This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Security scanner auto virus, think removed. hjt att [Solved]

52 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got some auto security virus popping up telling me about bogus alerts. I forget what it was called because i kept trying to get out of it. It does not let u run atf cleaner, mbam spybots etc.

Got to run those in safe mode and tdsskill. It does not seem to be active anymore but want to be sure. Hjt log attached. Any recos appreciated.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:01:42 AM, on 3/9/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:WINDOWS.0System32smss.exe
C:WINDOWS.0system32winlogon.exe
C:WINDOWS.0system32services.exe
C:WINDOWS.0system32lsass.exe
C:WINDOWS.0system32svchost.exe
C:WINDOWS.0System32svchost.exe
C:WINDOWS.0system32svchost.exe
C:Program FilesLavasoftAd-AwareAAWService.exe
C:WINDOWS.0system32spoolsv.exe
C:WINDOWS.0Explorer.EXE
C:Program FilesCommon FilesAOLACSAOLAcsd.exe
C:WINDOWS.0system32svchost.exe
C:WINDOWS.0system32svchost.exe
C:WINDOWS.0system32imapi.exe
C:Program FilesMalwarebytes' Anti-Malwarellmbamservice.exe
C:Program FilesMalwarebytes' Anti-Malwarellmbamgui.exe
C:WINDOWS.0system32ctfmon.exe
C:WINDOWS.0system32taskmgr.exe
C:WINDOWS.0System32svchost.exe
C:WINDOWS.0System32svchost.exe
C:WINDOWS.0System32svchost.exe
C:Program Filesinternet exploreriexplore.exe
C:Program Filesinternet exploreriexplore.exe
C:Program FilesHewlett-PackardDigital ImagingSmart Web Printinghpswp_clipbook.exe
C:WINDOWS.0system32msiexec.exe
C:Program FilesTrend MicroHijackThisHiJackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://aol.com/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://home.sweetim.com
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:Program FilesHewlett-PackardDigital ImagingSmart Web Printinghpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:CreativesFilesRazaWebHook32.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:Program FilesAOLAOL Toolbar 5.0aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll
O2 - BHO: (no name) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - (no file)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:Program FilesHewlett-PackardDigital ImagingSmart Web Printinghpswp_BHO.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:Program FilesAOLAOL Toolbar 5.0aoltb.dll
O4 - HKLM..Run: [Malwarebytes' Anti-Malware] "C:Program FilesMalwarebytes' Anti-Malwarellmbamgui.exe" /starttray
O4 - HKLM..Run: [MSConfig] C:WINDOWS.0pchealthhelpctrBinariesMSCONFIG.EXE /auto
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWS.0system32ctfmon.exe
O4 - HKUSS-1-5-21-1415427462-1084713858-833570676-1005..Run: [ctfmon.exe] C:WINDOWS.0system32ctfmon.exe (User '?')
O4 - HKUSS-1-5-18..Run: [AOL Fast Start] "C:Program FilesAOL 9.1bAOL.EXE" -b (User '?')
O4 - HKUS.DEFAULT..Run: [AOL Fast Start] "C:Program FilesAOL 9.1bAOL.EXE" -b (User 'Default user')
O4 - .DEFAULT User Startup: Organize.lnk = ? (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:Program FilesinterMuteSpamSubtractSpamSub.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:program filesaolaol toolbar 5.0resourcesen-USlocalsearch.html
O8 - Extra context menu item: Download with &Shareaza - res://C:CreativesFilesRazaWebHook32.dll/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:Program FilesAOLAOL Toolbar 5.0aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:Program FilesHewlett-PackardDigital ImagingSmart Web Printinghpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWS.0Network Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWS.0Network Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O10 - Unknown file in Winsock LSP: c:windows.0system32nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - https://www.secure-session.com/include/XUpload.ocx
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:WINDOWS.0System32browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:WINDOWS.0System32browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:Program FilesCommon FilesAOLACSAOLAcsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:Program FilesLavasoftAd-AwareAAWService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:Program FilesMalwarebytes' Anti-Malwarellmbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:Program FilesMcAfee Security Scan2.0.181McCHSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:WINDOWS.0wanmpsvc.exe

–
End of file - 8752 bytes

ps. the computer is super slow. Not sure if its just old or what.

Anyone?
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
From my understanding, you have run MBAM and TDSSKiller. Both programs generate logs, so please post their contents. The MBAM log can be found by opening up the program and clicking on the Logs tab. The TDSSKiller log should be located in your root directly (typically C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please open them with Notepad and ensure Word Wrap (Format > Word Wrap) is off before copy and pasting them.

Please also run these two scans in normal mode and post the logs:

  • OTL

    Download OTL to your desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

[*]aswMBR


Please download aswMBR and save it to your desktop.

  • Double click aswMBR.exe to start the tool.
  • When prompted to download virus definitions, please do so.
  • Click Scan. Note: Do NOT attempt any Fix yet.
  • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
The otl when i try to open it everytime i get the unexpected windows error and forced to close it. mbam log. Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.03.08.03 Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking) Internet Explorer 8.0.6001.18702 Tom :: BASEMENT [administrator] 3/8/2012 10:53:17 PM mbam-log-2012-03-08 (22-53-17).txt Scan type: Full scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 527139 Time elapsed: 1 hour(s), 25 minute(s), 49 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Backdoor.Agent.Gen) -> Data: C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\X -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 9 C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\X (Rootkit.Dropper) -> Quarantined and deleted successfully. C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\00000001.@ (Backdoor.0Access) -> Quarantined and deleted successfully. C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\000000c0.@ (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\000000cb.@ (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\000000cf.@ (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\800000c0.@ (Rootkit.0Access) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{FFB3E3B2-9E42-4DFB-881F-E65F93D267FF}\RP227\A0045533.ini (Rootkit.0Access) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{FFB3E3B2-9E42-4DFB-881F-E65F93D267FF}\RP227\A0046533.ini (Rootkit.0Access) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{FFB3E3B2-9E42-4DFB-881F-E65F93D267FF}\RP227\A0050578.sys (Rootkit.0Access) -> Quarantined and deleted successfully. (end)
Tds Log 2012/03/09 08:42:55.0109 3844 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08 2012/03/09 08:43:00.0609 3844 ================================================================================ 2012/03/09 08:43:00.0609 3844 SystemInfo: 2012/03/09 08:43:00.0609 3844 2012/03/09 08:43:00.0609 3844 OS Version: 5.1.2600 ServicePack: 3.0 2012/03/09 08:43:00.0609 3844 Product type: Workstation 2012/03/09 08:43:00.0609 3844 ComputerName: BASEMENT 2012/03/09 08:43:00.0609 3844 UserName: Tom 2012/03/09 08:43:00.0609 3844 Windows directory: C:\WINDOWS.0 2012/03/09 08:43:00.0609 3844 System windows directory: C:\WINDOWS.0 2012/03/09 08:43:00.0609 3844 Processor architecture: Intel x86 2012/03/09 08:43:00.0609 3844 Number of processors: 1 2012/03/09 08:43:00.0609 3844 Page size: 0x1000 2012/03/09 08:43:00.0609 3844 Boot type: Normal boot 2012/03/09 08:43:00.0609 3844 ================================================================================ 2012/03/09 08:43:01.0421 3844 Initialize success 2012/03/09 08:43:06.0546 0632 ================================================================================ 2012/03/09 08:43:06.0546 0632 Scan started 2012/03/09 08:43:06.0546 0632 Mode: Manual; 2012/03/09 08:43:06.0546 0632 ================================================================================ 2012/03/09 08:43:11.0859 0632 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS.0\system32\DRIVERS\ACPI.sys 2012/03/09 08:43:11.0984 0632 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS.0\system32\drivers\ACPIEC.sys 2012/03/09 08:43:12.0218 0632 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS.0\system32\drivers\aec.sys 2012/03/09 08:43:12.0406 0632 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS.0\System32\drivers\afd.sys 2012/03/09 08:43:12.0578 0632 AFS2K (4c1e86ea5da67ab43fd1763561ddba74) C:\WINDOWS.0\system32\drivers\AFS2K.sys 2012/03/09 08:43:12.0921 0632 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS.0\system32\drivers\ALCXSENS.SYS 2012/03/09 08:43:13.0468 0632 ALCXWDM (8d6c30e515717248e0e52b85fd7ac466) C:\WINDOWS.0\system32\drivers\ALCXWDM.SYS 2012/03/09 08:43:14.0156 0632 AmdK7 (8fce268cdbdd83b23419d1f35f42c7b1) C:\WINDOWS.0\system32\DRIVERS\amdk7.sys 2012/03/09 08:43:14.0531 0632 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS.0\system32\DRIVERS\arp1394.sys 2012/03/09 08:43:14.0984 0632 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS.0\system32\DRIVERS\asyncmac.sys 2012/03/09 08:43:15.0171 0632 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS.0\system32\DRIVERS\atapi.sys 2012/03/09 08:43:15.0437 0632 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS.0\system32\DRIVERS\atmarpc.sys 2012/03/09 08:43:15.0640 0632 ATWPKT2 (f1babe0b950bc4e8d8178046c4aca0fe) C:\WINDOWS.0\system32\drivers\ATWPKT2.SYS 2012/03/09 08:43:15.0765 0632 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS.0\system32\DRIVERS\audstub.sys 2012/03/09 08:43:15.0921 0632 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS.0\system32\drivers\Beep.sys 2012/03/09 08:43:16.0078 0632 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS.0\system32\drivers\cbidf2k.sys 2012/03/09 08:43:16.0375 0632 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS.0\system32\drivers\Cdaudio.sys 2012/03/09 08:43:16.0546 0632 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS.0\system32\drivers\Cdfs.sys 2012/03/09 08:43:16.0750 0632 Cdr4_xp (bf79e659c506674c0497cc9c61f1a165) C:\WINDOWS.0\system32\drivers\Cdr4_xp.sys 2012/03/09 08:43:16.0937 0632 Cdralw2k (2c41cd49d82d5fd85c72d57b6ca25471) C:\WINDOWS.0\system32\drivers\Cdralw2k.sys 2012/03/09 08:43:17.0750 0632 cdudf_xp (66b9f9c62721f2347211c0c9bcce4e98) C:\WINDOWS.0\system32\drivers\cdudf_xp.sys 2012/03/09 08:43:19.0421 0632 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS.0\system32\DRIVERS\disk.sys 2012/03/09 08:43:19.0671 0632 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS.0\system32\drivers\dmboot.sys 2012/03/09 08:43:20.0015 0632 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS.0\system32\drivers\dmio.sys 2012/03/09 08:43:20.0218 0632 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS.0\system32\drivers\dmload.sys 2012/03/09 08:43:20.0359 0632 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS.0\system32\drivers\DMusic.sys 2012/03/09 08:43:20.0656 0632 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS.0\system32\drivers\drmkaud.sys 2012/03/09 08:43:20.0812 0632 DVDVRRdr_xp (c62e0ce202d7d704231bf6daea3b46ea) C:\WINDOWS.0\system32\drivers\DVDVRRdr_xp.sys 2012/03/09 08:43:20.0968 0632 dvd_2K (df112f6f01efedc21c9bc5ce822ce1d3) C:\WINDOWS.0\system32\drivers\dvd_2K.sys 2012/03/09 08:43:21.0265 0632 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS.0\system32\drivers\Fastfat.sys 2012/03/09 08:43:21.0437 0632 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS.0\system32\DRIVERS\fdc.sys 2012/03/09 08:43:21.0609 0632 FET5X86V (5faa391f5b4cd2c38be7ca270e13b444) C:\WINDOWS.0\system32\DRIVERS\fetnd5bv.sys 2012/03/09 08:43:21.0671 0632 FETND5BV (5faa391f5b4cd2c38be7ca270e13b444) C:\WINDOWS.0\system32\DRIVERS\fetnd5bv.sys 2012/03/09 08:43:21.0843 0632 FETNDISB (a583bc166495b07f704533754ce29cbd) C:\WINDOWS.0\system32\DRIVERS\fetnd5b.sys 2012/03/09 08:43:22.0062 0632 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS.0\system32\drivers\Fips.sys 2012/03/09 08:43:22.0171 0632 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS.0\system32\DRIVERS\flpydisk.sys 2012/03/09 08:43:22.0359 0632 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS.0\system32\drivers\fltmgr.sys 2012/03/09 08:43:22.0546 0632 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS.0\system32\drivers\Fs_Rec.sys 2012/03/09 08:43:22.0828 0632 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS.0\system32\DRIVERS\ftdisk.sys 2012/03/09 08:43:23.0015 0632 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS.0\system32\DRIVERS\msgpc.sys 2012/03/09 08:43:23.0171 0632 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS.0\system32\DRIVERS\hidusb.sys 2012/03/09 08:43:23.0421 0632 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS.0\system32\DRIVERS\HPZid412.sys 2012/03/09 08:43:23.0593 0632 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS.0\system32\DRIVERS\HPZipr12.sys 2012/03/09 08:43:23.0765 0632 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS.0\system32\DRIVERS\HPZius12.sys 2012/03/09 08:43:24.0031 0632 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS.0\system32\Drivers\HTTP.sys 2012/03/09 08:43:24.0484 0632 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS.0\system32\DRIVERS\i8042prt.sys 2012/03/09 08:43:24.0671 0632 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS.0\system32\DRIVERS\imapi.sys 2012/03/09 08:43:25.0046 0632 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS.0\system32\drivers\ip6fw.sys 2012/03/09 08:43:25.0234 0632 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS.0\system32\DRIVERS\ipfltdrv.sys 2012/03/09 08:43:25.0359 0632 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS.0\system32\DRIVERS\ipinip.sys 2012/03/09 08:43:25.0609 0632 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS.0\system32\DRIVERS\ipnat.sys 2012/03/09 08:43:25.0843 0632 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS.0\system32\DRIVERS\ipsec.sys 2012/03/09 08:43:26.0000 0632 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS.0\system32\DRIVERS\irenum.sys 2012/03/09 08:43:26.0156 0632 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS.0\system32\DRIVERS\isapnp.sys 2012/03/09 08:43:26.0359 0632 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS.0\system32\DRIVERS\kbdclass.sys 2012/03/09 08:43:26.0593 0632 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS.0\system32\DRIVERS\kbdhid.sys 2012/03/09 08:43:26.0843 0632 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS.0\system32\drivers\kmixer.sys 2012/03/09 08:43:27.0078 0632 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS.0\system32\drivers\KSecDD.sys 2012/03/09 08:43:27.0359 0632 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys 2012/03/09 08:43:27.0593 0632 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS.0\system32\DRIVERS\Lbd.sys 2012/03/09 08:43:28.0000 0632 ltmodem5 (9ee18a5a45552673a67532ea37370377) C:\WINDOWS.0\system32\DRIVERS\ltmdmnt.sys 2012/03/09 08:43:28.0406 0632 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS.0\system32\drivers\mbam.sys 2012/03/09 08:43:28.0546 0632 mmc_2K (a52ed33515755e825d090a47793b773f) C:\WINDOWS.0\system32\drivers\mmc_2K.sys 2012/03/09 08:43:28.0687 0632 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS.0\system32\drivers\mnmdd.sys 2012/03/09 08:43:28.0859 0632 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS.0\system32\drivers\Modem.sys 2012/03/09 08:43:29.0000 0632 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS.0\system32\DRIVERS\mouclass.sys 2012/03/09 08:43:29.0156 0632 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS.0\system32\DRIVERS\mouhid.sys 2012/03/09 08:43:29.0453 0632 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS.0\system32\drivers\MountMgr.sys 2012/03/09 08:43:29.0859 0632 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS.0\system32\DRIVERS\mrxdav.sys 2012/03/09 08:43:30.0312 0632 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS.0\system32\DRIVERS\mrxsmb.sys 2012/03/09 08:43:30.0687 0632 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS.0\system32\drivers\Msfs.sys 2012/03/09 08:43:30.0921 0632 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS.0\system32\drivers\MSKSSRV.sys 2012/03/09 08:43:31.0187 0632 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS.0\system32\drivers\MSPCLOCK.sys 2012/03/09 08:43:31.0640 0632 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS.0\system32\drivers\MSPQM.sys 2012/03/09 08:43:31.0890 0632 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS.0\system32\DRIVERS\mssmbios.sys 2012/03/09 08:43:32.0203 0632 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS.0\system32\drivers\Mup.sys 2012/03/09 08:43:32.0531 0632 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS.0\system32\drivers\NDIS.sys 2012/03/09 08:43:32.0859 0632 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS.0\system32\DRIVERS\ndistapi.sys 2012/03/09 08:43:33.0187 0632 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS.0\system32\DRIVERS\ndisuio.sys 2012/03/09 08:43:33.0562 0632 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS.0\system32\DRIVERS\ndiswan.sys 2012/03/09 08:43:33.0859 0632 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS.0\system32\drivers\NDProxy.sys 2012/03/09 08:43:34.0218 0632 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS.0\system32\DRIVERS\netbios.sys 2012/03/09 08:43:34.0578 0632 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS.0\system32\DRIVERS\netbt.sys 2012/03/09 08:43:34.0875 0632 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS.0\system32\DRIVERS\nic1394.sys 2012/03/09 08:43:35.0312 0632 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS.0\system32\DRIVERS\NMnt.sys 2012/03/09 08:43:35.0656 0632 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS.0\system32\drivers\NPF.sys 2012/03/09 08:43:36.0218 0632 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS.0\system32\drivers\Npfs.sys 2012/03/09 08:43:38.0671 0632 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS.0\system32\drivers\Ntfs.sys 2012/03/09 08:43:39.0078 0632 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\WINDOWS.0\system32\DRIVERS\NuidFltr.sys 2012/03/09 08:43:39.0203 0632 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS.0\system32\drivers\Null.sys 2012/03/09 08:43:39.0359 0632 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS.0\system32\DRIVERS\nwlnkflt.sys 2012/03/09 08:43:39.0546 0632 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS.0\system32\DRIVERS\nwlnkfwd.sys 2012/03/09 08:43:39.0734 0632 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS.0\system32\DRIVERS\nwlnkipx.sys 2012/03/09 08:43:39.0859 0632 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS.0\system32\DRIVERS\nwlnknb.sys 2012/03/09 08:43:40.0125 0632 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS.0\system32\DRIVERS\nwlnkspx.sys 2012/03/09 08:43:40.0328 0632 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS.0\system32\DRIVERS\ohci1394.sys 2012/03/09 08:43:40.0500 0632 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS.0\system32\DRIVERS\parport.sys 2012/03/09 08:43:40.0640 0632 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS.0\system32\drivers\PartMgr.sys 2012/03/09 08:43:40.0812 0632 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS.0\system32\drivers\ParVdm.sys 2012/03/09 08:43:40.0984 0632 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS.0\system32\DRIVERS\pci.sys 2012/03/09 08:43:41.0234 0632 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS.0\system32\drivers\PCIIde.sys 2012/03/09 08:43:41.0453 0632 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS.0\system32\drivers\Pcmcia.sys 2012/03/09 08:43:42.0234 0632 Point32 (e4910ce9d882bf825979fcf4636a9bd8) C:\WINDOWS.0\system32\DRIVERS\point32.sys 2012/03/09 08:43:42.0453 0632 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS.0\system32\DRIVERS\raspptp.sys 2012/03/09 08:43:42.0812 0632 psa805 (9de8617e636c9ae812efd6b32bbc128b) C:\WINDOWS.0\system32\drivers\psa805.sys 2012/03/09 08:43:43.0000 0632 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS.0\system32\DRIVERS\psched.sys 2012/03/09 08:43:43.0171 0632 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS.0\system32\DRIVERS\ptilink.sys 2012/03/09 08:43:43.0343 0632 pwd_2k (62d29677f6a7f018c5d49119cea67de5) C:\WINDOWS.0\system32\drivers\pwd_2k.sys 2012/03/09 08:43:43.0500 0632 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS.0\system32\Drivers\PxHelp20.sys 2012/03/09 08:43:44.0312 0632 QsndEnum (34854845f4c501b14e3ea993c8776b1e) C:\WINDOWS.0\system32\DRIVERS\QsndEnum.sys 2012/03/09 08:43:44.0578 0632 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS.0\system32\DRIVERS\rasacd.sys 2012/03/09 08:43:44.0781 0632 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS.0\system32\DRIVERS\rasl2tp.sys 2012/03/09 08:43:44.0937 0632 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS.0\system32\DRIVERS\raspppoe.sys 2012/03/09 08:43:45.0140 0632 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS.0\system32\DRIVERS\raspti.sys 2012/03/09 08:43:45.0390 0632 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS.0\system32\DRIVERS\rdbss.sys 2012/03/09 08:43:45.0687 0632 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS.0\system32\DRIVERS\RDPCDD.sys 2012/03/09 08:43:45.0968 0632 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS.0\system32\drivers\RDPWD.sys 2012/03/09 08:43:46.0312 0632 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS.0\system32\DRIVERS\redbook.sys 2012/03/09 08:43:46.0687 0632 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS.0\system32\DRIVERS\secdrv.sys 2012/03/09 08:43:46.0890 0632 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS.0\system32\DRIVERS\serenum.sys 2012/03/09 08:43:47.0109 0632 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS.0\system32\DRIVERS\serial.sys 2012/03/09 08:43:47.0437 0632 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS.0\system32\drivers\Sfloppy.sys 2012/03/09 08:43:47.0968 0632 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS.0\system32\drivers\splitter.sys 2012/03/09 08:43:48.0250 0632 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS.0\system32\DRIVERS\sr.sys 2012/03/09 08:43:48.0640 0632 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS.0\system32\DRIVERS\srv.sys 2012/03/09 08:43:48.0937 0632 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS.0\system32\DRIVERS\swenum.sys 2012/03/09 08:43:49.0281 0632 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS.0\system32\drivers\swmidi.sys 2012/03/09 08:43:49.0859 0632 SymEvent (c9b8f325b2a22cda1bda7b25181b1389) C:\Program Files\Symantec\SYMEVENT.SYS 2012/03/09 08:43:50.0140 0632 SYMREDRV (f26e71125da173d57caba3457c5e48cf) C:\WINDOWS.0\System32\Drivers\SYMREDRV.SYS 2012/03/09 08:43:50.0515 0632 SYMTDI (23b6adbaa7026c53b5ef102e56750b13) C:\WINDOWS.0\System32\Drivers\SYMTDI.SYS 2012/03/09 08:43:51.0250 0632 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS.0\system32\drivers\sysaudio.sys 2012/03/09 08:43:51.0687 0632 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS.0\system32\DRIVERS\tcpip.sys 2012/03/09 08:43:52.0281 0632 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS.0\system32\DRIVERS\tcpip6.sys 2012/03/09 08:43:52.0593 0632 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS.0\system32\drivers\TDPIPE.sys 2012/03/09 08:43:52.0953 0632 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS.0\system32\drivers\TDTCP.sys 2012/03/09 08:43:53.0250 0632 TermDD (88155247177638048422893737429d9e) C:\WINDOWS.0\system32\DRIVERS\termdd.sys 2012/03/09 08:43:53.0937 0632 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS.0\system32\DRIVERS\tunmp.sys 2012/03/09 08:43:54.0406 0632 UDFReadr (6fd853869610414509b43599831ad000) C:\WINDOWS.0\system32\drivers\UDFReadr.sys 2012/03/09 08:43:54.0734 0632 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS.0\system32\drivers\Udfs.sys 2012/03/09 08:43:55.0468 0632 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS.0\system32\DRIVERS\update.sys 2012/03/09 08:43:55.0968 0632 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS.0\system32\drivers\usbaudio.sys 2012/03/09 08:43:56.0328 0632 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS.0\system32\DRIVERS\usbccgp.sys 2012/03/09 08:43:56.0625 0632 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS.0\system32\DRIVERS\usbehci.sys 2012/03/09 08:43:57.0093 0632 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS.0\system32\DRIVERS\usbhub.sys 2012/03/09 08:43:57.0578 0632 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS.0\system32\DRIVERS\usbprint.sys 2012/03/09 08:43:57.0953 0632 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS.0\system32\DRIVERS\usbscan.sys 2012/03/09 08:43:58.0781 0632 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS.0\system32\DRIVERS\USBSTOR.SYS 2012/03/09 08:43:59.0453 0632 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS.0\system32\DRIVERS\usbuhci.sys 2012/03/09 08:43:59.0765 0632 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS.0\System32\drivers\vga.sys 2012/03/09 08:44:00.0375 0632 viaagp1 (4b039bbd037b01f5db5a144c837f283a) C:\WINDOWS.0\system32\DRIVERS\viaagp1.sys 2012/03/09 08:44:00.0765 0632 viagfx (45489356501ec6cbb789dece991d393f) C:\WINDOWS.0\system32\DRIVERS\vtmini.sys 2012/03/09 08:44:01.0406 0632 ViaIde (a5d8b6c8d43786d4215c1df6fab0aae0) C:\WINDOWS.0\system32\DRIVERS\viaidexp.sys 2012/03/09 08:44:01.0796 0632 viasraid (ebe101c01d80a42868f57b327be1b564) C:\WINDOWS.0\system32\DRIVERS\viasraid.sys 2012/03/09 08:44:02.0187 0632 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS.0\system32\drivers\VolSnap.sys 2012/03/09 08:44:02.0609 0632 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS.0\system32\DRIVERS\wanarp.sys 2012/03/09 08:44:02.0984 0632 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS.0\system32\DRIVERS\wanatw4.sys 2012/03/09 08:44:03.0484 0632 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS.0\system32\DRIVERS\Wdf01000.sys 2012/03/09 08:44:04.0015 0632 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS.0\system32\drivers\wdmaud.sys 2012/03/09 08:44:04.0468 0632 WinUSB (30fc6e5448d0cbaaa95280eeef7fedae) C:\WINDOWS.0\system32\DRIVERS\WinUSB.sys 2012/03/09 08:44:04.0859 0632 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS.0\system32\DRIVERS\wpdusb.sys 2012/03/09 08:44:05.0375 0632 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS.0\system32\DRIVERS\WudfPf.sys 2012/03/09 08:44:05.0734 0632 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS.0\system32\DRIVERS\wudfrd.sys 2012/03/09 08:44:06.0171 0632 ================================================================================ 2012/03/09 08:44:06.0171 0632 Scan finished 2012/03/09 08:44:06.0171 0632 ================================================================================ 2012/03/09 08:44:14.0390 2652 Deinitialize success
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-15 09:34:12 —————————– 09:34:12.906 OS Version: Windows 5.1.2600 Service Pack 3 09:34:12.906 Number of processors: 1 586 0xA00 09:34:12.906 ComputerName: BASEMENT UserName: Tom 09:34:14.062 Initialize success 09:35:04.312 AVAST engine defs: 12031401 09:35:19.437 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 09:35:19.468 Disk 0 Vendor: Maxtor_6Y160P0 YAR41BW0 Size: 156334MB BusType: 3 09:35:19.484 Disk 0 MBR read successfully 09:35:19.484 Disk 0 MBR scan 09:35:19.546 Disk 0 Windows XP default MBR code 09:35:19.546 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 5647 MB offset 63 09:35:19.578 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 150675 MB offset 11566800 09:35:19.609 Disk 0 scanning sectors +320150880 09:35:19.703 Disk 0 scanning C:\WINDOWS.0\system32\drivers 09:35:20.500 File: C:\WINDOWS.0\system32\drivers\AFS2K.SYS **INFECTED** Win32:Alureon-AJI [Rtk] 09:35:25.515 File: C:\WINDOWS.0\system32\drivers\DVDVRRdr_xp.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:35:35.796 File: C:\WINDOWS.0\system32\drivers\Udfreadr.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:35:37.859 Disk 0 trace - called modules: 09:35:37.875 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaidexp.sys PCIIDEX.SYS 09:35:37.875 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a51aab8] 09:35:37.875 3 CLASSPNP.SYS[f7657fd7] -> nt!IofCallDriver -> \Device\00000067[0x8a5306c0] 09:35:37.890 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a4d3940] 09:35:38.640 AVAST engine scan C:\WINDOWS.0 09:35:56.359 File: C:\WINDOWS.0\wanmpsvc.exe **INFECTED** Win32:Patched-WQ [Trj] 09:35:58.000 AVAST engine scan C:\WINDOWS.0\system32 09:40:10.859 AVAST engine scan C:\WINDOWS.0\system32\drivers 09:40:11.546 File: C:\WINDOWS.0\system32\drivers\AFS2K.SYS **INFECTED** Win32:Alureon-AJI [Rtk] 09:40:15.937 File: C:\WINDOWS.0\system32\drivers\DVDVRRdr_xp.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:40:27.843 File: C:\WINDOWS.0\system32\drivers\Udfreadr.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:40:37.703 AVAST engine scan C:\Documents and Settings\Tom 09:43:36.437 File: C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\80000000.@ **INFECTED** Win64:Sirefef-A [Trj] 09:43:36.546 File: C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\800000cb.@ **INFECTED** Win32:Sirefef-AO [Rtk] 09:43:36.625 File: C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\800000cf.@ **INFECTED** Win32:Trojan-gen 09:43:37.093 File: C:\Documents and Settings\Tom\Local Settings\Application Data\ilybnmel.exe **INFECTED** Win32:FakeAlert-CER [Trj] 09:56:41.812 AVAST engine scan C:\Documents and Settings\All Users.WINDOWS.0 10:11:38.484 Scan finished successfully 10:19:51.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Tom\Desktop\MBR.dat" 10:19:51.625 The log file has been saved successfully to "C:\Documents and Settings\Tom\Desktop\aswMBR.txt"
  • ComboFix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here.
  • Double click on ComboFix.exe & follow the prompts.

  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
log.



ComboFix 12-03-15.03 - Tom 03/15/2012 18:57:01.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1471.1108 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users.WINDOWS.0\Application Data\DragToDiscUserNameF.txt
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Guest\WINDOWS
c:\documents and settings\Owner\WINDOWS
c:\documents and settings\Tom\g2mdlhlpx.exe
c:\documents and settings\Tom\Local Settings\Application Data\b9173f48\U
c:\documents and settings\Tom\Local Settings\Application Data\b9173f48\U\80000000.@
c:\documents and settings\Tom\Local Settings\Application Data\b9173f48\U\800000cb.@
c:\documents and settings\Tom\Local Settings\Application Data\b9173f48\U\800000cf.@
c:\documents and settings\Tom\Local Settings\Application Data\ilybnmel.exe
c:\windows.0\
c:\windows.0\$NtUninstallKB31136$\4033664211
c:\windows.0\system32\Packet.dll
c:\windows.0\system32\SET1E7.tmp
c:\windows.0\system32\SET1E9.tmp
c:\windows.0\system32\SET1ED.tmp
c:\windows.0\system32\SET1F5.tmp
c:\windows.0\system32\wpcap.dll
c:\windows.0\$NtUninstallKB31136$ . . . . Failed to delete
.
c:\windows.0\system32\drivers\DVDVRRdr_xp.sys . . . is infected!! . . . Failed to find a valid replacement.
c:\windows.0\system32\drivers\cdrom.sys was missing
Restored copy from - c:\windows.0\system32\dllcache\cdrom.sys
.
c:\windows.0\system32\drivers\Udfreadr.sys . . . is infected!!
.
Infected copy of c:\program files\Common Files\AOL\ACS\AOLAcsd.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{FFB3E3B2-9E42-4DFB-881F-E65F93D267FF}\RP227\A0038587.exe
.
Infected copy of c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{FFB3E3B2-9E42-4DFB-881F-E65F93D267FF}\RP227\A0038584.exe
.
Infected copy of c:\windows.0\wanmpsvc.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{FFB3E3B2-9E42-4DFB-881F-E65F93D267FF}\RP227\A0038585.exe
.
Infected copy of c:\windows.0\wanmpsvc.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{FFB3E3B2-9E42-4DFB-881F-E65F93D267FF}\RP227\A0038585.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_.cdrom
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2012-02-15 to 2012-03-15 )))))))))))))))))))))))))))))))
.
.
2012-03-15 23:07 . 2008-04-13 19:40 62976 -c–a-w- c:\windows.0\system32\dllcache\cdrom.sys
2012-03-15 23:07 . 2008-04-13 19:40 62976 —-a-w- c:\windows.0\system32\drivers\cdrom.sys
2012-03-09 14:20 . 2012-03-12 15:36 ——– d—–w- c:\windows.0\SxsCaPendDel
2012-03-09 14:00 . 2012-03-09 14:00 388096 —-a-r- c:\documents and settings\Tom\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-31 23:39 . 2011-05-16 02:16 414368 —-a-w- c:\windows.0\system32\FlashPlayerCPLApp.cpl
2012-01-29 20:22 . 2012-01-29 20:22 1461992 —-a-w- c:\windows.0\system32\WdfCoInstaller01009.dll
2012-01-29 20:22 . 2012-01-29 20:22 851176 —-a-w- c:\windows.0\system32\WinUSBCoInstaller2.dll
2012-01-29 20:09 . 2012-01-29 20:09 544656 —-a-w- c:\windows.0\system32\deployJava1.dll
2012-01-29 20:09 . 2007-05-07 01:46 128000 —-a-w- c:\windows.0\system32\javacpl.cpl
2012-01-29 20:06 . 2012-01-29 20:06 83316104 —-a-w- C:\jdk-7u1-windows-i586.exe
2012-01-29 20:03 . 2012-01-29 20:02 29561554 —-a-w- C:\installer_r16-windows.exe
2012-01-29 20:02 . 2012-01-29 20:02 84132744 —-a-w- C:\jdk-7u1-windows-x64.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\AOL Desktop 9.6\AOL.EXE" [2011-01-13 42320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malwarell\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [N/A]
spamsubtract.lnk - c:\program files\interMute\SpamSubtract\SpamSub.exe [2003-10-14 557056]
.
c:\documents and settings\Guest\Start Menu\Programs\Startup\
Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [N/A]
spamsubtract.lnk - c:\program files\interMute\SpamSubtract\SpamSub.exe [2003-10-14 557056]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [N/A]
spamsubtract.lnk - c:\program files\interMute\SpamSubtract\SpamSub.exe [2003-10-14 557056]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows.0\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows.0\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tom^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Tom\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows.0\pss\Adobe Gamma.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows.0\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 08:44 500208 ——w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 09:57 406992 —-a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows.0\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2010-03-08 07:27 41800 —-a-w- c:\program files\Common Files\AOL\1168712829\ee\AOLSoftware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2009-11-18 20:13 54576 —-a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpbdfawep]
2007-04-25 18:28 954368 —-a-w- c:\program files\HP\Dfawep\bin\hpbdfawep.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2005-03-23 21:26 217088 —-a-w- c:\program files\Microsoft IntelliPoint\point32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-06-14 21:18 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-06-14 21:18 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-17 02:12 3872080 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QveCtl2Tray]
2003-07-08 19:35 704512 —-a-w- c:\program files\Philips\Aurilium Sound Agent 2\805cpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2005-03-09 02:13 1695744 —-a-w- c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-05-04 18:59 252136 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
2006-10-12 03:41 95960 —-a-w- c:\progra~1\SYMNET~1\SNDMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\type32]
2005-03-15 07:46 196608 —-a-w- c:\program files\Microsoft IntelliType Pro\type32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2004-10-22 15:53 53248 —-a-w- c:\windows.0\system32\VTTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"wuauserv"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"winmgmt"=2 (0x2)
"WebClient"=2 (0x2)
"TermService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre1.5.0_10\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1168712829\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\1168712829\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\CreativesFiles\\Shareaza.exe"=
"c:\\WINDOWS.0\\system32\\dpvsetup.exe"=
"c:\\Program Files\\AOL 9.5\\waol.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AOL Desktop 9.6\\waol.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"12555:TCP"= 12555:TCP:shareaza
"12555:UDP"= 12555:UDP:Shareaza2
"6346:TCP"= 6346:TCP:shareaza3
"6346:UDP"= 6346:UDP:shareaza4
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"12777:TCP"= 12777:TCP:sha
"12777:UDP"= 12777:UDP:sah2
.
R0 viasraid;viasraid;c:\windows.0\system32\drivers\viasraid.sys [10/31/2003 4:22 PM 77312]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malwarell\mbamservice.exe [11/15/2011 10:52 AM 652360]
R3 MBAMProtector;MBAMProtector;c:\windows.0\system32\drivers\mbam.sys [4/9/2010 7:01 PM 20464]
R3 psa805;Aurilium Sound Agent 2 (WDM);c:\windows.0\system32\drivers\psa805.sys [10/12/2006 12:51 AM 417536]
R3 QsndEnum;QSound Virtual Audio Devices Bus Enumerator;c:\windows.0\system32\drivers\QsndEnum.sys [10/12/2006 12:51 AM 12800]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 AM 227232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-13 c:\windows.0\Tasks\AdobeAAMUpdater-1.0-BASEMENT-Tom.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-02-22 08:44]
.
2009-01-28 c:\windows.0\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8224905129.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 04:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://aol.com/
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: Download with &Shareaza - c:\creativesfiles\RazaWebHook32.dll/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\7tmtob3r.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - SweetIM Search
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
.
HKU-Default-Run-AOL Fast Start - c:\program files\AOL 9.1b\AOL.EXE
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-DesktopAlert - c:\program files\DesktopAlert\DesktopAlert.exe
MSConfigStartUp-mnumsg - c:\program files\MyShoppingGenie\mnumsg.exe
MSConfigStartUp-sniffer - c:\windows.0\Temp\_ex-08.exe
MSConfigStartUp-WNicVIllUbjiXg - c:\documents and settings\All Users.WINDOWS.0\Application Data\WNicVIllUbjiXg.exe
AddRemove-Elasto Mania - c:\progra~1\ELASTO~1\UNWISE.EXE
AddRemove-FreeFileViewer_is1 - c:\program files\FreeFileViewer\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-15 19:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\.AFS2K]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\.DVDVRRdr_xp]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\.UDFReadr]
"ImagePath"="\*"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3444)
c:\windows.0\system32\WININET.dll
c:\windows.0\system32\ieframe.dll
c:\windows.0\system32\webcheck.dll
c:\windows.0\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows.0\system32\PortableDeviceTypes.dll
c:\windows.0\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\windows.0\system32\imapi.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows.0\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows.0\wanmpsvc.exe
c:\program files\AOL Desktop 9.6\waol.exe
c:\program files\AOL Desktop 9.6\shellmon.exe
.
**************************************************************************
.
Completion time: 2012-03-15 19:19:38 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-15 23:19
.
Pre-Run: 102,001,303,552 bytes free
Post-Run: 102,007,963,648 bytes free
.
- - End Of File - - 3D06D1B22F2CFCDA3CB7644B549D25EF
  • Back door warning

    I regret to inform you that your machine is infected with a back door. This type of malware is particularly nasty in that it aims to steal sensitive information from its victim. At the very least, I advise you to cease using all Internet banking websites, change passwords to all sites with sensitive information from a clean computer, and phone your bank to inform them that you may be a victim of identity theft. As the remote attacker has access to this machine, do NOT change your passwords or make any transactions on this computer. It may be prudent to backup your information, reformat, and reinstall, as when dealing with back doors there is no guarantee your computer will ever be completely clean, regardless of what the logs indicate.

    If you opt to reformat, please let me know and I will point you in the right direction. Otherwise, if you wish to carry out the disinfection, please continue with the following instructions.

  • TDSSKiller

    Please download a fresh copy of TDSSKiller.zip

    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • When the window opens, click on Change parameters
    • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS file system”
    • Click OK
    • Press Start Scan
    • IMPORTANT: As we are only looking for a log of what is on the machine right now, choose to Skip whatever is found
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI