This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tidserv Activity / Tidserv Activity 2 Errors [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 1:38:29.78 on Fri 01/20/2012 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_30 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.951 [GMT -5:00] . AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Owner\My Documents\Downloads\dds.scr . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\5.1.0.29\ips\IPSBHO.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\5.1.0.29\coIEPlg.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MJLSoftware] rundll32.exe "c:\documents and settings\owner\local settings\application data\apple\appleupdate\Appleupdt32.dll",DllRegisterServer uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [Norton Download Manager{NBRT41-B15-SOS-4abb-B07C-C084B04B4F12}] c:\documents and settings\all users\documents\norton\{nbrt41-b15-sos-4abb-b07c-c084b04b4f12}\NBRT-SOS-Downloader.exe /m mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [] mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRun: [AdobeData] rundll32.exe "c:\documents and settings\owner\local settings\application data\adobe\adobedata\Adobedata.dll",DllRegisterServer dRunOnce: [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f dRunOnce: [adaware_XP] reg.exe delete "HKCU\Software\adaware" /f IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\qcllsj9m.default\ FF - prefs.js: browser.search.selectedEngine - Search the Web FF - prefs.js: browser.startup.homepage - hxxp://xfinity.comcast.net/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=utf-8&rlz=1V2IPYX&q= FF - component: c:\documents and settings\all users\application data\white sky, inc\id vault\xpcom3\components\IdVault.XPCOM3.dll FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\nos\bin\np_gp.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\symds.sys [2012-1-19 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\symefa.sys [2012-1-19 744568] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\bashdefs\20111223.001\BHDrvx86.sys [2011-12-23 820344] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys [2012-1-19 136312] R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\5.1.0.29\ccsvchst.exe [2012-1-19 130008] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-1-19 106104] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2009-10-17 200192] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\ipsdefs\20120119.006\IDSXpx86.sys [2012-1-19 356280] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\virusdefs\20120119.020\NAVENG.SYS [2012-1-19 86136] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\virusdefs\20120119.020\NAVEX15.SYS [2012-1-19 1576312] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S1 MpKsl0165c987;MpKsl0165c987;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\mpksl0165c987.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\MpKsl0165c987.sys [?] S1 MpKsl021bb863;MpKsl021bb863;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{77a32496-0b2a-4014-bde6-2df4cd019e13}\mpksl021bb863.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{77a32496-0b2a-4014-bde6-2df4cd019e13}\MpKsl021bb863.sys [?] S1 MpKsl033bd8ab;MpKsl033bd8ab;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\mpksl033bd8ab.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\MpKsl033bd8ab.sys [?] S1 MpKsl0b4438d9;MpKsl0b4438d9;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2cd6bb9-5cfd-48f2-aa45-48b905306c0d}\mpksl0b4438d9.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2cd6bb9-5cfd-48f2-aa45-48b905306c0d}\MpKsl0b4438d9.sys [?] S1 MpKsl13d1a466;MpKsl13d1a466;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\mpksl13d1a466.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\MpKsl13d1a466.sys [?] S1 MpKsl157e641f;MpKsl157e641f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{16525893-536f-4834-b844-353bdace8349}\mpksl157e641f.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{16525893-536f-4834-b844-353bdace8349}\MpKsl157e641f.sys [?] S1 MpKsl17161570;MpKsl17161570;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{03895831-0ae6-45f0-80db-a399a63b06cf}\mpksl17161570.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{03895831-0ae6-45f0-80db-a399a63b06cf}\MpKsl17161570.sys [?] S1 MpKsl1950c7df;MpKsl1950c7df;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32346412-f188-42ec-8944-c97b8a2c874a}\mpksl1950c7df.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32346412-f188-42ec-8944-c97b8a2c874a}\MpKsl1950c7df.sys [?] S1 MpKsl226aef29;MpKsl226aef29;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7d9e246-62e6-4893-94cf-c11649be4232}\mpksl226aef29.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7d9e246-62e6-4893-94cf-c11649be4232}\MpKsl226aef29.sys [?] S1 MpKsl28f70872;MpKsl28f70872;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae6f129f-62e5-4e44-b91b-58b4d7ae314a}\mpksl28f70872.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae6f129f-62e5-4e44-b91b-58b4d7ae314a}\MpKsl28f70872.sys [?] S1 MpKsl2bda934d;MpKsl2bda934d;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{57ae026a-e759-40c7-bda5-d011a7149e6e}\mpksl2bda934d.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{57ae026a-e759-40c7-bda5-d011a7149e6e}\MpKsl2bda934d.sys [?] S1 MpKsl35207537;MpKsl35207537;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{777d79f4-f03c-44f7-bbec-83d084a0b6f0}\mpksl35207537.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{777d79f4-f03c-44f7-bbec-83d084a0b6f0}\MpKsl35207537.sys [?] S1 MpKsl37a92c79;MpKsl37a92c79;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fd726855-33dd-4ef8-89e4-3ffdaf1f9081}\mpksl37a92c79.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fd726855-33dd-4ef8-89e4-3ffdaf1f9081}\MpKsl37a92c79.sys [?] S1 MpKsl394cf1c2;MpKsl394cf1c2;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1ffb8a3e-6c29-4e05-a4fd-2878549e6069}\mpksl394cf1c2.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1ffb8a3e-6c29-4e05-a4fd-2878549e6069}\MpKsl394cf1c2.sys [?] S1 MpKsl3c6e1a91;MpKsl3c6e1a91;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ee4cc8eb-25a6-4ed8-bc86-02410c4e9b2c}\mpksl3c6e1a91.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ee4cc8eb-25a6-4ed8-bc86-02410c4e9b2c}\MpKsl3c6e1a91.sys [?] S1 MpKsl3ce485fd;MpKsl3ce485fd;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{91e8ac3d-d7e3-4dd2-bfd2-18092fc72590}\mpksl3ce485fd.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{91e8ac3d-d7e3-4dd2-bfd2-18092fc72590}\MpKsl3ce485fd.sys [?] S1 MpKsl401ff5cd;MpKsl401ff5cd;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\mpksl401ff5cd.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\MpKsl401ff5cd.sys [?] S1 MpKsl4b1580f8;MpKsl4b1580f8;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e20d9f1c-1917-4fc0-b59b-b4b80b70da67}\mpksl4b1580f8.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e20d9f1c-1917-4fc0-b59b-b4b80b70da67}\MpKsl4b1580f8.sys [?] S1 MpKsl5c58b1ea;MpKsl5c58b1ea;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{35c7dd68-846f-42d3-89d5-3f43c23d9430}\mpksl5c58b1ea.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{35c7dd68-846f-42d3-89d5-3f43c23d9430}\MpKsl5c58b1ea.sys [?] S1 MpKsl5fc99565;MpKsl5fc99565;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1093d047-ac9c-4532-9abf-2555330fa66b}\mpksl5fc99565.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1093d047-ac9c-4532-9abf-2555330fa66b}\MpKsl5fc99565.sys [?] S1 MpKsl616a72b0;MpKsl616a72b0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7012d965-adcd-4b1d-a3ef-b25735f3b993}\mpksl616a72b0.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7012d965-adcd-4b1d-a3ef-b25735f3b993}\MpKsl616a72b0.sys [?] S1 MpKsl61c17592;MpKsl61c17592;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6329dec0-dcad-493d-8294-ed0317854439}\mpksl61c17592.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6329dec0-dcad-493d-8294-ed0317854439}\MpKsl61c17592.sys [?] S1 MpKsl67523628;MpKsl67523628;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\mpksl67523628.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\MpKsl67523628.sys [?] S1 MpKsl6c8e42ae;MpKsl6c8e42ae;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bca08176-d89a-4c83-b338-f33dadd4083d}\mpksl6c8e42ae.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bca08176-d89a-4c83-b338-f33dadd4083d}\MpKsl6c8e42ae.sys [?] S1 MpKsl7048e524;MpKsl7048e524;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9c890a03-2b8c-4ee2-bab0-c9e9a250fd5e}\mpksl7048e524.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9c890a03-2b8c-4ee2-bab0-c9e9a250fd5e}\MpKsl7048e524.sys [?] S1 MpKsl729fe3b7;MpKsl729fe3b7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{91e8ac3d-d7e3-4dd2-bfd2-18092fc72590}\mpksl729fe3b7.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{91e8ac3d-d7e3-4dd2-bfd2-18092fc72590}\MpKsl729fe3b7.sys [?] S1 MpKsl73da1d00;MpKsl73da1d00;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{03895831-0ae6-45f0-80db-a399a63b06cf}\mpksl73da1d00.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{03895831-0ae6-45f0-80db-a399a63b06cf}\MpKsl73da1d00.sys [?] S1 MpKsl7a77928f;MpKsl7a77928f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\mpksl7a77928f.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\MpKsl7a77928f.sys [?] S1 MpKsl7bec6f07;MpKsl7bec6f07;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d7b68afe-b8ad-4746-b3f4-cc47079b242b}\mpksl7bec6f07.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d7b68afe-b8ad-4746-b3f4-cc47079b242b}\MpKsl7bec6f07.sys [?] S1 MpKsl7c0c970e;MpKsl7c0c970e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d973dad8-4b88-4fce-9975-208dcf48b1ca}\mpksl7c0c970e.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d973dad8-4b88-4fce-9975-208dcf48b1ca}\MpKsl7c0c970e.sys [?] S1 MpKsl7ff7cc8d;MpKsl7ff7cc8d;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e5f05a91-205a-42c0-82d7-18cddcd27fc8}\mpksl7ff7cc8d.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e5f05a91-205a-42c0-82d7-18cddcd27fc8}\MpKsl7ff7cc8d.sys [?] S1 MpKsl813b1a8c;MpKsl813b1a8c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d988e92a-8bcc-43cb-9afa-193b59a2c839}\mpksl813b1a8c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d988e92a-8bcc-43cb-9afa-193b59a2c839}\MpKsl813b1a8c.sys [?] S1 MpKsl8254ed7c;MpKsl8254ed7c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f0bb2bda-087e-4fd1-9b2f-38db524af509}\mpksl8254ed7c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f0bb2bda-087e-4fd1-9b2f-38db524af509}\MpKsl8254ed7c.sys [?] S1 MpKsl8ba93a74;MpKsl8ba93a74;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4c4d8ce5-d735-43de-b287-2100265ac48e}\mpksl8ba93a74.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4c4d8ce5-d735-43de-b287-2100265ac48e}\MpKsl8ba93a74.sys [?] S1 MpKsl9e2cfa34;MpKsl9e2cfa34;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\mpksl9e2cfa34.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\MpKsl9e2cfa34.sys [?] S1 MpKsla0316214;MpKsla0316214;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8bf06d28-7156-4383-b03b-eb6688541e37}\mpksla0316214.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8bf06d28-7156-4383-b03b-eb6688541e37}\MpKsla0316214.sys [?] S1 MpKsla95a9b33;MpKsla95a9b33;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{47c2eaec-2578-41c9-a28b-53df418d155c}\mpksla95a9b33.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{47c2eaec-2578-41c9-a28b-53df418d155c}\MpKsla95a9b33.sys [?] S1 MpKslae2a1a94;MpKslae2a1a94;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d1985527-4379-484b-8b7e-d074a37d3c41}\mpkslae2a1a94.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d1985527-4379-484b-8b7e-d074a37d3c41}\MpKslae2a1a94.sys [?] S1 MpKslb09a7a24;MpKslb09a7a24;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d910bfe7-5608-4825-9341-b58a0d0af5fe}\mpkslb09a7a24.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d910bfe7-5608-4825-9341-b58a0d0af5fe}\MpKslb09a7a24.sys [?] S1 MpKslb9145fcc;MpKslb9145fcc;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0992907f-8f55-4d9e-a581-ba92497867d5}\mpkslb9145fcc.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0992907f-8f55-4d9e-a581-ba92497867d5}\MpKslb9145fcc.sys [?] S1 MpKslbdbdeb31;MpKslbdbdeb31;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4717f30d-6fd0-4f01-8efd-c655493447e0}\mpkslbdbdeb31.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4717f30d-6fd0-4f01-8efd-c655493447e0}\MpKslbdbdeb31.sys [?] S1 MpKslc0d08019;MpKslc0d08019;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fd726855-33dd-4ef8-89e4-3ffdaf1f9081}\mpkslc0d08019.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fd726855-33dd-4ef8-89e4-3ffdaf1f9081}\MpKslc0d08019.sys [?] S1 MpKslc2a666a9;MpKslc2a666a9;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7a2dd85-5b60-461b-8758-401848273ddc}\mpkslc2a666a9.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7a2dd85-5b60-461b-8758-401848273ddc}\MpKslc2a666a9.sys [?] S1 MpKslc449459c;MpKslc449459c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fe38e2f3-3337-431e-b8c2-e501c38c5d91}\mpkslc449459c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fe38e2f3-3337-431e-b8c2-e501c38c5d91}\MpKslc449459c.sys [?] S1 MpKslc48c99d5;MpKslc48c99d5;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1093d047-ac9c-4532-9abf-2555330fa66b}\mpkslc48c99d5.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1093d047-ac9c-4532-9abf-2555330fa66b}\MpKslc48c99d5.sys [?] S1 MpKsld9bd6b7f;MpKsld9bd6b7f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{47c2eaec-2578-41c9-a28b-53df418d155c}\mpksld9bd6b7f.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{47c2eaec-2578-41c9-a28b-53df418d155c}\MpKsld9bd6b7f.sys [?] S1 MpKsle8dcf7dd;MpKsle8dcf7dd;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0bfe6824-b876-42cf-b5c1-7b19aa4389a7}\mpksle8dcf7dd.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0bfe6824-b876-42cf-b5c1-7b19aa4389a7}\MpKsle8dcf7dd.sys [?] S1 MpKslee655182;MpKslee655182;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{71137be7-c74b-411d-9ace-493ee0ffe569}\mpkslee655182.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{71137be7-c74b-411d-9ace-493ee0ffe569}\MpKslee655182.sys [?] S1 MpKslef24c03f;MpKslef24c03f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2279de4c-faff-4ad6-90c4-9a8e4f8501df}\mpkslef24c03f.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2279de4c-faff-4ad6-90c4-9a8e4f8501df}\MpKslef24c03f.sys [?] S1 MpKslffc88a78;MpKslffc88a78;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ccea5db8-8d8f-4d94-9a4d-b18a72364708}\mpkslffc88a78.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ccea5db8-8d8f-4d94-9a4d-b18a72364708}\MpKslffc88a78.sys [?] . =============== Created Last 30 ================ . 2012-01-20 05:41:36 ——– d—–w- c:\windows\system32\drivers\nbrtwizard\0401000.00F 2012-01-20 05:41:36 ——– d—–w- c:\windows\system32\drivers\NBRTWizard 2012-01-20 05:41:33 ——– d—–w- c:\program files\Norton Bootable Recovery Tool Wizard 2012-01-20 01:40:38 744568 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symefa.sys 2012-01-20 01:40:38 516216 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys 2012-01-20 01:40:38 50168 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys 2012-01-20 01:40:38 369784 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symtdi.sys 2012-01-20 01:40:38 340088 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symds.sys 2012-01-20 01:40:38 331384 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys 2012-01-20 01:40:38 296568 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys 2012-01-20 01:40:37 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys 2012-01-20 01:40:06 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D 2012-01-20 01:34:51 60872 —-a-w- c:\windows\system32\S32EVNT1.DLL 2012-01-20 01:34:51 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2012-01-20 01:34:51 ——– d—–w- c:\program files\Symantec 2012-01-20 01:34:51 ——– d—–w- c:\program files\common files\Symantec Shared 2012-01-20 01:34:04 ——– d—–w- c:\windows\system32\drivers\N360 2012-01-20 01:34:02 ——– d—–w- c:\program files\Norton Security Suite 2012-01-20 01:33:50 ——– d—–w- c:\program files\NortonInstaller 2012-01-20 01:33:50 ——– d—–w- c:\docume~1\alluse~1\applic~1\NortonInstaller 2012-01-20 01:17:42 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2012-01-20 01:17:42 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2012-01-20 01:17:41 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2012-01-20 01:17:40 97240 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2012-01-20 01:17:40 486360 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2012-01-20 01:17:40 2124760 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2012-01-20 01:17:40 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2012-01-20 01:17:39 814040 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2012-01-20 01:17:39 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2012-01-20 01:17:39 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2012-01-20 01:17:39 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2012-01-20 01:17:39 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll 2012-01-20 01:09:16 ——– d—–w- c:\windows\SxsCaPendDel 2012-01-20 01:03:07 ——– d—–w- c:\documents and settings\all users\GID 2012-01-20 00:54:21 ——– d—–w- c:\docume~1\alluse~1\applic~1\Norton 2012-01-20 00:20:50 ——– d—–w- c:\docume~1\alluse~1\applic~1\IsolatedStorage 2012-01-20 00:19:51 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\ID Vault 2012-01-20 00:19:44 ——– d—–w- c:\docume~1\owner\applic~1\ID Vault 2012-01-20 00:18:51 ——– d—–w- c:\program files\Constant Guard Protection Suite 2012-01-20 00:13:13 ——– d—–w- c:\windows\system32\XPSViewer 2012-01-20 00:12:10 27648 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2012-01-20 00:11:45 14048 ——w- c:\windows\system32\spmsg2.dll 2012-01-13 21:31:20 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-01-13 21:31:20 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2012-01-13 21:28:37 ——– d—–w- c:\program files\iPod 2012-01-13 21:27:15 ——– d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2012-01-13 21:27:14 ——– d—–w- c:\program files\iTunes 2012-01-13 21:21:07 ——– d—–w- c:\program files\Bonjour 2012-01-13 21:12:44 ——– d—–w- c:\docume~1\alluse~1\applic~1\White Sky, Inc 2012-01-13 15:43:55 ——– d—–w- c:\program files\Toolbar Cleaner 2012-01-13 15:20:38 73728 —-a-w- c:\windows\system32\javacpl.cpl 2012-01-13 08:36:04 ——– d—–w- c:\docume~1\owner\applic~1\Malwarebytes 2012-01-13 08:35:41 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2012-01-03 13:22:02 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2012-01-03 13:22:02 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll . ==================== Find3M ==================== . 2012-01-20 04:21:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe 2011-11-10 10:54:13 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20:51 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 —-a-w- c:\windows\system32\html.iec 2011-11-03 15:28:36 386048 —-a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28:36 1292288 —-a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-24 19:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 19:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts . ============= FINISH: 1:40:22.10 ===============
Hello Malman and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

======================================================

You can not run two real-time antiviruses at the same time. Although many have different methods of searching for and recognising threats, they will all be 'fighting' in memory to kick each other out, rendering them both ineffective.

If you have paid for Norton Security Suite then remove Microsoft Security Essentials through Add or Remove programs in the Control Panel.

======================================================

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan
    • only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
    • click Continue > Reboot now
  • copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
======================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • see this Link for programs that need to be disabled and instruction on how to disable them.
  • remember to re-enable them when we're done.
  • double click on ComboFix.exe & follow the prompts.
  • as part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please also remember to include the TDSSKiller log

Thanks

Satchfan
Satchfan thanks for your help.
—————————————————————————————————————————
I did not see the Microsoft Security Essentials in the Add / Remove product list. I had already removed it and rebooted, so I installed again, and removed again just incase there was a conflict at the time it was initially removed and some of it was left behind. Hopefully it is gone now.



I followed the other instructions as you had them documented, and here are the results:
————————————————————————————————————————–
TDSSKiller Log:
10:20:59.0421 0300 TDSS rootkit removing tool 2.7.6.0 Jan 19 2012 13:09:04
10:21:01.0421 0300 ============================================================
10:21:01.0421 0300 Current date / time: 2012/01/20 10:21:01.0421
10:21:01.0421 0300 SystemInfo:
10:21:01.0421 0300
10:21:01.0421 0300 OS Version: 5.1.2600 ServicePack: 3.0
10:21:01.0421 0300 Product type: Workstation
10:21:01.0421 0300 ComputerName: JUDY-LAPTOP
10:21:01.0421 0300 UserName: Owner
10:21:01.0421 0300 Windows directory: C:\WINDOWS
10:21:01.0421 0300 System windows directory: C:\WINDOWS
10:21:01.0421 0300 Processor architecture: Intel x86
10:21:01.0421 0300 Number of processors: 1
10:21:01.0437 0300 Page size: 0x1000
10:21:01.0437 0300 Boot type: Normal boot
10:21:01.0437 0300 ============================================================
10:21:06.0078 0300 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
10:21:06.0093 0300 Initialize success
10:21:43.0078 2720 ============================================================
10:21:43.0078 2720 Scan started
10:21:43.0078 2720 Mode: Manual;
10:21:43.0078 2720 ============================================================
10:21:43.0515 2720 Abiosdsk - ok
10:21:43.0531 2720 abp480n5 - ok
10:21:43.0640 2720 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:21:43.0640 2720 ACPI - ok
10:21:43.0687 2720 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
10:21:43.0687 2720 ACPIEC - ok
10:21:43.0718 2720 adpu160m - ok
10:21:43.0812 2720 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
10:21:43.0828 2720 aec - ok
10:21:43.0906 2720 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
10:21:43.0968 2720 AFD - ok
10:21:44.0015 2720 Aha154x - ok
10:21:44.0031 2720 aic78u2 - ok
10:21:44.0062 2720 aic78xx - ok
10:21:44.0125 2720 AliIde - ok
10:21:44.0218 2720 AmdK8 (a2d5f093f9cb160c183c77015704f156) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
10:21:44.0312 2720 AmdK8 - ok
10:21:44.0343 2720 amsint - ok
10:21:44.0421 2720 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
10:21:44.0421 2720 Arp1394 - ok
10:21:44.0468 2720 asc - ok
10:21:44.0515 2720 asc3350p - ok
10:21:44.0546 2720 asc3550 - ok
10:21:44.0640 2720 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:21:44.0640 2720 AsyncMac - ok
10:21:44.0687 2720 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:21:44.0687 2720 atapi - ok
10:21:44.0734 2720 Atdisk - ok
10:21:44.0890 2720 ati2mtag (9dc33d25ee0ed27752455a52f25ddb6e) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
10:21:44.0953 2720 ati2mtag - ok
10:21:45.0171 2720 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:21:45.0218 2720 Atmarpc - ok
10:21:45.0312 2720 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:21:45.0328 2720 audstub - ok
10:21:45.0421 2720 BCM43XX (e7debb46b9ef1f28932e533be4a3d1a9) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
10:21:45.0609 2720 BCM43XX - ok
10:21:45.0687 2720 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:21:45.0734 2720 Beep - ok
10:21:46.0062 2720 BHDrvx86 (e685ba3267c5a4ec4ce9e2b4a1481725) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111223.001\BHDrvx86.sys
10:21:46.0296 2720 BHDrvx86 - ok
10:21:46.0562 2720 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
10:21:46.0562 2720 BrScnUsb - ok
10:21:46.0656 2720 CAMCAUD (4ebc37b6677a6768b307ae40839d788f) C:\WINDOWS\system32\drivers\camc6aud.sys
10:21:46.0687 2720 CAMCAUD - ok
10:21:46.0781 2720 CAMCHALA (9a38fc432ad8b3400cefb70a7236979e) C:\WINDOWS\system32\drivers\camc6hal.sys
10:21:46.0828 2720 CAMCHALA - ok
10:21:46.0906 2720 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:21:46.0906 2720 cbidf2k - ok
10:21:46.0937 2720 cd20xrnt - ok
10:21:47.0000 2720 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:21:47.0015 2720 Cdaudio - ok
10:21:47.0093 2720 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
10:21:47.0093 2720 Cdfs - ok
10:21:47.0125 2720 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:21:47.0125 2720 Cdrom - ok
10:21:47.0140 2720 Changer - ok
10:21:47.0203 2720 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
10:21:47.0203 2720 CmBatt - ok
10:21:47.0218 2720 CmdIde - ok
10:21:47.0265 2720 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
10:21:47.0265 2720 Compbatt - ok
10:21:47.0312 2720 Cpqarray - ok
10:21:47.0343 2720 dac2w2k - ok
10:21:47.0359 2720 dac960nt - ok
10:21:47.0406 2720 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
10:21:47.0406 2720 Disk - ok
10:21:47.0484 2720 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
10:21:47.0531 2720 dmboot - ok
10:21:47.0656 2720 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
10:21:47.0671 2720 dmio - ok
10:21:47.0703 2720 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:21:47.0703 2720 dmload - ok
10:21:47.0781 2720 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
10:21:47.0781 2720 DMusic - ok
10:21:47.0828 2720 dpti2o - ok
10:21:47.0843 2720 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
10:21:47.0843 2720 drmkaud - ok
10:21:47.0968 2720 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
10:21:48.0000 2720 eeCtrl - ok
10:21:48.0046 2720 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
10:21:48.0062 2720 EraserUtilRebootDrv - ok
10:21:48.0140 2720 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
10:21:48.0156 2720 Fastfat - ok
10:21:48.0203 2720 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
10:21:48.0218 2720 Fdc - ok
10:21:48.0250 2720 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
10:21:48.0250 2720 Fips - ok
10:21:48.0281 2720 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
10:21:48.0281 2720 Flpydisk - ok
10:21:48.0328 2720 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
10:21:48.0328 2720 FltMgr - ok
10:21:48.0359 2720 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:21:48.0359 2720 Fs_Rec - ok
10:21:48.0390 2720 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:21:48.0390 2720 Ftdisk - ok
10:21:48.0468 2720 GEARAspiWDM (5ae3a887ece5bbb72cfab273c2fd1cfa) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
10:21:48.0468 2720 GEARAspiWDM - ok
10:21:48.0640 2720 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:21:48.0656 2720 Gpc - ok
10:21:48.0734 2720 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:21:48.0750 2720 HidUsb - ok
10:21:48.0796 2720 hpn - ok
10:21:49.0156 2720 HSFHWATI (13d4b70bf2f9bc550e9079da864d3ec1) C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys
10:21:49.0171 2720 HSFHWATI - ok
10:21:49.0281 2720 HSF_DP (dfa8f86c0dbca7db948043aa3be6793b) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
10:21:49.0328 2720 HSF_DP - ok
10:21:49.0406 2720 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
10:21:49.0421 2720 HTTP - ok
10:21:49.0453 2720 i2omgmt - ok
10:21:49.0468 2720 i2omp - ok
10:21:49.0546 2720 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:21:49.0562 2720 i8042prt - ok
10:21:49.0937 2720 IDSxpx86 (e72d3894d42355e9cd5fd77e1e4fea11) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120119.006\IDSxpx86.sys
10:21:49.0953 2720 IDSxpx86 - ok
10:21:50.0093 2720 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:21:50.0093 2720 Imapi - ok
10:21:50.0140 2720 ini910u - ok
10:21:50.0171 2720 IntelIde - ok
10:21:50.0218 2720 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
10:21:50.0234 2720 Ip6Fw - ok
10:21:50.0312 2720 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:21:50.0312 2720 IpFilterDriver - ok
10:21:50.0359 2720 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:21:50.0359 2720 IpInIp - ok
10:21:50.0406 2720 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:21:50.0421 2720 IpNat - ok
10:21:50.0453 2720 IPSec (a4e2ce9bfc36045184aaa66ea8759350) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:21:50.0468 2720 IPSec ( Virus.Win32.ZAccess.k ) - infected
10:21:50.0468 2720 IPSec - detected Virus.Win32.ZAccess.k (0)
10:21:50.0515 2720 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:21:50.0515 2720 IRENUM - ok
10:21:50.0578 2720 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:21:50.0578 2720 isapnp - ok
10:21:50.0625 2720 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:21:50.0625 2720 Kbdclass - ok
10:21:50.0671 2720 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
10:21:50.0671 2720 kmixer - ok
10:21:50.0718 2720 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
10:21:50.0718 2720 KSecDD - ok
10:21:50.0750 2720 Lbd - ok
10:21:50.0781 2720 lbrtfdc - ok
10:21:50.0859 2720 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
10:21:50.0859 2720 mdmxsdk - ok
10:21:50.0906 2720 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:21:50.0921 2720 mnmdd - ok
10:21:51.0046 2720 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
10:21:51.0046 2720 Modem - ok
10:21:51.0078 2720 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:21:51.0078 2720 Mouclass - ok
10:21:51.0125 2720 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:21:51.0125 2720 mouhid - ok
10:21:51.0156 2720 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
10:21:51.0156 2720 MountMgr - ok
10:21:51.0312 2720 MpKsl0165c987 - ok
10:21:51.0328 2720 MpKsl021bb863 - ok
10:21:51.0343 2720 MpKsl033bd8ab - ok
10:21:51.0359 2720 MpKsl0b4438d9 - ok
10:21:51.0375 2720 MpKsl13d1a466 - ok
10:21:51.0390 2720 MpKsl157e641f - ok
10:21:51.0406 2720 MpKsl17161570 - ok
10:21:51.0421 2720 MpKsl1950c7df - ok
10:21:51.0437 2720 MpKsl226aef29 - ok
10:21:51.0453 2720 MpKsl28f70872 - ok
10:21:51.0468 2720 MpKsl2bda934d - ok
10:21:51.0484 2720 MpKsl35207537 - ok
10:21:51.0500 2720 MpKsl37a92c79 - ok
10:21:51.0515 2720 MpKsl394cf1c2 - ok
10:21:51.0531 2720 MpKsl3c6e1a91 - ok
10:21:51.0562 2720 MpKsl3ce485fd - ok
10:21:51.0578 2720 MpKsl401ff5cd - ok
10:21:51.0593 2720 MpKsl4b1580f8 - ok
10:21:51.0609 2720 MpKsl5c58b1ea - ok
10:21:51.0625 2720 MpKsl5fc99565 - ok
10:21:51.0640 2720 MpKsl616a72b0 - ok
10:21:51.0656 2720 MpKsl61c17592 - ok
10:21:51.0671 2720 MpKsl67523628 - ok
10:21:51.0687 2720 MpKsl6c8e42ae - ok
10:21:51.0703 2720 MpKsl7048e524 - ok
10:21:51.0718 2720 MpKsl729fe3b7 - ok
10:21:51.0734 2720 MpKsl73da1d00 - ok
10:21:51.0750 2720 MpKsl7a77928f - ok
10:21:51.0765 2720 MpKsl7bec6f07 - ok
10:21:51.0765 2720 MpKsl7c0c970e - ok
10:21:51.0781 2720 MpKsl7ff7cc8d - ok
10:21:51.0796 2720 MpKsl813b1a8c - ok
10:21:51.0812 2720 MpKsl8254ed7c - ok
10:21:51.0828 2720 MpKsl8ba93a74 - ok
10:21:51.0843 2720 MpKsl9e2cfa34 - ok
10:21:51.0859 2720 MpKsla0316214 - ok
10:21:51.0875 2720 MpKsla95a9b33 - ok
10:21:51.0890 2720 MpKslae2a1a94 - ok
10:21:51.0906 2720 MpKslb09a7a24 - ok
10:21:51.0921 2720 MpKslb9145fcc - ok
10:21:51.0937 2720 MpKslbdbdeb31 - ok
10:21:51.0937 2720 MpKslc0d08019 - ok
10:21:51.0953 2720 MpKslc2a666a9 - ok
10:21:51.0968 2720 MpKslc449459c - ok
10:21:51.0984 2720 MpKslc48c99d5 - ok
10:21:52.0000 2720 MpKsld9bd6b7f - ok
10:21:52.0015 2720 MpKsle8dcf7dd - ok
10:21:52.0031 2720 MpKslee655182 - ok
10:21:52.0046 2720 MpKslef24c03f - ok
10:21:52.0062 2720 MpKslffc88a78 - ok
10:21:52.0078 2720 mraid35x - ok
10:21:52.0156 2720 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:21:52.0156 2720 MRxDAV - ok
10:21:52.0250 2720 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:21:52.0265 2720 MRxSmb - ok
10:21:52.0296 2720 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
10:21:52.0296 2720 Msfs - ok
10:21:52.0359 2720 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:21:52.0359 2720 MSKSSRV - ok
10:21:52.0406 2720 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:21:52.0406 2720 MSPCLOCK - ok
10:21:52.0437 2720 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
10:21:52.0453 2720 MSPQM - ok
10:21:52.0515 2720 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:21:52.0515 2720 mssmbios - ok
10:21:52.0812 2720 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
10:21:52.0828 2720 Mup - ok
10:21:53.0125 2720 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120119.035\NAVENG.SYS
10:21:53.0140 2720 NAVENG - ok
10:21:53.0250 2720 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120119.035\NAVEX15.SYS
10:21:53.0296 2720 NAVEX15 - ok
10:21:53.0421 2720 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
10:21:53.0437 2720 NDIS - ok
10:21:53.0546 2720 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:21:53.0546 2720 NdisTapi - ok
10:21:53.0593 2720 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:21:53.0593 2720 Ndisuio - ok
10:21:53.0625 2720 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:21:53.0625 2720 NdisWan - ok
10:21:53.0734 2720 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
10:21:53.0750 2720 NDProxy - ok
10:21:53.0781 2720 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:21:53.0781 2720 NetBIOS - ok
10:21:53.0828 2720 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:21:53.0828 2720 NetBT - ok
10:21:53.0890 2720 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
10:21:53.0890 2720 NIC1394 - ok
10:21:53.0921 2720 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
10:21:53.0921 2720 Npfs - ok
10:21:53.0984 2720 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
10:21:54.0000 2720 Ntfs - ok
10:21:54.0062 2720 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:21:54.0062 2720 Null - ok
10:21:54.0093 2720 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:21:54.0109 2720 NwlnkFlt - ok
10:21:54.0125 2720 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:21:54.0140 2720 NwlnkFwd - ok
10:21:54.0156 2720 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
10:21:54.0156 2720 ohci1394 - ok
10:21:54.0218 2720 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
10:21:54.0218 2720 Parport - ok
10:21:54.0312 2720 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
10:21:54.0312 2720 PartMgr - ok
10:21:54.0359 2720 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
10:21:54.0359 2720 ParVdm - ok
10:21:54.0421 2720 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
10:21:54.0437 2720 PCI - ok
10:21:54.0453 2720 PCIDump - ok
10:21:54.0500 2720 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:21:54.0500 2720 PCIIde - ok
10:21:54.0531 2720 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
10:21:54.0531 2720 Pcmcia - ok
10:21:54.0546 2720 PDCOMP - ok
10:21:54.0578 2720 PDFRAME - ok
10:21:54.0593 2720 PDRELI - ok
10:21:54.0625 2720 PDRFRAME - ok
10:21:54.0640 2720 perc2 - ok
10:21:54.0671 2720 perc2hib - ok
10:21:54.0765 2720 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:21:54.0765 2720 PptpMiniport - ok
10:21:54.0796 2720 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
10:21:54.0796 2720 Processor - ok
10:21:54.0812 2720 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
10:21:54.0828 2720 PSched - ok
10:21:54.0859 2720 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:21:54.0859 2720 Ptilink - ok
10:21:54.0875 2720 ql1080 - ok
10:21:54.0906 2720 Ql10wnt - ok
10:21:54.0921 2720 ql12160 - ok
10:21:54.0953 2720 ql1240 - ok
10:21:54.0968 2720 ql1280 - ok
10:21:55.0015 2720 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:21:55.0015 2720 RasAcd - ok
10:21:55.0046 2720 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:21:55.0062 2720 Rasl2tp - ok
10:21:55.0093 2720 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:21:55.0093 2720 RasPppoe - ok
10:21:55.0109 2720 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:21:55.0125 2720 Raspti - ok
10:21:55.0156 2720 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:21:55.0156 2720 Rdbss - ok
10:21:55.0187 2720 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:21:55.0187 2720 RDPCDD - ok
10:21:55.0265 2720 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
10:21:55.0281 2720 RDPWD - ok
10:21:55.0328 2720 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:21:55.0343 2720 redbook - ok
10:21:55.0421 2720 RTL8023xp (7f0413bdd7d53eb4c7a371e7f6f84df1) C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
10:21:55.0437 2720 RTL8023xp - ok
10:21:55.0484 2720 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
10:21:55.0484 2720 rtl8139 - ok
10:21:55.0625 2720 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
10:21:55.0625 2720 sdbus - ok
10:21:55.0765 2720 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:21:55.0765 2720 Secdrv - ok
10:21:55.0859 2720 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
10:21:55.0859 2720 Serial - ok
10:21:55.0937 2720 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:21:55.0937 2720 Sfloppy - ok
10:21:55.0984 2720 Simbad - ok
10:21:56.0031 2720 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
10:21:56.0046 2720 SONYPVU1 - ok
10:21:56.0062 2720 Sparrow - ok
10:21:56.0109 2720 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
10:21:56.0109 2720 splitter - ok
10:21:56.0140 2720 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
10:21:56.0140 2720 sr - ok
10:21:56.0265 2720 SRTSP (83726cf02eced69138948083e06b6eac) C:\WINDOWS\System32\Drivers\N360\0501000.01D\SRTSP.SYS
10:21:56.0281 2720 SRTSP - ok
10:21:56.0390 2720 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSPX.SYS
10:21:56.0406 2720 SRTSPX - ok
10:21:56.0531 2720 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
10:21:56.0546 2720 Srv - ok
10:21:56.0609 2720 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
10:21:56.0609 2720 StillCam - ok
10:21:56.0671 2720 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:21:56.0687 2720 swenum - ok
10:21:56.0703 2720 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
10:21:56.0718 2720 swmidi - ok
10:21:56.0750 2720 symc810 - ok
10:21:56.0781 2720 symc8xx - ok
10:21:56.0828 2720 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMDS.SYS
10:21:56.0859 2720 SymDS - ok
10:21:56.0921 2720 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMEFA.SYS
10:21:56.0968 2720 SymEFA - ok
10:21:57.0031 2720 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
10:21:57.0046 2720 SymEvent - ok
10:21:57.0203 2720 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\WINDOWS\system32\drivers\N360\0501000.01D\Ironx86.SYS
10:21:57.0218 2720 SymIRON - ok
10:21:57.0343 2720 SYMTDI (dec35ccaf7a222df918306cd2fdfbd39) C:\WINDOWS\System32\Drivers\N360\0501000.01D\SYMTDI.SYS
10:21:57.0375 2720 SYMTDI - ok
10:21:57.0390 2720 sym_hi - ok
10:21:57.0406 2720 sym_u3 - ok
10:21:57.0468 2720 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
10:21:57.0468 2720 sysaudio - ok
10:21:57.0578 2720 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:21:57.0593 2720 Tcpip - ok
10:21:57.0656 2720 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:21:57.0656 2720 TDPIPE - ok
10:21:57.0828 2720 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
10:21:57.0828 2720 TDTCP - ok
10:21:57.0937 2720 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:21:57.0937 2720 TermDD - ok
10:21:58.0031 2720 tifm21 (a900f20ac0ed38223fbb87d2884cafb9) C:\WINDOWS\system32\drivers\tifm21.sys
10:21:58.0031 2720 tifm21 - ok
10:21:58.0046 2720 TosIde - ok
10:21:58.0125 2720 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
10:21:58.0125 2720 Udfs - ok
10:21:58.0140 2720 ultra - ok
10:21:58.0203 2720 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
10:21:58.0234 2720 Update - ok
10:21:58.0312 2720 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:21:58.0312 2720 usbccgp - ok
10:21:58.0359 2720 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:21:58.0359 2720 usbehci - ok
10:21:58.0390 2720 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:21:58.0390 2720 usbhub - ok
10:21:58.0421 2720 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
10:21:58.0421 2720 usbohci - ok
10:21:58.0468 2720 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:21:58.0468 2720 usbprint - ok
10:21:58.0531 2720 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:21:58.0546 2720 USBSTOR - ok
10:21:58.0656 2720 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
10:21:58.0656 2720 VgaSave - ok
10:21:58.0734 2720 ViaIde - ok
10:21:58.0781 2720 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
10:21:58.0781 2720 VolSnap - ok
10:21:58.0859 2720 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:21:58.0875 2720 Wanarp - ok
10:21:58.0890 2720 WDICA - ok
10:21:58.0937 2720 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
10:21:58.0937 2720 wdmaud - ok
10:21:59.0062 2720 winachsf (473ee64c368ce2eed110376c11960259) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
10:21:59.0093 2720 winachsf - ok
10:21:59.0156 2720 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
10:21:59.0171 2720 WmiAcpi - ok
10:21:59.0250 2720 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:21:59.0265 2720 WudfPf - ok
10:21:59.0312 2720 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:21:59.0312 2720 WudfRd - ok
10:21:59.0406 2720 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
10:21:59.0546 2720 \Device\Harddisk0\DR0 - ok
10:21:59.0562 2720 Boot (0x1200) (2feb8264d130c5ec17a03d73e58d06bb) \Device\Harddisk0\DR0\Partition0
10:21:59.0562 2720 \Device\Harddisk0\DR0\Partition0 - ok
10:21:59.0562 2720 ============================================================
10:21:59.0562 2720 Scan finished
10:21:59.0562 2720 ============================================================
10:21:59.0578 2424 Detected object count: 1
10:21:59.0578 2424 Actual detected object count: 1
10:22:21.0375 2424 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\ipsec.sys) error 1813
10:22:23.0890 2424 Backup copy found, using it..
10:22:24.0156 2424 C:\WINDOWS\system32\DRIVERS\ipsec.sys - will be cured on reboot
10:22:28.0593 2424 IPSec ( Virus.Win32.ZAccess.k ) - User select action: Cure
10:22:38.0093 3196 Deinitialize success

—————————————————————————————————————————-
ComboFix Log: Attached

Attachments:

Hi Malman

Thanks for the logs.

It appears that what we have done so far may have done the trick but we need to have a good look as that infection is a nasty one.

Please run DDS again and send a new log.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Can you tell me if you are noticing any problems.

Satchfan
Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\MpKsl0165c987.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{77a32496-0b2a-4014-bde6-2df4cd019e13}\mpksl021bb863.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\mpksl033bd8ab.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2cd6bb9-5cfd-48f2-aa45-48b905306c0d}\MpKsl0b4438d9.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\mpksl13d1a466.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{16525893-536f-4834-b844-353bdace8349}\mpksl157e641f.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{03895831-0ae6-45f0-80db-a399a63b06cf}\mpksl17161570.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32346412-f188-42ec-8944-c97b8a2c874a}\mpksl1950c7df.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7d9e246-62e6-4893-94cf-c11649be4232}\mpksl226aef29.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae6f129f-62e5-4e44-b91b-58b4d7ae314a}\mpksl28f70872.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{57ae026a-e759-40c7-bda5-d011a7149e6e}\mpksl2bda934d.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{777d79f4-f03c-44f7-bbec-83d084a0b6f0}\mpksl35207537.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fd726855-33dd-4ef8-89e4-3ffdaf1f9081}\mpksl37a92c79.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1ffb8a3e-6c29-4e05-a4fd-2878549e6069}\mpksl394cf1c2.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ee4cc8eb-25a6-4ed8-bc86-02410c4e9b2c}\mpksl3c6e1a91.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{91e8ac3d-d7e3-4dd2-bfd2-18092fc72590}\mpksl3ce485fd.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\mpksl401ff5cd.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e20d9f1c-1917-4fc0-b59b-b4b80b70da67}\mpksl4b1580f8.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{35c7dd68-846f-42d3-89d5-3f43c23d9430}\mpksl5c58b1ea.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1093d047-ac9c-4532-9abf-2555330fa66b}\mpksl5fc99565.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7012d965-adcd-4b1d-a3ef-b25735f3b993}\mpksl616a72b0.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6329dec0-dcad-493d-8294-ed0317854439}\mpksl61c17592.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1878baf8-b19c-4b1f-8c01-4a98cef44267}\mpksl67523628.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bca08176-d89a-4c83-b338-f33dadd4083d}\mpksl6c8e42ae.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9c890a03-2b8c-4ee2-bab0-c9e9a250fd5e}\mpksl7048e524.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{91e8ac3d-d7e3-4dd2-bfd2-18092fc72590}\mpksl729fe3b7.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{03895831-0ae6-45f0-80db-a399a63b06cf}\mpksl73da1d00.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\mpksl7a77928f.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d7b68afe-b8ad-4746-b3f4-cc47079b242b}\mpksl7bec6f07.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d973dad8-4b88-4fce-9975-208dcf48b1ca}\mpksl7c0c970e.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e5f05a91-205a-42c0-82d7-18cddcd27fc8}\mpksl7ff7cc8d.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d988e92a-8bcc-43cb-9afa-193b59a2c839}\mpksl813b1a8c.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f0bb2bda-087e-4fd1-9b2f-38db524af509}\mpksl8254ed7c.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4c4d8ce5-d735-43de-b287-2100265ac48e}\mpksl8ba93a74.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7021e90b-6a01-4384-842f-6aedc2e952b1}\mpksl9e2cfa34.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8bf06d28-7156-4383-b03b-eb6688541e37}\mpksla0316214.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{47c2eaec-2578-41c9-a28b-53df418d155c}\mpksla95a9b33.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d1985527-4379-484b-8b7e-d074a37d3c41}\mpkslae2a1a94.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d910bfe7-5608-4825-9341-b58a0d0af5fe}\mpkslb09a7a24.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0992907f-8f55-4d9e-a581-ba92497867d5}\mpkslb9145fcc.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4717f30d-6fd0-4f01-8efd-c655493447e0}\mpkslbdbdeb31.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fd726855-33dd-4ef8-89e4-3ffdaf1f9081}\mpkslc0d08019.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7a2dd85-5b60-461b-8758-401848273ddc}\mpkslc2a666a9.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fe38e2f3-3337-431e-b8c2-e501c38c5d91}\mpkslc449459c.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1093d047-ac9c-4532-9abf-2555330fa66b}\mpkslc48c99d5.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{47c2eaec-2578-41c9-a28b-53df418d155c}\mpksld9bd6b7f.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0bfe6824-b876-42cf-b5c1-7b19aa4389a7}\mpksle8dcf7dd.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{71137be7-c74b-411d-9ace-493ee0ffe569}\mpkslee655182.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2279de4c-faff-4ad6-90c4-9a8e4f8501df}\mpkslef24c03f.sys
c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ccea5db8-8d8f-4d94-9a4d-b18a72364708}\mpkslffc88a78.sys

Driver::
MpKsl0165c987
MpKsl021bb863
MpKsl033bd8ab
MpKsl0b4438d9
MpKsl13d1a466
MpKsl157e641f
MpKsl17161570
MpKsl1950c7df
MpKsl226aef29
MpKsl28f70872
MpKsl2bda934d
MpKsl35207537
MpKsl37a92c79
MpKsl394cf1c2
MpKsl3c6e1a91
MpKsl3ce485fd
MpKsl401ff5cd
MpKsl4b1580f8
MpKsl5c58b1ea
MpKsl5fc99565
MpKsl616a72b0
MpKsl61c17592
MpKsl67523628
MpKsl6c8e42ae
MpKsl7048e524
MpKsl729fe3b7
MpKsl73da1d00
MpKsl7a77928f
MpKsl7bec6f07
MpKsl7c0c970e
MpKsl7ff7cc8d
MpKsl813b1a8c
MpKsl8254ed7c
MpKsl8ba93a74
MpKsl9e2cfa34
MpKsla0316214
MpKsla95a9b33
MpKslae2a1a94
MpKslb09a7a24
MpKslb9145fcc
MpKslbdbdeb31
MpKslc0d08019
MpKslc2a666a9
MpKslc449459c
MpKslc48c99d5
MpKsld9bd6b7f
MpKsle8dcf7dd
MpKslee655182
MpKslef24c03f
MpKslffc88a78

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

========================================

Could you also run TDSSKiller again and include the log.


Please copy and paste the logs, not attach them.

Logs to include:

ComboFix.txt
TDSSKiller log


Thanks

Satchfan
It has been several days since I posted instructions to help with your computer problem. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI