Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus, search engine redirect variety


  • This topic is locked This topic is locked
21 replies to this topic

#1 JayBallz

JayBallz

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 10 October 2011 - 07:11 PM

Hi, gang. I've been reading some other threads so I got a jump start, and did a TDSSKiller scan. Those results lie ahead. I am experiencing a search engine hijacking virus.

Using XP...can't get Malware Bytes or SuperAntiSpyware to run, obviously....I get some windows explorer crashes as well as Windows Security Cntr warnings/pop ups....my searches result in being redirected to Star feedsmixer and some other ad sites.

Noticeable problems on the PC started yesterday. I'll paste my TDSSKiller report below. Please let me know what other info I can post. Thanks so much.


22:20:04.0203 1132 TDSS rootkit removing tool 2.6.6.0 Oct 7 2011 12:45:24
22:20:04.0718 1132 ============================================================
22:20:04.0718 1132 Current date / time: 2011/10/09 22:20:04.0718
22:20:04.0718 1132 SystemInfo:
22:20:04.0718 1132
22:20:04.0718 1132 OS Version: 5.1.2600 ServicePack: 3.0
22:20:04.0718 1132 Product type: Workstation
22:20:04.0718 1132 ComputerName: ACER-330BB84976
22:20:04.0718 1132 UserName: Jason .....
22:20:04.0718 1132 Windows directory: C:\WINDOWS
22:20:04.0718 1132 System windows directory: C:\WINDOWS
22:20:04.0718 1132 Processor architecture: Intel x86
22:20:04.0718 1132 Number of processors: 2
22:20:04.0718 1132 Page size: 0x1000
22:20:04.0718 1132 Boot type: Normal boot
22:20:04.0718 1132 ============================================================
22:20:05.0343 1132 Initialize success
22:20:07.0875 0668 ============================================================
22:20:07.0875 0668 Scan started
22:20:07.0875 0668 Mode: Manual;
22:20:07.0875 0668 ============================================================
22:20:08.0218 0668 28be5bc8 (8f2bb1827cac01aee6a16e30a1260199) C:\WINDOWS\3361455656:3611403319.exe
22:20:08.0406 0668 Suspicious file (Hidden): C:\WINDOWS\3361455656:3611403319.exe. md5: 8f2bb1827cac01aee6a16e30a1260199
22:20:08.0406 0668 28be5bc8 ( HiddenFile.Multi.Generic ) - warning
22:20:08.0406 0668 28be5bc8 - detected HiddenFile.Multi.Generic (1)
22:20:08.0484 0668 Abiosdsk - ok
22:20:08.0593 0668 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
22:20:08.0593 0668 abp480n5 - ok
22:20:08.0656 0668 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:20:08.0671 0668 ACPI - ok
22:20:08.0750 0668 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
22:20:08.0750 0668 ACPIEC - ok
22:20:08.0875 0668 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
22:20:08.0875 0668 adpu160m - ok
22:20:08.0968 0668 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
22:20:08.0968 0668 aec - ok
22:20:09.0093 0668 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
22:20:09.0109 0668 AFD - ok
22:20:09.0171 0668 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
22:20:09.0171 0668 agp440 - ok
22:20:09.0203 0668 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
22:20:09.0203 0668 agpCPQ - ok
22:20:09.0234 0668 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
22:20:09.0234 0668 Aha154x - ok
22:20:09.0328 0668 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
22:20:09.0328 0668 aic78u2 - ok
22:20:09.0359 0668 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
22:20:09.0359 0668 aic78xx - ok
22:20:09.0406 0668 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
22:20:09.0406 0668 AliIde - ok
22:20:09.0453 0668 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
22:20:09.0468 0668 alim1541 - ok
22:20:09.0578 0668 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys
22:20:09.0671 0668 Ambfilt - ok
22:20:09.0781 0668 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
22:20:09.0796 0668 amdagp - ok
22:20:09.0828 0668 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
22:20:09.0828 0668 amsint - ok
22:20:09.0937 0668 AR5416 (2b7b6a3305fc34a543d34013c14d02a2) C:\WINDOWS\system32\DRIVERS\athw.sys
22:20:10.0015 0668 AR5416 - ok
22:20:10.0125 0668 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
22:20:10.0125 0668 asc - ok
22:20:10.0171 0668 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
22:20:10.0171 0668 asc3350p - ok
22:20:10.0187 0668 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
22:20:10.0203 0668 asc3550 - ok
22:20:10.0281 0668 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:20:10.0281 0668 AsyncMac - ok
22:20:10.0312 0668 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:20:10.0312 0668 atapi - ok
22:20:10.0390 0668 Atdisk - ok
22:20:10.0453 0668 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:20:10.0453 0668 Atmarpc - ok
22:20:10.0515 0668 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:20:10.0515 0668 audstub - ok
22:20:10.0546 0668 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:20:10.0546 0668 Beep - ok
22:20:10.0703 0668 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
22:20:10.0703 0668 cbidf - ok
22:20:10.0718 0668 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:20:10.0734 0668 cbidf2k - ok
22:20:10.0781 0668 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:20:10.0781 0668 CCDECODE - ok
22:20:10.0796 0668 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
22:20:10.0796 0668 cd20xrnt - ok
22:20:10.0843 0668 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:20:10.0843 0668 Cdaudio - ok
22:20:10.0968 0668 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
22:20:10.0968 0668 Cdfs - ok
22:20:11.0031 0668 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:20:11.0031 0668 Cdrom - ok
22:20:11.0046 0668 Changer - ok
22:20:11.0125 0668 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
22:20:11.0125 0668 CmBatt - ok
22:20:11.0171 0668 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
22:20:11.0171 0668 CmdIde - ok
22:20:11.0281 0668 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
22:20:11.0281 0668 Compbatt - ok
22:20:11.0328 0668 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
22:20:11.0343 0668 Cpqarray - ok
22:20:11.0375 0668 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
22:20:11.0375 0668 dac2w2k - ok
22:20:11.0406 0668 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
22:20:11.0406 0668 dac960nt - ok
22:20:11.0453 0668 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
22:20:11.0453 0668 Disk - ok
22:20:11.0593 0668 DKbFltr (08d30af92c270f2e76787c81589dbad6) C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
22:20:11.0593 0668 DKbFltr - ok
22:20:11.0687 0668 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
22:20:11.0703 0668 dmboot - ok
22:20:11.0796 0668 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
22:20:11.0812 0668 dmio - ok
22:20:11.0843 0668 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:20:11.0843 0668 dmload - ok
22:20:11.0875 0668 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
22:20:11.0875 0668 DMusic - ok
22:20:11.0937 0668 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
22:20:11.0937 0668 dpti2o - ok
22:20:12.0046 0668 DritekPortIO (5c918d413f5837e67a85775c9873775e) C:\PROGRA~1\LAUNCH~1\DPortIO.sys
22:20:12.0046 0668 DritekPortIO - ok
22:20:12.0156 0668 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
22:20:12.0156 0668 drmkaud - ok
22:20:12.0218 0668 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
22:20:12.0234 0668 Fastfat - ok
22:20:12.0296 0668 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
22:20:12.0296 0668 Fdc - ok
22:20:12.0312 0668 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
22:20:12.0312 0668 Fips - ok
22:20:12.0406 0668 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
22:20:12.0406 0668 Flpydisk - ok
22:20:12.0453 0668 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:20:12.0468 0668 FltMgr - ok
22:20:12.0500 0668 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:20:12.0500 0668 Fs_Rec - ok
22:20:12.0531 0668 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:20:12.0531 0668 Ftdisk - ok
22:20:12.0671 0668 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
22:20:12.0671 0668 GEARAspiWDM - ok
22:20:12.0734 0668 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:20:12.0734 0668 Gpc - ok
22:20:12.0796 0668 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:20:12.0812 0668 HDAudBus - ok
22:20:12.0953 0668 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
22:20:12.0953 0668 hpn - ok
22:20:13.0031 0668 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
22:20:13.0031 0668 HTTP - ok
22:20:13.0171 0668 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
22:20:13.0171 0668 i2omgmt - ok
22:20:13.0203 0668 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
22:20:13.0203 0668 i2omp - ok
22:20:13.0281 0668 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:20:13.0281 0668 i8042prt - ok
22:20:13.0593 0668 ialm (48846b31be5a4fa662ccfde7a1ba86b9) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
22:20:13.0750 0668 ialm - ok
22:20:13.0859 0668 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\WINDOWS\system32\drivers\iaStor.sys
22:20:13.0859 0668 iaStor - ok
22:20:13.0921 0668 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:20:13.0921 0668 Imapi - ok
22:20:14.0000 0668 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
22:20:14.0000 0668 ini910u - ok
22:20:14.0015 0668 int15.sys - ok
22:20:14.0265 0668 IntcAzAudAddService (cb1113029fae50c685198eabd9885161) C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:20:14.0406 0668 IntcAzAudAddService - ok
22:20:14.0531 0668 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
22:20:14.0546 0668 IntelIde - ok
22:20:14.0578 0668 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:20:14.0578 0668 intelppm - ok
22:20:14.0625 0668 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:20:14.0625 0668 Ip6Fw - ok
22:20:14.0718 0668 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:20:14.0718 0668 IpFilterDriver - ok
22:20:14.0750 0668 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:20:14.0765 0668 IpInIp - ok
22:20:14.0796 0668 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:20:14.0796 0668 IpNat - ok
22:20:14.0859 0668 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:20:14.0859 0668 IPSec - ok
22:20:14.0968 0668 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:20:14.0968 0668 IRENUM - ok
22:20:15.0031 0668 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:20:15.0031 0668 isapnp - ok
22:20:15.0078 0668 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:20:15.0078 0668 Kbdclass - ok
22:20:15.0140 0668 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
22:20:15.0140 0668 kmixer - ok
22:20:15.0265 0668 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
22:20:15.0265 0668 KSecDD - ok
22:20:15.0328 0668 L1c (6c8658587e91ea25b0fd2e71781ad228) C:\WINDOWS\system32\DRIVERS\l1c51x86.sys
22:20:15.0328 0668 L1c - ok
22:20:15.0359 0668 lbrtfdc - ok
22:20:15.0437 0668 M3000Srv (73fd60fda3ff60f0666e4614e93f0aaa) C:\WINDOWS\system32\Drivers\M3000KNT.sys
22:20:15.0437 0668 M3000Srv - ok
22:20:15.0546 0668 MBAMSwissArmy (0905dc0814d738cff53577a59ccd81e0) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
22:20:15.0546 0668 MBAMSwissArmy - ok
22:20:15.0625 0668 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:20:15.0625 0668 mnmdd - ok
22:20:15.0671 0668 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
22:20:15.0671 0668 Modem - ok
22:20:15.0828 0668 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys
22:20:15.0859 0668 Monfilt - ok
22:20:15.0984 0668 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:20:15.0984 0668 Mouclass - ok
22:20:16.0031 0668 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
22:20:16.0031 0668 MountMgr - ok
22:20:16.0078 0668 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
22:20:16.0078 0668 mraid35x - ok
22:20:16.0171 0668 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:20:16.0171 0668 MRxDAV - ok
22:20:16.0234 0668 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
22:20:16.0234 0668 Msfs - ok
22:20:16.0281 0668 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:20:16.0281 0668 MSKSSRV - ok
22:20:16.0328 0668 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:20:16.0328 0668 MSPCLOCK - ok
22:20:16.0390 0668 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
22:20:16.0390 0668 MSPQM - ok
22:20:16.0437 0668 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:20:16.0437 0668 mssmbios - ok
22:20:16.0500 0668 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
22:20:16.0500 0668 MSTEE - ok
22:20:16.0546 0668 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
22:20:16.0562 0668 Mup - ok
22:20:16.0640 0668 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:20:16.0640 0668 NABTSFEC - ok
22:20:16.0734 0668 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
22:20:16.0750 0668 NDIS - ok
22:20:16.0796 0668 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:20:16.0796 0668 NdisIP - ok
22:20:16.0875 0668 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:20:16.0875 0668 NdisTapi - ok
22:20:16.0937 0668 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:20:16.0937 0668 Ndisuio - ok
22:20:17.0000 0668 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:20:17.0000 0668 NdisWan - ok
22:20:17.0078 0668 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
22:20:17.0078 0668 NDProxy - ok
22:20:17.0125 0668 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:20:17.0140 0668 NetBIOS - ok
22:20:17.0171 0668 NetBT (4ed248a6f7c6da7d456a6946f94604ce) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:20:17.0187 0668 NetBT ( Rootkit.Win32.ZAccess.e ) - infected
22:20:17.0187 0668 NetBT - detected Rootkit.Win32.ZAccess.e (0)
22:20:17.0250 0668 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
22:20:17.0250 0668 Npfs - ok
22:20:17.0328 0668 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
22:20:17.0343 0668 Ntfs - ok
22:20:17.0484 0668 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:20:17.0484 0668 Null - ok
22:20:17.0515 0668 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:20:17.0515 0668 NwlnkFlt - ok
22:20:17.0546 0668 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:20:17.0546 0668 NwlnkFwd - ok
22:20:17.0593 0668 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
22:20:17.0593 0668 Parport - ok
22:20:17.0718 0668 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
22:20:17.0734 0668 PartMgr - ok
22:20:17.0765 0668 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
22:20:17.0765 0668 ParVdm - ok
22:20:17.0796 0668 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
22:20:17.0796 0668 PCI - ok
22:20:17.0812 0668 PCIDump - ok
22:20:17.0843 0668 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:20:17.0843 0668 PCIIde - ok
22:20:17.0875 0668 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
22:20:17.0875 0668 Pcmcia - ok
22:20:17.0968 0668 PDCOMP - ok
22:20:18.0000 0668 PDFRAME - ok
22:20:18.0015 0668 PDRELI - ok
22:20:18.0031 0668 PDRFRAME - ok
22:20:18.0093 0668 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
22:20:18.0093 0668 perc2 - ok
22:20:18.0125 0668 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
22:20:18.0125 0668 perc2hib - ok
22:20:18.0234 0668 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:20:18.0234 0668 PptpMiniport - ok
22:20:18.0343 0668 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
22:20:18.0343 0668 PSched - ok
22:20:18.0406 0668 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:20:18.0406 0668 Ptilink - ok
22:20:18.0437 0668 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
22:20:18.0437 0668 ql1080 - ok
22:20:18.0546 0668 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
22:20:18.0546 0668 Ql10wnt - ok
22:20:18.0625 0668 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
22:20:18.0625 0668 ql12160 - ok
22:20:18.0656 0668 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
22:20:18.0656 0668 ql1240 - ok
22:20:18.0671 0668 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
22:20:18.0671 0668 ql1280 - ok
22:20:18.0718 0668 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:20:18.0718 0668 RasAcd - ok
22:20:18.0812 0668 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:20:18.0812 0668 Rasl2tp - ok
22:20:18.0843 0668 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:20:18.0843 0668 RasPppoe - ok
22:20:18.0859 0668 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:20:18.0875 0668 Raspti - ok
22:20:18.0921 0668 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:20:18.0921 0668 Rdbss - ok
22:20:19.0031 0668 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:20:19.0031 0668 RDPCDD - ok
22:20:19.0125 0668 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:20:19.0125 0668 rdpdr - ok
22:20:19.0203 0668 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
22:20:19.0218 0668 RDPWD - ok
22:20:19.0359 0668 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
22:20:19.0359 0668 redbook - ok
22:20:19.0437 0668 RSUSBSTOR (7ffa9821b1c5e0e0667e0a2685cfb89f) C:\WINDOWS\system32\Drivers\RtsUStor.sys
22:20:19.0453 0668 RSUSBSTOR - ok
22:20:19.0546 0668 Rts516xIR - ok
22:20:19.0640 0668 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:20:19.0640 0668 Secdrv - ok
22:20:19.0687 0668 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
22:20:19.0687 0668 Serial - ok
22:20:19.0734 0668 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:20:19.0734 0668 Sfloppy - ok
22:20:19.0843 0668 Simbad - ok
22:20:19.0890 0668 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
22:20:19.0890 0668 sisagp - ok
22:20:19.0921 0668 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
22:20:19.0921 0668 SLIP - ok
22:20:20.0062 0668 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
22:20:20.0062 0668 Sparrow - ok
22:20:20.0093 0668 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
22:20:20.0109 0668 splitter - ok
22:20:20.0156 0668 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
22:20:20.0171 0668 sr - ok
22:20:20.0218 0668 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
22:20:20.0234 0668 Srv - ok
22:20:20.0359 0668 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:20:20.0359 0668 streamip - ok
22:20:20.0390 0668 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:20:20.0406 0668 swenum - ok
22:20:20.0453 0668 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
22:20:20.0453 0668 swmidi - ok
22:20:20.0562 0668 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
22:20:20.0578 0668 symc810 - ok
22:20:20.0609 0668 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
22:20:20.0609 0668 symc8xx - ok
22:20:20.0625 0668 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
22:20:20.0625 0668 sym_hi - ok
22:20:20.0656 0668 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
22:20:20.0656 0668 sym_u3 - ok
22:20:20.0703 0668 SynTP (5c3e900f41426a372de60675afc8aa07) C:\WINDOWS\system32\DRIVERS\SynTP.sys
22:20:20.0718 0668 SynTP - ok
22:20:20.0843 0668 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
22:20:20.0843 0668 sysaudio - ok
22:20:20.0921 0668 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:20:20.0937 0668 Tcpip - ok
22:20:21.0046 0668 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:20:21.0046 0668 TDPIPE - ok
22:20:21.0093 0668 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
22:20:21.0093 0668 TDTCP - ok
22:20:21.0125 0668 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:20:21.0125 0668 TermDD - ok
22:20:21.0187 0668 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
22:20:21.0187 0668 TosIde - ok
22:20:21.0328 0668 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
22:20:21.0343 0668 Udfs - ok
22:20:21.0406 0668 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
22:20:21.0406 0668 ultra - ok
22:20:21.0531 0668 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
22:20:21.0546 0668 Update - ok
22:20:21.0687 0668 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:20:21.0687 0668 usbccgp - ok
22:20:21.0703 0668 USBCCID - ok
22:20:21.0750 0668 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:20:21.0750 0668 usbehci - ok
22:20:21.0781 0668 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:20:21.0781 0668 usbhub - ok
22:20:21.0843 0668 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:20:21.0843 0668 usbscan - ok
22:20:21.0953 0668 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:20:21.0953 0668 USBSTOR - ok
22:20:22.0000 0668 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:20:22.0000 0668 usbuhci - ok
22:20:22.0062 0668 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
22:20:22.0062 0668 usbvideo - ok
22:20:22.0187 0668 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
22:20:22.0187 0668 VgaSave - ok
22:20:22.0234 0668 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
22:20:22.0234 0668 viaagp - ok
22:20:22.0265 0668 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
22:20:22.0281 0668 ViaIde - ok
22:20:22.0375 0668 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
22:20:22.0390 0668 VolSnap - ok
22:20:22.0437 0668 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:20:22.0437 0668 Wanarp - ok
22:20:22.0468 0668 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
22:20:22.0484 0668 Wdf01000 - ok
22:20:22.0578 0668 WDICA - ok
22:20:22.0625 0668 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
22:20:22.0625 0668 wdmaud - ok
22:20:22.0718 0668 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
22:20:22.0718 0668 WmiAcpi - ok
22:20:22.0812 0668 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:20:22.0812 0668 WSTCODEC - ok
22:20:22.0937 0668 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:20:22.0937 0668 WudfPf - ok
22:20:23.0000 0668 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:20:23.0000 0668 WudfRd - ok
22:20:23.0078 0668 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:20:23.0093 0668 \Device\Harddisk0\DR0 - ok
22:20:23.0109 0668 Boot (0x1200) (39c46ac3f67b85344f8d18d37935a07a) \Device\Harddisk0\DR0\Partition0
22:20:23.0109 0668 \Device\Harddisk0\DR0\Partition0 - ok
22:20:23.0109 0668 ============================================================
22:20:23.0109 0668 Scan finished
22:20:23.0109 0668 ============================================================
22:20:23.0156 3436 Detected object count: 2
22:20:23.0156 3436 Actual detected object count: 2
22:21:41.0734 3436 C:\WINDOWS\3361455656:3611403319.exe - copied to quarantine
22:21:41.0734 3436 28be5bc8 ( HiddenFile.Multi.Generic ) - User select action: Quarantine
22:21:41.0828 3436 C:\WINDOWS\system32\DRIVERS\netbt.sys - copied to quarantine
22:21:41.0828 3436 NetBT ( Rootkit.Win32.ZAccess.e ) - User select action: Quarantine
23:09:31.0546 0180 Deinitialize success

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:01 PM

Posted 10 October 2011 - 08:31 PM

Hello, run TDSS again. Reboot after.

Then,if you can run MBAM in normal and SAS insafe mode,
Post all logs and tell us how it is thanks.

MBAM
The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

SAS
To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log.
A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.


Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 10 October 2011 - 10:08 PM

My updates tdsskiller log is below. Malwarebytes still won't run. Will try Super AntiSpyware in safe mode after a reboot in a moment, so more on the way.



22:49:59.0406 1888 TDSS rootkit removing tool 2.6.6.0 Oct 7 2011 12:45:24
22:50:05.0031 1888 ============================================================
22:50:05.0031 1888 Current date / time: 2011/10/10 22:50:05.0031
22:50:05.0031 1888 SystemInfo:
22:50:05.0031 1888
22:50:05.0031 1888 OS Version: 5.1.2600 ServicePack: 3.0
22:50:05.0031 1888 Product type: Workstation
22:50:05.0031 1888 ComputerName: ACER-330BB84976
22:50:05.0046 1888 UserName: Jason >>>>>
22:50:05.0046 1888 Windows directory: C:\WINDOWS
22:50:05.0046 1888 System windows directory: C:\WINDOWS
22:50:05.0046 1888 Processor architecture: Intel x86
22:50:05.0046 1888 Number of processors: 2
22:50:05.0046 1888 Page size: 0x1000
22:50:05.0046 1888 Boot type: Normal boot
22:50:05.0046 1888 ============================================================
22:50:06.0906 1888 Initialize success
22:50:09.0031 3536 ============================================================
22:50:09.0031 3536 Scan started
22:50:09.0031 3536 Mode: Manual;
22:50:09.0031 3536 ============================================================
22:50:10.0171 3536 28be5bc8 (8f2bb1827cac01aee6a16e30a1260199) C:\WINDOWS\3361455656:3611403319.exe
22:50:11.0328 3536 Suspicious file (Hidden): C:\WINDOWS\3361455656:3611403319.exe. md5: 8f2bb1827cac01aee6a16e30a1260199
22:50:11.0328 3536 28be5bc8 ( HiddenFile.Multi.Generic ) - warning
22:50:11.0328 3536 28be5bc8 - detected HiddenFile.Multi.Generic (1)
22:50:11.0437 3536 Abiosdsk - ok
22:50:11.0500 3536 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
22:50:11.0500 3536 abp480n5 - ok
22:50:11.0562 3536 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:50:11.0578 3536 ACPI - ok
22:50:11.0593 3536 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
22:50:11.0593 3536 ACPIEC - ok
22:50:11.0640 3536 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
22:50:11.0640 3536 adpu160m - ok
22:50:11.0703 3536 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
22:50:11.0703 3536 aec - ok
22:50:11.0859 3536 AFD (10b5b921f711380e69a3105e9ea3b105) C:\WINDOWS\System32\drivers\afd.sys
22:50:11.0859 3536 AFD ( Rootkit.Win32.ZAccess.e ) - infected
22:50:11.0859 3536 AFD - detected Rootkit.Win32.ZAccess.e (0)
22:50:11.0906 3536 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
22:50:11.0906 3536 agp440 - ok
22:50:11.0921 3536 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
22:50:11.0921 3536 agpCPQ - ok
22:50:11.0937 3536 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
22:50:11.0953 3536 Aha154x - ok
22:50:11.0968 3536 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
22:50:11.0968 3536 aic78u2 - ok
22:50:12.0000 3536 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
22:50:12.0000 3536 aic78xx - ok
22:50:12.0046 3536 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
22:50:12.0046 3536 AliIde - ok
22:50:12.0093 3536 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
22:50:12.0109 3536 alim1541 - ok
22:50:12.0296 3536 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys
22:50:12.0390 3536 Ambfilt - ok
22:50:12.0546 3536 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
22:50:12.0546 3536 amdagp - ok
22:50:12.0593 3536 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
22:50:12.0593 3536 amsint - ok
22:50:12.0718 3536 AR5416 (2b7b6a3305fc34a543d34013c14d02a2) C:\WINDOWS\system32\DRIVERS\athw.sys
22:50:12.0765 3536 AR5416 - ok
22:50:12.0906 3536 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
22:50:12.0906 3536 asc - ok
22:50:12.0953 3536 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
22:50:12.0953 3536 asc3350p - ok
22:50:12.0968 3536 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
22:50:12.0984 3536 asc3550 - ok
22:50:13.0046 3536 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:50:13.0046 3536 AsyncMac - ok
22:50:13.0109 3536 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:50:13.0109 3536 atapi - ok
22:50:13.0125 3536 Atdisk - ok
22:50:13.0156 3536 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:50:13.0171 3536 Atmarpc - ok
22:50:13.0312 3536 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:50:13.0312 3536 audstub - ok
22:50:13.0390 3536 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:50:13.0390 3536 Beep - ok
22:50:13.0468 3536 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
22:50:13.0468 3536 cbidf - ok
22:50:13.0578 3536 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:50:13.0578 3536 cbidf2k - ok
22:50:13.0625 3536 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:50:13.0625 3536 CCDECODE - ok
22:50:13.0656 3536 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
22:50:13.0656 3536 cd20xrnt - ok
22:50:13.0703 3536 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:50:13.0703 3536 Cdaudio - ok
22:50:13.0765 3536 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
22:50:13.0765 3536 Cdfs - ok
22:50:13.0921 3536 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:50:13.0921 3536 Cdrom - ok
22:50:13.0953 3536 Changer - ok
22:50:14.0015 3536 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
22:50:14.0015 3536 CmBatt - ok
22:50:14.0078 3536 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
22:50:14.0078 3536 CmdIde - ok
22:50:14.0125 3536 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
22:50:14.0125 3536 Compbatt - ok
22:50:14.0171 3536 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
22:50:14.0171 3536 Cpqarray - ok
22:50:14.0218 3536 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
22:50:14.0218 3536 dac2w2k - ok
22:50:14.0265 3536 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
22:50:14.0265 3536 dac960nt - ok
22:50:14.0421 3536 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
22:50:14.0421 3536 Disk - ok
22:50:14.0500 3536 DKbFltr (08d30af92c270f2e76787c81589dbad6) C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
22:50:14.0500 3536 DKbFltr - ok
22:50:14.0593 3536 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
22:50:14.0625 3536 dmboot - ok
22:50:14.0750 3536 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
22:50:14.0765 3536 dmio - ok
22:50:14.0796 3536 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:50:14.0796 3536 dmload - ok
22:50:14.0859 3536 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
22:50:14.0875 3536 DMusic - ok
22:50:14.0953 3536 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
22:50:14.0953 3536 dpti2o - ok
22:50:15.0078 3536 DritekPortIO (5c918d413f5837e67a85775c9873775e) C:\PROGRA~1\LAUNCH~1\DPortIO.sys
22:50:15.0078 3536 DritekPortIO - ok
22:50:15.0234 3536 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
22:50:15.0234 3536 drmkaud - ok
22:50:15.0312 3536 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
22:50:15.0328 3536 Fastfat - ok
22:50:15.0375 3536 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
22:50:15.0390 3536 Fdc - ok
22:50:15.0406 3536 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
22:50:15.0406 3536 Fips - ok
22:50:15.0421 3536 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
22:50:15.0421 3536 Flpydisk - ok
22:50:15.0453 3536 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:50:15.0453 3536 FltMgr - ok
22:50:15.0484 3536 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:50:15.0484 3536 Fs_Rec - ok
22:50:15.0515 3536 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:50:15.0531 3536 Ftdisk - ok
22:50:15.0687 3536 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
22:50:15.0687 3536 GEARAspiWDM - ok
22:50:15.0750 3536 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:50:15.0750 3536 Gpc - ok
22:50:15.0859 3536 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:50:15.0859 3536 HDAudBus - ok
22:50:16.0031 3536 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
22:50:16.0031 3536 hpn - ok
22:50:16.0093 3536 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
22:50:16.0093 3536 HTTP - ok
22:50:16.0265 3536 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
22:50:16.0265 3536 i2omgmt - ok
22:50:16.0296 3536 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
22:50:16.0296 3536 i2omp - ok
22:50:16.0375 3536 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:50:16.0375 3536 i8042prt - ok
22:50:16.0656 3536 ialm (48846b31be5a4fa662ccfde7a1ba86b9) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
22:50:16.0875 3536 ialm - ok
22:50:17.0046 3536 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\WINDOWS\system32\drivers\iaStor.sys
22:50:17.0046 3536 iaStor - ok
22:50:17.0125 3536 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:50:17.0125 3536 Imapi - ok
22:50:17.0187 3536 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
22:50:17.0187 3536 ini910u - ok
22:50:17.0218 3536 int15.sys - ok
22:50:17.0468 3536 IntcAzAudAddService (cb1113029fae50c685198eabd9885161) C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:50:17.0656 3536 IntcAzAudAddService - ok
22:50:17.0796 3536 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
22:50:17.0796 3536 IntelIde - ok
22:50:17.0843 3536 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:50:17.0843 3536 intelppm - ok
22:50:17.0890 3536 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:50:17.0890 3536 Ip6Fw - ok
22:50:17.0937 3536 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:50:17.0937 3536 IpFilterDriver - ok
22:50:18.0062 3536 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:50:18.0062 3536 IpInIp - ok
22:50:18.0109 3536 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:50:18.0109 3536 IpNat - ok
22:50:18.0140 3536 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:50:18.0140 3536 IPSec - ok
22:50:18.0187 3536 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:50:18.0187 3536 IRENUM - ok
22:50:18.0234 3536 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:50:18.0234 3536 isapnp - ok
22:50:18.0359 3536 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:50:18.0359 3536 Kbdclass - ok
22:50:18.0437 3536 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
22:50:18.0453 3536 kmixer - ok
22:50:18.0484 3536 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
22:50:18.0484 3536 KSecDD - ok
22:50:18.0531 3536 L1c (6c8658587e91ea25b0fd2e71781ad228) C:\WINDOWS\system32\DRIVERS\l1c51x86.sys
22:50:18.0531 3536 L1c - ok
22:50:18.0562 3536 lbrtfdc - ok
22:50:18.0656 3536 M3000Srv (73fd60fda3ff60f0666e4614e93f0aaa) C:\WINDOWS\system32\Drivers\M3000KNT.sys
22:50:18.0656 3536 M3000Srv - ok
22:50:18.0828 3536 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:50:18.0828 3536 mnmdd - ok
22:50:18.0890 3536 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
22:50:18.0890 3536 Modem - ok
22:50:18.0968 3536 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys
22:50:19.0015 3536 Monfilt - ok
22:50:19.0156 3536 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:50:19.0156 3536 Mouclass - ok
22:50:19.0218 3536 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
22:50:19.0218 3536 MountMgr - ok
22:50:19.0265 3536 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
22:50:19.0265 3536 mraid35x - ok
22:50:19.0281 3536 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:50:19.0281 3536 MRxDAV - ok
22:50:19.0328 3536 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
22:50:19.0328 3536 Msfs - ok
22:50:19.0375 3536 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:50:19.0375 3536 MSKSSRV - ok
22:50:19.0421 3536 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:50:19.0421 3536 MSPCLOCK - ok
22:50:19.0515 3536 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
22:50:19.0515 3536 MSPQM - ok
22:50:19.0593 3536 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:50:19.0593 3536 mssmbios - ok
22:50:19.0640 3536 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
22:50:19.0640 3536 MSTEE - ok
22:50:19.0687 3536 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
22:50:19.0687 3536 Mup - ok
22:50:19.0828 3536 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:50:19.0828 3536 NABTSFEC - ok
22:50:19.0890 3536 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
22:50:19.0890 3536 NDIS - ok
22:50:19.0953 3536 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:50:19.0953 3536 NdisIP - ok
22:50:20.0000 3536 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:50:20.0000 3536 NdisTapi - ok
22:50:20.0140 3536 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:50:20.0156 3536 Ndisuio - ok
22:50:20.0187 3536 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:50:20.0187 3536 NdisWan - ok
22:50:20.0234 3536 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
22:50:20.0234 3536 NDProxy - ok
22:50:20.0265 3536 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:50:20.0265 3536 NetBIOS - ok
22:50:20.0328 3536 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:50:20.0343 3536 NetBT - ok
22:50:20.0484 3536 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
22:50:20.0484 3536 Npfs - ok
22:50:20.0562 3536 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
22:50:20.0578 3536 Ntfs - ok
22:50:20.0750 3536 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:50:20.0750 3536 Null - ok
22:50:20.0781 3536 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:50:20.0781 3536 NwlnkFlt - ok
22:50:20.0796 3536 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:50:20.0796 3536 NwlnkFwd - ok
22:50:20.0875 3536 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
22:50:20.0875 3536 Parport - ok
22:50:20.0890 3536 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
22:50:20.0890 3536 PartMgr - ok
22:50:21.0046 3536 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
22:50:21.0046 3536 ParVdm - ok
22:50:21.0078 3536 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
22:50:21.0078 3536 PCI - ok
22:50:21.0093 3536 PCIDump - ok
22:50:21.0109 3536 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:50:21.0125 3536 PCIIde - ok
22:50:21.0156 3536 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
22:50:21.0156 3536 Pcmcia - ok
22:50:21.0171 3536 PDCOMP - ok
22:50:21.0187 3536 PDFRAME - ok
22:50:21.0218 3536 PDRELI - ok
22:50:21.0234 3536 PDRFRAME - ok
22:50:21.0281 3536 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
22:50:21.0281 3536 perc2 - ok
22:50:21.0296 3536 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
22:50:21.0296 3536 perc2hib - ok
22:50:21.0390 3536 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:50:21.0390 3536 PptpMiniport - ok
22:50:21.0531 3536 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
22:50:21.0531 3536 PSched - ok
22:50:21.0562 3536 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:50:21.0562 3536 Ptilink - ok
22:50:21.0593 3536 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
22:50:21.0593 3536 ql1080 - ok
22:50:21.0609 3536 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
22:50:21.0609 3536 Ql10wnt - ok
22:50:21.0640 3536 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
22:50:21.0640 3536 ql12160 - ok
22:50:21.0671 3536 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
22:50:21.0671 3536 ql1240 - ok
22:50:21.0687 3536 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
22:50:21.0703 3536 ql1280 - ok
22:50:21.0734 3536 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:50:21.0750 3536 RasAcd - ok
22:50:21.0781 3536 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:50:21.0781 3536 Rasl2tp - ok
22:50:21.0796 3536 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:50:21.0812 3536 RasPppoe - ok
22:50:21.0828 3536 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:50:21.0828 3536 Raspti - ok
22:50:21.0859 3536 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:50:21.0875 3536 Rdbss - ok
22:50:22.0000 3536 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:50:22.0000 3536 RDPCDD - ok
22:50:22.0046 3536 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:50:22.0078 3536 rdpdr - ok
22:50:22.0156 3536 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
22:50:22.0156 3536 RDPWD - ok
22:50:22.0250 3536 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
22:50:22.0250 3536 redbook - ok
22:50:22.0421 3536 RSUSBSTOR (7ffa9821b1c5e0e0667e0a2685cfb89f) C:\WINDOWS\system32\Drivers\RtsUStor.sys
22:50:22.0421 3536 RSUSBSTOR - ok
22:50:22.0468 3536 Rts516xIR - ok
22:50:22.0562 3536 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:50:22.0578 3536 Secdrv - ok
22:50:22.0640 3536 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
22:50:22.0640 3536 Serial - ok
22:50:22.0703 3536 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:50:22.0703 3536 Sfloppy - ok
22:50:22.0828 3536 Simbad - ok
22:50:22.0890 3536 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
22:50:22.0890 3536 sisagp - ok
22:50:22.0921 3536 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
22:50:22.0921 3536 SLIP - ok
22:50:22.0968 3536 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
22:50:22.0968 3536 Sparrow - ok
22:50:23.0031 3536 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
22:50:23.0031 3536 splitter - ok
22:50:23.0078 3536 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
22:50:23.0093 3536 sr - ok
22:50:23.0250 3536 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
22:50:23.0265 3536 Srv - ok
22:50:23.0328 3536 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:50:23.0328 3536 streamip - ok
22:50:23.0375 3536 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:50:23.0375 3536 swenum - ok
22:50:23.0453 3536 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
22:50:23.0453 3536 swmidi - ok
22:50:23.0500 3536 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
22:50:23.0500 3536 symc810 - ok
22:50:23.0546 3536 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
22:50:23.0562 3536 symc8xx - ok
22:50:23.0656 3536 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
22:50:23.0656 3536 sym_hi - ok
22:50:23.0718 3536 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
22:50:23.0718 3536 sym_u3 - ok
22:50:23.0796 3536 SynTP (5c3e900f41426a372de60675afc8aa07) C:\WINDOWS\system32\DRIVERS\SynTP.sys
22:50:23.0796 3536 SynTP - ok
22:50:23.0859 3536 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
22:50:23.0875 3536 sysaudio - ok
22:50:23.0968 3536 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:50:23.0984 3536 Tcpip - ok
22:50:24.0125 3536 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:50:24.0125 3536 TDPIPE - ok
22:50:24.0156 3536 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
22:50:24.0171 3536 TDTCP - ok
22:50:24.0234 3536 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:50:24.0234 3536 TermDD - ok
22:50:24.0312 3536 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
22:50:24.0312 3536 TosIde - ok
22:50:24.0468 3536 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
22:50:24.0468 3536 Udfs - ok
22:50:24.0500 3536 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
22:50:24.0515 3536 ultra - ok
22:50:24.0546 3536 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
22:50:24.0562 3536 Update - ok
22:50:24.0656 3536 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:50:24.0656 3536 usbccgp - ok
22:50:24.0671 3536 USBCCID - ok
22:50:24.0750 3536 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:50:24.0750 3536 usbehci - ok
22:50:24.0859 3536 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:50:24.0875 3536 usbhub - ok
22:50:24.0937 3536 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:50:24.0937 3536 usbscan - ok
22:50:25.0000 3536 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:50:25.0000 3536 USBSTOR - ok
22:50:25.0078 3536 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:50:25.0078 3536 usbuhci - ok
22:50:25.0234 3536 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
22:50:25.0250 3536 usbvideo - ok
22:50:25.0296 3536 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
22:50:25.0296 3536 VgaSave - ok
22:50:25.0359 3536 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
22:50:25.0359 3536 viaagp - ok
22:50:25.0406 3536 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
22:50:25.0406 3536 ViaIde - ok
22:50:25.0531 3536 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
22:50:25.0531 3536 VolSnap - ok
22:50:25.0609 3536 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:50:25.0609 3536 Wanarp - ok
22:50:25.0656 3536 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
22:50:25.0687 3536 Wdf01000 - ok
22:50:25.0781 3536 WDICA - ok
22:50:25.0859 3536 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
22:50:25.0859 3536 wdmaud - ok
22:50:25.0984 3536 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
22:50:26.0000 3536 WmiAcpi - ok
22:50:26.0093 3536 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:50:26.0093 3536 WSTCODEC - ok
22:50:26.0140 3536 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:50:26.0140 3536 WudfPf - ok
22:50:26.0265 3536 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:50:26.0281 3536 WudfRd - ok
22:50:26.0359 3536 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:50:26.0375 3536 \Device\Harddisk0\DR0 - ok
22:50:26.0390 3536 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR3
22:50:26.0406 3536 \Device\Harddisk1\DR3 - ok
22:50:26.0421 3536 Boot (0x1200) (39c46ac3f67b85344f8d18d37935a07a) \Device\Harddisk0\DR0\Partition0
22:50:26.0421 3536 \Device\Harddisk0\DR0\Partition0 - ok
22:50:26.0437 3536 Boot (0x1200) (eda0bcd41917d6a8f40c5d93659cfebe) \Device\Harddisk1\DR3\Partition0
22:50:26.0437 3536 \Device\Harddisk1\DR3\Partition0 - ok
22:50:26.0437 3536 ============================================================
22:50:26.0437 3536 Scan finished
22:50:26.0437 3536 ============================================================
22:50:26.0468 2476 Detected object count: 2
22:50:26.0468 2476 Actual detected object count: 2
22:50:43.0140 2476 28be5bc8 ( HiddenFile.Multi.Generic ) - skipped by user
22:50:43.0140 2476 28be5bc8 ( HiddenFile.Multi.Generic ) - User select action: Skip
22:50:43.0218 2476 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\afd.sys) error 1813
22:50:44.0109 2476 Backup copy found, using it..
22:50:44.0187 2476 C:\WINDOWS\System32\drivers\afd.sys - will be cured on reboot
22:50:44.0187 2476 AFD ( Rootkit.Win32.ZAccess.e ) - User select action: Cure
22:50:48.0375 3800 Deinitialize success

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:01 PM

Posted 10 October 2011 - 10:13 PM

Are you getting an error or message from MBAM?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 10 October 2011 - 10:21 PM

It just starts and stops, gets about 20 seconds in and cuts off. Happens each time I try it. After that, it's no good to even initialize the start and I have to reinstall it each time I try.
Also, I can't get safe mode to initialize.

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:01 PM

Posted 10 October 2011 - 10:29 PM

SafeBootKeyRepair.exe
Let us see if we can get Safe mode to run.
Vista users my need to save it to the desktop first then right-click the icon and choose "Run as Administrator".

Please download and run SafeBootKeyRepair.exe.

Once it has completed, please try booting into Safe Mode.



This infection changes settings on your computer so that when you launch an executable, a file ending with .exe, it will instead launch the infection rather than the desired program. To fix this we must first download a Registry file that will fix these changes. From a clean computer, please download the following file and save it to a removable media such as a CD/DVD, external Drive, or USB flash drive.

FixNCR.reg

insert the removable device into the infected computer and open the folder the drive letter associated with it. You should now see the FixNCR.reg file that you had downloaded onto it. Double-click on the FixNCR.reg file to fix the Registry on your infected computer.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 10 October 2011 - 10:31 PM

Re: SASW...summary of error msg-
Windows cannot access the specified device, path, whatever. You may not have the appropriate permissions to access the file.

#8 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 10 October 2011 - 10:36 PM

Thanks a lot, Boop. Doing the safebootkeyrepair now. Has said Please Wait for several minutes. I am waiting....

#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:01 PM

Posted 10 October 2011 - 10:44 PM

Ok, i hope this all works now as I have to go.

Use Inherit.exe to fix inappropriate permissions.
Use this fix, when you see a box that states “Windows cannot not access the specified device, path, or file. You may have inappropriate permissions to access the item”.

Download This File
Save it next to mbam.exe (this file is located in the Malwarebytes Anti-malware home folder). Once done, drag and drop mbam.exe into Inherit.exe. Click OK and attempt to run Malwarebytes Anti-malware once again.


Or you can try a System Retore to a date before all this started and then run the tools.
Windows XP System Restore Guide
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 10 October 2011 - 10:45 PM

Still no safe mode. Gotta walk the dogs and iron clothes before bed. If I can, I will try the FixNCR...otherwise I will have to wait till tomorrow after work. THanks.

#11 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 11 October 2011 - 05:47 PM

I tried the inherit idea..no go. Same result...15-20 seconds of running, then malwarebytes cuts off and no longer operates if I try to relaunch it.

I will attempt a system restore date and attempt to run malwarebytes. If that doesn't work, I'll go back and try FixNCR.

#12 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 11 October 2011 - 06:11 PM

Made an attempt at system restore. Got this msg- Windows cannot find 'C:\program'. Make sure you typed the name correctly and then try again. To search for a file click the start button and then click search.

I was also alterted that my restoration was incomplete and no changes were made.

I am also now unable to connect to the internet on the PC, although I don't know if my wireless connection is simply down right now, or not. Trying to determine that now.

#13 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 11 October 2011 - 06:28 PM

Double clicked the FixNCR and it told me that the file had been added to the registry, or something like that.

My wireless connection is not the problem...this is now preventing my PC from connecting to the internet.

#14 JayBallz

JayBallz
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:01 PM

Posted 11 October 2011 - 06:41 PM

I tried to do place Malwarebytes on flash drive from uninfected PC and run it over on the infected computer, much like i did w/ FixNCR...the virus recognizes the program from its previous location on the infected PC, even though I've uninstalled it there.

Obviously, I can't re-download it on the infected PC as my internet connection is failing.

#15 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:01 PM

Posted 11 October 2011 - 08:29 PM

For the connection try these...

Please click Start > Run, type inetcpl.cpl in the runbox and press enter.
Click the Connections tab and click the LAN settings option.
Verify if "Use a proxy..." is checked, if so, UNcheck it and click OK/OK to exit.
Now check if the internet is working again.

OR

Go to Start ... Run and type in cmd
A dos Window will appear.
Type in the dos window: netsh winsock reset
Click on the enter key.

Reboot your system to complete the process.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users