This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Anti-virus program hasn't updated for 5 days [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello!

I am running Windows XP. Running Avira AntiVir Personal antivirus. When I attempt to update the virus definitions, it fails to do so. Log attached. Rebooted - didn't seem to help.

thank you,
Linda

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:04:56 PM, on 12/20/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Linda\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: DoneList.txt.lnk = D:\Linda\XP\Documents\DoneList.txt
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: GetRunningProcs_.lnk = D:\Linda\XP\BatScripts\zzGetRunning.bat
O4 - Startup: Login.bat.lnk = D:\Linda\XP\BatScripts\zzLogin.bat
O4 - Startup: Tasks.lnk = ?
O4 - Startup: zzScreenshot.lnk = D:\Linda\XP\BatScripts\scrshot.bat
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1306184705500
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1311380024843
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files\Secunia\PSI\sua.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

–
End of file - 7418 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!





HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt






Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Thank you Doris for responding. I was able to get Avira AntiVir to eventually update itself. But it seems odd. So I downloaded dds and ran it- log file below. . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.1.0 Run by [removed] at 22:21:33 on 2011-12-20 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2469 [GMT -5:00] . AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Java\jre7\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe C:\Program Files\Secunia\PSI\PSIA.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Apoint\Apoint.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Apoint\ApMsgFwd.exe C:\Program Files\Protector Suite QL\psqltray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Secunia\PSI\psi_tray.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Secunia\PSI\sua.exe C:\WINDOWS\system32\dllhost.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uInternet Connection Wizard,ShellNext = hxxp://www.sony.com/vaiopeople BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe mRun: [SonyPowerCfg] "c:\program files\sony\vaio power management\SPMgr.exe" mRun: [PSQLLauncher] "c:\program files\protector suite ql\launcher.exe" /startup mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime StartupFolder: c:\docume~1\linda\startm~1\programs\startup\doneli~1.lnk - d:\linda\xp\documents\DoneList.txt StartupFolder: c:\docume~1\linda\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\linda\startm~1\programs\startup\getrun~1.lnk - d:\linda\xp\batscripts\zzGetRunning.bat StartupFolder: c:\docume~1\linda\startm~1\programs\startup\loginb~1.lnk - d:\linda\xp\batscripts\zzLogin.bat StartupFolder: c:\docume~1\linda\startm~1\programs\startup\tasks.lnk - c:\windows\Tasks StartupFolder: c:\docume~1\linda\startm~1\programs\startup\zzscre~1.lnk - d:\linda\xp\batscripts\scrshot.bat StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1306184705500 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1311380024843 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{B22B77D3-86EE-4106-81C0-CBF625E26E65} : DhcpNameServer = 192.168.1.1 Notify: igfxcui - igfxdev.dll Notify: psfus - c:\windows\system32\psqlpwd.dll Notify: VESWinlogon - VESWinlogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Notification Packages = scecli psqlpwd . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\linda\application data\mozilla\firefox\profiles\i4r1jzvt.default\ FF - prefs.js: browser.startup.homepage - hxxps://www.duckduckgo.com/ FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\sumatrapdf\npPdfViewer.dll . ============= SERVICES / DRIVERS =============== . R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [2007-11-15 21408] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-5-22 11608] R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [2011-6-19 8576] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-5-22 136360] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-5-22 269480] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-5-22 66616] R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\seagate\seagate dashboard\SeagateDashboardService.exe [2010-7-6 14088] R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-10-14 994360] R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-10-14 399416] R3 5U870UVC;Sony Visual Communication Camera VGP-VCC7;c:\windows\system32\drivers\5U870.sys [2011-6-19 90240] R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-11-15 41216] R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544] R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2007-11-15 31104] R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2007-11-14 37040] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-11-15 812544] S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-5-9 13192] S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-5-9 8456] S3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\drivers\KORGUMDS.SYS [2011-3-30 24056] . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-12 01:34:58 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20:51 43520 ——w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 ——w- c:\windows\system32\html.iec 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 16:50:16 72080 —-a-w- c:\documents and settings\linda\g2mdlhlpx.exe 2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-24 18:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 18:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts 2011-10-24 18:06:24 128000 —-a-w- c:\windows\system32\javacpl.cpl 2011-10-24 18:06:23 544656 —-a-w- c:\windows\system32\deployJava1.dll 2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll . ============= FINISH: 22:21:59.09 ===============
TDSS killer reports nothing found: 22:35:48.0218 1724 TDSS rootkit removing tool [removed] Dec 13 2011 10:39:31 22:35:48.0625 1724 ============================================================ 22:35:48.0625 1724 Current date / time: 2011/12/20 22:35:48.0625 22:35:48.0625 1724 SystemInfo: 22:35:48.0625 1724 22:35:48.0625 1724 OS Version: 5.1.2600 ServicePack: 3.0 22:35:48.0625 1724 Product type: Workstation 22:35:48.0625 1724 ComputerName: LAMPC 22:35:48.0625 1724 UserName: Linda 22:35:48.0625 1724 Windows directory: C:\WINDOWS 22:35:48.0625 1724 System windows directory: C:\WINDOWS 22:35:48.0625 1724 Processor architecture: Intel x86 22:35:48.0625 1724 Number of processors: 2 22:35:48.0625 1724 Page size: 0x1000 22:35:48.0625 1724 Boot type: Normal boot 22:35:48.0625 1724 ============================================================ 22:35:50.0140 1724 Initialize success 22:36:02.0968 0508 ============================================================ 22:36:02.0968 0508 Scan started 22:36:02.0968 0508 Mode: Manual; 22:36:02.0968 0508 ============================================================ 22:36:03.0640 0508 5U870UVC (3d7e7f3851817075bc983d02206c6a07) C:\WINDOWS\system32\DRIVERS\5U870.sys 22:36:03.0640 0508 5U870UVC - ok 22:36:03.0671 0508 Abiosdsk - ok 22:36:03.0687 0508 abp480n5 - ok 22:36:03.0734 0508 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 22:36:03.0734 0508 ACPI - ok 22:36:03.0765 0508 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 22:36:03.0765 0508 ACPIEC - ok 22:36:03.0781 0508 adpu160m - ok 22:36:03.0796 0508 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 22:36:03.0796 0508 aec - ok 22:36:03.0843 0508 AegisP (a1ad1a4a9f18d900ca9c93fa3efdcb56) C:\WINDOWS\system32\DRIVERS\AegisP.sys 22:36:03.0843 0508 AegisP - ok 22:36:03.0921 0508 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 22:36:03.0921 0508 AFD - ok 22:36:03.0937 0508 Aha154x - ok 22:36:03.0953 0508 aic78u2 - ok 22:36:03.0953 0508 aic78xx - ok 22:36:03.0968 0508 AliIde - ok 22:36:03.0984 0508 amsint - ok 22:36:04.0015 0508 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 22:36:04.0015 0508 ApfiltrService - ok 22:36:04.0031 0508 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 22:36:04.0031 0508 Arp1394 - ok 22:36:04.0031 0508 asc - ok 22:36:04.0046 0508 asc3350p - ok 22:36:04.0062 0508 asc3550 - ok 22:36:04.0093 0508 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 22:36:04.0093 0508 AsyncMac - ok 22:36:04.0109 0508 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 22:36:04.0109 0508 atapi - ok 22:36:04.0125 0508 Atdisk - ok 22:36:04.0140 0508 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 22:36:04.0156 0508 Atmarpc - ok 22:36:04.0218 0508 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 22:36:04.0218 0508 audstub - ok 22:36:04.0281 0508 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys 22:36:04.0281 0508 avgio - ok 22:36:04.0343 0508 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys 22:36:04.0343 0508 avgntflt - ok 22:36:04.0375 0508 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys 22:36:04.0390 0508 avipbb - ok 22:36:04.0437 0508 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 22:36:04.0437 0508 Beep - ok 22:36:04.0515 0508 btaudio (cd29c842bf4e06af1f088e718948fbc1) C:\WINDOWS\system32\drivers\btaudio.sys 22:36:04.0531 0508 btaudio - ok 22:36:04.0593 0508 BTDriver (58a49bd10e08d3d4333a60dedcb1ced8) C:\WINDOWS\system32\DRIVERS\btport.sys 22:36:04.0593 0508 BTDriver - ok 22:36:04.0671 0508 BTKRNL (ce3fd44d049740ce2bd2425996cca7d7) C:\WINDOWS\system32\DRIVERS\btkrnl.sys 22:36:04.0718 0508 BTKRNL - ok 22:36:04.0796 0508 BTWDNDIS (80f61de965c116051614ac2f04222ff7) C:\WINDOWS\system32\DRIVERS\btwdndis.sys 22:36:04.0796 0508 BTWDNDIS - ok 22:36:05.0156 0508 btwhid (e48668b4a6a5cf68b33aecad18ee8e1e) C:\WINDOWS\system32\DRIVERS\btwhid.sys 22:36:05.0156 0508 btwhid - ok 22:36:05.0203 0508 BTWUSB (57e91e9925976bbc98984eebaaf1d84c) C:\WINDOWS\system32\Drivers\btwusb.sys 22:36:05.0203 0508 BTWUSB - ok 22:36:05.0250 0508 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 22:36:05.0250 0508 cbidf2k - ok 22:36:05.0281 0508 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 22:36:05.0281 0508 CCDECODE - ok 22:36:05.0296 0508 cd20xrnt - ok 22:36:05.0328 0508 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 22:36:05.0328 0508 Cdaudio - ok 22:36:05.0359 0508 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 22:36:05.0359 0508 Cdfs - ok 22:36:05.0375 0508 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 22:36:05.0390 0508 Cdrom - ok 22:36:05.0390 0508 Changer - ok 22:36:05.0421 0508 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 22:36:05.0421 0508 CmBatt - ok 22:36:05.0453 0508 CmdIde - ok 22:36:05.0453 0508 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 22:36:05.0468 0508 Compbatt - ok 22:36:05.0484 0508 Cpqarray - ok 22:36:05.0500 0508 dac2w2k - ok 22:36:05.0500 0508 dac960nt - ok 22:36:05.0531 0508 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 22:36:05.0531 0508 Disk - ok 22:36:05.0578 0508 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 22:36:05.0609 0508 dmboot - ok 22:36:05.0640 0508 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys 22:36:05.0640 0508 DMICall - ok 22:36:05.0687 0508 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 22:36:05.0687 0508 dmio - ok 22:36:05.0750 0508 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 22:36:05.0765 0508 dmload - ok 22:36:05.0812 0508 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 22:36:05.0812 0508 DMusic - ok 22:36:05.0828 0508 dpti2o - ok 22:36:05.0843 0508 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 22:36:05.0843 0508 drmkaud - ok 22:36:05.0875 0508 epmntdrv (f07ba56b0235f15eff8f10dc6389c42e) C:\WINDOWS\system32\epmntdrv.sys 22:36:05.0953 0508 epmntdrv - ok 22:36:05.0984 0508 EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\WINDOWS\system32\EuGdiDrv.sys 22:36:06.0015 0508 EuGdiDrv - ok 22:36:06.0078 0508 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 22:36:06.0078 0508 Fastfat - ok 22:36:06.0125 0508 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 22:36:06.0125 0508 Fdc - ok 22:36:06.0140 0508 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 22:36:06.0140 0508 Fips - ok 22:36:06.0156 0508 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 22:36:06.0156 0508 Flpydisk - ok 22:36:06.0187 0508 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 22:36:06.0203 0508 FltMgr - ok 22:36:06.0218 0508 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 22:36:06.0218 0508 Fs_Rec - ok 22:36:06.0234 0508 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 22:36:06.0250 0508 Ftdisk - ok 22:36:06.0281 0508 GEARAspiWDM (4ac51459805264affd5f6fdfb9d9235f) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 22:36:06.0296 0508 GEARAspiWDM - ok 22:36:06.0328 0508 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 22:36:06.0328 0508 Gpc - ok 22:36:06.0375 0508 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 22:36:06.0406 0508 HDAudBus - ok 22:36:06.0453 0508 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 22:36:06.0453 0508 hidusb - ok 22:36:06.0484 0508 hpn - ok 22:36:06.0546 0508 HSFHWAZL (be0a81f4337367ce94bb20e65b3d57c8) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 22:36:06.0546 0508 HSFHWAZL - ok 22:36:06.0593 0508 HSF_DPV (b46aa158f25ccbf03b12971b4c7f4723) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 22:36:06.0625 0508 HSF_DPV - ok 22:36:06.0671 0508 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 22:36:06.0671 0508 HTTP - ok 22:36:06.0796 0508 i2omgmt - ok 22:36:06.0843 0508 i2omp - ok 22:36:06.0875 0508 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 22:36:06.0875 0508 i8042prt - ok 22:36:07.0093 0508 ialm (8717f0297bbefac86264a233e4fb28c9) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 22:36:07.0265 0508 ialm - ok 22:36:07.0312 0508 IFXTPM (667cfdb801df771f47b7c39373c2d850) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS 22:36:07.0312 0508 IFXTPM - ok 22:36:07.0343 0508 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 22:36:07.0343 0508 Imapi - ok 22:36:07.0375 0508 ini910u - ok 22:36:07.0406 0508 IntelIde - ok 22:36:07.0437 0508 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 22:36:07.0437 0508 intelppm - ok 22:36:07.0500 0508 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 22:36:07.0515 0508 Ip6Fw - ok 22:36:07.0578 0508 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 22:36:07.0609 0508 IpFilterDriver - ok 22:36:07.0656 0508 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 22:36:07.0656 0508 IpInIp - ok 22:36:07.0687 0508 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 22:36:07.0703 0508 IpNat - ok 22:36:07.0734 0508 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 22:36:07.0734 0508 IPSec - ok 22:36:07.0796 0508 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 22:36:07.0796 0508 IRENUM - ok 22:36:07.0843 0508 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 22:36:07.0843 0508 isapnp - ok 22:36:07.0859 0508 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 22:36:07.0875 0508 Kbdclass - ok 22:36:07.0875 0508 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 22:36:07.0890 0508 kbdhid - ok 22:36:07.0921 0508 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 22:36:07.0937 0508 kmixer - ok 22:36:07.0984 0508 KORGUMDS (50deddce25c89382a23e605eb4e0236b) C:\WINDOWS\system32\Drivers\KORGUMDS.SYS 22:36:07.0984 0508 KORGUMDS - ok 22:36:08.0015 0508 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 22:36:08.0015 0508 KSecDD - ok 22:36:08.0031 0508 lbrtfdc - ok 22:36:08.0078 0508 mdmxsdk (74f4372af97a587ecec527ec34955712) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 22:36:08.0078 0508 mdmxsdk - ok 22:36:08.0171 0508 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 22:36:08.0171 0508 mnmdd - ok 22:36:08.0218 0508 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 22:36:08.0218 0508 Modem - ok 22:36:08.0250 0508 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 22:36:08.0250 0508 Mouclass - ok 22:36:08.0296 0508 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 22:36:08.0296 0508 mouhid - ok 22:36:08.0359 0508 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 22:36:08.0359 0508 MountMgr - ok 22:36:08.0375 0508 mraid35x - ok 22:36:08.0390 0508 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 22:36:08.0406 0508 MRxDAV - ok 22:36:08.0468 0508 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 22:36:08.0484 0508 MRxSmb - ok 22:36:08.0515 0508 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 22:36:08.0515 0508 Msfs - ok 22:36:08.0531 0508 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 22:36:08.0546 0508 MSKSSRV - ok 22:36:08.0578 0508 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 22:36:08.0578 0508 MSPCLOCK - ok 22:36:08.0625 0508 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 22:36:08.0625 0508 MSPQM - ok 22:36:08.0671 0508 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 22:36:08.0671 0508 mssmbios - ok 22:36:08.0765 0508 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 22:36:08.0781 0508 MSTEE - ok 22:36:08.0828 0508 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 22:36:08.0828 0508 Mup - ok 22:36:08.0875 0508 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 22:36:08.0875 0508 NABTSFEC - ok 22:36:08.0937 0508 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 22:36:08.0937 0508 NDIS - ok 22:36:08.0968 0508 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 22:36:08.0968 0508 NdisIP - ok 22:36:09.0031 0508 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 22:36:09.0031 0508 NdisTapi - ok 22:36:09.0093 0508 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 22:36:09.0093 0508 Ndisuio - ok 22:36:09.0109 0508 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 22:36:09.0125 0508 NdisWan - ok 22:36:09.0187 0508 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 22:36:09.0187 0508 NDProxy - ok 22:36:09.0218 0508 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 22:36:09.0218 0508 NetBIOS - ok 22:36:09.0265 0508 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 22:36:09.0265 0508 NetBT - ok 22:36:09.0406 0508 NETw4x32 (a9574f52e2fd5c1c1b4807a326e0488f) C:\WINDOWS\system32\DRIVERS\NETw4x32.sys 22:36:09.0484 0508 NETw4x32 - ok 22:36:09.0515 0508 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 22:36:09.0531 0508 NIC1394 - ok 22:36:09.0578 0508 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 22:36:09.0578 0508 Npfs - ok 22:36:09.0609 0508 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 22:36:09.0640 0508 Ntfs - ok 22:36:09.0687 0508 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 22:36:09.0687 0508 Null - ok 22:36:09.0953 0508 nv (a50a030be64fa2fdb548a2ee888f8adb) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 22:36:10.0171 0508 nv - ok 22:36:10.0218 0508 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 22:36:10.0218 0508 NwlnkFlt - ok 22:36:10.0250 0508 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 22:36:10.0250 0508 NwlnkFwd - ok 22:36:10.0296 0508 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 22:36:10.0296 0508 ohci1394 - ok 22:36:10.0312 0508 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 22:36:10.0312 0508 Parport - ok 22:36:10.0328 0508 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 22:36:10.0328 0508 PartMgr - ok 22:36:10.0359 0508 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 22:36:10.0359 0508 ParVdm - ok 22:36:10.0390 0508 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 22:36:10.0390 0508 PCI - ok 22:36:10.0406 0508 PCIDump - ok 22:36:10.0437 0508 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 22:36:10.0437 0508 PCIIde - ok 22:36:10.0468 0508 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 22:36:10.0484 0508 Pcmcia - ok 22:36:10.0500 0508 PDCOMP - ok 22:36:10.0531 0508 PDFRAME - ok 22:36:10.0546 0508 PDRELI - ok 22:36:10.0578 0508 PDRFRAME - ok 22:36:10.0609 0508 perc2 - ok 22:36:10.0640 0508 perc2hib - ok 22:36:10.0703 0508 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 22:36:10.0703 0508 PptpMiniport - ok 22:36:10.0765 0508 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 22:36:10.0765 0508 PSched - ok 22:36:10.0812 0508 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\WINDOWS\system32\DRIVERS\psi_mf.sys 22:36:10.0812 0508 PSI - ok 22:36:10.0843 0508 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 22:36:10.0843 0508 Ptilink - ok 22:36:10.0859 0508 PxHelp20 (59464c712c8c75e4513064f5a485582f) C:\WINDOWS\system32\Drivers\PxHelp20.sys 22:36:10.0875 0508 PxHelp20 - ok 22:36:10.0906 0508 ql1080 - ok 22:36:10.0937 0508 Ql10wnt - ok 22:36:10.0953 0508 ql12160 - ok 22:36:10.0984 0508 ql1240 - ok 22:36:11.0000 0508 ql1280 - ok 22:36:11.0046 0508 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 22:36:11.0046 0508 RasAcd - ok 22:36:11.0109 0508 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 22:36:11.0109 0508 Rasl2tp - ok 22:36:11.0125 0508 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 22:36:11.0125 0508 RasPppoe - ok 22:36:11.0156 0508 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 22:36:11.0156 0508 Raspti - ok 22:36:11.0203 0508 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 22:36:11.0218 0508 Rdbss - ok 22:36:11.0265 0508 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 22:36:11.0281 0508 RDPCDD - ok 22:36:11.0328 0508 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 22:36:11.0328 0508 rdpdr - ok 22:36:11.0390 0508 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 22:36:11.0390 0508 RDPWD - ok 22:36:11.0421 0508 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 22:36:11.0437 0508 redbook - ok 22:36:11.0484 0508 s24trans (eadfb87f911a7a75d1b80617f92901e8) C:\WINDOWS\system32\DRIVERS\s24trans.sys 22:36:11.0484 0508 s24trans - ok 22:36:11.0515 0508 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 22:36:11.0515 0508 Secdrv - ok 22:36:11.0562 0508 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 22:36:11.0562 0508 Serial - ok 22:36:11.0609 0508 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys 22:36:11.0609 0508 Sfloppy - ok 22:36:11.0656 0508 shpf (5b36e43a535345599515d20fa77c8026) C:\WINDOWS\system32\DRIVERS\shpf.sys 22:36:11.0656 0508 shpf - ok 22:36:11.0671 0508 Simbad - ok 22:36:11.0703 0508 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 22:36:11.0703 0508 SLIP - ok 22:36:11.0765 0508 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\Drivers\SonyNC.sys 22:36:11.0765 0508 SNC - ok 22:36:11.0796 0508 SonyImgF (ffdb6f1cb87b42f41b6de116cd6ef809) C:\WINDOWS\system32\DRIVERS\SonyImgF.sys 22:36:11.0796 0508 SonyImgF - ok 22:36:11.0828 0508 Sparrow - ok 22:36:11.0843 0508 SPI (bfd0e6f53957af8156084c436b825f70) C:\WINDOWS\system32\DRIVERS\SonyPI.sys 22:36:11.0843 0508 SPI - ok 22:36:11.0921 0508 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 22:36:11.0921 0508 splitter - ok 22:36:11.0953 0508 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 22:36:11.0953 0508 sr - ok 22:36:12.0062 0508 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 22:36:12.0078 0508 Srv - ok 22:36:12.0140 0508 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 22:36:12.0140 0508 ssmdrv - ok 22:36:12.0234 0508 STHDA (951801dfb54d86f611f0af47825476f9) C:\WINDOWS\system32\drivers\sthda.sys 22:36:12.0281 0508 STHDA - ok 22:36:12.0359 0508 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 22:36:12.0359 0508 streamip - ok 22:36:12.0406 0508 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 22:36:12.0406 0508 swenum - ok 22:36:12.0453 0508 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 22:36:12.0453 0508 swmidi - ok 22:36:12.0484 0508 symc810 - ok 22:36:12.0515 0508 symc8xx - ok 22:36:12.0531 0508 sym_hi - ok 22:36:12.0562 0508 sym_u3 - ok 22:36:12.0609 0508 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 22:36:12.0609 0508 sysaudio - ok 22:36:12.0671 0508 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 22:36:12.0687 0508 Tcpip - ok 22:36:12.0734 0508 TcUsb (53900527fa5e2ccc818c5894383772d1) C:\WINDOWS\system32\Drivers\tcusb.sys 22:36:12.0734 0508 TcUsb - ok 22:36:12.0781 0508 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 22:36:12.0781 0508 TDPIPE - ok 22:36:12.0843 0508 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 22:36:12.0843 0508 TDTCP - ok 22:36:12.0875 0508 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 22:36:12.0875 0508 TermDD - ok 22:36:12.0968 0508 ti21sony (909cd987b54a8179c9aee874d754721a) C:\WINDOWS\system32\drivers\ti21sony.sys 22:36:12.0984 0508 ti21sony - ok 22:36:13.0015 0508 TosIde - ok 22:36:13.0062 0508 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 22:36:13.0093 0508 Udfs - ok 22:36:13.0109 0508 ultra - ok 22:36:13.0187 0508 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 22:36:13.0203 0508 Update - ok 22:36:13.0265 0508 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 22:36:13.0281 0508 usbaudio - ok 22:36:13.0312 0508 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 22:36:13.0312 0508 usbccgp - ok 22:36:13.0328 0508 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 22:36:13.0343 0508 usbehci - ok 22:36:13.0343 0508 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 22:36:13.0359 0508 usbhub - ok 22:36:13.0375 0508 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 22:36:13.0375 0508 usbstor - ok 22:36:13.0406 0508 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 22:36:13.0406 0508 usbuhci - ok 22:36:13.0421 0508 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 22:36:13.0421 0508 usbvideo - ok 22:36:13.0468 0508 vcdrom (bfa4ae30b3ac10e9223830bf103f5a3f) C:\WINDOWS\system32\drivers\VCdRom.sys 22:36:13.0468 0508 vcdrom - ok 22:36:13.0515 0508 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 22:36:13.0515 0508 VgaSave - ok 22:36:13.0546 0508 ViaIde - ok 22:36:13.0578 0508 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 22:36:13.0578 0508 VolSnap - ok 22:36:13.0640 0508 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 22:36:13.0640 0508 Wanarp - ok 22:36:13.0671 0508 WDICA - ok 22:36:13.0750 0508 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 22:36:13.0750 0508 wdmaud - ok 22:36:13.0828 0508 winachsf (317dc24899ad7a06e3430bf45f292989) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 22:36:13.0875 0508 winachsf - ok 22:36:13.0968 0508 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 22:36:13.0968 0508 WSTCODEC - ok 22:36:14.0015 0508 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 22:36:14.0031 0508 WudfPf - ok 22:36:14.0078 0508 yukonwxp (2b77c863552ea9cdb989d484143ed016) C:\WINDOWS\system32\DRIVERS\yk51x86.sys 22:36:14.0093 0508 yukonwxp - ok 22:36:14.0125 0508 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 22:36:14.0296 0508 \Device\Harddisk0\DR0 - ok 22:36:14.0296 0508 Boot (0x1200) (5b561a9ee1d4f5c9c128d373241596c1) \Device\Harddisk0\DR0\Partition0 22:36:14.0312 0508 \Device\Harddisk0\DR0\Partition0 - ok 22:36:14.0328 0508 Boot (0x1200) (cbbad3592fd05be1670275afe7eef1c1) \Device\Harddisk0\DR0\Partition1 22:36:14.0328 0508 \Device\Harddisk0\DR0\Partition1 - ok 22:36:14.0343 0508 Boot (0x1200) (183e5a79760ea234368a2a95758ed7d8) \Device\Harddisk0\DR0\Partition2 22:36:14.0343 0508 \Device\Harddisk0\DR0\Partition2 - ok 22:36:14.0359 0508 Boot (0x1200) (c531c786e91dfef170fe53b7e0aa96f9) \Device\Harddisk0\DR0\Partition3 22:36:14.0359 0508 \Device\Harddisk0\DR0\Partition3 - ok 22:36:14.0375 0508 Boot (0x1200) (09287844aa3ed15703d2b1d6fa877c1d) \Device\Harddisk0\DR0\Partition4 22:36:14.0375 0508 \Device\Harddisk0\DR0\Partition4 - ok 22:36:14.0375 0508 ============================================================ 22:36:14.0375 0508 Scan finished 22:36:14.0375 0508 ============================================================ 22:36:14.0390 2160 Detected object count: 0 22:36:14.0390 2160 Actual detected object count: 0
You have 2 files that have a name that can be totally legit - or can be malware. Can you tell me if you know if you are using Easus Partition Master or not?

You have 2 files that have a name that can be totally legit - or can be malware. Can you tell me if you know if you are using Easus Partition Master or not?


Yes, I used Easeus Partition Master 8.0.1 Home Edition to set up my partitions initially. (Windows XP's disk management utility isn't very useful)

thank you,
Linda
Fantastic, that's what I was hoping. Then you are just fine. There are no signs of malware in your logs. Sometimes, there are just anomalies with antivirus programs and they don't update properly for a day or even a few days. As long as they get back on track, I wouldn't worry about it. If you continue to have problems updating, you might try uninstalling and re-installing the program. If you still have problems after that, and keeping in mind how important anti-virus is to the health of your computer, you might want to consider a different free solution. If it comes to that, we can certainly give you some suggestions on alternatives. But before you jump to that, give it some time and see if the problems persist. Let me know if I can be of any further assistance.

Fantastic, that's what I was hoping. Then you are just fine. There are no signs of malware in your logs. Sometimes, there are just anomalies with antivirus programs and they don't update properly for a day or even a few days. As long as they get back on track, I wouldn't worry about it.

If you continue to have problems updating, you might try uninstalling and re-installing the program. If you still have problems after that, and keeping in mind how important anti-virus is to the health of your computer, you might want to consider a different free solution. If it comes to that, we can certainly give you some suggestions on alternatives. But before you jump to that, give it some time and see if the problems persist.

Let me know if I can be of any further assistance.


Great! I use Avira AntiVir recommended on Doug's page, I think it was.

Have a great holiday, Doris! B)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI