I am running a Dell Dimension 3000 using Microsoft XP Professional with Service Pack 3 and all Microsoft updates installed soon after they have been released. I am currently using, and have used for several years, Symantec Enpoint Protection SEP) for my anti-virus program with all updates applied and current anti-virus signatures. SEP did not detect or prevent the Rootkit.ZeroAccess intrusion when it occurred. Nor did SEP detect the infection during full system scans that I periodically run.
However, I suspected that something was wrong with my system and upon investigation using Kaspersky's Root Kit Killer was able to diagnose the presence of Rootkit.ZeroAccess. TDSSKiller wasw not able to remove the rootkit virus. I used a rootkit tool that I found on the Symantec website to "partially" remove the virus. However, a check of the network traffic monitored and blocked by SEP revealed that rootkit-related code was still on my system and periodically attempting to "call home" and answer calls from "home." I have disconnected my computer from the internet until I am confident that the problem has been solved and am using a different computer to communicate with you.
I have followed the instructions in the Guide and include below the results from the actions I have taken. Unfortunately, I never could get DDS to run, either in normal mode or in safe mode. The script would simply hang and never complete. I let the script run for 20-30 minutes without completion. I have run all of the other diagnostic programs. Here are my results.
Thank you in advance for help,
The log from TDSSKiller after using the SEP Rootkit.ZeroAccess tool.
21:49:01.0093 3876 TDSS rootkit removing tool 2.7.19.0 Mar 5 2012 11:23:39
21:49:01.0140 3876 ============================================================
21:49:01.0140 3876 Current date / time: 2012/03/08 21:49:01.0140
21:49:01.0140 3876 SystemInfo:
21:49:01.0140 3876
21:49:01.0140 3876 OS Version: 5.1.2600 ServicePack: 3.0
21:49:01.0140 3876 Product type: Workstation
21:49:01.0140 3876 ComputerName: DEEGAN
21:49:01.0140 3876 UserName: jdeegan
21:49:01.0140 3876 Windows directory: C:\WINDOWS
21:49:01.0140 3876 System windows directory: C:\WINDOWS
21:49:01.0140 3876 Processor architecture: Intel x86
21:49:01.0140 3876 Number of processors: 2
21:49:01.0140 3876 Page size: 0x1000
21:49:01.0140 3876 Boot type: Normal boot
21:49:01.0140 3876 ============================================================
21:49:02.0984 3876 Drive \Device\Harddisk0\DR0 - Size: 0x1C9FEF0000 (114.50 Gb), SectorSize: 0x200, Cylinders: 0x3A62, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:49:02.0984 3876 Drive \Device\Harddisk1\DR1 - Size: 0x1C9FEF0000 (114.50 Gb), SectorSize: 0x200, Cylinders: 0x3A62, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:49:03.0156 3876 Drive \Device\Harddisk4\DR8 - Size: 0x7D00000 (0.12 Gb), SectorSize: 0x200, Cylinders: 0xF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:49:03.0156 3876 \Device\Harddisk0\DR0:
21:49:03.0156 3876 MBR used
21:49:03.0156 3876 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xE4F80E2
21:49:03.0156 3876 \Device\Harddisk1\DR1:
21:49:03.0156 3876 MBR used
21:49:03.0156 3876 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xE4FBFA3
21:49:03.0156 3876 \Device\Harddisk4\DR8:
21:49:03.0171 3876 MBR used
21:49:03.0171 3876 \Device\Harddisk4\DR8\Partition0: MBR, Type 0x6, StartLBA 0x20, BlocksNum 0x3E7DE
21:49:03.0203 3876 Initialize success
21:49:03.0203 3876 ============================================================
21:49:05.0062 1444 ============================================================
21:49:05.0062 1444 Scan started
21:49:05.0062 1444 Mode: Manual;
21:49:05.0062 1444 ============================================================
21:49:06.0156 1444 Abiosdsk - ok
21:49:06.0203 1444 abp480n5 - ok
21:49:06.0265 1444 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:49:06.0265 1444 ACPI - ok
21:49:06.0328 1444 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
21:49:06.0328 1444 ACPIEC - ok
21:49:06.0406 1444 adfs (73685e15ef8b0bd9c30f1af413f13d49) C:\WINDOWS\system32\drivers\adfs.sys
21:49:06.0406 1444 adfs - ok
21:49:06.0437 1444 adpu160m - ok
21:49:06.0500 1444 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
21:49:06.0515 1444 aec - ok
21:49:06.0562 1444 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
21:49:06.0562 1444 AFD - ok
21:49:06.0609 1444 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
21:49:06.0609 1444 agp440 - ok
21:49:06.0640 1444 Aha154x - ok
21:49:06.0671 1444 aic78u2 - ok
21:49:06.0703 1444 aic78xx - ok
21:49:06.0734 1444 AliIde - ok
21:49:06.0765 1444 amsint - ok
21:49:06.0796 1444 asc - ok
21:49:06.0828 1444 asc3350p - ok
21:49:06.0859 1444 asc3550 - ok
21:49:06.0921 1444 Aspi32 (5b01af89d16d562825c4db4530f20cbb) C:\WINDOWS\system32\drivers\aspi32.sys
21:49:06.0921 1444 Aspi32 - ok
21:49:06.0968 1444 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:49:06.0968 1444 AsyncMac - ok
21:49:07.0015 1444 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:49:07.0015 1444 atapi - ok
21:49:07.0046 1444 Atdisk - ok
21:49:07.0093 1444 atirage3 (79e888ccceafb49764b254c2537f1afb) C:\WINDOWS\system32\DRIVERS\atimpae.sys
21:49:07.0093 1444 atirage3 - ok
21:49:07.0140 1444 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:49:07.0140 1444 Atmarpc - ok
21:49:07.0171 1444 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:49:07.0171 1444 audstub - ok
21:49:07.0218 1444 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:49:07.0218 1444 Beep - ok
21:49:07.0265 1444 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:49:07.0281 1444 cbidf2k - ok
21:49:07.0312 1444 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
21:49:07.0312 1444 CCDECODE - ok
21:49:07.0343 1444 cd20xrnt - ok
21:49:07.0390 1444 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:49:07.0390 1444 Cdaudio - ok
21:49:07.0437 1444 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
21:49:07.0437 1444 Cdfs - ok
21:49:07.0484 1444 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:49:07.0484 1444 Cdrom - ok
21:49:07.0515 1444 Changer - ok
21:49:07.0578 1444 CmdIde - ok
21:49:07.0609 1444 Cohbtokdfh - ok
21:49:07.0656 1444 COH_Mon (86a22dff16e8ca67601044efe6825537) C:\WINDOWS\system32\Drivers\COH_Mon.sys
21:49:07.0656 1444 COH_Mon - ok
21:49:07.0703 1444 Cpqarray - ok
21:49:07.0781 1444 cpudrv (d01f685f8b4598d144b0cce9ff95d8d5) C:\Program Files\SystemRequirementsLab\cpudrv.sys
21:49:07.0781 1444 cpudrv - ok
21:49:07.0828 1444 cpuz132 - ok
21:49:07.0890 1444 CVirtA (5c706c06c1279952d2cc1a609ca948bf) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
21:49:07.0890 1444 CVirtA - ok
21:49:07.0937 1444 cwbmidi_device (7623d295feca7f311b750373fe9aed51) C:\WINDOWS\system32\drivers\cwbmidi.sys
21:49:07.0937 1444 cwbmidi_device - ok
21:49:07.0984 1444 cwbwdm_device (86e32e528092092188c58bcf4a9f96c5) C:\WINDOWS\system32\drivers\cwbwdm.sys
21:49:07.0984 1444 cwbwdm_device - ok
21:49:08.0015 1444 dac2w2k - ok
21:49:08.0031 1444 dac960nt - ok
21:49:08.0093 1444 DefragFS (d38c27df7b3e8840b4b92ed5c5c06c2c) C:\WINDOWS\system32\drivers\DefragFS.sys
21:49:08.0093 1444 DefragFS - ok
21:49:08.0156 1444 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
21:49:08.0156 1444 Disk - ok
21:49:08.0234 1444 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
21:49:08.0265 1444 dmboot - ok
21:49:08.0312 1444 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys
21:49:08.0328 1444 dmio - ok
21:49:08.0343 1444 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:49:08.0343 1444 dmload - ok
21:49:08.0390 1444 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
21:49:08.0406 1444 DMusic - ok
21:49:08.0468 1444 DNE (2eddbb3ef1dd5a28cb07c149d36e7286) C:\WINDOWS\system32\DRIVERS\dne2000.sys
21:49:08.0468 1444 DNE - ok
21:49:08.0500 1444 dpti2o - ok
21:49:08.0531 1444 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
21:49:08.0531 1444 drmkaud - ok
21:49:08.0593 1444 E100B (ac9cf17ee2ae003c98eb4f5336c38058) C:\WINDOWS\system32\DRIVERS\e100b325.sys
21:49:08.0593 1444 E100B - ok
21:49:08.0718 1444 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:49:08.0718 1444 eeCtrl - ok
21:49:08.0765 1444 EGATHDRV (7f220875288944c9c7856e2bc8613b1f) C:\WINDOWS\SYSTEM32\EGATHDRV.SYS
21:49:08.0765 1444 EGATHDRV - ok
21:49:08.0781 1444 EL90XBC - ok
21:49:08.0828 1444 EraserUtilRebootDrv (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:49:08.0828 1444 EraserUtilRebootDrv - ok
21:49:08.0890 1444 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
21:49:08.0890 1444 Fastfat - ok
21:49:08.0921 1444 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
21:49:08.0921 1444 Fdc - ok
21:49:08.0984 1444 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
21:49:08.0984 1444 Fips - ok
21:49:09.0015 1444 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
21:49:09.0031 1444 Flpydisk - ok
21:49:09.0078 1444 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
21:49:09.0078 1444 FltMgr - ok
21:49:09.0156 1444 FreshIO (caac750e6d27866c28494e0de9fa802a) C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys
21:49:09.0156 1444 FreshIO - ok
21:49:09.0187 1444 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:49:09.0187 1444 Fs_Rec - ok
21:49:09.0218 1444 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:49:09.0218 1444 Ftdisk - ok
21:49:09.0265 1444 GearAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
21:49:09.0265 1444 GearAspiWDM - ok
21:49:09.0328 1444 GenericMount (69f8f310654d699c7e5bd5c67279980f) C:\WINDOWS\system32\DRIVERS\GenericMount.sys
21:49:09.0328 1444 GenericMount - ok
21:49:09.0375 1444 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:49:09.0375 1444 Gpc - ok
21:49:09.0406 1444 hpn - ok
21:49:09.0453 1444 HPZid412 (30ca91e657cede2f95359d6ef186f650) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
21:49:09.0468 1444 HPZid412 - ok
21:49:09.0500 1444 HPZipr12 (efd31afa752aa7c7bbb57bcbe2b01c78) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
21:49:09.0500 1444 HPZipr12 - ok
21:49:09.0531 1444 HPZius12 (7ac43c38ca8fd7ed0b0a4466f753e06e) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
21:49:09.0531 1444 HPZius12 - ok
21:49:09.0578 1444 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
21:49:09.0578 1444 HTTP - ok
21:49:09.0609 1444 i2omgmt - ok
21:49:09.0640 1444 i2omp - ok
21:49:09.0687 1444 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:49:09.0703 1444 i8042prt - ok
21:49:09.0796 1444 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
21:49:09.0843 1444 ialm - ok
21:49:09.0906 1444 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys
21:49:09.0906 1444 Imapi - ok
21:49:09.0937 1444 ini910u - ok
21:49:09.0984 1444 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
21:49:09.0984 1444 IntelIde - ok
21:49:10.0015 1444 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:49:10.0015 1444 intelppm - ok
21:49:10.0078 1444 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
21:49:10.0078 1444 Ip6Fw - ok
21:49:10.0125 1444 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:49:10.0125 1444 IpFilterDriver - ok
21:49:10.0171 1444 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:49:10.0171 1444 IpInIp - ok
21:49:10.0203 1444 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:49:10.0203 1444 IpNat - ok
21:49:10.0250 1444 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:49:10.0250 1444 IPSec - ok
21:49:10.0281 1444 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:49:10.0296 1444 IRENUM - ok
21:49:10.0343 1444 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:49:10.0343 1444 isapnp - ok
21:49:10.0375 1444 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:49:10.0375 1444 Kbdclass - ok
21:49:10.0421 1444 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
21:49:10.0421 1444 kmixer - ok
21:49:10.0468 1444 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
21:49:10.0468 1444 KSecDD - ok
21:49:10.0500 1444 lbrtfdc - ok
21:49:10.0578 1444 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys
21:49:10.0578 1444 MBAMProtector - ok
21:49:10.0640 1444 mf (a7da20ab18a1bdae28b0f349e57da0d1) C:\WINDOWS\system32\DRIVERS\mf.sys
21:49:10.0640 1444 mf - ok
21:49:10.0687 1444 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:49:10.0687 1444 mnmdd - ok
21:49:10.0734 1444 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
21:49:10.0750 1444 Modem - ok
21:49:10.0781 1444 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:49:10.0781 1444 Mouclass - ok
21:49:10.0875 1444 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
21:49:10.0890 1444 MountMgr - ok
21:49:11.0078 1444 mraid35x - ok
21:49:11.0265 1444 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
21:49:11.0265 1444 MREMP50 - ok
21:49:11.0281 1444 MREMPR5 - ok
21:49:11.0375 1444 MRENDIS5 - ok
21:49:11.0484 1444 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
21:49:11.0484 1444 MRESP50 - ok
21:49:11.0687 1444 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:49:11.0718 1444 MRxDAV - ok
21:49:11.0781 1444 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:49:11.0796 1444 MRxSmb - ok
21:49:11.0828 1444 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
21:49:11.0828 1444 Msfs - ok
21:49:11.0890 1444 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:49:11.0890 1444 MSKSSRV - ok
21:49:11.0921 1444 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:49:11.0921 1444 MSPCLOCK - ok
21:49:11.0953 1444 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
21:49:11.0953 1444 MSPQM - ok
21:49:11.0984 1444 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:49:11.0984 1444 mssmbios - ok
21:49:12.0031 1444 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
21:49:12.0031 1444 MSTEE - ok
21:49:12.0078 1444 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
21:49:12.0078 1444 Mup - ok
21:49:12.0125 1444 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
21:49:12.0125 1444 NABTSFEC - ok
21:49:12.0187 1444 NAL (a467e1deb3bb2b57426c8a5993ba933e) C:\WINDOWS\system32\Drivers\iqvw32.sys
21:49:12.0187 1444 NAL - ok
21:49:12.0343 1444 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20120307.035\NAVENG.SYS
21:49:12.0343 1444 NAVENG - ok
21:49:12.0437 1444 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20120307.035\NAVEX15.SYS
21:49:12.0437 1444 NAVEX15 - ok
21:49:12.0484 1444 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
21:49:12.0484 1444 NDIS - ok
21:49:12.0531 1444 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
21:49:12.0531 1444 NdisIP - ok
21:49:12.0578 1444 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:49:12.0578 1444 NdisTapi - ok
21:49:12.0609 1444 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:49:12.0609 1444 Ndisuio - ok
21:49:12.0656 1444 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:49:12.0656 1444 NdisWan - ok
21:49:12.0718 1444 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
21:49:12.0718 1444 NDProxy - ok
21:49:12.0750 1444 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:49:12.0750 1444 NetBIOS - ok
21:49:12.0796 1444 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:49:12.0796 1444 NetBT - ok
21:49:12.0875 1444 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
21:49:12.0890 1444 nm - ok
21:49:12.0937 1444 NmPar (46253ca6d525c9d90a3dbf0ba0398bc9) C:\WINDOWS\system32\DRIVERS\NmPar.sys
21:49:12.0953 1444 NmPar - ok
21:49:13.0000 1444 NPF (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys
21:49:13.0000 1444 NPF - ok
21:49:13.0046 1444 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
21:49:13.0046 1444 Npfs - ok
21:49:13.0093 1444 NtApm (325ffaeceeace80d2643e6bdc7c1f9e2) C:\WINDOWS\system32\DRIVERS\NtApm.sys
21:49:13.0093 1444 NtApm - ok
21:49:13.0171 1444 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
21:49:13.0218 1444 Ntfs - ok
21:49:13.0250 1444 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:49:13.0250 1444 Null - ok
21:49:13.0796 1444 nv (4b54dcd6adee535df80f07c59ddd8f14) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:49:14.0281 1444 nv - ok
21:49:14.0343 1444 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:49:14.0343 1444 NwlnkFlt - ok
21:49:14.0375 1444 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:49:14.0375 1444 NwlnkFwd - ok
21:49:14.0437 1444 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
21:49:14.0437 1444 Parport - ok
21:49:14.0484 1444 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
21:49:14.0484 1444 PartMgr - ok
21:49:14.0531 1444 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
21:49:14.0531 1444 ParVdm - ok
21:49:14.0562 1444 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
21:49:14.0562 1444 PCI - ok
21:49:14.0593 1444 PCIDump - ok
21:49:14.0625 1444 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:49:14.0625 1444 PCIIde - ok
21:49:14.0687 1444 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
21:49:14.0687 1444 Pcmcia - ok
21:49:14.0718 1444 PDCOMP - ok
21:49:14.0750 1444 PDFRAME - ok
21:49:14.0781 1444 PDRELI - ok
21:49:14.0812 1444 PDRFRAME - ok
21:49:14.0843 1444 perc2 - ok
21:49:14.0875 1444 perc2hib - ok
21:49:15.0000 1444 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:49:15.0000 1444 PptpMiniport - ok
21:49:15.0031 1444 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
21:49:15.0046 1444 Processor - ok
21:49:15.0109 1444 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
21:49:15.0109 1444 PSched - ok
21:49:15.0156 1444 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\WINDOWS\system32\DRIVERS\psi_mf.sys
21:49:15.0156 1444 PSI - ok
21:49:15.0203 1444 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:49:15.0203 1444 Ptilink - ok
21:49:15.0250 1444 PxHelp20 (40fedd328f98245ad201cf5f9f311724) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
21:49:15.0250 1444 PxHelp20 - ok
21:49:15.0281 1444 ql1080 - ok
21:49:15.0296 1444 Ql10wnt - ok
21:49:15.0328 1444 ql12160 - ok
21:49:15.0359 1444 ql1240 - ok
21:49:15.0390 1444 ql1280 - ok
21:49:15.0437 1444 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:49:15.0437 1444 RasAcd - ok
21:49:15.0500 1444 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:49:15.0500 1444 Rasl2tp - ok
21:49:15.0562 1444 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:49:15.0562 1444 RasPppoe - ok
21:49:15.0609 1444 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:49:15.0609 1444 Raspti - ok
21:49:15.0656 1444 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:49:15.0656 1444 Rdbss - ok
21:49:15.0687 1444 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:49:15.0687 1444 RDPCDD - ok
21:49:15.0734 1444 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:49:15.0750 1444 rdpdr - ok
21:49:15.0796 1444 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
21:49:15.0812 1444 RDPWD - ok
21:49:15.0875 1444 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:49:15.0875 1444 redbook - ok
21:49:15.0906 1444 RimUsb - ok
21:49:15.0953 1444 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
21:49:15.0953 1444 RimVSerPort - ok
21:49:16.0000 1444 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
21:49:16.0000 1444 ROOTMODEM - ok
21:49:16.0093 1444 RTL8023xp (47b8ea4493ebffb3d6a0e06cd03c5aba) C:\WINDOWS\system32\DRIVERS\FA311XP.SYS
21:49:16.0093 1444 RTL8023xp - ok
21:49:16.0140 1444 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
21:49:16.0140 1444 rtl8139 - ok
21:49:16.0171 1444 SANDRA - ok
21:49:16.0218 1444 SBRE - ok
21:49:16.0296 1444 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:49:16.0296 1444 Secdrv - ok
21:49:16.0375 1444 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys
21:49:16.0406 1444 senfilt - ok
21:49:16.0453 1444 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
21:49:16.0453 1444 serenum - ok
21:49:16.0500 1444 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
21:49:16.0500 1444 Serial - ok
21:49:16.0578 1444 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:49:16.0593 1444 Sfloppy - ok
21:49:16.0625 1444 Simbad - ok
21:49:16.0671 1444 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
21:49:16.0671 1444 SLIP - ok
21:49:16.0750 1444 smwdm (86c4d93b7b7818d066c52fdb03c6c921) C:\WINDOWS\system32\drivers\smwdm.sys
21:49:16.0750 1444 smwdm - ok
21:49:16.0781 1444 Sparrow - ok
21:49:16.0921 1444 SPBBCDrv (e87cf104f12c92401c4d33c50a3d5dc8) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
21:49:16.0937 1444 SPBBCDrv - ok
21:49:16.0984 1444 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
21:49:16.0984 1444 splitter - ok
21:49:17.0031 1444 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\System32\DRIVERS\sr.sys
21:49:17.0031 1444 sr - ok
21:49:17.0093 1444 SRTSP (620bbcc5c4c4407447866793c36e1215) C:\WINDOWS\system32\Drivers\SRTSP.SYS
21:49:17.0093 1444 SRTSP - ok
21:49:17.0156 1444 SRTSPL (995e15de499ca58445e39a2fba7d170e) C:\WINDOWS\system32\Drivers\SRTSPL.SYS
21:49:17.0171 1444 SRTSPL - ok
21:49:17.0203 1444 SRTSPX (1b63f794f283b974a79084514df206a0) C:\WINDOWS\system32\Drivers\SRTSPX.SYS
21:49:17.0203 1444 SRTSPX - ok
21:49:17.0265 1444 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
21:49:17.0281 1444 Srv - ok
21:49:17.0312 1444 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
21:49:17.0312 1444 streamip - ok
21:49:17.0375 1444 SUSTUCAM (0349f7702b819986c292825c676d00fa) C:\WINDOWS\system32\DRIVERS\sustucam.sys
21:49:17.0375 1444 SUSTUCAM - ok
21:49:17.0421 1444 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:49:17.0421 1444 swenum - ok
21:49:17.0453 1444 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
21:49:17.0468 1444 swmidi - ok
21:49:17.0515 1444 symc810 - ok
21:49:17.0546 1444 symc8xx - ok
21:49:17.0593 1444 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
21:49:17.0609 1444 SymEvent - ok
21:49:17.0656 1444 SYMREDRV (394b2368212114d538316812af60fddd) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
21:49:17.0656 1444 SYMREDRV - ok
21:49:17.0703 1444 symsnap (a5cf31080e99718949bcc38c83f13452) C:\WINDOWS\system32\DRIVERS\symsnap.sys
21:49:17.0703 1444 symsnap - ok
21:49:17.0750 1444 SYMTDI (d46676bb414c7531bdffe637a33f5033) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
21:49:17.0750 1444 SYMTDI - ok
21:49:17.0781 1444 sym_hi - ok
21:49:17.0812 1444 sym_u3 - ok
21:49:17.0859 1444 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
21:49:17.0859 1444 sysaudio - ok
21:49:17.0890 1444 SysPlant (c8f9eb4ac42740d036b0b9f0809b335b) C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys
21:49:17.0890 1444 SysPlant - ok
21:49:17.0968 1444 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:49:17.0968 1444 Tcpip - ok
21:49:18.0031 1444 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
21:49:18.0046 1444 Tcpip6 - ok
21:49:18.0078 1444 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:49:18.0093 1444 TDPIPE - ok
21:49:18.0140 1444 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
21:49:18.0156 1444 TDTCP - ok
21:49:18.0203 1444 Teefer2 (75346634d815c9fda103ae5fada072b3) C:\WINDOWS\system32\DRIVERS\teefer2.sys
21:49:18.0203 1444 Teefer2 - ok
21:49:18.0250 1444 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:49:18.0250 1444 TermDD - ok
21:49:18.0296 1444 TosIde - ok
21:49:18.0359 1444 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
21:49:18.0359 1444 tunmp - ok
21:49:18.0406 1444 TVICHW32 (e266683fc95abdec17cd378564e1b54b) C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
21:49:18.0406 1444 TVICHW32 - ok
21:49:18.0453 1444 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
21:49:18.0468 1444 Udfs - ok
21:49:18.0500 1444 ultra - ok
21:49:18.0546 1444 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
21:49:18.0562 1444 Update - ok
21:49:18.0609 1444 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
21:49:18.0625 1444 usbaudio - ok
21:49:18.0671 1444 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:49:18.0671 1444 usbccgp - ok
21:49:18.0703 1444 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:49:18.0703 1444 usbehci - ok
21:49:18.0750 1444 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:49:18.0765 1444 usbhub - ok
21:49:18.0796 1444 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
21:49:18.0796 1444 usbprint - ok
21:49:18.0843 1444 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:49:18.0843 1444 usbscan - ok
21:49:18.0875 1444 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:49:18.0875 1444 USBSTOR - ok
21:49:18.0906 1444 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:49:18.0906 1444 usbuhci - ok
21:49:18.0953 1444 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
21:49:18.0953 1444 usbvideo - ok
21:49:19.0000 1444 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
21:49:19.0000 1444 VgaSave - ok
21:49:19.0031 1444 ViaIde - ok
21:49:19.0078 1444 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
21:49:19.0078 1444 VolSnap - ok
21:49:19.0109 1444 VProEventMonitor (ef3506b04eb9124240b35148eaacbaa5) C:\WINDOWS\system32\DRIVERS\vproeventmonitor.sys
21:49:19.0109 1444 VProEventMonitor - ok
21:49:19.0140 1444 vsdatant - ok
21:49:19.0218 1444 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:49:19.0218 1444 Wanarp - ok
21:49:19.0281 1444 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
21:49:19.0296 1444 Wdf01000 - ok
21:49:19.0328 1444 WDICA - ok
21:49:19.0375 1444 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
21:49:19.0375 1444 wdmaud - ok
21:49:19.0421 1444 WimFltr (090a2b8f055343815556a01f725f6c35) C:\WINDOWS\system32\DRIVERS\wimfltr.sys
21:49:19.0437 1444 WimFltr - ok
21:49:19.0609 1444 WPS (d81ef0d8716500a573cd82185ef3e42d) C:\WINDOWS\system32\drivers\wpsdrvnt.sys
21:49:19.0609 1444 WPS - ok
21:49:19.0671 1444 WpsHelper (ff983a25ae6f7d3f87f26bf51f02a201) C:\WINDOWS\system32\drivers\WpsHelper.sys
21:49:19.0671 1444 WpsHelper - ok
21:49:19.0718 1444 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
21:49:19.0718 1444 WSTCODEC - ok
21:49:19.0765 1444 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
21:49:19.0765 1444 WudfPf - ok
21:49:19.0812 1444 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
21:49:19.0812 1444 WudfRd - ok
21:49:19.0875 1444 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
21:49:19.0984 1444 \Device\Harddisk0\DR0 - ok
21:49:20.0000 1444 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1
21:49:22.0796 1444 \Device\Harddisk1\DR1 - ok
21:49:22.0828 1444 MBR (0x1B8) (ad00bc00aca714232fd4768277895154) \Device\Harddisk4\DR8
21:49:25.0593 1444 \Device\Harddisk4\DR8 - ok
21:49:25.0593 1444 Boot (0x1200) (89f2c810a8038e78c80a14ff359355e4) \Device\Harddisk0\DR0\Partition0
21:49:25.0593 1444 \Device\Harddisk0\DR0\Partition0 - ok
21:49:25.0609 1444 Boot (0x1200) (cd642ed4c466c642e62839d2aa735447) \Device\Harddisk1\DR1\Partition0
21:49:25.0609 1444 \Device\Harddisk1\DR1\Partition0 - ok
21:49:25.0640 1444 Boot (0x1200) (b66a625fb30818cf5e6150aa1cb4a95f) \Device\Harddisk4\DR8\Partition0
21:49:25.0640 1444 \Device\Harddisk4\DR8\Partition0 - ok
21:49:25.0640 1444 ============================================================
21:49:25.0640 1444 Scan finished
21:49:25.0640 1444 ============================================================
21:49:25.0671 1396 Detected object count: 0
21:49:25.0671 1396 Actual detected object count: 0
21:49:49.0234 3844 Deinitialize success
The log from Malwarebytes Anti-malware:
Malwarebytes Anti-Malware (PRO) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.07.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
jdeegan :: DEEGAN [administrator]
Protection: Enabled
3/7/2012 9:17:42 AM
mbam-log-2012-03-07 (09-17-42).txt
Scan type: Flash scan
Scan options enabled: Memory | Startup | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: Registry | File System | P2P
Objects scanned: 153266
Time elapsed: 1 minute(s), 6 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
The log from ansMBR:
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-06 13:08:30
-----------------------------
13:08:30.625 OS Version: Windows 5.1.2600 Service Pack 3
13:08:30.625 Number of processors: 2 586 0x401
13:08:30.625 ComputerName: DEEGAN UserName:
13:08:31.562 Initialize success
13:08:42.718 AVAST engine defs: 12030600
13:08:50.671 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
13:08:50.671 Disk 0 Vendor: Maxtor_6Y120P0 YAR41BW0 Size: 117246MB BusType: 3
13:08:50.671 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
13:08:50.671 Disk 1 Vendor: Maxtor_6Y120P0 YAR41BW0 Size: 117246MB BusType: 3
13:08:50.671 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T0L0-18
13:08:50.671 Disk 2 Vendor: IOMEGA_ZIP_250 42.S Size: 117246MB BusType: 2
13:08:50.687 Disk 0 MBR read successfully
13:08:50.687 Disk 0 MBR scan
13:08:50.718 Disk 0 Windows XP default MBR code
13:08:50.718 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 117232 MB offset 63
13:08:50.734 Disk 0 scanning sectors +240091425
13:08:50.781 Disk 0 scanning C:\WINDOWS\system32\drivers
13:09:08.140 Service scanning
13:09:26.859 Service SysPlant C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys **LOCKED** 32
13:09:27.203 Service Teefer2 C:\WINDOWS\system32\DRIVERS\teefer2.sys **LOCKED** 32
13:09:29.843 Service WPS C:\WINDOWS\system32\drivers\wpsdrvnt.sys **LOCKED** 32
13:09:29.906 Service WpsHelper C:\WINDOWS\system32\drivers\WpsHelper.sys **LOCKED** 32
13:09:30.781 Modules scanning
13:09:37.359 Disk 0 trace - called modules:
13:09:37.375 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
13:09:37.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a5acab8]
13:09:37.375 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x8a63ad98]
13:09:37.375 Scan finished successfully
13:10:00.343 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\jdeegan\Desktop\MBR.dat"
13:10:00.343 The log file has been saved successfully to "C:\Documents and Settings\jdeegan\Desktop\aswMBR.txt"
The log from Symantec Endpoint Protection:
Symantec Endpoint Protect Ver. 11.0.7101.1056
Virus Definitions dated 03/08/2012
Partial Log of Network Threat Protection Traffic log for 03/07/2012 and 03/08/2012
183517 3/7/2012 11:59:04 PM Blocked 10 Incoming UDP 192.168.1.2 00-1E-2A-47-63-5C 137 192.168.1.255 FF-FF-FF-FF-FF-FF 137 C:\WINDOWS\system32\ntoskrnl.exe jdeegan DEEGAN Default 9 3/7/2012 11:58:03 PM 3/7/2012 11:58:14 PM GUI%GUICONFIG#SRULE@NBBLOCK#BLOCK-UDP
183636 3/8/2012 7:12:07 AM Blocked 10 Outgoing UDP 192.168.1.255 FF-FF-FF-FF-FF-FF 138 192.168.1.2 00-1E-2A-47-63-5C 138 C:\WINDOWS\system32\ntoskrnl.exe jdeegan DEEGAN Default 1 3/8/2012 7:11:05 AM 3/8/2012 7:11:05 AM GUI%GUICONFIG#SRULE@NBBLOCK#BLOCK-UDP
....... more of the same
183657 3/8/2012 8:24:04 AM Blocked 10 Outgoing UDP 192.168.1.255 FF-FF-FF-FF-FF-FF 138 192.168.1.2 00-1E-2A-47-63-5C 138 C:\WINDOWS\system32\ntoskrnl.exe jdeegan DEEGAN Default 1 3/8/2012 8:23:03 AM 3/8/2012 8:23:03 AM GUI%GUICONFIG#SRULE@NBBLOCK#BLOCK-UDP
Finally, the log from GMER:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-08 08:27:05
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Maxtor_6Y120P0 rev.YAR41BW0
Running: GMER.exe; Driver: C:\DOCUME~1\jdeegan\LOCALS~1\Temp\ugtdapod.sys
---- System - GMER 1.0.15 ----
SSDT 8A222128 ZwAlertResumeThread
SSDT 8A4C4DC8 ZwAlertThread
SSDT 8A21E310 ZwAllocateVirtualMemory
SSDT 8A58D4D8 ZwConnectPort
SSDT 8A4150E8 ZwCreateMutant
SSDT 8A222160 ZwCreateThread
SSDT 8A23E410 ZwFreeVirtualMemory
SSDT 8A4151B8 ZwImpersonateAnonymousToken
SSDT 8A2216B8 ZwImpersonateThread
SSDT 8A239618 ZwMapViewOfSection
SSDT 8A248008 ZwOpenEvent
SSDT 8A4E81F0 ZwOpenProcessToken
SSDT 8A23B180 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xB6B87BA0]
SSDT 8A4B5AD0 ZwResumeThread
SSDT 8A431100 ZwSetContextThread
SSDT 8A22AF38 ZwSetInformationProcess
SSDT 8A221848 ZwSetInformationThread
SSDT 8A248130 ZwSuspendProcess
SSDT 8A41B788 ZwSuspendThread
SSDT 8A4D2738 ZwTerminateProcess
SSDT 8A225860 ZwTerminateThread
SSDT 8A4C6E78 ZwUnmapViewOfSection
SSDT 8A224BB0 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution + 122 804E497C 4 Bytes [E8, 50, 41, 8A]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB7105380, 0x8D6CD5, 0xE8000020]
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB7027F80]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AA5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD119 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB14 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254686 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E53AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E52E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E534C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E51B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E5214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E5412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E5276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 3E2EDB70 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ole32.dll!OleLoadFromStream 7752983B 5 Bytes JMP 3E3E5717 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 46CB3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 46CB41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!socket 71AB4211 5 Bytes JMP 46CB354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 46CB35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!send 71AB4C27 5 Bytes JMP 46CB3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!recv 71AB676F 5 Bytes JMP 46CB4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB14 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E53AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E52E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E534C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E51B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E5214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E5412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E5276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device ftdisk.sys (FT Disk Driver/Microsoft Corporation)
Device \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\IPMULTICAST wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Again, I could not get DDS to run successfully and am unable to produce its log.
However, I suspected that something was wrong with my system and upon investigation using Kaspersky's Root Kit Killer was able to diagnose the presence of Rootkit.ZeroAccess. TDSSKiller wasw not able to remove the rootkit virus. I used a rootkit tool that I found on the Symantec website to "partially" remove the virus. However, a check of the network traffic monitored and blocked by SEP revealed that rootkit-related code was still on my system and periodically attempting to "call home" and answer calls from "home." I have disconnected my computer from the internet until I am confident that the problem has been solved and am using a different computer to communicate with you.
I have followed the instructions in the Guide and include below the results from the actions I have taken. Unfortunately, I never could get DDS to run, either in normal mode or in safe mode. The script would simply hang and never complete. I let the script run for 20-30 minutes without completion. I have run all of the other diagnostic programs. Here are my results.
Thank you in advance for help,
The log from TDSSKiller after using the SEP Rootkit.ZeroAccess tool.
21:49:01.0093 3876 TDSS rootkit removing tool 2.7.19.0 Mar 5 2012 11:23:39
21:49:01.0140 3876 ============================================================
21:49:01.0140 3876 Current date / time: 2012/03/08 21:49:01.0140
21:49:01.0140 3876 SystemInfo:
21:49:01.0140 3876
21:49:01.0140 3876 OS Version: 5.1.2600 ServicePack: 3.0
21:49:01.0140 3876 Product type: Workstation
21:49:01.0140 3876 ComputerName: DEEGAN
21:49:01.0140 3876 UserName: jdeegan
21:49:01.0140 3876 Windows directory: C:\WINDOWS
21:49:01.0140 3876 System windows directory: C:\WINDOWS
21:49:01.0140 3876 Processor architecture: Intel x86
21:49:01.0140 3876 Number of processors: 2
21:49:01.0140 3876 Page size: 0x1000
21:49:01.0140 3876 Boot type: Normal boot
21:49:01.0140 3876 ============================================================
21:49:02.0984 3876 Drive \Device\Harddisk0\DR0 - Size: 0x1C9FEF0000 (114.50 Gb), SectorSize: 0x200, Cylinders: 0x3A62, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:49:02.0984 3876 Drive \Device\Harddisk1\DR1 - Size: 0x1C9FEF0000 (114.50 Gb), SectorSize: 0x200, Cylinders: 0x3A62, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:49:03.0156 3876 Drive \Device\Harddisk4\DR8 - Size: 0x7D00000 (0.12 Gb), SectorSize: 0x200, Cylinders: 0xF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:49:03.0156 3876 \Device\Harddisk0\DR0:
21:49:03.0156 3876 MBR used
21:49:03.0156 3876 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xE4F80E2
21:49:03.0156 3876 \Device\Harddisk1\DR1:
21:49:03.0156 3876 MBR used
21:49:03.0156 3876 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xE4FBFA3
21:49:03.0156 3876 \Device\Harddisk4\DR8:
21:49:03.0171 3876 MBR used
21:49:03.0171 3876 \Device\Harddisk4\DR8\Partition0: MBR, Type 0x6, StartLBA 0x20, BlocksNum 0x3E7DE
21:49:03.0203 3876 Initialize success
21:49:03.0203 3876 ============================================================
21:49:05.0062 1444 ============================================================
21:49:05.0062 1444 Scan started
21:49:05.0062 1444 Mode: Manual;
21:49:05.0062 1444 ============================================================
21:49:06.0156 1444 Abiosdsk - ok
21:49:06.0203 1444 abp480n5 - ok
21:49:06.0265 1444 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:49:06.0265 1444 ACPI - ok
21:49:06.0328 1444 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
21:49:06.0328 1444 ACPIEC - ok
21:49:06.0406 1444 adfs (73685e15ef8b0bd9c30f1af413f13d49) C:\WINDOWS\system32\drivers\adfs.sys
21:49:06.0406 1444 adfs - ok
21:49:06.0437 1444 adpu160m - ok
21:49:06.0500 1444 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
21:49:06.0515 1444 aec - ok
21:49:06.0562 1444 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
21:49:06.0562 1444 AFD - ok
21:49:06.0609 1444 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
21:49:06.0609 1444 agp440 - ok
21:49:06.0640 1444 Aha154x - ok
21:49:06.0671 1444 aic78u2 - ok
21:49:06.0703 1444 aic78xx - ok
21:49:06.0734 1444 AliIde - ok
21:49:06.0765 1444 amsint - ok
21:49:06.0796 1444 asc - ok
21:49:06.0828 1444 asc3350p - ok
21:49:06.0859 1444 asc3550 - ok
21:49:06.0921 1444 Aspi32 (5b01af89d16d562825c4db4530f20cbb) C:\WINDOWS\system32\drivers\aspi32.sys
21:49:06.0921 1444 Aspi32 - ok
21:49:06.0968 1444 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:49:06.0968 1444 AsyncMac - ok
21:49:07.0015 1444 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:49:07.0015 1444 atapi - ok
21:49:07.0046 1444 Atdisk - ok
21:49:07.0093 1444 atirage3 (79e888ccceafb49764b254c2537f1afb) C:\WINDOWS\system32\DRIVERS\atimpae.sys
21:49:07.0093 1444 atirage3 - ok
21:49:07.0140 1444 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:49:07.0140 1444 Atmarpc - ok
21:49:07.0171 1444 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:49:07.0171 1444 audstub - ok
21:49:07.0218 1444 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:49:07.0218 1444 Beep - ok
21:49:07.0265 1444 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:49:07.0281 1444 cbidf2k - ok
21:49:07.0312 1444 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
21:49:07.0312 1444 CCDECODE - ok
21:49:07.0343 1444 cd20xrnt - ok
21:49:07.0390 1444 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:49:07.0390 1444 Cdaudio - ok
21:49:07.0437 1444 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
21:49:07.0437 1444 Cdfs - ok
21:49:07.0484 1444 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:49:07.0484 1444 Cdrom - ok
21:49:07.0515 1444 Changer - ok
21:49:07.0578 1444 CmdIde - ok
21:49:07.0609 1444 Cohbtokdfh - ok
21:49:07.0656 1444 COH_Mon (86a22dff16e8ca67601044efe6825537) C:\WINDOWS\system32\Drivers\COH_Mon.sys
21:49:07.0656 1444 COH_Mon - ok
21:49:07.0703 1444 Cpqarray - ok
21:49:07.0781 1444 cpudrv (d01f685f8b4598d144b0cce9ff95d8d5) C:\Program Files\SystemRequirementsLab\cpudrv.sys
21:49:07.0781 1444 cpudrv - ok
21:49:07.0828 1444 cpuz132 - ok
21:49:07.0890 1444 CVirtA (5c706c06c1279952d2cc1a609ca948bf) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
21:49:07.0890 1444 CVirtA - ok
21:49:07.0937 1444 cwbmidi_device (7623d295feca7f311b750373fe9aed51) C:\WINDOWS\system32\drivers\cwbmidi.sys
21:49:07.0937 1444 cwbmidi_device - ok
21:49:07.0984 1444 cwbwdm_device (86e32e528092092188c58bcf4a9f96c5) C:\WINDOWS\system32\drivers\cwbwdm.sys
21:49:07.0984 1444 cwbwdm_device - ok
21:49:08.0015 1444 dac2w2k - ok
21:49:08.0031 1444 dac960nt - ok
21:49:08.0093 1444 DefragFS (d38c27df7b3e8840b4b92ed5c5c06c2c) C:\WINDOWS\system32\drivers\DefragFS.sys
21:49:08.0093 1444 DefragFS - ok
21:49:08.0156 1444 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
21:49:08.0156 1444 Disk - ok
21:49:08.0234 1444 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
21:49:08.0265 1444 dmboot - ok
21:49:08.0312 1444 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys
21:49:08.0328 1444 dmio - ok
21:49:08.0343 1444 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:49:08.0343 1444 dmload - ok
21:49:08.0390 1444 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
21:49:08.0406 1444 DMusic - ok
21:49:08.0468 1444 DNE (2eddbb3ef1dd5a28cb07c149d36e7286) C:\WINDOWS\system32\DRIVERS\dne2000.sys
21:49:08.0468 1444 DNE - ok
21:49:08.0500 1444 dpti2o - ok
21:49:08.0531 1444 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
21:49:08.0531 1444 drmkaud - ok
21:49:08.0593 1444 E100B (ac9cf17ee2ae003c98eb4f5336c38058) C:\WINDOWS\system32\DRIVERS\e100b325.sys
21:49:08.0593 1444 E100B - ok
21:49:08.0718 1444 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:49:08.0718 1444 eeCtrl - ok
21:49:08.0765 1444 EGATHDRV (7f220875288944c9c7856e2bc8613b1f) C:\WINDOWS\SYSTEM32\EGATHDRV.SYS
21:49:08.0765 1444 EGATHDRV - ok
21:49:08.0781 1444 EL90XBC - ok
21:49:08.0828 1444 EraserUtilRebootDrv (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:49:08.0828 1444 EraserUtilRebootDrv - ok
21:49:08.0890 1444 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
21:49:08.0890 1444 Fastfat - ok
21:49:08.0921 1444 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
21:49:08.0921 1444 Fdc - ok
21:49:08.0984 1444 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
21:49:08.0984 1444 Fips - ok
21:49:09.0015 1444 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
21:49:09.0031 1444 Flpydisk - ok
21:49:09.0078 1444 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
21:49:09.0078 1444 FltMgr - ok
21:49:09.0156 1444 FreshIO (caac750e6d27866c28494e0de9fa802a) C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys
21:49:09.0156 1444 FreshIO - ok
21:49:09.0187 1444 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:49:09.0187 1444 Fs_Rec - ok
21:49:09.0218 1444 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:49:09.0218 1444 Ftdisk - ok
21:49:09.0265 1444 GearAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
21:49:09.0265 1444 GearAspiWDM - ok
21:49:09.0328 1444 GenericMount (69f8f310654d699c7e5bd5c67279980f) C:\WINDOWS\system32\DRIVERS\GenericMount.sys
21:49:09.0328 1444 GenericMount - ok
21:49:09.0375 1444 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:49:09.0375 1444 Gpc - ok
21:49:09.0406 1444 hpn - ok
21:49:09.0453 1444 HPZid412 (30ca91e657cede2f95359d6ef186f650) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
21:49:09.0468 1444 HPZid412 - ok
21:49:09.0500 1444 HPZipr12 (efd31afa752aa7c7bbb57bcbe2b01c78) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
21:49:09.0500 1444 HPZipr12 - ok
21:49:09.0531 1444 HPZius12 (7ac43c38ca8fd7ed0b0a4466f753e06e) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
21:49:09.0531 1444 HPZius12 - ok
21:49:09.0578 1444 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
21:49:09.0578 1444 HTTP - ok
21:49:09.0609 1444 i2omgmt - ok
21:49:09.0640 1444 i2omp - ok
21:49:09.0687 1444 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:49:09.0703 1444 i8042prt - ok
21:49:09.0796 1444 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
21:49:09.0843 1444 ialm - ok
21:49:09.0906 1444 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys
21:49:09.0906 1444 Imapi - ok
21:49:09.0937 1444 ini910u - ok
21:49:09.0984 1444 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
21:49:09.0984 1444 IntelIde - ok
21:49:10.0015 1444 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:49:10.0015 1444 intelppm - ok
21:49:10.0078 1444 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
21:49:10.0078 1444 Ip6Fw - ok
21:49:10.0125 1444 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:49:10.0125 1444 IpFilterDriver - ok
21:49:10.0171 1444 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:49:10.0171 1444 IpInIp - ok
21:49:10.0203 1444 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:49:10.0203 1444 IpNat - ok
21:49:10.0250 1444 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:49:10.0250 1444 IPSec - ok
21:49:10.0281 1444 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:49:10.0296 1444 IRENUM - ok
21:49:10.0343 1444 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:49:10.0343 1444 isapnp - ok
21:49:10.0375 1444 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:49:10.0375 1444 Kbdclass - ok
21:49:10.0421 1444 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
21:49:10.0421 1444 kmixer - ok
21:49:10.0468 1444 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
21:49:10.0468 1444 KSecDD - ok
21:49:10.0500 1444 lbrtfdc - ok
21:49:10.0578 1444 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys
21:49:10.0578 1444 MBAMProtector - ok
21:49:10.0640 1444 mf (a7da20ab18a1bdae28b0f349e57da0d1) C:\WINDOWS\system32\DRIVERS\mf.sys
21:49:10.0640 1444 mf - ok
21:49:10.0687 1444 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:49:10.0687 1444 mnmdd - ok
21:49:10.0734 1444 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
21:49:10.0750 1444 Modem - ok
21:49:10.0781 1444 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:49:10.0781 1444 Mouclass - ok
21:49:10.0875 1444 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
21:49:10.0890 1444 MountMgr - ok
21:49:11.0078 1444 mraid35x - ok
21:49:11.0265 1444 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
21:49:11.0265 1444 MREMP50 - ok
21:49:11.0281 1444 MREMPR5 - ok
21:49:11.0375 1444 MRENDIS5 - ok
21:49:11.0484 1444 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
21:49:11.0484 1444 MRESP50 - ok
21:49:11.0687 1444 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:49:11.0718 1444 MRxDAV - ok
21:49:11.0781 1444 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:49:11.0796 1444 MRxSmb - ok
21:49:11.0828 1444 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
21:49:11.0828 1444 Msfs - ok
21:49:11.0890 1444 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:49:11.0890 1444 MSKSSRV - ok
21:49:11.0921 1444 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:49:11.0921 1444 MSPCLOCK - ok
21:49:11.0953 1444 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
21:49:11.0953 1444 MSPQM - ok
21:49:11.0984 1444 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:49:11.0984 1444 mssmbios - ok
21:49:12.0031 1444 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
21:49:12.0031 1444 MSTEE - ok
21:49:12.0078 1444 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
21:49:12.0078 1444 Mup - ok
21:49:12.0125 1444 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
21:49:12.0125 1444 NABTSFEC - ok
21:49:12.0187 1444 NAL (a467e1deb3bb2b57426c8a5993ba933e) C:\WINDOWS\system32\Drivers\iqvw32.sys
21:49:12.0187 1444 NAL - ok
21:49:12.0343 1444 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20120307.035\NAVENG.SYS
21:49:12.0343 1444 NAVENG - ok
21:49:12.0437 1444 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20120307.035\NAVEX15.SYS
21:49:12.0437 1444 NAVEX15 - ok
21:49:12.0484 1444 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
21:49:12.0484 1444 NDIS - ok
21:49:12.0531 1444 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
21:49:12.0531 1444 NdisIP - ok
21:49:12.0578 1444 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:49:12.0578 1444 NdisTapi - ok
21:49:12.0609 1444 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:49:12.0609 1444 Ndisuio - ok
21:49:12.0656 1444 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:49:12.0656 1444 NdisWan - ok
21:49:12.0718 1444 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
21:49:12.0718 1444 NDProxy - ok
21:49:12.0750 1444 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:49:12.0750 1444 NetBIOS - ok
21:49:12.0796 1444 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:49:12.0796 1444 NetBT - ok
21:49:12.0875 1444 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
21:49:12.0890 1444 nm - ok
21:49:12.0937 1444 NmPar (46253ca6d525c9d90a3dbf0ba0398bc9) C:\WINDOWS\system32\DRIVERS\NmPar.sys
21:49:12.0953 1444 NmPar - ok
21:49:13.0000 1444 NPF (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys
21:49:13.0000 1444 NPF - ok
21:49:13.0046 1444 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
21:49:13.0046 1444 Npfs - ok
21:49:13.0093 1444 NtApm (325ffaeceeace80d2643e6bdc7c1f9e2) C:\WINDOWS\system32\DRIVERS\NtApm.sys
21:49:13.0093 1444 NtApm - ok
21:49:13.0171 1444 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
21:49:13.0218 1444 Ntfs - ok
21:49:13.0250 1444 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:49:13.0250 1444 Null - ok
21:49:13.0796 1444 nv (4b54dcd6adee535df80f07c59ddd8f14) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:49:14.0281 1444 nv - ok
21:49:14.0343 1444 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:49:14.0343 1444 NwlnkFlt - ok
21:49:14.0375 1444 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:49:14.0375 1444 NwlnkFwd - ok
21:49:14.0437 1444 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
21:49:14.0437 1444 Parport - ok
21:49:14.0484 1444 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
21:49:14.0484 1444 PartMgr - ok
21:49:14.0531 1444 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
21:49:14.0531 1444 ParVdm - ok
21:49:14.0562 1444 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
21:49:14.0562 1444 PCI - ok
21:49:14.0593 1444 PCIDump - ok
21:49:14.0625 1444 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:49:14.0625 1444 PCIIde - ok
21:49:14.0687 1444 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
21:49:14.0687 1444 Pcmcia - ok
21:49:14.0718 1444 PDCOMP - ok
21:49:14.0750 1444 PDFRAME - ok
21:49:14.0781 1444 PDRELI - ok
21:49:14.0812 1444 PDRFRAME - ok
21:49:14.0843 1444 perc2 - ok
21:49:14.0875 1444 perc2hib - ok
21:49:15.0000 1444 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:49:15.0000 1444 PptpMiniport - ok
21:49:15.0031 1444 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
21:49:15.0046 1444 Processor - ok
21:49:15.0109 1444 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
21:49:15.0109 1444 PSched - ok
21:49:15.0156 1444 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\WINDOWS\system32\DRIVERS\psi_mf.sys
21:49:15.0156 1444 PSI - ok
21:49:15.0203 1444 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:49:15.0203 1444 Ptilink - ok
21:49:15.0250 1444 PxHelp20 (40fedd328f98245ad201cf5f9f311724) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
21:49:15.0250 1444 PxHelp20 - ok
21:49:15.0281 1444 ql1080 - ok
21:49:15.0296 1444 Ql10wnt - ok
21:49:15.0328 1444 ql12160 - ok
21:49:15.0359 1444 ql1240 - ok
21:49:15.0390 1444 ql1280 - ok
21:49:15.0437 1444 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:49:15.0437 1444 RasAcd - ok
21:49:15.0500 1444 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:49:15.0500 1444 Rasl2tp - ok
21:49:15.0562 1444 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:49:15.0562 1444 RasPppoe - ok
21:49:15.0609 1444 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:49:15.0609 1444 Raspti - ok
21:49:15.0656 1444 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:49:15.0656 1444 Rdbss - ok
21:49:15.0687 1444 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:49:15.0687 1444 RDPCDD - ok
21:49:15.0734 1444 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:49:15.0750 1444 rdpdr - ok
21:49:15.0796 1444 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
21:49:15.0812 1444 RDPWD - ok
21:49:15.0875 1444 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:49:15.0875 1444 redbook - ok
21:49:15.0906 1444 RimUsb - ok
21:49:15.0953 1444 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
21:49:15.0953 1444 RimVSerPort - ok
21:49:16.0000 1444 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
21:49:16.0000 1444 ROOTMODEM - ok
21:49:16.0093 1444 RTL8023xp (47b8ea4493ebffb3d6a0e06cd03c5aba) C:\WINDOWS\system32\DRIVERS\FA311XP.SYS
21:49:16.0093 1444 RTL8023xp - ok
21:49:16.0140 1444 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
21:49:16.0140 1444 rtl8139 - ok
21:49:16.0171 1444 SANDRA - ok
21:49:16.0218 1444 SBRE - ok
21:49:16.0296 1444 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:49:16.0296 1444 Secdrv - ok
21:49:16.0375 1444 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys
21:49:16.0406 1444 senfilt - ok
21:49:16.0453 1444 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
21:49:16.0453 1444 serenum - ok
21:49:16.0500 1444 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
21:49:16.0500 1444 Serial - ok
21:49:16.0578 1444 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:49:16.0593 1444 Sfloppy - ok
21:49:16.0625 1444 Simbad - ok
21:49:16.0671 1444 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
21:49:16.0671 1444 SLIP - ok
21:49:16.0750 1444 smwdm (86c4d93b7b7818d066c52fdb03c6c921) C:\WINDOWS\system32\drivers\smwdm.sys
21:49:16.0750 1444 smwdm - ok
21:49:16.0781 1444 Sparrow - ok
21:49:16.0921 1444 SPBBCDrv (e87cf104f12c92401c4d33c50a3d5dc8) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
21:49:16.0937 1444 SPBBCDrv - ok
21:49:16.0984 1444 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
21:49:16.0984 1444 splitter - ok
21:49:17.0031 1444 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\System32\DRIVERS\sr.sys
21:49:17.0031 1444 sr - ok
21:49:17.0093 1444 SRTSP (620bbcc5c4c4407447866793c36e1215) C:\WINDOWS\system32\Drivers\SRTSP.SYS
21:49:17.0093 1444 SRTSP - ok
21:49:17.0156 1444 SRTSPL (995e15de499ca58445e39a2fba7d170e) C:\WINDOWS\system32\Drivers\SRTSPL.SYS
21:49:17.0171 1444 SRTSPL - ok
21:49:17.0203 1444 SRTSPX (1b63f794f283b974a79084514df206a0) C:\WINDOWS\system32\Drivers\SRTSPX.SYS
21:49:17.0203 1444 SRTSPX - ok
21:49:17.0265 1444 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
21:49:17.0281 1444 Srv - ok
21:49:17.0312 1444 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
21:49:17.0312 1444 streamip - ok
21:49:17.0375 1444 SUSTUCAM (0349f7702b819986c292825c676d00fa) C:\WINDOWS\system32\DRIVERS\sustucam.sys
21:49:17.0375 1444 SUSTUCAM - ok
21:49:17.0421 1444 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:49:17.0421 1444 swenum - ok
21:49:17.0453 1444 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
21:49:17.0468 1444 swmidi - ok
21:49:17.0515 1444 symc810 - ok
21:49:17.0546 1444 symc8xx - ok
21:49:17.0593 1444 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
21:49:17.0609 1444 SymEvent - ok
21:49:17.0656 1444 SYMREDRV (394b2368212114d538316812af60fddd) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
21:49:17.0656 1444 SYMREDRV - ok
21:49:17.0703 1444 symsnap (a5cf31080e99718949bcc38c83f13452) C:\WINDOWS\system32\DRIVERS\symsnap.sys
21:49:17.0703 1444 symsnap - ok
21:49:17.0750 1444 SYMTDI (d46676bb414c7531bdffe637a33f5033) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
21:49:17.0750 1444 SYMTDI - ok
21:49:17.0781 1444 sym_hi - ok
21:49:17.0812 1444 sym_u3 - ok
21:49:17.0859 1444 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
21:49:17.0859 1444 sysaudio - ok
21:49:17.0890 1444 SysPlant (c8f9eb4ac42740d036b0b9f0809b335b) C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys
21:49:17.0890 1444 SysPlant - ok
21:49:17.0968 1444 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:49:17.0968 1444 Tcpip - ok
21:49:18.0031 1444 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
21:49:18.0046 1444 Tcpip6 - ok
21:49:18.0078 1444 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:49:18.0093 1444 TDPIPE - ok
21:49:18.0140 1444 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
21:49:18.0156 1444 TDTCP - ok
21:49:18.0203 1444 Teefer2 (75346634d815c9fda103ae5fada072b3) C:\WINDOWS\system32\DRIVERS\teefer2.sys
21:49:18.0203 1444 Teefer2 - ok
21:49:18.0250 1444 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:49:18.0250 1444 TermDD - ok
21:49:18.0296 1444 TosIde - ok
21:49:18.0359 1444 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
21:49:18.0359 1444 tunmp - ok
21:49:18.0406 1444 TVICHW32 (e266683fc95abdec17cd378564e1b54b) C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
21:49:18.0406 1444 TVICHW32 - ok
21:49:18.0453 1444 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
21:49:18.0468 1444 Udfs - ok
21:49:18.0500 1444 ultra - ok
21:49:18.0546 1444 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
21:49:18.0562 1444 Update - ok
21:49:18.0609 1444 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
21:49:18.0625 1444 usbaudio - ok
21:49:18.0671 1444 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:49:18.0671 1444 usbccgp - ok
21:49:18.0703 1444 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:49:18.0703 1444 usbehci - ok
21:49:18.0750 1444 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:49:18.0765 1444 usbhub - ok
21:49:18.0796 1444 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
21:49:18.0796 1444 usbprint - ok
21:49:18.0843 1444 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:49:18.0843 1444 usbscan - ok
21:49:18.0875 1444 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:49:18.0875 1444 USBSTOR - ok
21:49:18.0906 1444 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:49:18.0906 1444 usbuhci - ok
21:49:18.0953 1444 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
21:49:18.0953 1444 usbvideo - ok
21:49:19.0000 1444 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
21:49:19.0000 1444 VgaSave - ok
21:49:19.0031 1444 ViaIde - ok
21:49:19.0078 1444 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
21:49:19.0078 1444 VolSnap - ok
21:49:19.0109 1444 VProEventMonitor (ef3506b04eb9124240b35148eaacbaa5) C:\WINDOWS\system32\DRIVERS\vproeventmonitor.sys
21:49:19.0109 1444 VProEventMonitor - ok
21:49:19.0140 1444 vsdatant - ok
21:49:19.0218 1444 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:49:19.0218 1444 Wanarp - ok
21:49:19.0281 1444 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
21:49:19.0296 1444 Wdf01000 - ok
21:49:19.0328 1444 WDICA - ok
21:49:19.0375 1444 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
21:49:19.0375 1444 wdmaud - ok
21:49:19.0421 1444 WimFltr (090a2b8f055343815556a01f725f6c35) C:\WINDOWS\system32\DRIVERS\wimfltr.sys
21:49:19.0437 1444 WimFltr - ok
21:49:19.0609 1444 WPS (d81ef0d8716500a573cd82185ef3e42d) C:\WINDOWS\system32\drivers\wpsdrvnt.sys
21:49:19.0609 1444 WPS - ok
21:49:19.0671 1444 WpsHelper (ff983a25ae6f7d3f87f26bf51f02a201) C:\WINDOWS\system32\drivers\WpsHelper.sys
21:49:19.0671 1444 WpsHelper - ok
21:49:19.0718 1444 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
21:49:19.0718 1444 WSTCODEC - ok
21:49:19.0765 1444 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
21:49:19.0765 1444 WudfPf - ok
21:49:19.0812 1444 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
21:49:19.0812 1444 WudfRd - ok
21:49:19.0875 1444 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
21:49:19.0984 1444 \Device\Harddisk0\DR0 - ok
21:49:20.0000 1444 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1
21:49:22.0796 1444 \Device\Harddisk1\DR1 - ok
21:49:22.0828 1444 MBR (0x1B8) (ad00bc00aca714232fd4768277895154) \Device\Harddisk4\DR8
21:49:25.0593 1444 \Device\Harddisk4\DR8 - ok
21:49:25.0593 1444 Boot (0x1200) (89f2c810a8038e78c80a14ff359355e4) \Device\Harddisk0\DR0\Partition0
21:49:25.0593 1444 \Device\Harddisk0\DR0\Partition0 - ok
21:49:25.0609 1444 Boot (0x1200) (cd642ed4c466c642e62839d2aa735447) \Device\Harddisk1\DR1\Partition0
21:49:25.0609 1444 \Device\Harddisk1\DR1\Partition0 - ok
21:49:25.0640 1444 Boot (0x1200) (b66a625fb30818cf5e6150aa1cb4a95f) \Device\Harddisk4\DR8\Partition0
21:49:25.0640 1444 \Device\Harddisk4\DR8\Partition0 - ok
21:49:25.0640 1444 ============================================================
21:49:25.0640 1444 Scan finished
21:49:25.0640 1444 ============================================================
21:49:25.0671 1396 Detected object count: 0
21:49:25.0671 1396 Actual detected object count: 0
21:49:49.0234 3844 Deinitialize success
The log from Malwarebytes Anti-malware:
Malwarebytes Anti-Malware (PRO) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.07.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
jdeegan :: DEEGAN [administrator]
Protection: Enabled
3/7/2012 9:17:42 AM
mbam-log-2012-03-07 (09-17-42).txt
Scan type: Flash scan
Scan options enabled: Memory | Startup | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: Registry | File System | P2P
Objects scanned: 153266
Time elapsed: 1 minute(s), 6 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
The log from ansMBR:
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-06 13:08:30
-----------------------------
13:08:30.625 OS Version: Windows 5.1.2600 Service Pack 3
13:08:30.625 Number of processors: 2 586 0x401
13:08:30.625 ComputerName: DEEGAN UserName:
13:08:31.562 Initialize success
13:08:42.718 AVAST engine defs: 12030600
13:08:50.671 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
13:08:50.671 Disk 0 Vendor: Maxtor_6Y120P0 YAR41BW0 Size: 117246MB BusType: 3
13:08:50.671 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
13:08:50.671 Disk 1 Vendor: Maxtor_6Y120P0 YAR41BW0 Size: 117246MB BusType: 3
13:08:50.671 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T0L0-18
13:08:50.671 Disk 2 Vendor: IOMEGA_ZIP_250 42.S Size: 117246MB BusType: 2
13:08:50.687 Disk 0 MBR read successfully
13:08:50.687 Disk 0 MBR scan
13:08:50.718 Disk 0 Windows XP default MBR code
13:08:50.718 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 117232 MB offset 63
13:08:50.734 Disk 0 scanning sectors +240091425
13:08:50.781 Disk 0 scanning C:\WINDOWS\system32\drivers
13:09:08.140 Service scanning
13:09:26.859 Service SysPlant C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys **LOCKED** 32
13:09:27.203 Service Teefer2 C:\WINDOWS\system32\DRIVERS\teefer2.sys **LOCKED** 32
13:09:29.843 Service WPS C:\WINDOWS\system32\drivers\wpsdrvnt.sys **LOCKED** 32
13:09:29.906 Service WpsHelper C:\WINDOWS\system32\drivers\WpsHelper.sys **LOCKED** 32
13:09:30.781 Modules scanning
13:09:37.359 Disk 0 trace - called modules:
13:09:37.375 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
13:09:37.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a5acab8]
13:09:37.375 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x8a63ad98]
13:09:37.375 Scan finished successfully
13:10:00.343 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\jdeegan\Desktop\MBR.dat"
13:10:00.343 The log file has been saved successfully to "C:\Documents and Settings\jdeegan\Desktop\aswMBR.txt"
The log from Symantec Endpoint Protection:
Symantec Endpoint Protect Ver. 11.0.7101.1056
Virus Definitions dated 03/08/2012
Partial Log of Network Threat Protection Traffic log for 03/07/2012 and 03/08/2012
183517 3/7/2012 11:59:04 PM Blocked 10 Incoming UDP 192.168.1.2 00-1E-2A-47-63-5C 137 192.168.1.255 FF-FF-FF-FF-FF-FF 137 C:\WINDOWS\system32\ntoskrnl.exe jdeegan DEEGAN Default 9 3/7/2012 11:58:03 PM 3/7/2012 11:58:14 PM GUI%GUICONFIG#SRULE@NBBLOCK#BLOCK-UDP
183636 3/8/2012 7:12:07 AM Blocked 10 Outgoing UDP 192.168.1.255 FF-FF-FF-FF-FF-FF 138 192.168.1.2 00-1E-2A-47-63-5C 138 C:\WINDOWS\system32\ntoskrnl.exe jdeegan DEEGAN Default 1 3/8/2012 7:11:05 AM 3/8/2012 7:11:05 AM GUI%GUICONFIG#SRULE@NBBLOCK#BLOCK-UDP
....... more of the same
183657 3/8/2012 8:24:04 AM Blocked 10 Outgoing UDP 192.168.1.255 FF-FF-FF-FF-FF-FF 138 192.168.1.2 00-1E-2A-47-63-5C 138 C:\WINDOWS\system32\ntoskrnl.exe jdeegan DEEGAN Default 1 3/8/2012 8:23:03 AM 3/8/2012 8:23:03 AM GUI%GUICONFIG#SRULE@NBBLOCK#BLOCK-UDP
Finally, the log from GMER:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-08 08:27:05
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Maxtor_6Y120P0 rev.YAR41BW0
Running: GMER.exe; Driver: C:\DOCUME~1\jdeegan\LOCALS~1\Temp\ugtdapod.sys
---- System - GMER 1.0.15 ----
SSDT 8A222128 ZwAlertResumeThread
SSDT 8A4C4DC8 ZwAlertThread
SSDT 8A21E310 ZwAllocateVirtualMemory
SSDT 8A58D4D8 ZwConnectPort
SSDT 8A4150E8 ZwCreateMutant
SSDT 8A222160 ZwCreateThread
SSDT 8A23E410 ZwFreeVirtualMemory
SSDT 8A4151B8 ZwImpersonateAnonymousToken
SSDT 8A2216B8 ZwImpersonateThread
SSDT 8A239618 ZwMapViewOfSection
SSDT 8A248008 ZwOpenEvent
SSDT 8A4E81F0 ZwOpenProcessToken
SSDT 8A23B180 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xB6B87BA0]
SSDT 8A4B5AD0 ZwResumeThread
SSDT 8A431100 ZwSetContextThread
SSDT 8A22AF38 ZwSetInformationProcess
SSDT 8A221848 ZwSetInformationThread
SSDT 8A248130 ZwSuspendProcess
SSDT 8A41B788 ZwSuspendThread
SSDT 8A4D2738 ZwTerminateProcess
SSDT 8A225860 ZwTerminateThread
SSDT 8A4C6E78 ZwUnmapViewOfSection
SSDT 8A224BB0 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution + 122 804E497C 4 Bytes [E8, 50, 41, 8A]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB7105380, 0x8D6CD5, 0xE8000020]
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB7027F80]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AA5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD119 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB14 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254686 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E53AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E52E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E534C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E51B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E5214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E5412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E5276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 3E2EDB70 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ole32.dll!OleLoadFromStream 7752983B 5 Bytes JMP 3E3E5717 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 46CB3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 46CB41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!socket 71AB4211 5 Bytes JMP 46CB354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 46CB35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!send 71AB4C27 5 Bytes JMP 46CB3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2972] ws2_32.dll!recv 71AB676F 5 Bytes JMP 46CB4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB14 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E53AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E52E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E534C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E51B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E5214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E5412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E5276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device ftdisk.sys (FT Disk Driver/Microsoft Corporation)
Device \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\IPMULTICAST wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Again, I could not get DDS to run successfully and am unable to produce its log.