Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Search Engine Redirect virus


  • This topic is locked This topic is locked
6 replies to this topic

#1 Treefarn

Treefarn

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:09:30 AM

Posted 22 September 2011 - 09:07 PM

Whenever I do a search on any search engine, if I click on a link from the search results, they are getting redirected elsewhere. (They usually go through a site called morsearch.com.) I have run Malwarebytes, Adaware and SuperAntiSpyware after I updated them all. But it is still happening. Here is the logs from malwarebytes.

Please help!

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7777

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

9/22/2011 10:03:06 PM
mbam-log-2011-09-22 (22-03-06).txt

Scan type: Full scan (C:\|)
Objects scanned: 406144
Time elapsed: 56 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

BC AdBot (Login to Remove)

 


#2 Treefarn

Treefarn
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:09:30 AM

Posted 22 September 2011 - 09:27 PM

Here is Spybot results:

BurstMedia: Tracking cookie (Internet Explorer: neil) (Cookie, fixed)


WebTrends live: Tracking cookie (Internet Explorer: neil) (Cookie, fixed)


MediaPlex: Tracking cookie (Internet Explorer: neil) (Cookie, fixed)


DoubleClick: Tracking cookie (Chrome: Chrome) (Cookie, fixed)



--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-09-22 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-08-29 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-05-16 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-09-13 Includes\Malware.sbi (*)
2011-09-20 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-05-24 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2011-02-24 Includes\Security.sbi (*)
2011-05-03 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-06-14 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-13 Includes\Trojans.sbi (*)
2011-09-19 Includes\TrojansC-02.sbi (*)
2011-09-20 Includes\TrojansC-03.sbi (*)
2011-09-20 Includes\TrojansC-04.sbi (*)
2011-09-13 Includes\TrojansC-05.sbi (*)
2011-09-20 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

#3 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,906 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:30 AM

Posted 23 September 2011 - 08:40 PM

Hello amd welcome this file may come back.
.fsharproj

Please follow our Removal Guide here How to remove Google Redirects. You will move to the Automated Removal Instructions

If it finds something make sure Cure is selected
Next click Continue then Reboot now
A log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.


Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.

Please ask any needed questions,post logs and Let us know how the PC is running now.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#4 Treefarn

Treefarn
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:09:30 AM

Posted 24 September 2011 - 12:16 PM

Did the instructions, ran TDSS and Malwarebytes, still the same issue. The logs are below. It may be unrelated, but the last couple of times the computer has been rebooted, the first thing that pops up is a request to download a file. Not sure if it is the same file everytime, but it is always a PNG file. This time it asked to download 2 files, both of which I declined, dpctuhlk.png and trunidfl.png.

The last line of the MBAM log which shows a file that is infected was something my son downloaded on my last computer. We copied over some files from that computer onto this one, but that was 8 months ago. I don't think that is the issue. This is something that just started about 4 days ago. Anyway, I await your response and thank you in advance for the attention and assistance.




Here are the logs:

12:53:20.0775 6504 TDSS rootkit removing tool 2.6.0.0 Sep 23 2011 07:42:37
12:53:21.0029 6504 ============================================================
12:53:21.0030 6504 Current date / time: 2011/09/24 12:53:21.0029
12:53:21.0030 6504 SystemInfo:
12:53:21.0030 6504
12:53:21.0030 6504 OS Version: 6.1.7600 ServicePack: 0.0
12:53:21.0030 6504 Product type: Workstation
12:53:21.0030 6504 ComputerName: NEIL-PC
12:53:21.0031 6504 UserName: neil
12:53:21.0031 6504 Windows directory: C:\Windows
12:53:21.0031 6504 System windows directory: C:\Windows
12:53:21.0031 6504 Running under WOW64
12:53:21.0031 6504 Processor architecture: Intel x64
12:53:21.0031 6504 Number of processors: 4
12:53:21.0031 6504 Page size: 0x1000
12:53:21.0031 6504 Boot type: Normal boot
12:53:21.0031 6504 ============================================================
12:53:22.0166 6504 Initialize success
12:53:39.0693 2292 ============================================================
12:53:39.0693 2292 Scan started
12:53:39.0693 2292 Mode: Manual;
12:53:39.0693 2292 ============================================================
12:53:41.0134 2292 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
12:53:41.0139 2292 1394ohci - ok
12:53:41.0255 2292 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
12:53:41.0260 2292 ACPI - ok
12:53:41.0343 2292 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
12:53:41.0344 2292 AcpiPmi - ok
12:53:41.0455 2292 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
12:53:41.0462 2292 adp94xx - ok
12:53:41.0574 2292 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
12:53:41.0580 2292 adpahci - ok
12:53:41.0687 2292 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
12:53:41.0691 2292 adpu320 - ok
12:53:41.0835 2292 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
12:53:41.0845 2292 AFD - ok
12:53:41.0929 2292 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
12:53:41.0930 2292 agp440 - ok
12:53:42.0029 2292 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
12:53:42.0030 2292 aliide - ok
12:53:42.0044 2292 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
12:53:42.0045 2292 amdide - ok
12:53:42.0131 2292 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
12:53:42.0133 2292 AmdK8 - ok
12:53:42.0222 2292 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
12:53:42.0223 2292 AmdPPM - ok
12:53:42.0332 2292 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
12:53:42.0335 2292 amdsata - ok
12:53:42.0434 2292 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
12:53:42.0438 2292 amdsbs - ok
12:53:42.0533 2292 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
12:53:42.0533 2292 amdxata - ok
12:53:42.0623 2292 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
12:53:42.0625 2292 AppID - ok
12:53:42.0755 2292 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
12:53:42.0757 2292 arc - ok
12:53:42.0858 2292 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
12:53:42.0861 2292 arcsas - ok
12:53:42.0959 2292 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
12:53:42.0960 2292 AsyncMac - ok
12:53:43.0050 2292 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
12:53:43.0050 2292 atapi - ok
12:53:43.0185 2292 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
12:53:43.0194 2292 b06bdrv - ok
12:53:43.0290 2292 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
12:53:43.0294 2292 b57nd60a - ok
12:53:43.0498 2292 BCM43XX (810be94a9e42309b3f74217ac28bc6ac) C:\Windows\system32\DRIVERS\bcmwl664.sys
12:53:43.0564 2292 BCM43XX - ok
12:53:43.0669 2292 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
12:53:43.0670 2292 Beep - ok
12:53:43.0777 2292 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
12:53:43.0779 2292 blbdrive - ok
12:53:43.0899 2292 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
12:53:43.0901 2292 bowser - ok
12:53:43.0992 2292 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:53:43.0993 2292 BrFiltLo - ok
12:53:44.0003 2292 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:53:44.0004 2292 BrFiltUp - ok
12:53:44.0106 2292 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
12:53:44.0112 2292 Brserid - ok
12:53:44.0263 2292 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
12:53:44.0264 2292 BrSerWdm - ok
12:53:44.0341 2292 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
12:53:44.0342 2292 BrUsbMdm - ok
12:53:44.0430 2292 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
12:53:44.0431 2292 BrUsbSer - ok
12:53:44.0452 2292 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
12:53:44.0454 2292 BTHMODEM - ok
12:53:44.0548 2292 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
12:53:44.0550 2292 cdfs - ok
12:53:44.0655 2292 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
12:53:44.0658 2292 cdrom - ok
12:53:44.0756 2292 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
12:53:44.0758 2292 circlass - ok
12:53:44.0851 2292 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
12:53:44.0858 2292 CLFS - ok
12:53:44.0966 2292 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
12:53:44.0967 2292 CmBatt - ok
12:53:44.0992 2292 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
12:53:44.0994 2292 cmdide - ok
12:53:45.0080 2292 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
12:53:45.0823 2292 CNG - ok
12:53:45.0925 2292 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
12:53:45.0926 2292 Compbatt - ok
12:53:46.0030 2292 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
12:53:46.0032 2292 CompositeBus - ok
12:53:46.0133 2292 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
12:53:46.0134 2292 crcdisk - ok
12:53:46.0258 2292 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
12:53:46.0267 2292 CSC - ok
12:53:46.0395 2292 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
12:53:46.0398 2292 DfsC - ok
12:53:46.0500 2292 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
12:53:46.0502 2292 discache - ok
12:53:46.0589 2292 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
12:53:46.0591 2292 Disk - ok
12:53:46.0699 2292 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
12:53:46.0700 2292 drmkaud - ok
12:53:46.0826 2292 dsNcAdpt (3eef0b3489edbf725564e17c77cabafd) C:\Windows\system32\DRIVERS\dsNcAdpt.sys
12:53:46.0827 2292 dsNcAdpt - ok
12:53:46.0977 2292 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
12:53:46.0993 2292 DXGKrnl - ok
12:53:47.0177 2292 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
12:53:47.0242 2292 ebdrv - ok
12:53:47.0349 2292 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
12:53:47.0358 2292 elxstor - ok
12:53:47.0431 2292 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
12:53:47.0432 2292 ErrDev - ok
12:53:47.0530 2292 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
12:53:47.0534 2292 exfat - ok
12:53:47.0615 2292 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
12:53:47.0619 2292 fastfat - ok
12:53:47.0714 2292 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
12:53:47.0715 2292 fdc - ok
12:53:47.0811 2292 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
12:53:47.0813 2292 FileInfo - ok
12:53:47.0844 2292 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
12:53:47.0845 2292 Filetrace - ok
12:53:47.0928 2292 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
12:53:47.0929 2292 flpydisk - ok
12:53:48.0026 2292 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
12:53:48.0030 2292 FltMgr - ok
12:53:48.0114 2292 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
12:53:48.0116 2292 FsDepends - ok
12:53:48.0201 2292 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
12:53:48.0203 2292 Fs_Rec - ok
12:53:48.0317 2292 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
12:53:48.0321 2292 fvevol - ok
12:53:48.0410 2292 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
12:53:48.0412 2292 gagp30kx - ok
12:53:48.0453 2292 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
12:53:48.0454 2292 GEARAspiWDM - ok
12:53:48.0606 2292 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
12:53:48.0607 2292 hcw85cir - ok
12:53:48.0713 2292 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
12:53:48.0720 2292 HdAudAddService - ok
12:53:48.0817 2292 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
12:53:48.0820 2292 HDAudBus - ok
12:53:48.0899 2292 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
12:53:48.0900 2292 HidBatt - ok
12:53:48.0911 2292 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
12:53:48.0914 2292 HidBth - ok
12:53:48.0940 2292 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
12:53:48.0941 2292 HidIr - ok
12:53:49.0051 2292 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
12:53:49.0052 2292 HidUsb - ok
12:53:49.0162 2292 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
12:53:49.0164 2292 HpSAMD - ok
12:53:49.0267 2292 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
12:53:49.0283 2292 HTTP - ok
12:53:49.0381 2292 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
12:53:49.0382 2292 hwpolicy - ok
12:53:49.0486 2292 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
12:53:49.0489 2292 i8042prt - ok
12:53:49.0608 2292 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
12:53:49.0616 2292 iaStorV - ok
12:53:50.0068 2292 igfx (677aa5991026a65ada128c4b59cf2bad) C:\Windows\system32\DRIVERS\igdkmd64.sys
12:53:50.0310 2292 igfx - ok
12:53:50.0431 2292 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
12:53:50.0433 2292 iirsp - ok
12:53:50.0589 2292 IntcAzAudAddService (3c4b4ee54febb09f7e9f58776de96dca) C:\Windows\system32\drivers\RTKVHD64.sys
12:53:50.0633 2292 IntcAzAudAddService - ok
12:53:50.0749 2292 IntcDAud (03c74719d48056a1078f3a51ceb76baa) C:\Windows\system32\DRIVERS\IntcDAud.sys
12:53:50.0754 2292 IntcDAud - ok
12:53:50.0836 2292 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
12:53:50.0837 2292 intelide - ok
12:53:50.0930 2292 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
12:53:50.0932 2292 intelppm - ok
12:53:51.0045 2292 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:53:51.0047 2292 IpFilterDriver - ok
12:53:51.0061 2292 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
12:53:51.0063 2292 IPMIDRV - ok
12:53:51.0160 2292 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
12:53:51.0163 2292 IPNAT - ok
12:53:51.0274 2292 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
12:53:51.0275 2292 IRENUM - ok
12:53:51.0377 2292 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
12:53:51.0378 2292 isapnp - ok
12:53:51.0430 2292 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
12:53:51.0435 2292 iScsiPrt - ok
12:53:51.0504 2292 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
12:53:51.0506 2292 kbdclass - ok
12:53:51.0611 2292 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
12:53:51.0612 2292 kbdhid - ok
12:53:51.0691 2292 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
12:53:51.0693 2292 KSecDD - ok
12:53:51.0804 2292 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
12:53:51.0807 2292 KSecPkg - ok
12:53:51.0907 2292 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
12:53:51.0908 2292 ksthunk - ok
12:53:52.0061 2292 Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys
12:53:52.0062 2292 Lavasoft Kernexplorer - ok
12:53:52.0186 2292 Lbd (c8b3131857931ae76798a741cc52b021) C:\Windows\system32\DRIVERS\Lbd.sys
12:53:52.0187 2292 Lbd - ok
12:53:52.0297 2292 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
12:53:52.0299 2292 lltdio - ok
12:53:52.0407 2292 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
12:53:52.0409 2292 LSI_FC - ok
12:53:52.0513 2292 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
12:53:52.0515 2292 LSI_SAS - ok
12:53:52.0618 2292 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:53:52.0620 2292 LSI_SAS2 - ok
12:53:52.0715 2292 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:53:52.0717 2292 LSI_SCSI - ok
12:53:52.0814 2292 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
12:53:52.0817 2292 luafv - ok
12:53:52.0909 2292 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
12:53:52.0910 2292 megasas - ok
12:53:53.0006 2292 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
12:53:53.0010 2292 MegaSR - ok
12:53:53.0110 2292 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
12:53:53.0112 2292 Modem - ok
12:53:53.0211 2292 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
12:53:53.0213 2292 monitor - ok
12:53:53.0302 2292 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
12:53:53.0304 2292 mouclass - ok
12:53:53.0409 2292 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
12:53:53.0410 2292 mouhid - ok
12:53:53.0506 2292 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
12:53:53.0508 2292 mountmgr - ok
12:53:53.0600 2292 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
12:53:53.0603 2292 mpio - ok
12:53:53.0693 2292 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
12:53:53.0695 2292 mpsdrv - ok
12:53:53.0785 2292 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
12:53:53.0788 2292 MRxDAV - ok
12:53:53.0886 2292 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
12:53:53.0889 2292 mrxsmb - ok
12:53:54.0023 2292 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:53:54.0026 2292 mrxsmb10 - ok
12:53:54.0124 2292 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:53:54.0126 2292 mrxsmb20 - ok
12:53:54.0205 2292 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
12:53:54.0206 2292 msahci - ok
12:53:54.0298 2292 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
12:53:54.0301 2292 msdsm - ok
12:53:54.0421 2292 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
12:53:54.0421 2292 Msfs - ok
12:53:54.0532 2292 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
12:53:54.0533 2292 mshidkmdf - ok
12:53:54.0621 2292 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
12:53:54.0622 2292 msisadrv - ok
12:53:54.0740 2292 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
12:53:54.0741 2292 MSKSSRV - ok
12:53:54.0834 2292 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
12:53:54.0835 2292 MSPCLOCK - ok
12:53:54.0854 2292 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
12:53:54.0855 2292 MSPQM - ok
12:53:54.0946 2292 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
12:53:54.0955 2292 MsRPC - ok
12:53:55.0038 2292 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
12:53:55.0040 2292 mssmbios - ok
12:53:55.0131 2292 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
12:53:55.0132 2292 MSTEE - ok
12:53:55.0220 2292 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
12:53:55.0221 2292 MTConfig - ok
12:53:55.0300 2292 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
12:53:55.0301 2292 Mup - ok
12:53:55.0408 2292 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
12:53:55.0413 2292 NativeWifiP - ok
12:53:55.0530 2292 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
12:53:55.0544 2292 NDIS - ok
12:53:55.0642 2292 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
12:53:55.0643 2292 NdisCap - ok
12:53:55.0743 2292 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
12:53:55.0744 2292 NdisTapi - ok
12:53:55.0840 2292 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
12:53:55.0842 2292 Ndisuio - ok
12:53:55.0867 2292 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
12:53:55.0870 2292 NdisWan - ok
12:53:55.0969 2292 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
12:53:55.0971 2292 NDProxy - ok
12:53:56.0076 2292 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
12:53:56.0078 2292 NetBIOS - ok
12:53:56.0186 2292 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
12:53:56.0190 2292 NetBT - ok
12:53:56.0492 2292 NETwNs64 (eb43840babf5589e33186d094de7381d) C:\Windows\system32\DRIVERS\NETwNs64.sys
12:53:56.0571 2292 Suspicious file (Forged): C:\Windows\system32\DRIVERS\NETwNs64.sys. Real md5: eb43840babf5589e33186d094de7381d, Fake md5: d4105e6717e1e6208dead902b614f379
12:53:56.0603 2292 NETwNs64 ( ForgedFile.Multi.Generic ) - warning
12:53:56.0604 2292 NETwNs64 - detected ForgedFile.Multi.Generic (1)
12:53:56.0709 2292 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
12:53:56.0711 2292 nfrd960 - ok
12:53:56.0818 2292 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
12:53:56.0819 2292 Npfs - ok
12:53:56.0901 2292 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
12:53:56.0902 2292 nsiproxy - ok
12:53:57.0051 2292 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
12:53:57.0076 2292 Ntfs - ok
12:53:57.0160 2292 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
12:53:57.0161 2292 Null - ok
12:53:57.0269 2292 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
12:53:57.0272 2292 nvraid - ok
12:53:57.0371 2292 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
12:53:57.0375 2292 nvstor - ok
12:53:57.0475 2292 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
12:53:57.0477 2292 nv_agp - ok
12:53:57.0558 2292 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
12:53:57.0560 2292 ohci1394 - ok
12:53:57.0688 2292 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
12:53:57.0691 2292 Parport - ok
12:53:57.0768 2292 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
12:53:57.0770 2292 partmgr - ok
12:53:57.0863 2292 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
12:53:57.0866 2292 pci - ok
12:53:57.0883 2292 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
12:53:57.0884 2292 pciide - ok
12:53:57.0972 2292 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
12:53:57.0977 2292 pcmcia - ok
12:53:58.0066 2292 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
12:53:58.0066 2292 pcw - ok
12:53:58.0168 2292 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
12:53:58.0179 2292 PEAUTH - ok
12:53:58.0326 2292 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
12:53:58.0329 2292 PptpMiniport - ok
12:53:58.0440 2292 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
12:53:58.0442 2292 Processor - ok
12:53:58.0572 2292 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
12:53:58.0575 2292 Psched - ok
12:53:58.0716 2292 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
12:53:58.0740 2292 ql2300 - ok
12:53:58.0844 2292 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
12:53:58.0847 2292 ql40xx - ok
12:53:58.0943 2292 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
12:53:58.0944 2292 QWAVEdrv - ok
12:53:59.0081 2292 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
12:53:59.0126 2292 RasAcd - ok
12:53:59.0232 2292 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
12:53:59.0234 2292 RasAgileVpn - ok
12:53:59.0331 2292 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
12:53:59.0333 2292 Rasl2tp - ok
12:53:59.0435 2292 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
12:53:59.0437 2292 RasPppoe - ok
12:53:59.0531 2292 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
12:53:59.0534 2292 RasSstp - ok
12:53:59.0622 2292 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
12:53:59.0628 2292 rdbss - ok
12:53:59.0722 2292 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
12:53:59.0723 2292 rdpbus - ok
12:53:59.0809 2292 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
12:53:59.0810 2292 RDPCDD - ok
12:53:59.0851 2292 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
12:53:59.0854 2292 RDPDR - ok
12:53:59.0947 2292 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
12:53:59.0948 2292 RDPENCDD - ok
12:54:00.0041 2292 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
12:54:00.0042 2292 RDPREFMP - ok
12:54:00.0131 2292 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
12:54:00.0136 2292 RDPWD - ok
12:54:00.0238 2292 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
12:54:00.0241 2292 rdyboost - ok
12:54:00.0359 2292 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
12:54:00.0361 2292 rspndr - ok
12:54:00.0445 2292 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
12:54:00.0448 2292 RTL8167 - ok
12:54:00.0535 2292 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
12:54:00.0536 2292 s3cap - ok
12:54:00.0623 2292 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
12:54:00.0624 2292 SASDIFSV - ok
12:54:00.0642 2292 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
12:54:00.0643 2292 SASKUTIL - ok
12:54:00.0733 2292 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
12:54:00.0736 2292 sbp2port - ok
12:54:00.0835 2292 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
12:54:00.0836 2292 scfilter - ok
12:54:00.0940 2292 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
12:54:00.0941 2292 secdrv - ok
12:54:01.0042 2292 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
12:54:01.0043 2292 Serenum - ok
12:54:01.0165 2292 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
12:54:01.0167 2292 Serial - ok
12:54:01.0256 2292 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
12:54:01.0258 2292 sermouse - ok
12:54:01.0346 2292 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
12:54:01.0347 2292 sffdisk - ok
12:54:01.0429 2292 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
12:54:01.0430 2292 sffp_mmc - ok
12:54:01.0519 2292 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
12:54:01.0520 2292 sffp_sd - ok
12:54:01.0603 2292 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
12:54:01.0604 2292 sfloppy - ok
12:54:01.0702 2292 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:54:01.0704 2292 SiSRaid2 - ok
12:54:01.0795 2292 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
12:54:01.0797 2292 SiSRaid4 - ok
12:54:01.0900 2292 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
12:54:01.0902 2292 Smb - ok
12:54:02.0019 2292 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
12:54:02.0020 2292 spldr - ok
12:54:02.0160 2292 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
12:54:02.0169 2292 srv - ok
12:54:02.0281 2292 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
12:54:02.0289 2292 srv2 - ok
12:54:02.0411 2292 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
12:54:02.0414 2292 srvnet - ok
12:54:02.0511 2292 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
12:54:02.0512 2292 stexstor - ok
12:54:02.0632 2292 StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
12:54:02.0633 2292 StillCam - ok
12:54:02.0739 2292 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
12:54:02.0740 2292 storflt - ok
12:54:02.0835 2292 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
12:54:02.0837 2292 storvsc - ok
12:54:02.0927 2292 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
12:54:02.0929 2292 swenum - ok
12:54:03.0100 2292 SynTP (961cfac2a5318e212f459d651f28e0a4) C:\Windows\system32\DRIVERS\SynTP.sys
12:54:03.0126 2292 SynTP - ok
12:54:03.0285 2292 Tcpip (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\drivers\tcpip.sys
12:54:03.0310 2292 Tcpip - ok
12:54:03.0463 2292 TCPIP6 (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\DRIVERS\tcpip.sys
12:54:03.0483 2292 TCPIP6 - ok
12:54:03.0573 2292 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
12:54:03.0574 2292 tcpipreg - ok
12:54:03.0665 2292 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
12:54:03.0666 2292 TDPIPE - ok
12:54:03.0755 2292 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
12:54:03.0756 2292 TDTCP - ok
12:54:03.0846 2292 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
12:54:03.0849 2292 tdx - ok
12:54:03.0874 2292 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
12:54:03.0876 2292 TermDD - ok
12:54:03.0989 2292 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
12:54:03.0990 2292 tssecsrv - ok
12:54:04.0093 2292 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
12:54:04.0097 2292 tunnel - ok
12:54:04.0200 2292 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
12:54:04.0202 2292 uagp35 - ok
12:54:04.0231 2292 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
12:54:04.0237 2292 udfs - ok
12:54:04.0346 2292 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
12:54:04.0347 2292 uliagpkx - ok
12:54:04.0442 2292 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
12:54:04.0443 2292 umbus - ok
12:54:04.0553 2292 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
12:54:04.0554 2292 UmPass - ok
12:54:04.0666 2292 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys
12:54:04.0667 2292 USBAAPL64 - ok
12:54:04.0779 2292 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
12:54:04.0781 2292 usbccgp - ok
12:54:04.0865 2292 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
12:54:04.0867 2292 usbcir - ok
12:54:04.0980 2292 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\drivers\usbehci.sys
12:54:04.0982 2292 usbehci - ok
12:54:05.0097 2292 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
12:54:05.0103 2292 usbhub - ok
12:54:05.0202 2292 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
12:54:05.0203 2292 usbohci - ok
12:54:05.0300 2292 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
12:54:05.0301 2292 usbprint - ok
12:54:05.0402 2292 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:54:05.0404 2292 USBSTOR - ok
12:54:05.0519 2292 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\drivers\usbuhci.sys
12:54:05.0520 2292 usbuhci - ok
12:54:05.0633 2292 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
12:54:05.0637 2292 usbvideo - ok
12:54:05.0744 2292 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
12:54:05.0745 2292 vdrvroot - ok
12:54:05.0842 2292 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
12:54:05.0843 2292 vga - ok
12:54:05.0927 2292 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
12:54:05.0928 2292 VgaSave - ok
12:54:06.0027 2292 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
12:54:06.0031 2292 vhdmp - ok
12:54:06.0054 2292 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
12:54:06.0055 2292 viaide - ok
12:54:06.0142 2292 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
12:54:06.0146 2292 vmbus - ok
12:54:06.0231 2292 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
12:54:06.0232 2292 VMBusHID - ok
12:54:06.0336 2292 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
12:54:06.0338 2292 volmgr - ok
12:54:06.0440 2292 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
12:54:06.0447 2292 volmgrx - ok
12:54:06.0538 2292 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
12:54:06.0543 2292 volsnap - ok
12:54:06.0643 2292 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
12:54:06.0647 2292 vsmraid - ok
12:54:06.0740 2292 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
12:54:06.0741 2292 vwifibus - ok
12:54:06.0828 2292 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
12:54:06.0830 2292 vwififlt - ok
12:54:06.0930 2292 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
12:54:06.0931 2292 vwifimp - ok
12:54:07.0027 2292 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
12:54:07.0029 2292 WacomPen - ok
12:54:07.0122 2292 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
12:54:07.0124 2292 WANARP - ok
12:54:07.0139 2292 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
12:54:07.0141 2292 Wanarpv6 - ok
12:54:07.0253 2292 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
12:54:07.0254 2292 Wd - ok
12:54:07.0357 2292 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
12:54:07.0369 2292 Wdf01000 - ok
12:54:07.0489 2292 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
12:54:07.0490 2292 WfpLwf - ok
12:54:07.0588 2292 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
12:54:07.0589 2292 WIMMount - ok
12:54:07.0741 2292 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
12:54:07.0743 2292 WinUsb - ok
12:54:07.0853 2292 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
12:54:07.0855 2292 WmiAcpi - ok
12:54:07.0973 2292 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
12:54:07.0975 2292 ws2ifsl - ok
12:54:08.0094 2292 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
12:54:08.0095 2292 WSDPrintDevice - ok
12:54:08.0194 2292 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
12:54:08.0197 2292 WudfPf - ok
12:54:08.0318 2292 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
12:54:08.0322 2292 WUDFRd - ok
12:54:08.0376 2292 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
12:54:08.0391 2292 \Device\Harddisk0\DR0 - ok
12:54:08.0395 2292 Boot (0x1200) (f2b55e1afd5a324821bff010572b3a9c) \Device\Harddisk0\DR0\Partition0
12:54:08.0396 2292 \Device\Harddisk0\DR0\Partition0 - ok
12:54:08.0408 2292 Boot (0x1200) (8ab78f72e11346693df1a64d9eb9cb02) \Device\Harddisk0\DR0\Partition1
12:54:08.0409 2292 \Device\Harddisk0\DR0\Partition1 - ok
12:54:08.0410 2292 ============================================================
12:54:08.0410 2292 Scan finished
12:54:08.0410 2292 ============================================================
12:54:08.0425 5592 Detected object count: 1
12:54:08.0425 5592 Actual detected object count: 1
12:54:37.0391 5592 NETwNs64 ( ForgedFile.Multi.Generic ) - skipped by user
12:54:37.0391 5592 NETwNs64 ( ForgedFile.Multi.Generic ) - User select action: Skip
12:55:00.0890 1780 Deinitialize success



MBAM

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7467

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

8/14/2011 9:37:37 PM
mbam-log-2011-08-14 (21-37-37).txt

Scan type: Full scan (C:\|)
Objects scanned: 462154
Time elapsed: 1 hour(s), 8 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\neil\Desktop\from old computer\Work\languages\rosetta stone v3 app and crack\rosetta stone v3.2\rosetta stone v3.2 - patch.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.

#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,906 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:30 AM

Posted 26 September 2011 - 11:40 AM

The problem is the rosetta stone is a cracked (stolen) version it has infected the PC.

IMPORTANT NOTE: The practice of using cracking tools, keygens, warez or any pirated software is not only considered illegal activity but it is a serious security risk.

Cracking applications are used for illegally breaking (cracking) various copy-protection and registration techniques used in commercial software. These programs may be distributed via Web sites, Usenet, and P2P networks.

trendmicro.com/vinfo

...warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files...quick links in these sites also lead to malicious files. Ads and banners are also infection vectors...

Keygen and Crack Sites Distribute VIRUX and FakeAV

...warez/piracy sites ranked the highest in downloading spyware...just opening the web page usually sets off an exploit, never mind actually downloading anything. And by the time the malware is finished downloading, often the machine is trashed and rendered useless.

University of Washington spyware study

...One of the most aggressive and intrusive of all bad websites on the Internet are serial, warez, software cracking type sites...they sneak malware onto your system...Where do trojan viruses originate? One of the biggest malware distributors on the Internet are serial/warez/code cracking sites.

Bad Web Sites: Malware

When you use these kind of programs, be forewarned that some of the worst types of malware infections can be contracted and spread by visiting crack, keygen, warez and other pirated software sites. In many cases, those sites are infested with a smörgåsbord of malware and an increasing source of system infection. Those who attempt to get software for free can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.

Before we can continue, I need you to remove all cracks and keygens immediately to reduce the risk of infection/reinfection. If not, then we are just wasting time trying to clean your system. Further, other tools used during the disinfection process may detect crack and keygens so we need to ensure they have been removed.

Using these types of programs or the websites you visited to get them is almost a guaranteed way to get yourself infected!!


After removal you will need to post here.

Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
If Gmer won't run,skip it and move on.
Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 Treefarn

Treefarn
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:09:30 AM

Posted 29 September 2011 - 02:45 PM

Thanks. I have followed your instructions and created a new thread.

I physically removed the entire folder for 'Rosetta Stone' as requested in the other thread. It should be noted that that folder, that download, has never been accessed on this computer. That was downloaded on a previous computer. When we got a new computer, I copied over what I thought were important personal folders onto this new computer. No one has ever touched anything in that folder on this computer. I copied over that folder to this computer about 8 months ago, but the google redirect issue started about 2 weeks ago, so I am not certain this is the cause.

The new thread is at http://www.bleepingcomputer.com/forums/topic421113.html

#7 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,846 posts
  • ONLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:09:30 AM

Posted 01 October 2011 - 02:32 AM

Hello,

Now for the hard and frustrating part: waiting.

Now that you have posted a log, you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users