OK,
Is that the full log, or is their more of it?
Please do the following:
You will need to be able to boot into the recovery console for this:
This is how to beeot into the Recovery Console:
Restart your computer Before Windows loads, you will be prompted to choose which Operating System to start Use the up and down arrow key to select Microsoft Windows Recovery Console You must enter which Windows installation to log onto. Type 1 and press enter.
But first - Do the following:
Next, please download
maxlook , saving the file to your desktop.
Double click maxlook.exe to run it.
Note - you must run it only once!
As instructed when the tool runs, > restart the computer and logon to the
Recovery Console .
Execute the following bolded command at the
x :\windows> prompt <— the red x represents your operating system drive letter, usually C
batch look.bat
🖼 Click to load external image (Posted Image)
You will see
1 file copied many times then return to the
x :\windows> prompt.
Type
Exit to restart your computer then logon in normal mode.
Please run maxlook.exe again now.
Note - you must run it only once!
It will produce looklog.txt on the desktop and open it.
Please post the results here.
Hi,
That was the full maxhandle.txt file.
looklog.txt is below.
Run from C:\Documents and Settings\Donal\Desktop\maxlook.exe on 26/02/2010 at 14:04:21.29
C:\WINDOWS\system32\drivers\netbt.sys is infected!
2007-11-02 18:49:52 . 2004-08-04 04:00:00 - 162816 - 0C80E410CD2F47134407EE7DD19CC86B —-a-w- C:\i386\netbt.sys
2008-10-08 01:29:30 . 2004-08-04 04:00:00 - 162816 - 0C80E410CD2F47134407EE7DD19CC86B -c—-w- C:\WINDOWS\$NtServicePackUninstall$\netbt.sys
2008-04-13 19:21:00 . 2008-04-13 19:21:00 - 162816 - 74B2B2F5BEA5E9A3DC021D685551BD3D ——w- C:\WINDOWS\ServicePackFiles\i386\netbt.sys
2010-02-26 13:26:39 . 2008-04-13 19:21:00 - 162816 - 07E8ADAFB979D44D6C4B4C685EA05AFD —-a-w- C:\WINDOWS\system32\dllcache\netbt.sys
2004-08-10 11:51:15 . 2008-04-13 19:21:00 - 162816 - 07E8ADAFB979D44D6C4B4C685EA05AFD —-a-w- C:\WINDOWS\system32\drivers\netbt.sys
Rogue configuration file = C:\WINDOWS\system32\config\8monrowg.sav
There's netbt.sys again… Is it strange that GMER identifies that file as malware/rootkit when running in normal mode (before crashing) but not in safe mode?
Thanks
Hi,
Please do the following:
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:
Here's how to do that:
Click
Start > Run type
Notepad click
OK.
This will open an empty notepad file:
Copy all the text
inside of the code box -
Press Ctrl+C (or right click on the highlighted section and choose 'copy')
FCopy::
C:\WINDOWS\ServicePackFiles\i386\netbt.sys | C:\WINDOWS\system32\dllcache\netbt.sys
C:\WINDOWS\ServicePackFiles\i386\netbt.sys | C:\WINDOWS\system32\drivers\netbt.sys
Now
paste the copied text into the open notepad - press
CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click
File ;
2.Click
Save As … Change the directory to your
desktop ;
3.Change the
Save as type to
"All Files";
4.Type in the file name:
CFScript
5.Click
Save …
[external image: Posted Image]
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe. ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal. When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Reboot your computer, then repost a fresh maxhandle log
OK. ComboFix did much the same as before - i.e. detected rootkit activity, rebooted computer and continued scan. The log is below.
ComboFix 10-02-25.02 - Donal 26/02/2010 14:36:14.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.484 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Donal\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
The following files were disabled during the run:
c:\progra~1\PHAROS~1\Core\PRNTRACK.DLL
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
————— FCopy —————
c:\windows\ServicePackFiles\i386\netbt.sys –> c:\windows\system32\dllcache\netbt.sys
c:\windows\ServicePackFiles\i386\netbt.sys –> c:\windows\system32\drivers\netbt.sys
.
((((((((((((((((((((((((( Files Created from 2010-01-26 to 2010-02-26 )))))))))))))))))))))))))))))))
.
2010-02-26 13:57 . 2010-02-26 14:08 ——– d—–w- c:\windows\maxdriver
2010-02-26 13:26 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\dllcache\netbt.sys
2010-02-26 12:31 . 2010-02-26 12:31 13264416 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\cache\Dropbox-update-0.7.110.exe
2010-02-26 10:47 . 2008-11-18 13:15 417136 —-a-w- c:\windows\handle.exe
2010-02-26 05:10 . 2010-02-26 05:10 21979992 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\Dropbox.exe
2010-02-24 17:58 . 2010-02-24 18:18 ——– d—–w- c:\documents and settings\Donal\.artofillusion
2010-02-24 17:33 . 2010-02-24 17:34 ——– d—–w- c:\documents and settings\Donal\.SunDownloadManager
2010-02-24 17:24 . 2010-02-24 18:18 ——– d—–w- c:\program files\ArtOfIllusion
2010-02-24 16:47 . 2009-11-12 17:04 4296704 —-a-w- c:\windows\DXLib80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:53 2805760 —-a-w- c:\windows\DXLib80U.dll
2010-02-24 16:47 . 2009-09-01 17:03 473600 —-a-w- c:\windows\SYCLicense80Ux64_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 425984 —-a-w- c:\windows\SYCLicenseU_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 278528 —-a-w- c:\windows\SYCLicense_090901.dll
2010-02-24 16:47 . 2009-12-02 21:02 532480 —-a-w- c:\windows\SYCGUI71.dll
2010-02-24 16:47 . 2009-12-02 19:48 696320 —-a-w- c:\windows\SYCGUI80U.dll
2010-02-24 16:47 . 2009-12-02 19:47 824320 —-a-w- c:\windows\SYCGUI80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:41 2826240 —-a-w- c:\windows\DXLib71.dll
2010-02-24 16:47 . 2009-11-12 16:00 3055616 —-a-w- c:\windows\DXLib60.dll
2010-02-24 16:47 . 2009-12-02 19:24 532480 —-a-w- c:\windows\SYCGUI.dll
2010-02-24 16:47 . 2010-02-24 16:47 ——– d—–w- c:\program files\SYCODE
2010-02-24 01:23 . 2010-02-24 01:23 ——– d—–w- c:\program files\ERUNT
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\Donal\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 07:48 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-18 20:56 . 2010-02-18 20:56 102400 —-a-w- c:\windows\mmvem.exe
2010-02-11 17:08 . 2010-02-11 17:08 ——– d—–w- c:\documents and settings\Donal\Local Settings\Application Data\Mendeley Ltd
2010-02-11 17:07 . 2010-02-11 17:07 ——– d—–w- c:\program files\Mendeley Desktop
2010-02-03 12:51 . 2010-02-03 12:51 ——– d—–w- c:\documents and settings\Donal\Application Data\Clickteam
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 14:03 . 2007-11-05 20:40 ——– d—–w- c:\documents and settings\Donal\Application Data\OpenOffice.org2
2010-02-26 14:03 . 2010-01-09 15:20 ——– d—–w- c:\documents and settings\Donal\Application Data\Dropbox
2010-02-26 12:31 . 2010-01-09 15:21 91696 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\Uninstall.exe
2010-02-24 17:35 . 2010-02-24 17:35 ——– d—–w- c:\program files\JMF2.1.1e
2010-02-24 17:31 . 2006-04-20 11:16 ——– d—–w- c:\program files\Common Files\Java
2010-02-24 17:30 . 2006-04-20 11:16 ——– d—–w- c:\program files\Java
2010-02-24 00:00 . 2010-01-05 19:11 ——– d—–w- c:\program files\SyncBack
2010-02-22 21:33 . 2008-11-11 23:30 ——– d—–w- c:\program files\MATLAB71
2010-02-11 17:09 . 2007-11-05 20:41 1 —-a-w- c:\documents and settings\Donal\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-25 19:45 . 2010-01-25 19:44 ——– d—–w- c:\program files\Pharos
2010-01-25 17:28 . 2008-04-24 22:28 ——– d—–w- c:\documents and settings\Donal\Application Data\gtk-2.0
2010-01-21 01:53 . 2007-11-05 20:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-05 10:00 . 2004-08-10 11:51 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-10 11:51 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-10 11:50 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2006-04-20 10:56 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-26 03:53 . 2009-12-26 03:53 223440 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2009-12-17 17:14 . 2009-01-27 13:38 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2004-08-10 12:01 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-16 14:42 . 2009-12-24 11:03 872960 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 14:42 . 2009-12-24 11:03 43008 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 14:42 . 2009-12-24 11:03 340480 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 14:41 . 2009-12-24 11:03 346624 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-14 07:08 . 2004-08-10 11:50 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-10 14:54 . 2009-12-10 14:54 201728 —-a-w- c:\windows\system32\Analogy.scr
2009-12-09 01:19 . 2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
2009-12-08 19:26 . 2004-08-10 11:51 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 21:59 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2006-04-20 10:56 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-02-25_20.16.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-26 14:34 . 2010-02-26 14:34 16384 c:\windows\Temp\Perflib_Perfdata_7cc.dat
+ 2006-09-28 19:00 . 2006-09-28 19:00 82944 c:\windows\maxdriver\WudfRd.sys
+ 2006-09-28 18:55 . 2006-09-28 18:55 77568 c:\windows\maxdriver\WudfPf.sys
+ 2007-12-20 21:00 . 2008-04-13 18:46 19200 c:\windows\maxdriver\wstcodec.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 12032 c:\windows\maxdriver\ws2ifsl.sys
+ 2004-08-11 00:45 . 2006-10-18 20:00 38528 c:\windows\maxdriver\wpdusb.sys
+ 2006-04-20 11:19 . 2008-04-13 19:17 83072 c:\windows\maxdriver\wdmaud.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 25471 c:\windows\maxdriver\watv10nt.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 22271 c:\windows\maxdriver\watv06nt.sys
+ 2004-08-10 11:51 . 2008-04-13 18:57 34560 c:\windows\maxdriver\wanarp.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 11935 c:\windows\maxdriver\wadv11nt.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 11871 c:\windows\maxdriver\wadv09nt.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 11295 c:\windows\maxdriver\wadv08nt.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 11807 c:\windows\maxdriver\wadv07nt.sys
+ 2008-04-13 18:43 . 2008-04-13 18:43 14208 c:\windows\maxdriver\wacompen.sys
+ 2004-08-10 11:51 . 2008-04-13 18:41 52352 c:\windows\maxdriver\volsnap.sys
+ 2004-08-10 11:51 . 2008-04-13 18:44 81664 c:\windows\maxdriver\videoprt.sys
+ 2004-08-10 12:24 . 2008-04-13 18:36 42240 c:\windows\maxdriver\viaagp.sys
+ 2004-08-10 11:51 . 2008-04-13 18:44 20992 c:\windows\maxdriver\vga.sys
+ 2001-08-17 13:02 . 2004-08-04 04:00 58112 c:\windows\maxdriver\vdmindvd.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 20608 c:\windows\maxdriver\usbuhci.sys
+ 2007-11-01 12:54 . 2008-04-13 18:45 26368 c:\windows\maxdriver\usbstor.sys
+ 2008-11-05 02:12 . 2008-04-13 18:45 15104 c:\windows\maxdriver\usbscan.sys
+ 2009-10-17 22:08 . 2008-04-13 18:47 25856 c:\windows\maxdriver\usbprint.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 15872 c:\windows\maxdriver\usbintel.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 59520 c:\windows\maxdriver\usbhub.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 30208 c:\windows\maxdriver\usbehci.sys
+ 2009-10-13 17:20 . 2008-04-13 18:45 32128 c:\windows\maxdriver\usbccgp.sys
+ 2001-08-17 13:03 . 2008-04-13 18:45 25728 c:\windows\maxdriver\usbcamd2.sys
+ 2001-08-17 13:03 . 2008-04-13 18:45 25600 c:\windows\maxdriver\usbcamd.sys
+ 2008-04-13 18:56 . 2008-04-13 18:56 12800 c:\windows\maxdriver\usb8023x.sys
+ 2004-08-10 11:51 . 2008-04-13 18:56 12800 c:\windows\maxdriver\usb8023.sys
+ 2004-08-10 12:33 . 2001-08-17 12:52 36736 c:\windows\maxdriver\ultra.sys
+ 2004-08-10 11:51 . 2008-04-13 18:32 66048 c:\windows\maxdriver\udfs.sys
+ 2008-04-13 18:36 . 2008-04-13 18:36 44672 c:\windows\maxdriver\uagp35.sys
+ 2004-08-03 22:03 . 2008-04-13 18:56 12288 c:\windows\maxdriver\tunmp.sys
+ 2001-08-17 13:06 . 2004-08-04 04:00 21376 c:\windows\maxdriver\tsbvcap.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 16320 c:\windows\maxdriver\tostrans.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 39808 c:\windows\maxdriver\tosrfusb.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 50048 c:\windows\maxdriver\tosrfsnd.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 18612 c:\windows\maxdriver\tosrfnds.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 25420 c:\windows\maxdriver\tosrflan.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 62848 c:\windows\maxdriver\tosrfhid.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 64896 c:\windows\maxdriver\tosrfcom.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 36480 c:\windows\maxdriver\tosrfbnp.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 47104 c:\windows\maxdriver\tosporte.sys
+ 2001-08-17 13:01 . 2004-08-04 04:00 51712 c:\windows\maxdriver\tosdvd.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 48640 c:\windows\maxdriver\tosdbt.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 21120 c:\windows\maxdriver\tosbtsd2.sys
+ 2004-08-10 12:01 . 2008-04-14 00:13 40840 c:\windows\maxdriver\termdd.sys
+ 2004-08-10 12:01 . 2008-04-14 00:13 21896 c:\windows\maxdriver\tdtcp.sys
+ 2004-08-10 12:01 . 2008-04-14 00:13 12040 c:\windows\maxdriver\tdpipe.sys
+ 2004-08-10 11:51 . 2008-04-13 19:00 19072 c:\windows\maxdriver\tdi.sys
+ 2004-08-10 11:51 . 2008-04-13 18:40 14976 c:\windows\maxdriver\tape.sys
+ 2006-04-20 11:19 . 2008-04-13 19:15 60800 c:\windows\maxdriver\sysaudio.sys
+ 2004-08-10 12:28 . 2001-08-17 13:07 32640 c:\windows\maxdriver\symc8xx.sys
+ 2004-08-10 12:29 . 2001-08-17 13:07 16256 c:\windows\maxdriver\symc810.sys
+ 2004-08-10 12:29 . 2001-08-17 13:07 30688 c:\windows\maxdriver\sym_u3.sys
+ 2004-08-10 12:27 . 2001-08-17 13:07 28384 c:\windows\maxdriver\sym_hi.sys
+ 2006-04-20 11:19 . 2008-04-13 18:45 56576 c:\windows\maxdriver\swmidi.sys
+ 2007-12-20 21:00 . 2008-04-13 18:46 15232 c:\windows\maxdriver\streamip.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 49408 c:\windows\maxdriver\stream.sys
+ 2006-04-20 11:29 . 2004-07-14 10:28 23545 c:\windows\maxdriver\ssrtln.sys
+ 2004-08-10 12:02 . 2008-04-13 18:36 73472 c:\windows\maxdriver\sr.sys
+ 2004-08-10 12:24 . 2001-08-17 13:07 19072 c:\windows\maxdriver\sparrow.sys
+ 2004-08-03 22:09 . 2008-04-13 18:46 25344 c:\windows\maxdriver\sonydcam.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 14592 c:\windows\maxdriver\smclib.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 13240 c:\windows\maxdriver\slwdmsup.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 95424 c:\windows\maxdriver\slnthal.sys
+ 2007-12-20 21:00 . 2008-04-13 18:46 11136 c:\windows\maxdriver\slip.sys
+ 2004-08-10 12:22 . 2008-04-13 18:36 40960 c:\windows\maxdriver\sisagp.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 11392 c:\windows\maxdriver\sfloppy.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 11008 c:\windows\maxdriver\sffp_sd.sys
+ 2008-04-13 18:40 . 2008-04-13 18:40 10240 c:\windows\maxdriver\sffp_mmc.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 11904 c:\windows\maxdriver\sffdisk.sys
+ 2004-08-03 22:15 . 2008-04-13 19:15 64512 c:\windows\maxdriver\serial.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 15744 c:\windows\maxdriver\serenum.sys
+ 2010-02-26 14:03 . 2002-09-18 06:38 82944 c:\windows\maxdriver\sed.exe
+ 2004-08-10 11:51 . 2008-04-13 16:39 20480 c:\windows\maxdriver\secdrv.sys
+ 2004-08-03 22:07 . 2008-04-13 18:36 79232 c:\windows\maxdriver\sdbus.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 96384 c:\windows\maxdriver\scsiport.sys
+ 2007-08-07 00:15 . 2007-08-07 00:15 33052 c:\windows\maxdriver\scdemu.sys
+ 2005-12-28 12:22 . 2005-12-28 12:22 13568 c:\windows\maxdriver\s24trans.sys
+ 2008-04-13 18:56 . 2008-04-13 18:56 30592 c:\windows\maxdriver\rndismpx.sys
+ 2004-08-10 11:51 . 2008-04-13 18:56 30592 c:\windows\maxdriver\rndismp.sys
+ 2001-08-17 12:24 . 2004-08-04 04:00 12032 c:\windows\maxdriver\riodrv.sys
+ 2001-08-17 12:24 . 2004-08-04 04:00 12032 c:\windows\maxdriver\rio8drv.sys
+ 2006-04-20 10:58 . 2005-07-12 23:00 51328 c:\windows\maxdriver\rimsptsk.sys
+ 2006-04-20 10:58 . 2005-07-14 22:58 28544 c:\windows\maxdriver\rimmptsk.sys
+ 2008-04-13 18:46 . 2008-04-13 18:46 59136 c:\windows\maxdriver\rfcomm.sys
+ 2004-08-10 11:59 . 2008-04-13 18:40 57600 c:\windows\maxdriver\redbook.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 13776 c:\windows\maxdriver\recagent.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 34432 c:\windows\maxdriver\rawwan.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 16512 c:\windows\maxdriver\raspti.sys
+ 2004-08-10 11:51 . 2008-04-13 19:19 48384 c:\windows\maxdriver\raspptp.sys
+ 2004-08-10 11:51 . 2008-04-13 18:57 41472 c:\windows\maxdriver\raspppoe.sys
+ 2004-08-10 11:51 . 2008-04-13 19:19 51328 c:\windows\maxdriver\rasl2tp.sys
+ 2004-08-10 12:30 . 2001-08-17 12:52 49024 c:\windows\maxdriver\ql1280.sys
+ 2004-08-10 12:30 . 2001-08-17 12:52 40448 c:\windows\maxdriver\ql1240.sys
+ 2004-08-10 12:30 . 2001-08-17 12:52 45312 c:\windows\maxdriver\ql12160.sys
+ 2004-08-10 12:30 . 2001-08-17 12:52 33152 c:\windows\maxdriver\ql10wnt.sys
+ 2004-08-10 12:30 . 2001-08-17 12:52 40320 c:\windows\maxdriver\ql1080.sys
+ 2008-07-31 22:17 . 2008-07-31 22:17 43872 c:\windows\maxdriver\pxhelp20.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 17792 c:\windows\maxdriver\ptilink.sys
+ 2004-08-10 11:51 . 2008-04-13 18:56 69120 c:\windows\maxdriver\psched.sys
+ 2004-08-03 21:59 . 2008-04-13 18:31 35840 c:\windows\maxdriver\processr.sys
+ 2004-08-10 12:28 . 2001-08-17 13:07 27296 c:\windows\maxdriver\perc2.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 24960 c:\windows\maxdriver\pciidex.sys
+ 2004-08-03 22:07 . 2008-04-13 18:36 68224 c:\windows\maxdriver\pci.sys
+ 2004-08-10 11:51 . 2008-04-13 18:40 19712 c:\windows\maxdriver\partmgr.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 80128 c:\windows\maxdriver\parport.sys
+ 2004-08-03 21:59 . 2008-04-13 18:31 42752 c:\windows\maxdriver\p3.sys
+ 2006-04-20 11:27 . 2004-02-13 15:46 17153 c:\windows\maxdriver\omci.sys
+ 2006-04-20 11:04 . 2008-04-13 18:46 61696 c:\windows\maxdriver\ohci1394.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 55936 c:\windows\maxdriver\nwlnkspx.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 63232 c:\windows\maxdriver\nwlnknb.sys
+ 2004-08-10 11:51 . 2008-04-13 18:56 88320 c:\windows\maxdriver\nwlnkipx.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 32512 c:\windows\maxdriver\nwlnkfwd.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 12416 c:\windows\maxdriver\nwlnkflt.sys
+ 2004-08-10 11:51 . 2008-04-13 18:32 30848 c:\windows\maxdriver\npfs.sys
+ 2004-08-10 11:51 . 2008-04-13 18:53 40320 c:\windows\maxdriver\nmnt.sys
+ 2001-08-17 12:24 . 2004-08-04 04:00 12032 c:\windows\maxdriver\nikedrv.sys
+ 2004-08-03 21:58 . 2008-04-13 18:51 61824 c:\windows\maxdriver\nic1394.sys
+ 2008-01-03 19:46 . 2002-08-08 15:51 38951 c:\windows\maxdriver\NETMDUSB.sys
+ 2008-01-03 19:46 . 2005-10-31 10:46 36679 c:\windows\maxdriver\NETMD052.sys
+ 2008-01-03 19:46 . 2003-11-10 12:31 36232 c:\windows\maxdriver\NETMD033.sys
+ 2008-01-03 19:46 . 2003-04-01 18:55 35319 c:\windows\maxdriver\NETMD031.sys
+ 2004-08-10 11:51 . 2008-04-13 18:56 34688 c:\windows\maxdriver\netbios.sys
+ 2004-08-10 11:51 . 2008-04-13 18:57 40576 c:\windows\maxdriver\ndproxy.sys
+ 2004-08-10 11:51 . 2008-04-13 19:20 91520 c:\windows\maxdriver\ndiswan.sys
+ 2004-08-03 22:03 . 2008-04-13 18:55 14592 c:\windows\maxdriver\ndisuio.sys
+ 2004-08-10 11:51 . 2008-04-13 18:57 10112 c:\windows\maxdriver\ndistapi.sys
+ 2007-12-20 21:00 . 2008-04-13 18:46 10880 c:\windows\maxdriver\ndisip.sys
+ 2007-12-20 21:00 . 2008-04-13 18:46 85248 c:\windows\maxdriver\nabtsfec.sys
+ 2008-04-13 18:43 . 2008-04-13 18:43 12672 c:\windows\maxdriver\mutohpen.sys
+ 2004-08-03 22:07 . 2008-04-13 18:36 15488 c:\windows\maxdriver\mssmbios.sys
+ 2004-08-10 11:51 . 2008-04-13 18:56 35072 c:\windows\maxdriver\msgpc.sys
+ 2004-08-10 11:51 . 2008-04-13 18:32 19072 c:\windows\maxdriver\msfs.sys
+ 2004-08-10 12:27 . 2001-08-17 12:52 17280 c:\windows\maxdriver\mraid35x.sys
+ 2004-08-10 11:51 . 2008-04-13 18:39 42368 c:\windows\maxdriver\mountmgr.sys
+ 2009-04-21 02:52 . 2001-08-17 12:48 12160 c:\windows\maxdriver\mouhid.sys
+ 2004-08-03 21:58 . 2008-04-13 18:39 23040 c:\windows\maxdriver\mouclass.sys
+ 2004-08-03 22:08 . 2008-04-13 19:00 30080 c:\windows\maxdriver\modem.sys
+ 2004-08-03 22:07 . 2008-04-13 18:36 63744 c:\windows\maxdriver\mf.sys
+ 2006-04-20 10:58 . 2005-10-05 03:57 12544 c:\windows\maxdriver\mdmxsdk.sys
+ 2010-02-23 07:48 . 2010-01-07 16:07 38224 c:\windows\maxdriver\mbamswissarmy.sys
+ 2010-02-23 07:48 . 2010-01-07 16:07 19160 c:\windows\maxdriver\mbam.sys
+ 2004-08-10 11:51 . 2009-06-24 11:18 92928 c:\windows\maxdriver\ksecdd.sys
+ 2009-10-13 17:20 . 2008-04-13 18:39 14592 c:\windows\maxdriver\kbdhid.sys
+ 2004-08-03 21:58 . 2008-04-13 18:39 24576 c:\windows\maxdriver\kbdclass.sys
+ 2001-08-17 12:58 . 2008-04-13 18:36 37248 c:\windows\maxdriver\isapnp.sys
+ 2004-08-10 11:57 . 2008-04-13 18:54 11264 c:\windows\maxdriver\irenum.sys
+ 2004-08-10 11:51 . 2008-04-13 19:19 75264 c:\windows\maxdriver\ipsec.sys
+ 2004-08-10 11:51 . 2008-04-13 18:57 20864 c:\windows\maxdriver\ipinip.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 32896 c:\windows\maxdriver\ipfltdrv.sys
+ 2004-08-10 11:51 . 2008-04-13 18:53 36608 c:\windows\maxdriver\ip6fw.sys
+ 2004-08-03 21:59 . 2008-04-13 18:31 36352 c:\windows\maxdriver\intelppm.sys
+ 2004-08-10 12:32 . 2001-08-17 12:52 16000 c:\windows\maxdriver\ini910u.sys
+ 2004-08-03 22:00 . 2008-04-13 18:40 42112 c:\windows\maxdriver\imapi.sys
+ 2004-08-03 22:14 . 2008-04-13 19:18 52480 c:\windows\maxdriver\i8042prt.sys
+ 2004-08-10 12:30 . 2008-04-13 18:41 18560 c:\windows\maxdriver\i2omp.sys
+ 2004-08-10 12:28 . 2001-08-17 13:07 25952 c:\windows\maxdriver\hpn.sys
+ 2009-04-21 02:52 . 2008-04-13 18:45 10368 c:\windows\maxdriver\hidusb.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 24960 c:\windows\maxdriver\hidparse.sys
+ 2008-04-13 18:45 . 2008-04-13 18:45 19200 c:\windows\maxdriver\hidir.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 36864 c:\windows\maxdriver\hidclass.sys
+ 2008-04-13 18:46 . 2008-04-13 18:46 25600 c:\windows\maxdriver\hidbth.sys
+ 2008-04-13 18:36 . 2008-04-13 18:36 46464 c:\windows\maxdriver\gagp30kx.sys
+ 2008-05-22 13:52 . 2008-03-13 12:50 72000 c:\windows\maxdriver\ftser2k.sys
+ 2008-05-22 13:52 . 2008-03-13 12:51 57536 c:\windows\maxdriver\ftdibus.sys
+ 2001-08-17 12:57 . 2004-08-04 04:00 12160 c:\windows\maxdriver\fsvga.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 20480 c:\windows\maxdriver\flpydisk.sys
+ 2004-08-10 11:51 . 2008-04-13 18:33 44544 c:\windows\maxdriver\fips.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 27392 c:\windows\maxdriver\fdc.sys
+ 2004-08-03 22:00 . 2008-04-13 18:38 71168 c:\windows\maxdriver\dxg.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 10496 c:\windows\maxdriver\dxapi.sys
+ 2006-04-20 11:29 . 2004-11-23 01:56 40480 c:\windows\maxdriver\drvnddm.sys
+ 2006-04-20 11:29 . 2004-12-01 02:22 87488 c:\windows\maxdriver\drvmcdb.sys
+ 2006-04-20 11:19 . 2008-04-13 18:45 60160 c:\windows\maxdriver\drmk.sys
+ 2004-08-10 12:26 . 2001-08-17 13:07 20192 c:\windows\maxdriver\dpti2o.sys
+ 2006-04-20 11:19 . 2008-04-13 18:45 52864 c:\windows\maxdriver\dmusic.sys
+ 2004-08-10 11:50 . 2008-04-13 18:40 14208 c:\windows\maxdriver\diskdump.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 36352 c:\windows\maxdriver\disk.sys
+ 2004-08-10 12:32 . 2001-08-17 12:52 14720 c:\windows\maxdriver\dac960nt.sys
+ 2004-08-03 21:59 . 2008-04-13 18:31 36736 c:\windows\maxdriver\crusoe.sys
+ 2001-08-17 12:24 . 2004-08-04 04:00 11776 c:\windows\maxdriver\cpqdap01.sys
+ 2004-08-10 12:27 . 2001-08-17 12:52 14976 c:\windows\maxdriver\cpqarray.sys
+ 2006-04-20 11:04 . 2008-04-13 18:36 10240 c:\windows\maxdriver\compbatt.sys
+ 2006-04-20 11:04 . 2008-04-13 18:36 13952 c:\windows\maxdriver\cmbatt.sys
+ 2004-08-10 11:50 . 2008-04-13 19:16 49536 c:\windows\maxdriver\classpnp.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 62976 c:\windows\maxdriver\cdrom.sys
+ 2004-08-10 11:50 . 2008-04-13 19:14 63744 c:\windows\maxdriver\cdfs.sys
+ 2001-08-17 12:52 . 2004-08-04 04:00 18688 c:\windows\maxdriver\cdaudio.sys
+ 2007-12-20 21:00 . 2008-04-13 18:46 17024 c:\windows\maxdriver\ccdecode.sys
+ 2001-08-17 12:52 . 2001-08-17 12:52 13952 c:\windows\maxdriver\cbidf2k.sys
+ 2008-04-13 18:46 . 2008-04-13 18:46 18944 c:\windows\maxdriver\bthusb.sys
+ 2008-04-13 18:46 . 2008-04-13 18:46 36480 c:\windows\maxdriver\bthprint.sys
+ 2008-04-13 18:46 . 2008-04-13 18:46 37888 c:\windows\maxdriver\bthmodem.sys
+ 2008-04-13 18:46 . 2008-04-13 18:46 17024 c:\windows\maxdriver\bthenum.sys
+ 2004-08-10 11:50 . 2008-04-13 18:53 71552 c:\windows\maxdriver\bridge.sys
+ 2006-04-20 10:58 . 2005-08-05 15:32 45312 c:\windows\maxdriver\bcm4sbxp.sys
+ 2006-04-20 11:04 . 2008-04-13 18:36 14208 c:\windows\maxdriver\battc.sys
+ 2007-11-05 20:40 . 2009-11-08 02:04 28424 c:\windows\maxdriver\avgmfx86.sys
+ 2004-08-10 11:50 . 2008-04-13 18:51 55808 c:\windows\maxdriver\atmlane.sys
+ 2004-08-10 11:50 . 2004-08-04 04:00 31360 c:\windows\maxdriver\atmepvc.sys
+ 2004-08-10 11:50 . 2008-04-13 18:51 59904 c:\windows\maxdriver\atmarpc.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 63488 c:\windows\maxdriver\atinxsxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 31744 c:\windows\maxdriver\atinxbxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 73216 c:\windows\maxdriver\atintuxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 13824 c:\windows\maxdriver\atinttxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 28672 c:\windows\maxdriver\atinsnxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 52224 c:\windows\maxdriver\atinraxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 14336 c:\windows\maxdriver\atinpdxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 13824 c:\windows\maxdriver\atinmdxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 57856 c:\windows\maxdriver\atinbtxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 34735 c:\windows\maxdriver\ati1xsxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 29455 c:\windows\maxdriver\ati1xbxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 36463 c:\windows\maxdriver\ati1tuxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 21343 c:\windows\maxdriver\ati1ttxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 26367 c:\windows\maxdriver\ati1snxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 63663 c:\windows\maxdriver\ati1rvxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 30671 c:\windows\maxdriver\ati1raxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 12047 c:\windows\maxdriver\ati1pdxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 11615 c:\windows\maxdriver\ati1mdxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 56623 c:\windows\maxdriver\ati1btxx.sys
+ 2004-08-03 21:59 . 2008-04-13 18:40 96512 c:\windows\maxdriver\atapi.sys
+ 2004-08-10 11:50 . 2008-04-13 18:57 14336 c:\windows\maxdriver\asyncmac.sys
+ 2004-08-10 12:32 . 2001-08-17 12:51 14848 c:\windows\maxdriver\asc3550.sys
+ 2004-08-10 12:32 . 2001-08-17 12:52 22400 c:\windows\maxdriver\asc3350p.sys
+ 2004-08-10 12:32 . 2001-08-17 12:52 26496 c:\windows\maxdriver\asc.sys
+ 2004-08-03 21:58 . 2008-04-13 18:51 60800 c:\windows\maxdriver\arp1394.sys
+ 2006-04-20 11:21 . 2005-08-12 15:50 16128 c:\windows\maxdriver\APPDRV.SYS
+ 2004-08-10 12:32 . 2001-08-17 12:52 12032 c:\windows\maxdriver\amsint.sys
+ 2004-08-03 21:59 . 2008-04-13 18:31 37760 c:\windows\maxdriver\amdk7.sys
+ 2004-08-03 21:59 . 2008-04-13 18:31 37376 c:\windows\maxdriver\amdk6.sys
+ 2004-08-10 12:16 . 2008-04-13 18:36 43008 c:\windows\maxdriver\amdagp.sys
+ 2004-08-10 12:16 . 2008-04-13 18:36 42752 c:\windows\maxdriver\alim1541.sys
+ 2004-08-10 12:25 . 2001-08-17 13:07 56960 c:\windows\maxdriver\aic78xx.sys
+ 2004-08-10 12:25 . 2001-08-17 13:07 55168 c:\windows\maxdriver\aic78u2.sys
+ 2004-08-10 12:24 . 2001-08-17 12:52 12800 c:\windows\maxdriver\aha154x.sys
+ 2004-08-10 12:22 . 2008-04-13 18:36 44928 c:\windows\maxdriver\agpcpq.sys
+ 2004-08-10 11:58 . 2008-04-13 18:36 42368 c:\windows\maxdriver\agp440.sys
+ 2006-04-20 11:22 . 2006-04-20 11:22 21275 c:\windows\maxdriver\AegisP.sys
+ 2001-08-17 12:57 . 2004-08-04 04:00 11648 c:\windows\maxdriver\acpiec.sys
+ 2004-08-10 12:32 . 2001-08-17 12:52 23552 c:\windows\maxdriver\ABP480N5.SYS
+ 2006-04-20 11:04 . 2008-04-13 18:46 53376 c:\windows\maxdriver\1394bus.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 4352 c:\windows\maxdriver\wmilib.sys
+ 2007-11-01 12:29 . 2008-04-13 18:36 8832 c:\windows\maxdriver\wmiacpi.sys
+ 2004-08-10 12:36 . 2008-04-13 18:40 5376 c:\windows\maxdriver\viaide.sys
+ 2001-08-17 13:03 . 2004-08-04 04:00 4736 c:\windows\maxdriver\usbd.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 8573 c:\windows\maxdriver\tosrfec.sys
+ 2004-08-10 12:36 . 2001-08-17 12:51 4992 c:\windows\maxdriver\toside.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 3712 c:\windows\maxdriver\toshidpt.sys
+ 2004-08-03 21:58 . 2008-04-13 18:39 4352 c:\windows\maxdriver\swenum.sys
+ 2006-04-20 11:29 . 2004-07-14 10:29 5627 c:\windows\maxdriver\sscdbhk5.sys
+ 2006-04-20 11:19 . 2008-04-13 18:45 6272 c:\windows\maxdriver\splitter.sys
+ 2008-04-13 18:36 . 2008-04-13 18:36 5888 c:\windows\maxdriver\smbali.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 5888 c:\windows\maxdriver\rootmdm.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 4224 c:\windows\maxdriver\rdpcdd.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 8832 c:\windows\maxdriver\rasacd.sys
+ 2004-08-10 12:28 . 2001-08-17 13:07 5504 c:\windows\maxdriver\perc2hib.sys
+ 2001-08-17 12:51 . 2001-08-17 12:51 3328 c:\windows\maxdriver\pciide.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 6784 c:\windows\maxdriver\parvdm.sys
+ 2001-08-17 12:57 . 2004-08-04 04:00 3456 c:\windows\maxdriver\oprghdlr.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 2944 c:\windows\maxdriver\null.sys
+ 2007-12-20 21:00 . 2008-04-13 18:39 5504 c:\windows\maxdriver\mstee.sys
+ 2006-04-20 11:19 . 2008-04-13 18:39 4992 c:\windows\maxdriver\mspqm.sys
+ 2006-04-20 11:19 . 2008-04-13 18:39 5376 c:\windows\maxdriver\mspclock.sys
+ 2006-04-20 11:19 . 2008-04-13 18:39 7552 c:\windows\maxdriver\mskssrv.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 4224 c:\windows\maxdriver\mnmdd.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 7680 c:\windows\maxdriver\mcd.sys
+ 2004-08-10 11:58 . 2008-04-13 18:40 5504 c:\windows\maxdriver\intelide.sys
+ 2004-08-10 12:30 . 2008-04-13 18:41 8576 c:\windows\maxdriver\i2omgmt.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 7936 c:\windows\maxdriver\fs_rec.sys
+ 2006-04-20 11:04 . 2001-08-17 12:46 6400 c:\windows\maxdriver\enum1394.sys
+ 2004-08-10 11:51 . 2004-08-04 04:00 3328 c:\windows\maxdriver\dxgthk.sys
+ 2006-04-20 11:19 . 2008-04-13 18:45 2944 c:\windows\maxdriver\drmkaud.sys
+ 2004-08-10 11:50 . 2004-08-04 04:00 5888 c:\windows\maxdriver\dmload.sys
+ 2004-08-10 12:34 . 2001-08-17 12:51 6656 c:\windows\maxdriver\cmdide.sys
+ 2008-01-03 19:45 . 2006-10-18 02:00 2560 c:\windows\maxdriver\cdralw2k.sys
+ 2008-01-03 19:45 . 2006-10-18 02:00 2432 c:\windows\maxdriver\cdr4_xp.sys
+ 2004-08-10 12:31 . 2001-08-17 12:52 7680 c:\windows\maxdriver\cd20xrnt.sys
+ 2004-08-10 11:50 . 2004-08-04 04:00 4224 c:\windows\maxdriver\beep.sys
+ 2004-08-10 11:59 . 2001-08-17 12:59 3072 c:\windows\maxdriver\audstub.sys
+ 2006-04-20 11:26 . 2006-04-20 11:26 8552 c:\windows\maxdriver\asctrm.sys
+ 2004-08-10 12:34 . 2001-08-17 12:51 5248 c:\windows\maxdriver\aliide.sys
+ 2008-04-13 18:46 . 2008-04-13 18:46 121984 c:\windows\maxdriver\usbvideo.sys
+ 2004-08-03 22:08 . 2008-04-13 18:45 143872 c:\windows\maxdriver\usbport.sys
+ 2004-08-10 11:51 . 2008-04-13 18:39 384768 c:\windows\maxdriver\update.sys
+ 2009-12-26 03:53 . 2009-12-26 03:53 223440 c:\windows\maxdriver\truecrypt.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 160672 c:\windows\maxdriver\tosrfpcc.sys
+ 2006-02-01 18:08 . 2006-02-01 18:08 108800 c:\windows\maxdriver\tosrfbd.sys
+ 2004-08-10 11:51 . 2008-06-20 11:08 225856 c:\windows\maxdriver\tcpip6.sys
+ 2004-08-10 11:51 . 2008-06-20 11:51 361600 c:\windows\maxdriver\tcpip.sys
+ 2006-04-20 11:21 . 2005-11-29 03:36 191936 c:\windows\maxdriver\SynTP.sys
+ 2006-04-20 10:56 . 2009-12-31 16:50 353792 c:\windows\maxdriver\srv.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 404990 c:\windows\maxdriver\slntamr.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 129535 c:\windows\maxdriver\slnt7554.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 166912 c:\windows\maxdriver\s3gnbm.sys
+ 2004-08-10 11:51 . 2008-05-08 14:02 203136 c:\windows\maxdriver\rmcast.sys
+ 2006-04-20 10:58 . 2005-07-14 21:28 307968 c:\windows\maxdriver\rixdptsk.sys
+ 2004-08-10 12:01 . 2008-04-14 00:13 139656 c:\windows\maxdriver\rdpwd.sys
+ 2004-08-10 12:01 . 2008-04-13 18:32 196224 c:\windows\maxdriver\rdpdr.sys
+ 2004-08-10 11:51 . 2008-04-13 19:28 175744 c:\windows\maxdriver\rdbss.sys
+ 2004-03-16 10:58 . 2008-04-13 19:19 146048 c:\windows\maxdriver\portcls.sys
+ 2004-08-03 22:07 . 2008-04-13 18:36 120192 c:\windows\maxdriver\pcmcia.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 180360 c:\windows\maxdriver\ntmtlfax.sys
+ 2004-08-10 11:51 . 2008-04-13 19:15 574976 c:\windows\maxdriver\ntfs.sys
+ 2004-08-10 11:51 . 2008-04-13 19:21 162816 c:\windows\maxdriver\netbt.sys
+ 2004-08-10 11:51 . 2008-04-13 19:20 182656 c:\windows\maxdriver\ndis.sys
+ 2004-08-10 11:51 . 2008-04-13 19:17 105344 c:\windows\maxdriver\mup.sys
+ 2008-10-08 00:31 . 2004-08-03 21:29 452736 c:\windows\maxdriver\mtxparhm.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 126686 c:\windows\maxdriver\mtlmnt5.sys
+ 2006-04-20 10:56 . 2009-12-04 18:22 455424 c:\windows\maxdriver\mrxsmb.sys
+ 2004-08-10 11:51 . 2008-04-13 18:32 180608 c:\windows\maxdriver\mrxdav.sys
+ 2004-08-03 22:15 . 2008-04-13 19:16 141056 c:\windows\maxdriver\ks.sys
+ 2006-04-20 11:19 . 2008-04-13 18:45 172416 c:\windows\maxdriver\kmixer.sys
+ 2004-08-10 11:51 . 2008-04-13 18:57 152832 c:\windows\maxdriver\ipnat.sys
+ 2004-08-03 22:00 . 2009-10-20 16:20 265728 c:\windows\maxdriver\http.sys
+ 2006-04-20 10:58 . 2005-12-01 06:40 192512 c:\windows\maxdriver\HSXHWAZL.sys
+ 2006-04-20 10:58 . 2005-12-01 06:40 936960 c:\windows\maxdriver\HSX_DPV.sys
+ 2006-04-20 10:58 . 2005-12-01 06:40 669696 c:\windows\maxdriver\HSX_CNXT.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 685056 c:\windows\maxdriver\hsfcxts2.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 220032 c:\windows\maxdriver\hsfbs2s2.sys
+ 2004-08-12 16:45 . 2004-08-12 16:45 113664 c:\windows\maxdriver\Hdaudio.sys
+ 2004-08-12 16:45 . 2008-04-13 16:36 144384 c:\windows\maxdriver\hdaudbus.sys
+ 2001-08-17 12:52 . 2001-08-17 12:52 125056 c:\windows\maxdriver\ftdisk.sys
+ 2004-08-10 12:02 . 2008-04-13 18:32 129792 c:\windows\maxdriver\fltmgr.sys
+ 2004-08-10 11:51 . 2008-04-13 19:14 143744 c:\windows\maxdriver\fastfat.sys
+ 2004-08-10 11:59 . 2001-08-17 11:12 117760 c:\windows\maxdriver\e100b325.sys
+ 2004-08-10 11:50 . 2008-04-13 18:44 153344 c:\windows\maxdriver\dmio.sys
+ 2004-08-10 11:50 . 2008-04-13 18:44 799744 c:\windows\maxdriver\dmboot.sys
+ 2004-08-10 12:32 . 2001-08-17 12:52 179584 c:\windows\maxdriver\dac2w2k.sys
+ 2001-08-17 13:02 . 2004-08-04 04:00 262528 c:\windows\maxdriver\cinemst2.sys
+ 2008-04-13 18:46 . 2008-06-13 11:05 272128 c:\windows\maxdriver\bthport.sys
+ 2008-04-13 18:51 . 2008-04-13 18:51 101120 c:\windows\maxdriver\bthpan.sys
+ 2008-07-25 20:49 . 2009-11-10 09:13 360584 c:\windows\maxdriver\avgtdix.sys
+ 2008-07-25 20:49 . 2009-11-08 02:04 333192 c:\windows\maxdriver\avgldx86.sys
+ 2004-08-10 11:50 . 2004-08-04 04:00 352256 c:\windows\maxdriver\atmuni.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 104960 c:\windows\maxdriver\atinrvxx.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 701440 c:\windows\maxdriver\ati2mtag.sys
+ 2008-10-08 00:28 . 2004-08-03 21:29 327040 c:\windows\maxdriver\ati2mtaa.sys
+ 2004-08-10 11:50 . 2008-08-14 10:04 138496 c:\windows\maxdriver\afd.sys
+ 2006-04-20 11:19 . 2008-04-13 16:39 142592 c:\windows\maxdriver\aec.sys
+ 2004-08-10 12:25 . 2001-08-17 13:07 101888 c:\windows\maxdriver\adpu160m.sys
+ 2004-08-03 22:07 . 2008-04-13 18:36 187776 c:\windows\maxdriver\acpi.sys
+ 2006-04-20 10:58 . 2005-12-04 15:55 1428096 c:\windows\maxdriver\w39n51.sys
+ 2006-04-20 10:58 . 2005-11-16 20:36 1047816 c:\windows\maxdriver\sthda.sys
+ 2010-02-26 14:03 . 2009-12-11 21:48 1041920 c:\windows\maxdriver\pevFind.exe
+ 2004-08-10 11:59 . 2004-08-03 21:29 1897408 c:\windows\maxdriver\nv4_mini.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 1309184 c:\windows\maxdriver\mtlstrm.sys
+ 2006-04-20 10:58 . 2005-11-19 03:06 1364030 c:\windows\maxdriver\ialmnt5.sys
+ 2008-10-08 00:31 . 2004-08-03 21:41 1041536 c:\windows\maxdriver\hsfdpsp2.sys
+ 2007-12-20 20:55 . 2007-03-21 15:44 10198144 c:\windows\maxdriver\snpstd3.sys
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-05-28 401408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 397312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-15 839680]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-20 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-11-29 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-28 185872]
"MP10_EnsureFileVer"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Donal\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Donal\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2009-4-18 11000]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-20 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-08 02:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\jre\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\nms\\nmsd.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\pro_comm_msg.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\xtop.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\MD 86149 Notetaker\\Easy note taker.exe"=
"c:\\Documents and Settings\\Donal\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [25/07/2008 20:49 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [25/07/2008 20:49 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [08/11/2009 02:03 285392]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 11:42 64000]
S3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\DRIVERS\PTSimBus.sys –> c:\windows\system32\DRIVERS\PTSimBus.sys [?]
S3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\DRIVERS\PTSimHid.sys –> c:\windows\system32\DRIVERS\PTSimHid.sys [?]
S3 VSPerfDrv;Performance Tools Driver;c:\program files\Microsoft Visual Studio 8\Team Tools\Performance Tools\VSPerfDrv.sys [23/09/2005 02:42 54464]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 07:01 2799808]
— Other Services/Drivers In Memory —
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012Core.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]
2010-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012UA.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]
2010-02-24 c:\windows\Tasks\SyncBack Daily Iomega College 4 Sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]
2010-02-24 c:\windows\Tasks\SyncBack DropBox.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]
2010-02-21 c:\windows\Tasks\SyncBack Weekly HD sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]
2010-02-21 c:\windows\Tasks\SyncBack Weekly Images Backup Iomega.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.mhhe.com/simproject
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=2057
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://en-gb.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-26 14:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0xF77C7BDE]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7541f28
\Driver\ACPI -> ACPI.sys @ 0xf73d4cb8
\Driver\atapi -> atapi.sys @ 0xf738c852
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Bluetooth Device (Personal Area Network) -> SendCompleteHandler -> NDIS.sys @ 0xf7270bb0
PacketIndicateHandler -> NDIS.sys @ 0xf725fa0d
SendHandler -> NDIS.sys @ 0xf7273b40
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\@*& Æ]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
Completion time: 2010-02-26 14:49:07
ComboFix-quarantined-files.txt 2010-02-26 14:49
ComboFix2.txt 2010-02-25 23:20
ComboFix3.txt 2010-02-25 20:20
Pre-Run: 44,051,066,880 bytes free
Post-Run: 44,021,620,736 bytes free
- - End Of File - - 05A96429BF23D5A788200ED8AE7D0B6B
Then I rebooted and ran maxhandle. Here's the log:
Run from C:\Documents and Settings\Donal\My Documents\Downloads\maxhandle.exe on 26/02/2010 at 14:55:14.71
System pid: 4 177C: C:\WINDOWS\system32\config\8monrowg.sav
lsass.exe pid: 1040 540: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 1428 208: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 1716 104: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 2004 214: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
spoolsv.exe pid: 580 13C: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
jqs.exe pid: 876 F0: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
matlabserver.exe pid: 928 B0: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
sqlservr.exe pid: 2064 64: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
CTskMstr.exe pid: 2264 244: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
alg.exe pid: 2428 7C: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
Dropbox.exe pid: 1732 1F4: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
hmm,
this is a very stubborn infection to kill.
let's try this:
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:
Here's how to do that:
Click
Start > Run type
Notepad click
OK.
This will open an empty notepad file:
Copy all the text
inside of the code box -
Press Ctrl+C (or right click on the highlighted section and choose 'copy')
FCopy::
c:\windows\ServicePackFiles\i386\netbt.sys | c:\windows\system32\dllcache\netbt.sys
c:\windows\ServicePackFiles\i386\netbt.sys | c:\windows\system32\drivers\netbt.sys
File::
C:\WINDOWS\system32\config\8monrowg.sav
Now
paste the copied text into the open notepad - press
CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click
File ;
2.Click
Save As … Change the directory to your
desktop ;
3.Change the
Save as type to
"All Files";
4.Type in the file name:
CFScript
5.Click
Save …
[external image: Posted Image]
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe. ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal. When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Try that again,
then post a fresh maxhandle log
Uh oh.
I've had to move to another computer. Combofix ran, and the log said that netbt.sys had been disinfected, removed and replaced. Everything seemed to be running fine, except I noticed there were no hardware-/device-related icons in the icon tray (e.g. there were no networking icons) I rebooted to run maxhandle again. While Windows was loading, I got a BSOD with the following info:
[…]
The problem seems to be caused by the following file: netbt.sys
DRIVER_UNLOADED_WITHOUT_CANCELLING_PENDING_OPERATIONS
[…]
Technical information:
***STOP: 0x000000CE (0xF7797BDE, 0x00000008, 0xF7797BDE, 0x00000000)
netbt.sys
This keeps happening when I restart the computer. I can start Windows in safe mode, but not in safe mode with networking (if I try the latter I get another BSOD saying PAGE_FAULT_IN_NONPAGED_AREA )
I haven't tried starting the Recovery Console but presume I can since Windows is working in safe mode.
OK
boot back into the recovery console and do the following:
at the command prompt type in the following:
copy C:\i386\netbt.sys c:\windows\system32\drivers\netbt.sys
press enter
if it asks you if you wish to overwrite the file press "Y"
then type
copy C:\i386\netbt.sys c:\windows\system32\dllcache\netbt.sys
press enter
agree to the overwrite if asked.
(note the spaces between "copy" and "C:" and then the end of "sys" and the second "c:" )
type exit , to exit the recovery console
now try and boot normally.
When I type that and press enter it says
Access is denied
Before that, when it asks which Windows installation I want to log into, I type 1 and press enter. It doesn't ask for an Administer password, just goes straight to the C:\WINDOWS> prompt
When I restart after the BSOD one of the options I'm given is to start Windows in the Last Known Good Configuration (your most recent settings that worked) . Should I try this?
OK
lets try this first
still in recovery console:
At the command prompt, type the following command and press Enter:
disable netbt
Note the startup type, it should be service_demand_start
if it disables - then try the copy commands from before
then exit and try rebooting
yes,
if that doesn't work try last known good configuration
the startup type was SERVICE_SYSTEM_START AND IT WAS CHANGED TO SERVICE_DISABLED
Access was still denied when I tried the copy command.
Last known good configuration led to the same BSOD.
OK
go back into the Recovery console and try this command:
copy c:\windows\system32\dllcache\netbt.sys c:\windows\system32\drivers\netbt.sys
press enter
then type exit and give normal boot a try
Phew…
OK that worked, was able to boot normally. Waiting to run maxhandle again now. Thanks
OK good
this infection has really got a hold of those drivers, we'll see if this has finally got it