My system appears to be infected by XP Security 2012 that is posing as Windows Security.
Behavior is erratic. It attempts to open IE and go to addresses with fishy URLs.
Below is the copy of DDS.txt. The instructions said to zip and attach the attach.txt, so it is attached.
Thanks in advance for your help. My daughter will be excited to be able to use her computer again as she begins to explore colleges for the future.
Harold.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
Run by [removed] at 11:45:24 on 2012-02-26
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.516 [GMT -8:00]
.
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
svchost.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\server\mysql\bin\mysqld.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Temp\_ex-68.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\system32\wuauclt.exe
\\.\globalroot\SystemRoot\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\ping.exe
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\5.0\pdfforgeToolbarIE.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\5.0\pdfforgeToolbarIE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\5.0\pdfforgeToolbarIE.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [PRONoMgr.exe] c:\program files\intel\prosetwireless\ncs\proset\PRONoMgr.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [MozillaAgent] c:\windows\temp\_ex-68.exe
mRun: []
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9f.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: mswsock.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228361578657
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{40607D75-274A-4EEC-BACD-1D9C89442FE7} : DhcpNameServer = 192.168.1.254
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: Sebring - c:\windows\system32\LgNotify.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=20101206013308788&tb_oid=06-12-2010&tb_mrud=06-12-2010
FF - prefs.js: browser.startup.homepage - hxxp://kids.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - component: c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\components\MailUtil.dll
FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============
.
R? Apache2.2;Apache2.2
R? McComponentHostService;McAfee Security Scan Component Host Service
R? SavRoam;SavRoam
R? Symantec AntiVirus;Symantec AntiVirus
S? Application Updater;Application Updater
S? ccEvtMgr;Symantec Event Manager
S? ccSetMgr;Symantec Settings Manager
S? EraserUtilRebootDrv;EraserUtilRebootDrv
S? FsUsbExDisk;FsUsbExDisk
S? FsUsbExService;FsUsbExService
S? GTICARD;GTICARD
S? NAVENG;NAVENG
S? NAVEX15;NAVEX15
S? NPF;WinPcap Packet Driver (NPF)
S? SAVRT;SAVRT
S? SAVRTPEL;SAVRTPEL
.
=============== File Associations ===============
.
.exe=XPk
.
=============== Created Last 30 ================
.
2012-02-26 19:07:00 0 –sha-w- c:\windows\system32\dds_trash_log.cmd
2012-02-26 19:01:02 83968 —-a-w- c:\windows\system32\TnMaA74.exe
2012-02-26 18:58:24 51712 —-a-w- c:\windows\system32\TnMaA74.com
2012-02-26 18:55:14 ——– d—–w- c:\documents and settings\harold\application data\Search Settings
2012-02-26 18:55:05 ——– d—–w- c:\program files\pdfforge Toolbar
2012-02-26 18:55:05 ——– d—–w- c:\program files\common files\Spigot
2012-02-26 18:55:05 ——– d—–w- c:\program files\Application Updater
2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\tkn.exe
2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\jpi.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\xfd.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\orj.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\htk.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\edc.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\deb.exe
2012-02-26 18:49:27 316416 —-a-w- c:\documents and settings\harold\local settings\application data\ubx.exe
.
==================== Find3M ====================
.
2012-02-26 18:59:43 83968 —-a-w- c:\windows\system32\TnMaA74.exe_
2011-12-16 12:47:59 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-16 12:47:57 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-12-16 12:47:55 100880 —-a-w- c:\windows\system32\Packet.dll
.
============= FINISH: 11:54:18.20 ===============
Hello
Clairedog
I'm
Mithros , I'll be glad to help you with your computer problems.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.
Please read the following guidelines which will help to make cleaning your machine easier:
Malware logs are often lengthy and can take alot of time to research and interpret. Please be patient while I review your logs.The fixes I will give you are specific to your problem and should only be used for this issue on this machine . Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask ! Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone. PLEASE DO NOT install/uninstall any programs unless asked to .PLEASE DO NOT run any malware scans other than those requested .Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed! I will reply back shortly with instructions
Note to Vista and Windows 7 users: These tools MUST be run from the executable. (.exe) every time you run them These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hi Mithros.
Thank you for the quick reply. Just knowing someone is looking at this is a start. I'll wait to hear from you.
Thanks.
Hello
Clairedog and
My name is
JonTom
Malware Logs can sometimes take a lot of time to research and interpret.
Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
Please accept our apologies for the delay in response. I will be helping you with your system issues.
This machine is terribly infected. Besides the rogue security program I also see evidence of the Zero Access Rootkit.
If you use this machine for any kind of financial transactions, please go to an uninfected machine and change all of your passwords as soon as you can. It would also be very wise to back up all of your important data at this point.
Can you tell me if this is a business machine, and if there is any particular reason why you have not yet updated to XP SP3?
Before we begin any fixing I would like to see the logs that are generated from the following scans:
aswMBR
Download aswMBR.exe to your desktop. Double click the aswMBR.exe to run it. When asked if you want to download Avast's virus definitions please select Yes . Click the "Scan" button to start scan.
[external image: Posted Image]
On completion of the scan click save log , save it to your desktop and post in your next reply.
[external image: Posted Image]
MGADiag
Please download MGADiag by clicking here and save it to your desktop. Double click the [external image: Posted Image] icon on your desktop. Push [external image: Posted Image] Push [external image: Posted Image] Go to Start -> Run and type in "Notepad" Go to Edit -> Paste in notepad. "x" out all of the numbers and letters in the line beginning with "Windows Product Key:" Copy and paste that log here.
Please post the aswMBR log and the MGADiag log in your next reply.
Hi:
Thank you. I will run both of these when I get home from work this afternoon. This is a backup computer that is not used for financial transactions. It is running SP2 simply b/c it came out of active use and wasn't updated. More recently my daughter has been using it for school.
I will try to post again this evening.
Thanks. Have a good day.
Hello
Clairedog
I will try to post again this evening
Thanks for letting me know
Here you go.
Have a great day.
Harold
aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-02-29 20:00:55
—————————–
20:00:55.112 OS Version: Windows 5.1.2600 Service Pack 2
20:00:55.122 Number of processors: 1 586 0xD06
20:00:55.122 ComputerName: HG-LATITUDE UserName: Harold
20:00:56.364 Initialize success
20:01:01.091 AVAST engine download error: 0
20:09:44.514 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
20:09:44.514 Disk 0 Vendor: Hitachi_HTS721010G9AT00 MCZOA53A Size: 95396MB BusType: 3
20:09:44.524 Disk 0 MBR read successfully
20:09:44.524 Disk 0 MBR scan
20:09:44.524 Disk 0 TDL4@MBR code has been found
20:09:44.524 Disk 0 Windows XP default MBR code found via API
20:09:44.524 Disk 0 MBR hidden
20:09:44.524 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 95393 MB offset 63
20:09:44.524 Disk 0 MBR [TDL4] **ROOTKIT**
20:09:44.524 Disk 0 trace - called modules:
20:09:44.534 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8682cf10]<<
20:09:44.534 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8739fab8]
20:09:44.534 3 CLASSPNP.SYS[f761005b] -> nt!IofCallDriver -> [0x86993248]
20:09:44.874 \Driver\00001111[0x8640af10] -> IRP_MJ_CREATE -> 0x8682cf10
20:09:44.874 Scan finished successfully
20:10:26.864 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Harold\Desktop\MBR.dat"
20:10:26.864 The log file has been saved successfully to "C:\Documents and Settings\Harold\Desktop\aswMBR.txt"
Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A
Windows Product Key: *xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Windows Product Key Hash: 3g4CZGFEDgbKmn/oB4pa2FZsssU=
Windows Product ID: 76487-OEM-2211906-00102
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010100.2.0.pro
ID: {D627DB95-F288-4757-AF2A-51D736C17FAA}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: Registered, 1.9.40.0
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A
Vista WgaER Data–>
ThreatID(s): N/A
Version: N/A
Windows XP Notifications Data–>
Cached Result: 0
File Exists: Yes
Version: 1.9.40.0
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft
OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data–>
Office Status: 100 Genuine
Microsoft Office Professional Edition 2003 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-2_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005
Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data–>
Other data–>
Office Details: {D627DB95-F288-4757-AF2A-51D736C17FAA}1.9.0027.05.1.2600.2.00010100.2.0.prox32*****-*****-*****-*****-YD4YT76487-OEM-2211906-001022S-1-5-21-1078081533-1078145449-1343024091Dell Computer CorporationLatitude D800 Dell Computer CorporationA1320050630000000.000000+000Dell System,Dell Computer,Dell System,Dell System15923B07018400E204090409Pacific Standard Time(GMT-08:00)03100
Licensing Data–>
N/A
Windows Activation Technologies–>
N/A
HWID Data–>
N/A
OEM Activation 1.0 Data–>
BIOS string matches: yes
Marker string from BIOS: 18FAD:Dell Inc|18FAD:Microsoft Corporation
Marker string from OEMBIOS.DAT: Dell System,Dell Computer,Dell System,Dell System
OEM Activation 2.0 Data–>
N/A
Hello
Clairedog
Thank you for the logs.
It is running SP2 simply b/c it came out of active use and wasn't updated
Please do not update the machine at this time (I will tell you when it is safe to do so).
Since the system is without SP3, please keep internet use to an absolute minimum while we work together (this will help to reduce the chance of picking up additional malware).
There are several things that need our attention here.
When you ran aswMBR, a file called
MBR.dat was placed on your desktop (full path to file is C:\Documents and Settings\Harold\Desktop\MBR.dat).
Please
attach the MBR.dat file and post it in your next reply.
I would also like to see a log from the following tool. If any malicious items are identified you will be given the option to cure them. At this time,
please select skip rather than cure so I can review the log before we proceed.
TDSS Killer
Please read carefully and follow these steps. Download TDSSKiller and save it to your Desktop. Extract its contents to your desktop. Once extracted, open the TDSSKiller folder and double click on TDSSKiller.exe to run the application, then on Start Scan. If an infected file is detected, the default action will be Cure , please select Skip If a suspicious file is detected, the default action will be Skip , click on Continue. It may ask you to reboot the computer to complete the process. Click on Reboot Now . If no reboot is required, click on Report . A log file should appear. Please copy and paste the contents of that file here. If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt ". Please copy and paste the contents of that file here.
Please post the TDSSKiller log in your next reply.
21:43:27.0405 0756 TDSS rootkit removing tool [removed] Feb 29 2012 14:02:24
21:43:29.0428 0756 ============================================================
21:43:29.0428 0756 Current date / time: 2012/03/01 21:43:29.0428
21:43:29.0428 0756 SystemInfo:
21:43:29.0428 0756
21:43:29.0428 0756 OS Version: 5.1.2600 ServicePack: 2.0
21:43:29.0428 0756 Product type: Workstation
21:43:29.0428 0756 ComputerName: HG-LATITUDE
21:43:29.0428 0756 UserName: Harold
21:43:29.0428 0756 Windows directory: C:\WINDOWS
21:43:29.0428 0756 System windows directory: C:\WINDOWS
21:43:29.0428 0756 Processor architecture: Intel x86
21:43:29.0428 0756 Number of processors: 1
21:43:29.0428 0756 Page size: 0x1000
21:43:29.0428 0756 Boot type: Normal boot
21:43:29.0428 0756 ============================================================
21:43:33.0905 0756 Drive \Device\Harddisk0\DR0 - Size: 0x174A446000 (93.16 Gb), SectorSize: 0x200, Cylinders: 0x2F81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:43:33.0925 0756 \Device\Harddisk0\DR0:
21:43:33.0925 0756 MBR used
21:43:33.0925 0756 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xBA50E02
21:43:34.0285 0756 Initialize success
21:43:34.0285 0756 ============================================================
21:43:39.0513 4232 ============================================================
21:43:39.0513 4232 Scan started
21:43:39.0513 4232 Mode: Manual;
21:43:39.0513 4232 ============================================================
21:43:42.0467 4232 Abiosdsk - ok
21:43:42.0477 4232 abp480n5 - ok
21:43:42.0517 4232 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:43:42.0527 4232 ACPI - ok
21:43:42.0557 4232 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
21:43:42.0577 4232 ACPIEC - ok
21:43:42.0597 4232 adpu160m - ok
21:43:42.0637 4232 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys
21:43:42.0647 4232 aec - ok
21:43:42.0697 4232 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
21:43:42.0697 4232 AFD - ok
21:43:42.0767 4232 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
21:43:42.0787 4232 agp440 - ok
21:43:42.0808 4232 Aha154x - ok
21:43:42.0818 4232 aic78u2 - ok
21:43:42.0838 4232 aic78xx - ok
21:43:42.0868 4232 AliIde - ok
21:43:42.0878 4232 amsint - ok
21:43:42.0928 4232 ApfiltrService (2aa99fd81693729da66e38dbc108a704) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
21:43:42.0968 4232 ApfiltrService - ok
21:43:43.0018 4232 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
21:43:43.0028 4232 Arp1394 - ok
21:43:43.0068 4232 asc - ok
21:43:43.0088 4232 asc3350p - ok
21:43:43.0108 4232 asc3550 - ok
21:43:43.0148 4232 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:43:43.0158 4232 AsyncMac - ok
21:43:43.0198 4232 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:43:43.0198 4232 atapi - ok
21:43:43.0218 4232 Atdisk - ok
21:43:43.0238 4232 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:43:43.0268 4232 Atmarpc - ok
21:43:43.0308 4232 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:43:43.0318 4232 audstub - ok
21:43:43.0388 4232 b57w2k (b9543b0c771feab7ca095303007a159c) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
21:43:43.0408 4232 b57w2k - ok
21:43:43.0438 4232 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:43:43.0448 4232 Beep - ok
21:43:43.0478 4232 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:43:43.0489 4232 cbidf2k - ok
21:43:43.0519 4232 cd20xrnt - ok
21:43:43.0539 4232 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:43:43.0539 4232 Cdaudio - ok
21:43:43.0559 4232 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
21:43:43.0559 4232 Cdfs - ok
21:43:43.0599 4232 Cdr4_xp (837eef65af62d4e8a37c41d3879f7274) C:\WINDOWS\system32\drivers\Cdr4_xp.sys
21:43:43.0599 4232 Cdr4_xp - ok
21:43:43.0649 4232 Cdralw2k (579da2f9f5401f55dae2cf8779d61dfc) C:\WINDOWS\system32\drivers\Cdralw2k.sys
21:43:43.0649 4232 Cdralw2k - ok
21:43:43.0679 4232 Cdrom (066caf1fc1dfbf468a7610d77b7e0f01) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:43:43.0729 4232 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\cdrom.sys. Real md5: 066caf1fc1dfbf468a7610d77b7e0f01, Fake md5: e9c58e930283d5b8f1b1772698e8c99b
21:43:43.0729 4232 Cdrom ( Virus.Win32.ZAccess.k ) - infected
21:43:43.0729 4232 Cdrom - detected Virus.Win32.ZAccess.k (0)
21:43:43.0779 4232 cdudf_xp (cfd81f2140193fc7f1812e6d6eaf6795) C:\WINDOWS\system32\drivers\cdudf_xp.sys
21:43:43.0789 4232 cdudf_xp - ok
21:43:43.0829 4232 Changer - ok
21:43:43.0889 4232 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
21:43:43.0909 4232 CmBatt - ok
21:43:43.0929 4232 CmdIde - ok
21:43:43.0949 4232 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
21:43:43.0959 4232 Compbatt - ok
21:43:43.0979 4232 Cpqarray - ok
21:43:43.0999 4232 dac2w2k - ok
21:43:44.0019 4232 dac960nt - ok
21:43:44.0049 4232 DevUpper (913938a5382bfb2487aacaea408a14d2) C:\WINDOWS\system32\DRIVERS\tiumflt.sys
21:43:44.0059 4232 DevUpper - ok
21:43:44.0159 4232 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
21:43:44.0169 4232 Disk - ok
21:43:44.0240 4232 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
21:43:44.0280 4232 dmboot - ok
21:43:44.0340 4232 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
21:43:44.0370 4232 dmio - ok
21:43:44.0410 4232 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:43:44.0420 4232 dmload - ok
21:43:44.0470 4232 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
21:43:44.0470 4232 DMusic - ok
21:43:44.0490 4232 dpti2o - ok
21:43:44.0510 4232 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
21:43:44.0510 4232 drmkaud - ok
21:43:44.0550 4232 dvd_2K (677829f7010768eeeed8d0083e510dab) C:\WINDOWS\system32\drivers\dvd_2K.sys
21:43:44.0580 4232 dvd_2K - ok
21:43:44.0670 4232 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:43:44.0680 4232 eeCtrl - ok
21:43:44.0700 4232 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:43:44.0700 4232 EraserUtilRebootDrv - ok
21:43:44.0790 4232 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
21:43:44.0850 4232 Fastfat - ok
21:43:44.0870 4232 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys
21:43:44.0921 4232 Fdc - ok
21:43:45.0001 4232 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
21:43:45.0001 4232 Fips - ok
21:43:45.0021 4232 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys
21:43:45.0051 4232 Flpydisk - ok
21:43:45.0101 4232 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
21:43:45.0151 4232 FltMgr - ok
21:43:45.0201 4232 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS
21:43:45.0211 4232 FsUsbExDisk - ok
21:43:45.0271 4232 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:43:45.0271 4232 Fs_Rec - ok
21:43:45.0291 4232 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:43:45.0321 4232 Ftdisk - ok
21:43:45.0361 4232 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:43:45.0381 4232 Gpc - ok
21:43:45.0411 4232 GTICARD (b14d8f5dedf7c495c7d3104d58e1d31c) C:\WINDOWS\system32\DRIVERS\gticard.sys
21:43:45.0421 4232 GTICARD - ok
21:43:45.0461 4232 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
21:43:45.0481 4232 HidUsb - ok
21:43:45.0531 4232 hpn - ok
21:43:45.0571 4232 HSFHWICH (140ba850417896b6b3322048de280368) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
21:43:45.0612 4232 HSFHWICH - ok
21:43:45.0662 4232 HSF_DP (b2dfc168d6f7512faea085253c5a37ad) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
21:43:45.0702 4232 HSF_DP - ok
21:43:45.0742 4232 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
21:43:45.0752 4232 HTTP - ok
21:43:45.0802 4232 i2omgmt - ok
21:43:45.0812 4232 i2omp - ok
21:43:45.0852 4232 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:43:45.0872 4232 i8042prt - ok
21:43:45.0932 4232 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
21:43:45.0942 4232 Imapi - ok
21:43:45.0972 4232 ini910u - ok
21:43:46.0022 4232 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys
21:43:46.0032 4232 IntelIde - ok
21:43:46.0072 4232 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:43:46.0072 4232 intelppm - ok
21:43:46.0132 4232 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
21:43:46.0142 4232 Ip6Fw - ok
21:43:46.0192 4232 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:43:46.0202 4232 IpFilterDriver - ok
21:43:46.0232 4232 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:43:46.0242 4232 IpInIp - ok
21:43:46.0273 4232 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:43:46.0283 4232 IpNat - ok
21:43:46.0313 4232 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:43:46.0323 4232 IPSec - ok
21:43:46.0353 4232 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:43:46.0363 4232 IRENUM - ok
21:43:46.0413 4232 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:43:46.0443 4232 isapnp - ok
21:43:46.0513 4232 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:43:46.0523 4232 Kbdclass - ok
21:43:46.0563 4232 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
21:43:46.0563 4232 kbdhid - ok
21:43:46.0593 4232 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys
21:43:46.0593 4232 kmixer - ok
21:43:46.0643 4232 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
21:43:46.0663 4232 KSecDD - ok
21:43:46.0753 4232 lbrtfdc - ok
21:43:46.0813 4232 MDC8021X (0f528e44cdc78365be693ae723e3801c) C:\WINDOWS\system32\DRIVERS\mdc8021x.sys
21:43:46.0813 4232 MDC8021X - ok
21:43:46.0853 4232 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
21:43:46.0853 4232 mdmxsdk - ok
21:43:46.0903 4232 mmc_2K (9b90303a9c9405a6ce1466ff4aa20fdd) C:\WINDOWS\system32\drivers\mmc_2K.sys
21:43:46.0964 4232 mmc_2K - ok
21:43:47.0034 4232 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:43:47.0034 4232 mnmdd - ok
21:43:47.0074 4232 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
21:43:47.0074 4232 Modem - ok
21:43:47.0134 4232 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:43:47.0154 4232 Mouclass - ok
21:43:47.0204 4232 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
21:43:47.0214 4232 mouhid - ok
21:43:47.0284 4232 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
21:43:47.0294 4232 MountMgr - ok
21:43:47.0314 4232 mraid35x - ok
21:43:47.0334 4232 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:43:47.0344 4232 MRxDAV - ok
21:43:47.0384 4232 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:43:47.0394 4232 MRxSmb - ok
21:43:47.0424 4232 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
21:43:47.0424 4232 Msfs - ok
21:43:47.0484 4232 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:43:47.0494 4232 MSKSSRV - ok
21:43:47.0574 4232 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:43:47.0584 4232 MSPCLOCK - ok
21:43:47.0604 4232 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
21:43:47.0614 4232 MSPQM - ok
21:43:47.0644 4232 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:43:47.0644 4232 mssmbios - ok
21:43:47.0695 4232 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
21:43:47.0845 4232 Mup - ok
21:43:47.0955 4232 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111214.001\naveng.sys
21:43:47.0965 4232 NAVENG - ok
21:43:48.0055 4232 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111214.001\navex15.sys
21:43:48.0095 4232 NAVEX15 - ok
21:43:48.0175 4232 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
21:43:48.0205 4232 NDIS - ok
21:43:48.0245 4232 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:43:48.0255 4232 NdisTapi - ok
21:43:48.0295 4232 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:43:48.0295 4232 Ndisuio - ok
21:43:48.0315 4232 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:43:48.0446 4232 NdisWan - ok
21:43:48.0526 4232 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
21:43:48.0536 4232 NDProxy - ok
21:43:48.0586 4232 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:43:48.0586 4232 NetBIOS - ok
21:43:48.0626 4232 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:43:48.0626 4232 NetBT - ok
21:43:48.0716 4232 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys
21:43:48.0736 4232 NIC1394 - ok
21:43:48.0776 4232 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys
21:43:48.0776 4232 NPF - ok
21:43:48.0836 4232 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
21:43:48.0836 4232 Npfs - ok
21:43:48.0876 4232 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys
21:43:48.0946 4232 Ntfs - ok
21:43:48.0996 4232 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:43:48.0996 4232 Null - ok
21:43:49.0137 4232 nv (9e4b052c76949de445ad6439cd473548) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:43:49.0227 4232 nv - ok
21:43:49.0307 4232 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:43:49.0317 4232 NwlnkFlt - ok
21:43:49.0357 4232 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:43:49.0367 4232 NwlnkFwd - ok
21:43:49.0427 4232 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
21:43:49.0427 4232 ohci1394 - ok
21:43:49.0457 4232 OMCI (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
21:43:49.0477 4232 OMCI - ok
21:43:49.0547 4232 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
21:43:49.0577 4232 Parport - ok
21:43:49.0617 4232 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
21:43:49.0637 4232 PartMgr - ok
21:43:49.0667 4232 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
21:43:49.0667 4232 ParVdm - ok
21:43:49.0707 4232 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
21:43:49.0727 4232 pccsmcfd - ok
21:43:49.0768 4232 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
21:43:49.0788 4232 PCI - ok
21:43:49.0808 4232 PCIDump - ok
21:43:49.0828 4232 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:43:49.0848 4232 PCIIde - ok
21:43:49.0878 4232 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
21:43:49.0918 4232 Pcmcia - ok
21:43:49.0968 4232 PDCOMP - ok
21:43:49.0988 4232 PDFRAME - ok
21:43:50.0008 4232 PDRELI - ok
21:43:50.0028 4232 PDRFRAME - ok
21:43:50.0038 4232 perc2 - ok
21:43:50.0058 4232 perc2hib - ok
21:43:50.0128 4232 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:43:50.0148 4232 PptpMiniport - ok
21:43:50.0178 4232 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
21:43:50.0188 4232 PSched - ok
21:43:50.0208 4232 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:43:50.0248 4232 Ptilink - ok
21:43:50.0278 4232 pwd_2k (d8b90616a8bd53de281dbdb664c0984a) C:\WINDOWS\system32\drivers\pwd_2k.sys
21:43:50.0328 4232 pwd_2k - ok
21:43:50.0388 4232 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
21:43:50.0619 4232 PxHelp20 - ok
21:43:51.0310 4232 ql1080 - ok
21:43:51.0330 4232 Ql10wnt - ok
21:43:51.0350 4232 ql12160 - ok
21:43:51.0370 4232 ql1240 - ok
21:43:51.0380 4232 ql1280 - ok
21:43:51.0420 4232 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:43:51.0420 4232 RasAcd - ok
21:43:51.0460 4232 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:43:51.0470 4232 Rasl2tp - ok
21:43:51.0500 4232 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:43:51.0510 4232 RasPppoe - ok
21:43:51.0530 4232 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:43:51.0550 4232 Raspti - ok
21:43:51.0580 4232 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:43:51.0590 4232 Rdbss - ok
21:43:51.0610 4232 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:43:51.0610 4232 RDPCDD - ok
21:43:51.0660 4232 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:43:51.0690 4232 rdpdr - ok
21:43:51.0760 4232 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys
21:43:51.0800 4232 RDPWD - ok
21:43:51.0841 4232 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:43:51.0861 4232 redbook - ok
21:43:51.0931 4232 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\WINDOWS\system32\Drivers\RimUsb.sys
21:43:51.0951 4232 RimUsb - ok
21:43:51.0991 4232 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
21:43:52.0021 4232 RimVSerPort - ok
21:43:52.0171 4232 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
21:43:52.0191 4232 ROOTMODEM - ok
21:43:52.0291 4232 s24trans (41cf7128424f3bdc35b05be3cc8ce7ec) C:\WINDOWS\system32\DRIVERS\s24trans.sys
21:43:52.0291 4232 s24trans - ok
21:43:52.0381 4232 SAVRT (cdb565c093b0105086cc630b32f9e6e6) C:\Program Files\Symantec AntiVirus\savrt.sys
21:43:52.0491 4232 SAVRT - ok
21:43:52.0511 4232 SAVRTPEL (1042cb5a003f9aed8d6cec56a0fc6c49) C:\Program Files\Symantec AntiVirus\Savrtpel.sys
21:43:52.0532 4232 SAVRTPEL - ok
21:43:52.0602 4232 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:43:52.0632 4232 Secdrv - ok
21:43:52.0672 4232 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
21:43:52.0682 4232 serenum - ok
21:43:52.0702 4232 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
21:43:52.0712 4232 Serial - ok
21:43:52.0752 4232 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:43:52.0762 4232 Sfloppy - ok
21:43:52.0792 4232 Simbad - ok
21:43:52.0812 4232 Sparrow - ok
21:43:52.0902 4232 SPBBCDrv (cc22bf5631c4837abcd81d75de8fb1aa) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
21:43:52.0912 4232 SPBBCDrv - ok
21:43:52.0982 4232 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys
21:43:52.0982 4232 splitter - ok
21:43:53.0032 4232 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
21:43:53.0062 4232 sr - ok
21:43:53.0112 4232 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
21:43:53.0122 4232 Srv - ok
21:43:53.0172 4232 STAC97 (ae4797a1fc117c1d28a4ed80be42f734) C:\WINDOWS\system32\drivers\stac97.sys
21:43:53.0223 4232 STAC97 - ok
21:43:53.0303 4232 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
21:43:53.0313 4232 StillCam - ok
21:43:53.0363 4232 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:43:53.0373 4232 swenum - ok
21:43:53.0463 4232 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
21:43:53.0463 4232 swmidi - ok
21:43:53.0493 4232 symc810 - ok
21:43:53.0503 4232 symc8xx - ok
21:43:53.0603 4232 SymEvent (5156f63e684e8c864ff40e40d5309f41) C:\Program Files\Symantec\SYMEVENT.SYS
21:43:53.0653 4232 SymEvent - ok
21:43:53.0723 4232 SYMREDRV (5314e345dfc068504cfb2676d3b2ca39) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
21:43:54.0114 4232 SYMREDRV - ok
21:43:54.0234 4232 SYMTDI (8cd0a1478256240249b8ee88e6f25e94) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
21:43:54.0264 4232 SYMTDI - ok
21:43:54.0324 4232 sym_hi - ok
21:43:54.0394 4232 sym_u3 - ok
21:43:54.0494 4232 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
21:43:54.0494 4232 sysaudio - ok
21:43:54.0554 4232 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:43:54.0564 4232 Tcpip - ok
21:43:54.0635 4232 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:43:54.0705 4232 TDPIPE - ok
21:43:54.0765 4232 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
21:43:54.0825 4232 TDTCP - ok
21:43:54.0885 4232 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:43:54.0955 4232 TermDD - ok
21:43:55.0055 4232 tiumfwl (a4c6f3e34358c94e5c3acfc3392f8907) C:\WINDOWS\system32\drivers\tiumfwl.sys
21:43:55.0265 4232 tiumfwl - ok
21:43:55.0336 4232 TosIde - ok
21:43:55.0396 4232 UdfReadr_xp (4e75005b74be901c30f2636df40b0c15) C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
21:43:55.0406 4232 UdfReadr_xp - ok
21:43:55.0466 4232 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
21:43:55.0486 4232 Udfs - ok
21:43:55.0496 4232 UIUSys - ok
21:43:55.0516 4232 ultra - ok
21:43:55.0556 4232 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys
21:43:55.0626 4232 Update - ok
21:43:55.0686 4232 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:43:55.0706 4232 usbccgp - ok
21:43:55.0746 4232 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:43:55.0756 4232 usbehci - ok
21:43:55.0796 4232 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:43:55.0826 4232 usbhub - ok
21:43:55.0876 4232 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
21:43:55.0876 4232 usbprint - ok
21:43:55.0936 4232 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:43:55.0976 4232 usbscan - ok
21:43:56.0027 4232 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:43:56.0057 4232 USBSTOR - ok
21:43:56.0117 4232 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:43:56.0217 4232 usbuhci - ok
21:43:56.0497 4232 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
21:43:56.0547 4232 VgaSave - ok
21:43:56.0617 4232 ViaIde - ok
21:43:56.0728 4232 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
21:43:56.0978 4232 VolSnap - ok
21:43:57.0108 4232 w22n51 (4fed83668f087ecbe810ea90beceb765) C:\WINDOWS\system32\DRIVERS\w22n51.sys
21:43:57.0158 4232 w22n51 - ok
21:43:57.0198 4232 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:43:57.0198 4232 Wanarp - ok
21:43:57.0238 4232 WDICA - ok
21:43:57.0278 4232 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys
21:43:57.0278 4232 wdmaud - ok
21:43:57.0358 4232 winachsf (2dc7c0b6175a0a8ed84a4f70199c93b5) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
21:43:57.0399 4232 winachsf - ok
21:43:57.0609 4232 MBR (0x1B8) (6f9a1d528242bc09104b85e0becf5554) \Device\Harddisk0\DR0
21:43:57.0629 4232 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - infected
21:43:57.0629 4232 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.a (0)
21:43:57.0639 4232 Boot (0x1200) (b57b10d35f0c0a4ce2fa4f6298e87b7e) \Device\Harddisk0\DR0\Partition0
21:43:57.0639 4232 \Device\Harddisk0\DR0\Partition0 - ok
21:43:57.0649 4232 ============================================================
21:43:57.0649 4232 Scan finished
21:43:57.0649 4232 ============================================================
21:43:57.0669 4220 Detected object count: 2
21:43:57.0669 4220 Actual detected object count: 2
21:45:16.0943 4220 Cdrom ( Virus.Win32.ZAccess.k ) - skipped by user
21:45:16.0943 4220 Cdrom ( Virus.Win32.ZAccess.k ) - User select action: Skip
21:45:16.0943 4220 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - skipped by user
21:45:16.0943 4220 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - User select action: Skip
When I try to upload the MBR.DAT file I get an upload error that says that I am not permitted to upload this type of file?
Any suggestions?
Thanks
Hello
Clairedog
Thank you for the log.
Lets see if we can get the file attached before we continue.
Please
Right click on the file (MBR.dat) and select
Send to >
Compressed (zipped folder) . The file will be placed in a zipped folder on your desktop. See if you can attach the zipped folder in your next reply
MRB.zip attached. Sorry. Should have thought of that myself last night.
Have a good day.
Hello
Clairedog
Should have thought of that myself last night
No problem
Now that we have the MBR.dat attached we can continue:
Please run TDSSKiller as you did before, but this time, allow it to
Cure any malicious items it detects.
Once you have saved the TDSSKiller log, follow with the following tool:
Combofix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. Please note : If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes , to continue scanning for malware.When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.Do not "re-run" Combofix. If you have a problem, reply back for further instructions. Should there be issues with internet afterward:
In IE : Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> un check "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.
In Firefox : Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy .
Please post the TDSSKiller log and the Combofix log in your next reply.
Hi:
I thought that all antivirus was off; however when I ran combofix it indicated taht Symantec Corp Antivirus was still running. There was nothing in the system tray and no programs running. I looked at the processes to see if I could identify something to terminate but didn't know what to look for. I've attached a word doc with two screen shots of the processes running. Perhaps you can see something that you know is running as a part of SCA that I can terminate before running the Combo Fix.
Thanks.
Hello
Clairedog
however when I ran combofix it indicated taht Symantec Corp Antivirus was still running.
Did you try Right clicking on the Norton AntiVirus Corporate Edition icon located in your taskbar (bottom right hand corner of screen) and
Un checking
"Enable Filesystem Realtime Protection" ?
Give that a try then see if Combofix will run. If you are notified by Combofix that your AV is still running you may have to uninstall it (The Corporate Edition of Symantec AntiVirus is not commonly found on home computers so if you decide to uninstall it I will provide you with an alternative program later if you do not have the installation disk for Norton).
Let me know how you get on in your next reply