Unsolved
This post is more than 5 years old
45 Posts
0
2852
December 18th, 2010 12:00
"Redirect" - Bing & Google Searches
I need help in identifying and getting rid of something that is redirecting links to sites returned by Bing and Google searches.
Selecting some links returned by Bing and Google searches result in the selected site URL being changed ("Redirect") to a marketing site. For instance, using either Bing or Google to search for "Oceanmist", a farming business in California, the correct URL link for Ocean Mist Farms is returned as one of the options. When I select the Ocean Mist link, Internet Explorer starts the linking process to www.oceanmist.com, then something identified in History as "Redirect" changes the URL to one of many marketing sites, e.g. findstuff.com, or shopcompareus.com. However, when I return to the Google or Bing search page, without closing IE8, and again search for Oceanmist and select the same link, the Redirect does not occur and I go directly to the Ocean Mist site.
What is strange is that this only happens with certain sites. For instance, it happens with all search links that include a Wikipedia link, but it does not happen with any search link to an automobile company or dealer, or links to hobby sites. Also it only happens with an Inspiron Mini 1012 running Win7 Home and IE8, but not with an XPS17 and an Optiplex 755, both also running Win7 Home and IE8.
Deep system scans using ZoneAlarm Security Suite, version 9.3, and Registry searches using RegEdit turn up nothing. Attempts to isolate the HTML or Macro label from History to identify its file name appear to be blocked. When I uninstall and reinstall IE8, the Redirect does not occur the first time I use Bing or Google, but then after closing and re-executing IE8 the Redirect returns with the first Bing or Google search. So obviously an executable file is imbedded somewhere in the system and is somehow linked to initial Bing and Google search executions.
Can somebody help me identify and get rid of this?
BTW, I searched this forum for "Redirect" topics and found the predominate suggestion is to use MalwareBytes. I do not wish to re-install MalwareBytes on any of my systems due to a bad experience with that product, and their tech support, about a year ago. I am hoping there might be a technique or product, other than MalwareBytes that could help me.
Thanks


kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
December 19th, 2010 11:00
Hello Hytec,
I'm kevinf80 and I will be helping with any malware issues you may have with your system.
Please proceed as follows :-
Step 1
Download
Link 1
Link 2
TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.
Step 2
We need to see some additional information about what is happening in your machine.
Please perform the following scan:
2. Attach.txt
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
Step 3
Please download MBRCheck.exe to your desktop.
Step 4
Download Security Check by screen317 from HERE or HERE.
Save it to your Desktop.
Double click SecurityCheck.exe (Vista or Windows 7 users right click and select "Run as Administrator") and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
What i`d like in your reply :-
Kevin
Hytec
45 Posts
0
December 19th, 2010 15:00
Thanks Kevin, I understand that remote analysis of conditions such as this are difficult and time-consuming, especially when they must be on a "not-to-interfere" basis with more important requirements such as family and work.
I'm printing your instructions to make them easier to follow and implement. The Mini's screen is small which makes it difficult read without a legible backup. I expect to post the log file later this evening, or first thing in the morning.
Thanks again for your time and help, Hank
Hytec
45 Posts
0
December 19th, 2010 18:00
Security Check Log follows.....
Results of screen317's Security Check version 0.99.8
Windows 7 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Disabled!
ZoneAlarm Security Suite
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Java(TM) 6 Update 14
Out of date Java installed!
Adobe Flash Player
Adobe Reader 9.4.1
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent
Zone Labs ZoneAlarm zlclient.exe
Zone Labs ZoneAlarm MailFrontier mantispm.exe
``````````End of Log````````````
This completes Kevin's instructions. I now await further instructions.
Thanks for your time and effort, Hank
Hytec
45 Posts
0
December 19th, 2010 18:00
Per Kevin's instructions....
DDS.txt
DDS (Ver_10-12-12.02) - NTFSx86
Run by Henry Coolidge at 19:57:22.00 on Sun 12/19/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.1013.377 [GMT -6:00]
AV: ZoneAlarm Security Suite Antivirus *Enabled/Updated* {E9467272-859A-F159-FA9E-55E7E32D7A25}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ZoneAlarm Security Suite Anti-Spyware *Enabled/Updated* {52279396-A3A0-FED7-C02E-6E9598AA3098}
FW: ZoneAlarm Security Suite Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
C:\Program Files\QUALCOMM\QDLService2k\QDLService2kDell.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\WSED\WSED.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Henry Coolidge\Desktop\dds.com
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Bar = Preserve
uStart Page = hxxp://www.google.com/
BHO: Virtual Account Numbers Helper: {17424104-1444-4810-85d7-b4da413c5a9a} - c:\program files\virtual account numbers\CitiVANHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Virtual Account Numbers: {7a21a046-b886-4a62-9d69-ef2059b0a27b} - c:\program files\virtual account numbers\CitiVANToolbar.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\program files\dell\dell wireless wlan card\WLTRAY.exe
mRun: [WSED] c:\program files\wsed\WSED.exe
mRun: [ ]
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [2009-6-26 13680]
R1 RapportCerberus_19917;RapportCerberus_19917;c:\programdata\trusteer\rapport\store\exts\rapportcerberus\19917\RapportCerberus_19917.sys [2010-10-3 34792]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-10-3 169320]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [2009-12-12 143840]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-12 189440]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-12-12 174592]
=============== Created Last 30 ================
2010-12-13 05:07:39 -------- d-----w- c:\windows\Downloaded Program Files
2010-12-10 21:05:25 -------- d-----w- c:\users\henryc~1\appdata\roaming\PCDr
2010-12-03 09:28:10 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{430fd924-adeb-4e2a-a4e9-3c284e5c7558}\mpengine.dll
2010-11-24 11:57:44 7680 ----a-w- c:\program files\internet explorer\iecompat.dll
==================== Find3M ====================
2010-10-25 10:20:18 150552 ----a-w- c:\windows\system32\igfxpers.exe
2010-10-25 10:20:18 141848 ----a-w- c:\windows\system32\igfxtray.exe
2010-10-25 10:20:16 672792 ----a-w- c:\windows\system32\igfxcfg.exe
2010-10-25 10:20:16 252952 ----a-w- c:\windows\system32\igfxsrvc.exe
2010-10-25 10:20:16 173592 ----a-w- c:\windows\system32\hkcmd.exe
2010-10-25 10:20:16 173080 ----a-w- c:\windows\system32\igfxext.exe
2010-10-25 10:20:16 1006104 ----a-w- c:\windows\system32\igxpun.exe
2010-10-25 10:16:56 155648 ----a-w- c:\windows\system32\igfxCoIn_v2230.dll
2010-10-25 10:10:12 3829760 ----a-w- c:\windows\system32\igdumd32.dll
2010-10-25 10:08:20 536576 ----a-w- c:\windows\system32\igdumdx32.dll
2010-10-25 10:02:48 2686976 ----a-w- c:\windows\system32\ig4dev32.dll
2010-10-25 10:02:02 4104192 ----a-w- c:\windows\system32\ig4icd32.dll
2010-10-25 09:54:10 257536 ----a-w- c:\windows\system32\igfxTMM.dll
2010-10-25 09:54:06 59392 ----a-w- c:\windows\system32\oemdspif.dll
2010-10-25 09:54:04 23552 ----a-w- c:\windows\system32\igfxexps.dll
2010-10-25 09:54:02 199680 ----a-w- c:\windows\system32\igfxpph.dll
2010-10-25 09:54:02 119296 ----a-w- c:\windows\system32\igfxcpl.cpl
2010-10-25 09:53:44 51712 ----a-w- c:\windows\system32\igfxsrvc.dll
2010-10-25 09:53:28 130048 ----a-w- c:\windows\system32\igfxdo.dll
2010-10-25 09:53:20 94208 ----a-w- c:\windows\system32\hccutils.dll
2010-10-25 09:53:16 218112 ----a-w- c:\windows\system32\igfxdev.dll
2010-10-25 09:53:00 5702656 ----a-w- c:\windows\system32\igfxress.dll
2010-10-25 09:53:00 275968 ----a-w- c:\windows\system32\igfxrenu.lrc
2010-10-19 16:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-09-23 05:47:28 49016 ----a-w- c:\windows\system32\sirenacm.dll
2010-09-23 05:32:56 301936 ----a-w- c:\windows\WLXPGSS.SCR
2010-09-21 19:03:14 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7600 Disk: TOSHIBA_MK1655GSX rev.FG010D -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-0
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x84104555]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8410a7b0]; MOV EAX, [0x8410a82c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x81A8E458] -> \Device\Harddisk0\DR0[0x840DE898]
3 CLASSPNP[0x85DDA59E] -> ntkrnlpa!IofCallDriver[0x81A8E458] -> [0x8403EC10]
