Thanks. TDSSKiller did not offer the "cure" option. AVP reported a bunch of files as password protected, but I don't even know how to do that...
The NPE Log is ~1.7mb and is too big to attach... (?)Here are the logs/reports.
ComboFix 12-02-23.02 - Gary 02/26/2012 19:48:23.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.626 [GMT -6:00]
Running from: c:\documents and settings\Gary\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Gary\Desktop\cfscript.txt
AV: Norton AntiVirus *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
FILE ::
"c:\docume~1\Gary\LOCALS~1\Temp\fxjl958o.tmp\tidhook.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Gary\Application Data\Microsoft\~DFK303752.tmp
c:\documents and settings\Gary\Application Data\Microsoft\mjcriu.dll
c:\documents and settings\Gary\Application Data\Microsoft\peaadje.dll
c:\documents and settings\Gary\Application Data\Microsoft\qwadjb.dll
c:\documents and settings\Gary\Application Data\Microsoft\rsaadjd.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_12386535
-------\Legacy_16470951
-------\Legacy_39392380
-------\Legacy_57557279
-------\Legacy_TIDHOOK
-------\Service_12386535
-------\Service_16470951
-------\Service_39392380
-------\Service_57557279
-------\Service_TIDHOOK
.
.
((((((((((((((((((((((((( Files Created from 2012-01-27 to 2012-02-27 )))))))))))))))))))))))))))))))
.
.
2012-02-23 14:28 . 2012-02-23 14:28 -------- d-----w- C:\_OTL
2012-02-19 20:57 . 2012-02-19 20:57 32808 ----a-w- c:\windows\system32\drivers\FixZeroAccess.sys
2012-02-17 01:28 . 2012-02-17 01:28 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-17 00:55 . 2012-02-17 00:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\com.radioio.ioDesktop.CB8A51FDBDF8B5F2BC25A3DD7F59CC4ED6D8CF65.1
2012-02-17 00:55 . 2012-02-17 00:55 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2012-02-16 02:20 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-16 02:20 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 23:41 . 2012-02-15 23:41 -------- d-----w- C:\TDSSKiller_Quarantine
2012-02-14 04:07 . 2012-02-16 02:06 -------- d-----w- c:\documents and settings\Gary\Local Settings\Application Data\NPE
2012-02-10 01:26 . 2012-02-10 01:26 -------- d-----w- c:\program files\ioDesktop
2012-02-04 17:06 . 2012-02-04 17:06 -------- d-----w- c:\documents and settings\Gary\Local Settings\Application Data\Deployment
2012-02-02 00:14 . 2012-02-02 23:19 -------- d-----w- c:\windows\system32\drivers\NAV\1305000.091
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-17 01:28 . 2008-10-29 01:39 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-15 23:44 . 2002-08-29 10:00 64512 ----a-w- c:\windows\system32\drivers\serial.sys
2012-02-02 00:14 . 2010-08-12 02:07 60872 ----a-w- c:\windows\system32\S32EVNT1.DLL
2012-02-02 00:14 . 2010-08-12 02:07 141944 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-01-12 16:53 . 2002-08-29 10:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-24 23:48 . 2003-02-21 10:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-12-24 23:48 . 2003-03-19 04:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-12-17 19:46 . 2004-02-06 23:05 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2002-08-29 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2002-08-29 10:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2004-10-27 03:04 385024 ----a-w- c:\windows\system32\html.iec
2011-12-10 21:24 . 2012-01-09 14:14 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
(((((((((((((((((((((((((((((
SnapShot@2012-02-24_00.26.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-27 01:54 . 2012-02-27 01:54 16384 c:\windows\Temp\Perflib_Perfdata_758.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
.
R0 SMR250;Symantec SMR Utility Service 2.5.0;c:\windows\System32\drivers\SMR250.SYS [x]
R3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys [2004-11-01 17536]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1305000.091\SYMDS.SYS [2011-07-26 340088]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1305000.091\SYMEFA.SYS [2011-11-24 905336]
S1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx86.sys [2011-12-01 820344]
S1 ccSet_NAV;Norton AntiVirus Settings Manager;c:\windows\system32\drivers\NAV\1305000.091\ccSetx86.sys [2011-11-04 132744]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1305000.091\Ironx86.SYS [2011-11-17 149624]
S2 EarthLinkMonitor;EarthLink Monitor Service;c:\program files\EarthLink TotalAccess\WENGINE\wmonitor.exe [2005-01-26 65604]
S2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\19.5.0.145\ccSvcHst.exe [2011-11-30 138248]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-02-04 106104]
S3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.1.3\Definitions\IPSDefs\20120223.002\IDSxpx86.sys [2011-12-15 356280]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
NTIDrvr
FA312
AVCamUSB20
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1007087799-3521379142-2447425561-1007Core.job
- c:\documents and settings\Gary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-04 17:06]
.
2012-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1007087799-3521379142-2447425561-1007UA.job
- c:\documents and settings\Gary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-04 17:06]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mWindow Title = My Browser
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Trusted Zone: microsoft.com\www.update
TCP: Interfaces\{E4BDEE83-9F7E-40C0-A52D-81CE364EE7F8}: NameServer = 207.69.188.185,207.69.188.186
DPF: {050A3800-6C03-48A5-A6D7-14CCF18A700D} - hxxp://employees.oldrepublic.com/v4rdpchk.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-02-26 19:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\19.5.0.145\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\19.5.0.145\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3928)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
.
**************************************************************************
.
Completion time: 2012-02-26 19:58:58 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-27 01:58
ComboFix2.txt 2012-02-24 00:30
.
Pre-Run: 65,826,488,320 bytes free
Post-Run: 65,865,605,120 bytes free
.
- - End Of File - - 9CC22516DECB373CAF76ED2406D33E9C
20:22:02.0921 2904 TDSS rootkit removing tool 2.7.14.0 Feb 22 2012 16:54:49
20:22:02.0937 2904 ============================================================
20:22:02.0937 2904 Current date / time: 2012/02/26 20:22:02.0937
20:22:02.0937 2904 SystemInfo:
20:22:02.0937 2904
20:22:02.0937 2904 OS Version: 5.1.2600 ServicePack: 3.0
20:22:02.0937 2904 Product type: Workstation
20:22:02.0937 2904 ComputerName: RACERX
20:22:02.0937 2904 UserName: Gary
20:22:02.0937 2904 Windows directory: C:\WINDOWS
20:22:02.0937 2904 System windows directory: C:\WINDOWS
20:22:02.0937 2904 Processor architecture: Intel x86
20:22:02.0937 2904 Number of processors: 1
20:22:02.0937 2904 Page size: 0x1000
20:22:02.0937 2904 Boot type: Normal boot
20:22:02.0937 2904 ============================================================
20:22:04.0109 2904 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
20:22:04.0109 2904 Drive \Device\Harddisk1\DR7 - Size: 0x78000000 (1.88 Gb), SectorSize: 0x200, Cylinders: 0xF4, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:22:04.0125 2904 \Device\Harddisk0\DR0:
20:22:04.0125 2904 MBR used
20:22:04.0125 2904 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x94EAFF8
20:22:04.0125 2904 \Device\Harddisk1\DR7:
20:22:04.0125 2904 MBR used
20:22:04.0125 2904 \Device\Harddisk1\DR7\Partition0: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x3BFFC1
20:22:04.0187 2904 Initialize success
20:22:04.0187 2904 ============================================================
20:22:15.0343 2928 ============================================================
20:22:15.0343 2928 Scan started
20:22:15.0343 2928 Mode: Manual; SigCheck; TDLFS;
20:22:15.0343 2928 ============================================================
20:22:15.0640 2928 Abiosdsk - ok
20:22:15.0718 2928 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS
20:22:16.0000 2928 abp480n5 - ok
20:22:16.0156 2928 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:22:16.0328 2928 ACPI - ok
20:22:16.0468 2928 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
20:22:16.0609 2928 ACPIEC - ok
20:22:16.0750 2928 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys
20:22:16.0890 2928 adpu160m - ok
20:22:17.0062 2928 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
20:22:17.0109 2928 aeaudio - ok
20:22:17.0265 2928 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
20:22:17.0421 2928 aec - ok
20:22:17.0578 2928 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
20:22:17.0625 2928 AFD - ok
20:22:17.0734 2928 AFGMp50 - ok
20:22:17.0765 2928 AFGSp50 - ok
20:22:17.0859 2928 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\System32\DRIVERS\agp440.sys
20:22:18.0015 2928 agp440 - ok
20:22:18.0171 2928 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys
20:22:18.0312 2928 agpCPQ - ok
20:22:18.0468 2928 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys
20:22:18.0531 2928 Aha154x - ok
20:22:18.0687 2928 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys
20:22:18.0843 2928 aic78u2 - ok
20:22:19.0015 2928 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys
20:22:19.0156 2928 aic78xx - ok
20:22:19.0312 2928 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys
20:22:19.0453 2928 AliIde - ok
20:22:19.0593 2928 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys
20:22:19.0750 2928 alim1541 - ok
20:22:19.0937 2928 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys
20:22:20.0078 2928 amdagp - ok
20:22:20.0234 2928 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys
20:22:20.0312 2928 amsint - ok
20:22:20.0453 2928 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys
20:22:20.0609 2928 asc - ok
20:22:20.0750 2928 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys
20:22:20.0812 2928 asc3350p - ok
20:22:21.0000 2928 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys
20:22:21.0140 2928 asc3550 - ok
20:22:21.0296 2928 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:22:21.0453 2928 AsyncMac - ok
20:22:21.0609 2928 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
20:22:21.0750 2928 atapi - ok
20:22:21.0875 2928 Atdisk - ok
20:22:21.0937 2928 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:22:22.0093 2928 Atmarpc - ok
20:22:22.0265 2928 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
20:22:22.0421 2928 audstub - ok
20:22:22.0578 2928 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
20:22:22.0750 2928 Beep - ok
20:22:23.0109 2928 BHDrvx86 (e685ba3267c5a4ec4ce9e2b4a1481725) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx86.sys
20:22:23.0156 2928 BHDrvx86 - ok
20:22:23.0312 2928 BW2NDIS5 (71cb7616cb36d43ea787c41ab55fe458) C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
20:22:23.0328 2928 BW2NDIS5 ( UnsignedFile.Multi.Generic ) - warning
20:22:23.0328 2928 BW2NDIS5 - detected UnsignedFile.Multi.Generic (1)
20:22:23.0359 2928 catchme - ok
20:22:23.0500 2928 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys
20:22:23.0656 2928 cbidf - ok
20:22:23.0796 2928 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
20:22:23.0937 2928 cbidf2k - ok
20:22:24.0156 2928 ccSet_NAV (599e7f6259a127c174c49938d2aa6a60) C:\WINDOWS\system32\drivers\NAV\1305000.091\ccSetx86.sys
20:22:24.0171 2928 ccSet_NAV - ok
20:22:24.0343 2928 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys
20:22:24.0406 2928 cd20xrnt - ok
20:22:24.0562 2928 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
20:22:24.0718 2928 Cdaudio - ok
20:22:24.0890 2928 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
20:22:25.0046 2928 Cdfs - ok
20:22:25.0218 2928 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:22:25.0375 2928 Cdrom - ok
20:22:25.0484 2928 Changer - ok
20:22:25.0562 2928 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys
20:22:25.0718 2928 CmdIde - ok
20:22:25.0890 2928 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys
20:22:26.0046 2928 Cpqarray - ok
20:22:26.0265 2928 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys
20:22:26.0421 2928 dac2w2k - ok
20:22:26.0578 2928 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys
20:22:26.0734 2928 dac960nt - ok
20:22:26.0906 2928 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
20:22:27.0062 2928 Disk - ok
20:22:27.0250 2928 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
20:22:27.0406 2928 dmboot - ok
20:22:27.0546 2928 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
20:22:27.0703 2928 dmio - ok
20:22:27.0843 2928 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
20:22:28.0000 2928 dmload - ok
20:22:28.0171 2928 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
20:22:28.0328 2928 DMusic - ok
20:22:28.0468 2928 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys
20:22:28.0625 2928 dpti2o - ok
20:22:28.0796 2928 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
20:22:28.0937 2928 drmkaud - ok
20:22:29.0125 2928 drvmcdb (049177996e5e33b5faf40cad2b82098c) C:\WINDOWS\system32\drivers\drvmcdb.sys
20:22:29.0156 2928 drvmcdb ( UnsignedFile.Multi.Generic ) - warning
20:22:29.0156 2928 drvmcdb - detected UnsignedFile.Multi.Generic (1)
20:22:29.0312 2928 drvnddm (2f4134d073f972575c174e3d621f0107) C:\WINDOWS\system32\drivers\drvnddm.sys
20:22:29.0343 2928 drvnddm ( UnsignedFile.Multi.Generic ) - warning
20:22:29.0343 2928 drvnddm - detected UnsignedFile.Multi.Generic (1)
20:22:29.0500 2928 E100B (d57a8fc800b501ac05b10d00f66d127a) C:\WINDOWS\system32\DRIVERS\e100b325.sys
20:22:29.0531 2928 E100B - ok
20:22:29.0734 2928 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
20:22:29.0750 2928 eeCtrl - ok
20:22:29.0921 2928 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
20:22:30.0078 2928 EL90XBC - ok
20:22:30.0250 2928 EraserUtilRebootDrv (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
20:22:30.0265 2928 EraserUtilRebootDrv - ok
20:22:30.0453 2928 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
20:22:30.0609 2928 Fastfat - ok
20:22:30.0750 2928 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
20:22:30.0921 2928 Fdc - ok
20:22:31.0093 2928 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
20:22:31.0609 2928 Fips - ok
20:22:31.0765 2928 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:22:31.0921 2928 Flpydisk - ok
20:22:32.0093 2928 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
20:22:32.0265 2928 FltMgr - ok
20:22:32.0406 2928 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:22:32.0562 2928 Fs_Rec - ok
20:22:32.0734 2928 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:22:32.0921 2928 Ftdisk - ok
20:22:33.0078 2928 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:22:33.0234 2928 Gpc - ok
20:22:33.0390 2928 HCF_MSFT (4236e014632f4163f53ebb717f41594c) C:\WINDOWS\system32\DRIVERS\HCF_MSFT.sys
20:22:33.0609 2928 HCF_MSFT - ok
20:22:33.0750 2928 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:22:33.0890 2928 HidUsb - ok
20:22:34.0062 2928 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys
20:22:34.0203 2928 hpn - ok
20:22:34.0375 2928 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
20:22:34.0406 2928 HTTP - ok
20:22:34.0562 2928 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
20:22:34.0718 2928 i2omgmt - ok
20:22:34.0906 2928 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys
20:22:35.0046 2928 i2omp - ok
20:22:35.0203 2928 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:22:35.0359 2928 i8042prt - ok
20:22:35.0500 2928 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
20:22:35.0625 2928 i81x - ok
20:22:35.0765 2928 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
20:22:35.0890 2928 iAimFP0 - ok
20:22:36.0046 2928 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
20:22:36.0171 2928 iAimFP1 - ok
20:22:36.0328 2928 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
20:22:36.0484 2928 iAimFP2 - ok
20:22:36.0640 2928 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
20:22:36.0750 2928 iAimFP3 - ok
20:22:36.0937 2928 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
20:22:37.0062 2928 iAimFP4 - ok
20:22:37.0203 2928 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
20:22:37.0328 2928 iAimTV0 - ok
20:22:37.0484 2928 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
20:22:37.0609 2928 iAimTV1 - ok
20:22:37.0718 2928 iAimTV2 - ok
20:22:37.0796 2928 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
20:22:37.0921 2928 iAimTV3 - ok
20:22:38.0062 2928 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
20:22:38.0187 2928 iAimTV4 - ok
20:22:38.0562 2928 IDSxpx86 (cfbc1ce72e5353d428704659199147b1) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.1.3\Definitions\IPSDefs\20120223.002\IDSxpx86.sys
20:22:38.0593 2928 IDSxpx86 - ok
20:22:38.0765 2928 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
20:22:38.0906 2928 Imapi - ok
20:22:39.0093 2928 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys
20:22:39.0234 2928 ini910u - ok
20:22:39.0390 2928 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys
20:22:39.0531 2928 IntelIde - ok
20:22:39.0703 2928 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:22:39.0843 2928 intelppm - ok
20:22:40.0000 2928 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
20:22:40.0140 2928 ip6fw - ok
20:22:40.0296 2928 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:22:40.0437 2928 IpFilterDriver - ok
20:22:40.0593 2928 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:22:40.0734 2928 IpInIp - ok
20:22:40.0906 2928 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:22:41.0078 2928 IpNat - ok
20:22:41.0234 2928 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:22:41.0390 2928 IPSec - ok
20:22:41.0750 2928 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
20:22:41.0890 2928 IRENUM - ok
20:22:42.0062 2928 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:22:42.0218 2928 isapnp - ok
20:22:42.0375 2928 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:22:42.0531 2928 Kbdclass - ok
20:22:42.0687 2928 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:22:42.0843 2928 kbdhid - ok
20:22:43.0015 2928 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
20:22:43.0171 2928 kmixer - ok
20:22:43.0328 2928 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
20:22:43.0359 2928 KSecDD - ok
20:22:43.0484 2928 lbrtfdc - ok
20:22:43.0578 2928 mdmxsdk (29174d3d90ee4244fda6355a859691be) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
20:22:43.0578 2928 mdmxsdk - ok
20:22:43.0765 2928 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
20:22:43.0921 2928 mnmdd - ok
20:22:44.0109 2928 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
20:22:44.0265 2928 Modem - ok
20:22:44.0421 2928 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
20:22:44.0578 2928 MODEMCSA - ok
20:22:44.0734 2928 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:22:44.0890 2928 Mouclass - ok
20:22:45.0046 2928 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:22:45.0187 2928 mouhid - ok
20:22:45.0343 2928 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
20:22:45.0500 2928 MountMgr - ok
20:22:45.0640 2928 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys
20:22:45.0781 2928 mraid35x - ok
20:22:45.0953 2928 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:22:46.0109 2928 MRxDAV - ok
20:22:46.0265 2928 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:22:46.0328 2928 MRxSmb - ok
20:22:46.0484 2928 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
20:22:46.0640 2928 Msfs - ok
20:22:46.0781 2928 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:22:46.0921 2928 MSKSSRV - ok
20:22:47.0062 2928 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:22:47.0203 2928 MSPCLOCK - ok
20:22:47.0343 2928 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
20:22:47.0484 2928 MSPQM - ok
20:22:47.0640 2928 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:22:47.0781 2928 mssmbios - ok
20:22:47.0937 2928 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
20:22:47.0968 2928 Mup - ok
20:22:48.0265 2928 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.1.3\Definitions\VirusDefs\20120223.017\NAVENG.SYS
20:22:48.0281 2928 NAVENG - ok
20:22:48.0578 2928 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.1.3\Definitions\VirusDefs\20120223.017\NAVEX15.SYS
20:22:48.0671 2928 NAVEX15 - ok
20:22:48.0843 2928 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
20:22:49.0015 2928 NDIS - ok
20:22:49.0156 2928 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:22:49.0203 2928 NdisTapi - ok
20:22:49.0343 2928 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:22:49.0500 2928 Ndisuio - ok
20:22:49.0640 2928 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:22:49.0796 2928 NdisWan - ok
20:22:49.0968 2928 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
20:22:50.0015 2928 NDProxy - ok
20:22:50.0171 2928 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
20:22:50.0312 2928 NetBIOS - ok
20:22:50.0484 2928 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
20:22:50.0640 2928 NetBT - ok
20:22:50.0812 2928 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
20:22:50.0953 2928 Npfs - ok
20:22:51.0140 2928 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
20:22:51.0328 2928 Ntfs - ok
20:22:51.0515 2928 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
20:22:51.0671 2928 Null - ok
20:22:51.0875 2928 nv (66c90afbf0d10a93789f6544be459e72) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:22:51.0953 2928 nv - ok
20:22:52.0109 2928 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:22:52.0250 2928 NwlnkFlt - ok
20:22:52.0406 2928 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:22:52.0562 2928 NwlnkFwd - ok
20:22:52.0718 2928 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
20:22:52.0750 2928 omci ( UnsignedFile.Multi.Generic ) - warning
20:22:52.0750 2928 omci - detected UnsignedFile.Multi.Generic (1)
20:22:52.0937 2928 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys
20:22:53.0078 2928 P3 - ok
20:22:53.0234 2928 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
20:22:53.0390 2928 Parport - ok
20:22:53.0546 2928 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
20:22:53.0703 2928 PartMgr - ok
20:22:53.0859 2928 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
20:22:54.0015 2928 ParVdm - ok
20:22:54.0187 2928 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
20:22:54.0343 2928 PCI - ok
20:22:54.0453 2928 PCIDump - ok
20:22:54.0531 2928 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
20:22:54.0703 2928 PCIIde - ok
20:22:54.0843 2928 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
20:22:55.0000 2928 Pcmcia - ok
20:22:55.0125 2928 PDCOMP - ok
20:22:55.0218 2928 PDFRAME - ok
20:22:55.0250 2928 PDRELI - ok
20:22:55.0281 2928 PDRFRAME - ok
20:22:55.0328 2928 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys
20:22:55.0484 2928 perc2 - ok
20:22:55.0625 2928 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys
20:22:55.0781 2928 perc2hib - ok
20:22:55.0953 2928 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:22:56.0109 2928 PptpMiniport - ok
20:22:56.0281 2928 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
20:22:56.0406 2928 Processor - ok
20:22:56.0593 2928 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
20:22:56.0734 2928 PSched - ok
20:22:56.0906 2928 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:22:57.0062 2928 Ptilink - ok
20:22:57.0218 2928 PxHelp20 (b5dfb86a6caeae9b2bf3dedb43be6393) C:\WINDOWS\system32\Drivers\PxHelp20.sys
20:22:57.0250 2928 PxHelp20 ( UnsignedFile.Multi.Generic ) - warning
20:22:57.0250 2928 PxHelp20 - detected UnsignedFile.Multi.Generic (1)
20:22:57.0406 2928 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys
20:22:57.0562 2928 ql1080 - ok
20:22:57.0703 2928 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys
20:22:57.0859 2928 Ql10wnt - ok
20:22:58.0000 2928 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys
20:22:58.0156 2928 ql12160 - ok
20:22:58.0312 2928 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys
20:22:58.0453 2928 ql1240 - ok
20:22:58.0609 2928 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys
20:22:58.0765 2928 ql1280 - ok
20:22:58.0937 2928 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:22:59.0093 2928 RasAcd - ok
20:22:59.0265 2928 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:22:59.0421 2928 Rasl2tp - ok
20:22:59.0578 2928 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:22:59.0718 2928 RasPppoe - ok
20:22:59.0890 2928 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
20:23:00.0046 2928 Raspti - ok
20:23:00.0234 2928 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:23:00.0375 2928 Rdbss - ok
20:23:00.0546 2928 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:23:00.0703 2928 RDPCDD - ok
20:23:00.0859 2928 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:23:01.0015 2928 rdpdr - ok
20:23:01.0171 2928 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
20:23:01.0203 2928 RDPWD - ok
20:23:01.0359 2928 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
20:23:01.0500 2928 redbook - ok
20:23:01.0687 2928 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:23:01.0828 2928 Secdrv - ok
20:23:02.0000 2928 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
20:23:02.0156 2928 serenum - ok
20:23:02.0312 2928 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
20:23:02.0468 2928 Serial - ok
20:23:02.0625 2928 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
20:23:02.0781 2928 Sfloppy - ok
20:23:02.0906 2928 Simbad - ok
20:23:03.0031 2928 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys
20:23:03.0156 2928 sisagp - ok
20:23:03.0265 2928 SMR250 - ok
20:23:03.0375 2928 smwdm (5018a9db5eb62e3edb3110f82f556285) C:\WINDOWS\system32\drivers\smwdm.sys
20:23:03.0421 2928 smwdm - ok
20:23:03.0562 2928 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys
20:23:03.0640 2928 Sparrow - ok
20:23:03.0781 2928 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
20:23:03.0937 2928 splitter - ok
20:23:04.0078 2928 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
20:23:04.0218 2928 sr - ok
20:23:04.0453 2928 SRTSP (c16d048faf2978d2121f9f40594a6bdc) C:\WINDOWS\System32\Drivers\NAV\1305000.091\SRTSP.SYS
20:23:04.0484 2928 SRTSP - ok
20:23:04.0703 2928 SRTSPX (f0d02c2e25970c9c72a5cd278c17cdb6) C:\WINDOWS\system32\drivers\NAV\1305000.091\SRTSPX.SYS
20:23:04.0718 2928 SRTSPX - ok
20:23:04.0890 2928 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
20:23:04.0906 2928 Srv - ok
20:23:05.0078 2928 sscdbhk5 (7c0c9bdca2d351ff3b4f9b69f99aa995) C:\WINDOWS\system32\drivers\sscdbhk5.sys
20:23:05.0109 2928 sscdbhk5 ( UnsignedFile.Multi.Generic ) - warning
20:23:05.0109 2928 sscdbhk5 - detected UnsignedFile.Multi.Generic (1)
20:23:05.0281 2928 ssrtln (31726706d54894d5059f7471111a87bb) C:\WINDOWS\system32\drivers\ssrtln.sys
20:23:05.0281 2928 ssrtln ( UnsignedFile.Multi.Generic ) - warning
20:23:05.0281 2928 ssrtln - detected UnsignedFile.Multi.Generic (1)
20:23:05.0437 2928 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
20:23:05.0593 2928 swenum - ok
20:23:05.0718 2928 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
20:23:05.0875 2928 swmidi - ok
20:23:06.0031 2928 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys
20:23:06.0171 2928 symc810 - ok
20:23:06.0312 2928 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys
20:23:06.0468 2928 symc8xx - ok
20:23:06.0671 2928 SymDS (690fa0e61b90084c4d9a721bd4f3d779) C:\WINDOWS\system32\drivers\NAV\1305000.091\SYMDS.SYS
20:23:06.0703 2928 SymDS - ok
20:23:06.0953 2928 SymEFA (4e55148a2e044d02245cbcdbb266b98c) C:\WINDOWS\system32\drivers\NAV\1305000.091\SYMEFA.SYS
20:23:07.0031 2928 SymEFA - ok
20:23:07.0203 2928 SymEvent (74e2521e96176a4449570e50be91954d) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
20:23:07.0203 2928 SymEvent - ok
20:23:07.0390 2928 SymIM (a7100ea17ed9eaf365362a05bf430e77) C:\WINDOWS\system32\DRIVERS\SymIM.sys
20:23:07.0406 2928 SymIM - ok
20:23:07.0406 2928 SymIMMP (a7100ea17ed9eaf365362a05bf430e77) C:\WINDOWS\system32\DRIVERS\SymIM.sys
20:23:07.0421 2928 SymIMMP - ok
20:23:07.0656 2928 SymIRON (2c356cca706505cf63cbe39d532b9236) C:\WINDOWS\system32\drivers\NAV\1305000.091\Ironx86.SYS
20:23:07.0671 2928 SymIRON - ok
20:23:07.0921 2928 SYMTDI (508bd882040f9cb12319e3a4fc78edb9) C:\WINDOWS\System32\Drivers\NAV\1305000.091\SYMTDI.SYS
20:23:07.0937 2928 SYMTDI - ok
20:23:08.0093 2928 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys
20:23:08.0234 2928 sym_hi - ok
20:23:08.0375 2928 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys
20:23:08.0515 2928 sym_u3 - ok
20:23:08.0687 2928 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
20:23:08.0843 2928 sysaudio - ok
20:23:09.0031 2928 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:23:09.0062 2928 Tcpip - ok
20:23:09.0234 2928 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
20:23:09.0359 2928 TDPIPE - ok
20:23:09.0515 2928 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
20:23:09.0656 2928 TDTCP - ok
20:23:09.0796 2928 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
20:23:09.0953 2928 TermDD - ok
20:23:10.0078 2928 tfsnboio (b0d311f33c5b4a5858e4e6c965a79267) C:\WINDOWS\system32\dla\tfsnboio.sys
20:23:10.0109 2928 tfsnboio ( UnsignedFile.Multi.Generic ) - warning
20:23:10.0109 2928 tfsnboio - detected UnsignedFile.Multi.Generic (1)
20:23:10.0234 2928 tfsncofs (250f74fce5d1eccb29ad9abeb55f35d8) C:\WINDOWS\system32\dla\tfsncofs.sys
20:23:10.0265 2928 tfsncofs ( UnsignedFile.Multi.Generic ) - warning
20:23:10.0265 2928 tfsncofs - detected UnsignedFile.Multi.Generic (1)
20:23:10.0406 2928 tfsndrct (e23291934c59e1741ba83582e7a209c0) C:\WINDOWS\system32\dla\tfsndrct.sys
20:23:10.0437 2928 tfsndrct ( UnsignedFile.Multi.Generic ) - warning
20:23:10.0437 2928 tfsndrct - detected UnsignedFile.Multi.Generic (1)
20:23:10.0593 2928 tfsndres (0d863d020633025f1e4ad3e0e325d503) C:\WINDOWS\system32\dla\tfsndres.sys
20:23:10.0609 2928 tfsndres ( UnsignedFile.Multi.Generic ) - warning
20:23:10.0609 2928 tfsndres - detected UnsignedFile.Multi.Generic (1)
20:23:10.0765 2928 tfsnifs (e3e10696663e35062851a376299198bd) C:\WINDOWS\system32\dla\tfsnifs.sys
20:23:10.0796 2928 tfsnifs ( UnsignedFile.Multi.Generic ) - warning
20:23:10.0812 2928 tfsnifs - detected UnsignedFile.Multi.Generic (1)
20:23:10.0953 2928 tfsnopio (00cc366bdcbd8a9a1c95c1c59900dd9b) C:\WINDOWS\system32\dla\tfsnopio.sys
20:23:10.0984 2928 tfsnopio ( UnsignedFile.Multi.Generic ) - warning
20:23:10.0984 2928 tfsnopio - detected UnsignedFile.Multi.Generic (1)
20:23:11.0125 2928 tfsnpool (84a91d08f49831e8c24e4d25ddefae87) C:\WINDOWS\system32\dla\tfsnpool.sys
20:23:11.0156 2928 tfsnpool ( UnsignedFile.Multi.Generic ) - warning
20:23:11.0156 2928 tfsnpool - detected UnsignedFile.Multi.Generic (1)
20:23:11.0296 2928 tfsnudf (55b761c6e2d4fcedac3b46b6c0724830) C:\WINDOWS\system32\dla\tfsnudf.sys
20:23:11.0312 2928 tfsnudf ( UnsignedFile.Multi.Generic ) - warning
20:23:11.0312 2928 tfsnudf - detected UnsignedFile.Multi.Generic (1)
20:23:11.0421 2928 tfsnudfa (64c6e8c217e30ee595120c66f6e783ba) C:\WINDOWS\system32\dla\tfsnudfa.sys
20:23:11.0453 2928 tfsnudfa ( UnsignedFile.Multi.Generic ) - warning
20:23:11.0453 2928 tfsnudfa - detected UnsignedFile.Multi.Generic (1)
20:23:11.0609 2928 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys
20:23:11.0750 2928 TosIde - ok
20:23:11.0906 2928 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
20:23:12.0046 2928 Udfs - ok
20:23:12.0218 2928 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys
20:23:12.0281 2928 ultra - ok
20:23:12.0453 2928 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
20:23:12.0609 2928 Update - ok
20:23:12.0765 2928 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:23:12.0921 2928 usbehci - ok
20:23:13.0093 2928 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:23:13.0250 2928 usbhub - ok
20:23:13.0406 2928 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:23:13.0546 2928 usbscan - ok
20:23:13.0671 2928 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:23:13.0812 2928 USBSTOR - ok
20:23:13.0968 2928 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:23:14.0125 2928 usbuhci - ok
20:23:14.0281 2928 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
20:23:14.0421 2928 VgaSave - ok
20:23:14.0593 2928 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys
20:23:14.0718 2928 viaagp - ok
20:23:14.0921 2928 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
20:23:15.0046 2928 ViaIde - ok
20:23:15.0203 2928 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
20:23:15.0359 2928 VolSnap - ok
20:23:15.0531 2928 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:23:15.0671 2928 Wanarp - ok
20:23:15.0781 2928 wanatw - ok
20:23:15.0921 2928 WDICA - ok
20:23:16.0046 2928 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
20:23:16.0203 2928 wdmaud - ok
20:23:16.0421 2928 Winachcf (0ab973f5c373d58839632da1bee4c20b) C:\WINDOWS\system32\DRIVERS\winachcf.sys
20:23:16.0484 2928 Winachcf - ok
20:23:16.0656 2928 WmBEnum (671db6a9b772b807721147c28faf760f) C:\WINDOWS\system32\drivers\WmBEnum.sys
20:23:16.0687 2928 WmBEnum - ok
20:23:16.0843 2928 WmFilter (cffe18db8140b00335221907a694dd01) C:\WINDOWS\system32\drivers\WmFilter.sys
20:23:16.0890 2928 WmFilter - ok
20:23:17.0046 2928 WmHidLo (b1e80727e9b79b5c3c7ef5fba517f107) C:\WINDOWS\system32\drivers\WmHidLo.sys
20:23:17.0062 2928 WmHidLo - ok
20:23:17.0218 2928 WmVirHid (2e17ea3b132963e3c07d50d68d2df54e) C:\WINDOWS\system32\drivers\WmVirHid.sys
20:23:17.0250 2928 WmVirHid - ok
20:23:17.0406 2928 WmXlCore (0ece3bb49eb9ee42c411a0f1ec39dda9) C:\WINDOWS\system32\drivers\WmXlCore.sys
20:23:17.0421 2928 WmXlCore - ok
20:23:17.0593 2928 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:23:17.0750 2928 WS2IFSL - ok
20:23:17.0937 2928 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:23:17.0953 2928 WudfPf - ok
20:23:17.0984 2928 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
20:23:18.0234 2928 \Device\Harddisk0\DR0 - ok
20:23:18.0234 2928 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR7
20:23:22.0046 2928 \Device\Harddisk1\DR7 - ok
20:23:22.0078 2928 Boot (0x1200) (f7642172070d61af367481a7e25514f6) \Device\Harddisk0\DR0\Partition0
20:23:22.0078 2928 \Device\Harddisk0\DR0\Partition0 - ok
20:23:22.0078 2928 Boot (0x1200) (7d150c9438ebad2edee76a270e138327) \Device\Harddisk1\DR7\Partition0
20:23:22.0078 2928 \Device\Harddisk1\DR7\Partition0 - ok
20:23:22.0078 2928 ============================================================
20:23:22.0093 2928 Scan finished
20:23:22.0093 2928 ============================================================
20:23:22.0203 2936 Detected object count: 16
20:23:22.0203 2936 Actual detected object count: 16
20:24:41.0562 2936 BW2NDIS5 ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0562 2936 BW2NDIS5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0578 2936 drvmcdb ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0578 2936 drvmcdb ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0578 2936 drvnddm ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0578 2936 drvnddm ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0578 2936 omci ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0578 2936 omci ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0578 2936 PxHelp20 ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0578 2936 PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0578 2936 sscdbhk5 ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0578 2936 sscdbhk5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0578 2936 ssrtln ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0578 2936 ssrtln ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0593 2936 tfsnboio ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0593 2936 tfsnboio ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0593 2936 tfsncofs ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0593 2936 tfsncofs ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0593 2936 tfsndrct ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0593 2936 tfsndrct ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0593 2936 tfsndres ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0593 2936 tfsndres ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0593 2936 tfsnifs ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0593 2936 tfsnifs ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0593 2936 tfsnopio ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0593 2936 tfsnopio ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0609 2936 tfsnpool ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0609 2936 tfsnpool ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0609 2936 tfsnudf ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0609 2936 tfsnudf ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:24:41.0609 2936 tfsnudfa ( UnsignedFile.Multi.Generic ) - skipped by user
20:24:41.0609 2936 tfsnudfa ( UnsignedFile.Multi.Generic ) - User select action: Skip
AVP scan:
Status: Deleted (events: 3)
2/26/2012 21:34:45 Deleted virus Virus.Win32.ZAccess.c C:\TDSSKiller_Quarantine\15.02.2012_17.40.10\rtkt0000\svc0000\tsk0000.dta High
2/26/2012 21:34:48 Deleted virus Virus.Win32.ZAccess.k C:\WINDOWS\SYSTEM32\DRIVERS\cdrom.sys_backup High
2/26/2012 21:34:53 Deleted virus Virus.Win32.ZAccess.c C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys_backup High
Thanks.
gary