This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe taking up 100%

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Tomk, Here are the logs aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-20 21:58:10 —————————– 21:58:10.698 OS Version: Windows 6.1.7601 Service Pack 1 21:58:10.699 Number of processors: 2 586 0x1706 21:58:10.700 ComputerName: SYNTHESIZE UserName: Zero 21:58:13.746 Initialize success 22:34:55.038 AVAST engine defs: 11092000 22:35:22.634 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 22:35:22.637 Disk 0 Vendor: Hitachi_HDS721010CLA332 JP4OA3MA Size: 953869MB BusType: 3 22:35:22.641 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-3 22:35:22.648 Disk 1 Vendor: WDC_WD3200AAJS-65B4A0 01.03A01 Size: 305245MB BusType: 3 22:35:24.663 Disk 1 MBR read successfully 22:35:24.671 Disk 1 MBR scan 22:35:24.695 Disk 1 Windows 7 default MBR code 22:35:24.701 Disk 1 MBR hidden 22:35:24.707 Disk 1 scanning sectors +625139712 22:35:24.788 Disk 1 scanning C:\Windows\system32\drivers 22:35:24.800 Service scanning 22:35:37.262 Modules scanning 22:35:38.535 Disk 1 trace - called modules: 22:35:38.548 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x85e914d0]<< 22:35:38.554 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x85e34a20] 22:35:38.569 3 CLASSPNP.SYS[8918059e] -> nt!IofCallDriver -> [0x859bf918] 22:35:38.576 5 ACPI.sys[836ac3d4] -> nt!IofCallDriver -> \IdeDeviceP2T1L0-3[0x859c0030] 22:35:38.591 \Driver\atapi[0x85e37a50] -> IRP_MJ_CREATE -> 0x85e914d0 22:35:40.144 AVAST engine scan C:\Windows 22:35:40.166 AVAST engine scan C:\Windows\system32 22:35:40.182 AVAST engine scan C:\Windows\system32\drivers 22:35:40.189 AVAST engine scan C:\Users\Zero 22:35:40.207 AVAST engine scan C:\ProgramData 22:35:40.214 Scan finished successfully 22:36:22.967 Disk 1 MBR has been saved successfully to "C:\Users\Zero\Desktop\MBR.dat" 22:36:22.990 The log file has been saved successfully to "C:\Users\Zero\Desktop\aswMBR.txt"
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Also, please let me know how things seem to be running now?
Hi Tomk,

I'm still seeing Ping.exe in the processes list, and it's still taking up 100% of my CPU

and last night my NOD32 picked up something like this

2011/09/21 5:46:09 Startup scanner operating memory Operating memory Win32/Olmarik.TDL4 trojan unable to clean


and my system crashed after startup (Before I even read your latest reply)



Anyway, here are the logs from MBAM



Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7757

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

2011/09/21 7:15:23
mbam-log-2011-09-21 (07-15-23).txt

Scan type: Quick scan
Objects scanned: 198604
Time elapsed: 3 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Interesting… aswMBR should have picked up TDL4 - but it didn't find any.

Let's try this:

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    [external image: Posted Image]

  • If an infected file is detected, the default action will be Cure, click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt".
    Please copy and paste the contents of that file here.
Hi Tomk, I did a scan using TDSSKiller, here are the logs 2011/09/21 10:24:24.0102 5392 TDSS rootkit removing tool 2.5.23.0 Sep 20 2011 08:53:10 2011/09/21 10:24:25.0396 5392 ================================================================================ 2011/09/21 10:24:25.0396 5392 SystemInfo: 2011/09/21 10:24:25.0396 5392 2011/09/21 10:24:25.0396 5392 OS Version: 6.1.7601 ServicePack: 1.0 2011/09/21 10:24:25.0396 5392 Product type: Workstation 2011/09/21 10:24:25.0396 5392 ComputerName: SYNTHESIZE 2011/09/21 10:24:25.0396 5392 UserName: Zero 2011/09/21 10:24:25.0396 5392 Windows directory: C:\Windows 2011/09/21 10:24:25.0396 5392 System windows directory: C:\Windows 2011/09/21 10:24:25.0396 5392 Processor architecture: Intel x86 2011/09/21 10:24:25.0396 5392 Number of processors: 2 2011/09/21 10:24:25.0396 5392 Page size: 0x1000 2011/09/21 10:24:25.0396 5392 Boot type: Normal boot 2011/09/21 10:24:25.0396 5392 ================================================================================ 2011/09/21 10:24:26.0754 5392 Initialize success 2011/09/21 10:24:35.0693 2232 ================================================================================ 2011/09/21 10:24:35.0693 2232 Scan started 2011/09/21 10:24:35.0693 2232 Mode: Manual; 2011/09/21 10:24:35.0693 2232 ================================================================================ 2011/09/21 10:24:36.0519 2232 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 2011/09/21 10:24:36.0629 2232 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 2011/09/21 10:24:36.0691 2232 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 2011/09/21 10:24:36.0753 2232 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\drivers\adp94xx.sys 2011/09/21 10:24:36.0800 2232 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\drivers\adpahci.sys 2011/09/21 10:24:36.0847 2232 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\drivers\adpu320.sys 2011/09/21 10:24:36.0941 2232 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys 2011/09/21 10:24:36.0987 2232 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 2011/09/21 10:24:37.0065 2232 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\drivers\djsvs.sys 2011/09/21 10:24:37.0143 2232 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 2011/09/21 10:24:37.0175 2232 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 2011/09/21 10:24:37.0206 2232 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 2011/09/21 10:24:37.0268 2232 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\drivers\amdk8.sys 2011/09/21 10:24:37.0299 2232 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\drivers\amdppm.sys 2011/09/21 10:24:37.0393 2232 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys 2011/09/21 10:24:37.0455 2232 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\drivers\amdsbs.sys 2011/09/21 10:24:37.0487 2232 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys 2011/09/21 10:24:37.0565 2232 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 2011/09/21 10:24:37.0658 2232 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\drivers\arc.sys 2011/09/21 10:24:37.0689 2232 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\drivers\arcsas.sys 2011/09/21 10:24:37.0767 2232 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/09/21 10:24:37.0830 2232 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 2011/09/21 10:24:37.0892 2232 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\drivers\bxvbdx.sys 2011/09/21 10:24:37.0923 2232 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 2011/09/21 10:24:38.0017 2232 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 2011/09/21 10:24:38.0111 2232 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 2011/09/21 10:24:38.0142 2232 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 2011/09/21 10:24:38.0173 2232 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\BrFiltLo.sys 2011/09/21 10:24:38.0189 2232 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\BrFiltUp.sys 2011/09/21 10:24:38.0220 2232 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 2011/09/21 10:24:38.0251 2232 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 2011/09/21 10:24:38.0267 2232 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 2011/09/21 10:24:38.0298 2232 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 2011/09/21 10:24:38.0313 2232 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\drivers\bthmodem.sys 2011/09/21 10:24:38.0594 2232 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 2011/09/21 10:24:38.0641 2232 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys 2011/09/21 10:24:38.0719 2232 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\drivers\circlass.sys 2011/09/21 10:24:38.0750 2232 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 2011/09/21 10:24:38.0844 2232 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\drivers\CmBatt.sys 2011/09/21 10:24:38.0875 2232 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 2011/09/21 10:24:38.0937 2232 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 2011/09/21 10:24:38.0969 2232 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\drivers\compbatt.sys 2011/09/21 10:24:39.0015 2232 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\DRIVERS\CompositeBus.sys 2011/09/21 10:24:39.0062 2232 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\drivers\crcdisk.sys 2011/09/21 10:24:39.0140 2232 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys 2011/09/21 10:24:39.0203 2232 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 2011/09/21 10:24:39.0234 2232 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 2011/09/21 10:24:39.0296 2232 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\drivers\disk.sys 2011/09/21 10:24:39.0343 2232 dmvsc (2a958ef85db1b61ffca65044fa4bce9e) C:\Windows\system32\drivers\dmvsc.sys 2011/09/21 10:24:39.0452 2232 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 2011/09/21 10:24:39.0546 2232 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys 2011/09/21 10:24:39.0593 2232 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 2011/09/21 10:24:39.0795 2232 eamon (1b5ca1caffc594bd37dcc8d7ef849e0b) C:\Windows\system32\DRIVERS\eamon.sys 2011/09/21 10:24:39.0905 2232 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\drivers\evbdx.sys 2011/09/21 10:24:40.0092 2232 ehdrv (a4241545ecff3ee97041847d83936e1f) C:\Windows\system32\DRIVERS\ehdrv.sys 2011/09/21 10:24:40.0201 2232 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\drivers\elxstor.sys 2011/09/21 10:24:40.0310 2232 epfwwfpr (c7d800414eb8b87e835b5b236b118461) C:\Windows\system32\DRIVERS\epfwwfpr.sys 2011/09/21 10:24:40.0341 2232 epmntdrv (539ca34fbc74ec366a0d751028c32a08) C:\Windows\system32\epmntdrv.sys 2011/09/21 10:24:40.0373 2232 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 2011/09/21 10:24:40.0404 2232 EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\Windows\system32\EuGdiDrv.sys 2011/09/21 10:24:40.0451 2232 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 2011/09/21 10:24:40.0482 2232 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 2011/09/21 10:24:40.0529 2232 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\drivers\fdc.sys 2011/09/21 10:24:40.0591 2232 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 2011/09/21 10:24:40.0607 2232 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 2011/09/21 10:24:40.0638 2232 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\drivers\flpydisk.sys 2011/09/21 10:24:40.0685 2232 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 2011/09/21 10:24:40.0716 2232 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 2011/09/21 10:24:40.0747 2232 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 2011/09/21 10:24:40.0809 2232 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 2011/09/21 10:24:40.0856 2232 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\drivers\gagp30kx.sys 2011/09/21 10:24:41.0075 2232 hamachi (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys 2011/09/21 10:24:41.0121 2232 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 2011/09/21 10:24:41.0184 2232 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 2011/09/21 10:24:41.0277 2232 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/09/21 10:24:41.0293 2232 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\drivers\HidBatt.sys 2011/09/21 10:24:41.0340 2232 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\drivers\hidbth.sys 2011/09/21 10:24:41.0402 2232 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\drivers\hidir.sys 2011/09/21 10:24:41.0480 2232 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys 2011/09/21 10:24:41.0558 2232 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 2011/09/21 10:24:41.0605 2232 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 2011/09/21 10:24:41.0683 2232 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 2011/09/21 10:24:41.0792 2232 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/09/21 10:24:41.0870 2232 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys 2011/09/21 10:24:42.0073 2232 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/09/21 10:24:42.0229 2232 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\drivers\iirsp.sys 2011/09/21 10:24:42.0276 2232 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 2011/09/21 10:24:42.0323 2232 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 2011/09/21 10:24:42.0338 2232 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/09/21 10:24:42.0385 2232 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 2011/09/21 10:24:42.0416 2232 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 2011/09/21 10:24:42.0479 2232 irda (9f7e491fb0ba0f9e370163834fc1fe31) C:\Windows\system32\DRIVERS\irda.sys 2011/09/21 10:24:42.0557 2232 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 2011/09/21 10:24:42.0603 2232 irsir (5896b5ff6332ab2be1582523e9656a67) C:\Windows\system32\DRIVERS\irsir.sys 2011/09/21 10:24:42.0635 2232 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 2011/09/21 10:24:42.0681 2232 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 2011/09/21 10:24:42.0728 2232 ivusb (37412294ea4b70ed8b4a9338ebaeecaa) C:\Windows\system32\DRIVERS\ivusb.sys 2011/09/21 10:24:42.0806 2232 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/09/21 10:24:42.0869 2232 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/09/21 10:24:42.0900 2232 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys 2011/09/21 10:24:42.0931 2232 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 2011/09/21 10:24:43.0009 2232 libusb0 (e2f1dcf4a68cc6cf694fbfba1842f4cd) C:\Windows\system32\drivers\libusb0.sys 2011/09/21 10:24:43.0087 2232 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/09/21 10:24:43.0165 2232 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\drivers\lsi_fc.sys 2011/09/21 10:24:43.0196 2232 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\drivers\lsi_sas.sys 2011/09/21 10:24:43.0227 2232 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\drivers\lsi_sas2.sys 2011/09/21 10:24:43.0274 2232 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\drivers\lsi_scsi.sys 2011/09/21 10:24:43.0337 2232 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 2011/09/21 10:24:43.0368 2232 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\drivers\megasas.sys 2011/09/21 10:24:43.0446 2232 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\drivers\MegaSR.sys 2011/09/21 10:24:43.0555 2232 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\Windows\system32\drivers\Mkd2kfNt.sys 2011/09/21 10:24:43.0586 2232 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\Windows\system32\drivers\Mkd2Nadr.sys 2011/09/21 10:24:43.0649 2232 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 2011/09/21 10:24:43.0727 2232 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 2011/09/21 10:24:43.0758 2232 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 2011/09/21 10:24:43.0820 2232 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 2011/09/21 10:24:43.0851 2232 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 2011/09/21 10:24:43.0883 2232 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 2011/09/21 10:24:43.0914 2232 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 2011/09/21 10:24:43.0961 2232 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 2011/09/21 10:24:44.0054 2232 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/09/21 10:24:44.0085 2232 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/09/21 10:24:44.0117 2232 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/09/21 10:24:44.0148 2232 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 2011/09/21 10:24:44.0179 2232 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 2011/09/21 10:24:44.0241 2232 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 2011/09/21 10:24:44.0257 2232 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 2011/09/21 10:24:44.0288 2232 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 2011/09/21 10:24:44.0351 2232 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 2011/09/21 10:24:44.0366 2232 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/09/21 10:24:44.0397 2232 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 2011/09/21 10:24:44.0429 2232 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 2011/09/21 10:24:44.0444 2232 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/09/21 10:24:44.0460 2232 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 2011/09/21 10:24:44.0491 2232 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\drivers\MTConfig.sys 2011/09/21 10:24:44.0522 2232 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 2011/09/21 10:24:44.0600 2232 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 2011/09/21 10:24:44.0647 2232 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 2011/09/21 10:24:44.0709 2232 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 2011/09/21 10:24:44.0772 2232 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/09/21 10:24:44.0819 2232 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/09/21 10:24:44.0850 2232 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/09/21 10:24:44.0881 2232 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 2011/09/21 10:24:44.0959 2232 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 2011/09/21 10:24:45.0006 2232 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 2011/09/21 10:24:45.0115 2232 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\drivers\nfrd960.sys 2011/09/21 10:24:45.0177 2232 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 2011/09/21 10:24:45.0271 2232 npkcrypt (aaf9b4df67938753cb21808ea3574242) D:\Program Files\Level Up Games\Ragnarok Online\npkcrypt.sys 2011/09/21 10:24:45.0318 2232 npkcusb (3c956a5513a53e2244f0773104fa6d8f) D:\Program Files\Level Up Games\Ragnarok Online\npkcusb.sys 2011/09/21 10:24:45.0365 2232 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 2011/09/21 10:24:45.0427 2232 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys 2011/09/21 10:24:45.0474 2232 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 2011/09/21 10:24:45.0708 2232 nvlddmkm (4152708c0c24e30dae7fa87d5afe1d7b) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2011/09/21 10:24:45.0942 2232 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys 2011/09/21 10:24:45.0989 2232 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys 2011/09/21 10:24:46.0113 2232 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 2011/09/21 10:24:46.0160 2232 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 2011/09/21 10:24:46.0191 2232 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\drivers\parport.sys 2011/09/21 10:24:46.0223 2232 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys 2011/09/21 10:24:46.0238 2232 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\drivers\parvdm.sys 2011/09/21 10:24:46.0285 2232 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 2011/09/21 10:24:46.0301 2232 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 2011/09/21 10:24:46.0332 2232 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\drivers\pcmcia.sys 2011/09/21 10:24:46.0394 2232 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 2011/09/21 10:24:46.0441 2232 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 2011/09/21 10:24:46.0566 2232 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 2011/09/21 10:24:46.0597 2232 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\drivers\processr.sys 2011/09/21 10:24:46.0659 2232 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 2011/09/21 10:24:46.0706 2232 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys 2011/09/21 10:24:46.0737 2232 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\drivers\ql2300.sys 2011/09/21 10:24:46.0800 2232 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\drivers\ql40xx.sys 2011/09/21 10:24:46.0862 2232 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 2011/09/21 10:24:46.0893 2232 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 2011/09/21 10:24:46.0971 2232 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 2011/09/21 10:24:47.0003 2232 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/09/21 10:24:47.0065 2232 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/09/21 10:24:47.0127 2232 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 2011/09/21 10:24:47.0174 2232 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 2011/09/21 10:24:47.0205 2232 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 2011/09/21 10:24:47.0237 2232 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/09/21 10:24:47.0283 2232 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys 2011/09/21 10:24:47.0346 2232 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 2011/09/21 10:24:47.0377 2232 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 2011/09/21 10:24:47.0424 2232 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys 2011/09/21 10:24:47.0471 2232 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys 2011/09/21 10:24:47.0533 2232 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 2011/09/21 10:24:47.0642 2232 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 2011/09/21 10:24:47.0720 2232 RTL8167 (d5ede44ca85899e0478208c8413c1c31) C:\Windows\system32\DRIVERS\Rt86win7.sys 2011/09/21 10:24:47.0783 2232 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys 2011/09/21 10:24:47.0845 2232 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 2011/09/21 10:24:47.0923 2232 SCDEmu (20b2751cd4c8f3fd989739ca661b9f30) C:\Windows\system32\drivers\SCDEmu.sys 2011/09/21 10:24:47.0970 2232 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 2011/09/21 10:24:48.0032 2232 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/09/21 10:24:48.0110 2232 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 2011/09/21 10:24:48.0141 2232 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 2011/09/21 10:24:48.0188 2232 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\drivers\sermouse.sys 2011/09/21 10:24:48.0235 2232 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 2011/09/21 10:24:48.0266 2232 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 2011/09/21 10:24:48.0297 2232 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 2011/09/21 10:24:48.0329 2232 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\drivers\sfloppy.sys 2011/09/21 10:24:48.0375 2232 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 2011/09/21 10:24:48.0438 2232 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\drivers\SiSRaid2.sys 2011/09/21 10:24:48.0485 2232 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\drivers\sisraid4.sys 2011/09/21 10:24:48.0547 2232 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 2011/09/21 10:24:48.0625 2232 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 2011/09/21 10:24:48.0687 2232 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys 2011/09/21 10:24:48.0703 2232 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys 2011/09/21 10:24:48.0734 2232 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys 2011/09/21 10:24:48.0797 2232 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\drivers\stexstor.sys 2011/09/21 10:24:48.0859 2232 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys 2011/09/21 10:24:48.0906 2232 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys 2011/09/21 10:24:48.0953 2232 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 2011/09/21 10:24:48.0984 2232 Synth3dVsc (f2ad8960812fd111e20e84659ef19d43) C:\Windows\system32\drivers\synth3dvsc.sys 2011/09/21 10:24:49.0109 2232 Tcpip (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\drivers\tcpip.sys 2011/09/21 10:24:49.0202 2232 TCPIP6 (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\DRIVERS\tcpip.sys 2011/09/21 10:24:49.0249 2232 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 2011/09/21 10:24:49.0296 2232 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 2011/09/21 10:24:49.0327 2232 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys 2011/09/21 10:24:49.0358 2232 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 2011/09/21 10:24:49.0405 2232 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\DRIVERS\termdd.sys 2011/09/21 10:24:49.0436 2232 terminpt (052306fd76793d5d5ab5d9891fd1adbb) C:\Windows\system32\drivers\terminpt.sys 2011/09/21 10:24:49.0545 2232 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/09/21 10:24:49.0608 2232 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 2011/09/21 10:24:49.0623 2232 TsUsbGD (01246f0baad7b68ec0f472aa41e33282) C:\Windows\system32\drivers\TsUsbGD.sys 2011/09/21 10:24:49.0670 2232 tsusbhub (045acb987c650d8186c6b4a692223860) C:\Windows\system32\drivers\tsusbhub.sys 2011/09/21 10:24:49.0748 2232 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 2011/09/21 10:24:49.0779 2232 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\drivers\uagp35.sys 2011/09/21 10:24:49.0826 2232 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 2011/09/21 10:24:49.0889 2232 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 2011/09/21 10:24:49.0951 2232 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\DRIVERS\umbus.sys 2011/09/21 10:24:49.0982 2232 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\drivers\umpass.sys 2011/09/21 10:24:50.0045 2232 usbccgp (7e72e7d7e0757d59481d530fd2b0bfae) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/09/21 10:24:50.0091 2232 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 2011/09/21 10:24:50.0123 2232 usbehci (cfbce999c057d78979a181c9c60f208e) C:\Windows\system32\DRIVERS\usbehci.sys 2011/09/21 10:24:50.0154 2232 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\DRIVERS\usbhub.sys 2011/09/21 10:24:50.0201 2232 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\drivers\usbohci.sys 2011/09/21 10:24:50.0247 2232 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\drivers\usbprint.sys 2011/09/21 10:24:50.0279 2232 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/09/21 10:24:50.0310 2232 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/09/21 10:24:50.0388 2232 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\system32\Drivers\usbvideo.sys 2011/09/21 10:24:50.0450 2232 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 2011/09/21 10:24:50.0481 2232 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/09/21 10:24:50.0513 2232 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 2011/09/21 10:24:50.0591 2232 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 2011/09/21 10:24:50.0653 2232 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 2011/09/21 10:24:50.0684 2232 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\drivers\viac7.sys 2011/09/21 10:24:50.0778 2232 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 2011/09/21 10:24:50.0809 2232 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys 2011/09/21 10:24:50.0840 2232 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys 2011/09/21 10:24:50.0856 2232 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 2011/09/21 10:24:50.0918 2232 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 2011/09/21 10:24:50.0934 2232 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 2011/09/21 10:24:51.0027 2232 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\drivers\vsmraid.sys 2011/09/21 10:24:51.0059 2232 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 2011/09/21 10:24:51.0121 2232 wacmoumonitor (f24ee97511fb901189e11cbbd51605ba) C:\Windows\system32\DRIVERS\wacmoumonitor.sys 2011/09/21 10:24:51.0152 2232 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\Windows\system32\DRIVERS\wacommousefilter.sys 2011/09/21 10:24:51.0183 2232 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\drivers\wacompen.sys 2011/09/21 10:24:51.0246 2232 wacomvhid (846b58ea44bf8c92e4b59f4e2252c4c0) C:\Windows\system32\DRIVERS\wacomvhid.sys 2011/09/21 10:24:51.0293 2232 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 2011/09/21 10:24:51.0308 2232 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 2011/09/21 10:24:51.0355 2232 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\drivers\wd.sys 2011/09/21 10:24:51.0402 2232 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys 2011/09/21 10:24:51.0449 2232 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2011/09/21 10:24:51.0542 2232 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 2011/09/21 10:24:51.0573 2232 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 2011/09/21 10:24:51.0667 2232 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 2011/09/21 10:24:51.0761 2232 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/09/21 10:24:51.0807 2232 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 2011/09/21 10:24:51.0870 2232 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/09/21 10:24:51.0948 2232 zmeianoc7 (2cef7961887e167e22a0158d10738e07) C:\Windows\system32\drivers\zmeianoc7.sys 2011/09/21 10:24:51.0948 2232 Suspicious file (NoAccess): C:\Windows\system32\drivers\zmeianoc7.sys. md5: 2cef7961887e167e22a0158d10738e07 2011/09/21 10:24:51.0948 2232 Suspicious file (Hidden): C:\Windows\system32\drivers\zmeianoc7.sys. md5: 2cef7961887e167e22a0158d10738e07 2011/09/21 10:24:51.0963 2232 zmeianoc7 - detected LockedFile.Multi.Generic (1) 2011/09/21 10:24:51.0995 2232 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 2011/09/21 10:24:52.0026 2232 MBR (0x1B8) (de1996b5390bac8242e23168f828c750) \Device\Harddisk1\DR1 2011/09/21 10:24:52.0026 2232 \Device\Harddisk1\DR1 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/09/21 10:24:52.0026 2232 Boot (0x1200) (8a0754adfbe3b2fd8ae1fdc1ba318db9) \Device\Harddisk0\DR0\Partition0 2011/09/21 10:24:52.0073 2232 Boot (0x1200) (c1630443d70046ff3ff97424247b2baf) \Device\Harddisk1\DR1\Partition0 2011/09/21 10:24:52.0073 2232 ================================================================================ 2011/09/21 10:24:52.0073 2232 Scan finished 2011/09/21 10:24:52.0073 2232 ================================================================================ 2011/09/21 10:24:52.0088 5004 Detected object count: 2 2011/09/21 10:24:52.0088 5004 Actual detected object count: 2 2011/09/21 10:25:38.0030 5004 LockedFile.Multi.Generic(zmeianoc7) - User select action: Skip 2011/09/21 10:25:38.0046 5004 \Device\Harddisk1\DR1 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot 2011/09/21 10:25:38.0046 5004 \Device\Harddisk1\DR1 - ok 2011/09/21 10:25:38.0046 5004 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk1\DR1) - User select action: Cure 2011/09/21 10:25:45.0035 3920 Deinitialize success
Good. It found TDL4 for sure. :thumbup:

Please scan the following files

  • Please go to VirusTotal
  • On the page you'll find a "Browse" button.
  • Click on the Browse button.
  • In the Choose File to Upload window which opens, copy and paste this into the File Name box.
c:\windows\System32\ping.exe
  • Next, click the Open button.
  • Then click the "Send File" button just below.
  • This will scan the file. Please be patient.
  • If you get a message saying File has already been analyzed: click Reanalyze file now.
  • Once scanned, copy and paste the link to the results page in your next reply.
YukiYuki, You did perfect. The ping.exe file you have is legitimate. The backdoor trojan could have been using it… I suppose TDL4 could have also. How are things now?
YukiYuki,

I believe we got it. :woot:

Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Hi Tomk, I'm finished with the cleanup, and I would just like to say that I cannot thank you enough for your assistance in solving my computer's problems I've seen others help people out, and I must say, the people here truly are wonderful And I'll surely keep in mind the extra advice you gave me, I'm sure they will help out a lot Once again, I thank you

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI