Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus hiding all my .exe files for my Anti-virus software


  • This topic is locked This topic is locked

#46
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hi!

Please run this tool:


Running TDSSKiller

Download the latest version of TDSSKiller from here and save it to your Desktop.


  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

    Posted Image
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

    Posted Image
  • Click the Start Scan button.

    Posted Image
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    Posted Image
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

    Posted Image
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
  • 0

Advertisements


#47
frogmusic

frogmusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
Good morning, here is the TDSS log:


09:39:48.0546 3472 TDSS rootkit removing tool 2.6.9.0 Oct 14 2011 11:33:24
09:39:49.0031 3472 ============================================================
09:39:49.0031 3472 Current date / time: 2011/10/16 09:39:49.0031
09:39:49.0031 3472 SystemInfo:
09:39:49.0031 3472
09:39:49.0031 3472 OS Version: 5.1.2600 ServicePack: 3.0
09:39:49.0031 3472 Product type: Workstation
09:39:49.0031 3472 ComputerName: SEANS_COMPUTER
09:39:49.0031 3472 UserName: Owner
09:39:49.0031 3472 Windows directory: C:\WINDOWS
09:39:49.0031 3472 System windows directory: C:\WINDOWS
09:39:49.0031 3472 Processor architecture: Intel x86
09:39:49.0031 3472 Number of processors: 2
09:39:49.0031 3472 Page size: 0x1000
09:39:49.0031 3472 Boot type: Normal boot
09:39:49.0031 3472 ============================================================
09:39:49.0812 3472 Initialize success
09:39:56.0234 7752 ============================================================
09:39:56.0234 7752 Scan started
09:39:56.0234 7752 Mode: Manual; SigCheck; TDLFS;
09:39:56.0234 7752 ============================================================
09:39:56.0750 7752 .redbook - ok
09:39:56.0875 7752 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys
09:39:57.0718 7752 61883 - ok
09:39:57.0796 7752 Abiosdsk - ok
09:39:57.0828 7752 abp480n5 - ok
09:39:57.0875 7752 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
09:39:57.0968 7752 ACPI - ok
09:39:58.0062 7752 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
09:39:58.0156 7752 ACPIEC - ok
09:39:58.0187 7752 adpu160m - ok
09:39:58.0250 7752 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
09:39:58.0328 7752 aec - ok
09:39:58.0421 7752 Afc (a7b8a3a79d35215d798a300df49ed23f) C:\WINDOWS\system32\drivers\Afc.sys
09:39:58.0437 7752 Afc ( UnsignedFile.Multi.Generic ) - warning
09:39:58.0437 7752 Afc - detected UnsignedFile.Multi.Generic (1)
09:39:58.0484 7752 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
09:39:58.0546 7752 AFD - ok
09:39:58.0578 7752 Aha154x - ok
09:39:58.0593 7752 aic78u2 - ok
09:39:58.0609 7752 aic78xx - ok
09:39:58.0625 7752 AliIde - ok
09:39:58.0640 7752 amsint - ok
09:39:58.0718 7752 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
09:39:58.0812 7752 Arp1394 - ok
09:39:58.0812 7752 asc - ok
09:39:58.0828 7752 asc3350p - ok
09:39:58.0828 7752 asc3550 - ok
09:39:58.0843 7752 asusgsb - ok
09:39:58.0906 7752 ASUSVRC (94442e3029ff6c9f08140fe6718af4fb) C:\WINDOWS\system32\DRIVERS\AsusVRC.sys
09:39:58.0937 7752 ASUSVRC ( UnsignedFile.Multi.Generic ) - warning
09:39:58.0937 7752 ASUSVRC - detected UnsignedFile.Multi.Generic (1)
09:39:58.0968 7752 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
09:39:59.0062 7752 AsyncMac - ok
09:39:59.0093 7752 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
09:39:59.0187 7752 atapi - ok
09:39:59.0281 7752 AtcL001 (f732284e3ca19b38239853e2711041d4) C:\WINDOWS\system32\DRIVERS\l151x86.sys
09:39:59.0328 7752 AtcL001 - ok
09:39:59.0343 7752 Atdisk - ok
09:39:59.0421 7752 atksgt (3c4b9850a2631c2263507400d029057b) C:\WINDOWS\system32\DRIVERS\atksgt.sys
09:39:59.0531 7752 atksgt - ok
09:39:59.0578 7752 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
09:39:59.0671 7752 Atmarpc - ok
09:39:59.0765 7752 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
09:39:59.0859 7752 audstub - ok
09:39:59.0921 7752 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys
09:40:00.0000 7752 Avc - ok
09:40:00.0093 7752 BCM42RLY (438179abe9b7a922a21b8d6369ff52ff) C:\WINDOWS\System32\BCM42RLY.SYS
09:40:00.0125 7752 BCM42RLY ( UnsignedFile.Multi.Generic ) - warning
09:40:00.0125 7752 BCM42RLY - detected UnsignedFile.Multi.Generic (1)
09:40:00.0171 7752 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
09:40:00.0250 7752 Beep - ok
09:40:00.0328 7752 CamDrL (0f5ca31bb3fdb5c1e63c170cfbecc93b) C:\WINDOWS\system32\DRIVERS\Camdrl.sys
09:40:00.0406 7752 CamDrL - ok
09:40:00.0406 7752 catchme - ok
09:40:00.0437 7752 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
09:40:00.0515 7752 cbidf2k - ok
09:40:00.0593 7752 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
09:40:00.0687 7752 CCDECODE - ok
09:40:00.0734 7752 cd20xrnt - ok
09:40:00.0781 7752 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
09:40:00.0875 7752 Cdaudio - ok
09:40:00.0984 7752 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
09:40:01.0078 7752 Cdfs - ok
09:40:01.0093 7752 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
09:40:01.0187 7752 Cdrom - ok
09:40:01.0265 7752 Changer - ok
09:40:01.0281 7752 CmdIde - ok
09:40:01.0312 7752 Cpqarray - ok
09:40:01.0343 7752 dac2w2k - ok
09:40:01.0359 7752 dac960nt - ok
09:40:01.0421 7752 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
09:40:01.0515 7752 Disk - ok
09:40:01.0578 7752 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
09:40:01.0687 7752 dmboot - ok
09:40:01.0796 7752 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
09:40:01.0890 7752 dmio - ok
09:40:01.0953 7752 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
09:40:02.0031 7752 dmload - ok
09:40:02.0078 7752 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
09:40:02.0156 7752 DMusic - ok
09:40:02.0234 7752 dpti2o - ok
09:40:02.0296 7752 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
09:40:02.0359 7752 drmkaud - ok
09:40:02.0406 7752 EIO (0daf3544804650526751c478aeccce63) C:\WINDOWS\system32\drivers\EIO.sys
09:40:02.0437 7752 EIO ( UnsignedFile.Multi.Generic ) - warning
09:40:02.0437 7752 EIO - detected UnsignedFile.Multi.Generic (1)
09:40:02.0468 7752 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
09:40:02.0546 7752 Fastfat - ok
09:40:02.0609 7752 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
09:40:02.0687 7752 Fdc - ok
09:40:02.0765 7752 FilterService (a75ddc492d2d1d6558ad8003a4adb73a) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
09:40:02.0781 7752 FilterService - ok
09:40:02.0828 7752 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
09:40:02.0906 7752 Fips - ok
09:40:02.0937 7752 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
09:40:03.0031 7752 Flpydisk - ok
09:40:03.0093 7752 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
09:40:03.0171 7752 FltMgr - ok
09:40:03.0234 7752 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
09:40:03.0312 7752 Fs_Rec - ok
09:40:03.0359 7752 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
09:40:03.0437 7752 Ftdisk - ok
09:40:03.0531 7752 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
09:40:03.0609 7752 Gpc - ok
09:40:03.0687 7752 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
09:40:03.0781 7752 HDAudBus - ok
09:40:03.0875 7752 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
09:40:03.0953 7752 hidusb - ok
09:40:04.0000 7752 hpn - ok
09:40:04.0062 7752 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
09:40:04.0109 7752 HTTP - ok
09:40:04.0171 7752 i2omgmt - ok
09:40:04.0187 7752 i2omp - ok
09:40:04.0218 7752 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
09:40:04.0312 7752 i8042prt - ok
09:40:04.0343 7752 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
09:40:04.0437 7752 Imapi - ok
09:40:04.0484 7752 ini910u - ok
09:40:04.0625 7752 IntcAzAudAddService (cbddab14249b2f05407fc09ab8fffb88) C:\WINDOWS\system32\drivers\RtkHDAud.sys
09:40:04.0875 7752 IntcAzAudAddService - ok
09:40:04.0906 7752 IntelIde - ok
09:40:04.0984 7752 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
09:40:05.0062 7752 intelppm - ok
09:40:05.0093 7752 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
09:40:05.0187 7752 Ip6Fw - ok
09:40:05.0234 7752 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
09:40:05.0312 7752 IpFilterDriver - ok
09:40:05.0406 7752 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
09:40:05.0484 7752 IpInIp - ok
09:40:05.0515 7752 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
09:40:05.0593 7752 IpNat - ok
09:40:05.0703 7752 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
09:40:05.0796 7752 IPSec - ok
09:40:05.0843 7752 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
09:40:05.0921 7752 IRENUM - ok
09:40:05.0953 7752 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
09:40:06.0046 7752 isapnp - ok
09:40:06.0093 7752 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
09:40:06.0171 7752 Kbdclass - ok
09:40:06.0234 7752 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
09:40:06.0296 7752 kbdhid - ok
09:40:06.0359 7752 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys
09:40:06.0546 7752 klmd23 - ok
09:40:06.0640 7752 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
09:40:06.0734 7752 kmixer - ok
09:40:06.0828 7752 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
09:40:06.0890 7752 KSecDD - ok
09:40:06.0921 7752 lbrtfdc - ok
09:40:06.0984 7752 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
09:40:07.0015 7752 lirsgt - ok
09:40:07.0062 7752 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\system32\Drivers\LVPr2Mon.sys
09:40:07.0109 7752 LVPr2Mon - ok
09:40:07.0140 7752 LVRS (87ecce893d8aec5a9337b917742d339c) C:\WINDOWS\system32\DRIVERS\lvrs.sys
09:40:07.0171 7752 LVRS - ok
09:40:07.0203 7752 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\WINDOWS\system32\drivers\LVUSBSta.sys
09:40:07.0234 7752 LVUSBSta - ok
09:40:07.0390 7752 LVUVC (291f69b3dda0f033d2490c5ba5179f7c) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
09:40:07.0687 7752 LVUVC - ok
09:40:07.0796 7752 MCSTRM (5bb01b9f582259d1fb7653c5c1da3653) C:\WINDOWS\system32\drivers\MCSTRM.sys
09:40:07.0812 7752 MCSTRM ( UnsignedFile.Multi.Generic ) - warning
09:40:07.0812 7752 MCSTRM - detected UnsignedFile.Multi.Generic (1)
09:40:07.0859 7752 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
09:40:07.0937 7752 mnmdd - ok
09:40:07.0968 7752 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
09:40:08.0062 7752 Modem - ok
09:40:08.0125 7752 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
09:40:08.0203 7752 Mouclass - ok
09:40:08.0312 7752 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
09:40:08.0375 7752 mouhid - ok
09:40:08.0468 7752 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
09:40:08.0546 7752 MountMgr - ok
09:40:08.0625 7752 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
09:40:08.0656 7752 MpFilter - ok
09:40:08.0796 7752 MpKsl68b90787 (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A5B8BF60-E6E2-45CD-9082-F1D0A95F86FB}\MpKsl68b90787.sys
09:40:08.0812 7752 MpKsl68b90787 - ok
09:40:08.0890 7752 mraid35x - ok
09:40:08.0937 7752 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
09:40:09.0031 7752 MRxDAV - ok
09:40:09.0078 7752 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
09:40:09.0140 7752 MRxSmb - ok
09:40:09.0187 7752 MSDV (1477849772712bac69c144dcf2c9ce81) C:\WINDOWS\system32\DRIVERS\msdv.sys
09:40:09.0281 7752 MSDV - ok
09:40:09.0343 7752 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
09:40:09.0421 7752 Msfs - ok
09:40:09.0468 7752 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
09:40:09.0546 7752 MSKSSRV - ok
09:40:09.0656 7752 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
09:40:09.0718 7752 MSPCLOCK - ok
09:40:09.0812 7752 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
09:40:09.0906 7752 MSPQM - ok
09:40:09.0921 7752 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
09:40:10.0000 7752 mssmbios - ok
09:40:10.0078 7752 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
09:40:10.0156 7752 MSTEE - ok
09:40:10.0250 7752 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
09:40:10.0281 7752 MTsensor - ok
09:40:10.0375 7752 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
09:40:10.0421 7752 Mup - ok
09:40:10.0453 7752 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
09:40:10.0546 7752 NABTSFEC - ok
09:40:10.0656 7752 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
09:40:10.0750 7752 NDIS - ok
09:40:10.0843 7752 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
09:40:10.0937 7752 NdisIP - ok
09:40:10.0984 7752 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
09:40:11.0015 7752 NdisTapi - ok
09:40:11.0078 7752 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
09:40:11.0156 7752 Ndisuio - ok
09:40:11.0203 7752 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
09:40:11.0296 7752 NdisWan - ok
09:40:11.0390 7752 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
09:40:11.0421 7752 NDProxy - ok
09:40:11.0468 7752 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
09:40:11.0546 7752 NetBIOS - ok
09:40:11.0593 7752 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
09:40:11.0687 7752 NetBT - ok
09:40:11.0781 7752 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
09:40:11.0859 7752 NIC1394 - ok
09:40:11.0953 7752 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
09:40:12.0031 7752 Npfs - ok
09:40:12.0062 7752 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
09:40:12.0171 7752 Ntfs - ok
09:40:12.0265 7752 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
09:40:12.0343 7752 Null - ok
09:40:12.0921 7752 nv (b488eda5f3e9f8467fe999b00ccb146d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
09:40:13.0328 7752 nv ( UnsignedFile.Multi.Generic ) - warning
09:40:13.0328 7752 nv - detected UnsignedFile.Multi.Generic (1)
09:40:13.0437 7752 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
09:40:13.0531 7752 NwlnkFlt - ok
09:40:13.0640 7752 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
09:40:13.0734 7752 NwlnkFwd - ok
09:40:13.0796 7752 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
09:40:13.0875 7752 ohci1394 - ok
09:40:13.0921 7752 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
09:40:14.0015 7752 Parport - ok
09:40:14.0062 7752 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
09:40:14.0140 7752 PartMgr - ok
09:40:14.0203 7752 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
09:40:14.0281 7752 ParVdm - ok
09:40:14.0359 7752 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
09:40:14.0437 7752 PCI - ok
09:40:14.0500 7752 PCIDump - ok
09:40:14.0562 7752 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
09:40:14.0625 7752 PCIIde - ok
09:40:14.0703 7752 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
09:40:14.0781 7752 Pcmcia - ok
09:40:14.0843 7752 PDCOMP - ok
09:40:14.0843 7752 PDFRAME - ok
09:40:14.0890 7752 PDRELI - ok
09:40:14.0921 7752 PDRFRAME - ok
09:40:14.0921 7752 perc2 - ok
09:40:14.0953 7752 perc2hib - ok
09:40:15.0015 7752 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
09:40:15.0109 7752 PptpMiniport - ok
09:40:15.0140 7752 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
09:40:15.0234 7752 PSched - ok
09:40:15.0281 7752 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
09:40:15.0375 7752 Ptilink - ok
09:40:15.0453 7752 pxkbf (0c738845c7c12c45f05b127edff2cc87) C:\WINDOWS\system32\drivers\pxkbf.sys
09:40:15.0468 7752 pxkbf - ok
09:40:15.0515 7752 pxrts (04d1c97a0818f9378eeaa793a09f8202) C:\WINDOWS\system32\drivers\pxrts.sys
09:40:15.0578 7752 pxrts - ok
09:40:15.0609 7752 pxscan (e6e1f9f717feab3e16c3b160b17e6855) C:\WINDOWS\system32\drivers\pxscan.sys
09:40:15.0625 7752 pxscan - ok
09:40:15.0640 7752 ql1080 - ok
09:40:15.0656 7752 Ql10wnt - ok
09:40:15.0687 7752 ql12160 - ok
09:40:15.0703 7752 ql1240 - ok
09:40:15.0703 7752 ql1280 - ok
09:40:15.0781 7752 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
09:40:15.0859 7752 RasAcd - ok
09:40:15.0937 7752 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
09:40:16.0015 7752 Rasl2tp - ok
09:40:16.0062 7752 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
09:40:16.0140 7752 RasPppoe - ok
09:40:16.0203 7752 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
09:40:16.0281 7752 Raspti - ok
09:40:16.0343 7752 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
09:40:16.0421 7752 Rdbss - ok
09:40:16.0515 7752 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
09:40:16.0593 7752 RDPCDD - ok
09:40:16.0656 7752 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
09:40:16.0703 7752 RDPWD - ok
09:40:16.0812 7752 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
09:40:16.0890 7752 redbook - ok
09:40:16.0937 7752 RT73 (cb20f16afdba63707fb971e0922edec1) C:\WINDOWS\system32\DRIVERS\rt73.sys
09:40:17.0000 7752 RT73 ( UnsignedFile.Multi.Generic ) - warning
09:40:17.0000 7752 RT73 - detected UnsignedFile.Multi.Generic (1)
09:40:17.0078 7752 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
09:40:17.0156 7752 Secdrv - ok
09:40:17.0250 7752 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
09:40:17.0328 7752 serenum - ok
09:40:17.0375 7752 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
09:40:17.0468 7752 Serial - ok
09:40:17.0578 7752 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
09:40:17.0656 7752 Sfloppy - ok
09:40:17.0687 7752 Simbad - ok
09:40:17.0750 7752 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
09:40:17.0843 7752 SLIP - ok
09:40:17.0890 7752 Sparrow - ok
09:40:17.0968 7752 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
09:40:18.0046 7752 splitter - ok
09:40:18.0078 7752 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
09:40:18.0171 7752 sr - ok
09:40:18.0250 7752 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
09:40:18.0296 7752 Srv - ok
09:40:18.0343 7752 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
09:40:18.0437 7752 streamip - ok
09:40:18.0484 7752 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
09:40:18.0546 7752 swenum - ok
09:40:18.0593 7752 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
09:40:18.0687 7752 swmidi - ok
09:40:18.0734 7752 symc810 - ok
09:40:18.0734 7752 symc8xx - ok
09:40:18.0781 7752 sym_hi - ok
09:40:18.0796 7752 sym_u3 - ok
09:40:18.0843 7752 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
09:40:18.0921 7752 sysaudio - ok
09:40:19.0000 7752 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
09:40:19.0062 7752 Tcpip - ok
09:40:19.0125 7752 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
09:40:19.0203 7752 TDPIPE - ok
09:40:19.0250 7752 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
09:40:19.0328 7752 TDTCP - ok
09:40:19.0390 7752 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
09:40:19.0484 7752 TermDD - ok
09:40:19.0515 7752 TosIde - ok
09:40:19.0578 7752 TrueSight (4bfab463e1d1f20dfa83a04a9698934d) c:\windows\system32\drivers\TrueSight.sys
09:40:19.0656 7752 TrueSight ( UnsignedFile.Multi.Generic ) - warning
09:40:19.0656 7752 TrueSight - detected UnsignedFile.Multi.Generic (1)
09:40:19.0718 7752 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
09:40:19.0812 7752 Udfs - ok
09:40:19.0843 7752 ultra - ok
09:40:19.0921 7752 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
09:40:20.0015 7752 Update - ok
09:40:20.0093 7752 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
09:40:20.0187 7752 usbaudio - ok
09:40:20.0234 7752 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
09:40:20.0328 7752 usbccgp - ok
09:40:20.0406 7752 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
09:40:20.0468 7752 usbehci - ok
09:40:20.0546 7752 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
09:40:20.0625 7752 usbhub - ok
09:40:20.0703 7752 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
09:40:20.0781 7752 usbprint - ok
09:40:20.0859 7752 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
09:40:20.0921 7752 usbscan - ok
09:40:20.0953 7752 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:40:21.0046 7752 USBSTOR - ok
09:40:21.0109 7752 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
09:40:21.0171 7752 usbuhci - ok
09:40:21.0203 7752 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
09:40:21.0296 7752 VgaSave - ok
09:40:21.0296 7752 ViaIde - ok
09:40:21.0312 7752 Video3D - ok
09:40:21.0328 7752 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
09:40:21.0406 7752 VolSnap - ok
09:40:21.0453 7752 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
09:40:21.0546 7752 Wanarp - ok
09:40:21.0578 7752 WDICA - ok
09:40:21.0593 7752 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
09:40:21.0687 7752 wdmaud - ok
09:40:21.0781 7752 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
09:40:21.0828 7752 WpdUsb - ok
09:40:21.0890 7752 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
09:40:21.0968 7752 WSTCODEC - ok
09:40:22.0031 7752 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
09:40:22.0093 7752 WudfPf - ok
09:40:22.0140 7752 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
09:40:22.0187 7752 WudfRd - ok
09:40:22.0203 7752 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
09:40:22.0328 7752 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
09:40:22.0328 7752 \Device\Harddisk0\DR0 - detected TDSS File System (1)
09:40:22.0328 7752 Boot (0x1200) (3182683fadcc1894a1049495efce6d58) \Device\Harddisk0\DR0\Partition0
09:40:22.0328 7752 \Device\Harddisk0\DR0\Partition0 - ok
09:40:22.0328 7752 ============================================================
09:40:22.0328 7752 Scan finished
09:40:22.0328 7752 ============================================================
09:40:22.0437 7112 Detected object count: 9
09:40:22.0437 7112 Actual detected object count: 9
09:40:31.0906 7112 Afc ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0906 7112 Afc ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0906 7112 ASUSVRC ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0906 7112 ASUSVRC ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0921 7112 BCM42RLY ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0921 7112 BCM42RLY ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0921 7112 EIO ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0921 7112 EIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0921 7112 MCSTRM ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0921 7112 MCSTRM ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0921 7112 nv ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0921 7112 nv ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0921 7112 RT73 ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0921 7112 RT73 ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0921 7112 TrueSight ( UnsignedFile.Multi.Generic ) - skipped by user
09:40:31.0921 7112 TrueSight ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:40:31.0921 7112 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
09:40:31.0921 7112 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
09:40:36.0109 5928 Deinitialize success
  • 0

#48
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hi!

Please run this utility for me:


Running aswMBR.exe

Download aswMBR.exe ( 1.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image
  • 0

#49
frogmusic

frogmusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
Goodmorning, here is the aswMBR log:

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-17 09:05:30
-----------------------------
09:05:30.640 OS Version: Windows 5.1.2600 Service Pack 3
09:05:30.640 Number of processors: 2 586 0xF0B
09:05:30.640 ComputerName: SEANS_COMPUTER UserName: Owner
09:05:30.984 Initialize success
09:05:38.734 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-12
09:05:38.734 Disk 0 Vendor: MAXTOR_STM3160815AS 3.AAD Size: 152627MB BusType: 3
09:05:40.734 Disk 0 MBR read successfully
09:05:40.734 Disk 0 MBR scan
09:05:40.734 Disk 0 Windows XP default MBR code
09:05:40.734 Disk 0 scanning sectors +312560640
09:05:40.796 Disk 0 scanning C:\WINDOWS\system32\drivers
09:05:46.609 Service scanning
09:05:46.875 Service .redbook \* **LOCKED** 123
09:05:46.953 Service MpKslccae4844 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{940B3290-DB95-4FD2-8809-C26C6C6E8C7C}\MpKslccae4844.sys **LOCKED** 32
09:05:47.515 Modules scanning
09:05:51.500 Disk 0 trace - called modules:
09:05:51.515 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
09:05:51.515 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a98cab8]
09:05:52.015 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\00000070[0x8a9d69e8]
09:05:52.015 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-12[0x8a9d5d98]
09:05:52.015 Scan finished successfully
09:06:17.015 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
09:06:17.015 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
  • 0

#50
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hi!

Can you please zip up the following file and attach it for me in your next reply:

C:\Documents and Settings\Owner\Desktop\MBR.dat
  • 0

#51
frogmusic

frogmusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
Here ya go...
  • 0

#52
frogmusic

frogmusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
Oops, forgot something...

Attached Files

  • Attached File  MBR.zip   498bytes   37 downloads

  • 0

#53
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hi!

Your logs seem to indicate that you still maybe infected with a TDSS infection, but not all of the tools we are using are detecting this, and the ones that are, aren't capable of fixing it.

I'm going to provide instructions for fixing the MBR in the Recovery Console, and then see where that leaves us.

Reboot your machine and when the Boot Menu flashes up - select "Microsoft Windows Recovery Console"
(you need to be very fast with the arrow key as you only have a couple of seconds before it defaults to the windows XP bootup)

Posted Image

Posted Image

When you get to the above screen, take note of the number that references your operating system.
If it's '1' like the picture above, type 1 and press Enter


Posted Image

Next type FIXMBR

Posted Image

If it ask if you're sure you want to write a new MBR, answer 'Y'

Then type EXIT to reboot the machine.

Let me know how that goes and then delete the current copy of TDSSKiller from your desktop, and download a new version, followed by a new scan with it.


Running TDSSKiller

Download the latest version of TDSSKiller from here and save it to your Desktop.


  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

    Posted Image
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

    Posted Image
  • Click the Start Scan button.

    Posted Image
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    Posted Image
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

    Posted Image
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
  • 0

#54
frogmusic

frogmusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
Ok I did the fixmbr stuff, and downloaded a new Tdss killer. Here is the log:

11:40:41.0093 1104 TDSS rootkit removing tool 2.6.10.0 Oct 17 2011 15:43:23
11:40:41.0546 1104 ============================================================
11:40:41.0546 1104 Current date / time: 2011/10/17 11:40:41.0546
11:40:41.0546 1104 SystemInfo:
11:40:41.0546 1104
11:40:41.0546 1104 OS Version: 5.1.2600 ServicePack: 3.0
11:40:41.0546 1104 Product type: Workstation
11:40:41.0546 1104 ComputerName: SEANS_COMPUTER
11:40:41.0546 1104 UserName: Owner
11:40:41.0546 1104 Windows directory: C:\WINDOWS
11:40:41.0546 1104 System windows directory: C:\WINDOWS
11:40:41.0546 1104 Processor architecture: Intel x86
11:40:41.0546 1104 Number of processors: 2
11:40:41.0546 1104 Page size: 0x1000
11:40:41.0546 1104 Boot type: Normal boot
11:40:41.0546 1104 ============================================================
11:40:42.0250 1104 Initialize success
11:40:50.0171 3056 ============================================================
11:40:50.0171 3056 Scan started
11:40:50.0171 3056 Mode: Manual; SigCheck; TDLFS;
11:40:50.0171 3056 ============================================================
11:40:50.0718 3056 .redbook - ok
11:40:50.0828 3056 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys
11:40:51.0828 3056 61883 - ok
11:40:51.0890 3056 Abiosdsk - ok
11:40:51.0906 3056 abp480n5 - ok
11:40:51.0968 3056 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:40:52.0046 3056 ACPI - ok
11:40:52.0109 3056 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
11:40:52.0203 3056 ACPIEC - ok
11:40:52.0250 3056 adpu160m - ok
11:40:52.0281 3056 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
11:40:52.0390 3056 aec - ok
11:40:52.0437 3056 Afc (a7b8a3a79d35215d798a300df49ed23f) C:\WINDOWS\system32\drivers\Afc.sys
11:40:52.0453 3056 Afc ( UnsignedFile.Multi.Generic ) - warning
11:40:52.0453 3056 Afc - detected UnsignedFile.Multi.Generic (1)
11:40:52.0500 3056 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
11:40:52.0546 3056 AFD - ok
11:40:52.0562 3056 Aha154x - ok
11:40:52.0578 3056 aic78u2 - ok
11:40:52.0593 3056 aic78xx - ok
11:40:52.0609 3056 AliIde - ok
11:40:52.0625 3056 amsint - ok
11:40:52.0687 3056 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
11:40:52.0781 3056 Arp1394 - ok
11:40:52.0828 3056 asc - ok
11:40:52.0859 3056 asc3350p - ok
11:40:52.0890 3056 asc3550 - ok
11:40:52.0937 3056 asusgsb - ok
11:40:52.0984 3056 ASUSVRC (94442e3029ff6c9f08140fe6718af4fb) C:\WINDOWS\system32\DRIVERS\AsusVRC.sys
11:40:53.0015 3056 ASUSVRC ( UnsignedFile.Multi.Generic ) - warning
11:40:53.0015 3056 ASUSVRC - detected UnsignedFile.Multi.Generic (1)
11:40:53.0062 3056 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:40:53.0140 3056 AsyncMac - ok
11:40:53.0187 3056 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
11:40:53.0281 3056 atapi - ok
11:40:53.0359 3056 AtcL001 (f732284e3ca19b38239853e2711041d4) C:\WINDOWS\system32\DRIVERS\l151x86.sys
11:40:53.0421 3056 AtcL001 - ok
11:40:53.0468 3056 Atdisk - ok
11:40:53.0531 3056 atksgt (3c4b9850a2631c2263507400d029057b) C:\WINDOWS\system32\DRIVERS\atksgt.sys
11:40:53.0578 3056 atksgt - ok
11:40:53.0640 3056 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:40:53.0734 3056 Atmarpc - ok
11:40:53.0828 3056 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
11:40:53.0906 3056 audstub - ok
11:40:53.0953 3056 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys
11:40:54.0046 3056 Avc - ok
11:40:54.0109 3056 BCM42RLY (438179abe9b7a922a21b8d6369ff52ff) C:\WINDOWS\System32\BCM42RLY.SYS
11:40:54.0125 3056 BCM42RLY ( UnsignedFile.Multi.Generic ) - warning
11:40:54.0125 3056 BCM42RLY - detected UnsignedFile.Multi.Generic (1)
11:40:54.0171 3056 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
11:40:54.0250 3056 Beep - ok
11:40:54.0375 3056 CamDrL (0f5ca31bb3fdb5c1e63c170cfbecc93b) C:\WINDOWS\system32\DRIVERS\Camdrl.sys
11:40:54.0468 3056 CamDrL - ok
11:40:54.0468 3056 catchme - ok
11:40:54.0515 3056 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
11:40:54.0609 3056 cbidf2k - ok
11:40:54.0671 3056 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
11:40:54.0765 3056 CCDECODE - ok
11:40:54.0812 3056 cd20xrnt - ok
11:40:54.0859 3056 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
11:40:54.0968 3056 Cdaudio - ok
11:40:55.0062 3056 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
11:40:55.0140 3056 Cdfs - ok
11:40:55.0218 3056 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:40:55.0312 3056 Cdrom - ok
11:40:55.0359 3056 Changer - ok
11:40:55.0375 3056 CmdIde - ok
11:40:55.0406 3056 Cpqarray - ok
11:40:55.0421 3056 dac2w2k - ok
11:40:55.0453 3056 dac960nt - ok
11:40:55.0515 3056 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
11:40:55.0593 3056 Disk - ok
11:40:55.0656 3056 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
11:40:55.0765 3056 dmboot - ok
11:40:55.0843 3056 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
11:40:55.0937 3056 dmio - ok
11:40:55.0953 3056 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
11:40:56.0046 3056 dmload - ok
11:40:56.0125 3056 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
11:40:56.0203 3056 DMusic - ok
11:40:56.0250 3056 dpti2o - ok
11:40:56.0296 3056 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
11:40:56.0375 3056 drmkaud - ok
11:40:56.0453 3056 EIO (0daf3544804650526751c478aeccce63) C:\WINDOWS\system32\drivers\EIO.sys
11:40:56.0484 3056 EIO ( UnsignedFile.Multi.Generic ) - warning
11:40:56.0484 3056 EIO - detected UnsignedFile.Multi.Generic (1)
11:40:56.0578 3056 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
11:40:56.0656 3056 Fastfat - ok
11:40:56.0718 3056 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
11:40:56.0796 3056 Fdc - ok
11:40:56.0859 3056 FilterService (a75ddc492d2d1d6558ad8003a4adb73a) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
11:40:56.0875 3056 FilterService - ok
11:40:56.0906 3056 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
11:40:57.0000 3056 Fips - ok
11:40:57.0015 3056 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
11:40:57.0109 3056 Flpydisk - ok
11:40:57.0187 3056 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
11:40:57.0265 3056 FltMgr - ok
11:40:57.0343 3056 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:40:57.0421 3056 Fs_Rec - ok
11:40:57.0468 3056 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:40:57.0562 3056 Ftdisk - ok
11:40:57.0656 3056 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:40:57.0734 3056 Gpc - ok
11:40:57.0828 3056 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
11:40:57.0937 3056 HDAudBus - ok
11:40:57.0984 3056 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:40:58.0062 3056 hidusb - ok
11:40:58.0093 3056 hpn - ok
11:40:58.0140 3056 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
11:40:58.0218 3056 HTTP - ok
11:40:58.0265 3056 i2omgmt - ok
11:40:58.0296 3056 i2omp - ok
11:40:58.0328 3056 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:40:58.0406 3056 i8042prt - ok
11:40:58.0453 3056 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
11:40:58.0546 3056 Imapi - ok
11:40:58.0593 3056 ini910u - ok
11:40:58.0734 3056 IntcAzAudAddService (cbddab14249b2f05407fc09ab8fffb88) C:\WINDOWS\system32\drivers\RtkHDAud.sys
11:40:58.0937 3056 IntcAzAudAddService - ok
11:40:59.0031 3056 IntelIde - ok
11:40:59.0078 3056 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
11:40:59.0156 3056 intelppm - ok
11:40:59.0203 3056 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
11:40:59.0296 3056 Ip6Fw - ok
11:40:59.0343 3056 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:40:59.0421 3056 IpFilterDriver - ok
11:40:59.0484 3056 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:40:59.0578 3056 IpInIp - ok
11:40:59.0593 3056 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:40:59.0687 3056 IpNat - ok
11:40:59.0781 3056 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:40:59.0875 3056 IPSec - ok
11:40:59.0937 3056 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
11:41:00.0015 3056 IRENUM - ok
11:41:00.0078 3056 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:41:00.0171 3056 isapnp - ok
11:41:00.0218 3056 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:41:00.0296 3056 Kbdclass - ok
11:41:00.0390 3056 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
11:41:00.0468 3056 kbdhid - ok
11:41:00.0531 3056 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys
11:41:00.0734 3056 klmd23 - ok
11:41:00.0828 3056 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
11:41:00.0906 3056 kmixer - ok
11:41:00.0968 3056 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
11:41:01.0062 3056 KSecDD - ok
11:41:01.0109 3056 lbrtfdc - ok
11:41:01.0156 3056 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
11:41:01.0171 3056 lirsgt - ok
11:41:01.0218 3056 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\system32\Drivers\LVPr2Mon.sys
11:41:01.0234 3056 LVPr2Mon - ok
11:41:01.0281 3056 LVRS (87ecce893d8aec5a9337b917742d339c) C:\WINDOWS\system32\DRIVERS\lvrs.sys
11:41:01.0296 3056 LVRS - ok
11:41:01.0343 3056 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\WINDOWS\system32\drivers\LVUSBSta.sys
11:41:01.0359 3056 LVUSBSta - ok
11:41:01.0515 3056 LVUVC (291f69b3dda0f033d2490c5ba5179f7c) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
11:41:01.0750 3056 LVUVC - ok
11:41:01.0843 3056 MCSTRM (5bb01b9f582259d1fb7653c5c1da3653) C:\WINDOWS\system32\drivers\MCSTRM.sys
11:41:01.0875 3056 MCSTRM ( UnsignedFile.Multi.Generic ) - warning
11:41:01.0875 3056 MCSTRM - detected UnsignedFile.Multi.Generic (1)
11:41:01.0937 3056 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
11:41:02.0015 3056 mnmdd - ok
11:41:02.0078 3056 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
11:41:02.0171 3056 Modem - ok
11:41:02.0218 3056 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:41:02.0296 3056 Mouclass - ok
11:41:02.0390 3056 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:41:02.0468 3056 mouhid - ok
11:41:02.0546 3056 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
11:41:02.0640 3056 MountMgr - ok
11:41:02.0718 3056 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
11:41:02.0750 3056 MpFilter - ok
11:41:02.0890 3056 MpKsl105912c0 (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DEEB9A8D-729B-426C-B03E-947A1B298769}\MpKsl105912c0.sys
11:41:02.0921 3056 MpKsl105912c0 - ok
11:41:02.0984 3056 mraid35x - ok
11:41:03.0015 3056 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:41:03.0125 3056 MRxDAV - ok
11:41:03.0171 3056 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:41:03.0265 3056 MRxSmb - ok
11:41:03.0296 3056 MSDV (1477849772712bac69c144dcf2c9ce81) C:\WINDOWS\system32\DRIVERS\msdv.sys
11:41:03.0390 3056 MSDV - ok
11:41:03.0453 3056 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
11:41:03.0531 3056 Msfs - ok
11:41:03.0625 3056 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:41:03.0703 3056 MSKSSRV - ok
11:41:03.0781 3056 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:41:03.0843 3056 MSPCLOCK - ok
11:41:03.0953 3056 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:41:04.0031 3056 MSPQM - ok
11:41:04.0078 3056 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:41:04.0140 3056 mssmbios - ok
11:41:04.0203 3056 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
11:41:04.0281 3056 MSTEE - ok
11:41:04.0375 3056 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
11:41:04.0390 3056 MTsensor - ok
11:41:04.0468 3056 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:41:04.0515 3056 Mup - ok
11:41:04.0562 3056 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
11:41:04.0656 3056 NABTSFEC - ok
11:41:04.0703 3056 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:41:04.0796 3056 NDIS - ok
11:41:04.0906 3056 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
11:41:04.0984 3056 NdisIP - ok
11:41:05.0031 3056 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:41:05.0093 3056 NdisTapi - ok
11:41:05.0140 3056 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:41:05.0218 3056 Ndisuio - ok
11:41:05.0265 3056 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:41:05.0375 3056 NdisWan - ok
11:41:05.0468 3056 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:41:05.0500 3056 NDProxy - ok
11:41:05.0562 3056 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:41:05.0640 3056 NetBIOS - ok
11:41:05.0718 3056 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:41:05.0796 3056 NetBT - ok
11:41:05.0890 3056 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
11:41:05.0968 3056 NIC1394 - ok
11:41:06.0078 3056 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:41:06.0156 3056 Npfs - ok
11:41:06.0234 3056 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:41:06.0328 3056 Ntfs - ok
11:41:06.0421 3056 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:41:06.0500 3056 Null - ok
11:41:06.0687 3056 nv (b488eda5f3e9f8467fe999b00ccb146d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
11:41:07.0125 3056 nv ( UnsignedFile.Multi.Generic ) - warning
11:41:07.0140 3056 nv - detected UnsignedFile.Multi.Generic (1)
11:41:07.0234 3056 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:41:07.0328 3056 NwlnkFlt - ok
11:41:07.0421 3056 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:41:07.0500 3056 NwlnkFwd - ok
11:41:07.0578 3056 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
11:41:07.0656 3056 ohci1394 - ok
11:41:07.0750 3056 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
11:41:07.0843 3056 Parport - ok
11:41:07.0875 3056 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:41:07.0953 3056 PartMgr - ok
11:41:07.0984 3056 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
11:41:08.0062 3056 ParVdm - ok
11:41:08.0156 3056 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
11:41:08.0234 3056 PCI - ok
11:41:08.0250 3056 PCIDump - ok
11:41:08.0281 3056 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
11:41:08.0343 3056 PCIIde - ok
11:41:08.0453 3056 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
11:41:08.0531 3056 Pcmcia - ok
11:41:08.0578 3056 PDCOMP - ok
11:41:08.0625 3056 PDFRAME - ok
11:41:08.0625 3056 PDRELI - ok
11:41:08.0640 3056 PDRFRAME - ok
11:41:08.0671 3056 perc2 - ok
11:41:08.0671 3056 perc2hib - ok
11:41:08.0750 3056 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:41:08.0828 3056 PptpMiniport - ok
11:41:08.0843 3056 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:41:08.0937 3056 PSched - ok
11:41:08.0984 3056 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:41:09.0062 3056 Ptilink - ok
11:41:09.0171 3056 pxkbf (0c738845c7c12c45f05b127edff2cc87) C:\WINDOWS\system32\drivers\pxkbf.sys
11:41:09.0187 3056 pxkbf - ok
11:41:09.0218 3056 pxrts (04d1c97a0818f9378eeaa793a09f8202) C:\WINDOWS\system32\drivers\pxrts.sys
11:41:09.0265 3056 pxrts - ok
11:41:09.0281 3056 pxscan (e6e1f9f717feab3e16c3b160b17e6855) C:\WINDOWS\system32\drivers\pxscan.sys
11:41:09.0296 3056 pxscan - ok
11:41:09.0296 3056 ql1080 - ok
11:41:09.0312 3056 Ql10wnt - ok
11:41:09.0343 3056 ql12160 - ok
11:41:09.0359 3056 ql1240 - ok
11:41:09.0375 3056 ql1280 - ok
11:41:09.0406 3056 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:41:09.0500 3056 RasAcd - ok
11:41:09.0562 3056 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:41:09.0640 3056 Rasl2tp - ok
11:41:09.0750 3056 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:41:09.0828 3056 RasPppoe - ok
11:41:09.0828 3056 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:41:09.0906 3056 Raspti - ok
11:41:10.0000 3056 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:41:10.0093 3056 Rdbss - ok
11:41:10.0140 3056 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:41:10.0218 3056 RDPCDD - ok
11:41:10.0328 3056 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
11:41:10.0375 3056 RDPWD - ok
11:41:10.0421 3056 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:41:10.0515 3056 redbook - ok
11:41:10.0625 3056 RT73 (cb20f16afdba63707fb971e0922edec1) C:\WINDOWS\system32\DRIVERS\rt73.sys
11:41:10.0687 3056 RT73 ( UnsignedFile.Multi.Generic ) - warning
11:41:10.0687 3056 RT73 - detected UnsignedFile.Multi.Generic (1)
11:41:10.0765 3056 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:41:10.0843 3056 Secdrv - ok
11:41:10.0906 3056 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:41:10.0984 3056 serenum - ok
11:41:11.0078 3056 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
11:41:11.0171 3056 Serial - ok
11:41:11.0281 3056 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
11:41:11.0359 3056 Sfloppy - ok
11:41:11.0421 3056 Simbad - ok
11:41:11.0468 3056 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
11:41:11.0562 3056 SLIP - ok
11:41:11.0578 3056 Sparrow - ok
11:41:11.0609 3056 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:41:11.0703 3056 splitter - ok
11:41:11.0765 3056 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
11:41:11.0843 3056 sr - ok
11:41:11.0937 3056 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
11:41:11.0984 3056 Srv - ok
11:41:12.0078 3056 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
11:41:12.0156 3056 streamip - ok
11:41:12.0203 3056 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:41:12.0281 3056 swenum - ok
11:41:12.0359 3056 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:41:12.0453 3056 swmidi - ok
11:41:12.0515 3056 symc810 - ok
11:41:12.0546 3056 symc8xx - ok
11:41:12.0562 3056 sym_hi - ok
11:41:12.0578 3056 sym_u3 - ok
11:41:12.0625 3056 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:41:12.0703 3056 sysaudio - ok
11:41:12.0812 3056 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:41:12.0890 3056 Tcpip - ok
11:41:12.0968 3056 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:41:13.0046 3056 TDPIPE - ok
11:41:13.0062 3056 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:41:13.0156 3056 TDTCP - ok
11:41:13.0171 3056 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:41:13.0250 3056 TermDD - ok
11:41:13.0328 3056 TosIde - ok
11:41:13.0359 3056 TrueSight (4bfab463e1d1f20dfa83a04a9698934d) c:\windows\system32\drivers\TrueSight.sys
11:41:13.0437 3056 TrueSight ( UnsignedFile.Multi.Generic ) - warning
11:41:13.0437 3056 TrueSight - detected UnsignedFile.Multi.Generic (1)
11:41:13.0515 3056 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:41:13.0609 3056 Udfs - ok
11:41:13.0656 3056 ultra - ok
11:41:13.0718 3056 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:41:13.0812 3056 Update - ok
11:41:13.0906 3056 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
11:41:14.0000 3056 usbaudio - ok
11:41:14.0046 3056 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:41:14.0125 3056 usbccgp - ok
11:41:14.0234 3056 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:41:14.0296 3056 usbehci - ok
11:41:14.0390 3056 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:41:14.0484 3056 usbhub - ok
11:41:14.0578 3056 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
11:41:14.0656 3056 usbprint - ok
11:41:14.0734 3056 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
11:41:14.0796 3056 usbscan - ok
11:41:14.0906 3056 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:41:14.0984 3056 USBSTOR - ok
11:41:15.0031 3056 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
11:41:15.0093 3056 usbuhci - ok
11:41:15.0171 3056 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
11:41:15.0250 3056 VgaSave - ok
11:41:15.0312 3056 ViaIde - ok
11:41:15.0359 3056 Video3D - ok
11:41:15.0421 3056 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
11:41:15.0515 3056 VolSnap - ok
11:41:15.0593 3056 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:41:15.0687 3056 Wanarp - ok
11:41:15.0750 3056 WDICA - ok
11:41:15.0812 3056 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
11:41:15.0921 3056 wdmaud - ok
11:41:16.0031 3056 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
11:41:16.0109 3056 WpdUsb - ok
11:41:16.0218 3056 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
11:41:16.0312 3056 WSTCODEC - ok
11:41:16.0375 3056 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:41:16.0437 3056 WudfPf - ok
11:41:16.0468 3056 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:41:16.0500 3056 WudfRd - ok
11:41:16.0531 3056 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
11:41:16.0671 3056 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
11:41:16.0671 3056 \Device\Harddisk0\DR0 - detected TDSS File System (1)
11:41:16.0671 3056 Boot (0x1200) (3182683fadcc1894a1049495efce6d58) \Device\Harddisk0\DR0\Partition0
11:41:16.0671 3056 \Device\Harddisk0\DR0\Partition0 - ok
11:41:16.0671 3056 ============================================================
11:41:16.0671 3056 Scan finished
11:41:16.0671 3056 ============================================================
11:41:16.0781 3384 Detected object count: 9
11:41:16.0781 3384 Actual detected object count: 9
11:41:30.0562 3384 Afc ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0562 3384 Afc ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0562 3384 ASUSVRC ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0562 3384 ASUSVRC ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0562 3384 BCM42RLY ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0562 3384 BCM42RLY ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0562 3384 EIO ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0562 3384 EIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0562 3384 MCSTRM ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0562 3384 MCSTRM ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0578 3384 nv ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0578 3384 nv ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0578 3384 RT73 ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0578 3384 RT73 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0578 3384 TrueSight ( UnsignedFile.Multi.Generic ) - skipped by user
11:41:30.0578 3384 TrueSight ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:30.0578 3384 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
11:41:30.0578 3384 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
11:41:35.0375 3712 Deinitialize success
  • 0

#55
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
When you run TDSSKiller what options do you have once it gets to the:
\Device\Harddisk0\DR0 ( TDSS File System ) - ? Are you able to select Cure for it?
  • 0

Advertisements


#56
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
I apologize if I've already asked this, but do you have your Windows XP disc?
  • 0

#57
frogmusic

frogmusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
My options are: Skip, Copy to Quarantine, or delete

Yes I have my Windows XP home edition disc that came with the computer when we bought it.
  • 0

#58
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hi!

Okay. Lets try fixing your Master Boot Record again. We'll do that a little differently this time:

Steps to perform on the problem machine:
  • Place your Windows XP Installation CD, and reboot.
    You should see this:
    Posted Image
    If you don't see the above, try pressing the F10 or F12 keys during boot and selecting the CDRom device from the list.
    If that doesn't work, enter BIOS Setup by pressing the F1, F2, F10 or Del key during boot and modifying the
    Boot Order or Boot Priority to make the CD/DVD first boot device.
  • Press any key to start Windows Setup (Don't worry.. we're not actually using setup at this point)
  • Wait a while for setup to start, until you see the following screen, then press the R key.
    Posted Image
  • Wait until you see this screen, and enter the number of your main installation. (Typically 1 for C:\Windows)
    Posted Image
  • Press Enter.
  • If prompted to do so, enter your Administrator password. If you don't have one, leave it blank and press enter.
  • From the command prompt, enter: FIXMBR
  • When you get to the above screen, take note of the number that references your operating system.
    If it's '1' like the picture above, type 1 and press Enter

    Posted Image
  • Next type FIXMBR

    Posted Image
  • If it ask if you're sure you want to write a new MBR, answer 'Y'
  • Then type EXIT to reboot the machine.

Let me know how that goes.
  • 0

#59
frogmusic

frogmusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
Ok, getting to the BIOS was a hassle, but I finally figured it out. I booted from the disc and did the FIXMBR steps.
  • 0

#60
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Okay. Glad to hear you got it figured out.

Can you please run a new scan with TDSSKiller and post the log for me to review?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP