This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Security 2012 Infection [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My system appears to be infected by XP Security 2012 that is posing as Windows Security. Behavior is erratic. It attempts to open IE and go to addresses with fishy URLs. Below is the copy of DDS.txt. The instructions said to zip and attach the attach.txt, so it is attached. Thanks in advance for your help. My daughter will be excited to be able to use her computer again as she begins to explore colleges for the future. Harold. . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14 Run by [removed] at 11:45:24 on 2012-02-26 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.516 [GMT -8:00] . AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\S24EvMon.exe svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ZCfgSvc.exe svchost.exe C:\Program Files\Application Updater\ApplicationUpdater.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\FsUsbExService.Exe C:\Program Files\Java\jre6\bin\jqs.exe C:\server\mysql\bin\mysqld.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\RegSrvc.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\Temp\_ex-68.exe C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe C:\Program Files\AIM\aim.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\1XConfig.exe C:\WINDOWS\system32\wuauclt.exe \\.\globalroot\SystemRoot\system32\svchost.exe -k netsvcs C:\WINDOWS\System32\ping.exe . ============== Pseudo HJT Report =============== . uURLSearchHooks: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\5.0\pdfforgeToolbarIE.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll BHO: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\5.0\pdfforgeToolbarIE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\5.0\pdfforgeToolbarIE.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [PRONoMgr.exe] c:\program files\intel\prosetwireless\ncs\proset\PRONoMgr.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [MozillaAgent] c:\windows\temp\_ex-68.exe mRun: [] mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe" dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9f.exe IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll LSP: mswsock.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228361578657 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{40607D75-274A-4EEC-BACD-1D9C89442FE7} : DhcpNameServer = 192.168.1.254 Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: Sebring - c:\windows\system32\LgNotify.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=20101206013308788&tb_oid=06-12-2010&tb_mrud=06-12-2010 FF - prefs.js: browser.startup.homepage - hxxp://kids.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p= FF - component: c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\components\MailUtil.dll FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll . —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false FF - user.js: browser.sessionstore.resume_from_crash - false FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false ============= SERVICES / DRIVERS =============== . R? Apache2.2;Apache2.2 R? McComponentHostService;McAfee Security Scan Component Host Service R? SavRoam;SavRoam R? Symantec AntiVirus;Symantec AntiVirus S? Application Updater;Application Updater S? ccEvtMgr;Symantec Event Manager S? ccSetMgr;Symantec Settings Manager S? EraserUtilRebootDrv;EraserUtilRebootDrv S? FsUsbExDisk;FsUsbExDisk S? FsUsbExService;FsUsbExService S? GTICARD;GTICARD S? NAVENG;NAVENG S? NAVEX15;NAVEX15 S? NPF;WinPcap Packet Driver (NPF) S? SAVRT;SAVRT S? SAVRTPEL;SAVRTPEL . =============== File Associations =============== . .exe=XPk . =============== Created Last 30 ================ . 2012-02-26 19:07:00 0 –sha-w- c:\windows\system32\dds_trash_log.cmd 2012-02-26 19:01:02 83968 —-a-w- c:\windows\system32\TnMaA74.exe 2012-02-26 18:58:24 51712 —-a-w- c:\windows\system32\TnMaA74.com 2012-02-26 18:55:14 ——– d—–w- c:\documents and settings\harold\application data\Search Settings 2012-02-26 18:55:05 ——– d—–w- c:\program files\pdfforge Toolbar 2012-02-26 18:55:05 ——– d—–w- c:\program files\common files\Spigot 2012-02-26 18:55:05 ——– d—–w- c:\program files\Application Updater 2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\tkn.exe 2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\jpi.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\xfd.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\orj.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\htk.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\edc.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\deb.exe 2012-02-26 18:49:27 316416 —-a-w- c:\documents and settings\harold\local settings\application data\ubx.exe . ==================== Find3M ==================== . 2012-02-26 18:59:43 83968 —-a-w- c:\windows\system32\TnMaA74.exe_ 2011-12-16 12:47:59 50704 —-a-w- c:\windows\system32\drivers\npf.sys 2011-12-16 12:47:57 281104 —-a-w- c:\windows\system32\wpcap.dll 2011-12-16 12:47:55 100880 —-a-w- c:\windows\system32\Packet.dll . ============= FINISH: 11:54:18.20 ===============

Attachments:

Hello Clairedog

:welcome:

I'm Mithros, I'll be glad to help you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:
  • Malware logs are often lengthy and can take alot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions
  • Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")


IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello Clairedog and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

Please accept our apologies for the delay in response. I will be helping you with your system issues.

This machine is terribly infected. Besides the rogue security program I also see evidence of the Zero Access Rootkit.

If you use this machine for any kind of financial transactions, please go to an uninfected machine and change all of your passwords as soon as you can. It would also be very wise to back up all of your important data at this point.



Can you tell me if this is a business machine, and if there is any particular reason why you have not yet updated to XP SP3?

Before we begin any fixing I would like to see the logs that are generated from the following scans:


  • aswMBR


    • Download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.
    • When asked if you want to download Avast's virus definitions please select Yes.
    • Click the "Scan" button to start scan.

    [external image: Posted Image]

    • On completion of the scan click save log, save it to your desktop and post in your next reply.

    [external image: Posted Image]

  • MGADiag


    • Please download MGADiag by clicking here and save it to your desktop.
    • Double click the [external image: Posted Image] icon on your desktop.
    • Push [external image: Posted Image]
    • Push [external image: Posted Image]
    • Go to Start -> Run and type in "Notepad"
    • Go to Edit -> Paste in notepad.
    • "x" out all of the numbers and letters in the line beginning with "Windows Product Key:"
    • Copy and paste that log here.

    Please post the aswMBR log and the MGADiag log in your next reply.
Hi: Thank you. I will run both of these when I get home from work this afternoon. This is a backup computer that is not used for financial transactions. It is running SP2 simply b/c it came out of active use and wasn't updated. More recently my daughter has been using it for school. I will try to post again this evening. Thanks. Have a good day.
Here you go. Have a great day. Harold aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software Run date: 2012-02-29 20:00:55 —————————– 20:00:55.112 OS Version: Windows 5.1.2600 Service Pack 2 20:00:55.122 Number of processors: 1 586 0xD06 20:00:55.122 ComputerName: HG-LATITUDE UserName: Harold 20:00:56.364 Initialize success 20:01:01.091 AVAST engine download error: 0 20:09:44.514 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 20:09:44.514 Disk 0 Vendor: Hitachi_HTS721010G9AT00 MCZOA53A Size: 95396MB BusType: 3 20:09:44.524 Disk 0 MBR read successfully 20:09:44.524 Disk 0 MBR scan 20:09:44.524 Disk 0 TDL4@MBR code has been found 20:09:44.524 Disk 0 Windows XP default MBR code found via API 20:09:44.524 Disk 0 MBR hidden 20:09:44.524 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 95393 MB offset 63 20:09:44.524 Disk 0 MBR [TDL4] **ROOTKIT** 20:09:44.524 Disk 0 trace - called modules: 20:09:44.534 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8682cf10]<< 20:09:44.534 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8739fab8] 20:09:44.534 3 CLASSPNP.SYS[f761005b] -> nt!IofCallDriver -> [0x86993248] 20:09:44.874 \Driver\00001111[0x8640af10] -> IRP_MJ_CREATE -> 0x8682cf10 20:09:44.874 Scan finished successfully 20:10:26.864 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Harold\Desktop\MBR.dat" 20:10:26.864 The log file has been saved successfully to "C:\Documents and Settings\Harold\Desktop\aswMBR.txt" Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Status: Genuine Validation Code: 0 Cached Validation Code: N/A Windows Product Key: *xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Windows Product Key Hash: 3g4CZGFEDgbKmn/oB4pa2FZsssU= Windows Product ID: 76487-OEM-2211906-00102 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010100.2.0.pro ID: {D627DB95-F288-4757-AF2A-51D736C17FAA}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: Registered, 1.9.40.0 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A Version: N/A Windows XP Notifications Data–> Cached Result: 0 File Exists: Yes Version: 1.9.40.0 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 100 Genuine Microsoft Office Professional Edition 2003 - 100 Genuine OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-2_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32) Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {D627DB95-F288-4757-AF2A-51D736C17FAA}1.9.0027.05.1.2600.2.00010100.2.0.prox32*****-*****-*****-*****-YD4YT76487-OEM-2211906-001022S-1-5-21-1078081533-1078145449-1343024091Dell Computer CorporationLatitude D800 Dell Computer CorporationA1320050630000000.000000+000Dell System,Dell Computer,Dell System,Dell System15923B07018400E204090409Pacific Standard Time(GMT-08:00)03100 Licensing Data–> N/A Windows Activation Technologies–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: 18FAD:Dell Inc|18FAD:Microsoft Corporation Marker string from OEMBIOS.DAT: Dell System,Dell Computer,Dell System,Dell System OEM Activation 2.0 Data–> N/A
Hello Clairedog

Thank you for the logs.

It is running SP2 simply b/c it came out of active use and wasn't updated

Please do not update the machine at this time (I will tell you when it is safe to do so).

Since the system is without SP3, please keep internet use to an absolute minimum while we work together (this will help to reduce the chance of picking up additional malware).


There are several things that need our attention here.

When you ran aswMBR, a file called MBR.dat was placed on your desktop (full path to file is C:\Documents and Settings\Harold\Desktop\MBR.dat).

Please attach the MBR.dat file and post it in your next reply.


I would also like to see a log from the following tool. If any malicious items are identified you will be given the option to cure them. At this time, please select skip rather than cure so I can review the log before we proceed.


  • TDSS Killer


  • Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and double click on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, please select Skip
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Please post the TDSSKiller log in your next reply.
21:43:27.0405 0756 TDSS rootkit removing tool [removed] Feb 29 2012 14:02:24 21:43:29.0428 0756 ============================================================ 21:43:29.0428 0756 Current date / time: 2012/03/01 21:43:29.0428 21:43:29.0428 0756 SystemInfo: 21:43:29.0428 0756 21:43:29.0428 0756 OS Version: 5.1.2600 ServicePack: 2.0 21:43:29.0428 0756 Product type: Workstation 21:43:29.0428 0756 ComputerName: HG-LATITUDE 21:43:29.0428 0756 UserName: Harold 21:43:29.0428 0756 Windows directory: C:\WINDOWS 21:43:29.0428 0756 System windows directory: C:\WINDOWS 21:43:29.0428 0756 Processor architecture: Intel x86 21:43:29.0428 0756 Number of processors: 1 21:43:29.0428 0756 Page size: 0x1000 21:43:29.0428 0756 Boot type: Normal boot 21:43:29.0428 0756 ============================================================ 21:43:33.0905 0756 Drive \Device\Harddisk0\DR0 - Size: 0x174A446000 (93.16 Gb), SectorSize: 0x200, Cylinders: 0x2F81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 21:43:33.0925 0756 \Device\Harddisk0\DR0: 21:43:33.0925 0756 MBR used 21:43:33.0925 0756 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xBA50E02 21:43:34.0285 0756 Initialize success 21:43:34.0285 0756 ============================================================ 21:43:39.0513 4232 ============================================================ 21:43:39.0513 4232 Scan started 21:43:39.0513 4232 Mode: Manual; 21:43:39.0513 4232 ============================================================ 21:43:42.0467 4232 Abiosdsk - ok 21:43:42.0477 4232 abp480n5 - ok 21:43:42.0517 4232 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 21:43:42.0527 4232 ACPI - ok 21:43:42.0557 4232 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 21:43:42.0577 4232 ACPIEC - ok 21:43:42.0597 4232 adpu160m - ok 21:43:42.0637 4232 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 21:43:42.0647 4232 aec - ok 21:43:42.0697 4232 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 21:43:42.0697 4232 AFD - ok 21:43:42.0767 4232 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys 21:43:42.0787 4232 agp440 - ok 21:43:42.0808 4232 Aha154x - ok 21:43:42.0818 4232 aic78u2 - ok 21:43:42.0838 4232 aic78xx - ok 21:43:42.0868 4232 AliIde - ok 21:43:42.0878 4232 amsint - ok 21:43:42.0928 4232 ApfiltrService (2aa99fd81693729da66e38dbc108a704) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 21:43:42.0968 4232 ApfiltrService - ok 21:43:43.0018 4232 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 21:43:43.0028 4232 Arp1394 - ok 21:43:43.0068 4232 asc - ok 21:43:43.0088 4232 asc3350p - ok 21:43:43.0108 4232 asc3550 - ok 21:43:43.0148 4232 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 21:43:43.0158 4232 AsyncMac - ok 21:43:43.0198 4232 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 21:43:43.0198 4232 atapi - ok 21:43:43.0218 4232 Atdisk - ok 21:43:43.0238 4232 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 21:43:43.0268 4232 Atmarpc - ok 21:43:43.0308 4232 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 21:43:43.0318 4232 audstub - ok 21:43:43.0388 4232 b57w2k (b9543b0c771feab7ca095303007a159c) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 21:43:43.0408 4232 b57w2k - ok 21:43:43.0438 4232 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 21:43:43.0448 4232 Beep - ok 21:43:43.0478 4232 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 21:43:43.0489 4232 cbidf2k - ok 21:43:43.0519 4232 cd20xrnt - ok 21:43:43.0539 4232 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 21:43:43.0539 4232 Cdaudio - ok 21:43:43.0559 4232 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 21:43:43.0559 4232 Cdfs - ok 21:43:43.0599 4232 Cdr4_xp (837eef65af62d4e8a37c41d3879f7274) C:\WINDOWS\system32\drivers\Cdr4_xp.sys 21:43:43.0599 4232 Cdr4_xp - ok 21:43:43.0649 4232 Cdralw2k (579da2f9f5401f55dae2cf8779d61dfc) C:\WINDOWS\system32\drivers\Cdralw2k.sys 21:43:43.0649 4232 Cdralw2k - ok 21:43:43.0679 4232 Cdrom (066caf1fc1dfbf468a7610d77b7e0f01) C:\WINDOWS\system32\DRIVERS\cdrom.sys 21:43:43.0729 4232 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\cdrom.sys. Real md5: 066caf1fc1dfbf468a7610d77b7e0f01, Fake md5: e9c58e930283d5b8f1b1772698e8c99b 21:43:43.0729 4232 Cdrom ( Virus.Win32.ZAccess.k ) - infected 21:43:43.0729 4232 Cdrom - detected Virus.Win32.ZAccess.k (0) 21:43:43.0779 4232 cdudf_xp (cfd81f2140193fc7f1812e6d6eaf6795) C:\WINDOWS\system32\drivers\cdudf_xp.sys 21:43:43.0789 4232 cdudf_xp - ok 21:43:43.0829 4232 Changer - ok 21:43:43.0889 4232 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 21:43:43.0909 4232 CmBatt - ok 21:43:43.0929 4232 CmdIde - ok 21:43:43.0949 4232 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys 21:43:43.0959 4232 Compbatt - ok 21:43:43.0979 4232 Cpqarray - ok 21:43:43.0999 4232 dac2w2k - ok 21:43:44.0019 4232 dac960nt - ok 21:43:44.0049 4232 DevUpper (913938a5382bfb2487aacaea408a14d2) C:\WINDOWS\system32\DRIVERS\tiumflt.sys 21:43:44.0059 4232 DevUpper - ok 21:43:44.0159 4232 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 21:43:44.0169 4232 Disk - ok 21:43:44.0240 4232 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 21:43:44.0280 4232 dmboot - ok 21:43:44.0340 4232 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 21:43:44.0370 4232 dmio - ok 21:43:44.0410 4232 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 21:43:44.0420 4232 dmload - ok 21:43:44.0470 4232 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 21:43:44.0470 4232 DMusic - ok 21:43:44.0490 4232 dpti2o - ok 21:43:44.0510 4232 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 21:43:44.0510 4232 drmkaud - ok 21:43:44.0550 4232 dvd_2K (677829f7010768eeeed8d0083e510dab) C:\WINDOWS\system32\drivers\dvd_2K.sys 21:43:44.0580 4232 dvd_2K - ok 21:43:44.0670 4232 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 21:43:44.0680 4232 eeCtrl - ok 21:43:44.0700 4232 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 21:43:44.0700 4232 EraserUtilRebootDrv - ok 21:43:44.0790 4232 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 21:43:44.0850 4232 Fastfat - ok 21:43:44.0870 4232 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 21:43:44.0921 4232 Fdc - ok 21:43:45.0001 4232 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 21:43:45.0001 4232 Fips - ok 21:43:45.0021 4232 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 21:43:45.0051 4232 Flpydisk - ok 21:43:45.0101 4232 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 21:43:45.0151 4232 FltMgr - ok 21:43:45.0201 4232 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS 21:43:45.0211 4232 FsUsbExDisk - ok 21:43:45.0271 4232 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 21:43:45.0271 4232 Fs_Rec - ok 21:43:45.0291 4232 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 21:43:45.0321 4232 Ftdisk - ok 21:43:45.0361 4232 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 21:43:45.0381 4232 Gpc - ok 21:43:45.0411 4232 GTICARD (b14d8f5dedf7c495c7d3104d58e1d31c) C:\WINDOWS\system32\DRIVERS\gticard.sys 21:43:45.0421 4232 GTICARD - ok 21:43:45.0461 4232 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 21:43:45.0481 4232 HidUsb - ok 21:43:45.0531 4232 hpn - ok 21:43:45.0571 4232 HSFHWICH (140ba850417896b6b3322048de280368) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys 21:43:45.0612 4232 HSFHWICH - ok 21:43:45.0662 4232 HSF_DP (b2dfc168d6f7512faea085253c5a37ad) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 21:43:45.0702 4232 HSF_DP - ok 21:43:45.0742 4232 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 21:43:45.0752 4232 HTTP - ok 21:43:45.0802 4232 i2omgmt - ok 21:43:45.0812 4232 i2omp - ok 21:43:45.0852 4232 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 21:43:45.0872 4232 i8042prt - ok 21:43:45.0932 4232 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 21:43:45.0942 4232 Imapi - ok 21:43:45.0972 4232 ini910u - ok 21:43:46.0022 4232 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 21:43:46.0032 4232 IntelIde - ok 21:43:46.0072 4232 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 21:43:46.0072 4232 intelppm - ok 21:43:46.0132 4232 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 21:43:46.0142 4232 Ip6Fw - ok 21:43:46.0192 4232 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 21:43:46.0202 4232 IpFilterDriver - ok 21:43:46.0232 4232 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 21:43:46.0242 4232 IpInIp - ok 21:43:46.0273 4232 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 21:43:46.0283 4232 IpNat - ok 21:43:46.0313 4232 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 21:43:46.0323 4232 IPSec - ok 21:43:46.0353 4232 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 21:43:46.0363 4232 IRENUM - ok 21:43:46.0413 4232 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 21:43:46.0443 4232 isapnp - ok 21:43:46.0513 4232 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 21:43:46.0523 4232 Kbdclass - ok 21:43:46.0563 4232 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 21:43:46.0563 4232 kbdhid - ok 21:43:46.0593 4232 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 21:43:46.0593 4232 kmixer - ok 21:43:46.0643 4232 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 21:43:46.0663 4232 KSecDD - ok 21:43:46.0753 4232 lbrtfdc - ok 21:43:46.0813 4232 MDC8021X (0f528e44cdc78365be693ae723e3801c) C:\WINDOWS\system32\DRIVERS\mdc8021x.sys 21:43:46.0813 4232 MDC8021X - ok 21:43:46.0853 4232 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 21:43:46.0853 4232 mdmxsdk - ok 21:43:46.0903 4232 mmc_2K (9b90303a9c9405a6ce1466ff4aa20fdd) C:\WINDOWS\system32\drivers\mmc_2K.sys 21:43:46.0964 4232 mmc_2K - ok 21:43:47.0034 4232 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 21:43:47.0034 4232 mnmdd - ok 21:43:47.0074 4232 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 21:43:47.0074 4232 Modem - ok 21:43:47.0134 4232 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 21:43:47.0154 4232 Mouclass - ok 21:43:47.0204 4232 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 21:43:47.0214 4232 mouhid - ok 21:43:47.0284 4232 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 21:43:47.0294 4232 MountMgr - ok 21:43:47.0314 4232 mraid35x - ok 21:43:47.0334 4232 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 21:43:47.0344 4232 MRxDAV - ok 21:43:47.0384 4232 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 21:43:47.0394 4232 MRxSmb - ok 21:43:47.0424 4232 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 21:43:47.0424 4232 Msfs - ok 21:43:47.0484 4232 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 21:43:47.0494 4232 MSKSSRV - ok 21:43:47.0574 4232 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 21:43:47.0584 4232 MSPCLOCK - ok 21:43:47.0604 4232 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 21:43:47.0614 4232 MSPQM - ok 21:43:47.0644 4232 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 21:43:47.0644 4232 mssmbios - ok 21:43:47.0695 4232 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 21:43:47.0845 4232 Mup - ok 21:43:47.0955 4232 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111214.001\naveng.sys 21:43:47.0965 4232 NAVENG - ok 21:43:48.0055 4232 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111214.001\navex15.sys 21:43:48.0095 4232 NAVEX15 - ok 21:43:48.0175 4232 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 21:43:48.0205 4232 NDIS - ok 21:43:48.0245 4232 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 21:43:48.0255 4232 NdisTapi - ok 21:43:48.0295 4232 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 21:43:48.0295 4232 Ndisuio - ok 21:43:48.0315 4232 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 21:43:48.0446 4232 NdisWan - ok 21:43:48.0526 4232 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 21:43:48.0536 4232 NDProxy - ok 21:43:48.0586 4232 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 21:43:48.0586 4232 NetBIOS - ok 21:43:48.0626 4232 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 21:43:48.0626 4232 NetBT - ok 21:43:48.0716 4232 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 21:43:48.0736 4232 NIC1394 - ok 21:43:48.0776 4232 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys 21:43:48.0776 4232 NPF - ok 21:43:48.0836 4232 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 21:43:48.0836 4232 Npfs - ok 21:43:48.0876 4232 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 21:43:48.0946 4232 Ntfs - ok 21:43:48.0996 4232 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 21:43:48.0996 4232 Null - ok 21:43:49.0137 4232 nv (9e4b052c76949de445ad6439cd473548) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 21:43:49.0227 4232 nv - ok 21:43:49.0307 4232 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 21:43:49.0317 4232 NwlnkFlt - ok 21:43:49.0357 4232 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 21:43:49.0367 4232 NwlnkFwd - ok 21:43:49.0427 4232 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 21:43:49.0427 4232 ohci1394 - ok 21:43:49.0457 4232 OMCI (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys 21:43:49.0477 4232 OMCI - ok 21:43:49.0547 4232 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 21:43:49.0577 4232 Parport - ok 21:43:49.0617 4232 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 21:43:49.0637 4232 PartMgr - ok 21:43:49.0667 4232 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 21:43:49.0667 4232 ParVdm - ok 21:43:49.0707 4232 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 21:43:49.0727 4232 pccsmcfd - ok 21:43:49.0768 4232 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 21:43:49.0788 4232 PCI - ok 21:43:49.0808 4232 PCIDump - ok 21:43:49.0828 4232 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 21:43:49.0848 4232 PCIIde - ok 21:43:49.0878 4232 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 21:43:49.0918 4232 Pcmcia - ok 21:43:49.0968 4232 PDCOMP - ok 21:43:49.0988 4232 PDFRAME - ok 21:43:50.0008 4232 PDRELI - ok 21:43:50.0028 4232 PDRFRAME - ok 21:43:50.0038 4232 perc2 - ok 21:43:50.0058 4232 perc2hib - ok 21:43:50.0128 4232 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 21:43:50.0148 4232 PptpMiniport - ok 21:43:50.0178 4232 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 21:43:50.0188 4232 PSched - ok 21:43:50.0208 4232 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 21:43:50.0248 4232 Ptilink - ok 21:43:50.0278 4232 pwd_2k (d8b90616a8bd53de281dbdb664c0984a) C:\WINDOWS\system32\drivers\pwd_2k.sys 21:43:50.0328 4232 pwd_2k - ok 21:43:50.0388 4232 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys 21:43:50.0619 4232 PxHelp20 - ok 21:43:51.0310 4232 ql1080 - ok 21:43:51.0330 4232 Ql10wnt - ok 21:43:51.0350 4232 ql12160 - ok 21:43:51.0370 4232 ql1240 - ok 21:43:51.0380 4232 ql1280 - ok 21:43:51.0420 4232 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 21:43:51.0420 4232 RasAcd - ok 21:43:51.0460 4232 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 21:43:51.0470 4232 Rasl2tp - ok 21:43:51.0500 4232 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 21:43:51.0510 4232 RasPppoe - ok 21:43:51.0530 4232 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 21:43:51.0550 4232 Raspti - ok 21:43:51.0580 4232 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys 21:43:51.0590 4232 Rdbss - ok 21:43:51.0610 4232 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 21:43:51.0610 4232 RDPCDD - ok 21:43:51.0660 4232 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 21:43:51.0690 4232 rdpdr - ok 21:43:51.0760 4232 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 21:43:51.0800 4232 RDPWD - ok 21:43:51.0841 4232 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 21:43:51.0861 4232 redbook - ok 21:43:51.0931 4232 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\WINDOWS\system32\Drivers\RimUsb.sys 21:43:51.0951 4232 RimUsb - ok 21:43:51.0991 4232 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 21:43:52.0021 4232 RimVSerPort - ok 21:43:52.0171 4232 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 21:43:52.0191 4232 ROOTMODEM - ok 21:43:52.0291 4232 s24trans (41cf7128424f3bdc35b05be3cc8ce7ec) C:\WINDOWS\system32\DRIVERS\s24trans.sys 21:43:52.0291 4232 s24trans - ok 21:43:52.0381 4232 SAVRT (cdb565c093b0105086cc630b32f9e6e6) C:\Program Files\Symantec AntiVirus\savrt.sys 21:43:52.0491 4232 SAVRT - ok 21:43:52.0511 4232 SAVRTPEL (1042cb5a003f9aed8d6cec56a0fc6c49) C:\Program Files\Symantec AntiVirus\Savrtpel.sys 21:43:52.0532 4232 SAVRTPEL - ok 21:43:52.0602 4232 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 21:43:52.0632 4232 Secdrv - ok 21:43:52.0672 4232 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 21:43:52.0682 4232 serenum - ok 21:43:52.0702 4232 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys 21:43:52.0712 4232 Serial - ok 21:43:52.0752 4232 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 21:43:52.0762 4232 Sfloppy - ok 21:43:52.0792 4232 Simbad - ok 21:43:52.0812 4232 Sparrow - ok 21:43:52.0902 4232 SPBBCDrv (cc22bf5631c4837abcd81d75de8fb1aa) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 21:43:52.0912 4232 SPBBCDrv - ok 21:43:52.0982 4232 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 21:43:52.0982 4232 splitter - ok 21:43:53.0032 4232 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 21:43:53.0062 4232 sr - ok 21:43:53.0112 4232 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 21:43:53.0122 4232 Srv - ok 21:43:53.0172 4232 STAC97 (ae4797a1fc117c1d28a4ed80be42f734) C:\WINDOWS\system32\drivers\stac97.sys 21:43:53.0223 4232 STAC97 - ok 21:43:53.0303 4232 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys 21:43:53.0313 4232 StillCam - ok 21:43:53.0363 4232 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 21:43:53.0373 4232 swenum - ok 21:43:53.0463 4232 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 21:43:53.0463 4232 swmidi - ok 21:43:53.0493 4232 symc810 - ok 21:43:53.0503 4232 symc8xx - ok 21:43:53.0603 4232 SymEvent (5156f63e684e8c864ff40e40d5309f41) C:\Program Files\Symantec\SYMEVENT.SYS 21:43:53.0653 4232 SymEvent - ok 21:43:53.0723 4232 SYMREDRV (5314e345dfc068504cfb2676d3b2ca39) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 21:43:54.0114 4232 SYMREDRV - ok 21:43:54.0234 4232 SYMTDI (8cd0a1478256240249b8ee88e6f25e94) C:\WINDOWS\System32\Drivers\SYMTDI.SYS 21:43:54.0264 4232 SYMTDI - ok 21:43:54.0324 4232 sym_hi - ok 21:43:54.0394 4232 sym_u3 - ok 21:43:54.0494 4232 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 21:43:54.0494 4232 sysaudio - ok 21:43:54.0554 4232 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 21:43:54.0564 4232 Tcpip - ok 21:43:54.0635 4232 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 21:43:54.0705 4232 TDPIPE - ok 21:43:54.0765 4232 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 21:43:54.0825 4232 TDTCP - ok 21:43:54.0885 4232 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 21:43:54.0955 4232 TermDD - ok 21:43:55.0055 4232 tiumfwl (a4c6f3e34358c94e5c3acfc3392f8907) C:\WINDOWS\system32\drivers\tiumfwl.sys 21:43:55.0265 4232 tiumfwl - ok 21:43:55.0336 4232 TosIde - ok 21:43:55.0396 4232 UdfReadr_xp (4e75005b74be901c30f2636df40b0c15) C:\WINDOWS\system32\drivers\UdfReadr_xp.sys 21:43:55.0406 4232 UdfReadr_xp - ok 21:43:55.0466 4232 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 21:43:55.0486 4232 Udfs - ok 21:43:55.0496 4232 UIUSys - ok 21:43:55.0516 4232 ultra - ok 21:43:55.0556 4232 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 21:43:55.0626 4232 Update - ok 21:43:55.0686 4232 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 21:43:55.0706 4232 usbccgp - ok 21:43:55.0746 4232 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 21:43:55.0756 4232 usbehci - ok 21:43:55.0796 4232 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 21:43:55.0826 4232 usbhub - ok 21:43:55.0876 4232 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 21:43:55.0876 4232 usbprint - ok 21:43:55.0936 4232 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 21:43:55.0976 4232 usbscan - ok 21:43:56.0027 4232 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 21:43:56.0057 4232 USBSTOR - ok 21:43:56.0117 4232 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 21:43:56.0217 4232 usbuhci - ok 21:43:56.0497 4232 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 21:43:56.0547 4232 VgaSave - ok 21:43:56.0617 4232 ViaIde - ok 21:43:56.0728 4232 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 21:43:56.0978 4232 VolSnap - ok 21:43:57.0108 4232 w22n51 (4fed83668f087ecbe810ea90beceb765) C:\WINDOWS\system32\DRIVERS\w22n51.sys 21:43:57.0158 4232 w22n51 - ok 21:43:57.0198 4232 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 21:43:57.0198 4232 Wanarp - ok 21:43:57.0238 4232 WDICA - ok 21:43:57.0278 4232 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 21:43:57.0278 4232 wdmaud - ok 21:43:57.0358 4232 winachsf (2dc7c0b6175a0a8ed84a4f70199c93b5) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 21:43:57.0399 4232 winachsf - ok 21:43:57.0609 4232 MBR (0x1B8) (6f9a1d528242bc09104b85e0becf5554) \Device\Harddisk0\DR0 21:43:57.0629 4232 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - infected 21:43:57.0629 4232 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.a (0) 21:43:57.0639 4232 Boot (0x1200) (b57b10d35f0c0a4ce2fa4f6298e87b7e) \Device\Harddisk0\DR0\Partition0 21:43:57.0639 4232 \Device\Harddisk0\DR0\Partition0 - ok 21:43:57.0649 4232 ============================================================ 21:43:57.0649 4232 Scan finished 21:43:57.0649 4232 ============================================================ 21:43:57.0669 4220 Detected object count: 2 21:43:57.0669 4220 Actual detected object count: 2 21:45:16.0943 4220 Cdrom ( Virus.Win32.ZAccess.k ) - skipped by user 21:45:16.0943 4220 Cdrom ( Virus.Win32.ZAccess.k ) - User select action: Skip 21:45:16.0943 4220 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - skipped by user 21:45:16.0943 4220 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - User select action: Skip
When I try to upload the MBR.DAT file I get an upload error that says that I am not permitted to upload this type of file? Any suggestions? Thanks
Hello Clairedog

Thank you for the log.

Lets see if we can get the file attached before we continue.

Please Right click on the file (MBR.dat) and select Send to > Compressed (zipped folder). The file will be placed in a zipped folder on your desktop. See if you can attach the zipped folder in your next reply :)
Hello Clairedog

Should have thought of that myself last night

No problem :)

Now that we have the MBR.dat attached we can continue:

Please run TDSSKiller as you did before, but this time, allow it to Cure any malicious items it detects.

Once you have saved the TDSSKiller log, follow with the following tool:


  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Please post the TDSSKiller log and the Combofix log in your next reply.
Hi: I thought that all antivirus was off; however when I ran combofix it indicated taht Symantec Corp Antivirus was still running. There was nothing in the system tray and no programs running. I looked at the processes to see if I could identify something to terminate but didn't know what to look for. I've attached a word doc with two screen shots of the processes running. Perhaps you can see something that you know is running as a part of SCA that I can terminate before running the Combo Fix. Thanks.
Hello Clairedog

however when I ran combofix it indicated taht Symantec Corp Antivirus was still running.

Did you try Right clicking on the Norton AntiVirus Corporate Edition icon located in your taskbar (bottom right hand corner of screen) and Unchecking "Enable Filesystem Realtime Protection"?

Give that a try then see if Combofix will run. If you are notified by Combofix that your AV is still running you may have to uninstall it (The Corporate Edition of Symantec AntiVirus is not commonly found on home computers so if you decide to uninstall it I will provide you with an alternative program later if you do not have the installation disk for Norton).

Let me know how you get on in your next reply :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI