Next?!?
Ok. First of all, I will go through what I've gone through so far. I don't want to go any further without figuring out what you want me to do.
1. Malwarebytes did the same as before. It started running the scan then closed about 10-15 seconds after running.
2. TDDS log isnt listed as a notepad file or anything like that. I ran it again and noticed that there was a report button so here is the log for that run. It found 2 this time (both of which were on the original scan) but didn't find the rtk0000 folder/files this time.
23:48:31.0006 1696 TDSS rootkit removing tool 2.6.15.0 Nov 3 2011 17:15:49
23:48:31.0475 1696 ============================================================
23:48:31.0475 1696 Current date / time: 2011/11/04 23:48:31.0475
23:48:31.0475 1696 SystemInfo:
23:48:31.0475 1696
23:48:31.0475 1696 OS Version: 6.0.6002 ServicePack: 2.0
23:48:31.0475 1696 Product type: Workstation
23:48:31.0475 1696 ComputerName: SUSAN-PC
23:48:31.0475 1696 UserName: Susan
23:48:31.0475 1696 Windows directory: C:\Windows
23:48:31.0475 1696 System windows directory: C:\Windows
23:48:31.0475 1696 Processor architecture: Intel x86
23:48:31.0475 1696 Number of processors: 2
23:48:31.0475 1696 Page size: 0x1000
23:48:31.0475 1696 Boot type: Safe boot with network
23:48:31.0475 1696 ============================================================
23:48:32.0131 1696 Initialize success
23:48:34.0959 1564 ============================================================
23:48:34.0959 1564 Scan started
23:48:34.0959 1564 Mode: Manual;
23:48:34.0959 1564 ============================================================
23:48:35.0771 1564 8a878ddd (3f6d4cefcf143832bea93daf44d89b7a) C:\Windows\3717040010:1970827810.exe
23:48:35.0771 1564 Suspicious file (Hidden): C:\Windows\3717040010:1970827810.exe. md5: 3f6d4cefcf143832bea93daf44d89b7a
23:48:35.0787 1564 8a878ddd ( Rootkit.Win32.PMax.gen ) - infected
23:48:35.0787 1564 8a878ddd - detected Rootkit.Win32.PMax.gen (0)
23:48:35.0850 1564 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
23:48:35.0865 1564 ACPI - ok
23:48:35.0928 1564 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
23:48:35.0943 1564 adp94xx - ok
23:48:36.0006 1564 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
23:48:36.0021 1564 adpahci - ok
23:48:36.0053 1564 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
23:48:36.0053 1564 adpu160m - ok
23:48:36.0115 1564 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
23:48:36.0115 1564 adpu320 - ok
23:48:36.0209 1564 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
23:48:36.0209 1564 AFD - ok
23:48:36.0303 1564 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
23:48:36.0318 1564 agp440 - ok
23:48:36.0396 1564 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
23:48:36.0396 1564 aic78xx - ok
23:48:36.0428 1564 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
23:48:36.0428 1564 aliide - ok
23:48:36.0490 1564 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
23:48:36.0490 1564 amdagp - ok
23:48:36.0553 1564 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
23:48:36.0553 1564 amdide - ok
23:48:36.0600 1564 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
23:48:36.0600 1564 AmdK7 - ok
23:48:36.0662 1564 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
23:48:36.0662 1564 AmdK8 - ok
23:48:36.0756 1564 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
23:48:36.0756 1564 arc - ok
23:48:36.0834 1564 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
23:48:36.0834 1564 arcsas - ok
23:48:36.0896 1564 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\Windows\system32\drivers\aswFsBlk.sys
23:48:36.0912 1564 aswFsBlk - ok
23:48:36.0975 1564 aswMonFlt (4804753a4ec7d67cc22d226bffd1c1e3) C:\Windows\system32\drivers\aswMonFlt.sys
23:48:36.0975 1564 aswMonFlt - ok
23:48:37.0053 1564 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\Windows\system32\drivers\aswRdr.sys
23:48:37.0053 1564 aswRdr - ok
23:48:37.0131 1564 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\Windows\system32\drivers\aswSnx.sys
23:48:37.0146 1564 aswSnx - ok
23:48:37.0209 1564 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\Windows\system32\drivers\aswSP.sys
23:48:37.0225 1564 aswSP - ok
23:48:37.0318 1564 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\Windows\system32\drivers\aswTdi.sys
23:48:37.0318 1564 aswTdi - ok
23:48:37.0365 1564 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
23:48:37.0381 1564 AsyncMac - ok
23:48:37.0443 1564 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
23:48:37.0443 1564 atapi - ok
23:48:37.0537 1564 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
23:48:37.0537 1564 Beep - ok
23:48:37.0584 1564 blbdrive - ok
23:48:37.0646 1564 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
23:48:37.0646 1564 bowser - ok
23:48:37.0709 1564 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
23:48:37.0709 1564 BrFiltLo - ok
23:48:37.0771 1564 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
23:48:37.0771 1564 BrFiltUp - ok
23:48:37.0803 1564 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
23:48:37.0803 1564 Brserid - ok
23:48:37.0881 1564 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
23:48:37.0881 1564 BrSerWdm - ok
23:48:37.0943 1564 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
23:48:37.0943 1564 BrUsbMdm - ok
23:48:37.0990 1564 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
23:48:37.0990 1564 BrUsbSer - ok
23:48:38.0053 1564 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
23:48:38.0053 1564 BTHMODEM - ok
23:48:38.0146 1564 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
23:48:38.0146 1564 cdfs - ok
23:48:38.0178 1564 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
23:48:38.0193 1564 cdrom - ok
23:48:38.0287 1564 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
23:48:38.0303 1564 circlass - ok
23:48:38.0350 1564 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
23:48:38.0350 1564 CLFS - ok
23:48:38.0475 1564 CmBatt (0fed59edb4a83ff17f1778827b88ab1a) C:\Windows\system32\DRIVERS\CmBatt.sys
23:48:38.0475 1564 CmBatt - ok
23:48:38.0521 1564 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
23:48:38.0521 1564 cmdide - ok
23:48:38.0553 1564 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
23:48:38.0553 1564 Compbatt - ok
23:48:38.0631 1564 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
23:48:38.0631 1564 crcdisk - ok
23:48:38.0678 1564 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
23:48:38.0678 1564 Crusoe - ok
23:48:38.0818 1564 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
23:48:38.0818 1564 disk - ok
23:48:38.0865 1564 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
23:48:38.0865 1564 drmkaud - ok
23:48:38.0943 1564 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
23:48:38.0959 1564 DXGKrnl - ok
23:48:39.0053 1564 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
23:48:39.0053 1564 E1G60 - ok
23:48:39.0100 1564 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
23:48:39.0100 1564 Ecache - ok
23:48:39.0162 1564 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
23:48:39.0178 1564 elxstor - ok
23:48:39.0287 1564 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
23:48:39.0287 1564 exfat - ok
23:48:39.0475 1564 F-Secure Standalone Minifilter (1838a21b5abb3c76191573c06584f07e) C:\Users\ADMINI~1\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys
23:48:39.0475 1564 F-Secure Standalone Minifilter - ok
23:48:39.0553 1564 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
23:48:39.0553 1564 fastfat - ok
23:48:39.0600 1564 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
23:48:39.0600 1564 fdc - ok
23:48:39.0693 1564 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
23:48:39.0693 1564 FileInfo - ok
23:48:39.0740 1564 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
23:48:39.0740 1564 Filetrace - ok
23:48:39.0787 1564 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
23:48:39.0787 1564 flpydisk - ok
23:48:39.0881 1564 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
23:48:39.0881 1564 FltMgr - ok
23:48:39.0959 1564 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
23:48:39.0959 1564 Fs_Rec - ok
23:48:40.0021 1564 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
23:48:40.0021 1564 gagp30kx - ok
23:48:40.0084 1564 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
23:48:40.0100 1564 HdAudAddService - ok
23:48:40.0287 1564 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
23:48:40.0334 1564 HDAudBus - ok
23:48:40.0365 1564 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
23:48:40.0365 1564 HidBth - ok
23:48:40.0459 1564 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
23:48:40.0459 1564 HidIr - ok
23:48:40.0506 1564 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
23:48:40.0506 1564 HidUsb - ok
23:48:40.0553 1564 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
23:48:40.0553 1564 HpCISSs - ok
23:48:40.0646 1564 HSF_DPV (1882827f41dee51c70e24c567c35bfb5) C:\Windows\system32\DRIVERS\HSX_DPV.sys
23:48:40.0678 1564 HSF_DPV - ok
23:48:40.0725 1564 HSXHWBS2 (5f60f0ad32d43b9ab9ac9373117d8e54) C:\Windows\system32\DRIVERS\HSXHWBS2.sys
23:48:40.0740 1564 HSXHWBS2 - ok
23:48:40.0818 1564 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys
23:48:40.0834 1564 HTTP - ok
23:48:40.0865 1564 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
23:48:40.0865 1564 i2omp - ok
23:48:40.0975 1564 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
23:48:40.0975 1564 i8042prt - ok
23:48:41.0053 1564 ialm (8318e04a6455ced1020bcc5039b62cfa) C:\Windows\system32\DRIVERS\ialmnt5.sys
23:48:41.0084 1564 ialm - ok
23:48:41.0162 1564 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
23:48:41.0162 1564 iaStorV - ok
23:48:41.0225 1564 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
23:48:41.0225 1564 iirsp - ok
23:48:41.0334 1564 IntcAzAudAddService (a47b2875680ad67b35c6150bd0203056) C:\Windows\system32\drivers\RTKVHDA.sys
23:48:41.0381 1564 IntcAzAudAddService - ok
23:48:41.0459 1564 intelide (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
23:48:41.0459 1564 intelide - ok
23:48:41.0521 1564 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
23:48:41.0521 1564 intelppm - ok
23:48:41.0600 1564 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
23:48:41.0600 1564 IpFilterDriver - ok
23:48:41.0631 1564 IpInIp - ok
23:48:41.0678 1564 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
23:48:41.0678 1564 IPMIDRV - ok
23:48:41.0740 1564 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
23:48:41.0740 1564 IPNAT - ok
23:48:41.0834 1564 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
23:48:41.0834 1564 IRENUM - ok
23:48:41.0881 1564 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
23:48:41.0881 1564 isapnp - ok
23:48:41.0975 1564 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
23:48:41.0990 1564 iScsiPrt - ok
23:48:42.0037 1564 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
23:48:42.0037 1564 iteatapi - ok
23:48:42.0115 1564 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
23:48:42.0115 1564 iteraid - ok
23:48:42.0162 1564 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
23:48:42.0162 1564 kbdclass - ok
23:48:42.0225 1564 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
23:48:42.0225 1564 kbdhid - ok
23:48:42.0318 1564 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
23:48:42.0334 1564 KSecDD - ok
23:48:42.0428 1564 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
23:48:42.0428 1564 Lavasoft Kernexplorer - ok
23:48:42.0521 1564 Lbd (336abe8721cbc3110f1c6426da633417) C:\Windows\system32\DRIVERS\Lbd.sys
23:48:42.0521 1564 Lbd - ok
23:48:42.0568 1564 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
23:48:42.0568 1564 lltdio - ok
23:48:42.0631 1564 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
23:48:42.0631 1564 LSI_FC - ok
23:48:42.0709 1564 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
23:48:42.0725 1564 LSI_SAS - ok
23:48:42.0771 1564 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
23:48:42.0771 1564 LSI_SCSI - ok
23:48:42.0803 1564 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
23:48:42.0803 1564 luafv - ok
23:48:42.0912 1564 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
23:48:42.0912 1564 mdmxsdk - ok
23:48:42.0959 1564 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
23:48:42.0959 1564 megasas - ok
23:48:43.0021 1564 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
23:48:43.0021 1564 Modem - ok
23:48:43.0115 1564 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
23:48:43.0115 1564 monitor - ok
23:48:43.0146 1564 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
23:48:43.0146 1564 mouclass - ok
23:48:43.0178 1564 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
23:48:43.0193 1564 mouhid - ok
23:48:43.0240 1564 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
23:48:43.0240 1564 MountMgr - ok
23:48:43.0334 1564 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
23:48:43.0334 1564 mpio - ok
23:48:43.0365 1564 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
23:48:43.0365 1564 mpsdrv - ok
23:48:43.0412 1564 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
23:48:43.0428 1564 Mraid35x - ok
23:48:43.0475 1564 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
23:48:43.0475 1564 MREMP50 - ok
23:48:43.0506 1564 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
23:48:43.0506 1564 MRESP50 - ok
23:48:43.0600 1564 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
23:48:43.0600 1564 MRxDAV - ok
23:48:43.0646 1564 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
23:48:43.0646 1564 mrxsmb - ok
23:48:43.0693 1564 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
23:48:43.0693 1564 mrxsmb10 - ok
23:48:43.0771 1564 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
23:48:43.0771 1564 mrxsmb20 - ok
23:48:43.0803 1564 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
23:48:43.0803 1564 msahci - ok
23:48:43.0850 1564 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
23:48:43.0850 1564 msdsm - ok
23:48:43.0912 1564 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
23:48:43.0912 1564 Msfs - ok
23:48:43.0990 1564 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
23:48:43.0990 1564 msisadrv - ok
23:48:44.0068 1564 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
23:48:44.0068 1564 MSKSSRV - ok
23:48:44.0115 1564 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
23:48:44.0115 1564 MSPCLOCK - ok
23:48:44.0162 1564 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
23:48:44.0178 1564 MSPQM - ok
23:48:44.0225 1564 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
23:48:44.0225 1564 MsRPC - ok
23:48:44.0287 1564 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
23:48:44.0287 1564 mssmbios - ok
23:48:44.0334 1564 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
23:48:44.0350 1564 MSTEE - ok
23:48:44.0381 1564 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
23:48:44.0381 1564 Mup - ok
23:48:44.0443 1564 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
23:48:44.0459 1564 NativeWifiP - ok
23:48:44.0521 1564 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
23:48:44.0537 1564 NDIS - ok
23:48:44.0600 1564 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
23:48:44.0600 1564 NdisTapi - ok
23:48:44.0662 1564 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
23:48:44.0662 1564 Ndisuio - ok
23:48:44.0709 1564 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
23:48:44.0709 1564 NdisWan - ok
23:48:44.0771 1564 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
23:48:44.0771 1564 NDProxy - ok
23:48:44.0834 1564 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
23:48:44.0834 1564 NetBIOS - ok
23:48:44.0881 1564 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
23:48:44.0881 1564 netbt - ok
23:48:45.0037 1564 NETw2v32 (6e9edc1020b319e7676387b8cdf2398c) C:\Windows\system32\DRIVERS\NETw2v32.sys
23:48:45.0084 1564 NETw2v32 - ok
23:48:45.0146 1564 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
23:48:45.0146 1564 nfrd960 - ok
23:48:45.0209 1564 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
23:48:45.0209 1564 Npfs - ok
23:48:45.0271 1564 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
23:48:45.0271 1564 nsiproxy - ok
23:48:45.0365 1564 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
23:48:45.0396 1564 Ntfs - ok
23:48:45.0459 1564 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
23:48:45.0459 1564 ntrigdigi - ok
23:48:45.0521 1564 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
23:48:45.0521 1564 Null - ok
23:48:45.0568 1564 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
23:48:45.0568 1564 nvraid - ok
23:48:45.0631 1564 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
23:48:45.0631 1564 nvstor - ok
23:48:45.0693 1564 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
23:48:45.0693 1564 nv_agp - ok
23:48:45.0725 1564 NwlnkFlt - ok
23:48:45.0740 1564 NwlnkFwd - ok
23:48:45.0865 1564 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys
23:48:45.0865 1564 ohci1394 - ok
23:48:45.0959 1564 Parport (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
23:48:45.0959 1564 Parport - ok
23:48:46.0037 1564 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
23:48:46.0037 1564 partmgr - ok
23:48:46.0084 1564 Parvdm (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
23:48:46.0084 1564 Parvdm - ok
23:48:46.0146 1564 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
23:48:46.0146 1564 pci - ok
23:48:46.0240 1564 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
23:48:46.0240 1564 pciide - ok
23:48:46.0303 1564 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\DRIVERS\pcmcia.sys
23:48:46.0303 1564 pcmcia - ok
23:48:46.0396 1564 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
23:48:46.0412 1564 PEAUTH - ok
23:48:46.0521 1564 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
23:48:46.0521 1564 PptpMiniport - ok
23:48:46.0600 1564 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
23:48:46.0600 1564 Processor - ok
23:48:46.0678 1564 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
23:48:46.0678 1564 PSched - ok
23:48:46.0787 1564 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
23:48:46.0803 1564 ql2300 - ok
23:48:46.0834 1564 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
23:48:46.0834 1564 ql40xx - ok
23:48:46.0881 1564 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
23:48:46.0881 1564 QWAVEdrv - ok
23:48:47.0021 1564 R300 (554685122b4f973e21d66c2baaf29543) C:\Windows\system32\DRIVERS\atikmdag.sys
23:48:47.0053 1564 R300 - ok
23:48:47.0146 1564 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
23:48:47.0146 1564 RasAcd - ok
23:48:47.0178 1564 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
23:48:47.0193 1564 Rasl2tp - ok
23:48:47.0240 1564 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
23:48:47.0240 1564 RasPppoe - ok
23:48:47.0303 1564 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
23:48:47.0303 1564 RasSstp - ok
23:48:47.0381 1564 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
23:48:47.0381 1564 rdbss - ok
23:48:47.0428 1564 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
23:48:47.0428 1564 RDPCDD - ok
23:48:47.0490 1564 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
23:48:47.0506 1564 rdpdr - ok
23:48:47.0568 1564 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
23:48:47.0568 1564 RDPENCDD - ok
23:48:47.0631 1564 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
23:48:47.0631 1564 RDPWD - ok
23:48:47.0709 1564 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
23:48:47.0709 1564 rspndr - ok
23:48:47.0771 1564 RTL8023xp (166911eada13cd34dd8f8c667707be94) C:\Windows\system32\DRIVERS\Rtnicxp.sys
23:48:47.0771 1564 RTL8023xp - ok
23:48:47.0818 1564 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
23:48:47.0818 1564 sbp2port - ok
23:48:47.0881 1564 sdbus (4339a2585708c7d9b0c0ce5aad3dd6ff) C:\Windows\system32\DRIVERS\sdbus.sys
23:48:47.0881 1564 sdbus - ok
23:48:47.0975 1564 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
23:48:47.0975 1564 secdrv - ok
23:48:48.0053 1564 Serenum (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
23:48:48.0053 1564 Serenum - ok
23:48:48.0084 1564 Serial (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
23:48:48.0084 1564 Serial - ok
23:48:48.0178 1564 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
23:48:48.0178 1564 sermouse - ok
23:48:48.0256 1564 sffdisk (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
23:48:48.0256 1564 sffdisk - ok
23:48:48.0303 1564 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
23:48:48.0303 1564 sffp_mmc - ok
23:48:48.0350 1564 sffp_sd (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
23:48:48.0350 1564 sffp_sd - ok
23:48:48.0396 1564 sfloppy (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys
23:48:48.0396 1564 sfloppy - ok
23:48:48.0459 1564 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
23:48:48.0459 1564 sisagp - ok
23:48:48.0521 1564 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
23:48:48.0521 1564 SiSRaid2 - ok
23:48:48.0568 1564 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
23:48:48.0568 1564 SiSRaid4 - ok
23:48:48.0631 1564 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
23:48:48.0631 1564 Smb - ok
23:48:48.0678 1564 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
23:48:48.0678 1564 spldr - ok
23:48:48.0756 1564 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
23:48:48.0756 1564 srv - ok
23:48:48.0818 1564 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
23:48:48.0818 1564 srv2 - ok
23:48:48.0850 1564 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
23:48:48.0850 1564 srvnet - ok
23:48:48.0928 1564 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
23:48:48.0928 1564 swenum - ok
23:48:48.0975 1564 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
23:48:48.0990 1564 Symc8xx - ok
23:48:49.0037 1564 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
23:48:49.0037 1564 Sym_hi - ok
23:48:49.0100 1564 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
23:48:49.0100 1564 Sym_u3 - ok
23:48:49.0193 1564 Tcpip (2756186e287139310997090797e0182b) C:\Windows\system32\drivers\tcpip.sys
23:48:49.0225 1564 Tcpip - ok
23:48:49.0303 1564 Tcpip6 (2756186e287139310997090797e0182b) C:\Windows\system32\DRIVERS\tcpip.sys
23:48:49.0318 1564 Tcpip6 - ok
23:48:49.0365 1564 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
23:48:49.0365 1564 tcpipreg - ok
23:48:49.0396 1564 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
23:48:49.0396 1564 TDPIPE - ok
23:48:49.0443 1564 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
23:48:49.0443 1564 TDTCP - ok
23:48:49.0521 1564 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
23:48:49.0537 1564 tdx - ok
23:48:49.0568 1564 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
23:48:49.0568 1564 TermDD - ok
23:48:49.0631 1564 tmrkb (7e2887341a3164dedc9b89082c24aeca) C:\Windows\system32\DRIVERS\tmrkb.sys
23:48:49.0631 1564 Suspicious file (Forged): C:\Windows\system32\DRIVERS\tmrkb.sys. Real md5: 7e2887341a3164dedc9b89082c24aeca, Fake md5: b44d1e95a4c70853230a2e1cd0dac0b9
23:48:49.0631 1564 tmrkb ( ForgedFile.Multi.Generic ) - warning
23:48:49.0631 1564 tmrkb - detected ForgedFile.Multi.Generic (1)
23:48:49.0740 1564 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
23:48:49.0740 1564 tssecsrv - ok
23:48:49.0787 1564 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
23:48:49.0787 1564 tunmp - ok
23:48:49.0834 1564 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
23:48:49.0834 1564 tunnel - ok
23:48:49.0912 1564 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
23:48:49.0912 1564 uagp35 - ok
23:48:49.0959 1564 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
23:48:49.0959 1564 udfs - ok
23:48:50.0037 1564 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
23:48:50.0053 1564 uliagpkx - ok
23:48:50.0131 1564 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
23:48:50.0146 1564 uliahci - ok
23:48:50.0178 1564 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
23:48:50.0178 1564 UlSata - ok
23:48:50.0209 1564 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
23:48:50.0225 1564 ulsata2 - ok
23:48:50.0271 1564 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
23:48:50.0271 1564 umbus - ok
23:48:50.0350 1564 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
23:48:50.0350 1564 usbccgp - ok
23:48:50.0396 1564 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
23:48:50.0412 1564 usbcir - ok
23:48:50.0459 1564 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
23:48:50.0459 1564 usbehci - ok
23:48:50.0537 1564 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
23:48:50.0537 1564 usbhub - ok
23:48:50.0584 1564 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
23:48:50.0584 1564 usbohci - ok
23:48:50.0631 1564 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
23:48:50.0631 1564 usbprint - ok
23:48:50.0709 1564 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
23:48:50.0709 1564 USBSTOR - ok
23:48:50.0756 1564 usbuhci (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
23:48:50.0756 1564 usbuhci - ok
23:48:50.0818 1564 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
23:48:50.0818 1564 vga - ok
23:48:50.0881 1564 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
23:48:50.0881 1564 VgaSave - ok
23:48:50.0959 1564 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
23:48:50.0959 1564 viaagp - ok
23:48:51.0006 1564 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
23:48:51.0006 1564 ViaC7 - ok
23:48:51.0053 1564 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
23:48:51.0053 1564 viaide - ok
23:48:51.0131 1564 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
23:48:51.0131 1564 volmgr - ok
23:48:51.0178 1564 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
23:48:51.0193 1564 volmgrx - ok
23:48:51.0271 1564 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
23:48:51.0271 1564 volsnap - ok
23:48:51.0350 1564 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
23:48:51.0365 1564 vsmraid - ok
23:48:51.0412 1564 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
23:48:51.0412 1564 WacomPen - ok
23:48:51.0475 1564 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
23:48:51.0475 1564 Wanarp - ok
23:48:51.0475 1564 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
23:48:51.0475 1564 Wanarpv6 - ok
23:48:51.0537 1564 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
23:48:51.0537 1564 Wd - ok
23:48:51.0615 1564 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
23:48:51.0631 1564 Wdf01000 - ok
23:48:51.0740 1564 winachsf (e096ffb754f1e45ae1bddac1275ae2c5) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
23:48:51.0756 1564 winachsf - ok
23:48:51.0865 1564 WmiAcpi (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
23:48:51.0865 1564 WmiAcpi - ok
23:48:51.0943 1564 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
23:48:51.0943 1564 ws2ifsl - ok
23:48:52.0037 1564 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
23:48:52.0037 1564 WUDFRd - ok
23:48:52.0100 1564 XAudio (e3fcf2870b5d7979b3bf10e98a71c847) C:\Windows\system32\DRIVERS\xaudio.sys
23:48:52.0100 1564 XAudio - ok
23:48:52.0193 1564 yukonwlh (7d1f3b131d503ef43ee594b5a2b9b427) C:\Windows\system32\DRIVERS\yk60x86.sys
23:48:52.0193 1564 yukonwlh - ok
23:48:52.0225 1564 MBR (0x1B8) (943cc8d9009a7f8da0e7fc257c230977) \Device\Harddisk0\DR0
23:48:52.0240 1564 \Device\Harddisk0\DR0 - ok
23:48:52.0240 1564 Boot (0x1200) (bbf90931a3432221e158e8f6f44da305) \Device\Harddisk0\DR0\Partition0
23:48:52.0240 1564 \Device\Harddisk0\DR0\Partition0 - ok
23:48:52.0271 1564 Boot (0x1200) (025108f3986ccbd49435e7a25691a402) \Device\Harddisk0\DR0\Partition1
23:48:52.0271 1564 \Device\Harddisk0\DR0\Partition1 - ok
23:48:52.0271 1564 ============================================================
23:48:52.0271 1564 Scan finished
23:48:52.0271 1564 ============================================================
23:48:52.0287 0964 Detected object count: 2
23:48:52.0287 0964 Actual detected object count: 2
23:49:11.0490 0964 C:\Windows\3717040010:1970827810.exe - copied to quarantine
23:49:11.0490 0964 8a878ddd ( Rootkit.Win32.PMax.gen ) - User select action: Quarantine
23:49:11.0584 0964 C:\Windows\system32\DRIVERS\tmrkb.sys - copied to quarantine
23:49:11.0584 0964 tmrkb ( ForgedFile.Multi.Generic ) - User select action: Quarantine
3. There is no Java on this system because when I noticed that Java files were infected, I tried to disable the virus, but the Java files kept coming up as infected so I uninstalled it but haven't gone back to reinstall it.
4. I have uninstalled and reinstalled Adobe Reader to 10.1.1
5. Mozilla Firefox was uninstalled. It was never used anyway.
6. Avast is the only true anti-virus program that is supposedly running. Panda and F-Secure were only installed into the browser to attempt to run some online scans. I have uninstalled avast because the service woudln't stop.I will reinstall once we are finished.
7. Combofix log is as follows:
ComboFix 11-11-08.02 - Administrator 11/08/2011 21:38:15.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1917.1176 [GMT -6:00]
Running from: c:\users\Administrator\Desktop\ComboFix2.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files\iexplore
c:\program files\iexplore\iExplore.exe (3).exe
c:\program files\iexplore\iExplore.exe.exe
c:\program files\iexplore\iExplre.exe
c:\programdata\Windows
c:\users\Susan\1BD.jpg
c:\users\Susan\1BDA.jpg
c:\users\Susan\2zoo.jpg
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_8a878ddd
-------\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-10-09 to 2011-11-09 )))))))))))))))))))))))))))))))
.
.
2011-11-09 03:44 . 2011-11-09 03:44 -------- d-----w- c:\users\Susan\AppData\Local\temp
2011-11-09 03:44 . 2011-11-09 03:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-09 03:12 . 2011-11-09 03:20 -------- d-----w- C:\ComboFix
2011-11-09 01:15 . 2011-11-09 01:15 -------- d-----w- c:\program files\ESET
2011-10-31 05:21 . 2011-11-01 04:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-31 03:17 . 2011-10-31 03:28 -------- d-----w- c:\program files\Boom
2011-10-31 03:04 . 2011-11-05 04:49 -------- d-----w- C:\TDSSKiller_Quarantine
2011-10-26 05:55 . 2011-10-26 05:55 65808 ----a-w- c:\windows\system32\drivers\tmrkb.sys
2011-10-26 05:55 . 2011-10-26 05:55 205072 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-10-26 05:24 . 2011-10-26 05:24 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-26 05:21 . 2011-10-26 05:21 -------- dc----w- c:\windows\system32\DRVSTORE
2011-10-26 05:21 . 2011-08-18 20:25 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-10-26 05:20 . 2011-10-26 05:20 -------- d-----w- c:\program files\Lavasoft
2011-10-26 05:20 . 2011-10-26 05:20 -------- d-----w- c:\programdata\Lavasoft
2011-10-26 04:46 . 2011-10-26 04:46 -------- d-----w- c:\programdata\F-Secure
2011-10-26 02:59 . 2011-10-26 05:09 -------- d-----w- c:\program files\Panda Security
2011-10-19 03:47 . 2011-11-01 04:04 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-10-19 03:46 . 2011-10-26 02:46 -------- d-----w- c:\program files\BLAH
2011-10-19 03:40 . 2011-10-26 01:46 -------- d-----w- c:\program files\ABC123
2011-10-19 02:48 . 2011-10-19 03:22 -------- d-----w- c:\users\Administrator
2011-10-19 01:08 . 2011-10-19 01:08 -------- d-----w- c:\program files\Trend Micro
2011-10-19 01:00 . 2011-10-19 03:20 -------- d-----w- c:\program files\jkl
2011-10-18 02:55 . 2011-10-18 12:56 -------- d-----w- c:\program files\iExpl
2011-10-18 02:49 . 2011-10-18 02:49 -------- d-----w- c:\program files\PragmaDigm
2011-10-18 02:38 . 2011-10-18 02:38 -------- d-----w- c:\users\Susan\AppData\Roaming\U3
2011-10-16 23:10 . 2011-11-01 04:12 -------- d-----w- c:\programdata\AVAST Software
2011-10-16 23:10 . 2011-10-16 23:10 -------- d-----w- c:\program files\AVAST Software
2011-10-15 13:26 . 2011-09-06 13:30 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-10-15 13:17 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-15 13:17 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-15 13:17 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-15 13:17 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-15 13:17 . 2011-09-14 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-10-15 13:17 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-15 13:17 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-15 13:17 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2011-10-15 13:17 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-10-15 13:17 . 2011-09-12 23:14 7269712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0840402E-10B0-44B9-89FF-33C8A13B97A5}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-09 01:04 . 2011-07-16 01:08 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrpConv]
grpconv -o [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3074645540-534623877-3370066440-1000]
"EnableNotificationsRef"=dword:00000002
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3074645540-534623877-3370066440-500]
"EnableNotificationsRef"=dword:00000002
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-10-26 2151640]
R2 tmrkb;tmrkb;c:\windows\system32\DRIVERS\tmrkb.sys [2011-10-26 65808]
R3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;c:\users\ADMINI~1\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-08-18 15232]
R3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-08-18 64512]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-08-18 05:24]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = <local>
TCP: DhcpNameServer = 192.168.0.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-08 21:47
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\windows\3717040010:1970827810.exe 784 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3074645540-534623877-3370066440-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,3b,1b,21,83,17,
e1,69,99,45,06,a6,34,d4,a9,2c,96,14,19
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,c3,f8,
a3,56,97,bb,59,a5,e2,42,e0,cc,4a,f4,15
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,3b,1b,8f,83,96,
18,e4,9d,32,05,a1,72,3a,0b,78,2b,a1,a9
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,3b,1b,74,c9,22,
8e,31,19,d4,02,97,c3,13,24,73,48,22,dc
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,3b,1b,0c,15,cd,
06,9e,bd,e8,0a,bc,99,b8,17,89,6e,fc,d9
.
[HKEY_USERS\S-1-5-21-3074645540-534623877-3370066440-500\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:99,32,7e,b5,0a,8e,cc,01
.
[HKEY_USERS\S-1-5-21-3074645540-534623877-3370066440-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,bd,27,72,99,ca,69,46,82,a1,99,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,bd,27,72,99,ca,69,46,82,a1,99,\
"027C9CB72E593A8F02C55092F385DBAC99DF56D067"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,bd,27,72,99,ca,69,46,82,a1,99,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2011-11-08 21:52:38 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-09 03:52
.
Pre-Run: 114,160,132,096 bytes free
Post-Run: 114,436,988,928 bytes free
.
- - End Of File - - 3F936BE94095DD71008644932F670918
SAS file in next post.