:00:42.0046 1724 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
20:00:42.0046 1724 wdmaud - ok
20:00:42.0109 1724 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
20:00:42.0109 1724 WSTCODEC - ok
20:00:42.0140 1724 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:00:42.0140 1724 WudfPf - ok
20:00:42.0156 1724 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:00:42.0156 1724 WudfRd - ok
20:00:42.0187 1724 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
20:00:42.0265 1724 \Device\Harddisk0\DR0 - ok
20:00:42.0265 1724 Boot (0x1200) (3283816abb86e6b4be01263f897c0fa2) \Device\Harddisk0\DR0\Partition0
20:00:42.0265 1724 \Device\Harddisk0\DR0\Partition0 - ok
20:00:42.0281 1724 ============================================================
20:00:42.0281 1724 Scan finished
20:00:42.0281 1724 ============================================================
20:00:42.0281 3928 Detected object count: 0
20:00:42.0281 3928 Actual detected object count: 0
20:00:47.0578 2132 Deinitialize success

This post has been edited by cyberjunkie: 27 September 2011 - 01:04 PM


#18 User is offline   etavares 

  • Bleepin' Remover
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 10,743
  • Joined: 16-August 08
  • Gender:Male

Posted 30 September 2011 - 05:20 AM

Hello, cyberjunkie.

OK, great! Let's do a final scan to confirm you're clean.



Step 1

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware

  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.



Step 2

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.

  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


etavares

If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Posted Image
Unified Network of Instructors and Trusted Eliminators


#19 User is offline   etavares 

  • Bleepin' Remover
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 10,743
  • Joined: 16-August 08
  • Gender:Male

Posted 04 October 2011 - 05:06 PM

still with me?

If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Posted Image
Unified Network of Instructors and Trusted Eliminators


#20 User is offline   etavares 

  • Bleepin' Remover
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 10,743
  • Joined: 16-August 08
  • Gender:Male

Posted 07 October 2011 - 04:57 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.

If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Posted Image
Unified Network of Instructors and Trusted Eliminators


Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users