Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

No internet afer virus removal


  • Please log in to reply
15 replies to this topic

#1 misters

misters

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 11 January 2012 - 06:53 AM

Hello, I can not get onto the internet after a virus removal.

I am running windows xp and had the Backdoor.Tidserv activity 2 virus which was invisible on a scan but Norton popped up with a warning and suggested that I download and ran their FixTDSS.exe removal tool.

I downloaded the file directly from their site and ran the tool and it did not fix the problem, and made things worse by not letting me log onto my computer unless I ran it in safe mode or used the system restore point.

I used the system restore point, but I still had the virus. I then discovered Kaspersky's TDSSKiller.zip application which I ran and has seemed to remove the virus but my internet now doesnt work.

I have done full system scans with Norton 2012, Spybot, Malware bytes (which did error near completion), and ran CC Cleaner.

When I try loading Firefox or IE, I get the website cannot be displayed and there is no modem activity (I'm connecting via wired). A diagnosis in IE says that I have a problem with WinSock.

I downloaded MicrosoftFixit50203 from the Microsoft website but that didnt work. I also tried WinsockxpFix which also didnt work. I then tried Start - Run - 'CHKDSK' which aparantly replaced a couple of files but still wont let me onto the web and I still have the Winsock notification.

Can anyone recommend my next step or an easy fix. If it helps, I should have a disk that came with the laptop somewhere, that is a manufacturers version of windows (with a load of bloatware).

Thanks in advance for any help.

Edited by hamluis, 11 January 2012 - 10:15 AM.
Moved from XP to Am I Infected.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:07 AM

Posted 11 January 2012 - 10:20 AM

Download

http://download.bleepingcomputer.com/farbar/FSS.exe


and run it on the infected PC.


* Click on "Scan".
* It will create a log (FSS.txt) in the same directory the tool is run.
* Please copy and paste the log to your reply

#3 misters

misters
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 12 January 2012 - 04:13 AM

Hi, thanks for the reply.

I ran the file and here's the log:

Farbar Service Scanner
Ran by (administrator) on 11-01-2012 at 20:07:17
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============
Dhcp Service is not running. Checking service configuration:
The start type of Dhcp service is OK.
The ImagePath of Dhcp service is OK.
The ServiceDll of Dhcp service is OK.

afd Service is not running. Checking service configuration:
The start type of afd service is OK.
The ImagePath of afd: "system32\drivers\tsk2C.tmp".


Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Attempt to access Google IP returned error: Google IP is unreachable
Attempt to access Yahoo IP returend error: Yahoo IP is unreachable


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
AegisP(9) Gpc(6) IPSec(4) NetBT(5) PSched(7) s24trans(8) SYMTDI(10) Tcpip(3)
0x0A000000040000000100000002000000030000000A0000000500000006000000070000000800000009000000
IpSec Tag value is correct.

**** End of log ****

#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:07 AM

Posted 12 January 2012 - 04:50 AM

To be on safer side before running registry fixes i would suggest you to

Download

http://www.snapfiles.com/get/erunt.html

Install it and backup your registry to C:/Windows/erdnt

Now,download afd.reg

http://www.mediafire.com/?067al4xazmyl0gx

Download and launch it,click YES when you receive a prompt

Restart your PC and check your browser

Good luck

#5 misters

misters
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 12 January 2012 - 06:09 AM

Excellent, I've just downloaded them and I will try them when I get home tonight.

Just a query, but how do I launch the afd.reg.txt file, I'm assuming it will just end up opening in notepad?

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:07 AM

Posted 12 January 2012 - 11:04 AM

Just rename

afd.reg.txt to afd.reg and launch it

good luck

Edited by narenxp, 12 January 2012 - 11:04 AM.


#7 misters

misters
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 12 January 2012 - 02:51 PM

Hi,

I did as you said, rebooted but now my laptop won't turn on unless I go into safe mode or system restore. Any clue?

#8 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:07 AM

Posted 12 January 2012 - 07:51 PM

Please boot into safemode and do a system restore.

See if you can boot into normal mode.

Let me know after that
Good luck

#9 misters

misters
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 13 January 2012 - 04:50 AM

Hi,

Yes I tried that and i still can't get onto the internet.

Sorry, this is turning into a bit of a mission isn't it!

#10 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:07 AM

Posted 13 January 2012 - 09:29 AM

Can you boot into normal mode?

Download

http://support.kaspersky.com/downloads/utils/tdsskiller.exe

Click on SCAN and post the log

#11 misters

misters
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 13 January 2012 - 11:40 AM

Yes, after I rebooted from launching afd.reg, I couldnt reboot, so I selected the system restore and I can now get in but not access the internet.

I ran TDSSKiller before, but I will run it again and post the log.

Thanks for your help so far.

#12 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:07 AM

Posted 13 January 2012 - 11:49 AM

I also need your gmer log

Please download GMER from here

http://www2.gmer.net/download.php

Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.

GMER will open to the Rootkit/Malware tab and perform an automatic Full Scan when first run. (do not use the computer while the scan is in progress)

If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
Now click the Scan button. If you see a rootkit warning window, click OK.
When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
Click the Copy button and paste the results into your next reply.

#13 misters

misters
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 16 January 2012 - 04:53 AM

Hi, right here's the TDSSKiller log that I ran on saturday:

15:48:27.0203 4016 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
15:48:27.0218 4016 ============================================================
15:48:27.0218 4016 Current date / time: 2012/01/14 15:48:27.0218
15:48:27.0218 4016 SystemInfo:
15:48:27.0218 4016
15:48:27.0218 4016 OS Version: 5.1.2600 ServicePack: 3.0
15:48:27.0218 4016 Product type: Workstation
15:48:27.0218 4016 ComputerName:
15:48:27.0218 4016 UserName:
15:48:27.0218 4016 Windows directory: C:\WINDOWS
15:48:27.0218 4016 System windows directory: C:\WINDOWS
15:48:27.0218 4016 Processor architecture: Intel x86
15:48:27.0218 4016 Number of processors: 2
15:48:27.0218 4016 Page size: 0x1000
15:48:27.0218 4016 Boot type: Normal boot
15:48:27.0218 4016 ============================================================
15:48:29.0312 4016 Initialize success
15:48:41.0031 5908 ============================================================
15:48:41.0031 5908 Scan started
15:48:41.0031 5908 Mode: Manual;
15:48:41.0031 5908 ============================================================
15:48:41.0640 5908 29594527 - ok
15:48:41.0671 5908 Abiosdsk - ok
15:48:41.0718 5908 abp480n5 - ok
15:48:41.0796 5908 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
15:48:41.0796 5908 ACPI - ok
15:48:41.0875 5908 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
15:48:41.0875 5908 ACPIEC - ok
15:48:41.0921 5908 adpu160m - ok
15:48:42.0015 5908 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
15:48:42.0015 5908 aec - ok
15:48:42.0125 5908 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
15:48:42.0125 5908 AegisP - ok
15:48:42.0156 5908 AFD - ok
15:48:42.0203 5908 Aha154x - ok
15:48:42.0250 5908 aic78u2 - ok
15:48:42.0296 5908 aic78xx - ok
15:48:42.0375 5908 alcan5wn (0940030d5a5869067ccc03e3b0b8dec7) C:\WINDOWS\system32\DRIVERS\alcan5wn.sys
15:48:42.0375 5908 alcan5wn - ok
15:48:42.0453 5908 alcaudsl (4c9577888c53243e2991456f510488a1) C:\WINDOWS\system32\DRIVERS\alcaudsl.sys
15:48:42.0453 5908 alcaudsl - ok
15:48:42.0546 5908 AliIde - ok
15:48:42.0593 5908 amsint - ok
15:48:42.0656 5908 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
15:48:42.0671 5908 ApfiltrService - ok
15:48:42.0781 5908 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
15:48:42.0781 5908 Arp1394 - ok
15:48:42.0812 5908 asc - ok
15:48:42.0859 5908 asc3350p - ok
15:48:42.0953 5908 asc3550 - ok
15:48:43.0000 5908 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
15:48:43.0000 5908 AsyncMac - ok
15:48:43.0062 5908 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
15:48:43.0062 5908 atapi - ok
15:48:43.0125 5908 Atdisk - ok
15:48:43.0281 5908 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
15:48:43.0281 5908 Atmarpc - ok
15:48:43.0406 5908 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
15:48:43.0406 5908 audstub - ok
15:48:43.0484 5908 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
15:48:43.0484 5908 Beep - ok
15:48:43.0734 5908 BHDrvx86 (9d14d76e4e7b9b2ead17149011db2b11) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20111221.003\BHDrvx86.sys
15:48:43.0750 5908 BHDrvx86 - ok
15:48:43.0859 5908 BTCFilterService - ok
15:48:43.0937 5908 C-Dilla (b77634d2a76e8851ddfd883d096106c7) C:\WINDOWS\system32\drivers\CDANT.SYS
15:48:43.0937 5908 C-Dilla - ok
15:48:44.0000 5908 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
15:48:44.0015 5908 cbidf2k - ok
15:48:44.0093 5908 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
15:48:44.0093 5908 CCDECODE - ok
15:48:44.0140 5908 cd20xrnt - ok
15:48:44.0234 5908 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
15:48:44.0234 5908 Cdaudio - ok
15:48:44.0296 5908 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
15:48:44.0312 5908 Cdfs - ok
15:48:44.0375 5908 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
15:48:44.0375 5908 Cdrom - ok
15:48:44.0406 5908 Changer - ok
15:48:44.0468 5908 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
15:48:44.0468 5908 CmBatt - ok
15:48:44.0515 5908 CmdIde - ok
15:48:44.0593 5908 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
15:48:44.0593 5908 Compbatt - ok
15:48:44.0656 5908 Cpqarray - ok
15:48:44.0718 5908 dac2w2k - ok
15:48:44.0765 5908 dac960nt - ok
15:48:44.0843 5908 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
15:48:44.0843 5908 Disk - ok
15:48:44.0968 5908 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
15:48:45.0000 5908 dmboot - ok
15:48:45.0109 5908 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys
15:48:45.0109 5908 DMICall - ok
15:48:45.0171 5908 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
15:48:45.0187 5908 dmio - ok
15:48:45.0265 5908 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
15:48:45.0265 5908 dmload - ok
15:48:45.0343 5908 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
15:48:45.0359 5908 DMusic - ok
15:48:45.0421 5908 dpti2o - ok
15:48:45.0500 5908 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
15:48:45.0500 5908 drmkaud - ok
15:48:45.0593 5908 E100B (5c940a174dfb2c42b9f6ba6edc2baa0b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
15:48:45.0593 5908 E100B - ok
15:48:45.0671 5908 e1express (389cf2cded384be477c3b3f15747d495) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
15:48:45.0671 5908 e1express - ok
15:48:45.0781 5908 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
15:48:45.0781 5908 eeCtrl - ok
15:48:45.0828 5908 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
15:48:45.0828 5908 EraserUtilRebootDrv - ok
15:48:45.0984 5908 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
15:48:45.0984 5908 Fastfat - ok
15:48:46.0046 5908 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
15:48:46.0046 5908 Fdc - ok
15:48:46.0109 5908 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
15:48:46.0109 5908 Fips - ok
15:48:46.0203 5908 FixTDSS (77d6ffaa3010b66fb4692532d75a585f) C:\WINDOWS\system32\drivers\FixTDSS.sys
15:48:46.0203 5908 FixTDSS - ok
15:48:46.0343 5908 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
15:48:46.0343 5908 Flpydisk - ok
15:48:46.0406 5908 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
15:48:46.0406 5908 FltMgr - ok
15:48:46.0468 5908 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
15:48:46.0468 5908 Fs_Rec - ok
15:48:46.0546 5908 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
15:48:46.0546 5908 Ftdisk - ok
15:48:46.0671 5908 GearAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
15:48:46.0671 5908 GearAspiWDM - ok
15:48:46.0750 5908 ggflt (007aea2e06e7cef7372e40c277163959) C:\WINDOWS\system32\DRIVERS\ggflt.sys
15:48:46.0750 5908 ggflt - ok
15:48:46.0828 5908 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\WINDOWS\system32\DRIVERS\ggsemc.sys
15:48:46.0828 5908 ggsemc - ok
15:48:46.0921 5908 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
15:48:46.0921 5908 Gpc - ok
15:48:47.0109 5908 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
15:48:47.0109 5908 HDAudBus - ok
15:48:47.0203 5908 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
15:48:47.0203 5908 HidUsb - ok
15:48:47.0250 5908 hpn - ok
15:48:47.0343 5908 HSFHWAZL (acc46dda7fece95a253ae88cea172e12) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
15:48:47.0343 5908 HSFHWAZL - ok
15:48:47.0421 5908 HSF_DPV (c9f4e7da78a02623abf78a4a34ce79b1) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
15:48:47.0468 5908 HSF_DPV - ok
15:48:47.0609 5908 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
15:48:47.0625 5908 HTTP - ok
15:48:47.0671 5908 i2omgmt - ok
15:48:47.0718 5908 i2omp - ok
15:48:47.0796 5908 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
15:48:47.0796 5908 i8042prt - ok
15:48:48.0000 5908 IDSxpx86 (e72d3894d42355e9cd5fd77e1e4fea11) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20120104.002\IDSxpx86.sys
15:48:48.0015 5908 IDSxpx86 - ok
15:48:48.0140 5908 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
15:48:48.0140 5908 Imapi - ok
15:48:48.0187 5908 ini910u - ok
15:48:48.0234 5908 IntelIde - ok
15:48:48.0281 5908 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
15:48:48.0296 5908 intelppm - ok
15:48:48.0375 5908 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
15:48:48.0375 5908 Ip6Fw - ok
15:48:48.0500 5908 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
15:48:48.0500 5908 IpFilterDriver - ok
15:48:48.0593 5908 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
15:48:48.0593 5908 IpInIp - ok
15:48:48.0687 5908 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
15:48:48.0687 5908 IpNat - ok
15:48:48.0750 5908 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
15:48:48.0750 5908 IPSec - ok
15:48:48.0828 5908 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
15:48:48.0828 5908 IRENUM - ok
15:48:48.0937 5908 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
15:48:48.0937 5908 isapnp - ok
15:48:49.0015 5908 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
15:48:49.0015 5908 Kbdclass - ok
15:48:49.0078 5908 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
15:48:49.0078 5908 kbdhid - ok
15:48:49.0156 5908 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
15:48:49.0156 5908 kmixer - ok
15:48:49.0281 5908 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
15:48:49.0281 5908 KSecDD - ok
15:48:49.0343 5908 Lavasoft Kernexplorer - ok
15:48:49.0390 5908 Lbd - ok
15:48:49.0437 5908 lbrtfdc - ok
15:48:49.0531 5908 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
15:48:49.0531 5908 mdmxsdk - ok
15:48:49.0734 5908 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
15:48:49.0734 5908 MHNDRV - ok
15:48:49.0828 5908 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
15:48:49.0828 5908 mnmdd - ok
15:48:49.0906 5908 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
15:48:49.0906 5908 Modem - ok
15:48:49.0953 5908 motccgp - ok
15:48:49.0984 5908 motccgpfl - ok
15:48:50.0046 5908 motmodem - ok
15:48:50.0109 5908 MotoSwitchService - ok
15:48:50.0140 5908 Motousbnet - ok
15:48:50.0187 5908 motusbdevice - ok
15:48:50.0281 5908 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
15:48:50.0281 5908 Mouclass - ok
15:48:50.0359 5908 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
15:48:50.0359 5908 mouhid - ok
15:48:50.0437 5908 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
15:48:50.0437 5908 MountMgr - ok
15:48:50.0531 5908 mraid35x - ok
15:48:50.0578 5908 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
15:48:50.0578 5908 MRxDAV - ok
15:48:50.0703 5908 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
15:48:50.0718 5908 MRxSmb - ok
15:48:50.0765 5908 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
15:48:50.0765 5908 Msfs - ok
15:48:50.0843 5908 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
15:48:50.0843 5908 MSKSSRV - ok
15:48:50.0921 5908 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
15:48:50.0921 5908 MSPCLOCK - ok
15:48:51.0000 5908 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
15:48:51.0015 5908 MSPQM - ok
15:48:51.0093 5908 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
15:48:51.0093 5908 mssmbios - ok
15:48:51.0171 5908 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
15:48:51.0171 5908 MSTEE - ok
15:48:51.0265 5908 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
15:48:51.0265 5908 Mup - ok
15:48:51.0375 5908 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
15:48:51.0375 5908 NABTSFEC - ok
15:48:51.0531 5908 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20120105.007\NAVENG.SYS
15:48:51.0531 5908 NAVENG - ok
15:48:51.0625 5908 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20120105.007\NAVEX15.SYS
15:48:51.0640 5908 NAVEX15 - ok
15:48:51.0796 5908 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
15:48:51.0812 5908 NDIS - ok
15:48:51.0890 5908 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
15:48:51.0890 5908 NdisIP - ok
15:48:51.0968 5908 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
15:48:51.0968 5908 NdisTapi - ok
15:48:52.0031 5908 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
15:48:52.0031 5908 Ndisuio - ok
15:48:52.0140 5908 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
15:48:52.0140 5908 NdisWan - ok
15:48:52.0218 5908 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
15:48:52.0218 5908 NDProxy - ok
15:48:52.0281 5908 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
15:48:52.0281 5908 NetBIOS - ok
15:48:52.0343 5908 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
15:48:52.0343 5908 NetBT - ok
15:48:52.0500 5908 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
15:48:52.0515 5908 NIC1394 - ok
15:48:52.0609 5908 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
15:48:52.0609 5908 Npfs - ok
15:48:52.0703 5908 Nsynas32 (788fe8115ed732afcdcfb307f9e7a932) C:\WINDOWS\system32\drivers\Nsynas32.sys
15:48:52.0703 5908 Nsynas32 - ok
15:48:52.0781 5908 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
15:48:52.0812 5908 Ntfs - ok
15:48:52.0875 5908 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
15:48:52.0890 5908 Null - ok
15:48:53.0109 5908 nv (57e81d1fde97bb98f7373bce2f4ffb21) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
15:48:53.0312 5908 nv - ok
15:48:53.0437 5908 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
15:48:53.0437 5908 NwlnkFlt - ok
15:48:53.0500 5908 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
15:48:53.0500 5908 NwlnkFwd - ok
15:48:53.0578 5908 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
15:48:53.0578 5908 ohci1394 - ok
15:48:53.0687 5908 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
15:48:53.0687 5908 Parport - ok
15:48:53.0750 5908 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
15:48:53.0750 5908 PartMgr - ok
15:48:53.0875 5908 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
15:48:53.0890 5908 ParVdm - ok
15:48:53.0937 5908 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
15:48:53.0937 5908 PCI - ok
15:48:53.0984 5908 PCIDump - ok
15:48:54.0046 5908 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
15:48:54.0046 5908 PCIIde - ok
15:48:54.0234 5908 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
15:48:54.0234 5908 Pcmcia - ok
15:48:54.0281 5908 PDCOMP - ok
15:48:54.0359 5908 PDFRAME - ok
15:48:54.0406 5908 PDRELI - ok
15:48:54.0453 5908 PDRFRAME - ok
15:48:54.0484 5908 perc2 - ok
15:48:54.0531 5908 perc2hib - ok
15:48:54.0609 5908 pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys
15:48:54.0609 5908 pfc - ok
15:48:54.0687 5908 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
15:48:54.0687 5908 PptpMiniport - ok
15:48:54.0765 5908 PrivateDisk (d4644a982b8748353ff3805591531f46) C:\WINDOWS\system32\Drivers\PrivateDiskM.sys
15:48:54.0765 5908 PrivateDisk - ok
15:48:54.0859 5908 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
15:48:54.0875 5908 PSched - ok
15:48:54.0921 5908 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
15:48:54.0921 5908 Ptilink - ok
15:48:54.0984 5908 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
15:48:55.0000 5908 PxHelp20 - ok
15:48:55.0046 5908 ql1080 - ok
15:48:55.0093 5908 Ql10wnt - ok
15:48:55.0140 5908 ql12160 - ok
15:48:55.0171 5908 ql1240 - ok
15:48:55.0265 5908 ql1280 - ok
15:48:55.0343 5908 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
15:48:55.0343 5908 RasAcd - ok
15:48:55.0421 5908 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
15:48:55.0421 5908 Rasl2tp - ok
15:48:55.0484 5908 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
15:48:55.0484 5908 RasPppoe - ok
15:48:55.0562 5908 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
15:48:55.0578 5908 Raspti - ok
15:48:55.0625 5908 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
15:48:55.0625 5908 Rdbss - ok
15:48:55.0734 5908 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
15:48:55.0734 5908 RDPCDD - ok
15:48:55.0812 5908 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
15:48:55.0828 5908 rdpdr - ok
15:48:55.0921 5908 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
15:48:55.0921 5908 RDPWD - ok
15:48:55.0984 5908 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
15:48:55.0984 5908 redbook - ok
15:48:56.0078 5908 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
15:48:56.0078 5908 ROOTMODEM - ok
15:48:56.0218 5908 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
15:48:56.0218 5908 s24trans - ok
15:48:56.0296 5908 s3017bus (aa786ad3a2684d39630744787b00e6f4) C:\WINDOWS\system32\DRIVERS\s3017bus.sys
15:48:56.0296 5908 s3017bus - ok
15:48:56.0375 5908 s3017mdfl (cba4ca5bce44084e98ce420fd6692d3a) C:\WINDOWS\system32\DRIVERS\s3017mdfl.sys
15:48:56.0375 5908 s3017mdfl - ok
15:48:56.0453 5908 s3017mdm (68036eff647970d6c0399789c8707cad) C:\WINDOWS\system32\DRIVERS\s3017mdm.sys
15:48:56.0453 5908 s3017mdm - ok
15:48:56.0515 5908 s3017mgmt (3672e7f9349bd98fd3f5ac33e7b2b1a6) C:\WINDOWS\system32\DRIVERS\s3017mgmt.sys
15:48:56.0515 5908 s3017mgmt - ok
15:48:56.0593 5908 s3017nd5 (b1133b37eb184aef81d56b4302dbae9c) C:\WINDOWS\system32\DRIVERS\s3017nd5.sys
15:48:56.0593 5908 s3017nd5 - ok
15:48:56.0703 5908 s3017obex (d81b1d504aa1426622e7ec09f25130a9) C:\WINDOWS\system32\DRIVERS\s3017obex.sys
15:48:56.0703 5908 s3017obex - ok
15:48:56.0781 5908 s3017unic (7b95c53ea8bb585013767eef2875c0a0) C:\WINDOWS\system32\DRIVERS\s3017unic.sys
15:48:56.0781 5908 s3017unic - ok
15:48:56.0875 5908 S6U12BScanner (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\drivers\usbscan.sys
15:48:56.0875 5908 S6U12BScanner - ok
15:48:56.0984 5908 SE26bus (d12cd1cce29256af57b3a0a0a4eb4985) C:\WINDOWS\system32\DRIVERS\SE26bus.sys
15:48:56.0984 5908 SE26bus - ok
15:48:57.0046 5908 SE26mdfl (271e52ebe93af39d3410f5481f36202a) C:\WINDOWS\system32\DRIVERS\SE26mdfl.sys
15:48:57.0046 5908 SE26mdfl - ok
15:48:57.0109 5908 SE26mdm (c6b688bc8af4d2d384dbcb3fa4681fca) C:\WINDOWS\system32\DRIVERS\SE26mdm.sys
15:48:57.0109 5908 SE26mdm - ok
15:48:57.0187 5908 SE26mgmt (046b56284d7c2cbf25d6edeefc74cab8) C:\WINDOWS\system32\DRIVERS\SE26mgmt.sys
15:48:57.0187 5908 SE26mgmt - ok
15:48:57.0265 5908 se26nd5 (4380ec5a1451e740c589c313cffd830e) C:\WINDOWS\system32\DRIVERS\se26nd5.sys
15:48:57.0265 5908 se26nd5 - ok
15:48:57.0343 5908 SE26obex (e6a884ea26c38087a419c4221a354168) C:\WINDOWS\system32\DRIVERS\SE26obex.sys
15:48:57.0343 5908 SE26obex - ok
15:48:57.0406 5908 se26unic (4d3e5a8968ba82728bd4d352d12589f5) C:\WINDOWS\system32\DRIVERS\se26unic.sys
15:48:57.0406 5908 se26unic - ok
15:48:57.0484 5908 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
15:48:57.0500 5908 Secdrv - ok
15:48:57.0578 5908 seehcri (e5b56569a9f79b70314fede6c953641e) C:\WINDOWS\system32\DRIVERS\seehcri.sys
15:48:57.0578 5908 seehcri - ok
15:48:57.0796 5908 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
15:48:57.0828 5908 Serial - ok
15:48:58.0031 5908 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
15:48:58.0109 5908 Sfloppy - ok
15:48:58.0265 5908 SI3132 (716a724a447c559f122ea140d636fa48) C:\WINDOWS\system32\DRIVERS\SI3132.sys
15:48:58.0265 5908 SI3132 - ok
15:48:58.0343 5908 SiFilter (72cf151fb410e544904dbc7d7f29b796) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
15:48:58.0343 5908 SiFilter - ok
15:48:58.0390 5908 Simbad - ok
15:48:58.0437 5908 SiRemFil (62fd549acf2943f89612a8777295fa57) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys
15:48:58.0437 5908 SiRemFil - ok
15:48:58.0500 5908 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
15:48:58.0500 5908 SLIP - ok
15:48:58.0578 5908 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\Drivers\SonyNC.sys
15:48:58.0578 5908 SNC - ok
15:48:58.0671 5908 SonyImgF (fb77021110eaa16ea6e0961c844ef0d2) C:\WINDOWS\system32\DRIVERS\SonyImgF.sys
15:48:58.0671 5908 SonyImgF - ok
15:48:58.0750 5908 Sparrow - ok
15:48:58.0828 5908 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
15:48:58.0828 5908 splitter - ok
15:48:58.0890 5908 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
15:48:58.0890 5908 sr - ok
15:48:59.0015 5908 SRTSP (83726cf02eced69138948083e06b6eac) C:\WINDOWS\System32\Drivers\NIS\1206000.01D\SRTSP.SYS
15:48:59.0015 5908 SRTSP - ok
15:48:59.0093 5908 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\WINDOWS\system32\drivers\NIS\1206000.01D\SRTSPX.SYS
15:48:59.0093 5908 SRTSPX - ok
15:48:59.0171 5908 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
15:48:59.0171 5908 Srv - ok
15:48:59.0343 5908 STHDA (c80ec509026f6cc88486742083386ff6) C:\WINDOWS\system32\drivers\sthda.sys
15:48:59.0343 5908 STHDA - ok
15:48:59.0437 5908 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
15:48:59.0437 5908 streamip - ok
15:48:59.0484 5908 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
15:48:59.0484 5908 swenum - ok
15:48:59.0578 5908 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
15:48:59.0578 5908 swmidi - ok
15:48:59.0640 5908 symc810 - ok
15:48:59.0687 5908 symc8xx - ok
15:48:59.0796 5908 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\WINDOWS\system32\drivers\NIS\1206000.01D\SYMDS.SYS
15:48:59.0812 5908 SymDS - ok
15:48:59.0937 5908 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\WINDOWS\system32\drivers\NIS\1206000.01D\SYMEFA.SYS
15:48:59.0984 5908 SymEFA - ok
15:49:00.0078 5908 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
15:49:00.0078 5908 SymEvent - ok
15:49:00.0140 5908 SYMFW - ok
15:49:00.0203 5908 SYMIDS - ok
15:49:00.0296 5908 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\WINDOWS\system32\drivers\NIS\1206000.01D\Ironx86.SYS
15:49:00.0296 5908 SymIRON - ok
15:49:00.0406 5908 symlcbrd (b226f8a4d780acdf76145b58bb791d5b) C:\WINDOWS\system32\drivers\symlcbrd.sys
15:49:00.0406 5908 symlcbrd - ok
15:49:00.0453 5908 SYMNDIS - ok
15:49:00.0562 5908 SymSnap (b8fae6b464d9a2abeb0c80fb03ee5f96) C:\WINDOWS\system32\drivers\SymSnap.sys
15:49:00.0578 5908 SymSnap - ok
15:49:00.0671 5908 SYMTDI (dec35ccaf7a222df918306cd2fdfbd39) C:\WINDOWS\System32\Drivers\NIS\1206000.01D\SYMTDI.SYS
15:49:00.0671 5908 SYMTDI - ok
15:49:00.0734 5908 sym_hi - ok
15:49:00.0796 5908 sym_u3 - ok
15:49:00.0875 5908 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
15:49:00.0875 5908 sysaudio - ok
15:49:00.0968 5908 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
15:49:00.0984 5908 Tcpip - ok
15:49:01.0062 5908 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
15:49:01.0062 5908 TDPIPE - ok
15:49:01.0140 5908 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
15:49:01.0140 5908 TDTCP - ok
15:49:01.0218 5908 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
15:49:01.0218 5908 TermDD - ok
15:49:01.0343 5908 ti21sony (3106074a87bd5a16e2a3af6902bb6d91) C:\WINDOWS\system32\drivers\ti21sony.sys
15:49:01.0343 5908 ti21sony - ok
15:49:01.0421 5908 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
15:49:01.0421 5908 toshidpt - ok
15:49:01.0468 5908 TosIde - ok
15:49:01.0531 5908 tosporte (d626e0af9232d8799d3a449530f3c220) C:\WINDOWS\system32\DRIVERS\tosporte.sys
15:49:01.0531 5908 tosporte - ok
15:49:01.0593 5908 Tosrfbd (294675c8e4316302efe14b1a1219d942) C:\WINDOWS\system32\Drivers\tosrfbd.sys
15:49:01.0593 5908 Tosrfbd - ok
15:49:01.0718 5908 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
15:49:01.0718 5908 Tosrfbnp - ok
15:49:01.0781 5908 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
15:49:01.0781 5908 Tosrfcom - ok
15:49:01.0828 5908 Tosrfhid (31b0145c289d2b3e3e9948345caa7b6f) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
15:49:01.0843 5908 Tosrfhid - ok
15:49:01.0906 5908 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
15:49:01.0906 5908 tosrfnds - ok
15:49:01.0968 5908 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
15:49:01.0968 5908 TosRfSnd - ok
15:49:02.0062 5908 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
15:49:02.0062 5908 Tosrfusb - ok
15:49:02.0218 5908 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
15:49:02.0218 5908 Udfs - ok
15:49:02.0265 5908 ultra - ok
15:49:02.0359 5908 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
15:49:02.0359 5908 Update - ok
15:49:02.0421 5908 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
15:49:02.0421 5908 usbehci - ok
15:49:02.0531 5908 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
15:49:02.0546 5908 usbhub - ok
15:49:02.0593 5908 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
15:49:02.0593 5908 usbprint - ok
15:49:02.0718 5908 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
15:49:02.0718 5908 usbscan - ok
15:49:02.0796 5908 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
15:49:02.0796 5908 USBSTOR - ok
15:49:02.0859 5908 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
15:49:02.0859 5908 usbuhci - ok
15:49:02.0921 5908 usbvm321 (c7f4158ea3915f4194aee233ff8d4728) C:\WINDOWS\system32\Drivers\usbvm321.sys
15:49:02.0921 5908 usbvm321 - ok
15:49:03.0015 5908 V2IMount (b413e1467c92a65610166c932877e147) C:\WINDOWS\system32\drivers\V2IMount.sys
15:49:03.0015 5908 V2IMount - ok
15:49:03.0093 5908 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
15:49:03.0093 5908 VgaSave - ok
15:49:03.0171 5908 ViaIde - ok
15:49:03.0250 5908 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
15:49:03.0265 5908 VolSnap - ok
15:49:03.0406 5908 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys
15:49:03.0453 5908 w39n51 - ok
15:49:03.0515 5908 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
15:49:03.0531 5908 Wanarp - ok
15:49:03.0656 5908 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
15:49:03.0671 5908 Wdf01000 - ok
15:49:03.0703 5908 WDICA - ok
15:49:03.0828 5908 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
15:49:03.0828 5908 wdmaud - ok
15:49:03.0953 5908 winachsf (c1d5cbd8aa0d674da1ba1bb189696396) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
15:49:03.0984 5908 winachsf - ok
15:49:04.0093 5908 WmBEnum (bc3ecbcb40147bdae3ad2fd0b4b346d8) C:\WINDOWS\system32\drivers\WmBEnum.sys
15:49:04.0093 5908 WmBEnum - ok
15:49:04.0171 5908 WmFilter (19f9881d8b3484fedb605d0216876898) C:\WINDOWS\system32\drivers\WmFilter.sys
15:49:04.0171 5908 WmFilter - ok
15:49:04.0234 5908 WmVirHid (7a51545a6409a25eedbdbd97d019e8cc) C:\WINDOWS\system32\drivers\WmVirHid.sys
15:49:04.0234 5908 WmVirHid - ok
15:49:04.0312 5908 WmXlCore (1f083b3bc73017e60c3ca85cf4a70753) C:\WINDOWS\system32\drivers\WmXlCore.sys
15:49:04.0312 5908 WmXlCore - ok
15:49:04.0406 5908 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
15:49:04.0421 5908 WpdUsb - ok
15:49:04.0515 5908 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
15:49:04.0515 5908 WSTCODEC - ok
15:49:04.0609 5908 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
15:49:04.0609 5908 WudfPf - ok
15:49:04.0671 5908 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
15:49:04.0671 5908 WudfRd - ok
15:49:04.0718 5908 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
15:49:04.0953 5908 \Device\Harddisk0\DR0 - ok
15:49:04.0953 5908 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk2\DR6
15:49:04.0968 5908 \Device\Harddisk2\DR6 - ok
15:49:04.0968 5908 Boot (0x1200) (cfe057e260a45b7c8cc0874dcc3179ff) \Device\Harddisk0\DR0\Partition0
15:49:04.0968 5908 \Device\Harddisk0\DR0\Partition0 - ok
15:49:05.0000 5908 Boot (0x1200) (eb142777c4f384232b133eee9aadf225) \Device\Harddisk0\DR0\Partition1
15:49:05.0000 5908 \Device\Harddisk0\DR0\Partition1 - ok
15:49:05.0000 5908 Boot (0x1200) (353e315473892e1493a8338173e00c06) \Device\Harddisk2\DR6\Partition0
15:49:05.0000 5908 \Device\Harddisk2\DR6\Partition0 - ok
15:49:05.0000 5908 ============================================================
15:49:05.0000 5908 Scan finished
15:49:05.0000 5908 ============================================================
15:49:05.0015 5904 Detected object count: 0
15:49:05.0015 5904 Actual detected object count: 0

#14 misters

misters
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:07 AM

Posted 16 January 2012 - 04:55 AM

And here the GMER log, also ran on saturday:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-14 23:55:24
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e FUJITSU_MHV2160BT rev.00000013
Running: vj1lcdii.exe; Driver: C:\DOCUME~1\MRSHAR~1\LOCALS~1\Temp\kxlcypow.sys


---- System - GMER 1.0.15 ----

SSDT 8A71BE78 ZwConnectPort
SSDT 8A90D080 ZwLoadDriver

---- Kernel code sections - GMER 1.0.15 ----

? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8B86360, 0x21E0FD, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\program files\real\realplayer\update\realsched.exe[1560] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}

---- Devices - GMER 1.0.15 ----

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device ftdisk.sys (FT Disk Driver/Microsoft Corporation)

AttachedDevice SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

---- Files - GMER 1.0.15 ----

File C:\System Volume Information\EfaData\SYMEFA.DB-journal 512 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509 0 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\bckfg.tmp 863 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\cfg.ini 77 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\keywords 37 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\kwrd.dll 223744 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\L 0 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\L\rgkhsbin 138496 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\U 0 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\U\00000001.@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\U\80000000.@ 11264 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB58345$\1777109509\U\80000032.@ 77312 bytes
File C:\WINDOWS\$NtUninstallKB58345$\3504858996 0 bytes

---- EOF - GMER 1.0.15 ----

#15 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:07 AM

Posted 16 January 2012 - 11:00 AM

You are still infected

Read the preparation guide

http://www.bleepingcomputer.com/forums/topic34773.html

Create a new topic here

http://www.bleepingcomputer.com/forums/forum22.html

Good luck




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users