Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possible virus/malware infection - please help?!


  • Please log in to reply
3 replies to this topic

#1 leocliff

leocliff

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:07 AM

Posted 30 November 2010 - 04:15 AM

Hello can anyone please help me? The issues first started when AVG displayed virus warnings 7 days ago. I was searching google, and it took me to a website that appeared to be my 'my documents' folder. The folder icons were flashing to show they were infected. A message appeared which told me that some of my folders were infected and it prompted me to download a file. I didn't download the file. I ran a full scan (see results below).

Issues I'm having:
- google searches are re-directing me to random websites. sometimes a warning appears saying the site i'm about to enter contains malware
- slow computer, startup, opening folders, new webpages
- sometimes applications stop responding
- my documents folder froze, task manager wouldn't work - had to force restart
- AVG wouldn't remove all the viruses from the scan below:


"Infection";"May be infected by unknown virus";"c:\Users\Leo\Desktop\Leolocal2.exe";"N/A";"29/11/2010, 8:58:13 AM"
"Infection";"May be infected by unknown virus";"c:\Users\Leo\Desktop\LeoRemote.exe";"N/A";"29/11/2010, 8:58:16 AM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Cookies\leo@m.webtrends[2].txt";"N/A";"24/11/2010, 10:38:11 AM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\agent_clifford@m.webtrends[2].txt";"N/A";"24/11/2010, 10:53:35 AM"
"Warning";"Found Tracking cookie.Fastclick";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\agent_clifford@fastclick[2].txt";"N/A";"24/11/2010, 10:53:36 AM"
"Warning";"Found Tracking cookie.Yieldmanager";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\Low\agent_clifford@ad.yieldmanager[1].txt";"N/A";"24/11/2010, 10:53:37 AM"
"Warning";"Found Tracking cookie.Adbrite";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\Low\agent_clifford@adbrite[1].txt";"N/A";"24/11/2010, 10:53:37 AM"
"Warning";"Found Tracking cookie.Fastclick";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\Low\agent_clifford@fastclick[1].txt";"N/A";"24/11/2010, 10:53:39 AM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\Low\agent_clifford@m.webtrends[2].txt";"N/A";"24/11/2010, 10:53:40 AM"
"Warning";"Found Tracking cookie.Mediaplex";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\Low\agent_clifford@mediaplex[2].txt";"N/A";"24/11/2010, 10:53:41 AM"
"Warning";"Found Tracking cookie.2o7";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\Low\agent_clifford@msnportal.112.2o7[1].txt";"N/A";"24/11/2010, 10:53:41 AM"
"Warning";"Found Tracking cookie.Revsci";"C:\Windows.old\Documents and Settings\Agent Clifford\AppData\Roaming\Microsoft\Windows\Cookies\Low\agent_clifford@revsci[1].txt";"N/A";"24/11/2010, 10:53:41 AM"
"Warning";"Found Tracking cookie.Webtrendslive";"C:\Windows.old\Windows\Temp\Cookies\agent_clifford@statse.webtrendslive[2].txt";"N/A";"24/11/2010, 11:09:28 AM"
"Warning";"Found Tracking cookie.2o7";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@2o7[2].txt";"N/A";"24/11/2010, 11:14:50 AM"
"Warning";"Found Tracking cookie.Yieldmanager";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@ad.yieldmanager[2].txt";"N/A";"24/11/2010, 11:14:50 AM"
"Warning";"Found Tracking cookie.Adbrite";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@adbrite[2].txt";"N/A";"24/11/2010, 11:14:51 AM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@atdmt[1].txt";"N/A";"24/11/2010, 11:14:51 AM"
"Warning";"Found Tracking cookie.Serving-sys";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@bs.serving-sys[1].txt";"N/A";"24/11/2010, 11:14:51 AM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@m.webtrends[1].txt";"N/A";"24/11/2010, 11:14:52 AM"
"Warning";"Found Tracking cookie.Mediaplex";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@mediaplex[2].txt";"N/A";"24/11/2010, 11:14:52 AM"
"Warning";"Found Tracking cookie.2o7";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@msnportal.112.2o7[1].txt";"N/A";"24/11/2010, 11:14:53 AM"
"Warning";"Found Tracking cookie.Overture";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@overture[2].txt";"N/A";"24/11/2010, 11:14:53 AM"
"Warning";"Found Tracking cookie.Pro-market";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@pro-market[2].txt";"N/A";"24/11/2010, 11:14:53 AM"
"Warning";"Found Tracking cookie.Questionmarket";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@questionmarket[2].txt";"N/A";"24/11/2010, 11:14:54 AM"
"Warning";"Found Tracking cookie.Serving-sys";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@serving-sys[2].txt";"N/A";"24/11/2010, 11:14:54 AM"
"Warning";"Found Tracking cookie.Webtrendslive";"C:\Windows.old.000\Documents and Settings\Leo\AppData\Roaming\Microsoft\Windows\Cookies\Low\leo@statse.webtrendslive[1].txt";"N/A";"24/11/2010, 11:14:55 AM"
"Infection";"Trojan horse Hiloti.BP";"C:\Windows\system32\config\systemprofile\AppData\Local\Quoncd.dll";"N/A";"24/11/2010, 12:00:17 PM"
"Warning";"Found registry key with reference to infected file C:\Windows\system32\config\systemprofile\AppData\Local\Quoncd.dll";"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\Abifeyevalanah";"N/A";"24/11/2010, 12:00:17 PM"
"Infection";"Trojan horse Downloader.Generic10.AOCW";"C:\Windows\TEMP\Tjy.exe";"N/A";"24/11/2010, 12:00:18 PM"
"Warning";"Found registry key with reference to infected file C:\Windows\TEMP\Tjy.exe";"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\HJRUDZ5DT2";"N/A";"24/11/2010, 12:00:18 PM"
"Infection";"Trojan horse Hiloti.BO";"C:\Windows\System32\config\systemprofile\AppData\Local\ayogixoret.dll";"N/A";"24/11/2010, 12:27:06 PM"
"Infection";"Trojan horse Dropper.Generic2.BWYW";"C:\Windows\Temp\changea.exe";"N/A";"24/11/2010, 12:28:42 PM"
"Infection";"Trojan horse Crypt.ACPK";"C:\Windows\Temp\ckvqy.exe";"N/A";"24/11/2010, 12:28:42 PM"
"Infection";"Trojan horse Hiloti.BP";"C:\Windows\Temp\lhxk.exe";"N/A";"24/11/2010, 12:28:44 PM"
"Infection";"Trojan horse Generic20.KSG";"C:\Windows\Temp\msdtca.exe";"N/A";"24/11/2010, 12:28:44 PM"
"Infection";"Trojan horse Generic20.MAH";"C:\Windows\Temp\Tj0.exe";"N/A";"24/11/2010, 12:28:44 PM"
"Infection";"Trojan horse FakeAV.FTI";"C:\Windows\Temp\Tj1.exe";"N/A";"24/11/2010, 12:28:44 PM"
"Infection";"Trojan horse Downloader.Generic10.AKOJ";"C:\Windows\Temp\Tjv.exe";"N/A";"24/11/2010, 12:28:44 PM"
"Infection";"Trojan horse Downloader.Generic10.AKOJ";"C:\Windows\Temp\Tjw.exe";"N/A";"24/11/2010, 12:28:45 PM"
"Infection";"Trojan horse Downloader.Generic10.AODB";"C:\Windows\Temp\Tjx.exe";"N/A";"24/11/2010, 12:28:45 PM"
"Infection";"Trojan horse Downloader.Generic10.AKOJ";"C:\Windows\Temp\Tjz.exe";"N/A";"24/11/2010, 12:28:45 PM"
"Infection";"Trojan horse Downloader.Generic10.ANLO";"C:\Windows\Temp\wkhtr.exe";"N/A";"24/11/2010, 12:28:46 PM"
"Infection";"Trojan horse FakeAlert.VN";"C:\Windows\Temp\esbo.exe";"N/A";"24/11/2010, 12:28:46 PM"
"Malware";"Trojan.Downloader";"C:\WINDOWS\TEMP\OYPU\SETUP.EXE";"N/A";"28/11/2010, 11:55:55 PM"
"Malware";"Other:Malware-gen";"C:\USERS\LEO\APPDATA\LOCAL\TEMP\ESENTUTLA.EXE";"N/A";"28/11/2010, 10:00:22 PM"

BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 PM

Posted 30 November 2010 - 08:09 AM

Please download the TDSS Rootkit Removing Tool (TDSSKiller.zip) and save it to your Desktop. <-Important!!!
Be sure to print out and follow all instructions for performing a scan or refer to these instructions with screenshots.
  • Extract (unzip) the file to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the Desktop. Vista/Windows 7 users refer to these instructions if you're unsure how to unzip a file.
  • If you don't have an extracting program, you can download TDSSKiller.exe and use that instead.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • When the program opens, click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure is selected, then click Continue > Reboot now to finish the cleaning process.<- Important!!
    Note: If 'Suspicious' objects are detected, you will be given the option to Skip or Quarantine. Skip will be the default selection.
  • A log file named TDSSKiller_version_date_time_log.txt will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.
-- If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these instructions. In some cases it may be necessary to redownload TDSSKiller and randomly rename it before downloading and saving to the computer.

-- For any files detected as 'Suspicious' (except those identified as Forged to be cured after reboot) get a second opinion by submitting to Jotti's virusscan or VirusTotal. In the "File to upload & scan" box, browse to the location of the suspicious file and submit (upload) it for scanning/analysis.


Please download Malwarebytes Anti-Malware (v1.50) and save it to your desktop.

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.



.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 leocliff

leocliff
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:07 AM

Posted 01 December 2010 - 06:45 AM

Thanks a lot for your help! I ran TDSSKiller. Below is the log. Now awaiting your instructions. Thanks.


2010/12/01 22:26:39.0892 TDSS rootkit removing tool 2.4.10.0 Nov 28 2010 18:35:56
2010/12/01 22:26:39.0892 ================================================================================
2010/12/01 22:26:39.0892 SystemInfo:
2010/12/01 22:26:39.0892
2010/12/01 22:26:39.0892 OS Version: 6.1.7600 ServicePack: 0.0
2010/12/01 22:26:39.0892 Product type: Workstation
2010/12/01 22:26:39.0893 ComputerName: LEO-PC
2010/12/01 22:26:39.0897 UserName: Leo
2010/12/01 22:26:39.0897 Windows directory: C:\Windows
2010/12/01 22:26:39.0897 System windows directory: C:\Windows
2010/12/01 22:26:39.0897 Processor architecture: Intel x86
2010/12/01 22:26:39.0897 Number of processors: 2
2010/12/01 22:26:39.0897 Page size: 0x1000
2010/12/01 22:26:39.0897 Boot type: Normal boot
2010/12/01 22:26:39.0897 ================================================================================
2010/12/01 22:26:40.0385 Initialize success
2010/12/01 22:27:25.0362 ================================================================================
2010/12/01 22:27:25.0362 Scan started
2010/12/01 22:27:25.0362 Mode: Manual;
2010/12/01 22:27:25.0362 ================================================================================
2010/12/01 22:27:26.0686 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2010/12/01 22:27:26.0735 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2010/12/01 22:27:26.0933 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2010/12/01 22:27:27.0021 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2010/12/01 22:27:27.0168 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2010/12/01 22:27:27.0258 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2010/12/01 22:27:27.0441 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2010/12/01 22:27:27.0518 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2010/12/01 22:27:27.0680 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2010/12/01 22:27:27.0771 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2010/12/01 22:27:27.0920 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2010/12/01 22:27:27.0991 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2010/12/01 22:27:28.0146 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2010/12/01 22:27:28.0197 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2010/12/01 22:27:28.0325 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2010/12/01 22:27:28.0514 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2010/12/01 22:27:28.0674 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2010/12/01 22:27:28.0900 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2010/12/01 22:27:29.0110 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2010/12/01 22:27:29.0156 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2010/12/01 22:27:29.0194 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/12/01 22:27:29.0361 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2010/12/01 22:27:29.0575 atikmdag (04f09923a393e4e0e8453a8f78361e73) C:\Windows\system32\DRIVERS\atikmdag.sys
2010/12/01 22:27:29.0924 AVGIDSDriver (1ca8e5fe74efd5826bbd76c0470e6ae4) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
2010/12/01 22:27:30.0002 AVGIDSEH (b9b6e535b9b49c463f68f4bcdd232944) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
2010/12/01 22:27:30.0166 AVGIDSFilter (32a76fd3fc12d09c586730ef63b4b20b) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
2010/12/01 22:27:30.0259 AVGIDSShim (84431da40330cdfd84a7b92bcf0d4a05) C:\Windows\system32\DRIVERS\AVGIDSShim.Sys
2010/12/01 22:27:30.0455 Avgldx86 (1119e5bec6e749e0d292f0f84d48edba) C:\Windows\system32\DRIVERS\avgldx86.sys
2010/12/01 22:27:30.0695 Avgmfx86 (54f1a9b4c9b540c2d8ac4baa171696b1) C:\Windows\system32\DRIVERS\avgmfx86.sys
2010/12/01 22:27:30.0763 Avgrkx86 (8da3b77993c5f354cc2977b7ea06d03a) C:\Windows\system32\DRIVERS\avgrkx86.sys
2010/12/01 22:27:30.0973 Avgtdix (354e0fec3bfdfa9c369e0f67ac362f9f) C:\Windows\system32\DRIVERS\avgtdix.sys
2010/12/01 22:27:31.0079 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2010/12/01 22:27:31.0277 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2010/12/01 22:27:31.0341 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2010/12/01 22:27:31.0532 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2010/12/01 22:27:31.0591 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
2010/12/01 22:27:31.0634 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2010/12/01 22:27:31.0801 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2010/12/01 22:27:31.0883 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2010/12/01 22:27:32.0070 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2010/12/01 22:27:32.0095 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2010/12/01 22:27:32.0130 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2010/12/01 22:27:32.0255 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\DRIVERS\BthEnum.sys
2010/12/01 22:27:32.0281 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2010/12/01 22:27:32.0316 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
2010/12/01 22:27:32.0497 BTHPORT (4a34888e13224678dd062466afec4240) C:\Windows\system32\Drivers\BTHport.sys
2010/12/01 22:27:32.0555 BTHUSB (fa04c63916fa221dbb91fce153d07a55) C:\Windows\system32\Drivers\BTHUSB.sys
2010/12/01 22:27:32.0748 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2010/12/01 22:27:32.0809 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2010/12/01 22:27:32.0983 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2010/12/01 22:27:33.0043 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2010/12/01 22:27:33.0246 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/12/01 22:27:33.0290 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2010/12/01 22:27:33.0332 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2010/12/01 22:27:33.0520 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2010/12/01 22:27:33.0565 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2010/12/01 22:27:33.0766 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2010/12/01 22:27:33.0875 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
2010/12/01 22:27:34.0110 dc3d (33e7ab50f87f97abd9057205e27cb182) C:\Windows\system32\DRIVERS\dc3d.sys
2010/12/01 22:27:34.0236 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
2010/12/01 22:27:34.0411 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2010/12/01 22:27:34.0461 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2010/12/01 22:27:34.0681 Dot4 (b5e479eb83707dd698f66953e922042c) C:\Windows\system32\DRIVERS\Dot4.sys
2010/12/01 22:27:34.0774 Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2010/12/01 22:27:34.0902 dot4usb (cf491ff38d62143203c065260567e2f7) C:\Windows\system32\DRIVERS\dot4usb.sys
2010/12/01 22:27:35.0034 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2010/12/01 22:27:35.0113 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
2010/12/01 22:27:35.0400 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2010/12/01 22:27:35.0726 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2010/12/01 22:27:35.0778 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2010/12/01 22:27:35.0989 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2010/12/01 22:27:36.0071 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2010/12/01 22:27:36.0146 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2010/12/01 22:27:36.0220 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2010/12/01 22:27:36.0392 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2010/12/01 22:27:36.0431 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/12/01 22:27:36.0490 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2010/12/01 22:27:36.0697 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2010/12/01 22:27:36.0731 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2010/12/01 22:27:36.0801 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2010/12/01 22:27:36.0994 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2010/12/01 22:27:37.0028 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2010/12/01 22:27:37.0111 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2010/12/01 22:27:37.0300 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/12/01 22:27:37.0342 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2010/12/01 22:27:37.0368 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2010/12/01 22:27:37.0396 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2010/12/01 22:27:37.0596 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2010/12/01 22:27:37.0707 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2010/12/01 22:27:37.0918 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2010/12/01 22:27:38.0190 hwdatacard (1fc7a63148e4f2bd831dab0dc732026d) C:\Windows\system32\DRIVERS\ewusbmdm.sys
2010/12/01 22:27:38.0266 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2010/12/01 22:27:38.0499 hwusbdev (a259d3619aa23d4562581067f85e2006) C:\Windows\system32\DRIVERS\ewusbdev.sys
2010/12/01 22:27:38.0619 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/12/01 22:27:38.0822 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2010/12/01 22:27:38.0893 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2010/12/01 22:27:39.0078 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2010/12/01 22:27:39.0140 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2010/12/01 22:27:39.0189 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/12/01 22:27:39.0381 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2010/12/01 22:27:39.0420 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2010/12/01 22:27:39.0468 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2010/12/01 22:27:39.0648 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2010/12/01 22:27:39.0696 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/12/01 22:27:39.0756 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/12/01 22:27:39.0962 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/12/01 22:27:40.0021 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2010/12/01 22:27:40.0082 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2010/12/01 22:27:40.0307 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/12/01 22:27:40.0550 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys
2010/12/01 22:27:40.0747 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\Windows\system32\DRIVERS\lmimirr.sys
2010/12/01 22:27:40.0892 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\Windows\system32\drivers\LMIRfsDriver.sys
2010/12/01 22:27:41.0049 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2010/12/01 22:27:41.0131 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2010/12/01 22:27:41.0183 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2010/12/01 22:27:41.0213 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2010/12/01 22:27:41.0357 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2010/12/01 22:27:41.0449 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2010/12/01 22:27:41.0499 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2010/12/01 22:27:41.0645 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2010/12/01 22:27:41.0727 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2010/12/01 22:27:41.0868 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2010/12/01 22:27:42.0250 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2010/12/01 22:27:42.0332 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2010/12/01 22:27:42.0457 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2010/12/01 22:27:42.0523 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2010/12/01 22:27:42.0572 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2010/12/01 22:27:42.0723 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/12/01 22:27:42.0820 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/12/01 22:27:42.0852 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/12/01 22:27:42.0909 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2010/12/01 22:27:43.0009 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2010/12/01 22:27:43.0118 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2010/12/01 22:27:43.0146 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2010/12/01 22:27:43.0212 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2010/12/01 22:27:43.0371 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2010/12/01 22:27:43.0450 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/12/01 22:27:43.0482 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2010/12/01 22:27:43.0525 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2010/12/01 22:27:43.0674 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/12/01 22:27:43.0765 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2010/12/01 22:27:43.0815 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2010/12/01 22:27:43.0949 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2010/12/01 22:27:44.0107 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2010/12/01 22:27:44.0258 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2010/12/01 22:27:44.0407 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2010/12/01 22:27:44.0489 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/12/01 22:27:44.0517 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/12/01 22:27:44.0558 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/12/01 22:27:44.0696 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2010/12/01 22:27:44.0791 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2010/12/01 22:27:44.0929 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2010/12/01 22:27:45.0183 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\Windows\system32\DRIVERS\netw5v32.sys
2010/12/01 22:27:45.0489 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2010/12/01 22:27:45.0574 nmwcd (28e36e677849174c910faaead3e60e9e) C:\Windows\system32\drivers\ccdcmb.sys
2010/12/01 22:27:45.0770 nmwcdc (3823deb17f9f6775de0187a98fa0536d) C:\Windows\system32\drivers\ccdcmbo.sys
2010/12/01 22:27:45.0998 NPF (b9730495e0cf674680121e34bd95a73b) C:\Windows\system32\drivers\npf.sys
2010/12/01 22:27:46.0064 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2010/12/01 22:27:46.0110 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2010/12/01 22:27:46.0183 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2010/12/01 22:27:46.0364 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys
2010/12/01 22:27:46.0426 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2010/12/01 22:27:46.0477 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2010/12/01 22:27:46.0649 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2010/12/01 22:27:46.0692 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2010/12/01 22:27:46.0735 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/12/01 22:27:46.0999 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2010/12/01 22:27:47.0029 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2010/12/01 22:27:47.0074 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2010/12/01 22:27:47.0298 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys
2010/12/01 22:27:47.0376 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2010/12/01 22:27:47.0413 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2010/12/01 22:27:47.0587 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/12/01 22:27:47.0627 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2010/12/01 22:27:47.0679 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2010/12/01 22:27:47.0997 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2010/12/01 22:27:48.0068 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2010/12/01 22:27:48.0234 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2010/12/01 22:27:48.0369 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
2010/12/01 22:27:48.0515 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2010/12/01 22:27:48.0711 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2010/12/01 22:27:48.0756 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2010/12/01 22:27:48.0801 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2010/12/01 22:27:48.0897 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2010/12/01 22:27:49.0081 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/12/01 22:27:49.0142 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/12/01 22:27:49.0330 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2010/12/01 22:27:49.0371 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2010/12/01 22:27:49.0413 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2010/12/01 22:27:49.0441 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/12/01 22:27:49.0619 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
2010/12/01 22:27:49.0689 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2010/12/01 22:27:49.0734 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2010/12/01 22:27:50.0064 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2010/12/01 22:27:50.0154 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2010/12/01 22:27:50.0347 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
2010/12/01 22:27:50.0448 rimsptsk (942264f8248b6e0995648ae99740bc14) C:\Windows\system32\DRIVERS\rimsptsk.sys
2010/12/01 22:27:50.0692 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2010/12/01 22:27:50.0756 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
2010/12/01 22:27:50.0823 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2010/12/01 22:27:51.0014 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2010/12/01 22:27:51.0105 sdbus (7b48cff3a475fe849dea65ec4d35c425) C:\Windows\system32\DRIVERS\sdbus.sys
2010/12/01 22:27:51.0289 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/12/01 22:27:51.0372 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2010/12/01 22:27:51.0399 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2010/12/01 22:27:51.0443 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2010/12/01 22:27:51.0690 SFEP (8b7c1768d2cde2e02e09a66563ddfd16) C:\Windows\system32\DRIVERS\SFEP.sys
2010/12/01 22:27:51.0762 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/12/01 22:27:51.0809 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2010/12/01 22:27:51.0851 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/12/01 22:27:51.0984 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2010/12/01 22:27:52.0036 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2010/12/01 22:27:52.0167 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2010/12/01 22:27:52.0220 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2010/12/01 22:27:52.0318 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2010/12/01 22:27:52.0517 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2010/12/01 22:27:52.0730 srv (2dbedfb1853f06110ec2aa7f3213c89f) C:\Windows\system32\DRIVERS\srv.sys
2010/12/01 22:27:52.0875 srv2 (db37131d1027c50ea7ee21c8bb4536aa) C:\Windows\system32\DRIVERS\srv2.sys
2010/12/01 22:27:53.0158 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
2010/12/01 22:27:53.0345 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
2010/12/01 22:27:53.0549 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
2010/12/01 22:27:53.0736 srvnet (f5980b74124db9233b33f86fc5ebbb4f) C:\Windows\system32\DRIVERS\srvnet.sys
2010/12/01 22:27:53.0824 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2010/12/01 22:27:54.0014 StillCam (edb05bd63148796f23ea78506404a538) C:\Windows\system32\DRIVERS\serscan.sys
2010/12/01 22:27:54.0087 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
2010/12/01 22:27:54.0146 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
2010/12/01 22:27:54.0323 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2010/12/01 22:27:54.0470 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2010/12/01 22:27:54.0714 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2010/12/01 22:27:54.0901 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2010/12/01 22:27:54.0949 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2010/12/01 22:27:54.0974 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2010/12/01 22:27:55.0025 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2010/12/01 22:27:55.0074 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2010/12/01 22:27:55.0307 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/12/01 22:27:55.0370 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2010/12/01 22:27:55.0412 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2010/12/01 22:27:55.0587 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2010/12/01 22:27:55.0667 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2010/12/01 22:27:55.0709 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2010/12/01 22:27:55.0879 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2010/12/01 22:27:55.0977 upperdev (b1b8bee26227dad9835019201552cb05) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
2010/12/01 22:27:56.0022 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/12/01 22:27:56.0220 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2010/12/01 22:27:56.0256 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2010/12/01 22:27:56.0372 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
2010/12/01 22:27:56.0584 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2010/12/01 22:27:56.0649 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2010/12/01 22:27:56.0733 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2010/12/01 22:27:56.0886 usbser (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\drivers\usbser.sys
2010/12/01 22:27:57.0018 UsbserFilt (98e1ff1d732c6c7200b6c59d4ff8c1c3) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
2010/12/01 22:27:57.0089 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/12/01 22:27:57.0238 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/12/01 22:27:57.0324 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\Windows\system32\Drivers\usbvideo.sys
2010/12/01 22:27:57.0497 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2010/12/01 22:27:57.0580 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/12/01 22:27:57.0622 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2010/12/01 22:27:57.0763 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2010/12/01 22:27:57.0819 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2010/12/01 22:27:57.0849 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2010/12/01 22:27:57.0913 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2010/12/01 22:27:57.0985 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
2010/12/01 22:27:58.0162 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
2010/12/01 22:27:58.0235 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2010/12/01 22:27:58.0293 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2010/12/01 22:27:58.0443 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2010/12/01 22:27:58.0563 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2010/12/01 22:27:58.0626 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2010/12/01 22:27:58.0842 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2010/12/01 22:27:58.0951 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/12/01 22:27:58.0974 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/12/01 22:27:59.0185 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2010/12/01 22:27:59.0272 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2010/12/01 22:27:59.0498 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2010/12/01 22:27:59.0555 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2010/12/01 22:27:59.0695 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2010/12/01 22:27:59.0833 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/12/01 22:27:59.0955 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/12/01 22:28:00.0034 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2010/12/01 22:28:00.0197 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/12/01 22:28:00.0357 yukonw7 (b07c5b7efdf936ff93d4f540938725be) C:\Windows\system32\DRIVERS\yk62x86.sys
2010/12/01 22:28:00.0430 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2010/12/01 22:28:00.0438 ================================================================================
2010/12/01 22:28:00.0438 Scan finished
2010/12/01 22:28:00.0438 ================================================================================
2010/12/01 22:28:00.0457 Detected object count: 1
2010/12/01 22:29:56.0814 \HardDisk0 - will be cured after reboot
2010/12/01 22:29:56.0816 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2010/12/01 22:30:56.0587 Deinitialize success

#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 PM

Posted 01 December 2010 - 07:42 AM

This is the pertinent section of the log which indicates a TDSS rootkit infected the Master Boot Record (MBR) and that it will be cured after reboot.

2010/12/01 22:28:00.0430 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2010/12/01 22:28:00.0438 ================================================================================
2010/12/01 22:28:00.0438 Scan finished
2010/12/01 22:28:00.0438 ================================================================================
2010/12/01 22:28:00.0457 Detected object count: 1
2010/12/01 22:29:56.0814 \HardDisk0 - will be cured after reboot
2010/12/01 22:29:56.0816 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure

This particular malware alters the MBR of the system drive to ensure persistent execution of malicious code. Essentially, it overwrites the MBR of the hard disk with its own code and stores a copy of the original MBR at another sector using rootkit techniques to hide itself. To learn more about these types of infections please refer to:Please reboot if you have not done so already. Rerun TDSSKiller again and post the new log to confirm the infection was cured.

Don't forget to post the results of the Malwarebytes' scan.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users