This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PING.EXE High CPU Usage [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My wife's laptop recently had the 2011 Antivirus Virus on it. I thought I had followed the instructions correctly to remove it but apparently it has burried itself further in her system than I thought. The PING.EXE process is using up to 100% of the CPU at times and making the laptop nearly unusable. Whenever it does start to spool itself up like that, Norton gives me "High CPU Usage by TCP/IP Command" pop-up warnings. Whenever it does this while I am browsing in Firefox, webpages will either fail to load or they will automatically redirect to spam search sites that have nothing to do with what was being searched. I have installed and attached the HJT log below:

_______________________________

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:46:57 PM, on 12/24/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Lauret\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 6106 bytes

______________________________

Any help in removing this nuissance is appreciated as it is getting out of my comfort zone in messing with it.
Hi drsulli,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
===================================================

In your next reply, please post the following:
  • DDS log
  • aswMBR log
  • TDSSKiller log
📎DDS_Attach.txtThank you for the prompt repsonse. I have run the logs you requested and posted them below: ____________ DDS LOG . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30 Run by [removed] at 9:57:10 on 2011-12-25 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1234 [GMT -5:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\rundll32.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\rundll32.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Windows\system32\msiexec.exe C:\Windows\system32\wuauclt.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\System32\ping.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\svchost.exe -k swprv . ============== Pseudo HJT Report =============== . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit uPolicies-explorer: HideSCAHealth = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: HideFastUserSwitching = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{4A58DC7B-18F9-40E0-ABAE-F7CEBDC2B2DF} : DhcpNameServer = 192.168.1.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\users\lauret\appdata\roaming\mozilla\firefox\profiles\hlu0htmn.default\ FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - plugin: c:\users\lauret\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\users\lauret\appdata\roaming\move networks\plugins\npqmp071505000011.dll FF - plugin: c:\users\lauret\appdata\roaming\move networks\plugins\npqmp071701000002.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-12-18 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-12-18 744568] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111221.003\BHDrvx86.sys [2011-12-22 819320] R1 IDSvix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20111223.001\IDSvix86.sys [2011-12-24 368248] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-12-18 136312] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys [2011-12-18 331384] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccSvcHst.exe [2011-12-18 130008] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-8-28 24652] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-12-18 106104] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968] . =============== Created Last 30 ================ . 2011-12-24 22:57:15 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-12-24 22:57:14 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2011-12-24 22:57:14 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2011-12-24 22:57:14 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2011-12-24 22:57:14 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll 2011-12-24 21:38:03 29184 —-a-w- c:\windows\system32\I8rYY8V.com 2011-12-19 04:18:03 ——– d—–w- c:\users\lauret\appdata\local\{697B084D-E9DE-4F66-A198-2EB865BFFCC8} 2011-12-19 04:17:44 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-12-19 04:17:41 ——– d—–w- c:\users\lauret\appdata\local\{67B93E90-C46A-4863-BAD0-0261B1A5DBA0} 2011-12-19 04:17:39 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2011-12-19 04:16:21 744568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys 2011-12-19 04:16:21 50168 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys 2011-12-19 04:16:21 340088 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys 2011-12-19 04:16:21 331384 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys 2011-12-19 04:16:21 296568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys 2011-12-19 04:16:20 516216 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys 2011-12-19 04:16:20 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys 2011-12-19 01:31:34 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D 2011-12-19 01:31:34 ——– d—–w- c:\windows\system32\drivers\N360 2011-12-19 01:31:32 ——– d—–w- c:\program files\Norton 360 2011-12-18 12:48:36 ——– d—–w- c:\users\lauret\appdata\local\{49924F84-B916-4E85-83E2-5B9CAADB2621} 2011-12-18 12:48:00 ——– d—–w- c:\users\lauret\appdata\local\{02EAE8E0-A6A2-457F-BCC7-C9E982D415D3} 2011-12-17 12:21:22 ——– d—–w- c:\programdata\NortonInstaller 2011-12-17 12:21:22 ——– d—–w- c:\program files\NortonInstaller 2011-12-17 12:19:47 ——– d—–w- c:\programdata\Norton 2011-12-17 12:05:55 ——– d—–w- c:\users\lauret\appdata\local\{9B70D02F-822B-492D-B268-1528EFECDD71} 2011-12-17 12:05:35 ——– d—–w- c:\users\lauret\appdata\local\{40464F0A-60DA-40B7-B5CA-FA635BBBBDD8} 2011-12-16 23:57:06 ——– d—–w- c:\users\lauret\appdata\local\{7BF63D29-C376-4AA3-9F6A-62C3A75BB8B1} 2011-12-16 23:56:45 ——– d—–w- c:\users\lauret\appdata\local\{7E53D3F6-55F2-4138-8746-5FE8D9820F97} 2011-12-15 13:41:20 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-12-15 13:41:20 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-12-15 13:41:19 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-12-15 13:41:17 2043904 —-a-w- c:\windows\system32\win32k.sys 2011-12-15 13:41:15 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-12-15 13:41:12 49152 —-a-w- c:\windows\system32\csrsrv.dll 2011-12-15 13:41:07 2048 —-a-w- c:\windows\system32\tzres.dll 2011-12-14 14:01:16 ——– d—–w- c:\users\lauret\appdata\local\{472B5DDA-5614-447B-9670-28CFD82F8EFC} 2011-12-14 01:40:54 ——– d—–w- c:\users\lauret\appdata\local\{3D22FF24-83F1-4611-A210-8A577A8E99F5} 2011-12-14 01:40:33 ——– d—–w- c:\users\lauret\appdata\local\{AC29A327-F78D-47D4-ADE8-2BF11B3263A5} 2011-12-14 01:08:58 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-01 18:13:00 ——– d—–w- c:\users\lauret\appdata\local\{FDCA4A67-5444-4F0E-9B58-C5F94074CB28} 2011-12-01 18:12:43 ——– d—–w- c:\users\lauret\appdata\local\{72EF95A4-74A6-4D22-96DE-3128BA0B1590} 2011-11-26 22:06:04 ——– d—–w- c:\users\lauret\appdata\local\{82DF8E73-6120-4B65-BED0-6B82C66D98B7} 2011-11-26 22:05:52 ——– d—–w- c:\users\lauret\appdata\local\{2A16786A-A340-4B7E-96D5-DB0AB2D57ECE} . ==================== Find3M ==================== . 2011-12-01 18:11:46 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-10 10:54:13 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-11-03 22:47:42 1798144 —-a-w- c:\windows\system32\jscript9.dll 2011-11-03 22:40:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2011-11-03 22:39:47 1127424 —-a-w- c:\windows\system32\wininet.dll 2011-11-03 22:31:57 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-10-02 21:33:29 87608 —-a-w- c:\users\lauret\appdata\roaming\inst.exe 2011-10-02 21:33:29 47360 —-a-w- c:\users\lauret\appdata\roaming\pcouffin.sys . ============= FINISH: 9:57:57.69 =============== ________________ ___________________ aswMBR aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-25 09:58:59 —————————– 09:58:59.737 OS Version: Windows 6.0.6002 Service Pack 2 09:58:59.737 Number of processors: 2 586 0x6802 09:58:59.738 ComputerName: LAURET-PC UserName: Lauret 09:59:03.667 Initialize success 09:59:42.144 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 09:59:42.148 Disk 0 Vendor: ST9200827AS 3.BHA Size: 190782MB BusType: 3 09:59:44.189 Disk 0 MBR read successfully 09:59:44.193 Disk 0 MBR scan 09:59:44.196 Disk 0 unknown MBR code 09:59:44.201 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 178746 MB offset 63 09:59:44.232 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 12033 MB offset 366073155 09:59:44.239 Disk 0 scanning sectors +390716865 09:59:44.329 Disk 0 scanning C:\Windows\system32\drivers 09:59:53.855 Service scanning 09:59:55.699 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 09:59:56.288 Modules scanning 10:00:02.228 Module: C:\Windows\system32\DRIVERS\smb.sys **SUSPICIOUS** 10:00:11.324 Disk 0 trace - called modules: 10:00:11.730 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x87afcf10]<< 10:00:11.739 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8588b620] 10:00:11.746 3 CLASSPNP.SYS[8a3b08b3] -> nt!IofCallDriver -> [0x87abc670] 10:00:11.754 \Driver\00001947[0x85fe5ef8] -> IRP_MJ_CREATE -> 0x87afcf10 10:00:11.761 Scan finished successfully 10:00:33.757 Disk 0 MBR has been saved successfully to "C:\Users\Lauret\Desktop\MBR.dat" 10:00:33.767 The log file has been saved successfully to "C:\Users\Lauret\Desktop\aswMBR.txt" _______________ _______________ TDSKiller 10:01:34.0742 6076 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 10:01:36.0742 6076 ============================================================ 10:01:36.0742 6076 Current date / time: 2011/12/25 10:01:36.0742 10:01:36.0742 6076 SystemInfo: 10:01:36.0742 6076 10:01:36.0742 6076 OS Version: 6.0.6002 ServicePack: 2.0 10:01:36.0742 6076 Product type: Workstation 10:01:36.0742 6076 ComputerName: LAURET-PC 10:01:36.0742 6076 UserName: Lauret 10:01:36.0742 6076 Windows directory: C:\Windows 10:01:36.0742 6076 System windows directory: C:\Windows 10:01:36.0742 6076 Processor architecture: Intel x86 10:01:36.0742 6076 Number of processors: 2 10:01:36.0742 6076 Page size: 0x1000 10:01:36.0742 6076 Boot type: Normal boot 10:01:36.0742 6076 ============================================================ 10:01:38.0252 6076 Initialize success 10:01:46.0062 4172 ============================================================ 10:01:46.0062 4172 Scan started 10:01:46.0062 4172 Mode: Manual; 10:01:46.0062 4172 ============================================================ 10:01:47.0512 4172 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 10:01:47.0512 4172 ACPI - ok 10:01:47.0632 4172 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 10:01:47.0642 4172 adp94xx - ok 10:01:47.0682 4172 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 10:01:47.0682 4172 adpahci - ok 10:01:47.0732 4172 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 10:01:47.0732 4172 adpu160m - ok 10:01:47.0792 4172 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 10:01:47.0792 4172 adpu320 - ok 10:01:47.0952 4172 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 10:01:47.0952 4172 AFD - ok 10:01:48.0042 4172 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 10:01:48.0052 4172 agp440 - ok 10:01:48.0112 4172 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 10:01:48.0112 4172 aic78xx - ok 10:01:48.0142 4172 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 10:01:48.0142 4172 aliide - ok 10:01:48.0192 4172 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 10:01:48.0192 4172 amdagp - ok 10:01:48.0212 4172 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 10:01:48.0222 4172 amdide - ok 10:01:48.0262 4172 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 10:01:48.0262 4172 AmdK7 - ok 10:01:48.0292 4172 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys 10:01:48.0292 4172 AmdK8 - ok 10:01:48.0422 4172 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 10:01:48.0422 4172 arc - ok 10:01:48.0482 4172 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 10:01:48.0482 4172 arcsas - ok 10:01:48.0522 4172 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 10:01:48.0522 4172 AsyncMac - ok 10:01:48.0582 4172 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 10:01:48.0582 4172 atapi - ok 10:01:48.0662 4172 athr (fa4e39b289d3a9606f03c90a933b2b1f) C:\Windows\system32\DRIVERS\athr.sys 10:01:48.0702 4172 athr - ok 10:01:48.0862 4172 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 10:01:48.0872 4172 BCM43XV - ok 10:01:48.0952 4172 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 10:01:48.0952 4172 Beep - ok 10:01:49.0222 4172 BHDrvx86 (9d14d76e4e7b9b2ead17149011db2b11) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111221.003\BHDrvx86.sys 10:01:49.0252 4172 BHDrvx86 - ok 10:01:49.0392 4172 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 10:01:49.0392 4172 blbdrive - ok 10:01:49.0492 4172 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 10:01:49.0492 4172 bowser - ok 10:01:49.0562 4172 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 10:01:49.0562 4172 BrFiltLo - ok 10:01:49.0592 4172 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 10:01:49.0592 4172 BrFiltUp - ok 10:01:49.0642 4172 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 10:01:49.0642 4172 Brserid - ok 10:01:49.0672 4172 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 10:01:49.0672 4172 BrSerWdm - ok 10:01:49.0712 4172 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 10:01:49.0712 4172 BrUsbMdm - ok 10:01:49.0732 4172 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 10:01:49.0732 4172 BrUsbSer - ok 10:01:49.0772 4172 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 10:01:49.0772 4172 BTHMODEM - ok 10:01:49.0812 4172 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 10:01:49.0812 4172 cdfs - ok 10:01:49.0862 4172 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 10:01:49.0862 4172 cdrom - ok 10:01:49.0902 4172 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 10:01:49.0902 4172 circlass - ok 10:01:49.0942 4172 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 10:01:49.0952 4172 CLFS - ok 10:01:50.0012 4172 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 10:01:50.0012 4172 CmBatt - ok 10:01:50.0042 4172 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 10:01:50.0042 4172 cmdide - ok 10:01:50.0112 4172 CnxtHdAudService (b6e7991e3d6146c04c85cd31af22a381) C:\Windows\system32\drivers\CHDRT32.sys 10:01:50.0112 4172 CnxtHdAudService - ok 10:01:50.0202 4172 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 10:01:50.0202 4172 Compbatt - ok 10:01:50.0222 4172 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 10:01:50.0222 4172 crcdisk - ok 10:01:50.0242 4172 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 10:01:50.0252 4172 Crusoe - ok 10:01:50.0332 4172 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 10:01:50.0332 4172 DfsC - ok 10:01:50.0412 4172 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 10:01:50.0412 4172 disk - ok 10:01:50.0492 4172 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys 10:01:50.0492 4172 Dot4 - ok 10:01:50.0542 4172 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys 10:01:50.0552 4172 Dot4Print - ok 10:01:50.0582 4172 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys 10:01:50.0582 4172 dot4usb - ok 10:01:50.0702 4172 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 10:01:50.0702 4172 drmkaud - ok 10:01:50.0772 4172 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 10:01:50.0822 4172 DXGKrnl - ok 10:01:50.0902 4172 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 10:01:50.0902 4172 E1G60 - ok 10:01:51.0012 4172 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 10:01:51.0012 4172 Ecache - ok 10:01:51.0152 4172 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 10:01:51.0152 4172 eeCtrl - ok 10:01:51.0302 4172 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 10:01:51.0302 4172 elxstor - ok 10:01:51.0452 4172 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 10:01:51.0452 4172 EraserUtilRebootDrv - ok 10:01:51.0552 4172 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 10:01:51.0552 4172 ErrDev - ok 10:01:51.0642 4172 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 10:01:51.0642 4172 exfat - ok 10:01:51.0672 4172 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 10:01:51.0682 4172 fastfat - ok 10:01:51.0812 4172 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 10:01:51.0812 4172 fdc - ok 10:01:51.0892 4172 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 10:01:51.0892 4172 FileInfo - ok 10:01:51.0932 4172 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 10:01:51.0932 4172 Filetrace - ok 10:01:51.0962 4172 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 10:01:51.0962 4172 flpydisk - ok 10:01:52.0012 4172 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 10:01:52.0012 4172 FltMgr - ok 10:01:52.0102 4172 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 10:01:52.0102 4172 Fs_Rec - ok 10:01:52.0142 4172 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 10:01:52.0142 4172 gagp30kx - ok 10:01:52.0202 4172 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\Drivers\GEARAspiWDM.sys 10:01:52.0202 4172 GEARAspiWDM - ok 10:01:52.0252 4172 HdAudAddService (7be40bb4cd16d8760e18ea981ff452ec) C:\Windows\system32\drivers\CHDART.sys 10:01:52.0252 4172 HdAudAddService - ok 10:01:52.0302 4172 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 10:01:52.0312 4172 HDAudBus - ok 10:01:52.0352 4172 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 10:01:52.0352 4172 HidBth - ok 10:01:52.0392 4172 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 10:01:52.0392 4172 HidIr - ok 10:01:52.0512 4172 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 10:01:52.0512 4172 HidUsb - ok 10:01:52.0612 4172 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 10:01:52.0612 4172 HpCISSs - ok 10:01:52.0682 4172 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 10:01:52.0682 4172 HpqKbFiltr - ok 10:01:52.0712 4172 HpqRemHid (115c0933b3ed51dfbec4449348c8065b) C:\Windows\system32\DRIVERS\HpqRemHid.sys 10:01:52.0712 4172 HpqRemHid - ok 10:01:52.0782 4172 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 10:01:52.0782 4172 HSFHWAZL - ok 10:01:52.0862 4172 HSF_DPV (cc267848cb3508e72762be65734e764d) C:\Windows\system32\DRIVERS\HSX_DPV.sys 10:01:52.0912 4172 HSF_DPV - ok 10:01:53.0022 4172 HSXHWAZL (a2882945cc4b6e3e4e9e825590438888) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 10:01:53.0022 4172 HSXHWAZL - ok 10:01:53.0102 4172 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 10:01:53.0112 4172 HTTP - ok 10:01:53.0172 4172 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 10:01:53.0172 4172 i2omp - ok 10:01:53.0222 4172 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 10:01:53.0222 4172 i8042prt - ok 10:01:53.0262 4172 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 10:01:53.0262 4172 iaStorV - ok 10:01:53.0502 4172 IDSvix86 (9bc8840de4140e8e2a6fc3192e054a8c) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111223.001\IDSvix86.sys 10:01:53.0512 4172 IDSvix86 - ok 10:01:53.0582 4172 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 10:01:53.0582 4172 iirsp - ok 10:01:53.0742 4172 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 10:01:53.0742 4172 intelide - ok 10:01:53.0792 4172 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 10:01:53.0792 4172 intelppm - ok 10:01:53.0842 4172 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 10:01:53.0842 4172 IpFilterDriver - ok 10:01:53.0852 4172 IpInIp - ok 10:01:53.0902 4172 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 10:01:53.0902 4172 IPMIDRV - ok 10:01:53.0942 4172 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 10:01:53.0942 4172 IPNAT - ok 10:01:53.0972 4172 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 10:01:53.0972 4172 IRENUM - ok 10:01:54.0012 4172 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 10:01:54.0012 4172 isapnp - ok 10:01:54.0082 4172 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 10:01:54.0082 4172 iScsiPrt - ok 10:01:54.0162 4172 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 10:01:54.0162 4172 iteatapi - ok 10:01:54.0232 4172 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 10:01:54.0232 4172 iteraid - ok 10:01:54.0272 4172 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 10:01:54.0272 4172 kbdclass - ok 10:01:54.0332 4172 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 10:01:54.0332 4172 kbdhid - ok 10:01:54.0392 4172 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 10:01:55.0002 4172 KSecDD - ok 10:01:55.0902 4172 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 10:01:55.0902 4172 lltdio - ok 10:01:56.0102 4172 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 10:01:56.0102 4172 LSI_FC - ok 10:01:56.0162 4172 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 10:01:56.0162 4172 LSI_SAS - ok 10:01:56.0222 4172 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 10:01:56.0232 4172 LSI_SCSI - ok 10:01:56.0262 4172 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 10:01:56.0272 4172 luafv - ok 10:01:56.0312 4172 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 10:01:56.0312 4172 mdmxsdk - ok 10:01:56.0342 4172 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 10:01:56.0352 4172 megasas - ok 10:01:56.0482 4172 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 10:01:56.0492 4172 MegaSR - ok 10:01:56.0552 4172 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 10:01:56.0552 4172 Modem - ok 10:01:56.0602 4172 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 10:01:56.0602 4172 monitor - ok 10:01:56.0642 4172 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 10:01:56.0642 4172 mouclass - ok 10:01:56.0682 4172 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 10:01:56.0682 4172 mouhid - ok 10:01:56.0712 4172 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 10:01:56.0722 4172 MountMgr - ok 10:01:56.0762 4172 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 10:01:56.0762 4172 mpio - ok 10:01:56.0852 4172 MpKsl553ab19e - ok 10:01:56.0942 4172 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 10:01:56.0942 4172 mpsdrv - ok 10:01:56.0992 4172 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 10:01:56.0992 4172 Mraid35x - ok 10:01:57.0042 4172 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 10:01:57.0042 4172 MRxDAV - ok 10:01:57.0112 4172 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 10:01:57.0112 4172 mrxsmb - ok 10:01:57.0212 4172 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 10:01:57.0212 4172 mrxsmb10 - ok 10:01:57.0232 4172 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 10:01:57.0232 4172 mrxsmb20 - ok 10:01:57.0282 4172 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 10:01:57.0282 4172 msahci - ok 10:01:57.0342 4172 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 10:01:57.0352 4172 msdsm - ok 10:01:57.0392 4172 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 10:01:57.0392 4172 Msfs - ok 10:01:57.0442 4172 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 10:01:57.0442 4172 msisadrv - ok 10:01:57.0542 4172 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 10:01:57.0542 4172 MSKSSRV - ok 10:01:57.0602 4172 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 10:01:57.0602 4172 MSPCLOCK - ok 10:01:57.0722 4172 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 10:01:57.0722 4172 MSPQM - ok 10:01:57.0772 4172 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 10:01:57.0772 4172 MsRPC - ok 10:01:57.0812 4172 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 10:01:57.0812 4172 mssmbios - ok 10:01:57.0902 4172 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 10:01:57.0902 4172 MSTEE - ok 10:01:58.0052 4172 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 10:01:58.0052 4172 Mup - ok 10:01:58.0132 4172 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 10:01:58.0132 4172 NativeWifiP - ok 10:01:58.0342 4172 NAVENG (862f55824ac81295837b0ab63f91071f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111223.035\NAVENG.SYS 10:01:58.0342 4172 NAVENG - ok 10:01:58.0672 4172 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111223.035\NAVEX15.SYS 10:01:58.0732 4172 NAVEX15 - ok 10:01:58.0882 4172 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 10:01:58.0892 4172 NDIS - ok 10:01:59.0092 4172 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 10:01:59.0092 4172 NdisTapi - ok 10:01:59.0142 4172 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 10:01:59.0142 4172 Ndisuio - ok 10:01:59.0222 4172 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 10:01:59.0222 4172 NdisWan - ok 10:01:59.0312 4172 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 10:01:59.0312 4172 NDProxy - ok 10:01:59.0552 4172 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 10:01:59.0562 4172 NetBIOS - ok 10:01:59.0602 4172 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 10:01:59.0622 4172 netbt - ok 10:01:59.0722 4172 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 10:01:59.0722 4172 nfrd960 - ok 10:01:59.0812 4172 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 10:01:59.0812 4172 Npfs - ok 10:01:59.0922 4172 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 10:01:59.0922 4172 nsiproxy - ok 10:02:00.0022 4172 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 10:02:00.0052 4172 Ntfs - ok 10:02:00.0162 4172 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 10:02:00.0162 4172 ntrigdigi - ok 10:02:00.0182 4172 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 10:02:00.0182 4172 Null - ok 10:02:00.0262 4172 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys 10:02:00.0292 4172 NVENETFD - ok 10:02:01.0082 4172 nvlddmkm (05200c3a9b1370aa2d8c99f1a464168b) C:\Windows\system32\DRIVERS\nvlddmkm.sys 10:02:01.0252 4172 nvlddmkm - ok 10:02:01.0602 4172 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 10:02:01.0612 4172 nvraid - ok 10:02:01.0742 4172 nvsmu (9aebc32f9d6e02ebee0369ab296fe7c8) C:\Windows\system32\DRIVERS\nvsmu.sys 10:02:01.0742 4172 nvsmu - ok 10:02:01.0802 4172 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 10:02:01.0802 4172 nvstor - ok 10:02:01.0832 4172 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 10:02:01.0832 4172 nv_agp - ok 10:02:01.0872 4172 NwlnkFlt - ok 10:02:01.0922 4172 NwlnkFwd - ok 10:02:02.0052 4172 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 10:02:02.0062 4172 ohci1394 - ok 10:02:02.0132 4172 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 10:02:02.0132 4172 Parport - ok 10:02:02.0202 4172 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 10:02:02.0202 4172 partmgr - ok 10:02:02.0242 4172 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 10:02:02.0242 4172 Parvdm - ok 10:02:02.0422 4172 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 10:02:02.0432 4172 pci - ok 10:02:02.0462 4172 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys 10:02:02.0462 4172 pciide - ok 10:02:02.0512 4172 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 10:02:02.0512 4172 pcmcia - ok 10:02:02.0572 4172 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys 10:02:02.0572 4172 pcouffin - ok 10:02:02.0642 4172 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 10:02:02.0702 4172 PEAUTH - ok 10:02:02.0832 4172 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 10:02:02.0832 4172 PptpMiniport - ok 10:02:02.0892 4172 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 10:02:02.0892 4172 Processor - ok 10:02:03.0052 4172 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 10:02:03.0052 4172 PSched - ok 10:02:03.0202 4172 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 10:02:03.0252 4172 ql2300 - ok 10:02:03.0312 4172 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 10:02:03.0312 4172 ql40xx - ok 10:02:03.0392 4172 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 10:02:03.0392 4172 QWAVEdrv - ok 10:02:03.0432 4172 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 10:02:03.0432 4172 RasAcd - ok 10:02:03.0472 4172 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 10:02:03.0472 4172 Rasl2tp - ok 10:02:03.0512 4172 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 10:02:03.0512 4172 RasPppoe - ok 10:02:03.0572 4172 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 10:02:03.0572 4172 RasSstp - ok 10:02:03.0622 4172 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 10:02:03.0632 4172 rdbss - ok 10:02:03.0652 4172 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 10:02:03.0652 4172 RDPCDD - ok 10:02:03.0692 4172 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 10:02:03.0702 4172 rdpdr - ok 10:02:03.0712 4172 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 10:02:03.0712 4172 RDPENCDD - ok 10:02:03.0782 4172 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 10:02:03.0792 4172 RDPWD - ok 10:02:03.0912 4172 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys 10:02:03.0912 4172 rimmptsk - ok 10:02:03.0942 4172 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys 10:02:03.0942 4172 rimsptsk - ok 10:02:03.0982 4172 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys 10:02:03.0982 4172 rismxdp - ok 10:02:04.0042 4172 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 10:02:04.0052 4172 rspndr - ok 10:02:04.0092 4172 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 10:02:04.0092 4172 sbp2port - ok 10:02:04.0272 4172 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 10:02:04.0272 4172 sdbus - ok 10:02:04.0362 4172 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 10:02:04.0362 4172 secdrv - ok 10:02:04.0402 4172 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 10:02:04.0402 4172 Serenum - ok 10:02:04.0452 4172 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 10:02:04.0452 4172 Serial - ok 10:02:04.0472 4172 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 10:02:04.0472 4172 sermouse - ok 10:02:04.0552 4172 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 10:02:04.0552 4172 sffdisk - ok 10:02:04.0582 4172 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 10:02:04.0582 4172 sffp_mmc - ok 10:02:04.0642 4172 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 10:02:04.0642 4172 sffp_sd - ok 10:02:04.0672 4172 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 10:02:04.0672 4172 sfloppy - ok 10:02:04.0712 4172 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 10:02:04.0712 4172 sisagp - ok 10:02:04.0732 4172 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 10:02:04.0732 4172 SiSRaid2 - ok 10:02:04.0752 4172 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 10:02:04.0752 4172 SiSRaid4 - ok 10:02:04.0872 4172 Smb (719f5ce4a8e6659e016309d618954b1c) C:\Windows\system32\DRIVERS\smb.sys 10:02:04.0872 4172 Smb - ok 10:02:05.0042 4172 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 10:02:05.0042 4172 spldr - ok 10:02:05.0252 4172 sptd (7f1b7c4d446cd3f926af45b8c48bd593) C:\Windows\system32\Drivers\sptd.sys 10:02:05.0252 4172 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 7f1b7c4d446cd3f926af45b8c48bd593 10:02:05.0282 4172 sptd ( LockedFile.Multi.Generic ) - warning 10:02:05.0282 4172 sptd - detected LockedFile.Multi.Generic (1) 10:02:05.0442 4172 SRTSP (83726cf02eced69138948083e06b6eac) C:\Windows\system32\drivers\N360\0501000.01D\SRTSP.SYS 10:02:05.0452 4172 SRTSP - ok 10:02:05.0722 4172 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS 10:02:05.0722 4172 SRTSPX - ok 10:02:05.0862 4172 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 10:02:05.0872 4172 srv - ok 10:02:05.0952 4172 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 10:02:05.0962 4172 srv2 - ok 10:02:06.0022 4172 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 10:02:06.0022 4172 srvnet - ok 10:02:06.0082 4172 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 10:02:06.0082 4172 swenum - ok 10:02:06.0122 4172 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 10:02:06.0122 4172 Symc8xx - ok 10:02:06.0232 4172 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS 10:02:06.0242 4172 SymDS - ok 10:02:06.0482 4172 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS 10:02:06.0492 4172 SymEFA - ok 10:02:06.0652 4172 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\Windows\system32\Drivers\SYMEVENT.SYS 10:02:06.0662 4172 SymEvent - ok 10:02:06.0702 4172 SymIMMP - ok 10:02:06.0942 4172 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS 10:02:06.0972 4172 SymIRON - ok 10:02:07.0142 4172 SYMTDIv (5136f99a60ddbdeb1f6fd1eefc44407f) C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS 10:02:07.0172 4172 SYMTDIv - ok 10:02:07.0302 4172 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 10:02:07.0302 4172 Sym_hi - ok 10:02:07.0782 4172 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 10:02:07.0782 4172 Sym_u3 - ok 10:02:08.0112 4172 SynTP (067cb9d745407a8c1b26e89a6a2ce152) C:\Windows\system32\DRIVERS\SynTP.sys 10:02:08.0122 4172 SynTP - ok 10:02:08.0252 4172 Tcpip (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\drivers\tcpip.sys 10:02:08.0292 4172 Tcpip - ok 10:02:08.0382 4172 Tcpip6 (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\DRIVERS\tcpip.sys 10:02:08.0392 4172 Tcpip6 - ok 10:02:08.0412 4172 tcpipreg (3fc13f09af9be487c7b4fac4070a036c) C:\Windows\system32\drivers\tcpipreg.sys 10:02:08.0412 4172 tcpipreg - ok 10:02:08.0472 4172 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 10:02:08.0482 4172 TDPIPE - ok 10:02:08.0542 4172 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 10:02:08.0542 4172 TDTCP - ok 10:02:08.0612 4172 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 10:02:08.0612 4172 tdx - ok 10:02:08.0712 4172 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 10:02:08.0712 4172 TermDD - ok 10:02:08.0792 4172 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 10:02:08.0802 4172 tssecsrv - ok 10:02:08.0872 4172 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 10:02:08.0872 4172 tunmp - ok 10:02:08.0932 4172 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 10:02:08.0932 4172 tunnel - ok 10:02:08.0962 4172 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 10:02:08.0962 4172 uagp35 - ok 10:02:09.0012 4172 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 10:02:09.0012 4172 udfs - ok 10:02:09.0062 4172 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 10:02:09.0062 4172 uliagpkx - ok 10:02:09.0112 4172 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 10:02:09.0122 4172 uliahci - ok 10:02:09.0152 4172 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 10:02:09.0152 4172 UlSata - ok 10:02:09.0182 4172 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 10:02:09.0182 4172 ulsata2 - ok 10:02:09.0212 4172 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 10:02:09.0212 4172 umbus - ok 10:02:09.0262 4172 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 10:02:09.0262 4172 usbccgp - ok 10:02:09.0302 4172 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 10:02:09.0302 4172 usbcir - ok 10:02:09.0352 4172 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 10:02:09.0352 4172 usbehci - ok 10:02:09.0412 4172 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 10:02:09.0412 4172 usbhub - ok 10:02:09.0422 4172 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys 10:02:09.0422 4172 usbohci - ok 10:02:09.0462 4172 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 10:02:09.0462 4172 usbprint - ok 10:02:09.0512 4172 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 10:02:09.0512 4172 usbscan - ok 10:02:09.0662 4172 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 10:02:09.0672 4172 USBSTOR - ok 10:02:09.0742 4172 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 10:02:09.0742 4172 usbuhci - ok 10:02:10.0052 4172 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 10:02:10.0062 4172 usbvideo - ok 10:02:10.0142 4172 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 10:02:10.0142 4172 vga - ok 10:02:10.0212 4172 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 10:02:10.0212 4172 VgaSave - ok 10:02:10.0242 4172 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 10:02:10.0242 4172 viaagp - ok 10:02:10.0272 4172 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 10:02:10.0272 4172 ViaC7 - ok 10:02:10.0332 4172 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 10:02:10.0332 4172 viaide - ok 10:02:10.0372 4172 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 10:02:10.0372 4172 volmgr - ok 10:02:10.0442 4172 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 10:02:10.0442 4172 volmgrx - ok 10:02:10.0502 4172 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 10:02:10.0512 4172 volsnap - ok 10:02:10.0562 4172 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 10:02:10.0572 4172 vsmraid - ok 10:02:10.0622 4172 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 10:02:10.0622 4172 WacomPen - ok 10:02:10.0692 4172 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 10:02:10.0702 4172 Wanarp - ok 10:02:10.0752 4172 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 10:02:10.0752 4172 Wanarpv6 - ok 10:02:10.0772 4172 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 10:02:10.0772 4172 Wd - ok 10:02:10.0832 4172 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 10:02:10.0842 4172 Wdf01000 - ok 10:02:11.0032 4172 winachsf (0acd399f5db3df1b58903cf4949ab5a8) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 10:02:11.0062 4172 winachsf - ok 10:02:11.0152 4172 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 10:02:11.0152 4172 WmiAcpi - ok 10:02:11.0242 4172 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 10:02:11.0252 4172 WpdUsb - ok 10:02:11.0332 4172 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 10:02:11.0332 4172 ws2ifsl - ok 10:02:11.0432 4172 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 10:02:11.0432 4172 WUDFRd - ok 10:02:12.0172 4172 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys 10:02:12.0172 4172 XAudio - ok 10:02:12.0262 4172 MBR (0x1B8) (1a1a06f62e891045814007163c1c76c3) \Device\Harddisk0\DR0 10:02:12.0302 4172 \Device\Harddisk0\DR0 - ok 10:02:12.0312 4172 Boot (0x1200) (0d58f86005da2213beab1543be5ed097) \Device\Harddisk0\DR0\Partition0 10:02:12.0312 4172 \Device\Harddisk0\DR0\Partition0 - ok 10:02:12.0352 4172 Boot (0x1200) (7f28142866938740324274d1260a6a2c) \Device\Harddisk0\DR0\Partition1 10:02:12.0352 4172 \Device\Harddisk0\DR0\Partition1 - ok 10:02:12.0352 4172 ============================================================ 10:02:12.0352 4172 Scan finished 10:02:12.0352 4172 ============================================================ 10:02:12.0382 5196 Detected object count: 1 10:02:12.0382 5196 Actual detected object count: 1 10:02:22.0974 5196 sptd ( LockedFile.Multi.Generic ) - skipped by user 10:02:22.0975 5196 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 10:02:34.0467 3396 Deinitialize success ______________ Hope this helps. The DDS Attach file has been attached as well. -drsulli
Hi drsulli,

Perfect, thanks for the logs! And Merry Christmas :)

Next, Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Thanks again for the help, however I believe my wife's laptop has an old copy of Microsoft Security Essentials that was removed improperly or incompletely. MSE is not currently installed however the combofix tool says that it is finding MSE processes running prior to starting. I was able to disable Norton 360 Auto-Protect. That said, the combofix tool will start to run and begin its scan and will never finish. It just kind of stalls out even after leaving it running for 5 hours or more. However, Norton while scanning did find two trojans called "ZeroAccessTrojan" which it prompted me to remove manually. I downloaded a ZeroAccessFixtool program from Symantec's website. It rebooted the computer and then scanned for and removed/repaired the files infected with the ZeroAccess Trojan. I do no know that this is the same trojan that was causing the PING.EXE file to run however I have not seen it running since this repair so I have my fingers crossed.
drsulli,

Yes, ZeroAccess is the infection that is responsible for PING.EXE, however ComboFix is the only tool that can completely remove a ZeroAccess infection. Other tools will simply remove parts of it. MSE might have interfered with ComboFix, causing it to stall. Did Norton start scanning while you were running ComboFix?

I would like you to try the following to clean up the failed removal of MSE.

Please download AppRemover and save it to your desktop.
  • Double click on AppRemover.exe to run it.
  • Uncheck "Enable anonymous usage statistics. No personal data will be recorded."
  • Click on the Next button.
  • Click on "Remove Security Application" or "Clean Up a Failed Uninstall" depending on what you want to do. (you want the failed uninstall)
  • Click on the Next button.
  • A scan begins, please wait. Once done, click on the Next button.
  • Now you should have a list of your installed programs, choose the one you want to remove and click on the Next button.
  • Follow the last step and reboot if asked to do so.
===================================================

Then run ComboFix again and post the log.
Hi drsulli,

It is my pleasure :). Can you browse to your C:\ drive and see if there are any logs there named ComboFix.txt? Also, browse to c:\qoobox and see if combofix-quarantined-files.txt exists. If either log is there, please post them.
Those directories do exist, but those log files do not. My wife is taking her laptop away from the home for business for a bit so it may be a few weeks until I can work on it again. Thanks for the help and hopefully when she brings it back we can continue.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI