Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan horse BackDoor.Generic14.BZSZ


  • This topic is locked This topic is locked
9 replies to this topic

#1 delta6

delta6

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:11:05 PM

Posted 05 December 2011 - 08:06 AM

While streaming "Walking Dead".. firefox shuts down, AVG detects something wrong needs reboot. So I did.. No Firefox now, can only run Opera. Every time I run a program it asks "run as?".. unable to do system restore. "";"C:\WINDOWS\system32\drivers\mrxsmb.sys";"Trojan horse BackDoor.Generic14.BZSZ";"Object is white-listed (critical/system file that should not be removed)"

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:05 PM

Posted 05 December 2011 - 08:00 PM

Hello what is your Operating System?

Can you run MBAM?

Next run MBAM (MalwareBytes):

Please download Malwarebytes Anti-Malware and save it to your desktop.
Download Link 1
Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

Troubleshoot Malwarebytes' Anti-Malware
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 kdlan

kdlan

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:05 PM

Posted 08 December 2011 - 12:30 PM

Same virus....I have a vista operating system on a dell laptop. This has disabled my keyboard and touch pad. I know the problem is not hardware related...I also have a linux operating system that I can boot to and the keyboard and touch pad work fine when running it. I downloaded MBAM and followed your instructions exactly..no luck. Any more suggestions?

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:05 PM

Posted 08 December 2011 - 04:08 PM

Please Download
TDSSKiller.zip

>>> Double-click on TDSSKiller.exe to run the application.
  • Click on the Start Scan button and wait for the scan and disinfection process to be over.
  • If an infected file is detected, the default action will be Cure, click on Continue
    Posted Image
  • If a suspicious file is detected, the default action will be Skip, click on Continue
    Posted Image
  • If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.
  • If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.

Please post the logs for my review.


I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


NOTE: In some instances if no malware is found there will be no log produced.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 kdlan

kdlan

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:05 PM

Posted 08 December 2011 - 10:45 PM

I ran the TDSSKiller and the ESET online Scan. Still not working. I tried to export a text file from ESET but it wouldn't let me save it.
Here is the report from TDSSKiller.
21:29:21.0782 4588 TDSS rootkit removing tool 2.6.22.0 Dec 7 2011 13:21:06
21:29:21.0989 4588 ============================================================
21:29:21.0989 4588 Current date / time: 2011/12/08 21:29:21.0989
21:29:21.0989 4588 SystemInfo:
21:29:21.0989 4588
21:29:21.0989 4588 OS Version: 6.0.6002 ServicePack: 2.0
21:29:21.0989 4588 Product type: Workstation
21:29:21.0989 4588 ComputerName: COURTNEY-PC
21:29:21.0990 4588 UserName: courtney
21:29:21.0990 4588 Windows directory: C:\Windows
21:29:21.0990 4588 System windows directory: C:\Windows
21:29:21.0990 4588 Processor architecture: Intel x86
21:29:21.0990 4588 Number of processors: 2
21:29:21.0990 4588 Page size: 0x1000
21:29:21.0990 4588 Boot type: Normal boot
21:29:21.0990 4588 ============================================================
21:29:22.0577 4588 Initialize success
21:29:31.0188 5896 ============================================================
21:29:31.0188 5896 Scan started
21:29:31.0188 5896 Mode: Manual;
21:29:31.0188 5896 ============================================================
21:29:31.0432 5896 .i8042prt - ok
21:29:31.0663 5896 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
21:29:31.0667 5896 ACPI - ok
21:29:31.0804 5896 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
21:29:31.0809 5896 adp94xx - ok
21:29:31.0872 5896 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
21:29:31.0876 5896 adpahci - ok
21:29:31.0944 5896 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
21:29:31.0946 5896 adpu160m - ok
21:29:32.0007 5896 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
21:29:32.0009 5896 adpu320 - ok
21:29:32.0215 5896 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
21:29:32.0219 5896 AFD - ok
21:29:32.0305 5896 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
21:29:32.0306 5896 agp440 - ok
21:29:32.0344 5896 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
21:29:32.0346 5896 aic78xx - ok
21:29:32.0384 5896 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
21:29:32.0385 5896 aliide - ok
21:29:32.0421 5896 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
21:29:32.0423 5896 amdagp - ok
21:29:32.0468 5896 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
21:29:32.0469 5896 amdide - ok
21:29:32.0529 5896 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
21:29:32.0530 5896 AmdK7 - ok
21:29:32.0593 5896 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
21:29:32.0595 5896 AmdK8 - ok
21:29:32.0669 5896 ApfiltrService (b83f9da84f7079451c1c6a4a2f140920) C:\Windows\system32\DRIVERS\Apfiltr.sys
21:29:32.0671 5896 ApfiltrService - ok
21:29:32.0745 5896 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
21:29:32.0746 5896 arc - ok
21:29:32.0791 5896 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
21:29:32.0793 5896 arcsas - ok
21:29:32.0854 5896 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
21:29:32.0855 5896 AsyncMac - ok
21:29:32.0895 5896 atapi (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
21:29:32.0896 5896 atapi - ok
21:29:33.0031 5896 AvgLdx86 (bc12f2404bb6f2b6b2ff3c4c246cb752) C:\Windows\System32\Drivers\avgldx86.sys
21:29:33.0036 5896 AvgLdx86 - ok
21:29:33.0065 5896 AvgMfx86 (5903d729d4f0c5bca74123c96a1b29e0) C:\Windows\System32\Drivers\avgmfx86.sys
21:29:33.0067 5896 AvgMfx86 - ok
21:29:33.0106 5896 AvgTdiX (92d8e1e8502e649b60e70074eb29c380) C:\Windows\System32\Drivers\avgtdix.sys
21:29:33.0108 5896 AvgTdiX - ok
21:29:33.0182 5896 BCM42RLY (423c7b87e886ac93d22936ea82665f83) C:\Windows\system32\drivers\BCM42RLY.sys
21:29:33.0184 5896 BCM42RLY - ok
21:29:33.0296 5896 BCM43XX (41a70777e892c3dea606758366566a77) C:\Windows\system32\DRIVERS\bcmwl6.sys
21:29:33.0313 5896 BCM43XX - ok
21:29:33.0389 5896 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
21:29:33.0391 5896 Beep - ok
21:29:33.0447 5896 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
21:29:33.0448 5896 blbdrive - ok
21:29:33.0551 5896 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
21:29:33.0552 5896 bowser - ok
21:29:33.0602 5896 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
21:29:33.0603 5896 BrFiltLo - ok
21:29:33.0633 5896 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
21:29:33.0634 5896 BrFiltUp - ok
21:29:33.0701 5896 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
21:29:33.0702 5896 Brserid - ok
21:29:33.0747 5896 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
21:29:33.0748 5896 BrSerWdm - ok
21:29:33.0804 5896 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
21:29:33.0805 5896 BrUsbMdm - ok
21:29:33.0844 5896 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
21:29:33.0845 5896 BrUsbSer - ok
21:29:33.0901 5896 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
21:29:33.0902 5896 BTHMODEM - ok
21:29:33.0946 5896 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
21:29:33.0948 5896 cdfs - ok
21:29:34.0036 5896 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
21:29:34.0038 5896 cdrom - ok
21:29:34.0078 5896 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
21:29:34.0079 5896 circlass - ok
21:29:34.0152 5896 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
21:29:34.0155 5896 CLFS - ok
21:29:34.0263 5896 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
21:29:34.0264 5896 CmBatt - ok
21:29:34.0299 5896 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
21:29:34.0300 5896 cmdide - ok
21:29:34.0330 5896 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
21:29:34.0332 5896 Compbatt - ok
21:29:34.0353 5896 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
21:29:34.0354 5896 crcdisk - ok
21:29:34.0388 5896 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
21:29:34.0389 5896 Crusoe - ok
21:29:34.0492 5896 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
21:29:34.0494 5896 DfsC - ok
21:29:34.0596 5896 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
21:29:34.0598 5896 disk - ok
21:29:34.0687 5896 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
21:29:34.0688 5896 drmkaud - ok
21:29:34.0799 5896 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
21:29:34.0807 5896 DXGKrnl - ok
21:29:34.0875 5896 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
21:29:34.0878 5896 e1express - ok
21:29:34.0907 5896 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
21:29:34.0912 5896 E1G60 - ok
21:29:35.0011 5896 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
21:29:35.0014 5896 Ecache - ok
21:29:35.0087 5896 elagopro (7ec42ec12a4bac14bcca99fb06f2d125) C:\Windows\system32\DRIVERS\elagopro.sys
21:29:35.0088 5896 elagopro - ok
21:29:35.0144 5896 elaunidr (dfeabb7cfffadea4a912ab95bdc3177a) C:\Windows\system32\DRIVERS\elaunidr.sys
21:29:35.0145 5896 elaunidr - ok
21:29:35.0205 5896 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
21:29:35.0210 5896 elxstor - ok
21:29:35.0278 5896 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
21:29:35.0279 5896 ErrDev - ok
21:29:35.0364 5896 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
21:29:35.0394 5896 exfat - ok
21:29:35.0468 5896 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
21:29:35.0471 5896 fastfat - ok
21:29:35.0507 5896 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
21:29:35.0508 5896 fdc - ok
21:29:35.0560 5896 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
21:29:35.0562 5896 FileInfo - ok
21:29:35.0603 5896 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
21:29:35.0604 5896 Filetrace - ok
21:29:35.0665 5896 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
21:29:35.0666 5896 flpydisk - ok
21:29:35.0732 5896 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
21:29:35.0735 5896 FltMgr - ok
21:29:35.0789 5896 FlyUsb (85e5ad3a9d56fd6f92db5fc9ca62e2e4) C:\Windows\system32\DRIVERS\FlyUsb.sys
21:29:35.0790 5896 FlyUsb - ok
21:29:35.0876 5896 FsUsbExDisk (cbe5f69a5e5b918225f420ba748f3742) C:\Windows\system32\FsUsbExDisk.SYS
21:29:35.0879 5896 FsUsbExDisk - ok
21:29:35.0934 5896 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
21:29:35.0935 5896 Fs_Rec - ok
21:29:35.0976 5896 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
21:29:35.0977 5896 gagp30kx - ok
21:29:36.0040 5896 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:29:36.0041 5896 GEARAspiWDM - ok
21:29:36.0136 5896 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
21:29:36.0144 5896 HDAudBus - ok
21:29:36.0190 5896 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
21:29:36.0191 5896 HidBth - ok
21:29:36.0220 5896 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
21:29:36.0221 5896 HidIr - ok
21:29:36.0285 5896 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
21:29:36.0286 5896 HidUsb - ok
21:29:36.0327 5896 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
21:29:36.0329 5896 HpCISSs - ok
21:29:36.0395 5896 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
21:29:36.0400 5896 HTTP - ok
21:29:36.0436 5896 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
21:29:36.0437 5896 i2omp - ok
21:29:36.0482 5896 i8042prt (55f7cd9a600bee83cb8f6a524dcebe4e) C:\Windows\system32\DRIVERS\i8042prt.sys
21:29:36.0506 5896 i8042prt ( Rootkit.Win32.ZAccess.k ) - infected
21:29:36.0506 5896 i8042prt - detected Rootkit.Win32.ZAccess.k (0)
21:29:36.0599 5896 iaStor (80c633722da72e97f3f5b3b11325696d) C:\Windows\system32\drivers\iastor.sys
21:29:36.0603 5896 iaStor - ok
21:29:36.0654 5896 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
21:29:36.0657 5896 iaStorV - ok
21:29:36.0811 5896 igfx (8dad27dd28a4274866767c89c0bf154f) C:\Windows\system32\DRIVERS\igdkmd32.sys
21:29:36.0841 5896 igfx - ok
21:29:36.0889 5896 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
21:29:36.0890 5896 iirsp - ok
21:29:36.0969 5896 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
21:29:36.0970 5896 intelide - ok
21:29:37.0019 5896 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
21:29:37.0020 5896 intelppm - ok
21:29:37.0079 5896 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:29:37.0081 5896 IpFilterDriver - ok
21:29:37.0097 5896 IpInIp - ok
21:29:37.0135 5896 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
21:29:37.0137 5896 IPMIDRV - ok
21:29:37.0164 5896 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
21:29:37.0166 5896 IPNAT - ok
21:29:37.0213 5896 irda (e50a95179211b12946f7e035d60af560) C:\Windows\system32\DRIVERS\irda.sys
21:29:37.0215 5896 irda - ok
21:29:37.0261 5896 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
21:29:37.0262 5896 IRENUM - ok
21:29:37.0323 5896 irsir (5896b5ff6332ab2be1582523e9656a67) C:\Windows\system32\DRIVERS\irsir.sys
21:29:37.0325 5896 irsir - ok
21:29:37.0375 5896 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
21:29:37.0377 5896 isapnp - ok
21:29:37.0450 5896 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
21:29:37.0453 5896 iScsiPrt - ok
21:29:37.0483 5896 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
21:29:37.0484 5896 iteatapi - ok
21:29:37.0535 5896 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
21:29:37.0536 5896 iteraid - ok
21:29:37.0570 5896 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
21:29:37.0571 5896 kbdclass - ok
21:29:37.0612 5896 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
21:29:37.0613 5896 kbdhid - ok
21:29:37.0685 5896 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
21:29:37.0691 5896 KSecDD - ok
21:29:37.0785 5896 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
21:29:37.0786 5896 lltdio - ok
21:29:37.0858 5896 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
21:29:37.0861 5896 LSI_FC - ok
21:29:37.0912 5896 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
21:29:37.0913 5896 LSI_SAS - ok
21:29:37.0964 5896 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
21:29:37.0966 5896 LSI_SCSI - ok
21:29:38.0017 5896 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
21:29:38.0019 5896 luafv - ok
21:29:38.0098 5896 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys
21:29:38.0099 5896 MBAMProtector - ok
21:29:38.0211 5896 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
21:29:38.0213 5896 megasas - ok
21:29:38.0278 5896 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
21:29:38.0284 5896 MegaSR - ok
21:29:38.0371 5896 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
21:29:38.0372 5896 Modem - ok
21:29:38.0420 5896 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
21:29:38.0422 5896 monitor - ok
21:29:38.0462 5896 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
21:29:38.0463 5896 mouclass - ok
21:29:38.0518 5896 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
21:29:38.0519 5896 mouhid - ok
21:29:38.0572 5896 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
21:29:38.0573 5896 MountMgr - ok
21:29:38.0634 5896 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
21:29:38.0637 5896 mpio - ok
21:29:38.0679 5896 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
21:29:38.0681 5896 mpsdrv - ok
21:29:38.0736 5896 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
21:29:38.0738 5896 Mraid35x - ok
21:29:38.0873 5896 MREMP50 (80b2ec735495823ae5771a5f603e73bd) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
21:29:38.0875 5896 MREMP50 - ok
21:29:38.0883 5896 MREMP50a64 - ok
21:29:38.0945 5896 MRESP50 (37d7c22f7e26da90e2d2d260e5d27846) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
21:29:38.0946 5896 MRESP50 - ok
21:29:38.0953 5896 MRESP50a64 - ok
21:29:39.0041 5896 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
21:29:39.0044 5896 MRxDAV - ok
21:29:39.0140 5896 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
21:29:39.0142 5896 mrxsmb - ok
21:29:39.0216 5896 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:29:39.0219 5896 mrxsmb10 - ok
21:29:39.0245 5896 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:29:39.0247 5896 mrxsmb20 - ok
21:29:39.0297 5896 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
21:29:39.0299 5896 msahci - ok
21:29:39.0345 5896 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
21:29:39.0347 5896 msdsm - ok
21:29:39.0387 5896 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
21:29:39.0388 5896 Msfs - ok
21:29:39.0419 5896 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
21:29:39.0420 5896 msisadrv - ok
21:29:39.0486 5896 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
21:29:39.0487 5896 MSKSSRV - ok
21:29:39.0515 5896 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
21:29:39.0517 5896 MSPCLOCK - ok
21:29:39.0554 5896 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
21:29:39.0555 5896 MSPQM - ok
21:29:39.0626 5896 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
21:29:39.0629 5896 MsRPC - ok
21:29:39.0693 5896 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
21:29:39.0694 5896 mssmbios - ok
21:29:39.0726 5896 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
21:29:39.0727 5896 MSTEE - ok
21:29:39.0768 5896 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
21:29:39.0770 5896 Mup - ok
21:29:39.0851 5896 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
21:29:39.0853 5896 NativeWifiP - ok
21:29:39.0943 5896 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
21:29:39.0951 5896 NDIS - ok
21:29:39.0968 5896 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
21:29:39.0969 5896 NdisTapi - ok
21:29:40.0012 5896 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
21:29:40.0013 5896 Ndisuio - ok
21:29:40.0064 5896 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
21:29:40.0066 5896 NdisWan - ok
21:29:40.0091 5896 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
21:29:40.0092 5896 NDProxy - ok
21:29:40.0111 5896 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
21:29:40.0113 5896 NetBIOS - ok
21:29:40.0189 5896 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
21:29:40.0192 5896 netbt - ok
21:29:40.0267 5896 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
21:29:40.0269 5896 nfrd960 - ok
21:29:40.0306 5896 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
21:29:40.0328 5896 Npfs - ok
21:29:40.0360 5896 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
21:29:40.0361 5896 nsiproxy - ok
21:29:40.0475 5896 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
21:29:40.0490 5896 Ntfs - ok
21:29:40.0542 5896 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
21:29:40.0543 5896 ntrigdigi - ok
21:29:40.0557 5896 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
21:29:40.0571 5896 Null - ok
21:29:40.0613 5896 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
21:29:40.0615 5896 nvraid - ok
21:29:40.0658 5896 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
21:29:40.0659 5896 nvstor - ok
21:29:40.0699 5896 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
21:29:40.0701 5896 nv_agp - ok
21:29:40.0726 5896 NwlnkFlt - ok
21:29:40.0744 5896 NwlnkFwd - ok
21:29:40.0791 5896 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
21:29:40.0793 5896 ohci1394 - ok
21:29:40.0856 5896 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
21:29:40.0858 5896 Parport - ok
21:29:40.0903 5896 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
21:29:40.0905 5896 partmgr - ok
21:29:40.0948 5896 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
21:29:40.0949 5896 Parvdm - ok
21:29:41.0018 5896 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
21:29:41.0021 5896 pci - ok
21:29:41.0068 5896 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
21:29:41.0069 5896 pciide - ok
21:29:41.0119 5896 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
21:29:41.0122 5896 pcmcia - ok
21:29:41.0185 5896 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
21:29:41.0196 5896 PEAUTH - ok
21:29:41.0282 5896 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
21:29:41.0284 5896 PptpMiniport - ok
21:29:41.0323 5896 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
21:29:41.0324 5896 Processor - ok
21:29:41.0415 5896 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
21:29:41.0417 5896 PSched - ok
21:29:41.0488 5896 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys
21:29:41.0490 5896 PxHelp20 - ok
21:29:41.0571 5896 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
21:29:41.0585 5896 ql2300 - ok
21:29:41.0630 5896 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
21:29:41.0632 5896 ql40xx - ok
21:29:41.0680 5896 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
21:29:41.0681 5896 QWAVEdrv - ok
21:29:41.0806 5896 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys
21:29:41.0832 5896 R300 - ok
21:29:41.0872 5896 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
21:29:41.0874 5896 RasAcd - ok
21:29:41.0910 5896 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
21:29:41.0911 5896 Rasl2tp - ok
21:29:41.0980 5896 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
21:29:41.0982 5896 RasPppoe - ok
21:29:42.0046 5896 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
21:29:42.0048 5896 RasSstp - ok
21:29:42.0124 5896 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
21:29:42.0127 5896 rdbss - ok
21:29:42.0143 5896 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
21:29:42.0145 5896 RDPCDD - ok
21:29:42.0193 5896 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
21:29:42.0197 5896 rdpdr - ok
21:29:42.0212 5896 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
21:29:42.0213 5896 RDPENCDD - ok
21:29:42.0259 5896 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
21:29:42.0285 5896 RDPWD - ok
21:29:42.0346 5896 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
21:29:42.0347 5896 rspndr - ok
21:29:42.0402 5896 RTSTOR (8f6b5cfcd472fd3e54a68d211ec4617b) C:\Windows\system32\drivers\RTSTOR.SYS
21:29:42.0404 5896 RTSTOR - ok
21:29:42.0454 5896 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
21:29:42.0456 5896 sbp2port - ok
21:29:42.0530 5896 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
21:29:42.0532 5896 secdrv - ok
21:29:42.0575 5896 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
21:29:42.0578 5896 Serenum - ok
21:29:42.0647 5896 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
21:29:42.0649 5896 Serial - ok
21:29:42.0700 5896 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
21:29:42.0701 5896 sermouse - ok
21:29:42.0764 5896 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
21:29:42.0766 5896 sffdisk - ok
21:29:42.0809 5896 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
21:29:42.0810 5896 sffp_mmc - ok
21:29:42.0847 5896 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
21:29:42.0848 5896 sffp_sd - ok
21:29:42.0892 5896 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
21:29:42.0893 5896 sfloppy - ok
21:29:42.0954 5896 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
21:29:42.0956 5896 sisagp - ok
21:29:42.0999 5896 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
21:29:43.0001 5896 SiSRaid2 - ok
21:29:43.0041 5896 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
21:29:43.0042 5896 SiSRaid4 - ok
21:29:43.0131 5896 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
21:29:43.0133 5896 Smb - ok
21:29:43.0169 5896 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
21:29:43.0170 5896 spldr - ok
21:29:43.0250 5896 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
21:29:43.0255 5896 srv - ok
21:29:43.0341 5896 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
21:29:43.0344 5896 srv2 - ok
21:29:43.0374 5896 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
21:29:43.0376 5896 srvnet - ok
21:29:43.0448 5896 ssadbus (6d83ff6722baf7e82a4521dbec363e5a) C:\Windows\system32\DRIVERS\ssadbus.sys
21:29:43.0450 5896 ssadbus - ok
21:29:43.0519 5896 ssadmdfl (5ae42e90f99749e0e35b9989a2d0275c) C:\Windows\system32\DRIVERS\ssadmdfl.sys
21:29:43.0521 5896 ssadmdfl - ok
21:29:43.0570 5896 ssadmdm (9285d8aba50a4d6482b1574448f9eb76) C:\Windows\system32\DRIVERS\ssadmdm.sys
21:29:43.0572 5896 ssadmdm - ok
21:29:43.0679 5896 sscdbus (069351a1d7d291013177a90ae6edccbc) C:\Windows\system32\DRIVERS\sscdbus.sys
21:29:43.0681 5896 sscdbus - ok
21:29:43.0717 5896 sscdmdfl (1c925be223a5c0f9f469252292a48df6) C:\Windows\system32\DRIVERS\sscdmdfl.sys
21:29:43.0718 5896 sscdmdfl - ok
21:29:43.0754 5896 sscdmdm (ae3e77ae0fbdb07eb1ac3fed74a0695e) C:\Windows\system32\DRIVERS\sscdmdm.sys
21:29:43.0756 5896 sscdmdm - ok
21:29:43.0864 5896 STHDA (14a9ad287fda70a06463e09c4328c1f2) C:\Windows\system32\DRIVERS\stwrt.sys
21:29:43.0869 5896 STHDA - ok
21:29:43.0945 5896 StillCam (ef70b3d22b4bffda6ea851ecb063efaa) C:\Windows\system32\DRIVERS\serscan.sys
21:29:43.0946 5896 StillCam - ok
21:29:44.0035 5896 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
21:29:44.0036 5896 swenum - ok
21:29:44.0072 5896 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
21:29:44.0074 5896 Symc8xx - ok
21:29:44.0114 5896 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
21:29:44.0115 5896 Sym_hi - ok
21:29:44.0180 5896 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
21:29:44.0181 5896 Sym_u3 - ok
21:29:44.0305 5896 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
21:29:44.0316 5896 Tcpip - ok
21:29:44.0357 5896 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
21:29:44.0368 5896 Tcpip6 - ok
21:29:44.0438 5896 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
21:29:44.0439 5896 tcpipreg - ok
21:29:44.0489 5896 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
21:29:44.0491 5896 TDPIPE - ok
21:29:44.0536 5896 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
21:29:44.0538 5896 TDTCP - ok
21:29:44.0597 5896 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
21:29:44.0599 5896 tdx - ok
21:29:44.0659 5896 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
21:29:44.0660 5896 TermDD - ok
21:29:44.0742 5896 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
21:29:44.0743 5896 tssecsrv - ok
21:29:44.0782 5896 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
21:29:44.0784 5896 tunmp - ok
21:29:44.0856 5896 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
21:29:44.0858 5896 tunnel - ok
21:29:44.0896 5896 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
21:29:44.0897 5896 uagp35 - ok
21:29:44.0967 5896 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
21:29:44.0970 5896 udfs - ok
21:29:45.0035 5896 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
21:29:45.0037 5896 uliagpkx - ok
21:29:45.0087 5896 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
21:29:45.0090 5896 uliahci - ok
21:29:45.0132 5896 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
21:29:45.0134 5896 UlSata - ok
21:29:45.0176 5896 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
21:29:45.0178 5896 ulsata2 - ok
21:29:45.0211 5896 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
21:29:45.0213 5896 umbus - ok
21:29:45.0278 5896 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\Windows\system32\Drivers\usbaapl.sys
21:29:45.0280 5896 USBAAPL - ok
21:29:45.0372 5896 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
21:29:45.0374 5896 usbccgp - ok
21:29:45.0414 5896 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
21:29:45.0416 5896 usbcir - ok
21:29:45.0481 5896 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
21:29:45.0483 5896 usbehci - ok
21:29:45.0554 5896 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
21:29:45.0557 5896 usbhub - ok
21:29:45.0597 5896 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
21:29:45.0599 5896 usbohci - ok
21:29:45.0645 5896 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
21:29:45.0646 5896 usbprint - ok
21:29:45.0707 5896 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
21:29:45.0709 5896 usbscan - ok
21:29:45.0768 5896 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:29:45.0769 5896 USBSTOR - ok
21:29:45.0789 5896 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
21:29:45.0791 5896 usbuhci - ok
21:29:45.0890 5896 VBoxDrv (7be10a4eaf9c7475a28c6fafdf756499) C:\Windows\system32\DRIVERS\VBoxDrv.sys
21:29:45.0892 5896 VBoxDrv - ok
21:29:45.0938 5896 VBoxNetAdp (a1989b6f174ad6ee1c3de55cb942c91f) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
21:29:45.0940 5896 VBoxNetAdp - ok
21:29:45.0984 5896 VBoxNetFlt (19ba977f1714d51b9fad6b188989ea03) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
21:29:45.0986 5896 VBoxNetFlt - ok
21:29:46.0030 5896 VBoxUSBMon (779744e022f3733c2d36014036ed74c2) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
21:29:46.0032 5896 VBoxUSBMon - ok
21:29:46.0096 5896 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
21:29:46.0098 5896 vga - ok
21:29:46.0122 5896 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
21:29:46.0123 5896 VgaSave - ok
21:29:46.0164 5896 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
21:29:46.0166 5896 viaagp - ok
21:29:46.0202 5896 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
21:29:46.0204 5896 ViaC7 - ok
21:29:46.0246 5896 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
21:29:46.0248 5896 viaide - ok
21:29:46.0267 5896 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
21:29:46.0270 5896 volmgr - ok
21:29:46.0351 5896 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
21:29:46.0355 5896 volmgrx - ok
21:29:46.0395 5896 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
21:29:46.0399 5896 volsnap - ok
21:29:46.0455 5896 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
21:29:46.0457 5896 vsmraid - ok
21:29:46.0517 5896 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
21:29:46.0518 5896 WacomPen - ok
21:29:46.0572 5896 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
21:29:46.0574 5896 Wanarp - ok
21:29:46.0599 5896 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
21:29:46.0601 5896 Wanarpv6 - ok
21:29:46.0655 5896 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
21:29:46.0656 5896 Wd - ok
21:29:46.0712 5896 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
21:29:46.0719 5896 Wdf01000 - ok
21:29:46.0821 5896 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
21:29:46.0823 5896 WmiAcpi - ok
21:29:46.0932 5896 WpdUsb (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys
21:29:46.0933 5896 WpdUsb - ok
21:29:46.0970 5896 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
21:29:46.0971 5896 ws2ifsl - ok
21:29:47.0052 5896 WSDPrintDevice (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys
21:29:47.0053 5896 WSDPrintDevice - ok
21:29:47.0108 5896 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
21:29:47.0110 5896 WUDFRd - ok
21:29:47.0203 5896 yukonwlh (1a51df1a5c658d534ed980d18f7982de) C:\Windows\system32\DRIVERS\yk60x86.sys
21:29:47.0207 5896 yukonwlh - ok
21:29:47.0264 5896 MBR (0x1B8) (d83f94e05deced58921d4d8b25a861b7) \Device\Harddisk0\DR0
21:29:47.0276 5896 \Device\Harddisk0\DR0 - ok
21:29:47.0288 5896 Boot (0x1200) (c65ebb53ad6ab8ce1915d4348cce8aee) \Device\Harddisk0\DR0\Partition0
21:29:47.0290 5896 \Device\Harddisk0\DR0\Partition0 - ok
21:29:47.0314 5896 Boot (0x1200) (b6bf62f45efc1bfb7f4ceac255772549) \Device\Harddisk0\DR0\Partition1
21:29:47.0316 5896 \Device\Harddisk0\DR0\Partition1 - ok
21:29:47.0317 5896 ============================================================
21:29:47.0317 5896 Scan finished
21:29:47.0317 5896 ============================================================
21:29:47.0339 5524 Detected object count: 1
21:29:47.0340 5524 Actual detected object count: 1
21:29:53.0107 5524 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\Windows\system32\drivers\i8042prt.sys) error 1813
21:30:00.0754 5524 Backup copy not found, trying to cure infected file..
21:30:00.0787 5524 C:\Windows\system32\DRIVERS\i8042prt.sys - Cure failed (FFFFFFFF)
21:30:00.0787 5524 C:\Windows\system32\DRIVERS\i8042prt.sys - processing error
21:30:03.0684 5524 i8042prt ( Rootkit.Win32.ZAccess.k ) - User select action: Cure

Any help is very much appreciated. Working with a USB keyboard and mouse for now.

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:05 PM

Posted 08 December 2011 - 11:36 PM

Ok, The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is "C:\Program

Files\EsetOnlineScanner\log.txt".
You can view this file by navigating to the directory and double-clicking it in Windows Explorer, or by copying and pasting the path

specification above (including the quotation marks) into the Start >> Run dialog box from the Start Menu on the desktop.


This is the important section of the TDSS log

21:29:47.0339 5524 Detected object count: 1
21:29:47.0340 5524 Actual detected object count: 1
21:29:53.0107 5524 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\Windows\system32\drivers\i8042prt.sys) error 1813
21:30:00.0754 5524 Backup copy not found, trying to cure infected file..
21:30:00.0787 5524 C:\Windows\system32\DRIVERS\i8042prt.sys - Cure failed (FFFFFFFF)
21:30:00.0787 5524 C:\Windows\system32\DRIVERS\i8042prt.sys - processing error
21:30:03.0684 5524 i8042prt ( Rootkit.Win32.ZAccess.k ) - User select action: Cure


The cure failed,not Good.
I think it best if we let our Malware removal team dig this out..

We need a deeper look. Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
If Gmer won't run,skip it and move on.
Include a link back to this topic.

Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 kdlan

kdlan

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:05 PM

Posted 09 December 2011 - 07:26 PM

I downloaded DeFogger and ran the program. It didn't ask me to restart my computer. I went ahead and downloaded DDS but it would only download as a notepad file that is jibberish. Here is the log file from defogger. Did it disable my CD emulation programs? I'm not quite sure what the problem is??

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 18:20 on 09/12/2011 (courtney)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-

Thanks

#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:05 PM

Posted 09 December 2011 - 08:13 PM

please download this file: xp_scr_fix.

Unpack the file onto your desktop and double-click it. You will be asked if you wish to merge the file with you registry, say yes.

You should then be able to run DDS.scr.

W7
Please try this download: scr_fix_w7.zip

Vista
please try this: scrfx_vista



If you cannot get DDS to work, please try this instead.

Please download OTL by OldTimer and save it to your Desktop.
  • Close all other applications and windows so that you have nothing open.
  • Double click on the Posted Image icon on your desktop.

    Vista/Windows 7 users right-click and select Run As Administrator.
    If you receive a UAC prompt asking if you would like to continue running the program, you should press the Continue button.
  • Under Output, ensure that Minimal Output is selected.
  • Click the "Scan All Users" checkbox.
    Leave the remaining selections to the default settings.
  • Click the Posted Image button.
  • Do not use the computer while the scan is in progress.
  • When the scan is complete, two log files will open in Notepad:
    • OTListIt.txt <- (will be maximized)
    • Extras.txt <- (will be minimized in the Task Bar).
  • Both logs are automatically saved to the Desktop.
  • Please copy and paste the contents of OTListIt.txt and Extras.txt in your next reply.
    If the Extras.txt log is too long, you may need to add a second reply to your thread or upload it as an attachment.
  • Click the red X in the upper right corner to exit OTL.
Important: Be sure to mention that you tried to follow the Prep Guide but were unable to get DDS to run. If OTL did not work, then reply back here.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 kdlan

kdlan

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:05 PM

Posted 09 December 2011 - 08:18 PM

I was able to download and run DDS.pif. I've downloaded GMER and have attached both log files to the "virus, trojan, spyware, and malware removal logs"

Thanks for the help.

#10 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,112 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:11:05 PM

Posted 10 December 2011 - 02:19 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/topic431605.html you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Internet Security, NoScript Firefox ext.


animinionsmalltext.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users