This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_22
Run by [removed] at 15:20:32 on 2011-12-24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.298 [GMT -6:00]
.
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
.
============== Running Processes ===============
.
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Webroot\WRSA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\HP Photosmart 5510 series\bin\HPNetworkCommunicator.exe
C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.msnbc.com
uSearch Page = hxxp://www.msnbc.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = ;*.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [HP Photosmart 5510 series (NET)] "c:\program files\hp\hp photosmart 5510 series\bin\ScanToPCActivationApp.exe" -deviceID "CN18H08BQT05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: []
mRun: [WRSVC] "c:\program files\webroot\WRSA.exe" -ul
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\monito~1.lnk - c:\windows\system32\RunDll32.exe
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - c:\program files\hewlett-packard\smartprint\smartprintsetup.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo1.walgreens.com/WalgreensActivia.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1272745288942
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: DhcpNameServer = [removed] [removed] [removed]
TCP: Interfaces\{4039D714-EBCA-4D39-B751-7AF3A8C3380E} : DhcpNameServer = [removed] [removed] [removed]
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\common files\microsoft shared\information retrieval\itss51.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\wrr4ifwe.default\
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [2009-3-26 15172]
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2011-12-24 107336]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-6-15 249648]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-2-17 24652]
R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2011-12-24 637208]
R3 Linksys_adapter_H;Linksys Adapter Network Driver;c:\windows\system32\drivers\AE2500xp.sys [2011-12-16 1034240]
S2 COMServer;COMServer;"c:\windows\system32\msapps\comsrvr.exe" s –> c:\windows\system32\msapps\comsrvr.exe [?]
S2 dlyuojvsmw;dlyuojvsmw;\??\c:\windows\system32\drivers\nhhiqsce.sys –> c:\windows\system32\drivers\nhhiqsce.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-4-17 135664]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2008-2-3 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2008-2-3 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2008-2-3 166384]
S2 SessionLauncher;SessionLauncher;c:\docume~1\owner\locals~1\temp\dx9\sessionlauncher.exe –> c:\docume~1\owner\locals~1\temp\dx9\SessionLauncher.exe [?]
S3 adxapie;adxapie;\??\c:\docume~1\owner\locals~1\temp\adxapie.sys –> c:\docume~1\owner\locals~1\temp\adxapie.sys [?]
S3 EraserUtilDrv10821;EraserUtilDrv10821;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10821.sys –> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10821.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-4-17 135664]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2008-2-3 313840]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2008-2-3 1112560]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2010-4-6 112384]
S4 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-7-7 195336]
S4 HPHNDUSVC;HP Home Network Diagnostic Support Service;c:\windows\system32\svchost.exe -k HPHNDUService [2005-4-13 14336]
.
=============== Created Last 30 ================
.
2011-12-24 19:20:58 ——– d—–w- C:\Docum
2011-12-24 16:10:13 141272 —-a-w- c:\windows\system32\WRusr.dll
2011-12-24 16:10:11 107336 —-a-w- c:\windows\system32\drivers\WRkrn.sys
2011-12-24 16:08:19 ——– d—–w- c:\documents and settings\all users\application data\WRData
2011-12-16 13:53:25 1034240 —-a-r- c:\windows\system32\drivers\AE2500xp.sys
2011-12-16 13:51:28 68224 —-a-r- c:\windows\system32\WanPacket.dll
2011-12-16 13:51:28 53299 —-a-r- c:\windows\system32\pthreadVC.dll
2011-12-16 13:51:28 34064 —-a-r- c:\windows\system32\drivers\npf.sys
2011-12-16 13:51:28 240248 —-a-r- c:\windows\system32\wpcap.dll
2011-12-16 13:51:27 88696 —-a-r- c:\windows\system32\packet.dll
2011-12-12 02:17:31 388096 —-a-r- c:\documents and settings\owner\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-12 02:17:29 ——– d—–w- c:\program files\Trend Micro
2011-12-11 22:40:18 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-12-11 22:40:18 ——– d—–w- c:\windows\system32\wbem\Repository
.
==================== Find3M ====================
.
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-31 23:43:21 832512 —-a-w- c:\windows\system32\wininet.dll
2011-10-31 23:43:21 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-10-31 23:43:21 1830912 ——w- c:\windows\system32\inetcpl.cpl
2011-10-31 23:43:20 17408 ——w- c:\windows\system32\corpol.dll
2011-10-29 15:03:28 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-14 23:38:00 456192 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-02-24 16:42:42 267592 -c–a-w- c:\program files\Uninstall Ask Toolbar.dll
.
============= FINISH: 15:24:21.29 ===============
Hi Dadrepairman,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

What kind of symptoms are you experiencing while using the internet?

===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Issues with internet Issues connecting to router lack of connectivity Connect to the router but not the internet recently removed PCI adapter and am using only USB adapter linksys 2500 Thanks Per your request the two logs. Looks like we found an ugly one. I am using Webroot and have scanned within the last 36 hours ________________________________________________________________________________ _____________________ 17:06:16.0750 0200 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 17:06:17.0078 0200 ============================================================ 17:06:17.0078 0200 Current date / time: 2011/12/26 17:06:17.0078 17:06:17.0078 0200 SystemInfo: 17:06:17.0078 0200 17:06:17.0078 0200 OS Version: 5.1.2600 ServicePack: 3.0 17:06:17.0093 0200 Product type: Workstation 17:06:17.0093 0200 ComputerName: DOWN 17:06:17.0093 0200 UserName: Owner 17:06:17.0093 0200 Windows directory: C:\WINDOWS 17:06:17.0093 0200 System windows directory: C:\WINDOWS 17:06:17.0093 0200 Processor architecture: Intel x86 17:06:17.0093 0200 Number of processors: 1 17:06:17.0093 0200 Page size: 0x1000 17:06:17.0093 0200 Boot type: Normal boot 17:06:17.0093 0200 ============================================================ 17:06:24.0328 0200 Initialize success 17:06:25.0968 1664 ============================================================ 17:06:25.0968 1664 Scan started 17:06:25.0968 1664 Mode: Manual; 17:06:25.0968 1664 ============================================================ 17:06:26.0437 1664 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys 17:06:26.0437 1664 61883 - ok 17:06:26.0515 1664 Abiosdsk - ok 17:06:26.0546 1664 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 17:06:26.0562 1664 abp480n5 - ok 17:06:26.0625 1664 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 17:06:26.0640 1664 ACPI - ok 17:06:26.0796 1664 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 17:06:26.0796 1664 ACPIEC - ok 17:06:26.0843 1664 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 17:06:26.0843 1664 adpu160m - ok 17:06:26.0968 1664 adxapie - ok 17:06:27.0156 1664 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 17:06:27.0156 1664 aec - ok 17:06:27.0343 1664 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 17:06:27.0343 1664 AFD - ok 17:06:27.0531 1664 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 17:06:27.0531 1664 agp440 - ok 17:06:27.0656 1664 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 17:06:27.0656 1664 agpCPQ - ok 17:06:27.0750 1664 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 17:06:27.0750 1664 Aha154x - ok 17:06:27.0781 1664 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 17:06:27.0781 1664 aic78u2 - ok 17:06:27.0812 1664 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 17:06:27.0812 1664 aic78xx - ok 17:06:27.0968 1664 ALCXWDM (95aa37bec6c72c277c2caeaee736dd2d) C:\WINDOWS\system32\drivers\ALCXWDM.SYS 17:06:28.0031 1664 ALCXWDM - ok 17:06:28.0171 1664 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 17:06:28.0171 1664 AliIde - ok 17:06:28.0234 1664 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 17:06:28.0234 1664 alim1541 - ok 17:06:28.0343 1664 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 17:06:28.0343 1664 amdagp - ok 17:06:28.0453 1664 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 17:06:28.0468 1664 amsint - ok 17:06:28.0546 1664 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 17:06:28.0546 1664 Arp1394 - ok 17:06:28.0609 1664 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 17:06:28.0609 1664 asc - ok 17:06:28.0640 1664 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 17:06:28.0640 1664 asc3350p - ok 17:06:28.0671 1664 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 17:06:28.0671 1664 asc3550 - ok 17:06:28.0765 1664 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 17:06:28.0765 1664 ASCTRM - ok 17:06:28.0890 1664 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 17:06:28.0890 1664 AsyncMac - ok 17:06:29.0000 1664 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 17:06:29.0000 1664 atapi - ok 17:06:29.0062 1664 Atdisk - ok 17:06:29.0171 1664 ati2mtag (e564f459722294f0e3a47527783bd03c) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 17:06:29.0187 1664 ati2mtag - ok 17:06:29.0375 1664 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 17:06:29.0375 1664 Atmarpc - ok 17:06:29.0453 1664 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 17:06:29.0453 1664 audstub - ok 17:06:29.0515 1664 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys 17:06:29.0515 1664 Avc - ok 17:06:29.0593 1664 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 17:06:29.0609 1664 Beep - ok 17:06:29.0687 1664 BTKRNL (f61a79aadc40d7d719aa6c251ac074c2) C:\WINDOWS\system32\drivers\btkrnl.sys 17:06:29.0703 1664 BTKRNL - ok 17:06:29.0890 1664 BTSERIAL (2734d1e5c2f023c8be24f56d3e51382c) C:\WINDOWS\system32\drivers\btserial.sys 17:06:29.0890 1664 BTSERIAL - ok 17:06:29.0937 1664 BTSLBCSP (88be2d743ee82245658e5085d1fdc502) C:\WINDOWS\system32\drivers\btslbcsp.sys 17:06:29.0937 1664 BTSLBCSP - ok 17:06:30.0093 1664 catchme - ok 17:06:30.0234 1664 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 17:06:30.0234 1664 cbidf - ok 17:06:30.0265 1664 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 17:06:30.0265 1664 cbidf2k - ok 17:06:30.0328 1664 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 17:06:30.0328 1664 CCDECODE - ok 17:06:30.0375 1664 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 17:06:30.0375 1664 cd20xrnt - ok 17:06:30.0421 1664 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 17:06:30.0421 1664 Cdaudio - ok 17:06:30.0500 1664 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 17:06:30.0500 1664 Cdfs - ok 17:06:30.0593 1664 Cdr4_xp (837eef65af62d4e8a37c41d3879f7274) C:\WINDOWS\system32\drivers\Cdr4_xp.sys 17:06:30.0593 1664 Cdr4_xp - ok 17:06:30.0687 1664 Cdralw2k (579da2f9f5401f55dae2cf8779d61dfc) C:\WINDOWS\system32\drivers\Cdralw2k.sys 17:06:30.0687 1664 Cdralw2k - ok 17:06:30.0781 1664 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 17:06:30.0781 1664 Cdrom - ok 17:06:30.0843 1664 Changer - ok 17:06:30.0890 1664 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 17:06:30.0890 1664 CmdIde - ok 17:06:30.0937 1664 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 17:06:30.0937 1664 Cpqarray - ok 17:06:30.0984 1664 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 17:06:30.0984 1664 dac2w2k - ok 17:06:31.0093 1664 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 17:06:31.0093 1664 dac960nt - ok 17:06:31.0187 1664 DCamUSBEMPIA (5118ea8a2f55fa4d4295516500b78229) C:\WINDOWS\system32\DRIVERS\emDevice.sys 17:06:31.0187 1664 DCamUSBEMPIA - ok 17:06:31.0296 1664 DcCam (b1ad007f9a7dd8cfc981958d5c167d2d) C:\WINDOWS\system32\DRIVERS\DcCam.sys 17:06:31.0296 1664 DcCam - ok 17:06:31.0390 1664 DcFpoint (5fd20284caaf112201311619ff89fa44) C:\WINDOWS\system32\DRIVERS\DcFpoint.sys 17:06:31.0390 1664 DcFpoint - ok 17:06:31.0515 1664 DCFS2K (867f7e6841b15d32481c3f1b83364e3a) C:\WINDOWS\system32\drivers\dcfs2k.sys 17:06:31.0515 1664 DCFS2K - ok 17:06:31.0640 1664 DcLps (1b889ac45faf088ff2af690779368956) C:\WINDOWS\system32\DRIVERS\DcLps.sys 17:06:31.0640 1664 DcLps - ok 17:06:31.0750 1664 DcPTP (4afaea300a82f0470dc8b8abd619aba8) C:\WINDOWS\system32\DRIVERS\DcPTP.sys 17:06:31.0750 1664 DcPTP - ok 17:06:31.0875 1664 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 17:06:31.0875 1664 Disk - ok 17:06:31.0937 1664 dlyuojvsmw - ok 17:06:32.0015 1664 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 17:06:32.0015 1664 dmboot - ok 17:06:32.0187 1664 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 17:06:32.0187 1664 dmio - ok 17:06:32.0375 1664 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 17:06:32.0375 1664 dmload - ok 17:06:32.0500 1664 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 17:06:32.0500 1664 DMusic - ok 17:06:32.0625 1664 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 17:06:32.0625 1664 dpti2o - ok 17:06:32.0718 1664 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 17:06:32.0718 1664 drmkaud - ok 17:06:32.0812 1664 emAudio (200da4f1964c11b3c19a07f937394624) C:\WINDOWS\system32\drivers\emAudio.sys 17:06:32.0812 1664 emAudio - ok 17:06:32.0937 1664 EraserUtilDrv10821 - ok 17:06:33.0125 1664 Exportit (7ae55f93da22f0732993bce6093105dd) C:\WINDOWS\system32\DRIVERS\exportit.sys 17:06:33.0125 1664 Exportit - ok 17:06:33.0312 1664 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 17:06:33.0312 1664 Fastfat - ok 17:06:33.0500 1664 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 17:06:33.0500 1664 Fdc - ok 17:06:33.0718 1664 FilterService (f83c0fd028dd37be4a337b138eba6b7b) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys 17:06:33.0718 1664 FilterService - ok 17:06:33.0906 1664 FiltUSBEMPIA (6f87e4706f59463b74bc4fad0f67338f) C:\WINDOWS\system32\DRIVERS\emFilter.sys 17:06:33.0906 1664 FiltUSBEMPIA - ok 17:06:34.0031 1664 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 17:06:34.0031 1664 Fips - ok 17:06:34.0125 1664 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 17:06:34.0125 1664 Flpydisk - ok 17:06:34.0250 1664 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 17:06:34.0250 1664 FltMgr - ok 17:06:34.0343 1664 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 17:06:34.0343 1664 Fs_Rec - ok 17:06:34.0453 1664 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 17:06:34.0453 1664 Ftdisk - ok 17:06:34.0562 1664 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 17:06:34.0562 1664 GEARAspiWDM - ok 17:06:34.0656 1664 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 17:06:34.0656 1664 Gpc - ok 17:06:34.0703 1664 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 17:06:34.0703 1664 HidUsb - ok 17:06:34.0781 1664 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 17:06:34.0781 1664 hpn - ok 17:06:34.0875 1664 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 17:06:34.0875 1664 HPZid412 - ok 17:06:34.0984 1664 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 17:06:34.0984 1664 HPZipr12 - ok 17:06:35.0046 1664 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 17:06:35.0046 1664 HPZius12 - ok 17:06:35.0125 1664 HSFHWBS2 (c02dc9d4358e43d088f2061c2b2bf30e) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 17:06:35.0140 1664 HSFHWBS2 - ok 17:06:35.0343 1664 HSF_DP (b2dfc168d6f7512faea085253c5a37ad) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 17:06:35.0359 1664 HSF_DP - ok 17:06:35.0593 1664 HSF_DPV (cbf6831420a97e8fbb91e5f52b707ef7) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 17:06:35.0625 1664 HSF_DPV - ok 17:06:35.0796 1664 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 17:06:35.0828 1664 HTTP - ok 17:06:36.0000 1664 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 17:06:36.0000 1664 i2omgmt - ok 17:06:36.0046 1664 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 17:06:36.0046 1664 i2omp - ok 17:06:36.0078 1664 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 17:06:36.0078 1664 i8042prt - ok 17:06:36.0109 1664 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 17:06:36.0109 1664 Imapi - ok 17:06:36.0187 1664 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 17:06:36.0187 1664 ini910u - ok 17:06:36.0296 1664 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 17:06:36.0296 1664 IntelIde - ok 17:06:36.0390 1664 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 17:06:36.0390 1664 Ip6Fw - ok 17:06:36.0500 1664 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 17:06:36.0500 1664 IpFilterDriver - ok 17:06:36.0609 1664 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 17:06:36.0609 1664 IpInIp - ok 17:06:36.0718 1664 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 17:06:36.0718 1664 IpNat - ok 17:06:36.0906 1664 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 17:06:36.0906 1664 IPSec - ok 17:06:37.0000 1664 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 17:06:37.0000 1664 IRENUM - ok 17:06:37.0109 1664 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 17:06:37.0109 1664 isapnp - ok 17:06:37.0218 1664 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 17:06:37.0218 1664 Kbdclass - ok 17:06:37.0312 1664 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 17:06:37.0312 1664 kbdhid - ok 17:06:37.0421 1664 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 17:06:37.0421 1664 kmixer - ok 17:06:37.0609 1664 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 17:06:37.0609 1664 KSecDD - ok 17:06:37.0671 1664 lbrtfdc - ok 17:06:37.0781 1664 Linksys_adapter_H (bcdf72dce41874b3ad9143d537b493b2) C:\WINDOWS\system32\DRIVERS\AE2500xp.sys 17:06:37.0812 1664 Linksys_adapter_H - ok 17:06:38.0031 1664 LVcKap (9ce361764c5dd5fa5506510fe5d2297b) C:\WINDOWS\system32\DRIVERS\LVcKap.sys 17:06:38.0046 1664 LVcKap - ok 17:06:38.0234 1664 LVPr2Mon (94d03b31f36bb362fa5713470fcf1c79) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys 17:06:38.0234 1664 LVPr2Mon - ok 17:06:38.0312 1664 LVUSBSta (8b79a50360fc31df6b7b979b686b4aa2) C:\WINDOWS\system32\drivers\LVUSBSta.sys 17:06:38.0312 1664 LVUSBSta - ok 17:06:38.0562 1664 LVUVC (5c20c4be679842cbee729b0cff5928bd) C:\WINDOWS\system32\DRIVERS\lvuvc.sys 17:06:38.0718 1664 LVUVC - ok 17:06:38.0921 1664 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 17:06:38.0921 1664 mdmxsdk - ok 17:06:39.0015 1664 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys 17:06:39.0015 1664 MHNDRV - ok 17:06:39.0125 1664 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 17:06:39.0125 1664 mnmdd - ok 17:06:39.0218 1664 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 17:06:39.0218 1664 Modem - ok 17:06:39.0328 1664 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 17:06:39.0328 1664 Mouclass - ok 17:06:39.0421 1664 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 17:06:39.0437 1664 mouhid - ok 17:06:39.0562 1664 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 17:06:39.0562 1664 MountMgr - ok 17:06:39.0640 1664 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys 17:06:39.0640 1664 MPE - ok 17:06:39.0750 1664 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 17:06:39.0750 1664 mraid35x - ok 17:06:39.0812 1664 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 17:06:39.0812 1664 MRxDAV - ok 17:06:40.0000 1664 MSDV (1477849772712bac69c144dcf2c9ce81) C:\WINDOWS\system32\DRIVERS\msdv.sys 17:06:40.0000 1664 MSDV - ok 17:06:40.0187 1664 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 17:06:40.0187 1664 Msfs - ok 17:06:40.0359 1664 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 17:06:40.0359 1664 MSKSSRV - ok 17:06:40.0484 1664 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 17:06:40.0484 1664 MSPCLOCK - ok 17:06:40.0593 1664 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 17:06:40.0593 1664 MSPQM - ok 17:06:40.0687 1664 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 17:06:40.0687 1664 mssmbios - ok 17:06:40.0781 1664 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 17:06:40.0781 1664 MSTEE - ok 17:06:40.0890 1664 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 17:06:40.0890 1664 Mup - ok 17:06:41.0078 1664 mxnic (e1cdf20697d992cf83ff86dd04df1285) C:\WINDOWS\system32\DRIVERS\mxnic.sys 17:06:41.0078 1664 mxnic - ok 17:06:41.0187 1664 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 17:06:41.0187 1664 NABTSFEC - ok 17:06:41.0312 1664 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 17:06:41.0312 1664 NDIS - ok 17:06:41.0484 1664 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 17:06:41.0484 1664 NdisIP - ok 17:06:41.0656 1664 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 17:06:41.0656 1664 NdisTapi - ok 17:06:41.0781 1664 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 17:06:41.0781 1664 Ndisuio - ok 17:06:41.0875 1664 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 17:06:41.0875 1664 NdisWan - ok 17:06:41.0968 1664 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 17:06:41.0968 1664 NDProxy - ok 17:06:42.0062 1664 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 17:06:42.0078 1664 NetBT - ok 17:06:42.0265 1664 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 17:06:42.0265 1664 NIC1394 - ok 17:06:42.0359 1664 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 17:06:42.0359 1664 Npfs - ok 17:06:42.0515 1664 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 17:06:42.0531 1664 Ntfs - ok 17:06:42.0734 1664 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 17:06:42.0734 1664 Null - ok 17:06:42.0953 1664 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 17:06:43.0015 1664 nv - ok 17:06:43.0156 1664 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 17:06:43.0156 1664 NwlnkFlt - ok 17:06:43.0218 1664 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 17:06:43.0218 1664 NwlnkFwd - ok 17:06:43.0296 1664 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 17:06:43.0296 1664 ohci1394 - ok 17:06:43.0406 1664 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys 17:06:43.0406 1664 P3 - ok 17:06:43.0531 1664 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 17:06:43.0531 1664 Parport - ok 17:06:43.0718 1664 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 17:06:43.0718 1664 PartMgr - ok 17:06:43.0828 1664 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 17:06:43.0828 1664 ParVdm - ok 17:06:43.0937 1664 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 17:06:43.0937 1664 PCI - ok 17:06:44.0015 1664 PCIDump - ok 17:06:44.0078 1664 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 17:06:44.0078 1664 PCIIde - ok 17:06:44.0156 1664 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 17:06:44.0171 1664 Pcmcia - ok 17:06:44.0250 1664 PDCOMP - ok 17:06:44.0265 1664 PDFRAME - ok 17:06:44.0296 1664 PDRELI - ok 17:06:44.0312 1664 PDRFRAME - ok 17:06:44.0375 1664 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 17:06:44.0375 1664 perc2 - ok 17:06:44.0500 1664 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 17:06:44.0500 1664 perc2hib - ok 17:06:44.0640 1664 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 17:06:44.0640 1664 PptpMiniport - ok 17:06:44.0750 1664 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 17:06:44.0750 1664 Processor - ok 17:06:44.0843 1664 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 17:06:44.0843 1664 PSched - ok 17:06:44.0937 1664 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 17:06:44.0937 1664 Ptilink - ok 17:06:45.0046 1664 PxHelp20 (d970470f8f39470bdae94d313a1ccdce) C:\WINDOWS\system32\Drivers\PxHelp20.sys 17:06:45.0046 1664 PxHelp20 - ok 17:06:45.0156 1664 PzWDM (36cf3653d367cbc72a38625543f3d4d1) C:\WINDOWS\system32\Drivers\PzWDM.sys 17:06:45.0156 1664 PzWDM - ok 17:06:45.0250 1664 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 17:06:45.0250 1664 ql1080 - ok 17:06:45.0328 1664 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 17:06:45.0343 1664 Ql10wnt - ok 17:06:45.0437 1664 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 17:06:45.0437 1664 ql12160 - ok 17:06:45.0562 1664 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 17:06:45.0562 1664 ql1240 - ok 17:06:45.0656 1664 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 17:06:45.0656 1664 ql1280 - ok 17:06:45.0750 1664 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 17:06:45.0750 1664 RasAcd - ok 17:06:45.0859 1664 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 17:06:45.0859 1664 Rasl2tp - ok 17:06:45.0953 1664 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 17:06:45.0953 1664 RasPppoe - ok 17:06:46.0046 1664 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 17:06:46.0046 1664 Raspti - ok 17:06:46.0156 1664 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 17:06:46.0156 1664 RDPCDD - ok 17:06:46.0218 1664 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 17:06:46.0234 1664 rdpdr - ok 17:06:46.0328 1664 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 17:06:46.0328 1664 RDPWD - ok 17:06:46.0515 1664 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 17:06:46.0515 1664 redbook - ok 17:06:46.0593 1664 RimUsb - ok 17:06:46.0656 1664 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 17:06:46.0656 1664 RimVSerPort - ok 17:06:46.0750 1664 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 17:06:46.0750 1664 ROOTMODEM - ok 17:06:46.0921 1664 RT61 (581e74880aeb1dba1cb5ac8e6e6c0a69) C:\WINDOWS\system32\DRIVERS\RT61.sys 17:06:46.0921 1664 RT61 - ok 17:06:47.0109 1664 RTL8023xp (e9877aa069dc11b03dbd1d33b8b2a3ca) C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys 17:06:47.0109 1664 RTL8023xp - ok 17:06:47.0187 1664 RTLWUSB (f564f1c5813b47a86903d42cd778311c) C:\WINDOWS\system32\DRIVERS\wg111v2.sys 17:06:47.0187 1664 RTLWUSB - ok 17:06:47.0359 1664 ScanUSBEMPIA (f5a633609777c212ec5ff19927fc5955) C:\WINDOWS\system32\DRIVERS\emScan.sys 17:06:47.0359 1664 ScanUSBEMPIA - ok 17:06:47.0468 1664 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 17:06:47.0468 1664 Secdrv - ok 17:06:47.0578 1664 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 17:06:47.0578 1664 Serenum - ok 17:06:47.0687 1664 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 17:06:47.0687 1664 Serial - ok 17:06:47.0796 1664 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 17:06:47.0796 1664 Sfloppy - ok 17:06:47.0859 1664 Simbad - ok 17:06:47.0921 1664 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 17:06:47.0921 1664 sisagp - ok 17:06:48.0015 1664 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 17:06:48.0015 1664 SLIP - ok 17:06:48.0125 1664 snpstd2 (6db1737f710860c1685bface72798535) C:\WINDOWS\system32\DRIVERS\snpstd2.sys 17:06:48.0125 1664 snpstd2 - ok 17:06:48.0312 1664 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 17:06:48.0312 1664 Sparrow - ok 17:06:48.0359 1664 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 17:06:48.0359 1664 splitter - ok 17:06:48.0437 1664 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 17:06:48.0437 1664 sr - ok 17:06:48.0578 1664 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 17:06:48.0578 1664 Srv - ok 17:06:48.0796 1664 SSKBFD (8564bc9598be1705477b7fa61d657c2b) C:\WINDOWS\system32\Drivers\sskbfd.sys 17:06:48.0796 1664 SSKBFD - ok 17:06:48.0984 1664 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys 17:06:48.0984 1664 StillCam - ok 17:06:49.0078 1664 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 17:06:49.0078 1664 streamip - ok 17:06:49.0187 1664 SunkFilt (86ca1a5c15a5a98d5533945fb1120b05) C:\WINDOWS\System32\Drivers\sunkfilt.sys 17:06:49.0187 1664 SunkFilt - ok 17:06:49.0296 1664 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 17:06:49.0296 1664 swenum - ok 17:06:49.0359 1664 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 17:06:49.0359 1664 swmidi - ok 17:06:49.0484 1664 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 17:06:49.0484 1664 symc810 - ok 17:06:49.0609 1664 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 17:06:49.0609 1664 symc8xx - ok 17:06:49.0718 1664 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 17:06:49.0718 1664 sym_hi - ok 17:06:49.0812 1664 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 17:06:49.0828 1664 sym_u3 - ok 17:06:49.0921 1664 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 17:06:49.0921 1664 sysaudio - ok 17:06:50.0062 1664 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 17:06:50.0062 1664 Tcpip - ok 17:06:50.0265 1664 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 17:06:50.0265 1664 TDPIPE - ok 17:06:50.0375 1664 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 17:06:50.0375 1664 TDTCP - ok 17:06:50.0593 1664 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 17:06:50.0593 1664 TermDD - ok 17:06:50.0781 1664 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 17:06:50.0781 1664 TosIde - ok 17:06:50.0984 1664 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 17:06:50.0984 1664 Udfs - ok 17:06:51.0093 1664 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 17:06:51.0093 1664 ultra - ok 17:06:51.0296 1664 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 17:06:51.0312 1664 Update - ok 17:06:51.0515 1664 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 17:06:51.0515 1664 USBAAPL - ok 17:06:51.0640 1664 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 17:06:51.0640 1664 usbaudio - ok 17:06:51.0843 1664 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 17:06:51.0843 1664 usbccgp - ok 17:06:51.0953 1664 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 17:06:51.0953 1664 usbehci - ok 17:06:52.0062 1664 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 17:06:52.0062 1664 usbhub - ok 17:06:52.0171 1664 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 17:06:52.0171 1664 usbohci - ok 17:06:52.0281 1664 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 17:06:52.0281 1664 usbprint - ok 17:06:52.0359 1664 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 17:06:52.0359 1664 usbscan - ok 17:06:52.0468 1664 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 17:06:52.0468 1664 USBSTOR - ok 17:06:52.0593 1664 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 17:06:52.0593 1664 usbvideo - ok 17:06:52.0703 1664 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys 17:06:52.0703 1664 usb_rndisx - ok 17:06:52.0890 1664 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 17:06:52.0890 1664 VgaSave - ok 17:06:52.0984 1664 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 17:06:52.0984 1664 viaagp - ok 17:06:53.0078 1664 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 17:06:53.0078 1664 ViaIde - ok 17:06:53.0187 1664 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 17:06:53.0187 1664 VolSnap - ok 17:06:53.0281 1664 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 17:06:53.0281 1664 Wanarp - ok 17:06:53.0343 1664 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys 17:06:53.0343 1664 wanatw - ok 17:06:53.0421 1664 WDICA - ok 17:06:53.0515 1664 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 17:06:53.0515 1664 wdmaud - ok 17:06:53.0671 1664 winachsf (59d043485a6eda2ed2685c81489ae5bd) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 17:06:53.0703 1664 winachsf - ok 17:06:53.0921 1664 WRkrn (20fe8507d2c728191f1e02b590a590bf) C:\WINDOWS\system32\drivers\WRkrn.sys 17:06:53.0921 1664 WRkrn - ok 17:06:54.0093 1664 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 17:06:54.0093 1664 WSTCODEC - ok 17:06:54.0156 1664 MBR (0x1B8) (b20939cd98b7710036274839082ae757) \Device\Harddisk0\DR0 17:06:54.0187 1664 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - infected 17:06:54.0187 1664 \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0) 17:06:54.0187 1664 MBR (0x1B8) (8ff255184f078c9c04e6a2ce66117c5c) \Device\Harddisk1\DR3 17:06:54.0203 1664 \Device\Harddisk1\DR3 - ok 17:06:54.0218 1664 Boot (0x1200) (ff1e78c5651cd4fce74d82e39a4f9062) \Device\Harddisk0\DR0\Partition0 17:06:54.0218 1664 \Device\Harddisk0\DR0\Partition0 - ok 17:06:54.0234 1664 Boot (0x1200) (710987d3f239ac8248edcad47c03b606) \Device\Harddisk0\DR0\Partition1 17:06:54.0234 1664 \Device\Harddisk0\DR0\Partition1 - ok 17:06:54.0234 1664 Boot (0x1200) (5e26ca2143066e040cf0fdadde170e77) \Device\Harddisk1\DR3\Partition0 17:06:54.0234 1664 \Device\Harddisk1\DR3\Partition0 - ok 17:06:54.0250 1664 ============================================================ 17:06:54.0250 1664 Scan finished 17:06:54.0250 1664 ============================================================ 17:06:54.0265 2052 Detected object count: 1 17:06:54.0265 2052 Actual detected object count: 1 17:08:01.0687 2052 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - skipped by user 17:08:01.0687 2052 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - User select action: Skip 17:08:53.0734 4000 Deinitialize success aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-26 17:00:12 —————————– 17:00:12.703 OS Version: Windows 5.1.2600 Service Pack 3 17:00:12.703 Number of processors: 1 586 0x2F02 17:00:12.703 ComputerName: DOWN UserName: 17:00:15.281 Initialize success 17:00:39.031 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-1f 17:00:39.046 Disk 0 Vendor: WDC_WD2000BB-22GUC0 08.02D08 Size: 190782MB BusType: 3 17:00:41.062 Disk 0 MBR read successfully 17:00:41.062 Disk 0 MBR scan 17:00:41.062 Disk 0 unknown MBR code 17:00:41.062 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 186512 MB offset 8723295 17:00:41.062 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4259 MB offset 63 17:00:41.062 Disk 0 scanning sectors +390700800 17:00:41.093 Disk 0 malicious Win32:MBRoot code @ sector 390700803 ! 17:00:41.093 Disk 0 PE file @ sector 390700825 ! 17:00:41.109 Disk 0 scanning C:\WINDOWS\system32\drivers 17:00:50.203 Service scanning 17:00:51.828 Service WRkrn C:\WINDOWS\System32\drivers\WRkrn.sys **LOCKED** 32 17:00:52.343 Modules scanning 17:01:13.984 Disk 0 trace - called modules: 17:01:14.000 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 17:01:14.000 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d5c030] 17:01:14.015 3 CLASSPNP.SYS[f7650fd7] -> nt!IofCallDriver -> \Device\0000009d[0x85d579e8] 17:01:14.015 5 ACPI.sys[f7467620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-1f[0x85d56d98] 17:01:14.015 Scan finished successfully 17:02:17.250 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 17:02:17.265 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
Thanks for the info. Let's try and remove your infections first as that might be affecting your internet connectivity.

Next, Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
I thought I had turned off the webroot but it was still running

ComboFix 11-12-26.03 - Owner 12/26/2011 17:58:10.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.272 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\invokesi.exe
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\HelpAssistant\GoToAssistDownloadHelper.exe
c:\documents and settings\HelpAssistant\WINDOWS
c:\documents and settings\Owner\Application Data\iniasd.txt
c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
c:\documents and settings\Owner\My Documents\~WRL0002.tmp
c:\documents and settings\Owner\My Documents\~WRL0079.tmp
c:\documents and settings\Owner\My Documents\~WRL0481.tmp
c:\documents and settings\Owner\My Documents\~WRL0570.tmp
c:\documents and settings\Owner\My Documents\~WRL0714.tmp
c:\documents and settings\Owner\My Documents\~WRL0929.tmp
c:\documents and settings\Owner\My Documents\~WRL1930.tmp
c:\documents and settings\Owner\My Documents\~WRL2614.tmp
c:\documents and settings\Owner\WINDOWS
C:\p2hhr.bat
c:\program files\Internet Explorer\SET52.tmp
c:\program files\Internet Explorer\SET53.tmp
c:\program files\Internet Explorer\SET55.tmp
c:\program files\Internet Explorer\SETCAE.tmp
C:\Thumbs.db
c:\windows\alcrmv.exe
c:\windows\bf23567.dat
c:\windows\ikaculowam._sy
c:\windows\system32\CF27596.exe
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\drivers\npf.sys
c:\windows\system32\GroupPolicy\User\Scripts\Logon\autorun.bat
c:\windows\system32\OLDC2.tmp
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SET5F.tmp
c:\windows\system32\SET60.tmp
c:\windows\system32\SET62.tmp
c:\windows\system32\SET63.tmp
c:\windows\system32\SET64.tmp
c:\windows\system32\SET65.tmp
c:\windows\system32\SET66.tmp
c:\windows\system32\SET68.tmp
c:\windows\system32\SET6A.tmp
c:\windows\system32\SET6B.tmp
c:\windows\system32\SET6C.tmp
c:\windows\system32\SET6F.tmp
c:\windows\system32\SET70.tmp
c:\windows\system32\SET73.tmp
c:\windows\system32\SET74.tmp
c:\windows\system32\SET76.tmp
c:\windows\system32\SET79.tmp
c:\windows\system32\SET7A.tmp
c:\windows\system32\SET7B.tmp
c:\windows\system32\SET7C.tmp
c:\windows\system32\SET7D.tmp
c:\windows\system32\SET7E.tmp
c:\windows\system32\SET82.tmp
c:\windows\system32\SET83.tmp
c:\windows\system32\SET84.tmp
c:\windows\system32\SET85.tmp
c:\windows\system32\SET86.tmp
c:\windows\system32\SET87.tmp
c:\windows\system32\SET88.tmp
c:\windows\system32\SET89.tmp
c:\windows\system32\SET8A.tmp
c:\windows\system32\SET8B.tmp
c:\windows\system32\SET8C.tmp
c:\windows\system32\SET8E.tmp
c:\windows\system32\SET8F.tmp
c:\windows\system32\SET90.tmp
c:\windows\system32\SET91.tmp
c:\windows\system32\SETCBD.tmp
c:\windows\system32\SETCBE.tmp
c:\windows\system32\SETCBF.tmp
c:\windows\system32\SETCC0.tmp
c:\windows\system32\SETCCF.tmp
c:\windows\system32\SETCD5.tmp
c:\windows\system32\SETCDC.tmp
c:\windows\system32\SETCE3.tmp
c:\windows\system32\SETCE4.tmp
c:\windows\system32\SETCE5.tmp
c:\windows\system32\SETCE7.tmp
c:\windows\system32\SETCF1.tmp
c:\windows\system32\SETCF3.tmp
c:\windows\system32\SETCF4.tmp
c:\windows\system32\SETCF5.tmp
c:\windows\system32\SETCF6.tmp
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\TEMP\logishrd\LVPrcInj02.dll
.
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_COMSERVER
——-\Legacy_USNJSVC
——-\Service_COMServer
——-\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-11-27 to 2011-12-27 )))))))))))))))))))))))))))))))
.
.
2011-12-27 00:10 . 2008-04-14 00:12 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2011-12-27 00:10 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2011-12-24 19:20 . 2011-12-24 19:21 ——– d—–w- C:\Docum
2011-12-24 16:10 . 2011-12-24 16:10 141272 —-a-w- c:\windows\system32\WRusr.dll
2011-12-24 16:10 . 2011-12-24 16:10 107336 —-a-w- c:\windows\system32\drivers\WRkrn.sys
2011-12-16 13:53 . 2011-03-30 06:22 1034240 —-a-r- c:\windows\system32\drivers\AE2500xp.sys
2011-12-12 02:17 . 2011-12-12 02:17 ——– d—–w- c:\program files\Trend Micro
2011-12-11 22:40 . 2011-12-11 22:40 ——– d—–w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-26 16:02 . 2011-10-29 15:03 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 2005-04-13 16:56 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07 . 2005-04-13 16:55 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-31 23:43 . 2005-04-13 16:56 832512 —-a-w- c:\windows\system32\wininet.dll
2011-10-31 23:43 . 2005-04-13 16:55 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-10-31 23:43 . 2005-04-13 16:55 1830912 ——w- c:\windows\system32\inetcpl.cpl
2011-10-31 23:43 . 2005-04-13 16:55 17408 ——w- c:\windows\system32\corpol.dll
2011-10-28 05:31 . 2005-04-13 16:55 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2005-04-13 16:55 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-04 05:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-14 23:38 . 2005-04-13 16:55 456192 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2005-04-13 17:16 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2005-04-13 16:55 599040 —-a-w- c:\windows\system32\crypt32.dll
2008-02-24 16:42 . 2010-07-19 17:10 267592 -c–a-w- c:\program files\Uninstall Ask Toolbar.dll
2011-11-13 18:29 . 2011-10-07 01:43 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-21 1207080]
"HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-05-25 1801064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208]
"WRSVC"="c:\program files\Webroot\WRSA.exe" [2011-12-24 637208]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Monitor Ink Alerts - HP Photosmart 5510 series (Network).lnk - c:\windows\system32\RunDll32.exe [2005-4-13 33280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digimax Viewer 2.1.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digimax Viewer 2.1.lnk
backup=c:\windows\pss\Digimax Viewer 2.1.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^scandisk.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\scandisk.lnk
backup=c:\windows\pss\scandisk.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-03-18 04:05 339968 -c–a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
2005-05-03 21:02 543232 -c–a-w- c:\windows\zHotkey.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dcmsvc]
2009-04-07 19:53 30440 -c–a-w- c:\program files\dcmsvc\dcmsvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2008-02-03 08:43 113136 -c–a-w- c:\program files\Roxio\CinePlayer\DMXLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 19:56 64512 -c–a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-06-21 04:36 1207080 —-a-w- c:\progra~1\MI3AA1~1\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2011-03-24 18:13 49208 —-a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
2006-02-17 16:59 124520 -c–a-w- c:\program files\Common Files\AOL\IPHSend\IPHSend.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 23:06 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2008-02-13 19:02 564496 —-a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-02-13 19:06 2196240 —-a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2007-10-18 17:34 5724184 -c–a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 18:50 155648 -c–a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nike+ Connect]
2010-10-01 15:26 299008 —-a-w- c:\program files\Nike\Nike+ Connect\Nike+ Connect daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
2007-12-11 23:21 227914 -c–a-w- c:\program files\Plaxo\2.13.1.3\PlaxoHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 17:17 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-03 03:24 32768 -c–a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2007-03-26 13:07 228088 -c–a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-10-09 19:11 25623336 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2]
2004-01-06 00:34 40960 -c–a-w- c:\windows\vsnpstd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-04-15 18:01 77824 -c–a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 16:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
2004-11-15 22:04 135168 -c–a-w- c:\program files\Digital Media Reader\shwiconEM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB2Check]
2006-11-06 19:31 81920 -c–a-w- c:\windows\system32\PCLECoInst.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135205439\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135205439\\ee\\aim6.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3246:TCP"= 3246:TCP:Services
"3389:TCP"= 3389:TCP:*:Disabled:Remote Desktop
.
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [3/26/2009 7:41 PM 15172]
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [12/24/2011 10:10 AM 107336]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [6/15/2011 4:33 PM 249648]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/17/2007 7:43 AM 24652]
R3 Linksys_adapter_H;Linksys Adapter Network Driver;c:\windows\system32\drivers\AE2500xp.sys [12/16/2011 7:53 AM 1034240]
S2 dlyuojvsmw;dlyuojvsmw;\??\c:\windows\system32\drivers\nhhiqsce.sys –> c:\windows\system32\drivers\nhhiqsce.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/17/2011 8:52 PM 135664]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [2/3/2008 7:24 AM 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2/3/2008 7:23 AM 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2/3/2008 7:23 AM 166384]
S2 SessionLauncher;SessionLauncher;c:\docume~1\Owner\LOCALS~1\Temp\DX9\SessionLauncher.exe –> c:\docume~1\Owner\LOCALS~1\Temp\DX9\SessionLauncher.exe [?]
S2 WRSVC;WRSVC;c:\program files\Webroot\WRSA.exe [12/24/2011 10:10 AM 637208]
S3 adxapie;adxapie;\??\c:\docume~1\Owner\LOCALS~1\Temp\adxapie.sys –> c:\docume~1\Owner\LOCALS~1\Temp\adxapie.sys [?]
S3 EraserUtilDrv10821;EraserUtilDrv10821;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10821.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10821.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/17/2011 8:52 PM 135664]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2/3/2008 7:24 AM 313840]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2/3/2008 7:23 AM 1112560]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [4/6/2010 11:32 AM 112384]
S4 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [7/7/2011 6:31 PM 195336]
S4 HPHNDUSVC;HP Home Network Diagnostic Support Service;c:\windows\system32\svchost.exe -k HPHNDUService [4/13/2005 10:56 AM 14336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPHNDUService REG_MULTI_SZ HPHNDUSVC
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 18:34]
.
2011-12-26 c:\windows\Tasks\At1.job
- c:\program files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-05-25 22:13]
.
2011-12-24 c:\windows\Tasks\At2.job
- c:\program files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-05-25 22:13]
.
2011-12-26 c:\windows\Tasks\At3.job
- c:\program files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-05-25 22:13]
.
2011-12-24 c:\windows\Tasks\At4.job
- c:\program files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-05-25 22:13]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-18 02:52]
.
2011-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-18 02:52]
.
2011-12-26 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\documents and settings\All Users\Application Data\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
2011-12-27 c:\windows\Tasks\User_Feed_Synchronization-{40BAB767-0634-4F0E-ACD8-98DBCC8E7825}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 23:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.msnbc.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = ;*.local
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth; - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{22CC3EBD-C286-43aa-B8E6-06B115F74162} - c:\program files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
TCP: DhcpNameServer = [removed] [removed] [removed]
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\Common Files\Microsoft Shared\Information Retrieval\itss51.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\wrr4ifwe.default\
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
——- File Associations ——-
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Cleanup - c:\docume~1\Owner\LOCALS~1\Temp\20051215152057_mcappins.exe
MSConfigStartUp-msci - c:\docume~1\Owner\LOCALS~1\Temp\20051215152057_mcinfo.exe
MSConfigStartUp-Windows update loader - c:\windows\xpupdate.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-26 18:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2422651582-2935789365-712990506-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-2422651582-2935789365-712990506-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Param2"=""
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(7412)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\HP Photosmart 5510 series\bin\HPNetworkCommunicator.exe
.
**************************************************************************
.
Completion time: 2011-12-26 18:26:25 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-27 00:26
ComboFix2.txt 2009-07-07 00:58
.
Pre-Run: 81,952,940,032 bytes free
Post-Run: 82,055,524,352 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - FFF961203EDE65300BE107FBAC49A4F9
Hi Dadrepairman,

Looks like ComboFix did it's job, so not to worry.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/index.php?s=&showtopic=121737&view=findpost&p=765095

Driver::
dlyuojvsmw
adxapie

Collect::
c:\windows\system32\drivers\nhhiqsce.sys
c:\docume~1\Owner\LOCALS~1\Temp\adxapie.sys

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"=-
"52344:TCP"=-
"2479:TCP"=-
"3246:TCP"=-
"3389:TCP"=-
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste

===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also please describe how your computer behaves at the moment.
Computer Dropped script into Combo – Turned on combo – Wanted to create Microsoft recovery console, which it had done earlier – Said I was not connect but I was. aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-26 19:03:27 —————————– 19:03:27.126 OS Version: Windows 5.1.2600 Service Pack 3 19:03:27.126 Number of processors: 1 586 0x2F02 19:03:27.126 ComputerName: DOWN UserName: 19:03:28.969 Initialize success 19:03:36.032 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-1f 19:03:36.032 Disk 0 Vendor: WDC_WD2000BB-22GUC0 08.02D08 Size: 190782MB BusType: 3 19:03:38.048 Disk 0 MBR read successfully 19:03:38.048 Disk 0 MBR scan 19:03:38.048 Disk 0 unknown MBR code 19:03:38.079 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 186512 MB offset 8723295 19:03:38.079 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4259 MB offset 63 19:03:38.079 Disk 0 scanning sectors +390700800 19:03:38.094 Disk 0 malicious Win32:MBRoot code @ sector 390700803 ! 19:03:38.110 Disk 0 PE file @ sector 390700825 ! 19:03:38.126 Disk 0 scanning C:\WINDOWS\system32\drivers 19:03:46.813 Service scanning 19:03:48.235 Modules scanning 19:04:03.360 Disk 0 trace - called modules: 19:04:03.391 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 19:04:03.391 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d87030] 19:04:03.391 3 CLASSPNP.SYS[f7651fd7] -> nt!IofCallDriver -> \Device\0000009f[0x85d6c9e8] 19:04:03.391 5 ACPI.sys[f7468620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-1f[0x85d7e940] 19:04:03.391 Scan finished successfully 19:05:04.423 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 19:05:04.438 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR_after combo fix.txt" _________________ Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122605 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 12/26/2011 8:17:06 PM mbam-log-2011-12-26 (20-17-06).txt Scan type: Quick scan Objects scanned: 230673 Time elapsed: 8 minute(s), 42 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 6 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{C48635AD-D6B5-3EE4-AAA2-540D5A173658} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{C48635AD-D6B5-3EE4-AAA2-540D5A173658} (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\program files\uninstall ask toolbar.dll (Adware.AskSBAR) -> Quarantined and deleted successfully. c:\documents and settings\helpassistant\Desktop\antiviruspro_2010.lnk (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully. c:\documents and settings\helpassistant\Desktop\windows police pro.lnk (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully. c:\documents and settings\helpassistant\start menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully. c:\documents and settings\helpassistant\local settings\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\helpassistant\local settings\Temp\pskfo83wijf89uwuhal8.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
Hi Dadrepairman,

  • Re-Run aswMBR.
  • Click Scan.
  • On completion of the scan.
  • Click the FIXMBR button.

[external image: Posted Image]

[external image: Posted Image]

Save the log as before and post in your next reply
aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-26 21:30:49 —————————– 21:30:49.328 OS Version: Windows 5.1.2600 Service Pack 3 21:30:49.328 Number of processors: 1 586 0x2F02 21:30:49.328 ComputerName: DOWN UserName: 21:30:50.562 Initialize success 21:30:56.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-1f 21:30:56.062 Disk 0 Vendor: WDC_WD2000BB-22GUC0 08.02D08 Size: 190782MB BusType: 3 21:30:58.078 Disk 0 MBR read successfully 21:30:58.078 Disk 0 MBR scan 21:30:58.078 Disk 0 unknown MBR code 21:30:58.093 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 186512 MB offset 8723295 21:30:58.093 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4259 MB offset 63 21:30:58.093 Disk 0 scanning sectors +390700800 21:30:58.125 Disk 0 malicious Win32:MBRoot code @ sector 390700803 ! 21:30:58.140 Disk 0 scanning C:\WINDOWS\system32\drivers 21:31:07.500 Service scanning 21:31:08.375 Service WRkrn C:\WINDOWS\System32\drivers\WRkrn.sys **LOCKED** 32 21:31:08.890 Modules scanning 21:31:22.453 Disk 0 trace - called modules: 21:31:22.468 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 21:31:22.468 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d1f030] 21:31:22.468 3 CLASSPNP.SYS[f7660fd7] -> nt!IofCallDriver -> \Device\0000009c[0x85d629e8] 21:31:22.468 5 ACPI.sys[f7467620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-1f[0x85d61940] 21:31:22.468 Scan finished successfully 21:31:39.000 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 21:31:39.015 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\asw_2MBR.txt"
Fix MMR was not bold and could not be clicked on. I clicked on Fix instead. attached is the log aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-26 21:49:00 —————————– 21:49:00.437 OS Version: Windows 5.1.2600 Service Pack 3 21:49:00.437 Number of processors: 1 586 0x2F02 21:49:00.437 ComputerName: DOWN UserName: 21:49:01.234 Initialize success 21:49:07.250 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-1f 21:49:07.250 Disk 0 Vendor: WDC_WD2000BB-22GUC0 08.02D08 Size: 190782MB BusType: 3 21:49:09.265 Disk 0 MBR read successfully 21:49:09.265 Disk 0 MBR scan 21:49:09.265 Disk 0 unknown MBR code 21:49:09.281 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 186512 MB offset 8723295 21:49:09.281 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4259 MB offset 63 21:49:09.281 Disk 0 scanning sectors +390700800 21:49:09.296 Disk 0 malicious Win32:MBRoot code @ sector 390700803 ! 21:49:09.328 Disk 0 scanning C:\WINDOWS\system32\drivers 21:49:18.203 Service scanning 21:49:18.921 Service WRkrn C:\WINDOWS\System32\drivers\WRkrn.sys **LOCKED** 32 21:49:19.437 Modules scanning 21:49:26.734 Disk 0 trace - called modules: 21:49:26.750 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 21:49:26.750 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d1f030] 21:49:26.750 3 CLASSPNP.SYS[f7660fd7] -> nt!IofCallDriver -> \Device\0000009c[0x85d629e8] 21:49:26.750 5 ACPI.sys[f7467620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-1f[0x85d61940] 21:49:26.765 Scan finished successfully 21:50:36.937 Disk 0 MBR read successfully 21:50:36.937 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 186512 MB offset 8723295 21:50:36.937 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4259 MB offset 63 21:50:36.953 Disk 0 scanning sectors +390700800 21:50:36.984 Disk 0 malicious Win32:MBRoot code @ sector 390700803 ! 21:50:36.984 Disk 0 sector 390700803 cleaned 21:50:36.984 Verifying disinfection 21:50:49.015 Infection fixed successfully - please reboot ASAP 21:51:11.406 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 21:51:11.406 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\asw 3 MBR.txt"
No, that's legit. That file belongs to Webroot. aswMBR cleaned your MBR infection :). I want to see if the files I was trying to script out are still there.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI