Jump to content

Malwarebytes intercepting svchost.exe pings


Recommended Posts

Download ComboFix from one of these locations:

Link 1

Link 2 If using this link, Right Click and select Save As.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
  • Double click on ComboFix.exe & follow the prompts.
    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.
    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RC1.png

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.

4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

Link to post
Share on other sites

  • Replies 68
  • Created
  • Last Reply

Top Posters In This Topic

ComboFix 12-01-05.04 - Eric 01/05/2012 19:57:24.4.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2047.978 [GMT -5:00]

Running from: c:\users\Eric\Desktop\ComboFix2.exe

AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2011-12-06 to 2012-01-06 )))))))))))))))))))))))))))))))

.

.

2012-01-06 01:09 . 2012-01-06 01:09 -------- d-----w- c:\users\Eric\AppData\Local\temp

2012-01-06 01:09 . 2012-01-06 01:09 -------- d-----w- c:\users\Rachel\AppData\Local\temp

2012-01-06 01:09 . 2012-01-06 01:09 -------- d-----w- c:\users\Joshua\AppData\Local\temp

2012-01-06 01:09 . 2012-01-06 01:09 -------- d-----w- c:\users\Heather\AppData\Local\temp

2012-01-06 01:09 . 2012-01-06 01:09 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-01-06 01:09 . 2012-01-06 01:09 -------- d-----w- c:\users\Cindy\AppData\Local\temp

2012-01-03 23:50 . 2011-11-30 07:21 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D84E2452-780C-419A-BE7A-5C6936A1C1B1}\mpengine.dll

2011-12-31 19:01 . 2012-01-04 01:15 -------- d-----w- C:\ComboFix

2011-12-31 16:47 . 2011-12-31 16:48 -------- d-----w- c:\users\Eric\AppData\Roaming\QuickScan

2011-12-31 14:51 . 2011-12-31 14:51 -------- d-----w- c:\users\Eric\AppData\Roaming\SUPERAntiSpyware.com

2011-12-31 14:51 . 2011-12-31 14:54 -------- d-----w- c:\program files\SUPERAntiSpyware

2011-12-31 14:51 . 2011-12-31 14:51 -------- d-----w- c:\programdata\SUPERAntiSpyware.com

2011-12-31 01:22 . 2011-12-31 01:22 -------- d-----w- c:\users\Eric\AppData\Roaming\Malwarebytes

2011-12-31 01:20 . 2011-12-31 01:20 -------- d-----w- c:\programdata\Malwarebytes

2011-12-31 01:20 . 2011-12-31 01:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-12-31 01:20 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-12-16 00:01 . 2011-12-16 00:01 -------- d-----w- c:\users\Eric\AppData\Local\DDMSettings

2011-12-15 05:29 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll

2011-12-15 05:28 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe

2011-12-15 05:28 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe

2011-12-15 05:28 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys

2011-12-15 05:28 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat

2011-12-15 05:28 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll

2011-12-15 05:28 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-08 00:01 . 2011-05-14 11:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-11-15 19:29 . 2010-06-23 03:16 222080 ------w- c:\windows\system32\MpSigStub.exe

2011-10-20 23:26 . 2011-10-20 23:26 94208 ----a-w- c:\windows\system32\dpl100.dll

2009-08-14 17:33 . 2009-08-14 17:33 13136 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll

2009-08-14 17:33 . 2009-08-14 17:33 70488 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2009-08-14 17:33 . 2009-08-14 17:33 91480 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2009-08-14 17:33 . 2009-08-14 17:33 20824 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll

2009-08-14 17:34 . 2009-08-14 17:34 206160 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2009-08-14 17:33 . 2009-08-14 17:33 31064 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2009-08-14 17:33 . 2009-08-14 17:33 40280 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2007-03-16 22:33 . 2007-03-16 22:33 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll

2007-03-16 22:33 . 2007-03-16 22:33 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll

2007-03-16 22:33 . 2007-03-16 22:33 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll

2009-08-14 16:50 . 2009-08-14 16:50 652640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2009-08-14 17:33 . 2009-08-14 17:33 23896 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-31 4616064]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]

"RtHDVCpl"="RtHDVCpl.exe" [2007-05-08 4374528]

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]

"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]

"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]

"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-12-12 312200]

"dlcqmon.exe"="c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-01-12 292336]

"DLCQCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 106496]

"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-13 86016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-13 8497696]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-13 81920]

"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-1-19 711472]

WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2011-8-2 610120]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]

@="FSFilter Activity Monitor"

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

2011-07-19 22:29 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

2007-10-18 16:34 5724184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

.

R2 0213611324512046mcinstcleanup;McAfee Application Installer Cleanup (0213611324512046);c:\windows\TEMP\021361~1.EXE [x]

S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

.

Contents of the 'Scheduled Tasks' folder

.

2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 23:33]

.

2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 23:33]

.

2011-12-31 c:\windows\Tasks\Norton Security Scan for Eric.job

- c:\progra~1\NORTON~1\NORTON~1\Engine\301~1.8\Nss.exe [2011-01-11 04:47]

.

2012-01-06 c:\windows\Tasks\User_Feed_Synchronization-{53CF0712-FC3E-411B-B93E-104173FC8404}.job

- c:\windows\system32\msfeedssync.exe [2011-05-19 22:10]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://mail.google.com/mail/#inbox

mStart Page = hxxp://www.alienware.com/mothership

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

LSP: c:\windows\system32\wpclsp.dll

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{BA707ACE-D004-4A79-905F-6E7B6E65E099}: NameServer = 8.8.8.8

FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\cydrn59k.default\

FF - prefs.js: browser.search.selectedEngine - Secure Search

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=

FF - Ext: Click to call with Skype: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: Norton Toolbar: {7BA52691-1876-45ce-9EE6-54BCB3B04BBC} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn

FF - Ext: McAfee SiteAdvisor: {4ED1F68A-5463-4931-9384-8FFF5ED91D92} - c:\program files\McAfee\SiteAdvisor

FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\DivXHTML5

FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\users\Eric\AppData\Roaming\Move Networks

FF - user.js: network.protocol-handler.warn-external.dnupdate - false

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-01-05 20:09

Windows 6.0.6002 Service Pack 2 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCQCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]

"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.3.6\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"=hex:51,66,7a,6c,4c,1d,38,12,8d,ec,f8,

7b,2b,25,27,06,e7,c4,bc,f0,98,15,0d,de

"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,

0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70

"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,

02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7

"{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}"=hex:51,66,7a,6c,4c,1d,38,12,60,d8,39,

64,cd,04,79,07,f5,b7,d6,9a,c1,81,e0,1c

"{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40,

69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,

72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,

aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83

"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,

b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,

b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:1f,3a,9c,78,ed,c9,cc,01

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

"MSCurrentCountry"=dword:000000b5

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'Explorer.exe'(4452)

c:\windows\system32\btmmhook.dll

c:\windows\system32\fdproxy.dll

.

Completion time: 2012-01-05 20:14:05

ComboFix-quarantined-files.txt 2012-01-06 01:13

ComboFix2.txt 2012-01-05 00:03

ComboFix3.txt 2012-01-04 01:36

.

Pre-Run: 37,107,855,360 bytes free

Post-Run: 38,362,492,928 bytes free

.

- - End Of File - - 9F4072FC539C21FC276514DC0764D771

Link to post
Share on other sites

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:

Click Start > Run type Notepad click OK.

This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

FireFox::
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\cydrn59k.default\
FF - Ext: Click to call with Skype: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\users\Eric\AppData\Roaming\Move Networks

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;

2.Click Save As... Change the directory to your desktop;

3.Change the Save as type to "All Files";

4.Type in the file name: CFScript

5.Click Save ...

CFScriptB-4.gif

Drag CFScript.txt into ComboFix.exe

Then post the results log using Copy / Paste

Also please describe how your computer behaves at the moment.

Link to post
Share on other sites

ComboFix 12-01-06.03 - Eric 01/06/2012 18:28:05.5.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2047.700 [GMT -5:00]

Running from: c:\users\Eric\Desktop\ComboFix2.exe

AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2011-12-06 to 2012-01-06 )))))))))))))))))))))))))))))))

.

.

2012-01-06 23:40 . 2012-01-06 23:40 -------- d-----w- c:\users\Eric\AppData\Local\temp

2012-01-06 23:40 . 2012-01-06 23:40 -------- d-----w- c:\users\Rachel\AppData\Local\temp

2012-01-06 23:40 . 2012-01-06 23:40 -------- d-----w- c:\users\Joshua\AppData\Local\temp

2012-01-06 23:40 . 2012-01-06 23:40 -------- d-----w- c:\users\Heather\AppData\Local\temp

2012-01-06 23:40 . 2012-01-06 23:40 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-01-06 23:40 . 2012-01-06 23:40 -------- d-----w- c:\users\Cindy\AppData\Local\temp

2012-01-06 23:03 . 2012-01-06 23:03 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BA325CBF-E43A-48A2-B746-ED17AC54B987}\offreg.dll

2012-01-06 23:03 . 2011-11-30 07:21 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BA325CBF-E43A-48A2-B746-ED17AC54B987}\mpengine.dll

2012-01-06 22:42 . 2011-12-21 07:24 121816 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll

2011-12-31 19:01 . 2012-01-04 01:15 -------- d-----w- C:\ComboFix

2011-12-31 16:47 . 2011-12-31 16:48 -------- d-----w- c:\users\Eric\AppData\Roaming\QuickScan

2011-12-31 14:51 . 2011-12-31 14:51 -------- d-----w- c:\users\Eric\AppData\Roaming\SUPERAntiSpyware.com

2011-12-31 14:51 . 2011-12-31 14:54 -------- d-----w- c:\program files\SUPERAntiSpyware

2011-12-31 14:51 . 2011-12-31 14:51 -------- d-----w- c:\programdata\SUPERAntiSpyware.com

2011-12-31 01:22 . 2011-12-31 01:22 -------- d-----w- c:\users\Eric\AppData\Roaming\Malwarebytes

2011-12-31 01:20 . 2011-12-31 01:20 -------- d-----w- c:\programdata\Malwarebytes

2011-12-31 01:20 . 2011-12-31 01:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-12-31 01:20 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-12-16 00:01 . 2011-12-16 00:01 -------- d-----w- c:\users\Eric\AppData\Local\DDMSettings

2011-12-15 05:29 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll

2011-12-15 05:28 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe

2011-12-15 05:28 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe

2011-12-15 05:28 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys

2011-12-15 05:28 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat

2011-12-15 05:28 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll

2011-12-15 05:28 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-08 00:01 . 2011-05-14 11:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-11-15 19:29 . 2010-06-23 03:16 222080 ------w- c:\windows\system32\MpSigStub.exe

2011-10-20 23:26 . 2011-10-20 23:26 94208 ----a-w- c:\windows\system32\dpl100.dll

2009-08-14 17:33 . 2009-08-14 17:33 13136 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll

2009-08-14 17:33 . 2009-08-14 17:33 70488 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2009-08-14 17:33 . 2009-08-14 17:33 91480 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2009-08-14 17:33 . 2009-08-14 17:33 20824 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll

2009-08-14 17:34 . 2009-08-14 17:34 206160 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2009-08-14 17:33 . 2009-08-14 17:33 31064 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2009-08-14 17:33 . 2009-08-14 17:33 40280 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2007-03-16 22:33 . 2007-03-16 22:33 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll

2007-03-16 22:33 . 2007-03-16 22:33 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll

2007-03-16 22:33 . 2007-03-16 22:33 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll

2009-08-14 16:50 . 2009-08-14 16:50 652640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2009-08-14 17:33 . 2009-08-14 17:33 23896 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

2011-12-21 07:24 . 2012-01-06 22:42 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-31 4616064]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]

"RtHDVCpl"="RtHDVCpl.exe" [2007-05-08 4374528]

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]

"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]

"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]

"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-12-12 312200]

"dlcqmon.exe"="c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-01-12 292336]

"DLCQCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 106496]

"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-13 86016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-13 8497696]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-13 81920]

"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-1-19 711472]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]

@="FSFilter Activity Monitor"

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

2011-07-19 22:29 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

2007-10-18 16:34 5724184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

.

R2 0213611324512046mcinstcleanup;McAfee Application Installer Cleanup (0213611324512046);c:\windows\TEMP\021361~1.EXE [x]

S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

.

Contents of the 'Scheduled Tasks' folder

.

2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 23:33]

.

2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 23:33]

.

2011-12-31 c:\windows\Tasks\Norton Security Scan for Eric.job

- c:\progra~1\NORTON~1\NORTON~1\Engine\301~1.8\Nss.exe [2011-01-11 04:47]

.

2012-01-06 c:\windows\Tasks\User_Feed_Synchronization-{53CF0712-FC3E-411B-B93E-104173FC8404}.job

- c:\windows\system32\msfeedssync.exe [2011-05-19 22:10]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://mail.google.com/mail/#inbox

mStart Page = hxxp://www.alienware.com/mothership

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

LSP: c:\windows\system32\wpclsp.dll

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{BA707ACE-D004-4A79-905F-6E7B6E65E099}: NameServer = 8.8.8.8

FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\cydrn59k.default\

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-01-06 18:40

Windows 6.0.6002 Service Pack 2 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCQCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]

"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.3.6\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"=hex:51,66,7a,6c,4c,1d,38,12,8d,ec,f8,

7b,2b,25,27,06,e7,c4,bc,f0,98,15,0d,de

"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,

0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70

"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,

02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7

"{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}"=hex:51,66,7a,6c,4c,1d,38,12,60,d8,39,

64,cd,04,79,07,f5,b7,d6,9a,c1,81,e0,1c

"{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40,

69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,

72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,

aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83

"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,

b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,

b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:1f,3a,9c,78,ed,c9,cc,01

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

"MSCurrentCountry"=dword:000000b5

.

Completion time: 2012-01-06 18:44:43

ComboFix-quarantined-files.txt 2012-01-06 23:44

ComboFix2.txt 2012-01-06 01:14

ComboFix3.txt 2012-01-05 00:03

ComboFix4.txt 2012-01-04 01:36

.

Pre-Run: 37,054,160,896 bytes free

Post-Run: 37,089,075,200 bytes free

.

- - End Of File - - 9FBB07818A3E498FE2B44431FD8110C8

Link to post
Share on other sites

Its almost like I am getting clean and then reinfected by somewhere I go. Being honest though that I don't think I am going anywhere questionable. I could probably make a list of where I have gone but its no more than 5-10 sites. A couple of forums which I guess are the most likely vulnerable place (www.jeepforum.com and www.pirate4x4.com) compared to somewhere like Google, NYT, CNN, etc.

Link to post
Share on other sites

aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software

Run date: 2012-01-08 18:55:17

-----------------------------

18:55:17.438 OS Version: Windows 6.0.6002 Service Pack 2

18:55:17.438 Number of processors: 2 586 0xF06

18:55:17.440 ComputerName: ALIENWARE UserName: Eric

18:55:26.341 Initialize success

18:55:39.729 AVAST engine download error: 0

18:55:43.886 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-1

18:55:43.888 Disk 0 Vendor: ST9160823AS 3.ADC Size: 152627MB BusType: 3

18:55:43.899 Disk 0 MBR read successfully

18:55:43.901 Disk 0 MBR scan

18:55:43.903 Disk 0 TDL4@MBR code has been found

18:55:43.905 Disk 0 MBR hidden

18:55:43.908 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 145196 MB offset 63

18:55:43.933 Disk 0 Partition 2 00 12 Compaq diag NTFS 7427 MB offset 297363456

18:55:43.936 Disk 0 MBR [TDL4] **ROOTKIT**

18:55:43.939 Disk 0 trace - called modules:

18:55:43.942 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8609149f]<<

18:55:43.945 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8584f1c0]

18:55:43.949 3 CLASSPNP.SYS[87fa78b3] -> nt!IofCallDriver -> [0x84e09918]

18:55:43.953 5 acpi.sys[8069d6bc] -> nt!IofCallDriver -> [0x8448f390]

18:55:43.958 \Driver\atapi[0x86018508] -> IRP_MJ_CREATE -> 0x8609149f

18:55:43.962 Scan finished successfully

18:55:55.622 Disk 0 MBR has been saved successfully to "C:\Users\Eric\Documents\MBR.dat"

18:55:55.627 The log file has been saved successfully to "C:\Users\Eric\Documents\aswMBR.txt"

18:56:16.954 Disk 0 MBR has been saved successfully to "C:\Users\Eric\Desktop\MBR.dat"

18:56:16.959 The log file has been saved successfully to "C:\Users\Eric\Desktop\aswMBR.txt"

Link to post
Share on other sites

Ok, ran it again and hit fix this time. Log posted below. Seems to indicate it fixed something. Promptly rebooted after running as instructed by log. Interesting that happened on the reboot was that Norton triggered a message that it had auto removed "Trojan.gen.". Hadn't seen that before. Haven't seen the MBAM intercept messages so far, although that has happened before. I guess we will see. Here's the aswMBR log:

aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software

Run date: 2012-01-08 19:12:29

-----------------------------

19:12:29.985 OS Version: Windows 6.0.6002 Service Pack 2

19:12:29.985 Number of processors: 2 586 0xF06

19:12:29.987 ComputerName: ALIENWARE UserName: Eric

19:12:30.969 Initialize success

19:12:37.379 AVAST engine download error: 0

19:12:44.889 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-1

19:12:44.892 Disk 0 Vendor: ST9160823AS 3.ADC Size: 152627MB BusType: 3

19:12:44.929 Disk 0 MBR read successfully

19:12:44.931 Disk 0 MBR scan

19:12:44.933 Disk 0 TDL4@MBR code has been found

19:12:44.935 Disk 0 MBR hidden

19:12:44.979 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 145196 MB offset 63

19:12:45.003 Disk 0 Partition 2 00 12 Compaq diag NTFS 7427 MB offset 297363456

19:12:45.006 Disk 0 MBR [TDL4] **ROOTKIT**

19:12:45.010 Disk 0 trace - called modules:

19:12:45.014 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8609149f]<<

19:12:45.018 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8584f1c0]

19:12:45.021 3 CLASSPNP.SYS[87fa78b3] -> nt!IofCallDriver -> [0x84e09918]

19:12:45.026 5 acpi.sys[8069d6bc] -> nt!IofCallDriver -> [0x8448f390]

19:12:45.029 \Driver\atapi[0x86018508] -> IRP_MJ_CREATE -> 0x8609149f

19:12:45.034 Scan finished successfully

19:12:47.643 Disk 0 MBR read successfully

19:12:47.647 Disk 0 TDL4@MBR code has been found

19:12:47.652 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 145196 MB offset 63

19:12:47.677 Disk 0 Partition 2 00 12 Compaq diag NTFS 7427 MB offset 297363456

19:12:47.682 Disk 0 fixing MBR ...

19:12:47.686 Disk 0 MBR restored successfully

19:12:47.690 Verifying disinfection

19:12:59.805 Infection fixed successfully - please reboot ASAP

19:13:08.616 Disk 0 MBR has been saved successfully to "C:\Users\Eric\Desktop\MBR.dat"

19:13:08.621 The log file has been saved successfully to "C:\Users\Eric\Desktop\aswMBR.txt"

Link to post
Share on other sites

19:12:45.006 Disk 0 MBR [TDL4] **ROOTKIT**

I think it's still there.

Download TDSSKiller from here and save it to your Desktop.

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.

  1. Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
    tdss_1.jpg
  2. Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
    tdss_2.jpg
  3. Click the Start Scan button.
    tdss_3.jpg
  4. If a suspicious object is detected, the default action will be Skip, click on Continue.
    tdss_4.jpg
  5. If malicious objects are found, they will show in the Scan results and offer three (3) options.
  6. Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
    tdss_5.jpg

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.

Link to post
Share on other sites

OK. Ran TDSSKiller and got 3 suspicious items but zero malicious so just clicked through continue. Log posted below. Then I went off script a little. I should have asked you before. Apologies. Was thinking about your comment about TDL4 still showing up on the last aswMBR scan. But that was before I clicked "Fix". So I wondered if it would show up again if I ran the scan again so I did. Few things happened this time. First, the scan it did seemed much more detailed and I didn't think I did anything different in launching it. You will see this in the time stamps on the log that I'll post below. Second, during the scan Norton gave me a message on auto removal of "Trojan.gen.2". Lastly, the aswMBR scan seems to have highlighted different infections this time. Its almost like there were multiple layers and we stripped one off but have uncovered other layers. It only gives me the "FixMBR" option and I wasn't going to click that without asking you. Again sorry for not asking before running that scan.

Here's the TDSSKiller log:

19:31:58.0316 4560 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16

19:32:00.0305 4560 ============================================================

19:32:00.0306 4560 Current date / time: 2012/01/08 19:32:00.0305

19:32:00.0306 4560 SystemInfo:

19:32:00.0306 4560

19:32:00.0306 4560 OS Version: 6.0.6002 ServicePack: 2.0

19:32:00.0306 4560 Product type: Workstation

19:32:00.0306 4560 ComputerName: ALIENWARE

19:32:00.0306 4560 UserName: Eric

19:32:00.0306 4560 Windows directory: C:\Windows

19:32:00.0306 4560 System windows directory: C:\Windows

19:32:00.0306 4560 Processor architecture: Intel x86

19:32:00.0306 4560 Number of processors: 2

19:32:00.0306 4560 Page size: 0x1000

19:32:00.0306 4560 Boot type: Normal boot

19:32:00.0306 4560 ============================================================

19:32:02.0868 4560 Initialize success

19:33:22.0919 4144 ============================================================

19:33:22.0919 4144 Scan started

19:33:22.0919 4144 Mode: Manual; SigCheck; TDLFS;

19:33:22.0919 4144 ============================================================

19:33:25.0357 4144 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys

19:33:25.0592 4144 ACPI - ok

19:33:26.0140 4144 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys

19:33:26.0593 4144 adp94xx - ok

19:33:27.0046 4144 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys

19:33:27.0189 4144 adpahci - ok

19:33:27.0955 4144 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys

19:33:28.0378 4144 adpu160m - ok

19:33:28.0784 4144 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys

19:33:29.0284 4144 adpu320 - ok

19:33:29.0675 4144 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys

19:33:30.0050 4144 AFD - ok

19:33:30.0440 4144 AgereSoftModem (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys

19:33:30.0847 4144 AgereSoftModem - ok

19:33:31.0159 4144 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys

19:33:31.0222 4144 agp440 - ok

19:33:31.0659 4144 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys

19:33:32.0050 4144 aic78xx - ok

19:33:32.0301 4144 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys

19:33:32.0410 4144 aliide - ok

19:33:32.0457 4144 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys

19:33:32.0520 4144 amdagp - ok

19:33:32.0754 4144 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys

19:33:33.0035 4144 amdide - ok

19:33:33.0395 4144 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys

19:33:33.0582 4144 AmdK7 - ok

19:33:33.0926 4144 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys

19:33:34.0113 4144 AmdK8 - ok

19:33:34.0660 4144 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys

19:33:34.0816 4144 arc - ok

19:33:34.0941 4144 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys

19:33:35.0004 4144 arcsas - ok

19:33:35.0066 4144 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys

19:33:35.0145 4144 AsyncMac - ok

19:33:35.0223 4144 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys

19:33:35.0285 4144 atapi - ok

19:33:35.0582 4144 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys

19:33:35.0707 4144 Beep - ok

19:33:36.0098 4144 BHDrvx86 (76154fa6a742c613b44bb636b1a7c057) C:\Windows\System32\Drivers\N360\0308030.006\BHDrvx86.sys

19:33:36.0207 4144 BHDrvx86 - ok

19:33:36.0316 4144 blbdrive - ok

19:33:36.0473 4144 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys

19:33:36.0551 4144 bowser - ok

19:33:36.0832 4144 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys

19:33:36.0926 4144 BrFiltLo - ok

19:33:37.0223 4144 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys

19:33:37.0316 4144 BrFiltUp - ok

19:33:37.0785 4144 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys

19:33:37.0988 4144 Brserid - ok

19:33:38.0223 4144 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys

19:33:38.0598 4144 BrSerWdm - ok

19:33:38.0723 4144 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys

19:33:39.0129 4144 BrUsbMdm - ok

19:33:39.0457 4144 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys

19:33:39.0535 4144 BrUsbSer - ok

19:33:40.0051 4144 BthEnum (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys

19:33:40.0348 4144 BthEnum - ok

19:33:40.0879 4144 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys

19:33:41.0035 4144 BTHMODEM - ok

19:33:41.0270 4144 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys

19:33:41.0426 4144 BthPan - ok

19:33:41.0801 4144 BTHPORT (611ff3f2f095c8d4a6d4cfd9dcc09793) C:\Windows\system32\Drivers\BTHport.sys

19:33:42.0535 4144 BTHPORT - ok

19:33:42.0910 4144 BTHUSB (d330803eab2a15caec7f011f1d4cb30e) C:\Windows\system32\Drivers\BTHUSB.sys

19:33:43.0035 4144 BTHUSB - ok

19:33:43.0332 4144 btwaudio (c879f83c1f1fc1f8c7d568cb56cfc3ab) C:\Windows\system32\drivers\btwaudio.sys

19:33:43.0676 4144 btwaudio - ok

19:33:44.0020 4144 btwavdt (032d5459bb8af9266ce95b18f9cd59b2) C:\Windows\system32\drivers\btwavdt.sys

19:33:44.0191 4144 btwavdt - ok

19:33:44.0426 4144 btwrchid (0f3408c5934752db8316df09fccd7b33) C:\Windows\system32\DRIVERS\btwrchid.sys

19:33:44.0566 4144 btwrchid - ok

19:33:44.0895 4144 Cam5603D (232d5686aa08e8acd3c3203c86559ace) C:\Windows\system32\Drivers\BisonCam.sys

19:33:45.0035 4144 Cam5603D - ok

19:33:45.0224 4144 catchme - ok

19:33:45.0536 4144 ccHP (3182b846490dc4d71fabd4a8cb6b73ea) C:\Windows\System32\Drivers\N360\0308030.006\ccHPx86.sys

19:33:45.0817 4144 ccHP - ok

19:33:46.0114 4144 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys

19:33:46.0224 4144 cdfs - ok

19:33:46.0380 4144 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys

19:33:46.0552 4144 cdrom - ok

19:33:46.0958 4144 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys

19:33:47.0099 4144 circlass - ok

19:33:47.0192 4144 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys

19:33:47.0239 4144 CLFS - ok

19:33:47.0380 4144 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys

19:33:47.0521 4144 CmBatt - ok

19:33:47.0708 4144 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys

19:33:47.0802 4144 cmdide - ok

19:33:48.0350 4144 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys

19:33:48.0428 4144 Compbatt - ok

19:33:48.0818 4144 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys

19:33:48.0897 4144 crcdisk - ok

19:33:49.0131 4144 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys

19:33:49.0272 4144 Crusoe - ok

19:33:49.0537 4144 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys

19:33:49.0662 4144 DfsC - ok

19:33:49.0897 4144 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys

19:33:49.0990 4144 disk - ok

19:33:50.0303 4144 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys

19:33:50.0412 4144 drmkaud - ok

19:33:50.0740 4144 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys

19:33:50.0865 4144 DXGKrnl - ok

19:33:51.0147 4144 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys

19:33:51.0256 4144 E1G60 - ok

19:33:51.0334 4144 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys

19:33:51.0412 4144 Ecache - ok

19:33:51.0647 4144 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys

19:33:52.0006 4144 eeCtrl - ok

19:33:52.0490 4144 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys

19:33:52.0615 4144 elxstor - ok

19:33:52.0740 4144 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys

19:33:52.0787 4144 EraserUtilRebootDrv - ok

19:33:53.0147 4144 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys

19:33:53.0256 4144 exfat - ok

19:33:53.0600 4144 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys

19:33:53.0709 4144 fastfat - ok

19:33:54.0209 4144 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys

19:33:54.0443 4144 fdc - ok

19:33:54.0725 4144 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys

19:33:54.0787 4144 FileInfo - ok

19:33:55.0178 4144 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys

19:33:55.0303 4144 Filetrace - ok

19:33:55.0412 4144 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys

19:33:55.0490 4144 flpydisk - ok

19:33:55.0631 4144 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys

19:33:55.0709 4144 FltMgr - ok

19:33:56.0350 4144 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys

19:33:56.0459 4144 Fs_Rec - ok

19:33:56.0615 4144 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys

19:33:56.0693 4144 gagp30kx - ok

19:33:57.0225 4144 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys

19:33:57.0303 4144 GEARAspiWDM - ok

19:33:57.0725 4144 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys

19:33:57.0850 4144 HdAudAddService - ok

19:33:58.0412 4144 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys

19:33:58.0553 4144 HDAudBus - ok

19:33:58.0787 4144 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys

19:33:58.0897 4144 HidBth - ok

19:33:59.0068 4144 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys

19:33:59.0162 4144 HidIr - ok

19:33:59.0350 4144 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys

19:33:59.0459 4144 HidUsb - ok

19:33:59.0678 4144 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys

19:33:59.0725 4144 HpCISSs - ok

19:33:59.0818 4144 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys

19:33:59.0897 4144 HTTP - ok

19:34:00.0256 4144 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys

19:34:00.0381 4144 i2omp - ok

19:34:00.0584 4144 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys

19:34:00.0756 4144 i8042prt - ok

19:34:01.0147 4144 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys

19:34:01.0209 4144 iaStorV - ok

19:34:01.0600 4144 IDSVix86 (9bc8840de4140e8e2a6fc3192e054a8c) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20120106.002\IDSvix86.sys

19:34:01.0990 4144 IDSVix86 - ok

19:34:02.0318 4144 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys

19:34:02.0412 4144 iirsp - ok

19:34:02.0772 4144 IntcAzAudAddService (f92f433a1b38041b365bfd4b021e42d2) C:\Windows\system32\drivers\RTKVHDA.sys

19:34:02.0943 4144 IntcAzAudAddService - ok

19:34:03.0397 4144 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys

19:34:03.0476 4144 intelide - ok

19:34:03.0757 4144 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys

19:34:03.0819 4144 intelppm - ok

19:34:04.0163 4144 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys

19:34:04.0272 4144 IpFilterDriver - ok

19:34:04.0569 4144 IpInIp - ok

19:34:04.0772 4144 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys

19:34:04.0851 4144 IPMIDRV - ok

19:34:05.0085 4144 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys

19:34:05.0147 4144 IPNAT - ok

19:34:05.0319 4144 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys

19:34:05.0397 4144 IRENUM - ok

19:34:05.0741 4144 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys

19:34:05.0804 4144 isapnp - ok

19:34:05.0960 4144 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys

19:34:06.0038 4144 iScsiPrt - ok

19:34:06.0397 4144 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys

19:34:06.0460 4144 iteatapi - ok

19:34:06.0663 4144 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys

19:34:06.0741 4144 iteraid - ok

19:34:06.0835 4144 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys

19:34:06.0897 4144 kbdclass - ok

19:34:06.0960 4144 kbdhid (d2600cb17b7408b4a83f231dc9a11ac3) C:\Windows\system32\drivers\kbdhid.sys

19:34:07.0038 4144 kbdhid - ok

19:34:07.0116 4144 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys

19:34:07.0210 4144 KSecDD - ok

19:34:07.0554 4144 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys

19:34:07.0647 4144 lltdio - ok

19:34:07.0804 4144 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys

19:34:07.0866 4144 LSI_FC - ok

19:34:07.0929 4144 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys

19:34:07.0991 4144 LSI_SAS - ok

19:34:08.0147 4144 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys

19:34:08.0241 4144 LSI_SCSI - ok

19:34:08.0351 4144 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys

19:34:08.0397 4144 luafv - ok

19:34:08.0507 4144 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys

19:34:08.0554 4144 MBAMProtector - ok

19:34:08.0679 4144 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys

19:34:08.0726 4144 megasas - ok

19:34:08.0757 4144 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys

19:34:08.0819 4144 Modem - ok

19:34:08.0882 4144 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys

19:34:08.0976 4144 monitor - ok

19:34:09.0163 4144 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys

19:34:09.0226 4144 mouclass - ok

19:34:09.0351 4144 mouhid (a3a6dff7e9e757db3df51a833bc28885) C:\Windows\system32\drivers\mouhid.sys

19:34:09.0476 4144 mouhid - ok

19:34:09.0835 4144 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys

19:34:09.0913 4144 MountMgr - ok

19:34:10.0335 4144 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys

19:34:10.0429 4144 mpio - ok

19:34:10.0788 4144 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys

19:34:10.0866 4144 mpsdrv - ok

19:34:11.0007 4144 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys

19:34:11.0069 4144 Mraid35x - ok

19:34:11.0147 4144 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys

19:34:11.0241 4144 MRxDAV - ok

19:34:11.0569 4144 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys

19:34:11.0694 4144 mrxsmb - ok

19:34:11.0929 4144 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys

19:34:12.0038 4144 mrxsmb10 - ok

19:34:12.0319 4144 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys

19:34:12.0569 4144 mrxsmb20 - ok

19:34:12.0679 4144 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys

19:34:12.0772 4144 msahci - ok

19:34:13.0038 4144 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys

19:34:13.0116 4144 msdsm - ok

19:34:13.0382 4144 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys

19:34:13.0476 4144 Msfs - ok

19:34:13.0585 4144 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys

19:34:13.0632 4144 msisadrv - ok

19:34:13.0694 4144 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys

19:34:13.0757 4144 MSKSSRV - ok

19:34:13.0819 4144 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys

19:34:13.0897 4144 MSPCLOCK - ok

19:34:14.0132 4144 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys

19:34:14.0210 4144 MSPQM - ok

19:34:14.0257 4144 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys

19:34:14.0319 4144 MsRPC - ok

19:34:14.0585 4144 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys

19:34:14.0663 4144 mssmbios - ok

19:34:14.0866 4144 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys

19:34:14.0960 4144 MSTEE - ok

19:34:15.0210 4144 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys

19:34:15.0288 4144 Mup - ok

19:34:15.0429 4144 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys

19:34:15.0507 4144 NativeWifiP - ok

19:34:15.0788 4144 NAVENG (862f55824ac81295837b0ab63f91071f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120107.009\NAVENG.SYS

19:34:15.0882 4144 NAVENG - ok

19:34:16.0601 4144 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120107.009\NAVEX15.SYS

19:34:16.0772 4144 NAVEX15 - ok

19:34:17.0210 4144 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys

19:34:17.0304 4144 NDIS - ok

19:34:17.0507 4144 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys

19:34:17.0632 4144 NdisTapi - ok

19:34:17.0772 4144 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys

19:34:17.0835 4144 Ndisuio - ok

19:34:17.0913 4144 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys

19:34:18.0054 4144 NdisWan - ok

19:34:18.0179 4144 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys

19:34:18.0257 4144 NDProxy - ok

19:34:18.0476 4144 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys

19:34:18.0569 4144 NetBIOS - ok

19:34:18.0913 4144 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys

19:34:19.0085 4144 netbt - ok

19:34:19.0757 4144 NETw3v32 (acc6170d80c69e50145b370023b64ed3) C:\Windows\system32\DRIVERS\NETw3v32.sys

19:34:19.0929 4144 NETw3v32 - ok

19:34:20.0257 4144 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys

19:34:20.0319 4144 nfrd960 - ok

19:34:20.0382 4144 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys

19:34:20.0444 4144 Npfs - ok

19:34:20.0757 4144 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys

19:34:20.0851 4144 nsiproxy - ok

19:34:21.0366 4144 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys

19:34:21.0601 4144 Ntfs - ok

19:34:21.0788 4144 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys

19:34:21.0882 4144 ntrigdigi - ok

19:34:21.0960 4144 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys

19:34:21.0991 4144 Null - ok

19:34:22.0413 4144 nvlddmkm (8ead4e71cf31962b124cdace9c29c714) C:\Windows\system32\DRIVERS\nvlddmkm.sys

19:34:23.0319 4144 nvlddmkm - ok

19:34:23.0444 4144 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys

19:34:23.0522 4144 nvraid - ok

19:34:23.0569 4144 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys

19:34:23.0632 4144 nvstor - ok

19:34:23.0710 4144 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys

19:34:23.0741 4144 nv_agp - ok

19:34:23.0757 4144 NwlnkFlt - ok

19:34:23.0772 4144 NwlnkFwd - ok

19:34:23.0835 4144 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys

19:34:23.0882 4144 ohci1394 - ok

19:34:23.0960 4144 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys

19:34:24.0038 4144 Parport - ok

19:34:24.0132 4144 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys

19:34:24.0194 4144 partmgr - ok

19:34:24.0226 4144 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys

19:34:24.0304 4144 Parvdm - ok

19:34:24.0429 4144 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys

19:34:24.0507 4144 pci - ok

19:34:24.0569 4144 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys

19:34:24.0632 4144 pciide - ok

19:34:24.0679 4144 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys

19:34:24.0757 4144 pcmcia - ok

19:34:24.0882 4144 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys

19:34:25.0007 4144 PEAUTH - ok

19:34:25.0116 4144 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys

19:34:25.0179 4144 PptpMiniport - ok

19:34:25.0273 4144 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys

19:34:25.0352 4144 Processor - ok

19:34:25.0398 4144 PROCEXP151 - ok

19:34:25.0461 4144 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys

19:34:25.0555 4144 PSched - ok

19:34:25.0695 4144 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys

19:34:25.0820 4144 ql2300 - ok

19:34:25.0836 4144 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys

19:34:25.0867 4144 ql40xx - ok

19:34:25.0945 4144 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys

19:34:25.0977 4144 QWAVEdrv - ok

19:34:26.0133 4144 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys

19:34:26.0398 4144 R300 - ok

19:34:26.0492 4144 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys

19:34:26.0555 4144 RasAcd - ok

19:34:26.0617 4144 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys

19:34:26.0695 4144 Rasl2tp - ok

19:34:26.0820 4144 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys

19:34:26.0883 4144 RasPppoe - ok

19:34:26.0930 4144 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys

19:34:26.0992 4144 RasSstp - ok

19:34:27.0070 4144 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys

19:34:27.0133 4144 rdbss - ok

19:34:27.0164 4144 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys

19:34:27.0227 4144 RDPCDD - ok

19:34:27.0320 4144 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys

19:34:27.0430 4144 rdpdr - ok

19:34:27.0523 4144 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys

19:34:27.0586 4144 RDPENCDD - ok

19:34:27.0633 4144 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys

19:34:27.0695 4144 RDPWD - ok

19:34:27.0820 4144 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys

19:34:27.0898 4144 RFCOMM - ok

19:34:28.0008 4144 rimmptsk (b39f1bd472e4992382875baf0b645c6d) C:\Windows\system32\DRIVERS\rimmptsk.sys

19:34:28.0055 4144 rimmptsk - ok

19:34:28.0086 4144 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys

19:34:28.0148 4144 rimsptsk - ok

19:34:28.0227 4144 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys

19:34:28.0273 4144 rspndr - ok

19:34:28.0367 4144 RTL8169 (283392af1860ecdb5e0f8ebd7f3d72df) C:\Windows\system32\DRIVERS\Rtlh86.sys

19:34:28.0461 4144 RTL8169 - ok

19:34:28.0539 4144 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS

19:34:28.0570 4144 SASDIFSV - ok

19:34:28.0602 4144 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

19:34:28.0633 4144 SASKUTIL - ok

19:34:28.0727 4144 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys

19:34:28.0773 4144 sbp2port - ok

19:34:28.0852 4144 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys

19:34:28.0930 4144 sdbus - ok

19:34:29.0008 4144 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys

19:34:29.0102 4144 secdrv - ok

19:34:29.0211 4144 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys

19:34:29.0289 4144 Serenum - ok

19:34:29.0398 4144 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys

19:34:29.0492 4144 Serial - ok

19:34:29.0523 4144 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys

19:34:29.0602 4144 sermouse - ok

19:34:29.0695 4144 sffdisk (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys

19:34:29.0773 4144 sffdisk - ok

19:34:29.0836 4144 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys

19:34:29.0898 4144 sffp_mmc - ok

19:34:29.0977 4144 sffp_sd (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys

19:34:30.0055 4144 sffp_sd - ok

19:34:30.0148 4144 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys

19:34:30.0242 4144 sfloppy - ok

19:34:30.0336 4144 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys

19:34:30.0414 4144 sisagp - ok

19:34:30.0445 4144 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys

19:34:30.0508 4144 SiSRaid2 - ok

19:34:30.0602 4144 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys

19:34:30.0664 4144 SiSRaid4 - ok

19:34:30.0742 4144 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys

19:34:30.0820 4144 Smb - ok

19:34:30.0945 4144 smserial (c8a58fc905c9184fa70e37f71060c64d) C:\Windows\system32\DRIVERS\smserial.sys

19:34:31.0070 4144 smserial - ok

19:34:31.0164 4144 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys

19:34:31.0227 4144 spldr - ok

19:34:31.0320 4144 SRTSP (e81f6caeab9ad5732e94c07c97866aa2) C:\Windows\System32\Drivers\N360\0308030.006\SRTSP.SYS

19:34:31.0383 4144 SRTSP - ok

19:34:31.0477 4144 SRTSPX (e28de499d942b08058bffac69d4122b6) C:\Windows\system32\drivers\N360\0308030.006\SRTSPX.SYS

19:34:31.0539 4144 SRTSPX - ok

19:34:31.0602 4144 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys

19:34:31.0695 4144 srv - ok

19:34:31.0805 4144 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys

19:34:31.0883 4144 srv2 - ok

19:34:31.0977 4144 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys

19:34:32.0070 4144 srvnet - ok

19:34:32.0195 4144 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys

19:34:32.0258 4144 swenum - ok

19:34:32.0336 4144 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys

19:34:32.0398 4144 Symc8xx - ok

19:34:32.0539 4144 SymEFA (d0885f6e24259a6c65e68d6ad749910a) C:\Windows\system32\drivers\N360\0308030.006\SYMEFA.SYS

19:34:32.0602 4144 SymEFA - ok

19:34:32.0680 4144 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS

19:34:32.0758 4144 SymEvent - ok

19:34:32.0852 4144 SYMFW (a8c45c36309ee066f9191e511f88ed76) C:\Windows\System32\Drivers\N360\0308030.006\SYMFW.SYS

19:34:32.0898 4144 SYMFW - ok

19:34:33.0023 4144 SymIM (34f1c9d5dcc19df1e824d6b73767b8af) C:\Windows\system32\DRIVERS\SymIMv.sys

19:34:33.0102 4144 SymIM - ok

19:34:33.0461 4144 SYMNDISV (d8b16289f39b63456f48ea95243a788a) C:\Windows\System32\Drivers\N360\0308030.006\SYMNDISV.SYS

19:34:33.0711 4144 SYMNDISV - ok

19:34:33.0852 4144 SYMTDI (26bc80ec79d7ba478249c266cbdf17b4) C:\Windows\System32\Drivers\N360\0308030.006\SYMTDI.SYS

19:34:33.0945 4144 SYMTDI - ok

19:34:34.0039 4144 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys

19:34:34.0102 4144 Sym_hi - ok

19:34:34.0148 4144 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys

19:34:34.0227 4144 Sym_u3 - ok

19:34:34.0320 4144 SynTP (1f452f22df0c00dd2529867e1ea0dc25) C:\Windows\system32\DRIVERS\SynTP.sys

19:34:34.0367 4144 SynTP - ok

19:34:34.0461 4144 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys

19:34:34.0539 4144 Tcpip - ok

19:34:34.0633 4144 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys

19:34:34.0680 4144 Tcpip6 - ok

19:34:34.0758 4144 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys

19:34:34.0805 4144 tcpipreg - ok

19:34:34.0852 4144 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys

19:34:34.0930 4144 TDPIPE - ok

19:34:35.0039 4144 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys

19:34:35.0102 4144 TDTCP - ok

19:34:35.0148 4144 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys

19:34:35.0195 4144 tdx - ok

19:34:35.0305 4144 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys

19:34:35.0367 4144 TermDD - ok

19:34:35.0461 4144 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys

19:34:35.0508 4144 tssecsrv - ok

19:34:35.0633 4144 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys

19:34:35.0695 4144 tunmp - ok

19:34:35.0742 4144 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys

19:34:35.0805 4144 tunnel - ok

19:34:35.0883 4144 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys

19:34:35.0945 4144 uagp35 - ok

19:34:36.0039 4144 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys

19:34:36.0102 4144 udfs - ok

19:34:36.0211 4144 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys

19:34:36.0242 4144 uliagpkx - ok

19:34:36.0289 4144 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys

19:34:36.0352 4144 uliahci - ok

19:34:36.0461 4144 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys

19:34:36.0523 4144 UlSata - ok

19:34:36.0570 4144 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys

19:34:36.0633 4144 ulsata2 - ok

19:34:36.0664 4144 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys

19:34:36.0758 4144 umbus - ok

19:34:36.0867 4144 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys

19:34:36.0945 4144 USBAAPL ( UnsignedFile.Multi.Generic ) - warning

19:34:36.0945 4144 USBAAPL - detected UnsignedFile.Multi.Generic (1)

19:34:37.0039 4144 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys

19:34:37.0133 4144 usbccgp - ok

19:34:37.0211 4144 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys

19:34:37.0273 4144 usbcir - ok

19:34:37.0367 4144 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys

19:34:37.0445 4144 usbehci - ok

19:34:37.0586 4144 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys

19:34:37.0664 4144 usbhub - ok

19:34:37.0711 4144 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys

19:34:37.0805 4144 usbohci - ok

19:34:37.0898 4144 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys

19:34:37.0992 4144 usbprint - ok

19:34:38.0055 4144 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys

19:34:38.0117 4144 usbscan - ok

19:34:38.0195 4144 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS

19:34:38.0258 4144 USBSTOR - ok

19:34:38.0321 4144 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys

19:34:38.0384 4144 usbuhci - ok

19:34:38.0493 4144 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys

19:34:38.0603 4144 vga - ok

19:34:38.0712 4144 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys

19:34:38.0790 4144 VgaSave - ok

19:34:38.0821 4144 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys

19:34:38.0899 4144 viaagp - ok

19:34:38.0978 4144 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys

19:34:39.0056 4144 ViaC7 - ok

19:34:39.0149 4144 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys

19:34:39.0181 4144 viaide - ok

19:34:39.0228 4144 viamraid (25700f5d901d8a8f4c7e851788a2707d) C:\Windows\system32\drivers\viamraid.sys

19:34:39.0306 4144 viamraid - ok

19:34:39.0415 4144 VirtualCamX86 (316397f47355e19075f3bacb11067e7c) C:\Windows\system32\DRIVERS\Ddpcvcam.sys

19:34:39.0478 4144 VirtualCamX86 - ok

19:34:39.0540 4144 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys

19:34:39.0587 4144 volmgr - ok

19:34:39.0665 4144 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys

19:34:39.0743 4144 volmgrx - ok

19:34:39.0853 4144 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys

19:34:39.0915 4144 volsnap - ok

19:34:39.0962 4144 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys

19:34:40.0009 4144 vsmraid - ok

19:34:40.0071 4144 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys

19:34:40.0149 4144 WacomPen - ok

19:34:40.0243 4144 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys

19:34:40.0306 4144 Wanarp - ok

19:34:40.0321 4144 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys

19:34:40.0353 4144 Wanarpv6 - ok

19:34:40.0446 4144 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys

19:34:40.0493 4144 Wd - ok

19:34:40.0556 4144 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys

19:34:40.0634 4144 Wdf01000 - ok

19:34:40.0743 4144 WimFltr (f9ad3a5e3fd7e0bdb18b8202b0fdd4e4) C:\Windows\system32\DRIVERS\wimfltr.sys

19:34:40.0821 4144 WimFltr - ok

19:34:40.0915 4144 WinDriver6 (097a8291df541f9b9af2c500797cdcaa) C:\Windows\system32\drivers\windrvr6.sys

19:34:40.0962 4144 WinDriver6 ( UnsignedFile.Multi.Generic ) - warning

19:34:40.0962 4144 WinDriver6 - detected UnsignedFile.Multi.Generic (1)

19:34:41.0071 4144 WmiAcpi (701a9f884a294327e9141d73746ee279) C:\Windows\system32\DRIVERS\wmiacpi.sys

19:34:41.0149 4144 WmiAcpi - ok

19:34:41.0274 4144 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys

19:34:41.0322 4144 WpdUsb - ok

19:34:41.0369 4144 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys

19:34:41.0416 4144 ws2ifsl - ok

19:34:41.0541 4144 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys

19:34:41.0619 4144 WUDFRd - ok

19:34:41.0697 4144 yukonwlh (a4822191c7cea271903c2a4fb6d9809d) C:\Windows\system32\DRIVERS\yk60x86.sys

19:34:41.0760 4144 yukonwlh - ok

19:34:41.0775 4144 MBR (0x1B8) (048134312428ad1a401581be277e58b7) \Device\Harddisk0\DR0

19:34:41.0994 4144 \Device\Harddisk0\DR0 ( TDSS File System ) - warning

19:34:41.0994 4144 \Device\Harddisk0\DR0 - detected TDSS File System (1)

19:34:41.0994 4144 Boot (0x1200) (c503a68adbfd6b4c9c511e45eee1230d) \Device\Harddisk0\DR0\Partition0

19:34:41.0994 4144 \Device\Harddisk0\DR0\Partition0 - ok

19:34:41.0994 4144 ============================================================

19:34:41.0994 4144 Scan finished

19:34:41.0994 4144 ============================================================

19:34:42.0010 5540 Detected object count: 3

19:34:42.0010 5540 Actual detected object count: 3

19:34:54.0557 5540 USBAAPL ( UnsignedFile.Multi.Generic ) - skipped by user

19:34:54.0557 5540 USBAAPL ( UnsignedFile.Multi.Generic ) - User select action: Skip

19:34:54.0557 5540 WinDriver6 ( UnsignedFile.Multi.Generic ) - skipped by user

19:34:54.0557 5540 WinDriver6 ( UnsignedFile.Multi.Generic ) - User select action: Skip

19:34:54.0557 5540 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user

19:34:54.0557 5540 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

19:35:05.0323 2216 Deinitialize success

And then here is the most recent aswMRB log:

aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software

Run date: 2012-01-08 19:36:07

-----------------------------

19:36:07.964 OS Version: Windows 6.0.6002 Service Pack 2

19:36:07.964 Number of processors: 2 586 0xF06

19:36:07.964 ComputerName: ALIENWARE UserName: Eric

19:36:09.808 Initialize success

19:36:39.513 AVAST engine defs: 12010801

19:36:48.466 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-1

19:36:48.466 Disk 0 Vendor: ST9160823AS 3.ADC Size: 152627MB BusType: 3

19:36:48.528 Disk 0 MBR read successfully

19:36:48.528 Disk 0 MBR scan

19:36:48.528 Disk 0 unknown MBR code

19:36:48.544 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 145196 MB offset 63

19:36:48.575 Disk 0 Partition 2 00 12 Compaq diag NTFS 7427 MB offset 297363456

19:36:48.606 Disk 0 scanning sectors +312573952

19:36:48.747 Disk 0 scanning C:\Windows\system32\drivers

19:37:13.076 Service scanning

19:37:14.732 Modules scanning

19:37:40.579 Disk 0 trace - called modules:

19:37:40.595 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys

19:37:40.595 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84c319d8]

19:37:40.610 3 CLASSPNP.SYS[87f9d8b3] -> nt!IofCallDriver -> [0x84052918]

19:37:40.610 5 acpi.sys[8069c6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-1[0x8408eb98]

19:37:41.376 AVAST engine scan C:\Windows

19:37:47.772 File: C:\Windows\PEV.exe **INFECTED** Win32:Rootkit-gen [Rtk]

19:37:52.290 AVAST engine scan C:\Windows\system32

19:41:40.725 AVAST engine scan C:\Windows\system32\drivers

19:41:56.100 AVAST engine scan C:\Users\Eric

19:44:37.583 File: C:\Users\Eric\AppData\Roaming\Adobe\Flash Player\NativeCache\58D75590E211D1B0C26C176059D52D75\676cdbe3\adobecp-200489-1.dll **INFECTED** Win32:Malware-gen

19:50:23.318 AVAST engine scan C:\ProgramData

19:59:51.848 Scan finished successfully

20:05:37.413 Disk 0 MBR has been saved successfully to "C:\Users\Eric\Desktop\MBR.dat"

20:05:37.413 The log file has been saved successfully to "C:\Users\Eric\Desktop\aswMBR.txt"

Link to post
Share on other sites

19:44:37.583 File: C:\Users\Eric\AppData\Roaming\Adobe\Flash Player\NativeCache\58D75590E211D1B0C26C176059D52D75\676cdbe3\adobecp-200489-1.dll **INFECTED** Win32:Malware-gen
Looks like you have a bad Flash Player

See if you can at least delete the .dll for now: adobecp-200489-1.dll

Run TDSSKiller again and fix the Detected object count: 3

Reboot and run a new aswMBR

Post both scan results again

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.