This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Security Suite

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Letting you know up front my wife brought me a pc from work to see if I can clean it, it has the infection Security Suite.

Here is the break down, cannot use the selfhelp because of this:

1. The system is Windows Vista Home Premuim 64 bit Service pack 1
2. Cannot boot to safe mode, will not let me, all it does boots back to normal mode and then the fake av runs
3. Cannot hook up to the internet, thats blocked out.
4. Cannot install any programs and exe.helper will not even work.

So is this system wasted and looking at a complete format ?

Jimbo
Jimbo,
Can you try to download MBAM to a USB device from a working pc?

You could also try it this way.

Print out these instructions as we may need to close every window that is open later in the fix.


It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.


Before we can do anything we must first end the processes that belongs to the fake Antivirus so that it does not interfere with the cleaning procedure. To do this, download the following file to your desktop.


Please download rkill


Once it is downloaded, double-click on the rkill.com in order to automatically attempt to stop any processes associated with Red Cross Antivirus and other Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step. If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by Red Cross Antivirus when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate Red Cross Antivirus . So, please try running Rkill until the malware is no longer running. You will then be able to proceed with the rest of the guide. If you continue having problems running rkill.com, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.

Do not reboot your computer after running rkill as the malware programs will start again.

Next:
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Should have said also, that I could not load up task manager also.

But anyhow, tried the rkill and all a window would do is pop up and go right back out, tried this a few times same result.

Tried to install MBAB and same thing it would kick right back out. So I rebooted the machine and as soon as the windows logo came up, I tried to load up the task manage right away to see what happened. Then it loaded and as soon as I saw the Security Suite, told it to end task.

It stopped the process, so I ran rkill a black window popped up, with something and then it told me to enter, it closed, so I ran the install for MBAB and it loaded, then once it loaded I ran a full scan, was trying to go so fast clicked on wrong one, so I said what the heck let it run.

Got finished, asked for a reboot, but dumb me forgot to not to reboot, but I did and Security Suite popped up again, ugggg.

So I hurried and loaded up the task manager again, it loaded and killed the Security Suite, opened up MBAB again, but this time I hooked it to the net and updated MBAB, it updated and I went for a full scan again. Once finished it asked for a reboot. - - At this point did not know if I should or not, so I went o heck lets go for it.

This time it booted and the Security Suite did not pop up. So this is where I stand atm and looks like nothing else is popping yet, did not hook it back to the net yet, thought I would come here and post the log's to see what next.

Here are the logs

Rkill

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish.
Ran as Alexis on 09/17/2010 at 12:47:02.

Services Stopped:
Processes terminated by Rkill or while it was running:
C:\Users\Alexis\Desktop\rkill.com
Rkill completed on 09/17/2010 at 12:47:06.

First Run with MBAB

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18943

9/17/2010 1:56:11 PM
mbam-log-2010-09-17 (09-13-11).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 279260
Time elapsed: 1 hour(s), 6 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 28
Registry Values Infected: 5
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iwokutu (Trojan.Agent.U) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ibiluxidigiba (Trojan.Agent.U) -> Delete on reboot.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files (x86)\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files (x86)\MyWebSearch\bar\2.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Alexis\Favorites\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\sDIDUNlc.dll (Trojan.Agent.U) -> Delete on reboot.
C:\Users\Alexis\AppData\Local\adiqariwi.dll (Trojan.Agent.U) -> Delete on reboot.
C:\Users\Alexis\AppData\Local\Temp\0.6296273774854847.exe (Trojan.Dropper) -> Quarantined and deleted successfully.


2nd run with MBAB

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4639

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18943

9/17/2010 2:58:55 PM
mbam-log-2010-09-17 (10-33-35).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 298697
Time elapsed: 1 hour(s), 2 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\enjdsemt (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\giqrmnuv (Rogue.SecuritySuite) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Alexis\AppData\Local\hcpfuknkv\fhvdepmuqiw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\vpreutbtn\fxoutfyuqiw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0GY7A7KW\jjdlsnvtov[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0GY7A7KW\lpkez[1].htm (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4DA30K9M\ofmupwryg[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4DA30K9M\sun[1].db (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TUJJIIJR\lpkezhfmu[1].htm (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TUJJIIJR\vvqkfy[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2NSYS8WX\WebfettiInitialSetup1.0.1.1[1].exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DVH4K8BZ\ZwinkyInitialSetup1.0.1.1[1].exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Temp\hogw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Temp\lqxn.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Users\Alexis\Desktop\o.dat (Trojan.Hiloti) -> Quarantined and deleted successfully.

Like I said it running and the pop up not comming up yet, I am able to get into control panel, and able to look at the hard drive and what not, like doing the things you can but I am going to leave the machine running.

I have to go run and take care of cutting grass in the yard and at the church, may log on tommrow to read and see what to do, it not I be by Monday Morning to see what next.

Jimbo
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.



Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Please read carefully and follow these steps.
  • Please download TDSSKiller.zip
    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • Press Start Scan
      • Only if Malicious objects are found then ensure Cure is selected
      • Then click Continue > Reboot now
    • Copy and paste the log in your next reply
      • A copy of the log will be saved automatically to the root directory, root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
    please post the contents of that log TDSSKiller and GooredFix log.
Ok here is the contents of Goored Fix log: GooredFix by jpshortstuff (03.07.10.1) Log created at 10:40 on 20/09/2010 (Alexis) Firefox version [Unable to determine] ========== GooredScan ========== Removing Orphan: "[removed]"="C:\Program Files (x86)\MyWebSearch\bar\firefox\" -> Success! ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [09:09 04/12/2009] -=E.O.F=- Here is the Content of TDSSkiller log: 2010/09/20 10:41:41.0545 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44 2010/09/20 10:41:41.0545 ================================================================================ 2010/09/20 10:41:41.0545 SystemInfo: 2010/09/20 10:41:41.0545 2010/09/20 10:41:41.0545 OS Version: 6.0.6001 ServicePack: 1.0 2010/09/20 10:41:41.0545 Product type: Workstation 2010/09/20 10:41:41.0545 ComputerName: ALEXIS-PC 2010/09/20 10:41:41.0545 UserName: Alexis 2010/09/20 10:41:41.0545 Windows directory: C:\Windows 2010/09/20 10:41:41.0545 System windows directory: C:\Windows 2010/09/20 10:41:41.0545 Running under WOW64 2010/09/20 10:41:41.0545 Processor architecture: Intel x64 2010/09/20 10:41:41.0545 Number of processors: 2 2010/09/20 10:41:41.0545 Page size: 0x1000 2010/09/20 10:41:41.0545 Boot type: Normal boot 2010/09/20 10:41:41.0545 ================================================================================ 2010/09/20 10:41:41.0545 Utility is running under WOW64 2010/09/20 10:41:41.0764 Initialize success 2010/09/20 10:41:47.0146 ================================================================================ 2010/09/20 10:41:47.0146 Scan started 2010/09/20 10:41:47.0146 Mode: Manual; 2010/09/20 10:41:47.0146 ================================================================================ 2010/09/20 10:41:48.0518 ACPI (8c99ed256a889d647935a97c543b7b85) C:\Windows\system32\drivers\acpi.sys 2010/09/20 10:41:48.0659 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys 2010/09/20 10:41:48.0784 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys 2010/09/20 10:41:48.0830 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys 2010/09/20 10:41:48.0955 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys 2010/09/20 10:41:49.0111 AFD (db37041ab857abc7e179e856d8e1582c) C:\Windows\system32\drivers\afd.sys 2010/09/20 10:41:49.0236 AgereSoftModem (6051b172930f3b2723d04c555f7ec55a) C:\Windows\system32\DRIVERS\agrsm64.sys 2010/09/20 10:41:49.0361 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys 2010/09/20 10:41:49.0517 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys 2010/09/20 10:41:49.0688 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys 2010/09/20 10:41:49.0735 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys 2010/09/20 10:41:49.0876 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys 2010/09/20 10:41:50.0016 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys 2010/09/20 10:41:50.0172 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys 2010/09/20 10:41:50.0312 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/09/20 10:41:50.0422 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys 2010/09/20 10:41:50.0702 AvgLdx64 (033157ae7f8067b85e94635491b69b03) C:\Windows\system32\Drivers\avgldx64.sys 2010/09/20 10:41:50.0843 AvgMfx64 (826e5265069f43069fcdbec6a4ea3f3c) C:\Windows\system32\Drivers\avgmfx64.sys 2010/09/20 10:41:50.0983 AvgTdiA (defebee78a1d11a9c5364cfe0536f795) C:\Windows\system32\Drivers\avgtdia.sys 2010/09/20 10:41:51.0139 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys 2010/09/20 10:41:51.0264 bowser (8b2b19031d0aeade6e1b933df1acba7e) C:\Windows\system32\DRIVERS\bowser.sys 2010/09/20 10:41:51.0404 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys 2010/09/20 10:41:51.0514 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys 2010/09/20 10:41:51.0670 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys 2010/09/20 10:41:51.0716 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys 2010/09/20 10:41:51.0841 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys 2010/09/20 10:41:51.0966 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys 2010/09/20 10:41:52.0060 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys 2010/09/20 10:41:52.0106 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys 2010/09/20 10:41:52.0200 cdrom (3b2fb35363423ed60c8fbf15fc8680bd) C:\Windows\system32\DRIVERS\cdrom.sys 2010/09/20 10:41:52.0325 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys 2010/09/20 10:41:52.0450 CLFS (caeda2572b7042b11062f327f099251d) C:\Windows\system32\CLFS.sys 2010/09/20 10:41:52.0637 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys 2010/09/20 10:41:52.0762 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys 2010/09/20 10:41:52.0918 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys 2010/09/20 10:41:53.0136 DfsC (bd4acc56e477ad7419cbe90fceeb621b) C:\Windows\system32\Drivers\dfsc.sys 2010/09/20 10:41:53.0276 disk (2dc415fc05fb8a079f896cbbacb19324) C:\Windows\system32\drivers\disk.sys 2010/09/20 10:41:53.0417 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys 2010/09/20 10:41:53.0542 DXGKrnl (412964040ce920ff83aff6b5b551bf99) C:\Windows\System32\drivers\dxgkrnl.sys 2010/09/20 10:41:53.0651 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys 2010/09/20 10:41:53.0822 e1yexpress (bddc6f6c49633aa85a30a989418e30f4) C:\Windows\system32\DRIVERS\e1y60x64.sys 2010/09/20 10:41:53.0947 Ecache (7343d950a34a95dcb7441642e3e6beef) C:\Windows\system32\drivers\ecache.sys 2010/09/20 10:41:54.0134 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys 2010/09/20 10:41:54.0259 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys 2010/09/20 10:41:54.0337 exfat (2a546b9a84658b0554b1ec35cd9adaf5) C:\Windows\system32\drivers\exfat.sys 2010/09/20 10:41:54.0446 fastfat (fe731d345ed9eeabbc72a59b35941834) C:\Windows\system32\drivers\fastfat.sys 2010/09/20 10:41:54.0587 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys 2010/09/20 10:41:54.0649 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys 2010/09/20 10:41:54.0743 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys 2010/09/20 10:41:54.0774 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/09/20 10:41:54.0868 FltMgr (7dacf1a3a4219575070c6dc7c957428a) C:\Windows\system32\drivers\fltmgr.sys 2010/09/20 10:41:54.0914 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys 2010/09/20 10:41:55.0024 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys 2010/09/20 10:41:55.0180 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys 2010/09/20 10:41:55.0336 HDAudBus (0c0d0f8a3ff09ecc81963d09ec6a0a84) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/09/20 10:41:55.0445 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys 2010/09/20 10:41:55.0570 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys 2010/09/20 10:41:55.0679 HidUsb (128e2da8483fdd4dd0c7b3f9abd6f323) C:\Windows\system32\DRIVERS\hidusb.sys 2010/09/20 10:41:55.0835 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys 2010/09/20 10:41:55.0960 HTTP (e690736da6c543f5d99c8fa27bea31db) C:\Windows\system32\drivers\HTTP.sys 2010/09/20 10:41:56.0038 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys 2010/09/20 10:41:56.0178 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/09/20 10:41:56.0365 iaStor (756879fa65978df948437ce3fd1eaccd) C:\Windows\system32\DRIVERS\iaStor.sys 2010/09/20 10:41:56.0490 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys 2010/09/20 10:41:56.0864 igfx (a124c87cd0b39c9e510e138534468383) C:\Windows\system32\DRIVERS\igdkmd64.sys 2010/09/20 10:41:57.0145 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys 2010/09/20 10:41:57.0301 IntcAzAudAddService (fdfc40441fac0f3114a974168125279f) C:\Windows\system32\drivers\RTKVHD64.sys 2010/09/20 10:41:57.0426 IntcHdmiAddService (be1cb000c655396c9def09aee3ea2d67) C:\Windows\system32\drivers\IntcHdmi.sys 2010/09/20 10:41:57.0520 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys 2010/09/20 10:41:57.0582 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys 2010/09/20 10:41:57.0691 IpFilterDriver (99b821f5bebd6a3cc3fe564f802ae0fd) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/09/20 10:41:57.0816 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys 2010/09/20 10:41:57.0941 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys 2010/09/20 10:41:58.0050 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys 2010/09/20 10:41:58.0222 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys 2010/09/20 10:41:58.0362 iScsiPrt (49e4ccbf74783fce5d2cc1ff6480e1f4) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/09/20 10:41:58.0487 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys 2010/09/20 10:41:58.0596 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys 2010/09/20 10:41:58.0643 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/09/20 10:41:58.0752 kbdhid (bf8783a5066cfecf45095459e8010fa7) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/09/20 10:41:58.0924 KSecDD (ccdcce6224e1e207e953af826b98a9d9) C:\Windows\system32\Drivers\ksecdd.sys 2010/09/20 10:41:59.0080 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys 2010/09/20 10:41:59.0251 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys 2010/09/20 10:41:59.0392 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys 2010/09/20 10:41:59.0438 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys 2010/09/20 10:41:59.0594 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys 2010/09/20 10:41:59.0704 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys 2010/09/20 10:41:59.0766 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys 2010/09/20 10:41:59.0891 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys 2010/09/20 10:42:00.0016 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys 2010/09/20 10:42:00.0156 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys 2010/09/20 10:42:00.0250 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys 2010/09/20 10:42:00.0390 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys 2010/09/20 10:42:00.0468 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys 2010/09/20 10:42:00.0593 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys 2010/09/20 10:42:00.0718 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys 2010/09/20 10:42:00.0780 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys 2010/09/20 10:42:00.0889 MRxDAV (fe2706c15f8345c342820e4e4583fea0) C:\Windows\system32\drivers\mrxdav.sys 2010/09/20 10:42:01.0014 mrxsmb (937512d4321b4f5218ad5a0aebf2b5cc) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/09/20 10:42:01.0139 mrxsmb10 (152b673b3984356390e7baa4199f1114) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/09/20 10:42:01.0217 mrxsmb20 (65e45c26ba6fd66cd2889913f73823ef) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/09/20 10:42:01.0357 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys 2010/09/20 10:42:01.0404 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys 2010/09/20 10:42:01.0591 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys 2010/09/20 10:42:01.0732 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys 2010/09/20 10:42:01.0950 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys 2010/09/20 10:42:02.0044 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/09/20 10:42:02.0106 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys 2010/09/20 10:42:02.0246 MsRPC (b8e32e6103fbba9fbb1d0c11ff0d13b5) C:\Windows\system32\drivers\MsRPC.sys 2010/09/20 10:42:02.0293 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/09/20 10:42:02.0402 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys 2010/09/20 10:42:02.0496 Mup (ddf133501f68d6988a0f55dfa88637b4) C:\Windows\system32\Drivers\mup.sys 2010/09/20 10:42:02.0590 mwlPSDFilter (fb3d139ad1ac117b99a16042c1dd02d1) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys 2010/09/20 10:42:02.0668 mwlPSDNServ (bf3f82a3ea6fbb6657dfe081a6ba4e2e) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys 2010/09/20 10:42:02.0746 mwlPSDVDisk (da24873dcb2891805692a03bad1e34b4) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys 2010/09/20 10:42:02.0964 NativeWifiP (73b99c98fa3a2ed1566e02d6fe1913a5) C:\Windows\system32\DRIVERS\nwifi.sys 2010/09/20 10:42:03.0151 NDIS (2a2ee457af36c5c9a6808c768bd3a12b) C:\Windows\system32\drivers\ndis.sys 2010/09/20 10:42:03.0292 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/09/20 10:42:03.0354 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/09/20 10:42:03.0463 NdisWan (52e3e8e35101399be9b2938c992aa087) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/09/20 10:42:03.0604 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys 2010/09/20 10:42:03.0697 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys 2010/09/20 10:42:03.0775 netbt (7a29ca243a629230799754162d80120f) C:\Windows\system32\DRIVERS\netbt.sys 2010/09/20 10:42:03.0931 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys 2010/09/20 10:42:04.0009 Npfs (b06154e2a2c91e9be5599fca53bc4cd0) C:\Windows\system32\drivers\Npfs.sys 2010/09/20 10:42:04.0087 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys 2010/09/20 10:42:04.0228 Ntfs (fe86ba5ac3b50e2ca911e9c60c07b638) C:\Windows\system32\drivers\Ntfs.sys 2010/09/20 10:42:04.0352 NTIDrvr (7d397449aaf52b0e7c79b64f6ad4473e) C:\Windows\system32\Drivers\NTIDrvr.sys 2010/09/20 10:42:04.0430 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys 2010/09/20 10:42:04.0555 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys 2010/09/20 10:42:04.0680 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys 2010/09/20 10:42:04.0789 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys 2010/09/20 10:42:04.0898 ohci1394 (1b30103fde512915a9214b108b6e7a9c) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/09/20 10:42:05.0039 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys 2010/09/20 10:42:05.0086 partmgr (5ab40c36894f4c06bdab0c9a2fba282d) C:\Windows\system32\drivers\partmgr.sys 2010/09/20 10:42:05.0210 pci (2a5b2a51559066ea84742909b5b2cd69) C:\Windows\system32\drivers\pci.sys 2010/09/20 10:42:05.0304 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys 2010/09/20 10:42:05.0382 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys 2010/09/20 10:42:05.0507 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys 2010/09/20 10:42:05.0741 PptpMiniport (f5739f2c6db2534c384ad5150808e8f5) C:\Windows\system32\DRIVERS\raspptp.sys 2010/09/20 10:42:05.0788 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys 2010/09/20 10:42:05.0928 PSched (0e0e205a296095fe4c631e6a4775ad6c) C:\Windows\system32\DRIVERS\pacer.sys 2010/09/20 10:42:06.0115 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys 2010/09/20 10:42:06.0240 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys 2010/09/20 10:42:06.0302 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys 2010/09/20 10:42:06.0380 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys 2010/09/20 10:42:06.0552 Rasl2tp (3b9085f91ef00abd15a6f36570e90e12) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/09/20 10:42:06.0661 RasPppoe (2ce1703c27196094fb6e4c6e439f2c21) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/09/20 10:42:06.0739 RasSstp (fcd04fa67e8b40fa0ad361dd38593942) C:\Windows\system32\DRIVERS\rassstp.sys 2010/09/20 10:42:06.0833 rdbss (33fa5b6136d92ee0f53f021c79091300) C:\Windows\system32\DRIVERS\rdbss.sys 2010/09/20 10:42:06.0942 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/09/20 10:42:07.0051 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys 2010/09/20 10:42:07.0160 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys 2010/09/20 10:42:07.0207 RDPWD (7747082f672aa2846235c9cea42e2e72) C:\Windows\system32\drivers\RDPWD.sys 2010/09/20 10:42:07.0410 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys 2010/09/20 10:42:07.0550 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys 2010/09/20 10:42:07.0706 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 2010/09/20 10:42:07.0800 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys 2010/09/20 10:42:07.0878 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys 2010/09/20 10:42:08.0003 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys 2010/09/20 10:42:08.0112 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys 2010/09/20 10:42:08.0174 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys 2010/09/20 10:42:08.0237 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys 2010/09/20 10:42:08.0330 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys 2010/09/20 10:42:08.0424 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys 2010/09/20 10:42:08.0518 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys 2010/09/20 10:42:08.0580 Smb (41eb2e8e005feedcafce301983eff932) C:\Windows\system32\DRIVERS\smb.sys 2010/09/20 10:42:08.0689 spldr (f9cb0672162f7f04248e2b82c1ff4617) C:\Windows\system32\drivers\spldr.sys 2010/09/20 10:42:08.0798 srv (4adb9a620ff071ee7d17487a87861659) C:\Windows\system32\DRIVERS\srv.sys 2010/09/20 10:42:08.0954 srv2 (2aea7a85ceb33abb332d35617990f50b) C:\Windows\system32\DRIVERS\srv2.sys 2010/09/20 10:42:09.0095 srvnet (a93df8babf7c7b9637a76e0eae5744b7) C:\Windows\system32\DRIVERS\srvnet.sys 2010/09/20 10:42:09.0251 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys 2010/09/20 10:42:09.0298 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys 2010/09/20 10:42:09.0422 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys 2010/09/20 10:42:09.0469 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys 2010/09/20 10:42:09.0688 Tcpip (7d86275fb640011b372fd566c0eafa8d) C:\Windows\system32\drivers\tcpip.sys 2010/09/20 10:42:09.0859 Tcpip6 (7d86275fb640011b372fd566c0eafa8d) C:\Windows\system32\DRIVERS\tcpip.sys 2010/09/20 10:42:09.0968 tcpipreg (c29d4b3b08ad0b7e8564814e4ff6a57b) C:\Windows\system32\drivers\tcpipreg.sys 2010/09/20 10:42:10.0015 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys 2010/09/20 10:42:10.0156 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys 2010/09/20 10:42:10.0218 tdx (8c39c72e0e853de04748c0337d9b9216) C:\Windows\system32\DRIVERS\tdx.sys 2010/09/20 10:42:10.0327 TermDD (3f0ebf6ee609f2a276c0d5faf244ec90) C:\Windows\system32\DRIVERS\termdd.sys 2010/09/20 10:42:10.0452 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/09/20 10:42:10.0499 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys 2010/09/20 10:42:10.0624 tunnel (2dc2c423572946e9a3131425bda73cb6) C:\Windows\system32\DRIVERS\tunnel.sys 2010/09/20 10:42:10.0686 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys 2010/09/20 10:42:10.0826 UBHelper (00c8ce31657624a125fdb90efd554371) C:\Windows\system32\drivers\UBHelper.sys 2010/09/20 10:42:10.0951 udfs (eca6629e33f122afff18a2ab7c3eb033) C:\Windows\system32\DRIVERS\udfs.sys 2010/09/20 10:42:11.0076 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys 2010/09/20 10:42:11.0154 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys 2010/09/20 10:42:11.0248 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys 2010/09/20 10:42:11.0294 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys 2010/09/20 10:42:11.0419 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys 2010/09/20 10:42:11.0560 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/09/20 10:42:11.0669 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys 2010/09/20 10:42:11.0794 usbehci (da6d8d8ed0a53c63ac6f4bd40fe83fbe) C:\Windows\system32\DRIVERS\usbehci.sys 2010/09/20 10:42:11.0840 usbhub (99045369ae3216216573d0775fd7ed56) C:\Windows\system32\DRIVERS\usbhub.sys 2010/09/20 10:42:11.0950 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys 2010/09/20 10:42:11.0996 usbprint (acfee697af477021bb3ec78c5431fed2) C:\Windows\system32\drivers\usbprint.sys 2010/09/20 10:42:12.0106 USBSTOR (586d9876a4945779c8eea926c0d16889) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/09/20 10:42:12.0152 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/09/20 10:42:12.0293 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/09/20 10:42:12.0340 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys 2010/09/20 10:42:12.0464 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys 2010/09/20 10:42:12.0480 volmgr (793d9b32a1c462c91f6f70358283ac97) C:\Windows\system32\drivers\volmgr.sys 2010/09/20 10:42:12.0527 volmgrx (5aa217da5dc4ff5b9ac9ab86563b3223) C:\Windows\system32\drivers\volmgrx.sys 2010/09/20 10:42:12.0636 volsnap (de4307412d98050239026e56a7dff3c0) C:\Windows\system32\drivers\volsnap.sys 2010/09/20 10:42:12.0730 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys 2010/09/20 10:42:12.0854 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys 2010/09/20 10:42:12.0917 Wanarp (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/20 10:42:12.0948 Wanarpv6 (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/20 10:42:13.0010 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys 2010/09/20 10:42:13.0198 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys 2010/09/20 10:42:13.0400 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/09/20 10:42:13.0494 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys 2010/09/20 10:42:13.0619 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/09/20 10:42:13.0681 ================================================================================ 2010/09/20 10:42:13.0681 Scan finished 2010/09/20 10:42:13.0681 ================================================================================ 2010/09/20 10:42:49.0202 Deinitialize success End of the logs.
Ok here is the log from run 3 of MBAM Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4639 Windows 6.0.6001 Service Pack 1 Internet Explorer 8.0.6001.18943 9/20/2010 1:40:44 PM mbam-log-2010-09-20 (13-40-44).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 280091 Time elapsed: 1 hour(s), 2 minute(s), 12 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) This machine did not have a Anti-Virus software on it, so I installed AVG, did not run a scan yet, but this popped up: Threat detected: C:users\alexis\appdata\local\microsoft\windows\temporary internet files\low\content .ie5\2nsys8wx\in.[1]htm - not sure what that means, again i did not run a scan yet using AVG. Posted this on the machine that was infected and looks like it running ok except for that msg and not running the scan, also java wants to update as does windows so I am waiting for futher instructions before doing anything.
Delete this folder
C:users\alexis\appdata\local\microsoft\windows\temporary internet files\low

I think ATF will run on a 64bit.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Delete this folder
C:users\alexis\appdata\local\microsoft\windows\temporary internet files\low

I think ATF will run on a 64bit.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.



Ok all done, so far so good all looks to be running ok for as speed wise it's getting it done heheh.

Jimbo1

Let me know how it goes, Jimbo :thumbup:



Guess I have to say, machine is running, on the net, rebooted quite a few times so I ran avg and no threats found, so I ran ATF one more time and also did a ccleaner, not the registry part tho and I going have to give this puppy a all clear. As I said for a 64 bit os and 4 gigs of ram this machine is getting it now.

Jimbo

Glad to see that :thumbup:

You should be good to go.



Good, thanks for the help, the girl at the wifes office would be happy now, lets hope this nasty hit to the 64 bit os does not hit again. Told wife if she plays with fire be perpare to get burnt.

Jimbo

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI