Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Blue Screen of Death, Trojans, and Other Viruses Infecting My Computer


  • Please log in to reply
11 replies to this topic

#1 jasondarrel

jasondarrel

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 25 October 2010 - 07:53 PM

I'm posting on behalf of my less-computer savvy friend. She's running on Windows Vista and she's given me these details:

- Typical virus infected issues like the computer freezing/slowing down, and IE not responding
- She said she heard a loud screeching noise when she opened IE, I'm guessing it's part of the virus she has
- I told her to DL and run Malwarebytes and Spybot S&D, which got rid of a handful of them
- Her computer still tells her she has Trojans
- She went back to an old restore point but was still infected
- Blue Screen of Death, and she has to run Windows in safe mode
- She leaves the computer alone for a while in order to start up normally

So she's pretty much really infected with a bunch of stuff and she has the BSOD. Should I tell her to get a HijackThis log?

Thanks in advance. I'm looking for any way for her not to have to backup and reformat her computer, and this forum has helped me avoid that before.

Edit: Oops, mods can you move this to Security? Thanks, I was an idiot and I didn't think to scroll down.

Edited by Budapest, 25 October 2010 - 11:42 PM.
Moved from Vista ~BP


BC AdBot (Login to Remove)

 


#2 jasondarrel

jasondarrel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 26 October 2010 - 08:09 PM

Bump, can someone please give us a hand?

#3 jasondarrel

jasondarrel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 27 October 2010 - 10:17 PM

Bump #2

#4 killerx525

killerx525

    Bleepin' Aussie


  • Members
  • 7,220 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Melbourne, Australia
  • Local time:10:32 AM

Posted 28 October 2010 - 06:56 AM

Use this. Post a screenshot of it showing mainly the highlighted red.

>Michael 
System1: CPU- Intel Core i7-5820K @ 4.4GHz, CPU Cooler- Noctua NH-D14, RAM- G.Skill Ripjaws 16GB Kit(4Gx4) DDR3 2133MHz, SSD/HDD- Samsung 850 EVO 250GB/Western Digital Caviar Black 1TB/Seagate Barracuada 3TB, GPU- 2x EVGA GTX980 Superclocked @1360/MHz1900MHz, Motherboard- Asus X99 Deluxe, Case- Custom Mac G5, PSU- EVGA P2-1000W, Soundcard- Realtek High Definition Audio, OS- Windows 10 Pro 64-Bit
Games: APB: Reloaded, Hours played: 3100+  System2: Late 2011 Macbook Pro 15inch   OFw63FY.png


#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:32 PM

Posted 28 October 2010 - 07:17 AM

Please follow these instructions: How to remove Google Redirects or the TDSS, TDL3, Alureon rootkit using TDSSKiller
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • When the program opens, click the Start Scan button.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure is selected, then click Continue > Reboot now to finish the cleaning process. <- Important!!
    Note: If 'Suspicious' objects are detected, you will be given the option to Skip or Quarantine. Skip will be the default selection.
  • A log file named TDSSKiller_version_date_time_log.txt will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.
-- For any files detected as 'Suspicious' (except those identified as Forged to be cured after reboot) get a second opinion by submitting to Jotti's virusscan or VirusTotal. In the "File to upload & scan" box, browse to the location of the suspicious file and submit (upload) it for scanning/analysis.


Please download Norman Malware Cleaner and save to your desktop.
alternate download link
Note: If you previously used Norman, delete that version and download it again as the tool is frequently updated!
  • Be sure to read all the information Norman provides on that same page.
  • Double-click on Norman_Malware_Cleaner.exe to start.
    The tool is very slow to load as it uses a special driver. This is normal so please be patient.
  • Read the End User License Agreement and click the Accept button to open the scanning window.
  • Click Start Scan to begin.
  • In some cases Norman Malware Cleaner may require that you restart the computer to completely remove an infection. If prompted, reboot to ensure that all infections are removed.
  • After the scan has finished, a log file a log file named NFix_date_time (i.e. NFix_2009-06-22_07-08-56.log) will be created on your desktop with the results.
  • Copy and paste the contents of that file in your next reply.
-- Note: If you need to scan usb flash drives and/or other removable drives, use the Add button to browse to the drives location, click on the drive to highlight and choose Ok.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#6 jasondarrel

jasondarrel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 01 November 2010 - 11:27 PM

Results of the rootkit scan, no infections:

2010/10/31 17:20:46.0240 TDSS rootkit removing tool 2.4.5.1 Oct 26 2010 11:28:49
2010/10/31 17:20:46.0240 ================================================================================
2010/10/31 17:20:46.0240 SystemInfo:
2010/10/31 17:20:46.0240
2010/10/31 17:20:46.0240 OS Version: 6.0.6002 ServicePack: 2.0
2010/10/31 17:20:46.0241 Product type: Workstation
2010/10/31 17:20:46.0241 ComputerName: OWNER-PC
2010/10/31 17:20:46.0241 UserName: Michelle
2010/10/31 17:20:46.0241 Windows directory: C:\Windows
2010/10/31 17:20:46.0241 System windows directory: C:\Windows
2010/10/31 17:20:46.0241 Running under WOW64
2010/10/31 17:20:46.0241 Processor architecture: Intel x64
2010/10/31 17:20:46.0241 Number of processors: 4
2010/10/31 17:20:46.0241 Page size: 0x1000
2010/10/31 17:20:46.0241 Boot type: Normal boot
2010/10/31 17:20:46.0241 ================================================================================
2010/10/31 17:20:46.0242 Utility is running under WOW64
2010/10/31 17:20:47.0067 Initialize success
2010/10/31 17:20:53.0273 ================================================================================
2010/10/31 17:20:53.0273 Scan started
2010/10/31 17:20:53.0273 Mode: Manual;
2010/10/31 17:20:53.0273 ================================================================================
2010/10/31 17:20:53.0788 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
2010/10/31 17:20:53.0913 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
2010/10/31 17:20:53.0993 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
2010/10/31 17:20:54.0043 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
2010/10/31 17:20:54.0073 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
2010/10/31 17:20:54.0174 AFD (12415ccfd3e7cec55b5184e67b039fe4) C:\Windows\system32\drivers\afd.sys
2010/10/31 17:20:54.0255 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
2010/10/31 17:20:54.0306 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
2010/10/31 17:20:54.0365 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
2010/10/31 17:20:54.0388 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
2010/10/31 17:20:54.0414 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
2010/10/31 17:20:54.0490 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
2010/10/31 17:20:54.0547 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
2010/10/31 17:20:54.0597 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/10/31 17:20:54.0666 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys
2010/10/31 17:20:54.0759 Avgfwfd (705417fd6c165ccf926aca943b478d68) C:\Windows\system32\DRIVERS\avgfwd6a.sys
2010/10/31 17:20:54.0870 AVGIDSDriver (4f1ae7de0cc6615323b7b959aa973b01) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
2010/10/31 17:20:54.0911 AVGIDSEH (a14e9123764dcb4386066bd9cdccde8d) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
2010/10/31 17:20:54.0933 AVGIDSFilter (dd0aa3178b548a6d95e1d35d675de2cd) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
2010/10/31 17:20:54.0979 Avgldx64 (ef415e445e5376624ed78685ee9647d4) C:\Windows\system32\DRIVERS\avgldx64.sys
2010/10/31 17:20:55.0069 Avgmfx64 (f5ffa3053d26c55edc112e66197eed09) C:\Windows\system32\DRIVERS\avgmfx64.sys
2010/10/31 17:20:55.0137 Avgrkx64 (5b3f127b26c08b1c7df5c5f111ca4030) C:\Windows\system32\DRIVERS\avgrkx64.sys
2010/10/31 17:20:55.0221 Avgtdia (ee472479301fef0b6a17e16d8a0deceb) C:\Windows\system32\DRIVERS\avgtdia.sys
2010/10/31 17:20:55.0278 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
2010/10/31 17:20:55.0295 bowser (8b2b19031d0aeade6e1b933df1acba7e) C:\Windows\system32\DRIVERS\bowser.sys
2010/10/31 17:20:55.0351 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
2010/10/31 17:20:55.0373 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
2010/10/31 17:20:55.0417 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
2010/10/31 17:20:55.0456 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
2010/10/31 17:20:55.0485 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
2010/10/31 17:20:55.0505 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
2010/10/31 17:20:55.0532 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
2010/10/31 17:20:55.0714 CAXHWBS3 (acbadab44c65e96983dbf5633318c355) C:\Windows\system32\DRIVERS\CAXHWBS3.sys
2010/10/31 17:20:55.0757 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
2010/10/31 17:20:55.0795 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
2010/10/31 17:20:55.0868 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
2010/10/31 17:20:55.0917 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
2010/10/31 17:20:56.0026 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
2010/10/31 17:20:56.0106 COH_Mon (4ac0614de43f8787ec1556560c752af8) C:\Windows\system32\Drivers\COH_Mon.sys
2010/10/31 17:20:56.0134 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
2010/10/31 17:20:56.0154 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
2010/10/31 17:20:56.0243 CtClsFlt (b18ab4f8f194e9f0e35d3af5af578d14) C:\Windows\system32\DRIVERS\CtClsFlt.sys
2010/10/31 17:20:56.0337 DfsC (36cd31121f228e7e79bae60aa45764c6) C:\Windows\system32\Drivers\dfsc.sys
2010/10/31 17:20:56.0423 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
2010/10/31 17:20:56.0514 Dot4 (74c02b1717740c3b8039539e23e4b53f) C:\Windows\system32\DRIVERS\Dot4.sys
2010/10/31 17:20:56.0570 Dot4Print (08321d1860235bf42cf2854234337aea) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2010/10/31 17:20:56.0608 dot4usb (4adccf0124f2b6911d3786a5d0e779e5) C:\Windows\system32\DRIVERS\dot4usb.sys
2010/10/31 17:20:56.0693 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
2010/10/31 17:20:56.0779 DXGKrnl (1d96e28ebcd96ad1b44a3fd02ca6433d) C:\Windows\System32\drivers\dxgkrnl.sys
2010/10/31 17:20:56.0887 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
2010/10/31 17:20:56.0984 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
2010/10/31 17:20:57.0079 eeCtrl (8ecb5d35f400706016931bd25ae1b554) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
2010/10/31 17:20:57.0148 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
2010/10/31 17:20:57.0198 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
2010/10/31 17:20:57.0286 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
2010/10/31 17:20:57.0333 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
2010/10/31 17:20:57.0382 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
2010/10/31 17:20:57.0441 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
2010/10/31 17:20:57.0468 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
2010/10/31 17:20:57.0502 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/10/31 17:20:57.0540 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
2010/10/31 17:20:57.0642 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
2010/10/31 17:20:57.0694 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
2010/10/31 17:20:57.0802 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2010/10/31 17:20:57.0923 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/10/31 17:20:58.0019 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
2010/10/31 17:20:58.0065 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
2010/10/31 17:20:58.0138 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
2010/10/31 17:20:58.0221 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
2010/10/31 17:20:58.0334 HSF_DP (c0a9096a732b912bfe1504d17c6b2385) C:\Windows\system32\DRIVERS\CAX_DP.sys
2010/10/31 17:20:58.0419 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
2010/10/31 17:20:58.0471 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
2010/10/31 17:20:58.0518 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/10/31 17:20:58.0593 iaStor (3c4cd264b04d79a43a0f124c067ba08e) C:\Windows\system32\drivers\iastor.sys
2010/10/31 17:20:58.0628 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
2010/10/31 17:20:58.0776 IDSvia64 (6baf60feca582235b3cbf3c9cdecdd98) C:\PROGRA~3\Symantec\DEFINI~1\SymcData\ipsdefs\20100422.001\IDSvia64.sys
2010/10/31 17:20:58.0809 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
2010/10/31 17:20:58.0900 IntcAzAudAddService (46cb3abe8150e7b181e86d4906de17e8) C:\Windows\system32\drivers\RTKVHD64.sys
2010/10/31 17:20:59.0024 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
2010/10/31 17:20:59.0052 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
2010/10/31 17:20:59.0132 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/10/31 17:20:59.0190 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
2010/10/31 17:20:59.0214 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
2010/10/31 17:20:59.0276 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
2010/10/31 17:20:59.0304 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
2010/10/31 17:20:59.0342 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/10/31 17:20:59.0366 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
2010/10/31 17:20:59.0397 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
2010/10/31 17:20:59.0424 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/10/31 17:20:59.0457 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/10/31 17:20:59.0488 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
2010/10/31 17:20:59.0522 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
2010/10/31 17:20:59.0610 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
2010/10/31 17:20:59.0654 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
2010/10/31 17:20:59.0681 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
2010/10/31 17:20:59.0706 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
2010/10/31 17:20:59.0743 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
2010/10/31 17:20:59.0820 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2010/10/31 17:20:59.0841 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
2010/10/31 17:20:59.0878 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
2010/10/31 17:20:59.0920 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
2010/10/31 17:20:59.0960 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
2010/10/31 17:20:59.0988 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
2010/10/31 17:21:00.0015 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
2010/10/31 17:21:00.0042 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
2010/10/31 17:21:00.0089 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
2010/10/31 17:21:00.0124 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
2010/10/31 17:21:00.0150 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
2010/10/31 17:21:00.0187 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
2010/10/31 17:21:00.0213 mrxsmb (d58d129e26705e83a4deba7177eb7972) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/10/31 17:21:00.0252 mrxsmb10 (d5be5c14e0f1dc489f5bb2a67983f630) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/10/31 17:21:00.0284 mrxsmb20 (09a2990c3b293c212816c9bc0d7c200e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/10/31 17:21:00.0307 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
2010/10/31 17:21:00.0334 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
2010/10/31 17:21:00.0360 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
2010/10/31 17:21:00.0417 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
2010/10/31 17:21:00.0448 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
2010/10/31 17:21:00.0497 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/10/31 17:21:00.0547 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
2010/10/31 17:21:00.0588 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
2010/10/31 17:21:00.0630 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/10/31 17:21:00.0680 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
2010/10/31 17:21:00.0695 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
2010/10/31 17:21:00.0769 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
2010/10/31 17:21:00.0937 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
2010/10/31 17:21:01.0047 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/10/31 17:21:01.0069 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/10/31 17:21:01.0089 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/10/31 17:21:01.0112 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
2010/10/31 17:21:01.0180 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
2010/10/31 17:21:01.0226 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
2010/10/31 17:21:01.0274 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
2010/10/31 17:21:01.0312 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
2010/10/31 17:21:01.0338 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
2010/10/31 17:21:01.0384 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
2010/10/31 17:21:01.0438 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
2010/10/31 17:21:01.0891 nvlddmkm (4e547afc67317f7b38c498f7f1fa570c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/10/31 17:21:02.0235 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
2010/10/31 17:21:02.0271 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
2010/10/31 17:21:02.0309 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
2010/10/31 17:21:02.0407 ohci1394 (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/10/31 17:21:02.0453 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
2010/10/31 17:21:02.0496 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
2010/10/31 17:21:02.0530 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
2010/10/31 17:21:02.0556 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
2010/10/31 17:21:02.0590 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
2010/10/31 17:21:02.0648 PdiPorts (4d83baaf24ebacaf01ff97531f0f5d0b) C:\Windows\system32\DRIVERS\PdiPorts.sys
2010/10/31 17:21:02.0680 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
2010/10/31 17:21:02.0826 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
2010/10/31 17:21:02.0854 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
2010/10/31 17:21:02.0935 Ps2 (1d0a3f565397d08707f3d75b88586645) C:\Windows\system32\DRIVERS\PS2.sys
2010/10/31 17:21:03.0015 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
2010/10/31 17:21:03.0051 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
2010/10/31 17:21:03.0109 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
2010/10/31 17:21:03.0142 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
2010/10/31 17:21:03.0159 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
2010/10/31 17:21:03.0186 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/10/31 17:21:03.0222 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/10/31 17:21:03.0258 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
2010/10/31 17:21:03.0301 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
2010/10/31 17:21:03.0335 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/10/31 17:21:03.0365 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
2010/10/31 17:21:03.0382 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
2010/10/31 17:21:03.0445 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
2010/10/31 17:21:03.0518 RLDesignVirtualAudioCableWdm (cf1eee81fd32238fc51adca9f2266b7d) C:\Windows\system32\DRIVERS\livecamv.sys
2010/10/31 17:21:03.0552 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
2010/10/31 17:21:03.0600 rt61x64 (51f0fd171844de3d9b9a0f4492db7aa4) C:\Windows\system32\DRIVERS\WMP54Gv41x64.sys
2010/10/31 17:21:03.0631 RTL8169 (82b66abf055611024e5dbb9fa556c11d) C:\Windows\system32\DRIVERS\Rtlh64.sys
2010/10/31 17:21:03.0664 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
2010/10/31 17:21:03.0708 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2010/10/31 17:21:03.0744 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys
2010/10/31 17:21:03.0766 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys
2010/10/31 17:21:03.0789 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
2010/10/31 17:21:03.0846 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
2010/10/31 17:21:03.0869 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
2010/10/31 17:21:03.0891 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
2010/10/31 17:21:03.0911 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
2010/10/31 17:21:03.0959 Sftfs (72cd52403efc137290cb5a328510ebca) C:\Windows\system32\DRIVERS\Sftfslh.sys
2010/10/31 17:21:04.0017 Sftplay (31a36ef71af36eabcc4b4f8ab8f76465) C:\Windows\system32\DRIVERS\Sftplaylh.sys
2010/10/31 17:21:04.0054 Sftredir (2d969194fcc8eb41ed1d52863bfe7f52) C:\Windows\system32\DRIVERS\Sftredirlh.sys
2010/10/31 17:21:04.0073 Sftvol (08b36d2f63af3ca2248458a4280c0c50) C:\Windows\system32\DRIVERS\Sftvollh.sys
2010/10/31 17:21:04.0108 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
2010/10/31 17:21:04.0137 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
2010/10/31 17:21:04.0186 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
2010/10/31 17:21:04.0268 SndTAudio (f1fb29b1efb60ba79ffe408bca77ef44) C:\Windows\system32\drivers\SndTAudio.sys
2010/10/31 17:21:04.0350 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
2010/10/31 17:21:04.0391 SRTSP (7e4cc24a23262a84ae99dbffef69a6b0) C:\Windows\system32\Drivers\SRTSP64.SYS
2010/10/31 17:21:04.0437 SRTSPL (8b1dedeba049a3e1daf8219eec87eb00) C:\Windows\system32\Drivers\SRTSPL64.SYS
2010/10/31 17:21:04.0481 SRTSPX (3db35652e4460da6730bb44908fa39cb) C:\Windows\system32\Drivers\SRTSPX64.SYS
2010/10/31 17:21:04.0521 srv (8cd33a47ca02c79038b669f31f95bdac) C:\Windows\system32\DRIVERS\srv.sys
2010/10/31 17:21:04.0553 srv2 (1bedf533096c56e70f87e3e3ee02caf5) C:\Windows\system32\DRIVERS\srv2.sys
2010/10/31 17:21:04.0569 srvnet (2b8c340f830c465f514d966f7e6a822f) C:\Windows\system32\DRIVERS\srvnet.sys
2010/10/31 17:21:04.0637 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
2010/10/31 17:21:04.0683 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
2010/10/31 17:21:04.0759 SYMDNS (9e65ac70e4528ab6db53b5f1bb1a3520) C:\Windows\System32\Drivers\SYMDNS.SYS
2010/10/31 17:21:04.0790 SymEvent (70c8d165063eb76f1a373b74456d2aab) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2010/10/31 17:21:04.0852 SYMFW (b9e27e6a85bcecaec4b82649a9e99ae5) C:\Windows\System32\Drivers\SYMFW.SYS
2010/10/31 17:21:04.0873 SymIM (93526d381fcff03e666b767e2a920ac9) C:\Windows\system32\DRIVERS\SymIMv.sys
2010/10/31 17:21:04.0895 SYMNDISV (7d9f8388933a31a8468751b556bb1c41) C:\Windows\System32\Drivers\SYMNDISV.SYS
2010/10/31 17:21:04.0927 SYMREDRV (c082fc0d3dd1f990d120049a2285b33c) C:\Windows\System32\Drivers\SYMREDRV.SYS
2010/10/31 17:21:04.0969 SYMTDI (4ea607f6fb7288acf624fa4078f93ac7) C:\Windows\System32\Drivers\SYMTDI.SYS
2010/10/31 17:21:05.0008 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
2010/10/31 17:21:05.0035 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
2010/10/31 17:21:05.0106 Tcpip (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\drivers\tcpip.sys
2010/10/31 17:21:05.0171 Tcpip6 (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\DRIVERS\tcpip.sys
2010/10/31 17:21:05.0217 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
2010/10/31 17:21:05.0243 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
2010/10/31 17:21:05.0264 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
2010/10/31 17:21:05.0295 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
2010/10/31 17:21:05.0336 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
2010/10/31 17:21:05.0409 TfFsMon (21ac1ffd8f59b0ebfbbb2c3467e9f2cf) C:\Windows\system32\drivers\TfFsMon.sys
2010/10/31 17:21:05.0427 TfNetMon (b0ebe0ce99e4751cf7637a09fead7eda) C:\Windows\system32\drivers\TfNetMon.sys
2010/10/31 17:21:05.0470 TfSysMon (d6e991dcdd91323d979878025f0ceaea) C:\Windows\system32\drivers\TfSysMon.sys
2010/10/31 17:21:05.0547 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/10/31 17:21:05.0611 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
2010/10/31 17:21:05.0680 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
2010/10/31 17:21:05.0721 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
2010/10/31 17:21:05.0774 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
2010/10/31 17:21:05.0826 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
2010/10/31 17:21:05.0868 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
2010/10/31 17:21:05.0910 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
2010/10/31 17:21:05.0956 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
2010/10/31 17:21:05.0997 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
2010/10/31 17:21:06.0112 USBAAPL64 (5cf1ead086176dd3348e920a40bed03d) C:\Windows\system32\Drivers\usbaapl64.sys
2010/10/31 17:21:06.0186 usbaudio (c6ba890de6e41857fbe84175519cae7d) C:\Windows\system32\drivers\usbaudio.sys
2010/10/31 17:21:06.0254 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/10/31 17:21:06.0297 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
2010/10/31 17:21:06.0347 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
2010/10/31 17:21:06.0413 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
2010/10/31 17:21:06.0452 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
2010/10/31 17:21:06.0498 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
2010/10/31 17:21:06.0574 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
2010/10/31 17:21:06.0641 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/10/31 17:21:06.0709 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/10/31 17:21:06.0789 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys
2010/10/31 17:21:06.0835 V0540Dev (29aee96165e9a2ff625693e47a7a7719) C:\Windows\system32\DRIVERS\V0540Vid.sys
2010/10/31 17:21:06.0918 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/10/31 17:21:06.0947 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
2010/10/31 17:21:06.0976 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
2010/10/31 17:21:07.0047 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
2010/10/31 17:21:07.0093 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
2010/10/31 17:21:07.0158 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
2010/10/31 17:21:07.0202 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
2010/10/31 17:21:07.0252 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
2010/10/31 17:21:07.0277 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/31 17:21:07.0293 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/31 17:21:07.0331 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
2010/10/31 17:21:07.0376 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
2010/10/31 17:21:07.0507 winachsf (0208b357535431071193a7b534f5cfef) C:\Windows\system32\DRIVERS\CAX_CNXT.sys
2010/10/31 17:21:07.0613 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
2010/10/31 17:21:07.0670 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
2010/10/31 17:21:07.0719 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/10/31 17:21:07.0754 XAudio (f22e443518bc599d12888daf292a56d8) C:\Windows\system32\DRIVERS\xaudio64.sys
2010/10/31 17:21:08.0066 ================================================================================
2010/10/31 17:21:08.0066 Scan finished
2010/10/31 17:21:08.0066 ================================================================================
2010/10/31 17:21:22.0979 ================================================================================
2010/10/31 17:21:22.0979 Scan started
2010/10/31 17:21:22.0979 Mode: Manual;
2010/10/31 17:21:22.0979 ================================================================================
2010/10/31 17:21:23.0318 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
2010/10/31 17:21:23.0385 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
2010/10/31 17:21:23.0416 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
2010/10/31 17:21:23.0449 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
2010/10/31 17:21:23.0479 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
2010/10/31 17:21:23.0529 AFD (12415ccfd3e7cec55b5184e67b039fe4) C:\Windows\system32\drivers\afd.sys
2010/10/31 17:21:23.0553 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
2010/10/31 17:21:23.0587 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
2010/10/31 17:21:23.0621 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
2010/10/31 17:21:23.0644 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
2010/10/31 17:21:23.0669 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
2010/10/31 17:21:23.0704 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
2010/10/31 17:21:23.0820 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
2010/10/31 17:21:23.0853 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/10/31 17:21:23.0905 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys
2010/10/31 17:21:23.0973 Avgfwfd (705417fd6c165ccf926aca943b478d68) C:\Windows\system32\DRIVERS\avgfwd6a.sys
2010/10/31 17:21:24.0059 AVGIDSDriver (4f1ae7de0cc6615323b7b959aa973b01) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
2010/10/31 17:21:24.0100 AVGIDSEH (a14e9123764dcb4386066bd9cdccde8d) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
2010/10/31 17:21:24.0148 AVGIDSFilter (dd0aa3178b548a6d95e1d35d675de2cd) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
2010/10/31 17:21:24.0193 Avgldx64 (ef415e445e5376624ed78685ee9647d4) C:\Windows\system32\DRIVERS\avgldx64.sys
2010/10/31 17:21:24.0258 Avgmfx64 (f5ffa3053d26c55edc112e66197eed09) C:\Windows\system32\DRIVERS\avgmfx64.sys
2010/10/31 17:21:24.0318 Avgrkx64 (5b3f127b26c08b1c7df5c5f111ca4030) C:\Windows\system32\DRIVERS\avgrkx64.sys
2010/10/31 17:21:24.0352 Avgtdia (ee472479301fef0b6a17e16d8a0deceb) C:\Windows\system32\DRIVERS\avgtdia.sys
2010/10/31 17:21:24.0392 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
2010/10/31 17:21:24.0406 bowser (8b2b19031d0aeade6e1b933df1acba7e) C:\Windows\system32\DRIVERS\bowser.sys
2010/10/31 17:21:24.0457 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
2010/10/31 17:21:24.0479 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
2010/10/31 17:21:24.0523 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
2010/10/31 17:21:24.0553 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
2010/10/31 17:21:24.0583 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
2010/10/31 17:21:24.0603 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
2010/10/31 17:21:24.0621 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
2010/10/31 17:21:24.0744 CAXHWBS3 (acbadab44c65e96983dbf5633318c355) C:\Windows\system32\DRIVERS\CAXHWBS3.sys
2010/10/31 17:21:24.0771 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
2010/10/31 17:21:24.0809 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
2010/10/31 17:21:24.0832 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
2010/10/31 17:21:24.0865 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
2010/10/31 17:21:24.0907 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
2010/10/31 17:21:24.0946 COH_Mon (4ac0614de43f8787ec1556560c752af8) C:\Windows\system32\Drivers\COH_Mon.sys
2010/10/31 17:21:24.0973 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
2010/10/31 17:21:24.0989 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
2010/10/31 17:21:25.0040 CtClsFlt (b18ab4f8f194e9f0e35d3af5af578d14) C:\Windows\system32\DRIVERS\CtClsFlt.sys
2010/10/31 17:21:25.0084 DfsC (36cd31121f228e7e79bae60aa45764c6) C:\Windows\system32\Drivers\dfsc.sys
2010/10/31 17:21:25.0129 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
2010/10/31 17:21:25.0170 Dot4 (74c02b1717740c3b8039539e23e4b53f) C:\Windows\system32\DRIVERS\Dot4.sys
2010/10/31 17:21:25.0201 Dot4Print (08321d1860235bf42cf2854234337aea) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2010/10/31 17:21:25.0223 dot4usb (4adccf0124f2b6911d3786a5d0e779e5) C:\Windows\system32\DRIVERS\dot4usb.sys
2010/10/31 17:21:25.0258 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
2010/10/31 17:21:25.0303 DXGKrnl (1d96e28ebcd96ad1b44a3fd02ca6433d) C:\Windows\System32\drivers\dxgkrnl.sys
2010/10/31 17:21:25.0343 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
2010/10/31 17:21:25.0380 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
2010/10/31 17:21:25.0469 eeCtrl (8ecb5d35f400706016931bd25ae1b554) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
2010/10/31 17:21:25.0537 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
2010/10/31 17:21:25.0571 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
2010/10/31 17:21:25.0642 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
2010/10/31 17:21:25.0681 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
2010/10/31 17:21:25.0713 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
2010/10/31 17:21:25.0764 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
2010/10/31 17:21:25.0816 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
2010/10/31 17:21:25.0858 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/10/31 17:21:25.0896 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
2010/10/31 17:21:25.0923 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
2010/10/31 17:21:25.0958 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
2010/10/31 17:21:25.0999 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2010/10/31 17:21:26.0079 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/10/31 17:21:26.0108 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
2010/10/31 17:21:26.0130 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
2010/10/31 17:21:26.0169 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
2010/10/31 17:21:26.0227 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
2010/10/31 17:21:26.0321 HSF_DP (c0a9096a732b912bfe1504d17c6b2385) C:\Windows\system32\DRIVERS\CAX_DP.sys
2010/10/31 17:21:26.0375 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
2010/10/31 17:21:26.0410 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
2010/10/31 17:21:26.0449 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/10/31 17:21:26.0492 iaStor (3c4cd264b04d79a43a0f124c067ba08e) C:\Windows\system32\drivers\iastor.sys
2010/10/31 17:21:26.0535 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
2010/10/31 17:21:26.0641 IDSvia64 (6baf60feca582235b3cbf3c9cdecdd98) C:\PROGRA~3\Symantec\DEFINI~1\SymcData\ipsdefs\20100422.001\IDSvia64.sys
2010/10/31 17:21:26.0665 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
2010/10/31 17:21:26.0732 IntcAzAudAddService (46cb3abe8150e7b181e86d4906de17e8) C:\Windows\system32\drivers\RTKVHD64.sys
2010/10/31 17:21:26.0763 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
2010/10/31 17:21:26.0783 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
2010/10/31 17:21:26.0830 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/10/31 17:21:26.0871 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
2010/10/31 17:21:26.0895 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
2010/10/31 17:21:26.0932 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
2010/10/31 17:21:26.0952 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
2010/10/31 17:21:26.0990 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/10/31 17:21:27.0013 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
2010/10/31 17:21:27.0036 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
2010/10/31 17:21:27.0064 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/10/31 17:21:27.0097 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/10/31 17:21:27.0169 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
2010/10/31 17:21:27.0195 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
2010/10/31 17:21:27.0249 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
2010/10/31 17:21:27.0301 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
2010/10/31 17:21:27.0337 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
2010/10/31 17:21:27.0362 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
2010/10/31 17:21:27.0391 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
2010/10/31 17:21:27.0451 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2010/10/31 17:21:27.0472 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
2010/10/31 17:21:27.0510 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
2010/10/31 17:21:27.0543 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
2010/10/31 17:21:27.0574 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
2010/10/31 17:21:27.0594 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
2010/10/31 17:21:27.0613 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
2010/10/31 17:21:27.0631 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
2010/10/31 17:21:27.0661 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
2010/10/31 17:21:27.0689 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
2010/10/31 17:21:27.0722 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
2010/10/31 17:21:27.0760 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
2010/10/31 17:21:27.0794 mrxsmb (d58d129e26705e83a4deba7177eb7972) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/10/31 17:21:27.0825 mrxsmb10 (d5be5c14e0f1dc489f5bb2a67983f630) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/10/31 17:21:27.0856 mrxsmb20 (09a2990c3b293c212816c9bc0d7c200e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/10/31 17:21:27.0880 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
2010/10/31 17:21:27.0899 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
2010/10/31 17:21:27.0923 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
2010/10/31 17:21:27.0948 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
2010/10/31 17:21:27.0980 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
2010/10/31 17:21:28.0003 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/10/31 17:21:28.0020 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
2010/10/31 17:21:28.0060 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
2010/10/31 17:21:28.0086 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/10/31 17:21:28.0103 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
2010/10/31 17:21:28.0116 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
2010/10/31 17:21:28.0158 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
2010/10/31 17:21:28.0292 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
2010/10/31 17:21:28.0312 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/10/31 17:21:28.0325 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/10/31 17:21:28.0344 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/10/31 17:21:28.0359 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
2010/10/31 17:21:28.0378 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
2010/10/31 17:21:28.0406 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
2010/10/31 17:21:28.0456 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
2010/10/31 17:21:28.0485 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
2010/10/31 17:21:28.0503 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
2010/10/31 17:21:28.0546 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
2010/10/31 17:21:28.0564 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
2010/10/31 17:21:28.0932 nvlddmkm (4e547afc67317f7b38c498f7f1fa570c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/10/31 17:21:29.0024 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
2010/10/31 17:21:29.0069 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
2010/10/31 17:21:29.0107 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
2010/10/31 17:21:29.0196 ohci1394 (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/10/31 17:21:29.0276 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
2010/10/31 17:21:29.0319 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
2010/10/31 17:21:29.0395 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
2010/10/31 17:21:29.0445 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
2010/10/31 17:21:29.0479 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
2010/10/31 17:21:29.0545 PdiPorts (4d83baaf24ebacaf01ff97531f0f5d0b) C:\Windows\system32\DRIVERS\PdiPorts.sys
2010/10/31 17:21:29.0604 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
2010/10/31 17:21:29.0716 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
2010/10/31 17:21:29.0743 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
2010/10/31 17:21:29.0799 Ps2 (1d0a3f565397d08707f3d75b88586645) C:\Windows\system32\DRIVERS\PS2.sys
2010/10/31 17:21:29.0838 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
2010/10/31 17:21:29.0884 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
2010/10/31 17:21:29.0924 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
2010/10/31 17:21:29.0965 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
2010/10/31 17:21:29.0982 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
2010/10/31 17:21:30.0004 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/10/31 17:21:30.0062 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/10/31 17:21:30.0098 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
2010/10/31 17:21:30.0141 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
2010/10/31 17:21:30.0166 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/10/31 17:21:30.0197 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
2010/10/31 17:21:30.0212 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
2010/10/31 17:21:30.0243 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
2010/10/31 17:21:30.0275 RLDesignVirtualAudioCableWdm (cf1eee81fd32238fc51adca9f2266b7d) C:\Windows\system32\DRIVERS\livecamv.sys
2010/10/31 17:21:30.0317 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
2010/10/31 17:21:30.0356 rt61x64 (51f0fd171844de3d9b9a0f4492db7aa4) C:\Windows\system32\DRIVERS\WMP54Gv41x64.sys
2010/10/31 17:21:30.0383 RTL8169 (82b66abf055611024e5dbb9fa556c11d) C:\Windows\system32\DRIVERS\Rtlh64.sys
2010/10/31 17:21:30.0454 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
2010/10/31 17:21:30.0498 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2010/10/31 17:21:30.0533 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys
2010/10/31 17:21:30.0555 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys
2010/10/31 17:21:30.0578 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
2010/10/31 17:21:30.0611 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
2010/10/31 17:21:30.0625 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
2010/10/31 17:21:30.0647 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
2010/10/31 17:21:30.0676 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
2010/10/31 17:21:30.0715 Sftfs (72cd52403efc137290cb5a328510ebca) C:\Windows\system32\DRIVERS\Sftfslh.sys
2010/10/31 17:21:30.0756 Sftplay (31a36ef71af36eabcc4b4f8ab8f76465) C:\Windows\system32\DRIVERS\Sftplaylh.sys
2010/10/31 17:21:30.0785 Sftredir (2d969194fcc8eb41ed1d52863bfe7f52) C:\Windows\system32\DRIVERS\Sftredirlh.sys
2010/10/31 17:21:30.0804 Sftvol (08b36d2f63af3ca2248458a4280c0c50) C:\Windows\system32\DRIVERS\Sftvollh.sys
2010/10/31 17:21:30.0839 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
2010/10/31 17:21:30.0869 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
2010/10/31 17:21:30.0917 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
2010/10/31 17:21:30.0966 SndTAudio (f1fb29b1efb60ba79ffe408bca77ef44) C:\Windows\system32\drivers\SndTAudio.sys
2010/10/31 17:21:31.0014 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
2010/10/31 17:21:31.0055 SRTSP (7e4cc24a23262a84ae99dbffef69a6b0) C:\Windows\system32\Drivers\SRTSP64.SYS
2010/10/31 17:21:31.0094 SRTSPL (8b1dedeba049a3e1daf8219eec87eb00) C:\Windows\system32\Drivers\SRTSPL64.SYS
2010/10/31 17:21:31.0129 SRTSPX (3db35652e4460da6730bb44908fa39cb) C:\Windows\system32\Drivers\SRTSPX64.SYS
2010/10/31 17:21:31.0169 srv (8cd33a47ca02c79038b669f31f95bdac) C:\Windows\system32\DRIVERS\srv.sys
2010/10/31 17:21:31.0201 srv2 (1bedf533096c56e70f87e3e3ee02caf5) C:\Windows\system32\DRIVERS\srv2.sys
2010/10/31 17:21:31.0215 srvnet (2b8c340f830c465f514d966f7e6a822f) C:\Windows\system32\DRIVERS\srvnet.sys
2010/10/31 17:21:31.0243 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
2010/10/31 17:21:31.0273 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
2010/10/31 17:21:31.0307 SYMDNS (9e65ac70e4528ab6db53b5f1bb1a3520) C:\Windows\System32\Drivers\SYMDNS.SYS
2010/10/31 17:21:31.0338 SymEvent (70c8d165063eb76f1a373b74456d2aab) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2010/10/31 17:21:31.0358 SYMFW (b9e27e6a85bcecaec4b82649a9e99ae5) C:\Windows\System32\Drivers\SYMFW.SYS
2010/10/31 17:21:31.0380 SymIM (93526d381fcff03e666b767e2a920ac9) C:\Windows\system32\DRIVERS\SymIMv.sys
2010/10/31 17:21:31.0402 SYMNDISV (7d9f8388933a31a8468751b556bb1c41) C:\Windows\System32\Drivers\SYMNDISV.SYS
2010/10/31 17:21:31.0450 SYMREDRV (c082fc0d3dd1f990d120049a2285b33c) C:\Windows\System32\Drivers\SYMREDRV.SYS
2010/10/31 17:21:31.0465 SYMTDI (4ea607f6fb7288acf624fa4078f93ac7) C:\Windows\System32\Drivers\SYMTDI.SYS
2010/10/31 17:21:31.0489 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
2010/10/31 17:21:31.0508 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
2010/10/31 17:21:31.0578 Tcpip (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\drivers\tcpip.sys
2010/10/31 17:21:31.0619 Tcpip6 (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\DRIVERS\tcpip.sys
2010/10/31 17:21:31.0665 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
2010/10/31 17:21:31.0682 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
2010/10/31 17:21:31.0703 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
2010/10/31 17:21:31.0735 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
2010/10/31 17:21:31.0767 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
2010/10/31 17:21:31.0798 TfFsMon (21ac1ffd8f59b0ebfbbb2c3467e9f2cf) C:\Windows\system32\drivers\TfFsMon.sys
2010/10/31 17:21:31.0816 TfNetMon (b0ebe0ce99e4751cf7637a09fead7eda) C:\Windows\system32\drivers\TfNetMon.sys
2010/10/31 17:21:31.0835 TfSysMon (d6e991dcdd91323d979878025f0ceaea) C:\Windows\system32\drivers\TfSysMon.sys
2010/10/31 17:21:31.0886 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/10/31 17:21:31.0909 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
2010/10/31 17:21:31.0945 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
2010/10/31 17:21:31.0977 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
2010/10/31 17:21:32.0030 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
2010/10/31 17:21:32.0065 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
2010/10/31 17:21:32.0091 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
2010/10/31 17:21:32.0124 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
2010/10/31 17:21:32.0154 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
2010/10/31 17:21:32.0186 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
2010/10/31 17:21:32.0218 USBAAPL64 (5cf1ead086176dd3348e920a40bed03d) C:\Windows\system32\Drivers\usbaapl64.sys
2010/10/31 17:21:32.0259 usbaudio (c6ba890de6e41857fbe84175519cae7d) C:\Windows\system32\drivers\usbaudio.sys
2010/10/31 17:21:32.0294 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/10/31 17:21:32.0328 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
2010/10/31 17:21:32.0362 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
2010/10/31 17:21:32.0394 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
2010/10/31 17:21:32.0433 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
2010/10/31 17:21:32.0479 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
2010/10/31 17:21:32.0514 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
2010/10/31 17:21:32.0556 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/10/31 17:21:32.0615 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/10/31 17:21:32.0645 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys
2010/10/31 17:21:32.0690 V0540Dev (29aee96165e9a2ff625693e47a7a7719) C:\Windows\system32\DRIVERS\V0540Vid.sys
2010/10/31 17:21:32.0724 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/10/31 17:21:32.0745 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
2010/10/31 17:21:32.0766 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
2010/10/31 17:21:32.0795 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
2010/10/31 17:21:32.0850 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
2010/10/31 17:21:32.0905 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
2010/10/31 17:21:32.0950 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
2010/10/31 17:21:33.0000 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
2010/10/31 17:21:33.0025 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/31 17:21:33.0041 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/31 17:21:33.0079 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
2010/10/31 17:21:33.0124 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
2010/10/31 17:21:33.0195 winachsf (0208b357535431071193a7b534f5cfef) C:\Windows\system32\DRIVERS\CAX_CNXT.sys
2010/10/31 17:21:33.0252 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
2010/10/31 17:21:33.0293 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
2010/10/31 17:21:33.0325 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/10/31 17:21:33.0352 XAudio (f22e443518bc599d12888daf292a56d8) C:\Windows\system32\DRIVERS\xaudio64.sys
2010/10/31 17:21:33.0624 ================================================================================
2010/10/31 17:21:33.0624 Scan finished
2010/10/31 17:21:33.0624 ================================================================================
2010/10/31 17:22:20.0517 Deinitialize success


Results of the Malware Cleaner:

Norman Malware Cleaner
Version 1.8.2
Copyright � 1990 - 2010, Norman ASA. Built 2010/10/31 00:54:24

Norman Scanner Engine Version: 6.06.07
Nvcbin.def Version: 6.06.00, Date: 2010/10/31 00:54:24, Variants: 7937924

Scan started: 2010/10/31 17:29:58

Running pre-scan cleanup routine:
Operating System: Microsoft Windows Vista 6.0.6002 Service Pack 2
Logged on user: Owner-PC\Michelle


Scanning kernel...

Kernel scan complete



Scanning running processes and process memory...

Number of processes/threads found: 4948
Number of processes/threads scanned: 4948
Number of processes/threads not scanned: 0
Number of infected processes/threads terminated: 0
Total scanning time: 2m 27s


Scanning file system...

Scanning: prescan

Scanning: C:\*.*

C:\hp\HPQWare\DTSHORTCUTS\es\Probar Microsoft Office 2007 durante 60 dfas.lnk (Error opening file: Not found)

C:\Program Files (x86)\HP Games\Luxor 3\Luxor3-WT.exe (Infected with W32/Suspicious_Gen2.RCL)
Deleted file

C:\Program Files (x86)\Online Services\MSN90\LaunchMsn.exe (Infected with W32/Obfuscated.S!genr)
Deleted file

C:\System Volume Information\{02D95~1 (Error opening file: Access denied)

C:\System Volume Information\{07726~1 (Error opening file: Access denied)

C:\System Volume Information\{0815F~1 (Error opening file: Access denied)

C:\System Volume Information\{093D7~1 (Error opening file: Access denied)

C:\System Volume Information\{093D7~2 (Error opening file: Access denied)

C:\System Volume Information\{093D7~3 (Error opening file: Access denied)

C:\System Volume Information\{20ADB~1 (Error opening file: Access denied)

C:\System Volume Information\{2107E~1 (Error opening file: Access denied)

C:\System Volume Information\{230CE~1 (Error opening file: Access denied)

C:\System Volume Information\{23DB1~1 (Error opening file: Access denied)

C:\System Volume Information\{2540C~1 (Error opening file: Access denied)

C:\System Volume Information\{2E648~1 (Error opening file: Access denied)

C:\System Volume Information\{2E650~1 (Error opening file: Access denied)

C:\System Volume Information\{38088~1 (Error opening file: Access denied)

C:\System Volume Information\{41D7E~1 (Error opening file: Access denied)

C:\System Volume Information\{55D6A~1 (Error opening file: Access denied)

C:\System Volume Information\{59A05~1 (Error opening file: Access denied)

C:\System Volume Information\{5A27E~1 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~1 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~2 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~3 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~4 (Error opening file: Access denied)

C:\System Volume Information\{AA2E1~1 (Error opening file: Access denied)

C:\System Volume Information\{AA2E1~2 (Error opening file: Access denied)

C:\System Volume Information\{AA9C9~1 (Error opening file: Access denied)

C:\System Volume Information\{B5D56~1 (Error opening file: Access denied)

C:\System Volume Information\{B5D56~2 (Error opening file: Access denied)

C:\System Volume Information\{C4792~1 (Error opening file: Access denied)

C:\System Volume Information\{CC8FD~1 (Error opening file: Access denied)

C:\System Volume Information\{CC8FD~2 (Error opening file: Access denied)

C:\System Volume Information\{CC8FD~3 (Error opening file: Access denied)

C:\System Volume Information\{DE143~1 (Error opening file: Access denied)

C:\System Volume Information\{E59F7~1 (Error opening file: Access denied)

C:\System Volume Information\{EE656~1 (Error opening file: Access denied)

C:\System Volume Information\{EFD2E~1 (Error opening file: Access denied)

C:\Users\Michelle\AppData\Local\Temp\symlcsv1.exe (Infected with W32/Agent.TVAA)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21374.tmp/cpak/Crimepack.class (Infected with Suspicious_Gen2.DWRNB)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/a0ee3d65141.class (Infected with JAVA/Agent.AR)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/a4cb9b1a8a5.class (Infected with Java/Rexec.A)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/a66d578f084.class (Infected with Java/Agent.AP)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/aa79d1019d8.class (Infected with JAVA/Agent.AU)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/ab16db71cdc.class (Infected with JAVA/Agent.AV)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/ab5601d4848.class (Infected with JAVA/Agent.AW)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/ae28546890f.class (Infected with JAVA/Agent.AX)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache21375.tmp/af439f03798.class (Infected with JAVA/Agent.AY)
Deleted file

C:\Users\Michelle\AppData\Local\Temp\Low\jar_cache618.tmp/cpak/Crimepack.class (Infected with Suspicious_Gen2.EDQRR)
Deleted file

C:\Windows\Temp\avg-4c90cc13-a68e-4035-82df-73243e02aa7f (Error opening file: Access denied)

C:\Windows\Temp\avg-5531996d-4b0a-4b5d-bd71-c50dcb24323b (Error opening file: Access denied)

C:\Windows\Temp\symlcsv1.exe (Infected with W32/Agent.TVAA)
Deleted file

Scanning: D:\*.*

Scanning: Q:\*.*

Scanning: C:\System Volume Information\*.*

C:\System Volume Information\{02D95~1 (Error opening file: Access denied)

C:\System Volume Information\{07726~1 (Error opening file: Access denied)

C:\System Volume Information\{0815F~1 (Error opening file: Access denied)

C:\System Volume Information\{093D7~1 (Error opening file: Access denied)

C:\System Volume Information\{093D7~2 (Error opening file: Access denied)

C:\System Volume Information\{093D7~3 (Error opening file: Access denied)

C:\System Volume Information\{20ADB~1 (Error opening file: Access denied)

C:\System Volume Information\{2107E~1 (Error opening file: Access denied)

C:\System Volume Information\{230CE~1 (Error opening file: Access denied)

C:\System Volume Information\{23DB1~1 (Error opening file: Access denied)

C:\System Volume Information\{2540C~1 (Error opening file: Access denied)

C:\System Volume Information\{2E648~1 (Error opening file: Access denied)

C:\System Volume Information\{2E650~1 (Error opening file: Access denied)

C:\System Volume Information\{38088~1 (Error opening file: Access denied)

C:\System Volume Information\{41D7E~1 (Error opening file: Access denied)

C:\System Volume Information\{55D6A~1 (Error opening file: Access denied)

C:\System Volume Information\{59A05~1 (Error opening file: Access denied)

C:\System Volume Information\{5A27E~1 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~1 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~2 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~3 (Error opening file: Access denied)

C:\System Volume Information\{8C7AE~4 (Error opening file: Access denied)

C:\System Volume Information\{AA2E1~1 (Error opening file: Access denied)

C:\System Volume Information\{AA2E1~2 (Error opening file: Access denied)

C:\System Volume Information\{AA9C9~1 (Error opening file: Access denied)

C:\System Volume Information\{B5D56~1 (Error opening file: Access denied)

C:\System Volume Information\{B5D56~2 (Error opening file: Access denied)

C:\System Volume Information\{C4792~1 (Error opening file: Access denied)

C:\System Volume Information\{CC8FD~1 (Error opening file: Access denied)

C:\System Volume Information\{CC8FD~2 (Error opening file: Access denied)

C:\System Volume Information\{CC8FD~3 (Error opening file: Access denied)

C:\System Volume Information\{DE143~1 (Error opening file: Access denied)

C:\System Volume Information\{E59F7~1 (Error opening file: Access denied)

C:\System Volume Information\{EE656~1 (Error opening file: Access denied)

C:\System Volume Information\{EFD2E~1 (Error opening file: Access denied)

Scanning: postscan


Running post-scan cleanup routine:
Set TCP/IP autotuning to "normal" (or it was already "normal")

Number of files found: 835711
Number of archives unpacked: 5973
Number of files scanned: 835574
Number of files not scanned: 137
Number of files skipped due to exclude list: 0
Number of infected files found: 14
Number of infected files repaired/deleted: 14
Number of infections removed: 14
Total scanning time: 3h 26m 28s



#7 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:32 PM

Posted 02 November 2010 - 06:58 AM

Please download TFC (Temp File Cleaner) by Old Timer and save it to your desktop.
alternate download link
  • Save any unsaved work. TFC will close ALL open programs including your browser!
  • Double-click on TFC.exe to run it. Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • TFC will clear out all temp folders (temp, IE temp, Java, FF, Opera, Chrome, Safari) for all user accounts including:
    • Administrator.
    • All Users.
    • LocalService.
    • NetworkService.
    • and any other accounts in the user folder.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.
-- Note: It is normal for the computer to be slow to boot after running TFC cleaner the first time.

Please perform a scan with Eset Online Anti-virus Scanner.
  • This scan requires Internet Explorer to work. If using a different browser, you will be given the option to download and use the ESET Smart Installer.
  • Vista/Windows 7 users need to run Internet Explorer as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run As Administrator from the context menu.
  • Click the green Posted Image button.
  • Read the End User License Agreement and check the box:
  • Check Posted Image.
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Check Remove found threats and Scan potentially unwanted applications. (If given the option, choose "Quarantine" instead of delete.)
  • Click the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer.
  • If offered the option to get information or buy software at any point, just close the window.
  • The scan will take a while so be patient and do NOT use the computer while the scan is running. Keep all other programs and windows closed.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop as ESETScan.txt.
  • Push the Posted Image button, then Finish.
  • Copy and paste the contents of ESETScan.txt in your next reply.
Note: A log.txt file will also be created and automatically saved in the C:\Program Files\EsetOnlineScanner\ folder.
If you did not save the ESETScan log, click Posted Image > Run..., then type or copy and paste everything in the code box below into the Open dialogue box:

C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Click Ok and the scan results will open in Notepad.
  • Copy and paste the contents of log.txt in your next reply.
-- Some online scanners will detect existing anti-virus software and refuse to cooperate. You may have to disable the real-time protection components of your existing anti-virus and try running the scan again. If you do this, remember to turn them back on after you are finished.

Edited by quietman7, 02 November 2010 - 06:59 AM.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#8 jasondarrel

jasondarrel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 02 November 2010 - 08:00 PM

^ Thanks, will be doing that next.

She just got the BSOD again today, and this is the message she showed me:

Posted Image

#9 jasondarrel

jasondarrel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 03 November 2010 - 10:18 PM

Results of the Eset scan:

Posted Image

As you can see, there isn't a button to export the log.txt file since there aren't any infections.

Today, she got the BOSD 4 times trying to turn on her computer. Upon getting the computer to start, it asks to either run normally or in Safe Mode. Then it asks her to do a system restore and when she clicks that, the blue screen comes.

She said the virus symptoms have stopped, she just has the BSOD problem.

#10 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:32 PM

Posted 04 November 2010 - 08:45 AM

Did all the crashes involve the same STOP error as the previous one? 0x000000D1

Crashes (BSOD), unexpected shutdowns, sudden freezing, random restarting, and booting problems could be symptomatic of a variety of things to include hardware/software issues, overheating caused by a failed processor fan, bad memory (RAM), failing or underpowered power supply, CPU overheating, motherboard, video card, faulty or unsigned device drivers, CMOS battery going bad, BIOS and firmware problems, dirty hardware components, programs hanging or unresponsive in the background, and sometimes malware. Even legitimate programs like CD Emulators (Daemon Tools, Alchohol 120%, Astroburn, AnyDVD) can trigger crashes, various stop error messages and system hangs so you may or may not be dealing with multiple issues. If the computer is overheating, it usually begins to shutdown/restart on a more regular basis. Troubleshooting for these kinds of issues can be arduous and time consuming. There are no shortcuts.

Since you were also dealing with malware, I recommend further investigation. Many of the tools we use in this forum are not capable of detecting all malware variants so more advanced tools are needed to investigate. Before that can be done you will need you to create and post a DDS log for further investigation.

Please read the pinned topic titled "Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help". If you cannot complete a step, then skip it and continue with the next. In Step 7 there are instructions for downloading and running DDS which will create a Pseudo HJT Report as part of its log.

When you have done that, post your log in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team Experts. A member of the Team will walk you through, step by step, on how to clean your computer. If you post your log back in this thread, the response from the Malware Response Team will be delayed because your post will have to be moved. This means it will fall in line behind any others posted that same day.

Start a new topic, give it a relevant title and post your log along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. An expert will analyze your log and reply with instructions advising you what to fix. After doing this, we would appreciate if you post a link to your log back here so we know that your getting help from the Malware Response Team.

Please be patient. It may take a while to get a response because the Malware Response Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have posted your log and are waiting, please DO NOT "bump" your post or make another reply until it has been responded to by a member of the Malware Response Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another Malware Response Team member is already assisting you and not open the thread to respond.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#11 jasondarrel

jasondarrel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 04 November 2010 - 06:33 PM

Before I start that whole other process, the BSODs are not the same. Here are the another 2 she had yesterday:

http://i56.tinypic.com/16gie81.jpg

http://i56.tinypic.com/x5b42x.jpg

#12 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:32 PM

Posted 04 November 2010 - 07:45 PM

As I said troubleshooting for these kinds of issues can be arduous and time consuming. There are no shortcuts. As such, I would recommend you eliminate malware as a possible cause so you can concentrate on troubleshooting.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users