Jeff
I really hate this pc...last note was in italics, now this one is F*^&%()'n underlined....it won't stop
OK -
17:17:56.0453 0x0c4c TDSS rootkit removing tool 3.0.0.25 Feb 27 2014 15:23:02
17:18:14.0796 0x0c4c ============================================================
17:18:14.0796 0x0c4c Current date / time: 2014/03/15 17:18:14.0796
17:18:14.0796 0x0c4c SystemInfo:
17:18:14.0796 0x0c4c
17:18:14.0796 0x0c4c OS Version: 5.1.2600 ServicePack: 3.0
17:18:14.0796 0x0c4c Product type: Workstation
17:18:14.0796 0x0c4c ComputerName: OURS
17:18:14.0828 0x0c4c UserName: Owner
17:18:14.0828 0x0c4c Windows directory: C:\WINDOWS
17:18:14.0828 0x0c4c System windows directory: C:\WINDOWS
17:18:14.0828 0x0c4c Processor architecture: Intel x86
17:18:14.0828 0x0c4c Number of processors: 1
17:18:14.0828 0x0c4c Page size: 0x1000
17:18:14.0828 0x0c4c Boot type: Normal boot
17:18:14.0828 0x0c4c ============================================================
17:18:17.0828 0x0c4c KLMD registered as C:\WINDOWS\system32\drivers\92093950.sys
17:18:18.0125 0x0c4c System UUID: {10C057C9-779A-566A-24B2-13DA8FAF047C}
17:18:20.0078 0x0c4c Drive \Device\Harddisk0\DR0 - Size: 0xDF99E6000 (55.90 Gb), SectorSize: 0x200, Cylinders: 0x1E49, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054
17:18:20.0140 0x0c4c ============================================================
17:18:20.0140 0x0c4c \Device\Harddisk0\DR0:
17:18:20.0203 0x0c4c MBR partitions:
17:18:20.0203 0x0c4c \Device\Harddisk0\DR0\Partition1: MBR, Type 0xB, StartLBA 0x3F, BlocksNum 0xA8E181
17:18:20.0203 0x0c4c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xA8E1C0, BlocksNum 0x6539AC0
17:18:20.0203 0x0c4c ============================================================
17:18:20.0281 0x0c4c C: <-> \Device\Harddisk0\DR0\Partition2
17:18:20.0281 0x0c4c D: <-> \Device\Harddisk0\DR0\Partition1
17:18:20.0281 0x0c4c ============================================================
17:18:20.0281 0x0c4c Initialize success
17:18:20.0281 0x0c4c ============================================================
17:18:23.0625 0x0d00 ============================================================
17:18:23.0625 0x0d00 Scan started
17:18:23.0625 0x0d00 Mode: Manual;
17:18:23.0625 0x0d00 ============================================================
17:18:23.0625 0x0d00 KSN ping started
17:18:38.0890 0x0d00 KSN ping finished: true
17:18:42.0578 0x0d00 ================ Scan system memory ========================
17:18:42.0609 0x0d00 System memory - ok
17:18:42.0625 0x0d00 ================ Scan services =============================
17:18:47.0421 0x0d00 Abiosdsk - ok
17:18:47.0437 0x0d00 abp480n5 - ok
17:18:49.0796 0x0d00 [ 8FD99680A539792A30E97944FDAECF17, 594F8E0C3695400B0C09A797AF6BDFAC6F750ECD67D0EE803914C572B1DCC43C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:18:49.0953 0x0d00 ACPI - ok
17:18:54.0796 0x0d00 [ 9859C0F6936E723E4892D7141B1327D5, 5E8F6A2FC4DF2E5E92A1D66ECC2810E08B42B64E9CD0DF4AD3F78EA8558B90AF ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
17:18:54.0875 0x0d00 ACPIEC - ok
17:18:54.0890 0x0d00 adpu160m - ok
17:18:55.0093 0x0d00 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
17:18:55.0281 0x0d00 aec - ok
17:18:55.0437 0x0d00 [ 322D0E36693D6E24A2398BEE62A268CD, FB0BFF5846E50DBCC2826639318A6A1DE79EE7DEA2719ED74A5F6F44454E13D0 ] AFD C:\WINDOWS\System32\drivers\afd.sys
17:18:55.0578 0x0d00 AFD - ok
17:18:55.0593 0x0d00 Aha154x - ok
17:18:55.0609 0x0d00 aic78u2 - ok
17:18:55.0625 0x0d00 aic78xx - ok
17:18:57.0843 0x0d00 [ 8D6C30E515717248E0E52B85FD7AC466, 3B3DDCA0EE82D5292F4E69A028D33E941225014B6BD030F71F7F7EED808A7721 ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS
17:18:59.0859 0x0d00 ALCXWDM - ok
17:18:59.0953 0x0d00 [ A9A3DAA780CA6C9671A19D52456705B4, 67C959144B57AE0BBF1D82DBED197F32CDB06FECD883A80C441A0202FE83FAB4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
17:18:59.0968 0x0d00 Alerter - ok
17:19:00.0046 0x0d00 [ 8C515081584A38AA007909CD02020B3D, A5E13CA10F702928E0DE84C74D0EA8ACCB117FD76FBABC55220C75C4FFD596DC ] ALG C:\WINDOWS\System32\alg.exe
17:19:00.0046 0x0d00 ALG - ok
17:19:00.0078 0x0d00 AliIde - ok
17:19:00.0296 0x0d00 [ 8FCE268CDBDD83B23419D1F35F42C7B1, DF1A5097DC5B5C35427460E866E16ED25C3DDD9217065B26C3214A5674BE37DB ] AmdK7 C:\WINDOWS\system32\DRIVERS\amdk7.sys
17:19:00.0328 0x0d00 AmdK7 - ok
17:19:00.0359 0x0d00 amsint - ok
17:19:00.0375 0x0d00 AppMgmt - ok
17:19:00.0390 0x0d00 asc - ok
17:19:00.0406 0x0d00 asc3350p - ok
17:19:00.0421 0x0d00 asc3550 - ok
17:19:06.0812 0x0d00 [ D33C507942299753868204CC7642FA27, 4E7096D6F4B1176C4823540427219988AC9180E70954D3BF32A6C15ED1332670 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
17:19:07.0078 0x0d00 aspnet_state - ok
17:19:07.0187 0x0d00 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:19:07.0218 0x0d00 AsyncMac - ok
17:19:07.0453 0x0d00 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
17:19:07.0515 0x0d00 atapi - ok
17:19:07.0578 0x0d00 Atdisk - ok
17:19:07.0875 0x0d00 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:19:07.0968 0x0d00 Atmarpc - ok
17:19:08.0140 0x0d00 [ DEF7A7882BEC100FE0B2CE2549188F9D, 462C95B63D0A1058291A2DC8CBFCB13D7D74CCD1CA43B613A7EB43D49E3276F8 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
17:19:08.0140 0x0d00 AudioSrv - ok
17:19:08.0187 0x0d00 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
17:19:08.0218 0x0d00 audstub - ok
17:19:08.0328 0x0d00 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
17:19:08.0375 0x0d00 Beep - ok
17:19:09.0937 0x0d00 [ 574738F61FCA2935F5265DC4E5691314, 3C7CCF064397186C3A3863DD2370AB6414A61B330097DCA4F299CA7BBAA3D1B4 ] BITS C:\WINDOWS\system32\qmgr.dll
17:19:10.0250 0x0d00 BITS - ok
17:19:10.0328 0x0d00 [ A06CE3399D16DB864F55FAEB1F1927A9, 3430FA8552D91670D9FB0A921C735ADBE2DA7FF108C199DDEEF2FB2E50713AF3 ] Browser C:\WINDOWS\System32\browser.dll
17:19:10.0343 0x0d00 Browser - ok
17:19:10.0578 0x0d00 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
17:19:10.0640 0x0d00 cbidf2k - ok
17:19:10.0656 0x0d00 cd20xrnt - ok
17:19:10.0828 0x0d00 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
17:19:10.0843 0x0d00 Cdaudio - ok
17:19:11.0015 0x0d00 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
17:19:11.0046 0x0d00 Cdfs - ok
17:19:11.0218 0x0d00 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:19:11.0328 0x0d00 Cdrom - ok
17:19:11.0359 0x0d00 Changer - ok
17:19:11.0421 0x0d00 [ 1CFE720EB8D93A7158A4EBC3AB178BDE, 65D2A9D9A88F38D4AF323134C151BA0F4B3CD0F6A134AF86E7AC9D07319F1726 ] CiSvc C:\WINDOWS\system32\cisvc.exe
17:19:11.0453 0x0d00 CiSvc - ok
17:19:11.0671 0x0d00 [ 34CBE729F38138217F9C80212A2A0C82, A9FD7A758D12E0818A11BEEF1CE772FEFA8373E92EF6C0DA8628CD4572CC9A43 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
17:19:11.0703 0x0d00 ClipSrv - ok
17:19:12.0046 0x0d00 [ 3C4D595E7F9B747325AEF28B4ADCAAE5, 4A283F3E2E659DA996EC16BC8181E9F521BDFDFCF246D0E432D65D2672AC9629 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:19:12.0468 0x0d00 clr_optimization_v2.0.50727_32 - ok
17:19:12.0484 0x0d00 CmdIde - ok
17:19:12.0531 0x0d00 COMSysApp - ok
17:19:12.0562 0x0d00 Cpqarray - ok
17:19:12.0937 0x0d00 [ 3D4E199942E29207970E04315D02AD3B, 0825960894CF9C86CC8775BDD2A262948A09CA495AA7FE9F210FAF49E7086383 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
17:19:12.0968 0x0d00 CryptSvc - ok
17:19:12.0984 0x0d00 dac2w2k - ok
17:19:13.0000 0x0d00 dac960nt - ok
17:19:13.0390 0x0d00 [ 2589FE6015A316C0F5D5112B4DA7B509, 2753785BA07A1A7A25E275332F5F9F403F6E8CBF396FD0905D6BA84B98C403A6 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
17:19:13.0609 0x0d00 DcomLaunch - ok
17:19:13.0906 0x0d00 [ 5E38D7684A49CACFB752B046357E0589, F192AD4190BCFB6939A5CBC91648FE63168AF79A5E227A111DEAD6A92E42AB8D ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
17:19:13.0953 0x0d00 Dhcp - ok
17:19:13.0984 0x0d00 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
17:19:14.0000 0x0d00 Disk - ok
17:19:14.0000 0x0d00 dmadmin - ok
17:19:14.0171 0x0d00 [ D992FE1274BDE0F84AD826ACAE022A41, C82BD6561A14F2932A761F5883A787B99031250EE5E9B7B5714AA045545C9B99 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
17:19:14.0281 0x0d00 dmboot - ok
17:19:14.0343 0x0d00 [ 7C824CF7BBDE77D95C08005717A95F6F, A73CB323B7A6410C3D3F258BF204E716ADF8C84C9E4F6562C57AB73DAED8CCDE ] dmio C:\WINDOWS\system32\drivers\dmio.sys
17:19:14.0359 0x0d00 dmio - ok
17:19:14.0390 0x0d00 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
17:19:14.0390 0x0d00 dmload - ok
17:19:14.0421 0x0d00 [ 57EDEC2E5F59F0335E92F35184BC8631, 61F6F0DC2D1A6C61D5EF0D5CC4BE0FFC217F1E61FDA3EA9F704709293656600F ] dmserver C:\WINDOWS\System32\dmserver.dll
17:19:14.0437 0x0d00 dmserver - ok
17:19:14.0468 0x0d00 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
17:19:14.0484 0x0d00 DMusic - ok
17:19:14.0531 0x0d00 [ 474B4DC3983173E4B4C9740B0DAC98A6, C0B1B5B3A87529FFA93BCFCC2BC013A96CAD7F5049ED4D999E8D5D9AC91F95B7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
17:19:14.0531 0x0d00 Dnscache - ok
17:19:14.0640 0x0d00 [ 0F0F6E687E5E15579EF4DA8DD6945814, 5C32D88119EB1465B2D719BEE2E05888D1A73454B5E33F2D4928DA710F8BFBA3 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
17:19:14.0656 0x0d00 Dot3svc - ok
17:19:14.0671 0x0d00 dpti2o - ok
17:19:14.0703 0x0d00 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
17:19:14.0703 0x0d00 drmkaud - ok
17:19:14.0812 0x0d00 [ 2187855A7703ADEF0CEF9EE4285182CC, 8233CC11F637866C0074043835A785EA2B616739B6B1181B143A253CF2508CFD ] EapHost C:\WINDOWS\System32\eapsvc.dll
17:19:14.0812 0x0d00 EapHost - ok
17:19:14.0875 0x0d00 [ BC93B4A066477954555966D77FEC9ECB, 27F5B780175EF46DA102EE33F7F33559C8B40C077EEA4405D579D9507F4B1C23 ] ERSvc C:\WINDOWS\System32\ersvc.dll
17:19:14.0875 0x0d00 ERSvc - ok
17:19:14.0953 0x0d00 [ 0E776ED5F7CC9F94299E70461B7B8185, 22750B3829133D1D4BB3CE2FA6247BE2373B5D15A6ED1C8A71673AA1CE7D9530 ] Eventlog C:\WINDOWS\system32\services.exe
17:19:14.0968 0x0d00 Eventlog - ok
17:19:15.0031 0x0d00 [ 19A799805B24990867B00C120D300C3A, 3C8CB64BE0508B5136D4F4919DA665AB86366EFFFFDD890A9B27E7CE39DCF098 ] EventSystem C:\WINDOWS\System32\es.dll
17:19:15.0046 0x0d00 EventSystem - ok
17:19:15.0109 0x0d00 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
17:19:15.0125 0x0d00 Fastfat - ok
17:19:15.0203 0x0d00 [ 1926899BF9FFE2602B63074971700412, F5C48EDBE5C6507527630B49C95BAA9F1E47EACC5A910F2B9A4528733E81A966 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
17:19:15.0218 0x0d00 FastUserSwitchingCompatibility - ok
17:19:15.0296 0x0d00 [ E97D6A8684466DF94FF3BC24FB787A07, 89E5A6889E3C5AB9AD3E80FFC16DD608278F3ADC282048B40B60196336A5CBEB ] Fax C:\WINDOWS\system32\fxssvc.exe
17:19:15.0312 0x0d00 Fax - ok
17:19:15.0359 0x0d00 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
17:19:15.0375 0x0d00 Fdc - ok
17:19:15.0421 0x0d00 [ D45926117EB9FA946A6AF572FBE1CAA3, 4C94EF009D778BE0BDF8F812F026B96F91F641BE30AA2531427A5E63DBD280DA ] Fips C:\WINDOWS\system32\drivers\Fips.sys
17:19:15.0421 0x0d00 Fips - ok
17:19:15.0453 0x0d00 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
17:19:15.0453 0x0d00 Flpydisk - ok
17:19:15.0546 0x0d00 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
17:19:15.0562 0x0d00 FltMgr - ok
17:19:15.0718 0x0d00 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:19:15.0734 0x0d00 Fs_Rec - ok
17:19:15.0796 0x0d00 [ 6AC26732762483366C3969C9E4D2259D, FF2C9A23CC17F380093F0BEA955B1925794271C2FEA16B9B7639668E6999BAE3 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys