Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help with possible virus


  • Please log in to reply
10 replies to this topic

#1 mckeeba3

mckeeba3

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:08:32 PM

Posted 01 March 2012 - 10:14 AM

Hi all.

I'm operating Windows XP with Norton 360 Premiere Edition. I'm not entirely computer illiterate but certainly not fluent.

After about a 10 day trip I booted up the computer and found an error message in a balloon coming from my Malwarebytes icon in the bottom right of the screen.

The error is: Successfully blocked access to a potentially malicious website: 206.161.121.4
type: outgoing

The computer gets progressively slower and slower, and sometimes will freeze with a corrupted screen (looks like the old cga monitors...cyan, magenta, etc)

I purchased MalwareBytes Pro, ran a full scan and found some tracking cookies. I rebooted.
I ran Norton 360 full scan and found nothing.
I ran SUPERAntiSpyware Free and it discovered tracking cookies as well as svchost.exe - fake. I quarantined and removed the files, then rebooted.
I just started up the computer again and am getting the same message.
I started Glary Utilities Process Manager and noticed that I have 6 instances of svchost.exe running, and one of them is running at 554k. It also shows a file called runservice.exe that it notes is dangerous.

A little help?

Edited by hamluis, 01 March 2012 - 10:18 AM.
Moved from XP to Am i Infected.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,040 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:32 PM

Posted 01 March 2012 - 11:03 AM

Hello and welcome,let's take a further look.

Run RKill....


Download and Run RKill
  • Please download RKill by Grinler from one of the 4 links below and save it to your desktop.

    Link 1
    Link 2
    Link 3
    Link 4

  • Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
  • Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
  • A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
  • If nothing happens or if the tool does not run, please let me know in your next reply

Do not reboot your computer after running rkill as the malware programs will start again. Or if rebooting is required run it again.


If you continue having problems running rkill.com, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.

>>>
Please download TDSSKiller.zip and and extract it.
  • Run TDSSKiller.exe.
  • Click Start scan.
  • When it is finished the utility outputs a list of detected objects with description.
    The utility automatically selects an action (Cure or Delete) for malicious objects.
    The utility prompts the user to select an action to apply to suspicious objects (Skip, by default). Let the options as it is and click Continue
  • Let reboot if needed and tell me if the tool needed a reboot.
  • Click on Report and post the contents of the text file that will open.

    Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. The Log have a name like: TDSSKiller.Version_Date_Time_log.txt.

Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.

Please ask any needed questions,post logs and Let us know how the PC is running now.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 mckeeba3

mckeeba3
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:08:32 PM

Posted 01 March 2012 - 12:04 PM

Ran RKill...
Here is log:
"This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 03/01/2012 at 11:14:14.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:



Rkill completed on 03/01/2012 at 11:14:32. "

Downloaded and ran TDSSKILLER


Instead of Skip the default was Cure, which I clicked.

An error log appeared from WIndows:
Windows_Drive Not Ready
Exception Processing Message c00000a3 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c
Options to Continue/Retry/Cancel

I clicked Continue, got the same message and clicked cancel.

Was then prompted to reboot.

Here is the log:
"11:16:17.0140 19200 TDSS rootkit removing tool 2.7.17.0 Feb 29 2012 14:02:24
11:16:18.0187 19200 ============================================================
11:16:18.0187 19200 Current date / time: 2012/03/01 11:16:18.0187
11:16:18.0187 19200 SystemInfo:
11:16:18.0187 19200
11:16:18.0187 19200 OS Version: 5.1.2600 ServicePack: 3.0
11:16:18.0187 19200 Product type: Workstation
11:16:18.0187 19200 ComputerName: MONKEY
11:16:18.0187 19200 UserName: user
11:16:18.0187 19200 Windows directory: C:\WINDOWS
11:16:18.0187 19200 System windows directory: C:\WINDOWS
11:16:18.0187 19200 Processor architecture: Intel x86
11:16:18.0187 19200 Number of processors: 2
11:16:18.0187 19200 Page size: 0x1000
11:16:18.0187 19200 Boot type: Normal boot
11:16:18.0187 19200 ============================================================
11:16:19.0406 19200 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:16:19.0484 19200 \Device\Harddisk0\DR0:
11:16:19.0484 19200 MBR used
11:16:19.0484 19200 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A380D41
11:16:19.0578 19200 Initialize success
11:16:19.0578 19200 ============================================================
11:16:23.0140 18716 ============================================================
11:16:23.0140 18716 Scan started
11:16:23.0140 18716 Mode: Manual;
11:16:23.0140 18716 ============================================================
11:16:23.0406 18716 Abiosdsk - ok
11:16:23.0406 18716 abp480n5 - ok
11:16:23.0453 18716 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:16:23.0453 18716 ACPI - ok
11:16:23.0500 18716 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
11:16:23.0500 18716 ACPIEC - ok
11:16:23.0515 18716 adpu160m - ok
11:16:23.0531 18716 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
11:16:23.0562 18716 aec - ok
11:16:23.0625 18716 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
11:16:23.0625 18716 AFD - ok
11:16:23.0625 18716 Aha154x - ok
11:16:23.0640 18716 aic78u2 - ok
11:16:23.0656 18716 aic78xx - ok
11:16:23.0656 18716 AliIde - ok
11:16:23.0671 18716 amsint - ok
11:16:23.0703 18716 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
11:16:23.0718 18716 Arp1394 - ok
11:16:23.0734 18716 asc - ok
11:16:23.0734 18716 asc3350p - ok
11:16:23.0750 18716 asc3550 - ok
11:16:23.0781 18716 Aspi32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys
11:16:23.0781 18716 Aspi32 - ok
11:16:23.0921 18716 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:16:23.0937 18716 AsyncMac - ok
11:16:24.0000 18716 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
11:16:24.0000 18716 atapi - ok
11:16:24.0015 18716 Atdisk - ok
11:16:24.0062 18716 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:16:24.0078 18716 Atmarpc - ok
11:16:24.0140 18716 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
11:16:24.0140 18716 audstub - ok
11:16:24.0171 18716 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
11:16:24.0171 18716 Beep - ok
11:16:24.0312 18716 BHDrvx86 (e685ba3267c5a4ec4ce9e2b4a1481725) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20120215.001\BHDrvx86.sys
11:16:24.0328 18716 BHDrvx86 - ok
11:16:24.0468 18716 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
11:16:24.0468 18716 BVRPMPR5 - ok
11:16:24.0500 18716 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
11:16:24.0531 18716 cbidf2k - ok
11:16:24.0593 18716 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
11:16:24.0609 18716 CCDECODE - ok
11:16:24.0703 18716 ccSet_NST (2b2f9b4a08190334a9c36446b208bae9) C:\WINDOWS\system32\drivers\NST\0200000.010\ccSetx86.sys
11:16:24.0703 18716 ccSet_NST - ok
11:16:24.0812 18716 cd20xrnt - ok
11:16:24.0843 18716 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
11:16:24.0843 18716 Cdaudio - ok
11:16:24.0890 18716 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
11:16:24.0890 18716 Cdfs - ok
11:16:24.0953 18716 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:16:24.0953 18716 Cdrom - ok
11:16:24.0953 18716 Changer - ok
11:16:24.0968 18716 CmdIde - ok
11:16:24.0984 18716 Cpqarray - ok
11:16:24.0984 18716 dac2w2k - ok
11:16:25.0000 18716 dac960nt - ok
11:16:25.0031 18716 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
11:16:25.0031 18716 Disk - ok
11:16:25.0078 18716 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
11:16:25.0109 18716 dmboot - ok
11:16:25.0140 18716 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
11:16:25.0156 18716 dmio - ok
11:16:25.0281 18716 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
11:16:25.0281 18716 dmload - ok
11:16:25.0328 18716 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
11:16:25.0343 18716 DMusic - ok
11:16:25.0406 18716 dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
11:16:25.0421 18716 dot4 - ok
11:16:25.0484 18716 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
11:16:25.0515 18716 Dot4Print - ok
11:16:25.0578 18716 dot4usb (6ec3af6bb5b30e488a0c559921f012e1) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
11:16:25.0578 18716 dot4usb - ok
11:16:25.0578 18716 dpti2o - ok
11:16:25.0609 18716 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
11:16:25.0640 18716 drmkaud - ok
11:16:25.0796 18716 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
11:16:25.0812 18716 eeCtrl - ok
11:16:25.0890 18716 ENTECH (fd9fc82f134b1c91004ffc76a5ae494b) C:\WINDOWS\system32\DRIVERS\ENTECH.sys
11:16:25.0890 18716 ENTECH - ok
11:16:25.0906 18716 EraserUtilRebootDrv (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
11:16:25.0921 18716 EraserUtilRebootDrv - ok
11:16:25.0953 18716 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
11:16:25.0953 18716 Fastfat - ok
11:16:26.0015 18716 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
11:16:26.0046 18716 Fdc - ok
11:16:26.0093 18716 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
11:16:26.0093 18716 Fips - ok
11:16:26.0109 18716 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
11:16:26.0109 18716 Flpydisk - ok
11:16:26.0125 18716 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
11:16:26.0125 18716 FltMgr - ok
11:16:26.0218 18716 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:16:26.0218 18716 Fs_Rec - ok
11:16:26.0234 18716 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:16:26.0234 18716 Ftdisk - ok
11:16:26.0250 18716 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
11:16:26.0250 18716 GEARAspiWDM - ok
11:16:26.0265 18716 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:16:26.0296 18716 Gpc - ok
11:16:26.0328 18716 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
11:16:26.0359 18716 HDAudBus - ok
11:16:26.0406 18716 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:16:26.0437 18716 HidUsb - ok
11:16:26.0437 18716 hpn - ok
11:16:26.0484 18716 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
11:16:26.0500 18716 HTTP - ok
11:16:26.0562 18716 i2omgmt - ok
11:16:26.0562 18716 i2omp - ok
11:16:26.0578 18716 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:16:26.0609 18716 i8042prt - ok
11:16:26.0875 18716 IDSxpx86 (cfbc1ce72e5353d428704659199147b1) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120229.002\IDSxpx86.sys
11:16:26.0875 18716 IDSxpx86 - ok
11:16:26.0953 18716 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
11:16:26.0984 18716 Imapi - ok
11:16:27.0093 18716 ini910u - ok
11:16:27.0218 18716 IntcAzAudAddService (6f336c2d18ba1e7ce8d0f31541c87a1d) C:\WINDOWS\system32\drivers\RtkHDAud.sys
11:16:27.0281 18716 IntcAzAudAddService - ok
11:16:27.0281 18716 IntelIde - ok
11:16:27.0312 18716 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
11:16:27.0343 18716 intelppm - ok
11:16:27.0453 18716 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
11:16:27.0484 18716 Ip6Fw - ok
11:16:27.0546 18716 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:16:27.0562 18716 IpFilterDriver - ok
11:16:27.0609 18716 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:16:27.0609 18716 IpInIp - ok
11:16:27.0640 18716 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:16:27.0656 18716 IpNat - ok
11:16:27.0718 18716 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:16:27.0718 18716 IPSec - ok
11:16:27.0734 18716 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
11:16:27.0750 18716 IRENUM - ok
11:16:27.0781 18716 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:16:27.0812 18716 isapnp - ok
11:16:27.0843 18716 JGOGO (c995c0e8b4503fac38793bb0236ad246) C:\WINDOWS\system32\DRIVERS\JGOGO.sys
11:16:27.0875 18716 JGOGO - ok
11:16:27.0984 18716 jraid (f4a31e66a61c0783f51157519b03280b) C:\WINDOWS\system32\DRIVERS\jraid.sys
11:16:27.0984 18716 jraid - ok
11:16:28.0015 18716 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:16:28.0046 18716 Kbdclass - ok
11:16:28.0093 18716 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
11:16:28.0109 18716 kbdhid - ok
11:16:28.0187 18716 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
11:16:28.0187 18716 kmixer - ok
11:16:28.0250 18716 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
11:16:28.0281 18716 KSecDD - ok
11:16:28.0312 18716 L8042Kbd (0c6e346cde730cf1356dd69ad6e9bc42) C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
11:16:28.0343 18716 L8042Kbd - ok
11:16:28.0500 18716 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
11:16:28.0500 18716 Lavasoft Kernexplorer - ok
11:16:28.0625 18716 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
11:16:28.0625 18716 Lbd - ok
11:16:28.0687 18716 LBeepKE (9ffd1cf2a782f2560e78eec4b8b8689e) C:\WINDOWS\system32\Drivers\LBeepKE.sys
11:16:28.0687 18716 LBeepKE - ok
11:16:28.0703 18716 lbrtfdc - ok
11:16:28.0734 18716 LHidFilt (7f9c7b28cf1c859e1c42619eea946dc8) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
11:16:28.0765 18716 LHidFilt - ok
11:16:28.0796 18716 LMouFilt (ab33792a87285344f43b5ce23421bab0) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
11:16:28.0843 18716 LMouFilt - ok
11:16:28.0890 18716 LVUSBSta (9e9306063ecd8aa91b3fb76678d3cee2) C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys
11:16:28.0890 18716 LVUSBSta - ok
11:16:28.0953 18716 MagicTune (f627e9da4d3d8dc05a15b68944302f14) C:\WINDOWS\system32\drivers\MTiCtwl.sys
11:16:28.0953 18716 MagicTune - ok
11:16:28.0968 18716 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys
11:16:28.0984 18716 MBAMProtector - ok
11:16:29.0140 18716 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
11:16:29.0140 18716 mnmdd - ok
11:16:29.0203 18716 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
11:16:29.0234 18716 Modem - ok
11:16:29.0296 18716 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:16:29.0328 18716 Mouclass - ok
11:16:29.0359 18716 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:16:29.0359 18716 mouhid - ok
11:16:29.0390 18716 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
11:16:29.0390 18716 MountMgr - ok
11:16:29.0390 18716 mraid35x - ok
11:16:29.0500 18716 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
11:16:29.0500 18716 MREMP50 - ok
11:16:29.0515 18716 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
11:16:29.0515 18716 MRESP50 - ok
11:16:29.0625 18716 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:16:29.0640 18716 MRxDAV - ok
11:16:29.0687 18716 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:16:29.0687 18716 MRxSmb - ok
11:16:29.0734 18716 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
11:16:29.0734 18716 Msfs - ok
11:16:29.0750 18716 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:16:29.0765 18716 MSKSSRV - ok
11:16:29.0812 18716 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:16:29.0828 18716 MSPCLOCK - ok
11:16:29.0875 18716 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:16:29.0890 18716 MSPQM - ok
11:16:29.0953 18716 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:16:29.0953 18716 mssmbios - ok
11:16:30.0078 18716 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
11:16:30.0078 18716 MSTEE - ok
11:16:30.0109 18716 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
11:16:30.0109 18716 MTsensor - ok
11:16:30.0156 18716 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:16:30.0156 18716 Mup - ok
11:16:30.0203 18716 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
11:16:30.0234 18716 NABTSFEC - ok
11:16:30.0468 18716 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120229.034\NAVENG.SYS
11:16:30.0468 18716 NAVENG - ok
11:16:30.0515 18716 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120229.034\NAVEX15.SYS
11:16:30.0546 18716 NAVEX15 - ok
11:16:30.0671 18716 NCPro (f627e9da4d3d8dc05a15b68944302f14) C:\WINDOWS\system32\drivers\MTictwl.sys
11:16:30.0671 18716 NCPro - ok
11:16:30.0718 18716 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:16:30.0718 18716 NDIS - ok
11:16:30.0765 18716 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
11:16:30.0765 18716 NdisIP - ok
11:16:30.0796 18716 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:16:30.0796 18716 NdisTapi - ok
11:16:30.0828 18716 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:16:30.0828 18716 Ndisuio - ok
11:16:30.0843 18716 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:16:30.0843 18716 NdisWan - ok
11:16:30.0875 18716 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:16:30.0890 18716 NDProxy - ok
11:16:31.0062 18716 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:16:31.0062 18716 NetBIOS - ok
11:16:31.0093 18716 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:16:31.0125 18716 NetBT - ok
11:16:31.0187 18716 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
11:16:31.0187 18716 NIC1394 - ok
11:16:31.0203 18716 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:16:31.0203 18716 Npfs - ok
11:16:31.0250 18716 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:16:31.0265 18716 Ntfs - ok
11:16:31.0296 18716 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:16:31.0296 18716 Null - ok
11:16:31.0515 18716 nv (18c9b152da7bea76b2f9e4b6412e0aaf) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
11:16:31.0812 18716 nv - ok
11:16:31.0953 18716 nvata (c03e15101f6d9e82cd9b0e7d715f5de3) C:\WINDOWS\system32\DRIVERS\nvata.sys
11:16:31.0953 18716 nvata - ok
11:16:32.0000 18716 nvatabus (c03e15101f6d9e82cd9b0e7d715f5de3) C:\WINDOWS\system32\drivers\nvatabus.sys
11:16:32.0000 18716 nvatabus - ok
11:16:32.0031 18716 NVENETFD (7d275ecda4628318912f6c945d5cf963) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
11:16:32.0031 18716 NVENETFD - ok
11:16:32.0062 18716 nvnetbus (b64aacefad2be5bff5353fe681253c67) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
11:16:32.0062 18716 nvnetbus - ok
11:16:32.0093 18716 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:16:32.0125 18716 NwlnkFlt - ok
11:16:32.0171 18716 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:16:32.0171 18716 NwlnkFwd - ok
11:16:32.0203 18716 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
11:16:32.0203 18716 ohci1394 - ok
11:16:32.0328 18716 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
11:16:32.0343 18716 Parport - ok
11:16:32.0390 18716 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:16:32.0390 18716 PartMgr - ok
11:16:32.0453 18716 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
11:16:32.0453 18716 ParVdm - ok
11:16:32.0468 18716 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
11:16:32.0468 18716 PCI - ok
11:16:32.0468 18716 PCIDump - ok
11:16:32.0531 18716 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
11:16:32.0531 18716 PCIIde - ok
11:16:32.0562 18716 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
11:16:32.0562 18716 Pcmcia - ok
11:16:32.0562 18716 PDCOMP - ok
11:16:32.0578 18716 PDFRAME - ok
11:16:32.0578 18716 PDRELI - ok
11:16:32.0593 18716 PDRFRAME - ok
11:16:32.0593 18716 perc2 - ok
11:16:32.0609 18716 perc2hib - ok
11:16:32.0656 18716 PID_PEPI (0da6c5e0c8da6cebe52daacfe7ae9de6) C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
11:16:32.0703 18716 PID_PEPI - ok
11:16:32.0812 18716 pnarp (36fcac4fa28b462ca867742dea59b0d0) C:\WINDOWS\system32\DRIVERS\pnarp.sys
11:16:32.0812 18716 pnarp - ok
11:16:32.0843 18716 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:16:32.0875 18716 PptpMiniport - ok
11:16:32.0937 18716 prodrv05 (0525725ac452c03f1123915acdb02bb2) C:\WINDOWS\System32\drivers\prodrv05.sys
11:16:32.0968 18716 prodrv05 - ok
11:16:33.0015 18716 prohlp01 (1c04b1134349f6a8900e955e9eacb4a2) C:\WINDOWS\system32\drivers\prohlp01.sys
11:16:33.0015 18716 prohlp01 - ok
11:16:33.0062 18716 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:16:33.0078 18716 PSched - ok
11:16:33.0140 18716 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:16:33.0140 18716 Ptilink - ok
11:16:33.0171 18716 purendis (d8ac00388262b1a4878a7ee12f31d376) C:\WINDOWS\system32\DRIVERS\purendis.sys
11:16:33.0203 18716 purendis - ok
11:16:33.0312 18716 ql1080 - ok
11:16:33.0312 18716 Ql10wnt - ok
11:16:33.0328 18716 ql12160 - ok
11:16:33.0328 18716 ql1240 - ok
11:16:33.0328 18716 ql1280 - ok
11:16:33.0359 18716 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:16:33.0359 18716 RasAcd - ok
11:16:33.0390 18716 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:16:33.0390 18716 Rasl2tp - ok
11:16:33.0406 18716 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:16:33.0437 18716 RasPppoe - ok
11:16:33.0468 18716 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:16:33.0468 18716 Raspti - ok
11:16:33.0500 18716 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:16:33.0500 18716 Rdbss - ok
11:16:33.0531 18716 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:16:33.0531 18716 RDPCDD - ok
11:16:33.0578 18716 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
11:16:33.0578 18716 RDPWD - ok
11:16:33.0703 18716 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:16:33.0750 18716 redbook - ok
11:16:33.0750 18716 RimUsb - ok
11:16:33.0781 18716 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
11:16:33.0812 18716 RimVSerPort - ok
11:16:33.0843 18716 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
11:16:33.0843 18716 ROOTMODEM - ok
11:16:33.0937 18716 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
11:16:33.0937 18716 SASDIFSV - ok
11:16:33.0937 18716 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
11:16:33.0953 18716 SASKUTIL - ok
11:16:34.0109 18716 sbp2port (b244960e5a1db8e9d5d17086de37c1e4) C:\WINDOWS\system32\DRIVERS\sbp2port.sys
11:16:34.0109 18716 sbp2port - ok
11:16:34.0171 18716 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:16:34.0187 18716 Secdrv - ok
11:16:34.0250 18716 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:16:34.0250 18716 serenum - ok
11:16:34.0265 18716 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
11:16:34.0281 18716 Serial - ok
11:16:34.0312 18716 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys
11:16:34.0312 18716 Sfloppy - ok
11:16:34.0328 18716 Simbad - ok
11:16:34.0406 18716 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
11:16:34.0406 18716 SLIP - ok
11:16:34.0421 18716 Sparrow - ok
11:16:34.0421 18716 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:16:34.0468 18716 splitter - ok
11:16:34.0468 18716 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
11:16:34.0468 18716 sr - ok
11:16:34.0531 18716 SRTSP (83726cf02eced69138948083e06b6eac) C:\WINDOWS\System32\Drivers\N360\0502000.00D\SRTSP.SYS
11:16:34.0562 18716 SRTSP - ok
11:16:34.0734 18716 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\WINDOWS\system32\drivers\N360\0502000.00D\SRTSPX.SYS
11:16:34.0734 18716 SRTSPX - ok
11:16:34.0796 18716 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
11:16:34.0796 18716 Srv - ok
11:16:34.0843 18716 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
11:16:34.0843 18716 StillCam - ok
11:16:34.0890 18716 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
11:16:34.0906 18716 streamip - ok
11:16:34.0984 18716 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:16:35.0000 18716 swenum - ok
11:16:35.0031 18716 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:16:35.0031 18716 swmidi - ok
11:16:35.0171 18716 symc810 - ok
11:16:35.0187 18716 symc8xx - ok
11:16:35.0234 18716 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\WINDOWS\system32\drivers\N360\0502000.00D\SYMDS.SYS
11:16:35.0265 18716 SymDS - ok
11:16:35.0328 18716 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\WINDOWS\system32\drivers\N360\0502000.00D\SYMEFA.SYS
11:16:35.0343 18716 SymEFA - ok
11:16:35.0375 18716 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
11:16:35.0375 18716 SymEvent - ok
11:16:35.0421 18716 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\WINDOWS\system32\drivers\N360\0502000.00D\Ironx86.SYS
11:16:35.0421 18716 SymIRON - ok
11:16:35.0593 18716 SYMTDI (336cace58f0359d5cbb1ae6b8a2fb205) C:\WINDOWS\System32\Drivers\N360\0502000.00D\SYMTDI.SYS
11:16:35.0625 18716 SYMTDI - ok
11:16:35.0640 18716 sym_hi - ok
11:16:35.0640 18716 sym_u3 - ok
11:16:35.0687 18716 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:16:35.0687 18716 sysaudio - ok
11:16:35.0765 18716 Tcpip (4afb3b0919649f95c1964aa1fad27d73) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:16:35.0765 18716 Tcpip - ok
11:16:35.0796 18716 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:16:35.0812 18716 TDPIPE - ok
11:16:35.0843 18716 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:16:35.0843 18716 TDTCP - ok
11:16:36.0000 18716 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:16:36.0000 18716 TermDD - ok
11:16:36.0015 18716 TosIde - ok
11:16:36.0062 18716 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:16:36.0062 18716 Udfs - ok
11:16:36.0062 18716 ultra - ok
11:16:36.0156 18716 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:16:36.0171 18716 Update - ok
11:16:36.0234 18716 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys
11:16:36.0234 18716 USBAAPL - ok
11:16:36.0265 18716 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
11:16:36.0296 18716 usbaudio - ok
11:16:36.0296 18716 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:16:36.0343 18716 usbccgp - ok
11:16:36.0390 18716 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:16:36.0421 18716 usbehci - ok
11:16:36.0593 18716 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:16:36.0593 18716 usbhub - ok
11:16:36.0593 18716 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
11:16:36.0593 18716 usbohci - ok
11:16:36.0640 18716 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
11:16:36.0656 18716 usbprint - ok
11:16:36.0671 18716 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
11:16:36.0671 18716 usbscan - ok
11:16:36.0734 18716 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:16:36.0734 18716 usbstor - ok
11:16:36.0765 18716 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
11:16:36.0796 18716 VgaSave - ok
11:16:36.0812 18716 ViaIde - ok
11:16:36.0859 18716 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
11:16:36.0859 18716 VolSnap - ok
11:16:36.0890 18716 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:16:36.0921 18716 Wanarp - ok
11:16:37.0046 18716 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
11:16:37.0062 18716 Wdf01000 - ok
11:16:37.0187 18716 WDICA - ok
11:16:37.0218 18716 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
11:16:37.0234 18716 wdmaud - ok
11:16:37.0265 18716 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
11:16:37.0265 18716 WpdUsb - ok
11:16:37.0296 18716 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
11:16:37.0296 18716 WSTCODEC - ok
11:16:37.0343 18716 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:16:37.0343 18716 WudfPf - ok
11:16:37.0343 18716 MBR (0x1B8) (1f753b395539269a3484aecd505b79bd) \Device\Harddisk0\DR0
11:16:37.0406 18716 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
11:16:37.0406 18716 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
11:16:37.0406 18716 Boot (0x1200) (bc0bd12630f468fc90a0d6258a903d5a) \Device\Harddisk0\DR0\Partition0
11:16:37.0406 18716 \Device\Harddisk0\DR0\Partition0 - ok
11:16:37.0406 18716 ============================================================
11:16:37.0406 18716 Scan finished
11:16:37.0406 18716 ============================================================
11:16:37.0406 14004 Detected object count: 1
11:16:37.0406 14004 Actual detected object count: 1
11:19:53.0984 14004 \Device\Harddisk0\DR0\# - copied to quarantine
11:19:53.0984 14004 \Device\Harddisk0\DR0 - copied to quarantine
11:19:54.0000 14004 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
11:19:54.0015 14004 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
11:19:54.0015 14004 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
11:19:54.0015 14004 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine
11:19:54.0015 14004 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine
11:19:54.0031 14004 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
11:19:54.0031 14004 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
11:19:54.0031 14004 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
11:19:54.0031 14004 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
11:19:54.0046 14004 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
11:19:54.0046 14004 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
11:19:54.0046 14004 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
11:19:54.0093 14004 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
11:19:54.0093 14004 \Device\Harddisk0\DR0 - ok
11:21:54.0546 14004 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
11:25:05.0093 19944 Deinitialize success"


Upon reboot I updated MBAM and ran a quick scan.

Here is the log:
"Malwarebytes Anti-Malware (PRO) 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.01.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
user :: MONKEY [administrator]

Protection: Enabled

3/1/2012 11:43:50 AM
mbam-log-2012-03-01 (11-43-50).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 224092
Time elapsed: 11 minute(s), 29 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)"

I have not seen the error messages again yet.

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,040 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:32 PM

Posted 01 March 2012 - 12:09 PM

Good, run TDSS again like this.

  • Run TDSSKiller.exe.
  • Click on Change Parameters
  • Put a check in the box of Detect TDLFS file system
  • Click Start scan.
  • When it is finished the utility outputs a list of detected objects with description.
    The utility automatically selects an action (Cure or Delete) for malicious objects.
    The utility prompts the user to select an action to apply to suspicious objects (Skip, by default). Let the options as it is and click Continue
  • Let reboot if needed and tell me if the tool needed a reboot.
  • Click on Report and post the contents of the text file that will open.

    Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. The Log have a name like: TDSSKiller.Version_Date_Time_log.txt.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 mckeeba3

mckeeba3
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:08:32 PM

Posted 01 March 2012 - 01:39 PM

Ran TDSSKiller again with Detect TDLFS.
1 suspicious file
here is the log:
"13:35:12.0937 3936 TDSS rootkit removing tool 2.7.17.0 Feb 29 2012 14:02:24
13:35:14.0937 3936 ============================================================
13:35:14.0937 3936 Current date / time: 2012/03/01 13:35:14.0937
13:35:14.0937 3936 SystemInfo:
13:35:14.0937 3936
13:35:14.0937 3936 OS Version: 5.1.2600 ServicePack: 3.0
13:35:14.0937 3936 Product type: Workstation
13:35:14.0937 3936 ComputerName: MONKEY
13:35:14.0937 3936 UserName: user
13:35:14.0937 3936 Windows directory: C:\WINDOWS
13:35:14.0937 3936 System windows directory: C:\WINDOWS
13:35:14.0937 3936 Processor architecture: Intel x86
13:35:14.0937 3936 Number of processors: 2
13:35:14.0937 3936 Page size: 0x1000
13:35:14.0937 3936 Boot type: Normal boot
13:35:14.0937 3936 ============================================================
13:35:17.0734 3936 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:35:17.0750 3936 \Device\Harddisk0\DR0:
13:35:17.0765 3936 MBR used
13:35:17.0765 3936 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A380D41
13:35:17.0859 3936 Initialize success
13:35:17.0859 3936 ============================================================
13:36:02.0859 6032 ============================================================
13:36:02.0859 6032 Scan started
13:36:02.0859 6032 Mode: Manual; TDLFS;
13:36:02.0859 6032 ============================================================
13:36:03.0093 6032 Abiosdsk - ok
13:36:03.0093 6032 abp480n5 - ok
13:36:03.0140 6032 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
13:36:03.0140 6032 ACPI - ok
13:36:03.0203 6032 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
13:36:03.0203 6032 ACPIEC - ok
13:36:03.0203 6032 adpu160m - ok
13:36:03.0234 6032 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
13:36:03.0234 6032 aec - ok
13:36:03.0265 6032 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
13:36:03.0265 6032 AFD - ok
13:36:03.0265 6032 Aha154x - ok
13:36:03.0281 6032 aic78u2 - ok
13:36:03.0281 6032 aic78xx - ok
13:36:03.0296 6032 AliIde - ok
13:36:03.0312 6032 amsint - ok
13:36:03.0328 6032 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
13:36:03.0328 6032 Arp1394 - ok
13:36:03.0343 6032 asc - ok
13:36:03.0343 6032 asc3350p - ok
13:36:03.0359 6032 asc3550 - ok
13:36:03.0375 6032 Aspi32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys
13:36:03.0375 6032 Aspi32 - ok
13:36:03.0515 6032 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
13:36:03.0515 6032 AsyncMac - ok
13:36:03.0562 6032 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
13:36:03.0562 6032 atapi - ok
13:36:03.0578 6032 Atdisk - ok
13:36:03.0625 6032 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
13:36:03.0625 6032 Atmarpc - ok
13:36:03.0640 6032 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
13:36:03.0640 6032 audstub - ok
13:36:03.0671 6032 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
13:36:03.0671 6032 Beep - ok
13:36:03.0906 6032 BHDrvx86 (e685ba3267c5a4ec4ce9e2b4a1481725) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20120215.001\BHDrvx86.sys
13:36:03.0906 6032 BHDrvx86 - ok
13:36:04.0046 6032 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
13:36:04.0046 6032 BVRPMPR5 - ok
13:36:04.0078 6032 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
13:36:04.0078 6032 cbidf2k - ok
13:36:04.0109 6032 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
13:36:04.0140 6032 CCDECODE - ok
13:36:04.0187 6032 ccSet_NST (2b2f9b4a08190334a9c36446b208bae9) C:\WINDOWS\system32\drivers\NST\0200000.010\ccSetx86.sys
13:36:04.0187 6032 ccSet_NST - ok
13:36:04.0203 6032 cd20xrnt - ok
13:36:04.0218 6032 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
13:36:04.0218 6032 Cdaudio - ok
13:36:04.0265 6032 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
13:36:04.0265 6032 Cdfs - ok
13:36:04.0375 6032 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
13:36:04.0390 6032 Cdrom - ok
13:36:04.0390 6032 Changer - ok
13:36:04.0406 6032 CmdIde - ok
13:36:04.0406 6032 Cpqarray - ok
13:36:04.0421 6032 dac2w2k - ok
13:36:04.0421 6032 dac960nt - ok
13:36:04.0484 6032 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
13:36:04.0484 6032 Disk - ok
13:36:04.0562 6032 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
13:36:04.0562 6032 dmboot - ok
13:36:04.0609 6032 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
13:36:04.0640 6032 dmio - ok
13:36:04.0703 6032 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
13:36:04.0703 6032 dmload - ok
13:36:04.0765 6032 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
13:36:04.0796 6032 DMusic - ok
13:36:04.0828 6032 dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
13:36:04.0828 6032 dot4 - ok
13:36:04.0968 6032 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
13:36:04.0968 6032 Dot4Print - ok
13:36:05.0000 6032 dot4usb (6ec3af6bb5b30e488a0c559921f012e1) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
13:36:05.0000 6032 dot4usb - ok
13:36:05.0015 6032 dpti2o - ok
13:36:05.0031 6032 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
13:36:05.0031 6032 drmkaud - ok
13:36:05.0140 6032 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
13:36:05.0140 6032 eeCtrl - ok
13:36:05.0171 6032 ENTECH (fd9fc82f134b1c91004ffc76a5ae494b) C:\WINDOWS\system32\DRIVERS\ENTECH.sys
13:36:05.0171 6032 ENTECH - ok
13:36:05.0187 6032 EraserUtilRebootDrv (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
13:36:05.0187 6032 EraserUtilRebootDrv - ok
13:36:05.0359 6032 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
13:36:05.0359 6032 Fastfat - ok
13:36:05.0390 6032 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
13:36:05.0390 6032 Fdc - ok
13:36:05.0421 6032 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
13:36:05.0421 6032 Fips - ok
13:36:05.0453 6032 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
13:36:05.0453 6032 Flpydisk - ok
13:36:05.0484 6032 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
13:36:05.0484 6032 FltMgr - ok
13:36:05.0515 6032 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
13:36:05.0515 6032 Fs_Rec - ok
13:36:05.0593 6032 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
13:36:05.0593 6032 Ftdisk - ok
13:36:05.0640 6032 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
13:36:05.0640 6032 GEARAspiWDM - ok
13:36:05.0718 6032 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
13:36:05.0718 6032 Gpc - ok
13:36:05.0750 6032 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
13:36:05.0750 6032 HDAudBus - ok
13:36:05.0765 6032 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
13:36:05.0765 6032 HidUsb - ok
13:36:05.0781 6032 hpn - ok
13:36:05.0812 6032 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
13:36:05.0812 6032 HTTP - ok
13:36:05.0843 6032 i2omgmt - ok
13:36:05.0859 6032 i2omp - ok
13:36:05.0890 6032 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
13:36:05.0890 6032 i8042prt - ok
13:36:06.0125 6032 IDSxpx86 (cfbc1ce72e5353d428704659199147b1) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120229.002\IDSxpx86.sys
13:36:06.0125 6032 IDSxpx86 - ok
13:36:06.0218 6032 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
13:36:06.0218 6032 Imapi - ok
13:36:06.0234 6032 ini910u - ok
13:36:06.0421 6032 IntcAzAudAddService (6f336c2d18ba1e7ce8d0f31541c87a1d) C:\WINDOWS\system32\drivers\RtkHDAud.sys
13:36:06.0484 6032 IntcAzAudAddService - ok
13:36:06.0562 6032 IntelIde - ok
13:36:06.0609 6032 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
13:36:06.0609 6032 intelppm - ok
13:36:06.0640 6032 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
13:36:06.0640 6032 Ip6Fw - ok
13:36:06.0687 6032 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
13:36:06.0687 6032 IpFilterDriver - ok
13:36:06.0750 6032 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
13:36:06.0750 6032 IpInIp - ok
13:36:06.0765 6032 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
13:36:06.0781 6032 IpNat - ok
13:36:06.0843 6032 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
13:36:06.0843 6032 IPSec - ok
13:36:06.0875 6032 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
13:36:06.0875 6032 IRENUM - ok
13:36:06.0968 6032 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
13:36:06.0968 6032 isapnp - ok
13:36:07.0015 6032 JGOGO (c995c0e8b4503fac38793bb0236ad246) C:\WINDOWS\system32\DRIVERS\JGOGO.sys
13:36:07.0031 6032 JGOGO - ok
13:36:07.0046 6032 jraid (f4a31e66a61c0783f51157519b03280b) C:\WINDOWS\system32\DRIVERS\jraid.sys
13:36:07.0046 6032 jraid - ok
13:36:07.0078 6032 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
13:36:07.0078 6032 Kbdclass - ok
13:36:07.0093 6032 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
13:36:07.0093 6032 kbdhid - ok
13:36:07.0156 6032 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
13:36:07.0156 6032 kmixer - ok
13:36:07.0234 6032 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
13:36:07.0234 6032 KSecDD - ok
13:36:07.0296 6032 L8042Kbd (0c6e346cde730cf1356dd69ad6e9bc42) C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
13:36:07.0296 6032 L8042Kbd - ok
13:36:07.0437 6032 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
13:36:07.0437 6032 Lavasoft Kernexplorer - ok
13:36:07.0468 6032 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
13:36:07.0468 6032 Lbd - ok
13:36:07.0515 6032 LBeepKE (9ffd1cf2a782f2560e78eec4b8b8689e) C:\WINDOWS\system32\Drivers\LBeepKE.sys
13:36:07.0515 6032 LBeepKE - ok
13:36:07.0515 6032 lbrtfdc - ok
13:36:07.0562 6032 LHidFilt (7f9c7b28cf1c859e1c42619eea946dc8) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
13:36:07.0562 6032 LHidFilt - ok
13:36:07.0625 6032 LMouFilt (ab33792a87285344f43b5ce23421bab0) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
13:36:07.0640 6032 LMouFilt - ok
13:36:07.0734 6032 LVUSBSta (9e9306063ecd8aa91b3fb76678d3cee2) C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys
13:36:07.0734 6032 LVUSBSta - ok
13:36:07.0796 6032 MagicTune (f627e9da4d3d8dc05a15b68944302f14) C:\WINDOWS\system32\drivers\MTiCtwl.sys
13:36:07.0796 6032 MagicTune - ok
13:36:07.0843 6032 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys
13:36:07.0843 6032 MBAMProtector - ok
13:36:07.0890 6032 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
13:36:07.0890 6032 mnmdd - ok
13:36:07.0921 6032 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
13:36:07.0921 6032 Modem - ok
13:36:07.0953 6032 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
13:36:07.0953 6032 Mouclass - ok
13:36:08.0046 6032 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
13:36:08.0046 6032 mouhid - ok
13:36:08.0062 6032 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
13:36:08.0062 6032 MountMgr - ok
13:36:08.0062 6032 mraid35x - ok
13:36:08.0140 6032 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
13:36:08.0156 6032 MREMP50 - ok
13:36:08.0156 6032 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
13:36:08.0156 6032 MRESP50 - ok
13:36:08.0203 6032 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
13:36:08.0203 6032 MRxDAV - ok
13:36:08.0265 6032 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
13:36:08.0281 6032 MRxSmb - ok
13:36:08.0390 6032 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
13:36:08.0390 6032 Msfs - ok
13:36:08.0406 6032 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
13:36:08.0406 6032 MSKSSRV - ok
13:36:08.0437 6032 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
13:36:08.0437 6032 MSPCLOCK - ok
13:36:08.0437 6032 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
13:36:08.0437 6032 MSPQM - ok
13:36:08.0468 6032 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
13:36:08.0468 6032 mssmbios - ok
13:36:08.0500 6032 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
13:36:08.0500 6032 MSTEE - ok
13:36:08.0531 6032 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
13:36:08.0531 6032 MTsensor - ok
13:36:08.0578 6032 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
13:36:08.0578 6032 Mup - ok
13:36:08.0687 6032 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
13:36:08.0687 6032 NABTSFEC - ok
13:36:08.0906 6032 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120301.001\NAVENG.SYS
13:36:08.0906 6032 NAVENG - ok
13:36:08.0953 6032 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120301.001\NAVEX15.SYS
13:36:08.0968 6032 NAVEX15 - ok
13:36:09.0093 6032 NCPro (f627e9da4d3d8dc05a15b68944302f14) C:\WINDOWS\system32\drivers\MTictwl.sys
13:36:09.0093 6032 NCPro - ok
13:36:09.0187 6032 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
13:36:09.0187 6032 NDIS - ok
13:36:09.0250 6032 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
13:36:09.0250 6032 NdisIP - ok
13:36:09.0265 6032 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
13:36:09.0265 6032 NdisTapi - ok
13:36:09.0281 6032 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
13:36:09.0281 6032 Ndisuio - ok
13:36:09.0296 6032 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
13:36:09.0296 6032 NdisWan - ok
13:36:09.0328 6032 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
13:36:09.0328 6032 NDProxy - ok
13:36:09.0484 6032 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
13:36:09.0484 6032 NetBIOS - ok
13:36:09.0531 6032 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
13:36:09.0546 6032 NetBT - ok
13:36:09.0562 6032 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
13:36:09.0578 6032 NIC1394 - ok
13:36:09.0578 6032 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
13:36:09.0578 6032 Npfs - ok
13:36:09.0625 6032 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
13:36:09.0625 6032 Ntfs - ok
13:36:09.0687 6032 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
13:36:09.0687 6032 Null - ok
13:36:09.0953 6032 nv (18c9b152da7bea76b2f9e4b6412e0aaf) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
13:36:10.0140 6032 nv - ok
13:36:10.0312 6032 nvata (c03e15101f6d9e82cd9b0e7d715f5de3) C:\WINDOWS\system32\DRIVERS\nvata.sys
13:36:10.0312 6032 nvata - ok
13:36:10.0343 6032 nvatabus (c03e15101f6d9e82cd9b0e7d715f5de3) C:\WINDOWS\system32\drivers\nvatabus.sys
13:36:10.0343 6032 nvatabus - ok
13:36:10.0375 6032 NVENETFD (7d275ecda4628318912f6c945d5cf963) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
13:36:10.0375 6032 NVENETFD - ok
13:36:10.0406 6032 nvnetbus (b64aacefad2be5bff5353fe681253c67) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
13:36:10.0406 6032 nvnetbus - ok
13:36:10.0437 6032 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
13:36:10.0437 6032 NwlnkFlt - ok
13:36:10.0437 6032 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
13:36:10.0437 6032 NwlnkFwd - ok
13:36:10.0453 6032 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
13:36:10.0453 6032 ohci1394 - ok
13:36:10.0593 6032 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
13:36:10.0609 6032 Parport - ok
13:36:10.0656 6032 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
13:36:10.0656 6032 PartMgr - ok
13:36:10.0734 6032 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
13:36:10.0734 6032 ParVdm - ok
13:36:10.0750 6032 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
13:36:10.0750 6032 PCI - ok
13:36:10.0750 6032 PCIDump - ok
13:36:10.0828 6032 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
13:36:10.0828 6032 PCIIde - ok
13:36:10.0875 6032 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
13:36:10.0875 6032 Pcmcia - ok
13:36:10.0890 6032 PDCOMP - ok
13:36:10.0890 6032 PDFRAME - ok
13:36:10.0906 6032 PDRELI - ok
13:36:10.0906 6032 PDRFRAME - ok
13:36:10.0921 6032 perc2 - ok
13:36:10.0921 6032 perc2hib - ok
13:36:10.0968 6032 PID_PEPI (0da6c5e0c8da6cebe52daacfe7ae9de6) C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
13:36:10.0984 6032 PID_PEPI - ok
13:36:11.0125 6032 pnarp (36fcac4fa28b462ca867742dea59b0d0) C:\WINDOWS\system32\DRIVERS\pnarp.sys
13:36:11.0125 6032 pnarp - ok
13:36:11.0171 6032 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
13:36:11.0171 6032 PptpMiniport - ok
13:36:11.0187 6032 prodrv05 (0525725ac452c03f1123915acdb02bb2) C:\WINDOWS\System32\drivers\prodrv05.sys
13:36:11.0187 6032 prodrv05 - ok
13:36:11.0218 6032 prohlp01 (1c04b1134349f6a8900e955e9eacb4a2) C:\WINDOWS\system32\drivers\prohlp01.sys
13:36:11.0218 6032 prohlp01 - ok
13:36:11.0250 6032 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
13:36:11.0265 6032 PSched - ok
13:36:11.0281 6032 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
13:36:11.0281 6032 Ptilink - ok
13:36:11.0312 6032 purendis (d8ac00388262b1a4878a7ee12f31d376) C:\WINDOWS\system32\DRIVERS\purendis.sys
13:36:11.0312 6032 purendis - ok
13:36:11.0328 6032 ql1080 - ok
13:36:11.0328 6032 Ql10wnt - ok
13:36:11.0328 6032 ql12160 - ok
13:36:11.0343 6032 ql1240 - ok
13:36:11.0343 6032 ql1280 - ok
13:36:11.0359 6032 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
13:36:11.0359 6032 RasAcd - ok
13:36:11.0500 6032 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
13:36:11.0500 6032 Rasl2tp - ok
13:36:11.0515 6032 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
13:36:11.0531 6032 RasPppoe - ok
13:36:11.0546 6032 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
13:36:11.0546 6032 Raspti - ok
13:36:11.0578 6032 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
13:36:11.0578 6032 Rdbss - ok
13:36:11.0671 6032 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
13:36:11.0671 6032 RDPCDD - ok
13:36:11.0703 6032 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
13:36:11.0718 6032 RDPWD - ok
13:36:11.0718 6032 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
13:36:11.0718 6032 redbook - ok
13:36:11.0734 6032 RimUsb - ok
13:36:11.0765 6032 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
13:36:11.0765 6032 RimVSerPort - ok
13:36:11.0890 6032 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
13:36:11.0890 6032 ROOTMODEM - ok
13:36:12.0031 6032 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
13:36:12.0031 6032 SASDIFSV - ok
13:36:12.0046 6032 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
13:36:12.0046 6032 SASKUTIL - ok
13:36:12.0093 6032 sbp2port (b244960e5a1db8e9d5d17086de37c1e4) C:\WINDOWS\system32\DRIVERS\sbp2port.sys
13:36:12.0093 6032 sbp2port - ok
13:36:12.0140 6032 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
13:36:12.0140 6032 Secdrv - ok
13:36:12.0171 6032 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
13:36:12.0171 6032 serenum - ok
13:36:12.0296 6032 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
13:36:12.0296 6032 Serial - ok
13:36:12.0328 6032 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys
13:36:12.0328 6032 Sfloppy - ok
13:36:12.0343 6032 Simbad - ok
13:36:12.0406 6032 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
13:36:12.0406 6032 SLIP - ok
13:36:12.0406 6032 Sparrow - ok
13:36:12.0421 6032 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
13:36:12.0421 6032 splitter - ok
13:36:12.0421 6032 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
13:36:12.0437 6032 sr - ok
13:36:12.0484 6032 SRTSP (83726cf02eced69138948083e06b6eac) C:\WINDOWS\System32\Drivers\N360\0502000.00D\SRTSP.SYS
13:36:12.0500 6032 SRTSP - ok
13:36:12.0546 6032 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\WINDOWS\system32\drivers\N360\0502000.00D\SRTSPX.SYS
13:36:12.0546 6032 SRTSPX - ok
13:36:12.0609 6032 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
13:36:12.0625 6032 Srv - ok
13:36:12.0843 6032 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
13:36:12.0843 6032 StillCam - ok
13:36:12.0921 6032 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
13:36:12.0921 6032 streamip - ok
13:36:12.0968 6032 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
13:36:12.0968 6032 swenum - ok
13:36:13.0015 6032 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
13:36:13.0015 6032 swmidi - ok
13:36:13.0031 6032 symc810 - ok
13:36:13.0031 6032 symc8xx - ok
13:36:13.0093 6032 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\WINDOWS\system32\drivers\N360\0502000.00D\SYMDS.SYS
13:36:13.0109 6032 SymDS - ok
13:36:13.0265 6032 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\WINDOWS\system32\drivers\N360\0502000.00D\SYMEFA.SYS
13:36:13.0296 6032 SymEFA - ok
13:36:13.0343 6032 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
13:36:13.0343 6032 SymEvent - ok
13:36:13.0390 6032 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\WINDOWS\system32\drivers\N360\0502000.00D\Ironx86.SYS
13:36:13.0390 6032 SymIRON - ok
13:36:13.0468 6032 SYMTDI (336cace58f0359d5cbb1ae6b8a2fb205) C:\WINDOWS\System32\Drivers\N360\0502000.00D\SYMTDI.SYS
13:36:13.0468 6032 SYMTDI - ok
13:36:13.0593 6032 sym_hi - ok
13:36:13.0609 6032 sym_u3 - ok
13:36:13.0656 6032 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
13:36:13.0656 6032 sysaudio - ok
13:36:13.0703 6032 Tcpip (4afb3b0919649f95c1964aa1fad27d73) C:\WINDOWS\system32\DRIVERS\tcpip.sys
13:36:13.0703 6032 Tcpip - ok
13:36:13.0734 6032 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
13:36:13.0750 6032 TDPIPE - ok
13:36:13.0781 6032 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
13:36:13.0781 6032 TDTCP - ok
13:36:13.0828 6032 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
13:36:13.0828 6032 TermDD - ok
13:36:13.0843 6032 TosIde - ok
13:36:13.0890 6032 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
13:36:13.0890 6032 Udfs - ok
13:36:13.0890 6032 ultra - ok
13:36:13.0984 6032 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
13:36:13.0984 6032 Update - ok
13:36:14.0156 6032 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys
13:36:14.0156 6032 USBAAPL - ok
13:36:14.0187 6032 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
13:36:14.0187 6032 usbaudio - ok
13:36:14.0203 6032 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
13:36:14.0203 6032 usbccgp - ok
13:36:14.0234 6032 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
13:36:14.0234 6032 usbehci - ok
13:36:14.0250 6032 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
13:36:14.0250 6032 usbhub - ok
13:36:14.0296 6032 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
13:36:14.0296 6032 usbohci - ok
13:36:14.0359 6032 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
13:36:14.0359 6032 usbprint - ok
13:36:14.0375 6032 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
13:36:14.0375 6032 usbscan - ok
13:36:14.0390 6032 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
13:36:14.0406 6032 usbstor - ok
13:36:14.0421 6032 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
13:36:14.0421 6032 VgaSave - ok
13:36:14.0421 6032 ViaIde - ok
13:36:14.0468 6032 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
13:36:14.0468 6032 VolSnap - ok
13:36:14.0500 6032 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
13:36:14.0500 6032 Wanarp - ok
13:36:14.0625 6032 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
13:36:14.0640 6032 Wdf01000 - ok
13:36:14.0640 6032 WDICA - ok
13:36:14.0656 6032 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
13:36:14.0656 6032 wdmaud - ok
13:36:14.0703 6032 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
13:36:14.0703 6032 WpdUsb - ok
13:36:14.0750 6032 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
13:36:14.0750 6032 WSTCODEC - ok
13:36:14.0765 6032 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
13:36:14.0765 6032 WudfPf - ok
13:36:14.0781 6032 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
13:36:14.0937 6032 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
13:36:14.0937 6032 \Device\Harddisk0\DR0 - detected TDSS File System (1)
13:36:14.0937 6032 Boot (0x1200) (bc0bd12630f468fc90a0d6258a903d5a) \Device\Harddisk0\DR0\Partition0
13:36:14.0937 6032 \Device\Harddisk0\DR0\Partition0 - ok
13:36:14.0937 6032 ============================================================
13:36:14.0937 6032 Scan finished
13:36:14.0937 6032 ============================================================
13:36:14.0937 4872 Detected object count: 1
13:36:14.0937 4872 Actual detected object count: 1
13:36:39.0031 4872 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
13:36:39.0031 4872 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
"

#6 mckeeba3

mckeeba3
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:08:32 PM

Posted 02 March 2012 - 10:06 AM

Well, so far so good on day 2. If you don't have anything more, then thanks very much for the help!

#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,040 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:32 PM

Posted 02 March 2012 - 10:13 AM

OK, sorry for the delay.

Looks good,one more and then we can mop up if all's good.

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


NOTE: In some instances if no malware is found there will be no log produced.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 mckeeba3

mckeeba3
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:08:32 PM

Posted 03 March 2012 - 03:44 PM

I had to run the scan twice as I accidentally exited the scan. I've attached the two logs, showing 4 files in total. I have not deleted them but they are quarantined.

"C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\6.0\4\ab0c0c4-34f865d2 multiple threats deleted - quarantined
C:\Documents and Settings\user\desktop\mp3mymp3install.exe multiple threats deleted - quarantined
C:\Documents and Settings\user\My Documents\My Videos\videora-ipod-504-setup.exe Win32/OpenCandy application deleted - quarantined"

"C:\TDSSKiller_Quarantine\01.03.2012_11.16.18\mbr0000\tdlfs0000\tsk0005.dta a variant of Win32/Rootkit.Kryptik.JG trojan cleaned by deleting - quarantined"

#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,040 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:32 PM

Posted 03 March 2012 - 09:20 PM

Good,how is it running now?
You need to change your financial passwords on here,if you have any as these stole them.
I would change my email anyway.

Anything in quarantine is safely separated from the rest of your computer, it cannot run from there, so it can do no harm. So the general advice is to put the infected files in quarantine for a while you go about your normal computer activities. If everything continues to run properly after a reasonable period of time (say, about a week), then delete the files in quarantine permanently.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 mckeeba3

mckeeba3
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:08:32 PM

Posted 05 March 2012 - 12:44 PM

Things looked good for a day or so...

Now the computer locks up fairly often. The screen freezes and all the colors are like the old RGA monitors. I then have to reboot the computer.

Any ideas?

#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,040 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:32 PM

Posted 05 March 2012 - 08:28 PM

Lets get a deeper look and be sure.
Please go here....Preparation Guide ,do steps 6-9.

Create a DDS log and post it in the new topic explained in step 9 which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
If GMER won't run skip it and move on.

Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users