PDA

View Full Version : Desktop caught something nasty



robsad
2011-02-04, 01:55
Here's the situation...

I downloaded a .exe and dbl clicked it. As soon as I double clicked it, it disappeared and my computer rebooted itself. It took forever to start back up and then it blue screened shortly after starting up. I restarted it in safe mode and attempted to do a system restore to my most recent point and the computer started up but was still extremely slow so I assumed something was wrong. I made my way here, downloaded DDS and attempted to run it. As I ran DDS I started getting multiple error messages about programs closing, nircmd.exe, sed.dat, and something along the lines of "Freeware implementation of REG.EXE." Before DDS could finish and produce a log, my computer bluescreened again. I went back to safe mode and tried to run DDS with the same result, a bluescreen error. I'm currently doing a full scan of my computer with malwarebyte in safe mode, but as of yet its not showing any infections.

Please help! and thank you!

Update: I ran spybot and it came up with 7 entries, and fixed them.


I was then able to run DDS and get a log without crashing. Log below:

DDS (Ver_10-12-12.02) - NTFS_AMD64 MINIMAL
Run by Robert at 19:14:23.19 on Thu 02/03/2011
Internet Explorer: 8.0.6001.18999 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4091.3260 [GMT -6:00]

AV: AVG Anti-Virus Free *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Robert\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uURLSearchHooks: SearchHook Class: {bc86e1ab-eda5-4059-938f-ce307b0c6f0a} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office12\GRA8E1~1.DLL
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: BHO Class: {dd92de22-ed91-4560-b788-dee2b26612e6} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\IEHelper.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
uRun: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe /A
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
StartupFolder: C:\Users\Robert\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Yammer.lnk - C:\Program Files (x86)\Yammer\Yammer.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOOPBE~1.LNK - C:\Program Files (x86)\nerds.de\LoopBe1\loopBeMon.exe
uPolicies-system: qskhomddbsacdctmfqofTaskMgr = 0 (0x0)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GR99D3~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office12\GRA8E1~1.DLL
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
mRun-x64: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
AppInit_DLLs-X64: avgrssta.dll
Hosts: 85.17.162.237 l2authd.lineage2.com
Hosts: 85.17.162.237 l2patcher.lineage2.com

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\fra4kn9z.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm080YYUS&ptb=yd.RMYRPxlLo_OWZ.gowpw&psa=&ind=2010041613&ptnrS=ZUxdm080YYUS&si=&st=kwd&n=77cecd0d&searchfor=
FF - component: C:\Program Files (x86)\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Users\Robert\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG9\Firefox
FF - Ext: XULRunner: {019E72A5-C434-4AAE-8E36-281B3288E1BF} - C:\Users\Robert\AppData\Local\{019E72A5-C434-4AAE-8E36-281B3288E1BF}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: ChatZilla: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2} - %profile%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

S1 AvgLdx64;AVG Free AVI Loader Driver x64;C:\Windows\System32\drivers\avgldx64.sys [2009-11-14 269904]
S1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;C:\Windows\System32\drivers\avgmfx64.sys [2009-11-14 35536]
S1 AvgTdiA;AVG Free Network Redirector x64;C:\Windows\System32\drivers\avgtdia.sys [2009-11-14 317520]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-4-6 202752]
S2 avg9wd;AVG Free WatchDog;C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2010-7-15 308136]
S2 BCUService;Browser Configuration Utility Service;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-9-10 212232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-1-7 378984]
S3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-4-6 6659072]
S3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-4-6 195584]
S3 ENTECH64;ENTECH64;C:\Windows\System32\drivers\Entech64.sys [2008-6-27 12744]
S3 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-1-25 155752]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2009-8-28 49152]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-11-8 89920]
S4 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-25 136176]
S4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2010-9-30 23680]

=============== File Associations ===============

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

=============== Created Last 30 ================

2011-02-03 21:20:20 -------- d-----w- C:\Users\Robert\AppData\Roaming\Softplicity
2011-02-03 21:17:15 -------- d-----w- C:\Program Files (x86)\A-PDF Merger
2011-02-03 20:57:54 -------- d-----w- C:\Users\Robert\AppData\Roaming\PrimoPDF
2011-02-03 20:57:26 -------- d-----w- C:\Program Files (x86)\Nitro PDF
2011-02-02 00:02:08 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-02-02 00:01:15 -------- d-----w- C:\Users\Robert\AppData\Local\Microsoft Help
2011-02-01 16:27:54 -------- d-----w- C:\Program Files (x86)\TrueGames
2011-01-26 18:48:16 -------- d-----w- C:\Program Files (x86)\Ventrilo
2011-01-25 19:20:02 -------- d-----w- C:\Users\Robert\AppData\Roaming\Yammer
2011-01-25 19:19:55 -------- d-----w- C:\Program Files (x86)\Yammer
2011-01-24 17:11:52 -------- d-----w- C:\Program Files (x86)\Guild Wars
2011-01-22 17:51:01 -------- d-----w- C:\Users\Robert\AppData\Roaming\RIFT
2011-01-22 17:50:55 -------- d-----w- C:\Program Files (x86)\RIFT
2011-01-13 16:09:19 -------- d-----w- C:\Users\Robert\AppData\Local\CRASH_DUMPS
2011-01-13 16:08:42 -------- d-----w- C:\Users\Robert\AppData\Local\SimuBugCatcher
2011-01-12 20:51:34 -------- d-----w- C:\Users\Robert\AppData\Local\player_client.exe
2011-01-12 06:29:31 -------- d-----w- C:\550a2a91129b02a23cb8cbd8ca92
2011-01-12 04:20:20 466944 ----a-w- C:\Windows\System32\odbc32.dll
2011-01-12 04:20:19 974848 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2011-01-12 04:20:19 708608 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2011-01-12 04:20:19 413696 ----a-w- C:\Windows\SysWow64\odbc32.dll
2011-01-12 04:20:19 253952 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2011-01-12 04:20:18 69632 ----a-w- C:\Program Files\Common Files\System\msadc\msadcs.dll
2011-01-12 04:20:18 57344 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadcs.dll
2011-01-12 04:20:18 286720 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-01-12 04:20:18 278528 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2011-01-12 04:20:18 241664 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2011-01-12 04:20:18 208896 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2011-01-12 04:20:18 180224 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2011-01-12 04:18:46 1251840 ----a-w- C:\Windows\System32\sdclt.exe
2011-01-11 22:49:04 -------- d-----w- C:\Users\Robert\AppData\Local\HeroEngine
2011-01-08 02:49:34 795752 ----a-w- C:\Windows\System32\easyUpdatusAPIU64.dll
2011-01-08 02:49:28 6143080 ----a-w- C:\Windows\System32\nvcpl.dll
2011-01-08 02:49:10 3156072 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-01-08 02:48:58 117864 ----a-w- C:\Windows\System32\nvmctray.dll
2011-01-08 02:48:58 1005160 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-01-06 04:23:21 0 ----a-w- C:\Users\Robert\AppData\Local\Bcoqilitaci.bin
2011-01-06 04:23:19 -------- d-----w- C:\Users\Robert\AppData\Local\{019E72A5-C434-4AAE-8E36-281B3288E1BF}
2011-01-05 21:12:19 -------- d-----w- C:\Program Files (x86)\Black Isle
2011-01-05 21:11:59 212992 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2011-01-05 05:56:26 -------- d-----w- C:\Program Files (x86)\Shadowbane - Throne of Oblivion

==================== Find3M ====================

2010-12-21 00:08:40 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-12-02 09:12:08 1359976 ----a-w- C:\Windows\System32\nvgenco64hda.dll
2010-11-12 00:44:54 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
2010-11-11 23:10:56 29288 ----a-w- C:\Windows\System32\nvhdap64.dll
2010-11-11 23:10:49 155752 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
2010-11-08 22:57:04 353592 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2010-11-06 11:18:48 500224 ----a-w- C:\Windows\System32\wmicmiplugin.dll
2010-11-06 11:18:27 655872 ----a-w- C:\Windows\System32\taskschd.dll
2010-11-06 11:18:27 410112 ----a-w- C:\Windows\System32\taskcomp.dll
2010-11-06 11:18:13 855040 ----a-w- C:\Windows\System32\schedsvc.dll

============= FINISH: 19:15:22.63 ===============

Blade81
2011-02-04, 07:35
Hi,

Please post attach.txt contents too.

robsad
2011-02-04, 08:24
Hmm attach.txt didnt pop up last time. And my PC is bluescreening again everytime I try to run DDS. I will continue to try though and post if I am successful.

heres what windows gave told me after i crashed, dunno if this is at all helpful:

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6002.2.2.0.768.3
Locale ID: 1033

Additional information about the problem:
BCCode: 1e
BCP1: FFFFFFFFC0000005
BCP2: FFFFF80002487703
BCP3: 0000000000000000
BCP4: FFFFFFFFFFFFFFFF
OS Version: 6_0_6002
Service Pack: 2_0
Product: 768_1

Files that help describe the problem:
C:\Windows\Minidump\Mini020411-03.dmp
C:\Users\Robert\AppData\Local\Temp\WER-97235-0.sysdata.xml
C:\Users\Robert\AppData\Local\Temp\WERE88A.tmp.version.txt

Blade81
2011-02-04, 10:31
Hi,

Please download MBRCheck (http://ad13.geekstogo.com/MBRCheck.exe) to your desktop.

1. Right click MBRCheck.exe and select run as administrator to run it.
2. It will open a black window, please do not fix anything (if it gives you an option).
3. Exit that window and it will produce a log (MBRCheck_date_time).
4. Please post that log in your reply.

robsad
2011-02-04, 17:19
MBRCheck log:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 64-bit
Base Board Manufacturer: Gigabyte Technology Co., Ltd.
BIOS Manufacturer: Award Software International, Inc.
System Manufacturer: Gigabyte Technology Co., Ltd.
System Product Name: P55M-UD2
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 86):
0x02414000 \SystemRoot\system32\ntoskrnl.exe
0x0292B000 \SystemRoot\system32\hal.dll
0x00606000 \SystemRoot\system32\kdcom.dll
0x00609000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00644000 \SystemRoot\system32\PSHED.dll
0x00658000 \SystemRoot\system32\CLFS.SYS
0x006B5000 \SystemRoot\system32\CI.dll
0x0080B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x008E5000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00B29000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x00B32000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x00B60000 \SystemRoot\system32\drivers\acpi.sys
0x00BB6000 \SystemRoot\system32\drivers\msisadrv.sys
0x00BC0000 \SystemRoot\system32\drivers\pci.sys
0x008F3000 \SystemRoot\System32\drivers\partmgr.sys
0x00908000 \SystemRoot\system32\drivers\volmgr.sys
0x0091C000 \SystemRoot\System32\drivers\volmgrx.sys
0x00BF0000 \SystemRoot\system32\drivers\pciide.sys
0x00982000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x00992000 \SystemRoot\System32\drivers\mountmgr.sys
0x00BF7000 \SystemRoot\system32\drivers\atapi.sys
0x009A5000 \SystemRoot\system32\drivers\ataport.SYS
0x009C9000 \SystemRoot\system32\DRIVERS\jraid.sys
0x00767000 \SystemRoot\system32\drivers\fltmgr.sys
0x009E7000 \SystemRoot\system32\drivers\fileinfo.sys
0x00C05000 \SystemRoot\System32\Drivers\ksecdd.sys
0x00E08000 \SystemRoot\system32\drivers\ndis.sys
0x00C8C000 \SystemRoot\system32\drivers\msrpc.sys
0x00CDC000 \SystemRoot\system32\drivers\NETIO.SYS
0x01009000 \SystemRoot\System32\drivers\tcpip.sys
0x0117F000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01204000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01384000 \SystemRoot\system32\drivers\volsnap.sys
0x013D0000 \SystemRoot\System32\Drivers\mup.sys
0x011AB000 \SystemRoot\System32\drivers\ecache.sys
0x013E2000 \SystemRoot\system32\drivers\disk.sys
0x00FCB000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x013F6000 \SystemRoot\system32\drivers\crcdisk.sys
0x00A00000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x011F1000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x00D35000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x00D7B000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x00D8C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x00DA8000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x00DB5000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x00DC7000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x00DD7000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x00DED000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x00AED000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x02608000 \SystemRoot\system32\DRIVERS\storport.sys
0x02665000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02672000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02685000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x02691000 \SystemRoot\system32\DRIVERS\swenum.sys
0x02693000 \SystemRoot\system32\DRIVERS\ks.sys
0x026C7000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x026D2000 \SystemRoot\system32\DRIVERS\umbus.sys
0x026E2000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x0272A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x02734000 \SystemRoot\System32\Drivers\Null.SYS
0x0273D000 \SystemRoot\System32\drivers\vga.sys
0x0274B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x02770000 \SystemRoot\System32\drivers\watchdog.sys
0x02780000 \SystemRoot\System32\Drivers\Msfs.SYS
0x0278B000 \SystemRoot\System32\Drivers\Npfs.SYS
0x0279C000 \SystemRoot\System32\Drivers\crashdmp.sys
0x027AA000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x027B6000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x027BE000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x027DA000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x027DC000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x027E7000 \SystemRoot\system32\DRIVERS\dot4usb.sys
0x007AE000 \SystemRoot\system32\DRIVERS\Dot4.sys
0x00080000 \SystemRoot\System32\win32k.sys
0x007D6000 \SystemRoot\System32\drivers\Dxapi.sys
0x00450000 \SystemRoot\System32\drivers\dxg.sys
0x027F7000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x011D7000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x02600000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x00800000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x006E0000 \SystemRoot\System32\TSDDD.dll
0x00880000 \SystemRoot\System32\framebuf.dll
0x007E2000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x04404000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x04420000 \SystemRoot\System32\Drivers\fastfat.SYS
0x774E0000 \Windows\System32\ntdll.dll

Processes (total 18):
0 System Idle Process
4 System
256 C:\Windows\System32\smss.exe
316 csrss.exe
352 csrss.exe
360 C:\Windows\System32\wininit.exe
412 C:\Windows\System32\winlogon.exe
448 C:\Windows\System32\services.exe
472 C:\Windows\System32\lsass.exe
480 C:\Windows\System32\lsm.exe
656 C:\Windows\System32\svchost.exe
720 C:\Windows\System32\svchost.exe
868 C:\Windows\System32\svchost.exe
908 C:\Windows\System32\svchost.exe
968 C:\Windows\System32\svchost.exe
804 C:\Windows\explorer.exe
988 C:\Windows\System32\WerFault.exe
920 C:\Users\Robert\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)

PhysicalDrive0 Model Number: HitachiHDP725050GLA360, Rev: GM4OA5CA

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: 9EFCD394EE24712FDC2F26CC1AB52246A9C5A49A


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Blade81
2011-02-04, 17:43
Hi,

1. Download TDSSKiller (http://support.kaspersky.com/downloads/utils/tdsskiller.zip) and extract its contents into a folder in desired location (i.e. c:\tdsskiller).
2. Execute the file TDSSKiller.exe.
3. Click Start Scan. If threats are found, select cure and click Continue (tool may prompt for a reboot).
4. Post back contents of log file in c: drive root (name should be in UtilityName.Version_Date_Time_log.txt format)

robsad
2011-02-04, 17:59
Thanks for your continued help...TDSS log:

2011/02/04 10:53:33.0261 0620 TDSS rootkit removing tool 2.4.16.0 Feb 1 2011 10:34:03
2011/02/04 10:53:33.0526 0620 ================================================================================
2011/02/04 10:53:33.0526 0620 SystemInfo:
2011/02/04 10:53:33.0526 0620
2011/02/04 10:53:33.0526 0620 OS Version: 6.0.6002 ServicePack: 2.0
2011/02/04 10:53:33.0526 0620 Product type: Workstation
2011/02/04 10:53:33.0526 0620 ComputerName: ROBERT-PC
2011/02/04 10:53:33.0557 0620 UserName: Robert
2011/02/04 10:53:33.0557 0620 Windows directory: C:\Windows
2011/02/04 10:53:33.0557 0620 System windows directory: C:\Windows
2011/02/04 10:53:33.0557 0620 Running under WOW64
2011/02/04 10:53:33.0557 0620 Processor architecture: Intel x64
2011/02/04 10:53:33.0557 0620 Number of processors: 4
2011/02/04 10:53:33.0557 0620 Page size: 0x1000
2011/02/04 10:53:33.0557 0620 Boot type: Safe boot
2011/02/04 10:53:33.0557 0620 ================================================================================
2011/02/04 10:53:34.0103 0620 Initialize success
2011/02/04 10:53:38.0175 0272 ================================================================================
2011/02/04 10:53:38.0175 0272 Scan started
2011/02/04 10:53:38.0175 0272 Mode: Manual;
2011/02/04 10:53:38.0175 0272 ================================================================================
2011/02/04 10:53:41.0295 0272 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
2011/02/04 10:53:41.0482 0272 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
2011/02/04 10:53:41.0607 0272 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
2011/02/04 10:53:41.0731 0272 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
2011/02/04 10:53:41.0856 0272 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
2011/02/04 10:53:42.0246 0272 AFD (12415ccfd3e7cec55b5184e67b039fe4) C:\Windows\system32\drivers\afd.sys
2011/02/04 10:53:42.0371 0272 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
2011/02/04 10:53:42.0418 0272 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
2011/02/04 10:53:42.0558 0272 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
2011/02/04 10:53:42.0699 0272 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
2011/02/04 10:53:42.0761 0272 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
2011/02/04 10:53:43.0525 0272 amdkmdag (cc0b8b1912967d429c4a2d2bd7a9e52d) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/02/04 10:53:43.0666 0272 amdkmdap (b855c99c23a57edeca29f49a3210b95c) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/02/04 10:53:43.0713 0272 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
2011/02/04 10:53:43.0759 0272 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
2011/02/04 10:53:43.0822 0272 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/02/04 10:53:43.0900 0272 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
2011/02/04 10:53:44.0071 0272 atikmdag (cc0b8b1912967d429c4a2d2bd7a9e52d) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/02/04 10:53:44.0181 0272 atksgt (09149d03629a44f4773e621c432d1d89) C:\Windows\system32\DRIVERS\atksgt.sys
2011/02/04 10:53:44.0274 0272 AvgLdx64 (b447db072bf939db9e07bef2adf4ecbd) C:\Windows\System32\Drivers\avgldx64.sys
2011/02/04 10:53:44.0368 0272 AvgMfx64 (405baabbb48f9176e220020b1a77c47b) C:\Windows\System32\Drivers\avgmfx64.sys
2011/02/04 10:53:44.0446 0272 AvgTdiA (ce90aec358a809e7bce6bb0f1da84622) C:\Windows\System32\Drivers\avgtdia.sys
2011/02/04 10:53:44.0493 0272 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
2011/02/04 10:53:44.0524 0272 bowser (8b2b19031d0aeade6e1b933df1acba7e) C:\Windows\system32\DRIVERS\bowser.sys
2011/02/04 10:53:44.0571 0272 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
2011/02/04 10:53:44.0617 0272 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
2011/02/04 10:53:44.0649 0272 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
2011/02/04 10:53:44.0680 0272 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
2011/02/04 10:53:44.0695 0272 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
2011/02/04 10:53:44.0711 0272 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
2011/02/04 10:53:44.0727 0272 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
2011/02/04 10:53:44.0867 0272 Cardex (2bd001601496ae87f7cb86f1fcd6f1ec) C:\Windows\SysWOW64\drivers\TBPANELX64.SYS
2011/02/04 10:53:44.0945 0272 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
2011/02/04 10:53:45.0007 0272 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
2011/02/04 10:53:45.0054 0272 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
2011/02/04 10:53:45.0117 0272 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
2011/02/04 10:53:45.0195 0272 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
2011/02/04 10:53:45.0210 0272 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
2011/02/04 10:53:45.0226 0272 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
2011/02/04 10:53:45.0335 0272 DfsC (36cd31121f228e7e79bae60aa45764c6) C:\Windows\system32\Drivers\dfsc.sys
2011/02/04 10:53:45.0413 0272 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
2011/02/04 10:53:45.0507 0272 Dot4 (74c02b1717740c3b8039539e23e4b53f) C:\Windows\system32\DRIVERS\Dot4.sys
2011/02/04 10:53:45.0553 0272 Dot4Print (08321d1860235bf42cf2854234337aea) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2011/02/04 10:53:45.0569 0272 dot4usb (4adccf0124f2b6911d3786a5d0e779e5) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/02/04 10:53:45.0631 0272 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
2011/02/04 10:53:45.0787 0272 DXGKrnl (1d96e28ebcd96ad1b44a3fd02ca6433d) C:\Windows\System32\drivers\dxgkrnl.sys
2011/02/04 10:53:45.0850 0272 e1express (17d40652ef3e55eeae187a89df40965a) C:\Windows\system32\DRIVERS\e1e6032e.sys
2011/02/04 10:53:45.0897 0272 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
2011/02/04 10:53:45.0990 0272 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
2011/02/04 10:53:46.0068 0272 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
2011/02/04 10:53:46.0177 0272 ENTECH64 (12c061d9f9621be916d58191872ec281) C:\Windows\system32\DRIVERS\ENTECH64.sys
2011/02/04 10:53:46.0209 0272 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
2011/02/04 10:53:46.0489 0272 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
2011/02/04 10:53:46.0848 0272 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
2011/02/04 10:53:47.0113 0272 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
2011/02/04 10:53:47.0550 0272 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
2011/02/04 10:53:47.0862 0272 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
2011/02/04 10:53:48.0361 0272 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/02/04 10:53:48.0658 0272 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
2011/02/04 10:53:49.0173 0272 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
2011/02/04 10:53:49.0375 0272 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
2011/02/04 10:53:49.0906 0272 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/02/04 10:53:50.0311 0272 HdAudAddService (68e732382b32417ff61fd663259b4b09) C:\Windows\system32\drivers\HdAudio.sys
2011/02/04 10:53:51.0013 0272 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/02/04 10:53:51.0481 0272 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
2011/02/04 10:53:51.0684 0272 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
2011/02/04 10:53:52.0168 0272 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
2011/02/04 10:53:52.0480 0272 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
2011/02/04 10:53:53.0182 0272 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
2011/02/04 10:53:53.0603 0272 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
2011/02/04 10:53:53.0977 0272 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/02/04 10:53:54.0367 0272 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
2011/02/04 10:53:54.0679 0272 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
2011/02/04 10:53:55.0662 0272 IntcAzAudAddService (135856ac71116ccff05ed8481745241b) C:\Windows\system32\drivers\RTKVHD64.sys
2011/02/04 10:53:56.0286 0272 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
2011/02/04 10:53:56.0583 0272 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
2011/02/04 10:53:57.0051 0272 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/02/04 10:53:57.0643 0272 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
2011/02/04 10:53:57.0955 0272 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
2011/02/04 10:53:58.0439 0272 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
2011/02/04 10:53:58.0673 0272 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
2011/02/04 10:53:58.0860 0272 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/02/04 10:53:58.0891 0272 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
2011/02/04 10:53:58.0954 0272 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
2011/02/04 10:53:59.0001 0272 JRAID (23ce9aae4e88b95484f616cc572391ac) C:\Windows\system32\DRIVERS\jraid.sys
2011/02/04 10:53:59.0032 0272 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/02/04 10:53:59.0094 0272 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/02/04 10:53:59.0172 0272 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
2011/02/04 10:53:59.0203 0272 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
2011/02/04 10:53:59.0297 0272 lirsgt (5ea407821bb3104c31a705175ab4f309) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/02/04 10:53:59.0328 0272 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
2011/02/04 10:53:59.0375 0272 LoopBeMidi1 (34405e324cef41e00d4f2de6d9440bb7) C:\Windows\system32\drivers\loopbe1.sys
2011/02/04 10:53:59.0437 0272 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
2011/02/04 10:53:59.0515 0272 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
2011/02/04 10:53:59.0562 0272 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
2011/02/04 10:53:59.0609 0272 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
2011/02/04 10:53:59.0671 0272 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
2011/02/04 10:53:59.0765 0272 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
2011/02/04 10:53:59.0843 0272 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
2011/02/04 10:53:59.0921 0272 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
2011/02/04 10:53:59.0937 0272 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
2011/02/04 10:53:59.0952 0272 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
2011/02/04 10:53:59.0983 0272 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
2011/02/04 10:54:00.0030 0272 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
2011/02/04 10:54:00.0093 0272 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
2011/02/04 10:54:00.0139 0272 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
2011/02/04 10:54:00.0171 0272 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
2011/02/04 10:54:00.0249 0272 mrxsmb (d58d129e26705e83a4deba7177eb7972) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/02/04 10:54:00.0280 0272 mrxsmb10 (d5be5c14e0f1dc489f5bb2a67983f630) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/02/04 10:54:00.0295 0272 mrxsmb20 (09a2990c3b293c212816c9bc0d7c200e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/02/04 10:54:00.0311 0272 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
2011/02/04 10:54:00.0373 0272 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
2011/02/04 10:54:00.0436 0272 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
2011/02/04 10:54:00.0467 0272 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
2011/02/04 10:54:00.0514 0272 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
2011/02/04 10:54:00.0529 0272 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/02/04 10:54:00.0545 0272 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
2011/02/04 10:54:00.0623 0272 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
2011/02/04 10:54:00.0670 0272 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/02/04 10:54:00.0685 0272 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
2011/02/04 10:54:00.0748 0272 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
2011/02/04 10:54:00.0810 0272 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
2011/02/04 10:54:00.0904 0272 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
2011/02/04 10:54:00.0951 0272 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/02/04 10:54:00.0966 0272 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/02/04 10:54:01.0029 0272 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/02/04 10:54:01.0060 0272 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
2011/02/04 10:54:01.0091 0272 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
2011/02/04 10:54:01.0153 0272 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
2011/02/04 10:54:01.0263 0272 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
2011/02/04 10:54:01.0309 0272 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
2011/02/04 10:54:01.0356 0272 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
2011/02/04 10:54:01.0434 0272 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
2011/02/04 10:54:01.0465 0272 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
2011/02/04 10:54:01.0559 0272 NVHDA (857fb74754ebff94ee3ad40788740916) C:\Windows\system32\drivers\nvhda64v.sys
2011/02/04 10:54:01.0809 0272 nvlddmkm (f12c5f17d48d9f5c70e4408b3ccb5443) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/02/04 10:54:01.0933 0272 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
2011/02/04 10:54:01.0965 0272 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
2011/02/04 10:54:02.0027 0272 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
2011/02/04 10:54:02.0136 0272 ohci1394 (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/02/04 10:54:02.0245 0272 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
2011/02/04 10:54:02.0308 0272 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
2011/02/04 10:54:02.0370 0272 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
2011/02/04 10:54:02.0401 0272 pciide (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys
2011/02/04 10:54:02.0433 0272 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
2011/02/04 10:54:02.0495 0272 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
2011/02/04 10:54:02.0635 0272 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
2011/02/04 10:54:02.0682 0272 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
2011/02/04 10:54:02.0760 0272 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
2011/02/04 10:54:02.0791 0272 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
2011/02/04 10:54:02.0869 0272 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
2011/02/04 10:54:02.0916 0272 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
2011/02/04 10:54:02.0916 0272 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
2011/02/04 10:54:02.0979 0272 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/02/04 10:54:03.0025 0272 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/02/04 10:54:03.0088 0272 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
2011/02/04 10:54:03.0197 0272 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
2011/02/04 10:54:03.0228 0272 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/02/04 10:54:03.0259 0272 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
2011/02/04 10:54:03.0275 0272 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
2011/02/04 10:54:03.0337 0272 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
2011/02/04 10:54:03.0384 0272 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
2011/02/04 10:54:03.0478 0272 RTL8169 (250cea5e2588e65e95fb2ac3166a1387) C:\Windows\system32\DRIVERS\Rtlh64.sys
2011/02/04 10:54:03.0525 0272 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
2011/02/04 10:54:03.0571 0272 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/02/04 10:54:03.0587 0272 Serenum (2449316316411d65bd2c761a6ffb2ce2) C:\Windows\system32\DRIVERS\serenum.sys
2011/02/04 10:54:03.0618 0272 Serial (4b438170be2fc8e0bd35ee87a960f84f) C:\Windows\system32\DRIVERS\serial.sys
2011/02/04 10:54:03.0681 0272 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
2011/02/04 10:54:03.0727 0272 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
2011/02/04 10:54:03.0774 0272 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
2011/02/04 10:54:03.0790 0272 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
2011/02/04 10:54:03.0805 0272 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
2011/02/04 10:54:03.0852 0272 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
2011/02/04 10:54:03.0899 0272 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
2011/02/04 10:54:03.0961 0272 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
2011/02/04 10:54:04.0055 0272 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
2011/02/04 10:54:04.0133 0272 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
2011/02/04 10:54:04.0211 0272 srv (8cd33a47ca02c79038b669f31f95bdac) C:\Windows\system32\DRIVERS\srv.sys
2011/02/04 10:54:04.0258 0272 srv2 (1bedf533096c56e70f87e3e3ee02caf5) C:\Windows\system32\DRIVERS\srv2.sys
2011/02/04 10:54:04.0273 0272 srvnet (2b8c340f830c465f514d966f7e6a822f) C:\Windows\system32\DRIVERS\srvnet.sys
2011/02/04 10:54:04.0367 0272 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
2011/02/04 10:54:04.0398 0272 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
2011/02/04 10:54:04.0429 0272 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
2011/02/04 10:54:04.0461 0272 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
2011/02/04 10:54:04.0585 0272 Tcpip (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\drivers\tcpip.sys
2011/02/04 10:54:04.0648 0272 Tcpip6 (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\DRIVERS\tcpip.sys
2011/02/04 10:54:04.0710 0272 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
2011/02/04 10:54:04.0741 0272 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
2011/02/04 10:54:04.0788 0272 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
2011/02/04 10:54:04.0835 0272 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
2011/02/04 10:54:04.0897 0272 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
2011/02/04 10:54:04.0991 0272 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/02/04 10:54:05.0038 0272 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
2011/02/04 10:54:05.0085 0272 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
2011/02/04 10:54:05.0131 0272 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
2011/02/04 10:54:05.0163 0272 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
2011/02/04 10:54:05.0194 0272 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
2011/02/04 10:54:05.0241 0272 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
2011/02/04 10:54:05.0319 0272 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
2011/02/04 10:54:05.0365 0272 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
2011/02/04 10:54:05.0412 0272 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
2011/02/04 10:54:05.0475 0272 USBAAPL64 (9e58997a211c8c9ac9e6cffa53614a73) C:\Windows\system32\Drivers\usbaapl64.sys
2011/02/04 10:54:05.0537 0272 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/02/04 10:54:05.0568 0272 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
2011/02/04 10:54:05.0677 0272 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
2011/02/04 10:54:05.0693 0272 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
2011/02/04 10:54:05.0740 0272 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
2011/02/04 10:54:05.0787 0272 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
2011/02/04 10:54:05.0833 0272 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
2011/02/04 10:54:05.0896 0272 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/02/04 10:54:05.0927 0272 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/02/04 10:54:05.0989 0272 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/02/04 10:54:05.0989 0272 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
2011/02/04 10:54:06.0005 0272 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
2011/02/04 10:54:06.0052 0272 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
2011/02/04 10:54:06.0130 0272 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
2011/02/04 10:54:06.0208 0272 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
2011/02/04 10:54:06.0255 0272 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
2011/02/04 10:54:06.0317 0272 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
2011/02/04 10:54:06.0395 0272 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/04 10:54:06.0411 0272 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/04 10:54:06.0457 0272 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
2011/02/04 10:54:06.0520 0272 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
2011/02/04 10:54:06.0613 0272 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
2011/02/04 10:54:06.0691 0272 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/02/04 10:54:06.0738 0272 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
2011/02/04 10:54:06.0785 0272 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/02/04 10:54:06.0816 0272 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/02/04 10:54:06.0847 0272 ================================================================================
2011/02/04 10:54:06.0847 0272 Scan finished
2011/02/04 10:54:06.0847 0272 ================================================================================
2011/02/04 10:54:06.0863 0856 Detected object count: 1
2011/02/04 10:54:24.0881 0856 \HardDisk0 - will be cured after reboot
2011/02/04 10:54:24.0881 0856 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2011/02/04 10:54:27.0751 0980 Deinitialize success

Blade81
2011-02-04, 21:32
Hi,

Please see if you're able to run dds now :)

robsad
2011-02-04, 23:25
Yessir, it ran without a hitch, you're awesome. Attaching both .txts to this post.

Blade81
2011-02-05, 10:37
Hi,

Let's do the following in normal mode (if possible).

You're required to uninstall AVG until we've finished the case.

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

robsad
2011-02-05, 15:58
Again, thank you for your help. Ran combofix, things I noticed that were different than the guide (dunno if these are a big deal or if the procedure just changed and the guide hasnt been updated). Combofix didn't back up my registry, didn't install a recovery console, didn't sever my internet connection and it rebooted my comp between the last stage and preparing the log report. Logs attached below...

Blade81
2011-02-05, 18:18
Hi again,


Open notepad and copy/paste the text in the quotebox below into it:



Firefox::
FF - ProfilePath - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\fra4kn9z.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm080YYUS&ptb=yd.RMYRPxlLo_OWZ.gowpw&psa=&ind=2010041613&ptnrS=ZUxdm080YYUS&si=&st=kwd&n=77cecd0d&searchfor=
Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"qskhomddbsacdctmfqofTaskMgr"=-



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 23 (http://java.sun.com/javase/downloads/index.jsp).
Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u23-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.


* Go here (http://www.eset.eu/online-scanner) to run an online scanner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is UNchecked.
Click Scan
Wait for the scan to finish.


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

robsad
2011-02-05, 23:06
Alright, went through and did all that stuff. Logs attached below. Many thanks for your continued help!

robsad
2011-02-05, 23:25
ComboFix wouldn't fit...zipped it

Blade81
2011-02-06, 00:19
Hi,

Delete C:\Users\Robert\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\20f951d8-1528f564 file (if found). Any issues left?

robsad
2011-02-06, 02:19
Couldn't find that file...

No everything seems to be running fine, should I be worried about the 2 infections that ESET found?

Blade81
2011-02-06, 10:24
Hi,

Use instructions here (http://www.java.com/en/download/help/plugin_cache.xml) to clear Java cache. That should take care of that second ESET finding (if it was still there). The first finding is ok if you know the program it was related to.

Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

A To disable the System Restore feature:

1. Click on the Start button.
2. Hover over the Computer option, right click on it and then click Properties.
3. On the left hand side, click Advanced Settings.
4. If asked to permit the action, click on Allow.
5. Click on the System Protection tab.
6. Uncheck any checkboxes listed for your hard drives.
7. Press OK.


B. Reboot.

C Turn ON System Restore.
Follow the steps like you did when disabling system restore but on step 6. check any checkboxes listed for your hard drives.



Now lets uninstall ComboFix:

Click START then RUN
Now copy-paste Combofix /uninstall in the runbox and click OK



UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.


hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok
Download and run Secunia Personal Software Inspector (PSI) (http://secunia.com/vulnerability_scanning/personal/) and fix its findings.



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

PS. You may reinstall AVG now.

robsad
2011-02-06, 17:02
Went through all those steps. All seems well with my computer now!

Thanks so much for your help. This is the second time I've come to this forum for assistance. You guys are so helpful and so knowledgeable. I am very appreciative of your help as I'm sure others are.

Blade81
2011-02-06, 18:41
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.