My wife's laptop recently had the 2011 Antivirus Virus on it. I thought I had followed the instructions correctly to remove it but apparently it has burried itself further in her system than I thought. The PING.EXE process is using up to 100% of the CPU at times and making the laptop nearly unusable. Whenever it does start to spool itself up like that, Norton gives me "High CPU Usage by TCP/IP Command" pop-up warnings. Whenever it does this while I am browsing in Firefox, webpages will either fail to load or they will automatically redirect to spam search sites that have nothing to do with what was being searched. I have installed and attached the HJT log below:
_______________________________
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:46:57 PM, on 12/24/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Lauret\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 6106 bytes
______________________________
Any help in removing this nuissance is appreciated as it is getting out of my comfort zone in messing with it.
Hi drsulli,
My name is
NoodleTech . I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine. Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer. The fixes are specific to your problem and should only be used for the issues on this machine. Do not delete anything unless instructed to. DO NOT use tools such as ComboFix without supervision. Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean. It's often worth reading through these instructions and printing them for ease of reference. If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry. Please reply to this thread. Do not start a new topic. Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.===================================================
Please download DDS by sUBs from one of the following links and save it to your desktop.
Disable any script blocking protection (How to Disable your Security Programs ) Double click DDS icon to run the tool (may take up to 3 minutes to run) When done, DDS.txt will open. After a few moments, attach.txt will open in a second window. Save both reports to your desktop. —————————————————
Post the contents of the DDS.txt report in your next replyAttach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse . Browse to where you saved the file, and click Open and then click UPLOAD .===================================================
Please download aswMBR.exe and save it to your desktop.
Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
Click
Scan
Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet. You will also notice another file created on the desktop named MBR.dat . Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well. ===================================================
Please download
TDSSKiller.zip
Extract it to your desktop Double click TDSSKiller.exe Press Start Scan .
If Malicious objects are found, DO NOT cure them. Choose Skip then click on Continue. Copy and paste the log in your next reply
A copy of the log will be saved automatically to the root of the drive (typically C:\) ===================================================
In your next reply, please post the following:
DDS log aswMBR log TDSSKiller log
📎 DDS_Attach.txtThank you for the prompt repsonse. I have run the logs you requested and posted them below:
____________
DDS LOG
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by [removed] at 9:57:10 on 2011-12-25
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1234 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\msiexec.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\ping.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{4A58DC7B-18F9-40E0-ABAE-F7CEBDC2B2DF} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\lauret\appdata\roaming\mozilla\firefox\profiles\hlu0htmn.default\
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\lauret\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\lauret\appdata\roaming\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\users\lauret\appdata\roaming\move networks\plugins\npqmp071701000002.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-12-18 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-12-18 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111221.003\BHDrvx86.sys [2011-12-22 819320]
R1 IDSvix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20111223.001\IDSvix86.sys [2011-12-24 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-12-18 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys [2011-12-18 331384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccSvcHst.exe [2011-12-18 130008]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-8-28 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-12-18 106104]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
.
=============== Created Last 30 ================
.
2011-12-24 22:57:15 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-12-24 22:57:14 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll
2011-12-24 22:57:14 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll
2011-12-24 22:57:14 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll
2011-12-24 22:57:14 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll
2011-12-24 21:38:03 29184 —-a-w- c:\windows\system32\I8rYY8V.com
2011-12-19 04:18:03 ——– d—–w- c:\users\lauret\appdata\local\{697B084D-E9DE-4F66-A198-2EB865BFFCC8}
2011-12-19 04:17:44 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-12-19 04:17:41 ——– d—–w- c:\users\lauret\appdata\local\{67B93E90-C46A-4863-BAD0-0261B1A5DBA0}
2011-12-19 04:17:39 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-12-19 04:16:21 744568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys
2011-12-19 04:16:21 50168 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys
2011-12-19 04:16:21 340088 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys
2011-12-19 04:16:21 331384 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys
2011-12-19 04:16:21 296568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys
2011-12-19 04:16:20 516216 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys
2011-12-19 04:16:20 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys
2011-12-19 01:31:34 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D
2011-12-19 01:31:34 ——– d—–w- c:\windows\system32\drivers\N360
2011-12-19 01:31:32 ——– d—–w- c:\program files\Norton 360
2011-12-18 12:48:36 ——– d—–w- c:\users\lauret\appdata\local\{49924F84-B916-4E85-83E2-5B9CAADB2621}
2011-12-18 12:48:00 ——– d—–w- c:\users\lauret\appdata\local\{02EAE8E0-A6A2-457F-BCC7-C9E982D415D3}
2011-12-17 12:21:22 ——– d—–w- c:\programdata\NortonInstaller
2011-12-17 12:21:22 ——– d—–w- c:\program files\NortonInstaller
2011-12-17 12:19:47 ——– d—–w- c:\programdata\Norton
2011-12-17 12:05:55 ——– d—–w- c:\users\lauret\appdata\local\{9B70D02F-822B-492D-B268-1528EFECDD71}
2011-12-17 12:05:35 ——– d—–w- c:\users\lauret\appdata\local\{40464F0A-60DA-40B7-B5CA-FA635BBBBDD8}
2011-12-16 23:57:06 ——– d—–w- c:\users\lauret\appdata\local\{7BF63D29-C376-4AA3-9F6A-62C3A75BB8B1}
2011-12-16 23:56:45 ——– d—–w- c:\users\lauret\appdata\local\{7E53D3F6-55F2-4138-8746-5FE8D9820F97}
2011-12-15 13:41:20 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-15 13:41:20 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-15 13:41:19 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-15 13:41:17 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-15 13:41:15 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-12-15 13:41:12 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-15 13:41:07 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-14 14:01:16 ——– d—–w- c:\users\lauret\appdata\local\{472B5DDA-5614-447B-9670-28CFD82F8EFC}
2011-12-14 01:40:54 ——– d—–w- c:\users\lauret\appdata\local\{3D22FF24-83F1-4611-A210-8A577A8E99F5}
2011-12-14 01:40:33 ——– d—–w- c:\users\lauret\appdata\local\{AC29A327-F78D-47D4-ADE8-2BF11B3263A5}
2011-12-14 01:08:58 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-01 18:13:00 ——– d—–w- c:\users\lauret\appdata\local\{FDCA4A67-5444-4F0E-9B58-C5F94074CB28}
2011-12-01 18:12:43 ——– d—–w- c:\users\lauret\appdata\local\{72EF95A4-74A6-4D22-96DE-3128BA0B1590}
2011-11-26 22:06:04 ——– d—–w- c:\users\lauret\appdata\local\{82DF8E73-6120-4B65-BED0-6B82C66D98B7}
2011-11-26 22:05:52 ——– d—–w- c:\users\lauret\appdata\local\{2A16786A-A340-4B7E-96D5-DB0AB2D57ECE}
.
==================== Find3M ====================
.
2011-12-01 18:11:46 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-10 10:54:13 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-11-03 22:47:42 1798144 —-a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 —-a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-02 21:33:29 87608 —-a-w- c:\users\lauret\appdata\roaming\inst.exe
2011-10-02 21:33:29 47360 —-a-w- c:\users\lauret\appdata\roaming\pcouffin.sys
.
============= FINISH: 9:57:57.69 ===============
________________
___________________
aswMBR
aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software
Run date: 2011-12-25 09:58:59
—————————–
09:58:59.737 OS Version: Windows 6.0.6002 Service Pack 2
09:58:59.737 Number of processors: 2 586 0x6802
09:58:59.738 ComputerName: LAURET-PC UserName: Lauret
09:59:03.667 Initialize success
09:59:42.144 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
09:59:42.148 Disk 0 Vendor: ST9200827AS 3.BHA Size: 190782MB BusType: 3
09:59:44.189 Disk 0 MBR read successfully
09:59:44.193 Disk 0 MBR scan
09:59:44.196 Disk 0 unknown MBR code
09:59:44.201 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 178746 MB offset 63
09:59:44.232 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 12033 MB offset 366073155
09:59:44.239 Disk 0 scanning sectors +390716865
09:59:44.329 Disk 0 scanning C:\Windows\system32\drivers
09:59:53.855 Service scanning
09:59:55.699 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
09:59:56.288 Modules scanning
10:00:02.228 Module: C:\Windows\system32\DRIVERS\smb.sys **SUSPICIOUS**
10:00:11.324 Disk 0 trace - called modules:
10:00:11.730 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x87afcf10]<<
10:00:11.739 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8588b620]
10:00:11.746 3 CLASSPNP.SYS[8a3b08b3] -> nt!IofCallDriver -> [0x87abc670]
10:00:11.754 \Driver\00001947[0x85fe5ef8] -> IRP_MJ_CREATE -> 0x87afcf10
10:00:11.761 Scan finished successfully
10:00:33.757 Disk 0 MBR has been saved successfully to "C:\Users\Lauret\Desktop\MBR.dat"
10:00:33.767 The log file has been saved successfully to "C:\Users\Lauret\Desktop\aswMBR.txt"
_______________
_______________
TDSKiller
10:01:34.0742 6076 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
10:01:36.0742 6076 ============================================================
10:01:36.0742 6076 Current date / time: 2011/12/25 10:01:36.0742
10:01:36.0742 6076 SystemInfo:
10:01:36.0742 6076
10:01:36.0742 6076 OS Version: 6.0.6002 ServicePack: 2.0
10:01:36.0742 6076 Product type: Workstation
10:01:36.0742 6076 ComputerName: LAURET-PC
10:01:36.0742 6076 UserName: Lauret
10:01:36.0742 6076 Windows directory: C:\Windows
10:01:36.0742 6076 System windows directory: C:\Windows
10:01:36.0742 6076 Processor architecture: Intel x86
10:01:36.0742 6076 Number of processors: 2
10:01:36.0742 6076 Page size: 0x1000
10:01:36.0742 6076 Boot type: Normal boot
10:01:36.0742 6076 ============================================================
10:01:38.0252 6076 Initialize success
10:01:46.0062 4172 ============================================================
10:01:46.0062 4172 Scan started
10:01:46.0062 4172 Mode: Manual;
10:01:46.0062 4172 ============================================================
10:01:47.0512 4172 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
10:01:47.0512 4172 ACPI - ok
10:01:47.0632 4172 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
10:01:47.0642 4172 adp94xx - ok
10:01:47.0682 4172 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
10:01:47.0682 4172 adpahci - ok
10:01:47.0732 4172 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
10:01:47.0732 4172 adpu160m - ok
10:01:47.0792 4172 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
10:01:47.0792 4172 adpu320 - ok
10:01:47.0952 4172 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
10:01:47.0952 4172 AFD - ok
10:01:48.0042 4172 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
10:01:48.0052 4172 agp440 - ok
10:01:48.0112 4172 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
10:01:48.0112 4172 aic78xx - ok
10:01:48.0142 4172 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
10:01:48.0142 4172 aliide - ok
10:01:48.0192 4172 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
10:01:48.0192 4172 amdagp - ok
10:01:48.0212 4172 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
10:01:48.0222 4172 amdide - ok
10:01:48.0262 4172 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
10:01:48.0262 4172 AmdK7 - ok
10:01:48.0292 4172 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
10:01:48.0292 4172 AmdK8 - ok
10:01:48.0422 4172 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
10:01:48.0422 4172 arc - ok
10:01:48.0482 4172 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
10:01:48.0482 4172 arcsas - ok
10:01:48.0522 4172 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
10:01:48.0522 4172 AsyncMac - ok
10:01:48.0582 4172 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
10:01:48.0582 4172 atapi - ok
10:01:48.0662 4172 athr (fa4e39b289d3a9606f03c90a933b2b1f) C:\Windows\system32\DRIVERS\athr.sys
10:01:48.0702 4172 athr - ok
10:01:48.0862 4172 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys
10:01:48.0872 4172 BCM43XV - ok
10:01:48.0952 4172 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
10:01:48.0952 4172 Beep - ok
10:01:49.0222 4172 BHDrvx86 (9d14d76e4e7b9b2ead17149011db2b11) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111221.003\BHDrvx86.sys
10:01:49.0252 4172 BHDrvx86 - ok
10:01:49.0392 4172 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
10:01:49.0392 4172 blbdrive - ok
10:01:49.0492 4172 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
10:01:49.0492 4172 bowser - ok
10:01:49.0562 4172 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
10:01:49.0562 4172 BrFiltLo - ok
10:01:49.0592 4172 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
10:01:49.0592 4172 BrFiltUp - ok
10:01:49.0642 4172 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
10:01:49.0642 4172 Brserid - ok
10:01:49.0672 4172 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
10:01:49.0672 4172 BrSerWdm - ok
10:01:49.0712 4172 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
10:01:49.0712 4172 BrUsbMdm - ok
10:01:49.0732 4172 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
10:01:49.0732 4172 BrUsbSer - ok
10:01:49.0772 4172 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
10:01:49.0772 4172 BTHMODEM - ok
10:01:49.0812 4172 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
10:01:49.0812 4172 cdfs - ok
10:01:49.0862 4172 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
10:01:49.0862 4172 cdrom - ok
10:01:49.0902 4172 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
10:01:49.0902 4172 circlass - ok
10:01:49.0942 4172 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
10:01:49.0952 4172 CLFS - ok
10:01:50.0012 4172 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
10:01:50.0012 4172 CmBatt - ok
10:01:50.0042 4172 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
10:01:50.0042 4172 cmdide - ok
10:01:50.0112 4172 CnxtHdAudService (b6e7991e3d6146c04c85cd31af22a381) C:\Windows\system32\drivers\CHDRT32.sys
10:01:50.0112 4172 CnxtHdAudService - ok
10:01:50.0202 4172 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
10:01:50.0202 4172 Compbatt - ok
10:01:50.0222 4172 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
10:01:50.0222 4172 crcdisk - ok
10:01:50.0242 4172 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
10:01:50.0252 4172 Crusoe - ok
10:01:50.0332 4172 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
10:01:50.0332 4172 DfsC - ok
10:01:50.0412 4172 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
10:01:50.0412 4172 disk - ok
10:01:50.0492 4172 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
10:01:50.0492 4172 Dot4 - ok
10:01:50.0542 4172 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
10:01:50.0552 4172 Dot4Print - ok
10:01:50.0582 4172 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
10:01:50.0582 4172 dot4usb - ok
10:01:50.0702 4172 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
10:01:50.0702 4172 drmkaud - ok
10:01:50.0772 4172 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
10:01:50.0822 4172 DXGKrnl - ok
10:01:50.0902 4172 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
10:01:50.0902 4172 E1G60 - ok
10:01:51.0012 4172 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
10:01:51.0012 4172 Ecache - ok
10:01:51.0152 4172 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
10:01:51.0152 4172 eeCtrl - ok
10:01:51.0302 4172 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
10:01:51.0302 4172 elxstor - ok
10:01:51.0452 4172 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
10:01:51.0452 4172 EraserUtilRebootDrv - ok
10:01:51.0552 4172 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
10:01:51.0552 4172 ErrDev - ok
10:01:51.0642 4172 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
10:01:51.0642 4172 exfat - ok
10:01:51.0672 4172 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
10:01:51.0682 4172 fastfat - ok
10:01:51.0812 4172 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
10:01:51.0812 4172 fdc - ok
10:01:51.0892 4172 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
10:01:51.0892 4172 FileInfo - ok
10:01:51.0932 4172 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
10:01:51.0932 4172 Filetrace - ok
10:01:51.0962 4172 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
10:01:51.0962 4172 flpydisk - ok
10:01:52.0012 4172 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
10:01:52.0012 4172 FltMgr - ok
10:01:52.0102 4172 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
10:01:52.0102 4172 Fs_Rec - ok
10:01:52.0142 4172 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
10:01:52.0142 4172 gagp30kx - ok
10:01:52.0202 4172 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\Drivers\GEARAspiWDM.sys
10:01:52.0202 4172 GEARAspiWDM - ok
10:01:52.0252 4172 HdAudAddService (7be40bb4cd16d8760e18ea981ff452ec) C:\Windows\system32\drivers\CHDART.sys
10:01:52.0252 4172 HdAudAddService - ok
10:01:52.0302 4172 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
10:01:52.0312 4172 HDAudBus - ok
10:01:52.0352 4172 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
10:01:52.0352 4172 HidBth - ok
10:01:52.0392 4172 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
10:01:52.0392 4172 HidIr - ok
10:01:52.0512 4172 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
10:01:52.0512 4172 HidUsb - ok
10:01:52.0612 4172 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
10:01:52.0612 4172 HpCISSs - ok
10:01:52.0682 4172 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
10:01:52.0682 4172 HpqKbFiltr - ok
10:01:52.0712 4172 HpqRemHid (115c0933b3ed51dfbec4449348c8065b) C:\Windows\system32\DRIVERS\HpqRemHid.sys
10:01:52.0712 4172 HpqRemHid - ok
10:01:52.0782 4172 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
10:01:52.0782 4172 HSFHWAZL - ok
10:01:52.0862 4172 HSF_DPV (cc267848cb3508e72762be65734e764d) C:\Windows\system32\DRIVERS\HSX_DPV.sys
10:01:52.0912 4172 HSF_DPV - ok
10:01:53.0022 4172 HSXHWAZL (a2882945cc4b6e3e4e9e825590438888) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
10:01:53.0022 4172 HSXHWAZL - ok
10:01:53.0102 4172 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
10:01:53.0112 4172 HTTP - ok
10:01:53.0172 4172 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
10:01:53.0172 4172 i2omp - ok
10:01:53.0222 4172 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
10:01:53.0222 4172 i8042prt - ok
10:01:53.0262 4172 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
10:01:53.0262 4172 iaStorV - ok
10:01:53.0502 4172 IDSvix86 (9bc8840de4140e8e2a6fc3192e054a8c) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111223.001\IDSvix86.sys
10:01:53.0512 4172 IDSvix86 - ok
10:01:53.0582 4172 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
10:01:53.0582 4172 iirsp - ok
10:01:53.0742 4172 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
10:01:53.0742 4172 intelide - ok
10:01:53.0792 4172 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
10:01:53.0792 4172 intelppm - ok
10:01:53.0842 4172 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:01:53.0842 4172 IpFilterDriver - ok
10:01:53.0852 4172 IpInIp - ok
10:01:53.0902 4172 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
10:01:53.0902 4172 IPMIDRV - ok
10:01:53.0942 4172 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
10:01:53.0942 4172 IPNAT - ok
10:01:53.0972 4172 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
10:01:53.0972 4172 IRENUM - ok
10:01:54.0012 4172 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
10:01:54.0012 4172 isapnp - ok
10:01:54.0082 4172 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
10:01:54.0082 4172 iScsiPrt - ok
10:01:54.0162 4172 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
10:01:54.0162 4172 iteatapi - ok
10:01:54.0232 4172 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
10:01:54.0232 4172 iteraid - ok
10:01:54.0272 4172 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
10:01:54.0272 4172 kbdclass - ok
10:01:54.0332 4172 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
10:01:54.0332 4172 kbdhid - ok
10:01:54.0392 4172 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
10:01:55.0002 4172 KSecDD - ok
10:01:55.0902 4172 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
10:01:55.0902 4172 lltdio - ok
10:01:56.0102 4172 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
10:01:56.0102 4172 LSI_FC - ok
10:01:56.0162 4172 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
10:01:56.0162 4172 LSI_SAS - ok
10:01:56.0222 4172 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
10:01:56.0232 4172 LSI_SCSI - ok
10:01:56.0262 4172 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
10:01:56.0272 4172 luafv - ok
10:01:56.0312 4172 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
10:01:56.0312 4172 mdmxsdk - ok
10:01:56.0342 4172 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
10:01:56.0352 4172 megasas - ok
10:01:56.0482 4172 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
10:01:56.0492 4172 MegaSR - ok
10:01:56.0552 4172 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
10:01:56.0552 4172 Modem - ok
10:01:56.0602 4172 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
10:01:56.0602 4172 monitor - ok
10:01:56.0642 4172 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
10:01:56.0642 4172 mouclass - ok
10:01:56.0682 4172 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
10:01:56.0682 4172 mouhid - ok
10:01:56.0712 4172 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
10:01:56.0722 4172 MountMgr - ok
10:01:56.0762 4172 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
10:01:56.0762 4172 mpio - ok
10:01:56.0852 4172 MpKsl553ab19e - ok
10:01:56.0942 4172 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
10:01:56.0942 4172 mpsdrv - ok
10:01:56.0992 4172 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
10:01:56.0992 4172 Mraid35x - ok
10:01:57.0042 4172 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
10:01:57.0042 4172 MRxDAV - ok
10:01:57.0112 4172 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:01:57.0112 4172 mrxsmb - ok
10:01:57.0212 4172 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:01:57.0212 4172 mrxsmb10 - ok
10:01:57.0232 4172 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:01:57.0232 4172 mrxsmb20 - ok
10:01:57.0282 4172 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
10:01:57.0282 4172 msahci - ok
10:01:57.0342 4172 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
10:01:57.0352 4172 msdsm - ok
10:01:57.0392 4172 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
10:01:57.0392 4172 Msfs - ok
10:01:57.0442 4172 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
10:01:57.0442 4172 msisadrv - ok
10:01:57.0542 4172 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
10:01:57.0542 4172 MSKSSRV - ok
10:01:57.0602 4172 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
10:01:57.0602 4172 MSPCLOCK - ok
10:01:57.0722 4172 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
10:01:57.0722 4172 MSPQM - ok
10:01:57.0772 4172 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
10:01:57.0772 4172 MsRPC - ok
10:01:57.0812 4172 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
10:01:57.0812 4172 mssmbios - ok
10:01:57.0902 4172 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
10:01:57.0902 4172 MSTEE - ok
10:01:58.0052 4172 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
10:01:58.0052 4172 Mup - ok
10:01:58.0132 4172 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
10:01:58.0132 4172 NativeWifiP - ok
10:01:58.0342 4172 NAVENG (862f55824ac81295837b0ab63f91071f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111223.035\NAVENG.SYS
10:01:58.0342 4172 NAVENG - ok
10:01:58.0672 4172 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111223.035\NAVEX15.SYS
10:01:58.0732 4172 NAVEX15 - ok
10:01:58.0882 4172 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
10:01:58.0892 4172 NDIS - ok
10:01:59.0092 4172 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
10:01:59.0092 4172 NdisTapi - ok
10:01:59.0142 4172 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
10:01:59.0142 4172 Ndisuio - ok
10:01:59.0222 4172 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
10:01:59.0222 4172 NdisWan - ok
10:01:59.0312 4172 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
10:01:59.0312 4172 NDProxy - ok
10:01:59.0552 4172 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
10:01:59.0562 4172 NetBIOS - ok
10:01:59.0602 4172 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
10:01:59.0622 4172 netbt - ok
10:01:59.0722 4172 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
10:01:59.0722 4172 nfrd960 - ok
10:01:59.0812 4172 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
10:01:59.0812 4172 Npfs - ok
10:01:59.0922 4172 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
10:01:59.0922 4172 nsiproxy - ok
10:02:00.0022 4172 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
10:02:00.0052 4172 Ntfs - ok
10:02:00.0162 4172 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
10:02:00.0162 4172 ntrigdigi - ok
10:02:00.0182 4172 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
10:02:00.0182 4172 Null - ok
10:02:00.0262 4172 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys
10:02:00.0292 4172 NVENETFD - ok
10:02:01.0082 4172 nvlddmkm (05200c3a9b1370aa2d8c99f1a464168b) C:\Windows\system32\DRIVERS\nvlddmkm.sys
10:02:01.0252 4172 nvlddmkm - ok
10:02:01.0602 4172 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
10:02:01.0612 4172 nvraid - ok
10:02:01.0742 4172 nvsmu (9aebc32f9d6e02ebee0369ab296fe7c8) C:\Windows\system32\DRIVERS\nvsmu.sys
10:02:01.0742 4172 nvsmu - ok
10:02:01.0802 4172 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
10:02:01.0802 4172 nvstor - ok
10:02:01.0832 4172 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
10:02:01.0832 4172 nv_agp - ok
10:02:01.0872 4172 NwlnkFlt - ok
10:02:01.0922 4172 NwlnkFwd - ok
10:02:02.0052 4172 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
10:02:02.0062 4172 ohci1394 - ok
10:02:02.0132 4172 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
10:02:02.0132 4172 Parport - ok
10:02:02.0202 4172 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
10:02:02.0202 4172 partmgr - ok
10:02:02.0242 4172 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
10:02:02.0242 4172 Parvdm - ok
10:02:02.0422 4172 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
10:02:02.0432 4172 pci - ok
10:02:02.0462 4172 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
10:02:02.0462 4172 pciide - ok
10:02:02.0512 4172 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
10:02:02.0512 4172 pcmcia - ok
10:02:02.0572 4172 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
10:02:02.0572 4172 pcouffin - ok
10:02:02.0642 4172 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
10:02:02.0702 4172 PEAUTH - ok
10:02:02.0832 4172 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
10:02:02.0832 4172 PptpMiniport - ok
10:02:02.0892 4172 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
10:02:02.0892 4172 Processor - ok
10:02:03.0052 4172 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
10:02:03.0052 4172 PSched - ok
10:02:03.0202 4172 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
10:02:03.0252 4172 ql2300 - ok
10:02:03.0312 4172 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
10:02:03.0312 4172 ql40xx - ok
10:02:03.0392 4172 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
10:02:03.0392 4172 QWAVEdrv - ok
10:02:03.0432 4172 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
10:02:03.0432 4172 RasAcd - ok
10:02:03.0472 4172 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:02:03.0472 4172 Rasl2tp - ok
10:02:03.0512 4172 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
10:02:03.0512 4172 RasPppoe - ok
10:02:03.0572 4172 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
10:02:03.0572 4172 RasSstp - ok
10:02:03.0622 4172 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
10:02:03.0632 4172 rdbss - ok
10:02:03.0652 4172 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:02:03.0652 4172 RDPCDD - ok
10:02:03.0692 4172 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
10:02:03.0702 4172 rdpdr - ok
10:02:03.0712 4172 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
10:02:03.0712 4172 RDPENCDD - ok
10:02:03.0782 4172 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
10:02:03.0792 4172 RDPWD - ok
10:02:03.0912 4172 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
10:02:03.0912 4172 rimmptsk - ok
10:02:03.0942 4172 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
10:02:03.0942 4172 rimsptsk - ok
10:02:03.0982 4172 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
10:02:03.0982 4172 rismxdp - ok
10:02:04.0042 4172 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
10:02:04.0052 4172 rspndr - ok
10:02:04.0092 4172 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
10:02:04.0092 4172 sbp2port - ok
10:02:04.0272 4172 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
10:02:04.0272 4172 sdbus - ok
10:02:04.0362 4172 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
10:02:04.0362 4172 secdrv - ok
10:02:04.0402 4172 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
10:02:04.0402 4172 Serenum - ok
10:02:04.0452 4172 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
10:02:04.0452 4172 Serial - ok
10:02:04.0472 4172 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
10:02:04.0472 4172 sermouse - ok
10:02:04.0552 4172 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
10:02:04.0552 4172 sffdisk - ok
10:02:04.0582 4172 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
10:02:04.0582 4172 sffp_mmc - ok
10:02:04.0642 4172 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
10:02:04.0642 4172 sffp_sd - ok
10:02:04.0672 4172 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
10:02:04.0672 4172 sfloppy - ok
10:02:04.0712 4172 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
10:02:04.0712 4172 sisagp - ok
10:02:04.0732 4172 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
10:02:04.0732 4172 SiSRaid2 - ok
10:02:04.0752 4172 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
10:02:04.0752 4172 SiSRaid4 - ok
10:02:04.0872 4172 Smb (719f5ce4a8e6659e016309d618954b1c) C:\Windows\system32\DRIVERS\smb.sys
10:02:04.0872 4172 Smb - ok
10:02:05.0042 4172 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
10:02:05.0042 4172 spldr - ok
10:02:05.0252 4172 sptd (7f1b7c4d446cd3f926af45b8c48bd593) C:\Windows\system32\Drivers\sptd.sys
10:02:05.0252 4172 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 7f1b7c4d446cd3f926af45b8c48bd593
10:02:05.0282 4172 sptd ( LockedFile.Multi.Generic ) - warning
10:02:05.0282 4172 sptd - detected LockedFile.Multi.Generic (1)
10:02:05.0442 4172 SRTSP (83726cf02eced69138948083e06b6eac) C:\Windows\system32\drivers\N360\0501000.01D\SRTSP.SYS
10:02:05.0452 4172 SRTSP - ok
10:02:05.0722 4172 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS
10:02:05.0722 4172 SRTSPX - ok
10:02:05.0862 4172 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
10:02:05.0872 4172 srv - ok
10:02:05.0952 4172 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
10:02:05.0962 4172 srv2 - ok
10:02:06.0022 4172 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
10:02:06.0022 4172 srvnet - ok
10:02:06.0082 4172 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
10:02:06.0082 4172 swenum - ok
10:02:06.0122 4172 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
10:02:06.0122 4172 Symc8xx - ok
10:02:06.0232 4172 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS
10:02:06.0242 4172 SymDS - ok
10:02:06.0482 4172 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS
10:02:06.0492 4172 SymEFA - ok
10:02:06.0652 4172 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\Windows\system32\Drivers\SYMEVENT.SYS
10:02:06.0662 4172 SymEvent - ok
10:02:06.0702 4172 SymIMMP - ok
10:02:06.0942 4172 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS
10:02:06.0972 4172 SymIRON - ok
10:02:07.0142 4172 SYMTDIv (5136f99a60ddbdeb1f6fd1eefc44407f) C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS
10:02:07.0172 4172 SYMTDIv - ok
10:02:07.0302 4172 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
10:02:07.0302 4172 Sym_hi - ok
10:02:07.0782 4172 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
10:02:07.0782 4172 Sym_u3 - ok
10:02:08.0112 4172 SynTP (067cb9d745407a8c1b26e89a6a2ce152) C:\Windows\system32\DRIVERS\SynTP.sys
10:02:08.0122 4172 SynTP - ok
10:02:08.0252 4172 Tcpip (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\drivers\tcpip.sys
10:02:08.0292 4172 Tcpip - ok
10:02:08.0382 4172 Tcpip6 (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\DRIVERS\tcpip.sys
10:02:08.0392 4172 Tcpip6 - ok
10:02:08.0412 4172 tcpipreg (3fc13f09af9be487c7b4fac4070a036c) C:\Windows\system32\drivers\tcpipreg.sys
10:02:08.0412 4172 tcpipreg - ok
10:02:08.0472 4172 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
10:02:08.0482 4172 TDPIPE - ok
10:02:08.0542 4172 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
10:02:08.0542 4172 TDTCP - ok
10:02:08.0612 4172 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
10:02:08.0612 4172 tdx - ok
10:02:08.0712 4172 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
10:02:08.0712 4172 TermDD - ok
10:02:08.0792 4172 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:02:08.0802 4172 tssecsrv - ok
10:02:08.0872 4172 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
10:02:08.0872 4172 tunmp - ok
10:02:08.0932 4172 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
10:02:08.0932 4172 tunnel - ok
10:02:08.0962 4172 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
10:02:08.0962 4172 uagp35 - ok
10:02:09.0012 4172 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
10:02:09.0012 4172 udfs - ok
10:02:09.0062 4172 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
10:02:09.0062 4172 uliagpkx - ok
10:02:09.0112 4172 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
10:02:09.0122 4172 uliahci - ok
10:02:09.0152 4172 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
10:02:09.0152 4172 UlSata - ok
10:02:09.0182 4172 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
10:02:09.0182 4172 ulsata2 - ok
10:02:09.0212 4172 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
10:02:09.0212 4172 umbus - ok
10:02:09.0262 4172 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
10:02:09.0262 4172 usbccgp - ok
10:02:09.0302 4172 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
10:02:09.0302 4172 usbcir - ok
10:02:09.0352 4172 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
10:02:09.0352 4172 usbehci - ok
10:02:09.0412 4172 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
10:02:09.0412 4172 usbhub - ok
10:02:09.0422 4172 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
10:02:09.0422 4172 usbohci - ok
10:02:09.0462 4172 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
10:02:09.0462 4172 usbprint - ok
10:02:09.0512 4172 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
10:02:09.0512 4172 usbscan - ok
10:02:09.0662 4172 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:02:09.0672 4172 USBSTOR - ok
10:02:09.0742 4172 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
10:02:09.0742 4172 usbuhci - ok
10:02:10.0052 4172 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
10:02:10.0062 4172 usbvideo - ok
10:02:10.0142 4172 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
10:02:10.0142 4172 vga - ok
10:02:10.0212 4172 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
10:02:10.0212 4172 VgaSave - ok
10:02:10.0242 4172 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
10:02:10.0242 4172 viaagp - ok
10:02:10.0272 4172 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
10:02:10.0272 4172 ViaC7 - ok
10:02:10.0332 4172 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
10:02:10.0332 4172 viaide - ok
10:02:10.0372 4172 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
10:02:10.0372 4172 volmgr - ok
10:02:10.0442 4172 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
10:02:10.0442 4172 volmgrx - ok
10:02:10.0502 4172 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
10:02:10.0512 4172 volsnap - ok
10:02:10.0562 4172 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
10:02:10.0572 4172 vsmraid - ok
10:02:10.0622 4172 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
10:02:10.0622 4172 WacomPen - ok
10:02:10.0692 4172 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
10:02:10.0702 4172 Wanarp - ok
10:02:10.0752 4172 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
10:02:10.0752 4172 Wanarpv6 - ok
10:02:10.0772 4172 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
10:02:10.0772 4172 Wd - ok
10:02:10.0832 4172 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
10:02:10.0842 4172 Wdf01000 - ok
10:02:11.0032 4172 winachsf (0acd399f5db3df1b58903cf4949ab5a8) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
10:02:11.0062 4172 winachsf - ok
10:02:11.0152 4172 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
10:02:11.0152 4172 WmiAcpi - ok
10:02:11.0242 4172 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
10:02:11.0252 4172 WpdUsb - ok
10:02:11.0332 4172 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
10:02:11.0332 4172 ws2ifsl - ok
10:02:11.0432 4172 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:02:11.0432 4172 WUDFRd - ok
10:02:12.0172 4172 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
10:02:12.0172 4172 XAudio - ok
10:02:12.0262 4172 MBR (0x1B8) (1a1a06f62e891045814007163c1c76c3) \Device\Harddisk0\DR0
10:02:12.0302 4172 \Device\Harddisk0\DR0 - ok
10:02:12.0312 4172 Boot (0x1200) (0d58f86005da2213beab1543be5ed097) \Device\Harddisk0\DR0\Partition0
10:02:12.0312 4172 \Device\Harddisk0\DR0\Partition0 - ok
10:02:12.0352 4172 Boot (0x1200) (7f28142866938740324274d1260a6a2c) \Device\Harddisk0\DR0\Partition1
10:02:12.0352 4172 \Device\Harddisk0\DR0\Partition1 - ok
10:02:12.0352 4172 ============================================================
10:02:12.0352 4172 Scan finished
10:02:12.0352 4172 ============================================================
10:02:12.0382 5196 Detected object count: 1
10:02:12.0382 5196 Actual detected object count: 1
10:02:22.0974 5196 sptd ( LockedFile.Multi.Generic ) - skipped by user
10:02:22.0975 5196 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
10:02:34.0467 3396 Deinitialize success
______________
Hope this helps. The DDS Attach file has been attached as well.
-drsulli
Hi drsulli,
Perfect, thanks for the logs! And Merry Christmas
Next, Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT- Save ComboFix.exe to your Desktop
====================================================
Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic
How to disable your security applications
====================================================
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt in your next reply for further review.
Thanks again for the help, however I believe my wife's laptop has an old copy of Microsoft Security Essentials that was removed improperly or incompletely. MSE is not currently installed however the combofix tool says that it is finding MSE processes running prior to starting. I was able to disable Norton 360 Auto-Protect. That said, the combofix tool will start to run and begin its scan and will never finish. It just kind of stalls out even after leaving it running for 5 hours or more. However, Norton while scanning did find two trojans called "ZeroAccessTrojan" which it prompted me to remove manually. I downloaded a ZeroAccessFixtool program from Symantec's website. It rebooted the computer and then scanned for and removed/repaired the files infected with the ZeroAccess Trojan. I do no know that this is the same trojan that was causing the PING.EXE file to run however I have not seen it running since this repair so I have my fingers crossed.
drsulli,
Yes, ZeroAccess is the infection that is responsible for PING.EXE, however ComboFix is the only tool that can completely remove a ZeroAccess infection. Other tools will simply remove parts of it. MSE might have interfered with ComboFix, causing it to stall. Did Norton start scanning while you were running ComboFix?
I would like you to try the following to clean up the failed removal of MSE.
Please download
AppRemover and save it to your desktop.
Double click on AppRemover.exe to run it. Uncheck "Enable anonymous usage statistics. No personal data will be recorded. " Click on the Next button. Click on "Remove Security Application " or "Clean Up a Failed Uninstall " depending on what you want to do. (you want the failed uninstall) Click on the Next button. A scan begins, please wait. Once done, click on the Next button. Now you should have a list of your installed programs, choose the one you want to remove and click on the Next button. Follow the last step and reboot if asked to do so. ===================================================
Then run ComboFix again and post the log.
I tried the appremover program. It finished its scan after 5-10 minutes and there were no programs in the list.
Ok, try running ComboFix again.
Sadly, still no dice on combofix. Any other thoughts?
Your help thus far has been highly appreciated btw.
Hi drsulli,
It is my pleasure :). Can you browse to your C:\ drive and see if there are any logs there named ComboFix.txt ? Also, browse to c:\qoobox and see if combofix-quarantined-files.txt exists. If either log is there, please post them.
Those directories do exist, but those log files do not. My wife is taking her laptop away from the home for business for a bit so it may be a few weeks until I can work on it again. Thanks for the help and hopefully when she brings it back we can continue.
No problem drsulli. In the meantime, I'll try to get a second opinion on why ComboFix won't run. Let me know when she returns.
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic