Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Potential infection causing svchost to take over computer


  • Please log in to reply
1 reply to this topic

#1 kc61

kc61

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 05 March 2011 - 11:21 AM

Everyone,

I have just joined the forum and look forward to interacting with all of you. I am an amateur computer user at best, but enjoy troubleshooting computer problems (sometimes).

I am having a very tricky issue with an old computer running Windows XP Professional sp3. I am seeing multiple symptoms, but I believe they may all have their root cause in one malware problem. Here's what's happening:

1. I continue to see an instance of svchost.exe take over the computer's memory and CPU. I have tried to troubleshoot this via Windows patches, disabling Windows update, etc but nothing consistently works.

2. When I try to use "Windows Update", my browser goes to the windowsupdate.microsoft.com site but the page will not load. I have tried using both Firefox 4 Beta (getting the message - "problem loading page - connection has timed out")and Internet explorer 8 (getting the message "Internet Explorer cannot display the webpage"). I tried a Microsoft Fixit update (50202) to update all of the Windows Update components but it doesn't appear to have worked.

3. When using either IE8 or Firefox, I get random webpages popping up on a new tab.

4. I have Norton 360 v5 installed and it frequently reports that is has block intrusion attempts or other attacks. I have run full systems scans and, while clearing some problems (Trojan.Gen.2, trojan.Pidief, suspicious.AD, Trojan.ADH.2), it has not stopped the above from continuing.

Thanks in advance for any help you might offer!

Edited by hamluis, 05 March 2011 - 01:06 PM.
Moved from XP forum to Am I Infected.


BC AdBot (Login to Remove)

 


#2 kc61

kc61
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 05 March 2011 - 06:07 PM

Although I haven't received any replies yet, I did want to post an update on my issue. In reading responses to other similar issues on this site, I saw that the first recommended step usual was to download and run the Kaspersky TDSSkiller program. I went ahead and did this and it seems to have cured my issue - I can now access Windows Update, no annoying browser redirects, no intrusion alerts (yet) and the svchost programs seem to be behaving.

I am copying the log from TDSSkiller here to add its diagnosis to the record (it seems to have found a problem from within the "Rootkit.Win32.TDSS" family [tdl4] - info on this class of issue is available on the Kaspersky site):

2011/03/05 17:19:39.0734 2840 TDSS rootkit removing tool 2.4.20.0 Mar 2 2011 10:44:30
2011/03/05 17:19:41.0031 2840 ================================================================================
2011/03/05 17:19:41.0031 2840 SystemInfo:
2011/03/05 17:19:41.0031 2840
2011/03/05 17:19:41.0031 2840 OS Version: 5.1.2600 ServicePack: 3.0
2011/03/05 17:19:41.0031 2840 Product type: Workstation
2011/03/05 17:19:41.0031 2840 ComputerName: HP7020LAPTOP

2011/03/05 17:19:41.0031 2840 Windows directory: C:\WINDOWS
2011/03/05 17:19:41.0031 2840 System windows directory: C:\WINDOWS
2011/03/05 17:19:41.0031 2840 Processor architecture: Intel x86
2011/03/05 17:19:41.0031 2840 Number of processors: 1
2011/03/05 17:19:41.0031 2840 Page size: 0x1000
2011/03/05 17:19:41.0031 2840 Boot type: Normal boot
2011/03/05 17:19:41.0031 2840 ================================================================================
2011/03/05 17:19:42.0343 2840 Initialize success
2011/03/05 17:19:50.0750 3180 ================================================================================
2011/03/05 17:19:50.0750 3180 Scan started
2011/03/05 17:19:50.0750 3180 Mode: Manual;
2011/03/05 17:19:50.0750 3180 ================================================================================
2011/03/05 17:19:52.0968 3180 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/03/05 17:19:53.0015 3180 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/03/05 17:19:53.0156 3180 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/03/05 17:19:53.0250 3180 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/03/05 17:19:53.0375 3180 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/03/05 17:19:53.0562 3180 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/03/05 17:19:53.0718 3180 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/03/05 17:19:53.0750 3180 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/03/05 17:19:53.0859 3180 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/03/05 17:19:53.0937 3180 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/03/05 17:19:54.0031 3180 BCM43XX (1b1cf5e962c15abca83d1ef2b3906e2f) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
2011/03/05 17:19:54.0125 3180 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/03/05 17:19:54.0390 3180 BHDrvx86 (32d6e07922d17bed40ae746fc86b8a68) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110225.002\BHDrvx86.sys
2011/03/05 17:19:54.0593 3180 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
2011/03/05 17:19:54.0625 3180 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
2011/03/05 17:19:54.0703 3180 CAMCAUD (d717659e299998fcc5538c5e5d7d515d) C:\WINDOWS\system32\drivers\camcaud.sys
2011/03/05 17:19:54.0796 3180 CAMCHALA (fcec25c999b3b46f12aebcc172503804) C:\WINDOWS\system32\drivers\camchal.sys
2011/03/05 17:19:54.0890 3180 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/03/05 17:19:54.0984 3180 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/03/05 17:19:55.0109 3180 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/03/05 17:19:55.0140 3180 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/03/05 17:19:55.0203 3180 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/03/05 17:19:55.0328 3180 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/03/05 17:19:55.0406 3180 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/03/05 17:19:55.0562 3180 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/03/05 17:19:55.0656 3180 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/03/05 17:19:55.0734 3180 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys
2011/03/05 17:19:55.0765 3180 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/03/05 17:19:55.0828 3180 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/03/05 17:19:55.0906 3180 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/03/05 17:19:55.0968 3180 eabfiltr (313ace43944bf93852d1e298cf35d2c8) C:\WINDOWS\System32\drivers\EABFiltr.sys
2011/03/05 17:19:56.0031 3180 eabusb (1ba14da377b66278335d4b9e8824cd42) C:\WINDOWS\System32\drivers\eabusb.sys
2011/03/05 17:19:56.0218 3180 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2011/03/05 17:19:56.0390 3180 EMCR (7f07571f50353b42e6a2d93f07bec118) C:\WINDOWS\system32\DRIVERS\EMCR7SK.sys
2011/03/05 17:19:56.0468 3180 ENECBPTH (1fec25c49afbc34accbf3dc53031affe) C:\WINDOWS\system32\drivers\ENECBPTH.sys
2011/03/05 17:19:56.0656 3180 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
2011/03/05 17:19:56.0750 3180 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/03/05 17:19:56.0906 3180 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/03/05 17:19:57.0000 3180 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/03/05 17:19:57.0078 3180 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/03/05 17:19:57.0140 3180 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/03/05 17:19:57.0171 3180 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/03/05 17:19:57.0203 3180 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/03/05 17:19:57.0312 3180 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2011/03/05 17:19:57.0390 3180 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/03/05 17:19:57.0515 3180 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/03/05 17:19:57.0625 3180 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2011/03/05 17:19:57.0703 3180 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2011/03/05 17:19:57.0796 3180 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2011/03/05 17:19:58.0046 3180 HSFHWICH (2d9f10d6e7baa20c4526ce6a16444581) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
2011/03/05 17:19:58.0171 3180 HSF_DP (2d566a7f0b4c54b417ac637cb608444b) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
2011/03/05 17:19:58.0359 3180 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/03/05 17:19:58.0500 3180 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/03/05 17:19:58.0812 3180 IDSxpx86 (0308238c582a55d83d34feee39542793) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110303.001\IDSxpx86.sys
2011/03/05 17:19:58.0968 3180 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/03/05 17:19:59.0125 3180 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/03/05 17:19:59.0187 3180 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/03/05 17:19:59.0250 3180 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/03/05 17:19:59.0359 3180 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/03/05 17:19:59.0421 3180 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/03/05 17:19:59.0500 3180 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/03/05 17:19:59.0578 3180 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
2011/03/05 17:19:59.0609 3180 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/03/05 17:19:59.0703 3180 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/03/05 17:19:59.0765 3180 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/03/05 17:19:59.0828 3180 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/03/05 17:19:59.0875 3180 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/03/05 17:20:00.0000 3180 mdmxsdk (b72d7ea394d5f1c5053368783ad7f7ed) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/03/05 17:20:00.0078 3180 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/03/05 17:20:00.0156 3180 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/03/05 17:20:00.0203 3180 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/03/05 17:20:00.0234 3180 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/03/05 17:20:00.0281 3180 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/03/05 17:20:00.0453 3180 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
2011/03/05 17:20:00.0562 3180 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
2011/03/05 17:20:00.0656 3180 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/03/05 17:20:00.0734 3180 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/03/05 17:20:00.0796 3180 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/03/05 17:20:00.0859 3180 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/03/05 17:20:00.0906 3180 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/03/05 17:20:00.0953 3180 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/03/05 17:20:01.0015 3180 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/03/05 17:20:01.0078 3180 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/03/05 17:20:01.0125 3180 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/03/05 17:20:01.0171 3180 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/03/05 17:20:01.0421 3180 NAVENG (c8ef74e4d8105b1d02d58ea4734cf616) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110305.002\NAVENG.SYS
2011/03/05 17:20:01.0578 3180 NAVEX15 (94b3164055d821a62944d9fe84036470) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110305.002\NAVEX15.SYS
2011/03/05 17:20:01.0796 3180 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/03/05 17:20:01.0843 3180 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/03/05 17:20:01.0906 3180 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/03/05 17:20:02.0000 3180 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/03/05 17:20:02.0031 3180 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/03/05 17:20:02.0078 3180 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/03/05 17:20:02.0140 3180 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/03/05 17:20:02.0187 3180 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/03/05 17:20:02.0265 3180 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/03/05 17:20:02.0312 3180 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/03/05 17:20:02.0328 3180 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys
2011/03/05 17:20:02.0390 3180 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/03/05 17:20:02.0562 3180 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/03/05 17:20:02.0703 3180 nv (d21cdbd7c5fce5d3dfbd2f3859e1eb4e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/03/05 17:20:02.0828 3180 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/03/05 17:20:02.0875 3180 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/03/05 17:20:02.0984 3180 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/03/05 17:20:03.0062 3180 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/03/05 17:20:03.0109 3180 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/03/05 17:20:03.0156 3180 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/03/05 17:20:03.0218 3180 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/03/05 17:20:03.0296 3180 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/03/05 17:20:03.0359 3180 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/03/05 17:20:03.0640 3180 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/03/05 17:20:03.0687 3180 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/03/05 17:20:03.0734 3180 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/03/05 17:20:03.0765 3180 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/03/05 17:20:04.0015 3180 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/03/05 17:20:04.0125 3180 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
2011/03/05 17:20:04.0234 3180 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/03/05 17:20:04.0281 3180 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/03/05 17:20:04.0312 3180 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/03/05 17:20:04.0375 3180 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/03/05 17:20:04.0421 3180 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/03/05 17:20:04.0500 3180 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/03/05 17:20:04.0578 3180 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/03/05 17:20:04.0625 3180 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/03/05 17:20:04.0734 3180 rtl8139 (2ef9c0dc26b30b2318b1fc3faa1f0ae7) C:\WINDOWS\system32\DRIVERS\R8139n51.SYS
2011/03/05 17:20:04.0828 3180 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/03/05 17:20:04.0906 3180 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
2011/03/05 17:20:04.0984 3180 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/03/05 17:20:05.0093 3180 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/03/05 17:20:05.0171 3180 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/03/05 17:20:05.0234 3180 SQTECH905C (e3879c514f59402e1a7ce58a5511816f) C:\WINDOWS\system32\Drivers\Capt905c.sys
2011/03/05 17:20:05.0312 3180 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/03/05 17:20:05.0421 3180 SRTSP (a7a104a61c4e30de9c58f8c372a5c209) C:\WINDOWS\system32\drivers\N360\0500000.07D\SRTSP.SYS
2011/03/05 17:20:05.0515 3180 SRTSPX (2833445f786bd000bb14c84a9d91347a) C:\WINDOWS\system32\drivers\N360\0500000.07D\SRTSPX.SYS
2011/03/05 17:20:05.0593 3180 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/03/05 17:20:05.0687 3180 StreamDispatcher (3e5aa17e13fba9969d17b5455bde8efd) C:\WINDOWS\system32\DRIVERS\strmdisp.sys
2011/03/05 17:20:05.0765 3180 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/03/05 17:20:05.0812 3180 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/03/05 17:20:05.0859 3180 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/03/05 17:20:06.0000 3180 SymDS (bdf077b897b5f9f929b6bf0cfd436962) C:\WINDOWS\system32\drivers\N360\0500000.07D\SYMDS.SYS
2011/03/05 17:20:06.0078 3180 SymEFA (7732298ad2eddd364c1d4f439d99ae7c) C:\WINDOWS\system32\drivers\N360\0500000.07D\SYMEFA.SYS
2011/03/05 17:20:06.0187 3180 SymEvent (5c76a63fac8a5580c5a1c4a4ed827782) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
2011/03/05 17:20:06.0234 3180 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\WINDOWS\system32\drivers\N360\0500000.07D\Ironx86.SYS
2011/03/05 17:20:06.0296 3180 SYMTDI (8c07683bf02b63ad71bcb2cf28af2d06) C:\WINDOWS\system32\drivers\N360\0500000.07D\SYMTDI.SYS
2011/03/05 17:20:06.0421 3180 SynTP (8a13f2ac3742a287578057f658fb01a0) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/03/05 17:20:06.0546 3180 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/03/05 17:20:06.0640 3180 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/03/05 17:20:06.0734 3180 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/03/05 17:20:06.0796 3180 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/03/05 17:20:06.0906 3180 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/03/05 17:20:07.0031 3180 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/03/05 17:20:07.0125 3180 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/03/05 17:20:07.0203 3180 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
2011/03/05 17:20:07.0265 3180 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/03/05 17:20:07.0359 3180 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/03/05 17:20:07.0421 3180 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/03/05 17:20:07.0484 3180 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/03/05 17:20:07.0546 3180 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/03/05 17:20:07.0656 3180 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/03/05 17:20:07.0734 3180 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/03/05 17:20:07.0765 3180 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/03/05 17:20:07.0843 3180 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/03/05 17:20:07.0953 3180 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/03/05 17:20:08.0062 3180 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/03/05 17:20:08.0171 3180 winachsf (88a5f20c6c221e50f01c00d8235db8c4) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/03/05 17:20:08.0265 3180 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
2011/03/05 17:20:08.0390 3180 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/03/05 17:20:08.0468 3180 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/03/05 17:20:08.0484 3180 ================================================================================
2011/03/05 17:20:08.0484 3180 Scan finished
2011/03/05 17:20:08.0484 3180 ================================================================================
2011/03/05 17:20:08.0484 3172 Detected object count: 1
2011/03/05 17:20:27.0500 3172 \HardDisk0 - will be cured after reboot
2011/03/05 17:20:27.0500 3172 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2011/03/05 17:20:40.0390 3892 Deinitialize success




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users