Hi, I redownloaded TDSSKiller and ran it as per your instructions:
18:41:32.0365 4028 TDSS rootkit removing tool 2.7.20.0 Mar 9 2012 17:10:43
18:41:34.0370 4028 ============================================================
18:41:34.0370 4028 Current date / time: 2012/03/15 18:41:34.0370
18:41:34.0370 4028 SystemInfo:
18:41:34.0370 4028
18:41:34.0370 4028 OS Version: 6.0.6002 ServicePack: 2.0
18:41:34.0370 4028 Product type: Workstation
18:41:34.0370 4028 ComputerName: JAMES-PC
18:41:34.0370 4028 UserName: James
18:41:34.0370 4028 Windows directory: C:\Windows
18:41:34.0370 4028 System windows directory: C:\Windows
18:41:34.0371 4028 Processor architecture: Intel x86
18:41:34.0371 4028 Number of processors: 2
18:41:34.0371 4028 Page size: 0x1000
18:41:34.0371 4028 Boot type: Normal boot
18:41:34.0371 4028 ============================================================
18:41:59.0366 4028 Drive \Device\Harddisk0\DR0 - Size: 0x3A35294400 (232.83 Gb), SectorSize: 0x200, Cylinders: 0x76BA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:41:59.0397 4028 Drive \Device\Harddisk1\DR1 - Size: 0x7A80000 (0.12 Gb), SectorSize: 0x200, Cylinders: 0xF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
18:41:59.0476 4028 \Device\Harddisk0\DR0:
18:41:59.0476 4028 MBR used
18:41:59.0476 4028 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2F800, BlocksNum 0x1400000
18:41:59.0476 4028 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x142F800, BlocksNum 0x1BD79000
18:41:59.0476 4028 \Device\Harddisk1\DR1:
18:41:59.0477 4028 MBR used
18:41:59.0477 4028 \Device\Harddisk1\DR1\Partition0: MBR, Type 0xB, StartLBA 0x20, BlocksNum 0x3AD2F
18:41:59.0564 4028 Initialize success
18:41:59.0564 4028 ============================================================
18:42:18.0577 3808 ============================================================
18:42:18.0577 3808 Scan started
18:42:18.0577 3808 Mode: Manual;
18:42:18.0577 3808 ============================================================
18:42:19.0187 3808 5689 - ok
18:42:19.0411 3808 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
18:42:19.0434 3808 ACPI - ok
18:42:19.0525 3808 ADIHdAudAddService (3db3fb83217627d9a0cb8bae6cc5b491) C:\Windows\system32\drivers\ADIHdAud.sys
18:42:19.0531 3808 ADIHdAudAddService - ok
18:42:19.0610 3808 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
18:42:19.0617 3808 adp94xx - ok
18:42:19.0669 3808 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
18:42:19.0674 3808 adpahci - ok
18:42:19.0704 3808 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
18:42:19.0707 3808 adpu160m - ok
18:42:19.0757 3808 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
18:42:19.0760 3808 adpu320 - ok
18:42:19.0976 3808 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
18:42:19.0981 3808 AFD - ok
18:42:20.0077 3808 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
18:42:20.0079 3808 agp440 - ok
18:42:20.0134 3808 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
18:42:20.0136 3808 aic78xx - ok
18:42:20.0186 3808 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
18:42:20.0187 3808 aliide - ok
18:42:20.0255 3808 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
18:42:20.0257 3808 amdagp - ok
18:42:20.0300 3808 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
18:42:20.0302 3808 amdide - ok
18:42:20.0321 3808 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
18:42:20.0322 3808 AmdK7 - ok
18:42:20.0347 3808 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
18:42:20.0348 3808 AmdK8 - ok
18:42:20.0571 3808 amdkmdag (da3cf5b94ad09290896e2b73df6d4173) C:\Windows\system32\DRIVERS\atikmdag.sys
18:42:20.0706 3808 amdkmdag - ok
18:42:20.0824 3808 amdkmdap (46a3f55772fd2d1526994693ae352579) C:\Windows\system32\DRIVERS\atikmpag.sys
18:42:20.0828 3808 amdkmdap - ok
18:42:20.0982 3808 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
18:42:20.0984 3808 arc - ok
18:42:21.0039 3808 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
18:42:21.0041 3808 arcsas - ok
18:42:21.0145 3808 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
18:42:21.0174 3808 AsyncMac - ok
18:42:21.0236 3808 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
18:42:21.0237 3808 atapi - ok
18:42:21.0595 3808 AtiHDAudioService (8579387516ec86d76404ddffc22214c4) C:\Windows\system32\drivers\AtihdLH3.sys
18:42:21.0620 3808 AtiHDAudioService - ok
18:42:21.0690 3808 AtiHdmiService (d7672d90ef03d0e2efdb02df5045a359) C:\Windows\system32\drivers\AtiHdmi.sys
18:42:21.0692 3808 AtiHdmiService - ok
18:42:22.0980 3808 atikmdag (da3cf5b94ad09290896e2b73df6d4173) C:\Windows\system32\DRIVERS\atikmdag.sys
18:42:23.0027 3808 atikmdag - ok
18:42:23.0132 3808 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
18:42:23.0134 3808 Beep - ok
18:42:23.0164 3808 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
18:42:23.0165 3808 blbdrive - ok
18:42:23.0247 3808 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
18:42:23.0249 3808 bowser - ok
18:42:23.0315 3808 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
18:42:23.0316 3808 BrFiltLo - ok
18:42:23.0333 3808 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
18:42:23.0334 3808 BrFiltUp - ok
18:42:23.0396 3808 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
18:42:23.0398 3808 Brserid - ok
18:42:23.0449 3808 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
18:42:23.0451 3808 BrSerWdm - ok
18:42:23.0469 3808 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
18:42:23.0470 3808 BrUsbMdm - ok
18:42:23.0483 3808 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
18:42:23.0484 3808 BrUsbSer - ok
18:42:23.0579 3808 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
18:42:23.0580 3808 BTHMODEM - ok
18:42:23.0661 3808 catchme - ok
18:42:23.0757 3808 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
18:42:23.0759 3808 cdfs - ok
18:42:23.0813 3808 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
18:42:23.0815 3808 cdrom - ok
18:42:23.0839 3808 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
18:42:23.0841 3808 circlass - ok
18:42:23.0925 3808 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
18:42:23.0929 3808 CLFS - ok
18:42:24.0026 3808 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
18:42:24.0027 3808 cmdide - ok
18:42:24.0056 3808 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
18:42:24.0057 3808 Compbatt - ok
18:42:24.0104 3808 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
18:42:24.0105 3808 crcdisk - ok
18:42:24.0142 3808 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
18:42:24.0144 3808 Crusoe - ok
18:42:24.0306 3808 CSC (9bdb2e89be8d0ef37b1f25c3d3fc192c) C:\Windows\system32\drivers\csc.sys
18:42:24.0311 3808 CSC - ok
18:42:24.0366 3808 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
18:42:24.0368 3808 DfsC - ok
18:42:24.0493 3808 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
18:42:24.0495 3808 disk - ok
18:42:24.0670 3808 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
18:42:24.0671 3808 drmkaud - ok
18:42:24.0770 3808 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
18:42:24.0771 3808 DSproct - ok
18:42:24.0883 3808 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\Windows\system32\DRIVERS\dsunidrv.sys
18:42:24.0884 3808 dsunidrv - ok
18:42:24.0925 3808 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
18:42:24.0933 3808 DXGKrnl - ok
18:42:25.0056 3808 e1express (04944f4fc4f0477185f5d26ae0ddb90e) C:\Windows\system32\DRIVERS\e1e6032.sys
18:42:25.0060 3808 e1express - ok
18:42:25.0127 3808 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
18:42:25.0130 3808 E1G60 - ok
18:42:25.0236 3808 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
18:42:25.0240 3808 Ecache - ok
18:42:25.0305 3808 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
18:42:25.0311 3808 elxstor - ok
18:42:25.0391 3808 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
18:42:25.0392 3808 ErrDev - ok
18:42:25.0468 3808 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
18:42:25.0471 3808 exfat - ok
18:42:25.0489 3808 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
18:42:25.0492 3808 fastfat - ok
18:42:25.0543 3808 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
18:42:25.0544 3808 fdc - ok
18:42:25.0604 3808 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
18:42:25.0605 3808 FileInfo - ok
18:42:25.0621 3808 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
18:42:25.0623 3808 Filetrace - ok
18:42:25.0670 3808 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
18:42:25.0671 3808 flpydisk - ok
18:42:25.0777 3808 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
18:42:25.0780 3808 FltMgr - ok
18:42:26.0141 3808 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
18:42:26.0168 3808 Fs_Rec - ok
18:42:26.0225 3808 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
18:42:26.0226 3808 gagp30kx - ok
18:42:26.0316 3808 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
18:42:26.0343 3808 GEARAspiWDM - ok
18:42:26.0407 3808 GemCCID (86d3d834d35ebe920d85ffedcef79faf) C:\Windows\system32\Drivers\GemCCID.sys
18:42:26.0409 3808 GemCCID - ok
18:42:26.0812 3808 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
18:42:26.0836 3808 HdAudAddService - ok
18:42:27.0429 3808 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
18:42:27.0437 3808 HDAudBus - ok
18:42:27.0512 3808 HECI (c865d1f6d03595df213dc3c67e4e4c58) C:\Windows\system32\DRIVERS\HECI.sys
18:42:27.0514 3808 HECI - ok
18:42:27.0540 3808 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
18:42:27.0541 3808 HidBth - ok
18:42:27.0598 3808 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
18:42:27.0600 3808 HidIr - ok
18:42:27.0670 3808 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
18:42:27.0671 3808 HidUsb - ok
18:42:27.0728 3808 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
18:42:27.0729 3808 HpCISSs - ok
18:42:27.0761 3808 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
18:42:27.0768 3808 HTTP - ok
18:42:27.0891 3808 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
18:42:27.0893 3808 i2omp - ok
18:42:27.0941 3808 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
18:42:27.0943 3808 i8042prt - ok
18:42:28.0049 3808 iaStor (e5a0034847537eaee3c00349d5c34c5f) C:\Windows\system32\drivers\iastor.sys
18:42:28.0051 3808 iaStor - ok
18:42:28.0076 3808 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
18:42:28.0081 3808 iaStorV - ok
18:42:28.0210 3808 igfx (a03b37dbc601c35de9591b6aa1a20c22) C:\Windows\system32\DRIVERS\igdkmd32.sys
18:42:28.0233 3808 igfx - ok
18:42:28.0309 3808 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
18:42:28.0310 3808 iirsp - ok
18:42:28.0359 3808 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
18:42:28.0361 3808 intelide - ok
18:42:28.0461 3808 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
18:42:28.0462 3808 intelppm - ok
18:42:28.0504 3808 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:42:28.0505 3808 IpFilterDriver - ok
18:42:28.0546 3808 IpInIp - ok
18:42:28.0566 3808 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
18:42:28.0568 3808 IPMIDRV - ok
18:42:28.0610 3808 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
18:42:28.0612 3808 IPNAT - ok
18:42:28.0724 3808 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
18:42:28.0725 3808 IRENUM - ok
18:42:28.0746 3808 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
18:42:28.0747 3808 isapnp - ok
18:42:28.0782 3808 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
18:42:28.0786 3808 iScsiPrt - ok
18:42:28.0857 3808 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
18:42:28.0859 3808 iteatapi - ok
18:42:28.0901 3808 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
18:42:28.0903 3808 iteraid - ok
18:42:28.0927 3808 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
18:42:28.0929 3808 kbdclass - ok
18:42:28.0998 3808 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
18:42:28.0999 3808 kbdhid - ok
18:42:29.0035 3808 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys
18:42:29.0043 3808 KSecDD - ok
18:42:29.0140 3808 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
18:42:29.0162 3808 lltdio - ok
18:42:29.0327 3808 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
18:42:29.0355 3808 LSI_FC - ok
18:42:29.0411 3808 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
18:42:29.0414 3808 LSI_SAS - ok
18:42:29.0480 3808 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
18:42:29.0482 3808 LSI_SCSI - ok
18:42:29.0574 3808 LTXMD_VAC (6e4880018d99b7f041a8d0b3f7f43b72) C:\Windows\system32\drivers\lmvac.sys
18:42:29.0613 3808 LTXMD_VAC - ok
18:42:29.0651 3808 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
18:42:29.0653 3808 luafv - ok
18:42:29.0775 3808 lvpopflt (9fb982de1c8dd769f8ed681dd878b12f) C:\Windows\system32\DRIVERS\lvpopflt.sys
18:42:29.0803 3808 lvpopflt - ok
18:42:29.0852 3808 LVPr2Mon (8be71d7edb8c7494913722059f760dd0) C:\Windows\system32\Drivers\LVPr2Mon.sys
18:42:29.0853 3808 LVPr2Mon - ok
18:42:30.0202 3808 LVRS (37072ec9299e825f4335cc554b6fac6a) C:\Windows\system32\DRIVERS\lvrs.sys
18:42:30.0206 3808 LVRS - ok
18:42:30.0537 3808 LVUVC (44876e70e07e9a653bbe423dbfa35a1a) C:\Windows\system32\DRIVERS\lvuvc.sys
18:42:30.0688 3808 LVUVC - ok
18:42:30.0802 3808 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
18:42:30.0804 3808 megasas - ok
18:42:30.0854 3808 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
18:42:30.0861 3808 MegaSR - ok
18:42:30.0949 3808 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
18:42:30.0951 3808 Modem - ok
18:42:31.0016 3808 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
18:42:31.0018 3808 monitor - ok
18:42:31.0037 3808 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
18:42:31.0038 3808 mouclass - ok
18:42:31.0081 3808 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
18:42:31.0082 3808 mouhid - ok
18:42:31.0101 3808 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
18:42:31.0103 3808 MountMgr - ok
18:42:31.0202 3808 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\Windows\system32\DRIVERS\MpFilter.sys
18:42:31.0205 3808 MpFilter - ok
18:42:31.0286 3808 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
18:42:31.0289 3808 mpio - ok
18:42:31.0353 3808 MpNWMon (2c3489660d4a8d514c123c3f0d67df46) C:\Windows\system32\DRIVERS\MpNWMon.sys
18:42:31.0354 3808 MpNWMon - ok
18:42:31.0397 3808 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
18:42:31.0399 3808 mpsdrv - ok
18:42:31.0470 3808 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
18:42:31.0472 3808 Mraid35x - ok
18:42:31.0526 3808 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
18:42:31.0529 3808 MRxDAV - ok
18:42:31.0591 3808 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
18:42:31.0594 3808 mrxsmb - ok
18:42:31.0654 3808 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:42:31.0658 3808 mrxsmb10 - ok
18:42:31.0695 3808 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:42:31.0697 3808 mrxsmb20 - ok
18:42:31.0765 3808 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
18:42:31.0767 3808 msahci - ok
18:42:31.0817 3808 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
18:42:31.0819 3808 msdsm - ok
18:42:31.0887 3808 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
18:42:31.0889 3808 Msfs - ok
18:42:31.0978 3808 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
18:42:31.0979 3808 msisadrv - ok
18:42:32.0216 3808 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
18:42:32.0217 3808 MSKSSRV - ok
18:42:32.0285 3808 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
18:42:32.0286 3808 MSPCLOCK - ok
18:42:32.0337 3808 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
18:42:32.0339 3808 MSPQM - ok
18:42:32.0365 3808 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
18:42:32.0368 3808 MsRPC - ok
18:42:32.0417 3808 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
18:42:32.0418 3808 mssmbios - ok
18:42:32.0516 3808 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
18:42:32.0518 3808 MSTEE - ok
18:42:32.0575 3808 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
18:42:32.0577 3808 Mup - ok
18:42:32.0659 3808 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
18:42:32.0662 3808 NativeWifiP - ok
18:42:32.0751 3808 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
18:42:32.0759 3808 NDIS - ok
18:42:32.0851 3808 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
18:42:32.0852 3808 NdisTapi - ok
18:42:32.0892 3808 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
18:42:32.0894 3808 Ndisuio - ok
18:42:32.0944 3808 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
18:42:32.0946 3808 NdisWan - ok
18:42:32.0982 3808 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
18:42:32.0984 3808 NDProxy - ok
18:42:33.0056 3808 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
18:42:33.0058 3808 NetBIOS - ok
18:42:33.0120 3808 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
18:42:33.0124 3808 netbt - ok
18:42:33.0302 3808 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
18:42:33.0304 3808 nfrd960 - ok
18:42:33.0349 3808 NisDrv (7b01c6172cfd0b10116175e09200d4b4) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
18:42:33.0351 3808 NisDrv - ok
18:42:33.0458 3808 NPF (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys
18:42:33.0480 3808 NPF - ok
18:42:33.0509 3808 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
18:42:33.0511 3808 Npfs - ok
18:42:33.0566 3808 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
18:42:33.0568 3808 nsiproxy - ok
18:42:33.0662 3808 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
18:42:33.0678 3808 Ntfs - ok
18:42:33.0786 3808 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
18:42:33.0788 3808 ntrigdigi - ok
18:42:33.0848 3808 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
18:42:33.0849 3808 Null - ok
18:42:33.0872 3808 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
18:42:33.0875 3808 nvraid - ok
18:42:33.0894 3808 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
18:42:33.0896 3808 nvstor - ok
18:42:33.0946 3808 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
18:42:33.0949 3808 nv_agp - ok
18:42:33.0958 3808 NwlnkFlt - ok
18:42:33.0970 3808 NwlnkFwd - ok
18:42:34.0030 3808 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
18:42:34.0032 3808 ohci1394 - ok
18:42:34.0137 3808 Parport (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
18:42:34.0139 3808 Parport - ok
18:42:34.0184 3808 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
18:42:34.0186 3808 partmgr - ok
18:42:34.0204 3808 Parvdm (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
18:42:34.0205 3808 Parvdm - ok
18:42:34.0278 3808 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
18:42:34.0281 3808 pci - ok
18:42:34.0334 3808 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
18:42:34.0336 3808 pciide - ok
18:42:34.0388 3808 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
18:42:34.0392 3808 pcmcia - ok
18:42:34.0466 3808 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
18:42:34.0478 3808 PEAUTH - ok
18:42:34.0577 3808 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
18:42:34.0579 3808 PptpMiniport - ok
18:42:34.0608 3808 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
18:42:34.0610 3808 Processor - ok
18:42:34.0666 3808 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
18:42:34.0668 3808 PSched - ok
18:42:34.0760 3808 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\Windows\system32\Drivers\PxHelp20.sys
18:42:34.0762 3808 PxHelp20 - ok
18:42:34.0842 3808 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
18:42:34.0856 3808 ql2300 - ok
18:42:34.0909 3808 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
18:42:34.0911 3808 ql40xx - ok
18:42:34.0959 3808 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
18:42:34.0961 3808 QWAVEdrv - ok
18:42:35.0148 3808 R300 (da3cf5b94ad09290896e2b73df6d4173) C:\Windows\system32\DRIVERS\atikmdag.sys
18:42:35.0190 3808 R300 - ok
18:42:35.0403 3808 RapportCerberus_34302 (6b6f0a77365667912360ff1d5e984f25) C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys
18:42:35.0407 3808 RapportCerberus_34302 - ok
18:42:35.0511 3808 RapportEI (43b9aa1423bf54367c5a3de1559780e8) C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys
18:42:35.0513 3808 RapportEI - ok
18:42:35.0618 3808 RapportIaso (dd3e4610de9252a957c5bd19bdf47ac4) c:\programdata\trusteer\rapport\store\exts\rapportms\28896\rapportiaso.sys
18:42:35.0619 3808 RapportIaso - ok
18:42:35.0704 3808 RapportKELL (118600ab8f15fe27f2c865f3fb4efa58) C:\Windows\system32\Drivers\RapportKELL.sys
18:42:35.0706 3808 RapportKELL - ok
18:42:35.0820 3808 RapportPG (4af05a67b643a5190dfcbb793273e0bc) C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys
18:42:35.0824 3808 RapportPG - ok
18:42:35.0924 3808 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
18:42:35.0926 3808 RasAcd - ok
18:42:35.0951 3808 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
18:42:35.0953 3808 Rasl2tp - ok
18:42:35.0987 3808 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
18:42:35.0989 3808 RasPppoe - ok
18:42:36.0005 3808 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
18:42:36.0007 3808 RasSstp - ok
18:42:36.0092 3808 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
18:42:36.0096 3808 rdbss - ok
18:42:36.0116 3808 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
18:42:36.0117 3808 RDPCDD - ok
18:42:36.0164 3808 rdpdr (943b18305eae3935598a9b4a3d560b4c) C:\Windows\system32\DRIVERS\rdpdr.sys
18:42:36.0169 3808 rdpdr - ok
18:42:36.0222 3808 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
18:42:36.0224 3808 RDPENCDD - ok
18:42:36.0258 3808 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys
18:42:36.0262 3808 RDPWD - ok
18:42:36.0329 3808 RimUsb (92d33f76769a028ddc54a863eb7de4a2) C:\Windows\system32\Drivers\RimUsb.sys
18:42:36.0330 3808 RimUsb - ok
18:42:36.0482 3808 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys
18:42:36.0483 3808 RimVSerPort - ok
18:42:36.0508 3808 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys
18:42:36.0509 3808 ROOTMODEM - ok
18:42:36.0588 3808 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
18:42:36.0590 3808 rspndr - ok
18:42:36.0733 3808 SAVOnAccess (127e21305c1880b550bea4b0adfd9d94) C:\Windows\system32\DRIVERS\savonaccess.sys
18:42:36.0780 3808 SAVOnAccess - ok
18:42:36.0877 3808 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
18:42:36.0879 3808 sbp2port - ok
18:42:36.0941 3808 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
18:42:36.0943 3808 secdrv - ok
18:42:37.0070 3808 Serenum (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
18:42:37.0071 3808 Serenum - ok
18:42:37.0175 3808 Serial (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
18:42:37.0178 3808 Serial - ok
18:42:37.0207 3808 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
18:42:37.0209 3808 sermouse - ok
18:42:37.0239 3808 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
18:42:37.0241 3808 sffdisk - ok
18:42:37.0288 3808 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
18:42:37.0289 3808 sffp_mmc - ok
18:42:37.0328 3808 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
18:42:37.0329 3808 sffp_sd - ok
18:42:37.0406 3808 sfloppy (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys
18:42:37.0422 3808 sfloppy - ok
18:42:37.0530 3808 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
18:42:37.0532 3808 sisagp - ok
18:42:37.0584 3808 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
18:42:37.0586 3808 SiSRaid2 - ok
18:42:37.0613 3808 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
18:42:37.0616 3808 SiSRaid4 - ok
18:42:37.0665 3808 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
18:42:37.0667 3808 Smb - ok
18:42:37.0750 3808 SophosBootDriver (6de03cbac3139d2fd8fba4aab4ac5bd0) C:\Windows\system32\DRIVERS\SophosBootDriver.sys
18:42:37.0768 3808 SophosBootDriver - ok
18:42:37.0821 3808 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
18:42:37.0822 3808 spldr - ok
18:42:37.0935 3808 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
18:42:37.0936 3808 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
18:42:37.0937 3808 sptd ( LockedFile.Multi.Generic ) - warning
18:42:37.0937 3808 sptd - detected LockedFile.Multi.Generic (1)
18:42:38.0015 3808 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
18:42:38.0020 3808 srv - ok
18:42:38.0067 3808 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
18:42:38.0070 3808 srv2 - ok
18:42:38.0115 3808 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
18:42:38.0117 3808 srvnet - ok
18:42:38.0181 3808 StillCam (ef70b3d22b4bffda6ea851ecb063efaa) C:\Windows\system32\DRIVERS\serscan.sys
18:42:38.0183 3808 StillCam - ok
18:42:38.0234 3808 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
18:42:38.0236 3808 swenum - ok
18:42:38.0290 3808 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
18:42:38.0292 3808 Symc8xx - ok
18:42:38.0305 3808 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
18:42:38.0307 3808 Sym_hi - ok
18:42:38.0325 3808 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
18:42:38.0327 3808 Sym_u3 - ok
18:42:38.0421 3808 Tcpip (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\drivers\tcpip.sys
18:42:38.0434 3808 Tcpip - ok
18:42:38.0595 3808 Tcpip6 (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\DRIVERS\tcpip.sys
18:42:38.0602 3808 Tcpip6 - ok
18:42:38.0671 3808 tcpipreg (3fc13f09af9be487c7b4fac4070a036c) C:\Windows\system32\drivers\tcpipreg.sys
18:42:38.0672 3808 tcpipreg - ok
18:42:38.0741 3808 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
18:42:38.0742 3808 TDPIPE - ok
18:42:38.0762 3808 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
18:42:38.0764 3808 TDTCP - ok
18:42:38.0822 3808 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
18:42:38.0824 3808 tdx - ok
18:42:38.0936 3808 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
18:42:38.0938 3808 TermDD - ok
18:42:38.0999 3808 TfFsMon (a56ec942ecabfb7849bfa76060f929fb) C:\Windows\system32\drivers\TfFsMon.sys
18:42:39.0001 3808 TfFsMon - ok
18:42:39.0050 3808 TfNetMon (917ef522563f6047685486efa486fb3c) C:\Windows\system32\drivers\TfNetMon.sys
18:42:39.0052 3808 TfNetMon - ok
18:42:39.0072 3808 TfSysMon (57edbb5fe7ff09bb21121d13bb950ba5) C:\Windows\system32\drivers\TfSysMon.sys
18:42:39.0074 3808 TfSysMon - ok
18:42:39.0172 3808 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
18:42:39.0173 3808 tssecsrv - ok
18:42:39.0192 3808 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
18:42:39.0193 3808 tunmp - ok
18:42:39.0217 3808 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
18:42:39.0218 3808 tunnel - ok
18:42:39.0264 3808 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
18:42:39.0266 3808 uagp35 - ok
18:42:39.0314 3808 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
18:42:39.0319 3808 udfs - ok
18:42:39.0367 3808 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
18:42:39.0369 3808 uliagpkx - ok
18:42:39.0434 3808 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
18:42:39.0438 3808 uliahci - ok
18:42:39.0460 3808 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
18:42:39.0463 3808 UlSata - ok
18:42:39.0514 3808 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
18:42:39.0516 3808 ulsata2 - ok
18:42:39.0611 3808 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
18:42:39.0612 3808 umbus - ok
18:42:39.0677 3808 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
18:42:39.0679 3808 usbaudio - ok
18:42:39.0751 3808 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
18:42:39.0753 3808 usbccgp - ok
18:42:39.0828 3808 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
18:42:39.0830 3808 usbcir - ok
18:42:39.0862 3808 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
18:42:39.0863 3808 usbehci - ok
18:42:39.0940 3808 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
18:42:39.0944 3808 usbhub - ok
18:42:40.0032 3808 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
18:42:40.0034 3808 usbohci - ok
18:42:40.0085 3808 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
18:42:40.0086 3808 usbprint - ok
18:42:40.0145 3808 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:42:40.0147 3808 USBSTOR - ok
18:42:40.0203 3808 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
18:42:40.0205 3808 usbuhci - ok
18:42:40.0264 3808 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
18:42:40.0268 3808 usbvideo - ok
18:42:40.0315 3808 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
18:42:40.0317 3808 vga - ok
18:42:40.0338 3808 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
18:42:40.0340 3808 VgaSave - ok
18:42:40.0386 3808 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
18:42:40.0388 3808 viaagp - ok
18:42:40.0408 3808 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
18:42:40.0409 3808 ViaC7 - ok
18:42:40.0449 3808 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
18:42:40.0451 3808 viaide - ok
18:42:40.0472 3808 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
18:42:40.0474 3808 volmgr - ok
18:42:40.0597 3808 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
18:42:40.0603 3808 volmgrx - ok
18:42:40.0682 3808 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
18:42:40.0686 3808 volsnap - ok
18:42:40.0738 3808 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
18:42:40.0741 3808 vsmraid - ok
18:42:40.0822 3808 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
18:42:40.0823 3808 WacomPen - ok
18:42:40.0841 3808 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
18:42:40.0844 3808 Wanarp - ok
18:42:40.0877 3808 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
18:42:40.0879 3808 Wanarpv6 - ok
18:42:40.0933 3808 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
18:42:40.0935 3808 Wd - ok
18:42:40.0987 3808 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
18:42:40.0994 3808 Wdf01000 - ok
18:42:41.0087 3808 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
18:42:41.0088 3808 WmiAcpi - ok
18:42:41.0180 3808 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
18:42:41.0181 3808 ws2ifsl - ok
18:42:41.0247 3808 WSDPrintDevice (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys
18:42:41.0248 3808 WSDPrintDevice - ok
18:42:41.0349 3808 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
18:42:41.0351 3808 WUDFRd - ok
18:42:41.0384 3808 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
18:42:41.0440 3808 \Device\Harddisk0\DR0 - ok
18:42:41.0451 3808 MBR (0x1B8) (973e9ba32fdbb305c552ed3e1ebf0686) \Device\Harddisk1\DR1
18:42:41.0461 3808 \Device\Harddisk1\DR1 - ok
18:42:41.0480 3808 Boot (0x1200) (47b7c63b1ff6106e81d91108af21ffb5) \Device\Harddisk0\DR0\Partition0
18:42:41.0481 3808 \Device\Harddisk0\DR0\Partition0 - ok
18:42:41.0487 3808 Boot (0x1200) (2550465ec1fd92fcd2071b2e5e16973e) \Device\Harddisk0\DR0\Partition1
18:42:41.0488 3808 \Device\Harddisk0\DR0\Partition1 - ok
18:42:41.0498 3808 Boot (0x1200) (cdcdee224afbb2371d076be8797665cf) \Device\Harddisk1\DR1\Partition0
18:42:41.0499 3808 \Device\Harddisk1\DR1\Partition0 - ok
18:42:41.0501 3808 ============================================================
18:42:41.0502 3808 Scan finished
18:42:41.0502 3808 ============================================================
18:42:41.0524 4672 Detected object count: 1
18:42:41.0524 4672 Actual detected object count: 1
18:43:27.0862 4672 C:\Windows\system32\Drivers\sptd.sys - copied to quarantine
18:43:28.0591 4672 sptd ( LockedFile.Multi.Generic ) - User select action: Quarantine
18:44:57.0073 3852 Deinitialize success
Then I rebooted.
=============================
As far as I am concerned MSE is the only functional, traditional AntiVirus program installed right now.
ThreatFire is not really an AV program in the traditional sense. It does not use virus definitions and can co-exist with AV programs.
http://www.threatfire.com/ If it had not been for ThreatFire I would not have known that the PC was still infected after the AVG scan. However, if you still want me to uninstall it, I will.
The version of Sophos installed is this one:
http://www.sophos.com/en-us/product...urity-scans/sophos-threat-detection-test.aspx
It does not have any resident shield functionality or even scheduled scan functionality. The only thing it does without user intervention as far as I can tell is to update itself. So it should not cause any conflicts with other AV programs. However, if you still want me to uninstall it, I will.
To be honest, I don't know what the final antivirus solution will be. This infection has shown to me (a) how lacking AVG is, and (b) how all definition based AntiVirus software I know about is behind the curve and therefore cannot protect you from new threats. Do you have any recommendations for an inexpensive AV solution for a small office environment? Probably 10 workstations, including some at people's homes. With a central management console. The server part should preferably be in the cloud, but I could install it on a Windows or Linux server.
=============================
RegTool: I too was suspicious of this file. It turns out (or at least it appears) that it was installed with Gemalto Classic Client (
http://www.gemalto.com/products/classic_client/ Classic Client is a smart card-based crypto-library product that brings portability and the highest level of security to enterprise networks.) Lots of other people have it installed in this location:
http://processchecker.com/file/RegTool.exe.html However, it probably does not need to run automatically from what I read here:
http://forums.epo.org/installation-and-maintenance/topic1923.html. If it is not installed on Citrix workstations, I guess it can be run manually when needed. However, it is located here:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
So I will not edit the registry without you telling me to.
============================
I downloaded and ran OTM as specified. Here is the log that opened after rebooting:
All processes killed
========== FILES ==========
========== PROCESSES ==========
No active process named C:\Users\James.SYNTEC_DOM1\Downloads\Cannon drivers\scan\MF tool box\MF drivers\omnipage\installer_omnipage_professional.exe was found!
No active process named C:\winnt\system32\repl\import\scripts.V2\Downloads\Cannon drivers\scan\MF tool box\MF drivers\omnipage\installer_omnipage_professional.exe was found!
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: AppData
->Temp folder emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 56466 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: James
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 51189886 bytes
->Flash cache emptied: 1280 bytes
User: James.SYNTEC_DOM1
->Temp folder emptied: 313725 bytes
->Temporary Internet Files folder emptied: 234784532 bytes
->Java cache emptied: 5121057 bytes
->FireFox cache emptied: 58530973 bytes
->Google Chrome cache emptied: 6417939 bytes
->Flash cache emptied: 250068 bytes
User: JAMES~1~SYN
->Temp folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5683560 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 41282544 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 385.00 mb
OTM by OldTimer - Version 3.1.19.0 log created on 03152012_192607
Files moved on Reboot...
Registry entries deleted on Reboot...