5 ACPI[0x85EC03B2] -> ntkrnlpa!IofCallDriver[0x81A8E458] -> \IdeDeviceP0T0L0-0[0x8402C030]
\Driver\atapi[0x840E43E0] -> IRP_MJ_CREATE -> 0x84104555
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x132; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-0 -> \??\IDE#DiskTOSHIBA_MK1655GSX_______________________FG010D__#5&21c0ba82&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
============= FINISH: 20:00:28.29 ===============
Attach.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 2/20/2010 11:56:56 AM
System Uptime: 12/19/2010 7:51:25 PM (1 hours ago)
Motherboard: Dell Inc. | | 0P9MDV
Processor: Intel(R) Atom(TM) CPU N450 @ 1.66GHz | CPU 1 | 983/667mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 134 GiB total, 110.413 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP184: 11/19/2010 2:14:19 AM - Windows Update
RP185: 11/23/2010 2:14:19 AM - Windows Update
RP186: 11/24/2010 4:57:42 PM - Windows Update
RP187: 11/24/2010 5:03:26 PM - Windows Update
RP188: 11/26/2010 3:26:39 AM - Windows Update
RP189: 11/30/2010 3:26:41 AM - Windows Update
RP190: 12/3/2010 3:26:40 AM - Windows Update
RP191: 12/10/2010 3:10:46 PM - Installed Dell Support Center
RP192: 12/10/2010 3:31:13 PM - Installed Dell Support Center
RP193: 12/10/2010 4:52:13 PM - Removed Dell Support Center
RP194: 12/11/2010 9:34:48 AM - Windows Modules Installer
RP195: 12/11/2010 10:14:06 AM - Windows Modules Installer
RP196: 12/19/2010 2:33:05 PM - Scheduled Checkpoint
==== Installed Programs ======================
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Reader 9.4.1
Advanced Audio FX Engine
Bing Bar
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Compatibility Pack for the 2007 Office system
D3DX10
Dell DataSafe Online
Dell Dock
Dell Driver Download Manager
Dell Edoc Viewer
Dell Mobile Broadband Manager
Dell Mobile Broadband Utility
Dell Touch Zone
Dell Touchpad
Dell Webcam Central
Dell Wireless HSPA Mini-Card Drivers
Dell Wireless WLAN Card Utility
EMSC
Epson Print CD
EPSON Printer Software
Feedback Tool
Function Keys
Google Earth
Google Update Helper
GoToAssist 8.0.0.514
InstallVC90Support
Intel(R) Graphics Media Accelerator Driver
Java(TM) 6 Update 14
Junk Mail filter update
Live! Cam Avatar Creator
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
MSVCRT
OGA Notifier 2.0.0048.0
Qualcomm Gobi 2000 Package for Dell
Rapport
Realtek USB 2.0 Card Reader
Security Update for CAPICOM (KB931906)
Virtual Account Numbers
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WSED
ZoneAlarm Security Suite
==== Event Viewer Messages From Past Week ========
12/19/2010 7:51:26 PM, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort0.
12/19/2010 7:50:47 PM, Error: Service Control Manager [7038] - The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
12/19/2010 7:50:47 PM, Error: Service Control Manager [7000] - The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure.
12/19/2010 7:50:47 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
12/19/2010 12:04:14 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 29 time(s).
12/19/2010 12:04:14 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 29 time(s).
12/19/2010 10:34:38 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 28 time(s).
12/19/2010 10:34:38 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 28 time(s).
12/19/2010 10:08:09 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 27 time(s).
12/19/2010 10:08:09 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 27 time(s).
12/19/2010 1:54:02 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 26 time(s).
12/19/2010 1:54:02 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 26 time(s).
12/19/2010 1:08:59 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 30 time(s).
12/19/2010 1:08:59 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 30 time(s).
12/18/2010 8:39:12 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 24 time(s).
12/18/2010 8:39:12 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 24 time(s).
12/18/2010 8:39:12 AM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
12/18/2010 4:42:11 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 23 time(s).
12/18/2010 4:42:11 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 23 time(s).
12/18/2010 4:42:11 AM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 3 time(s).
12/18/2010 4:42:11 AM, Error: Service Control Manager [7034] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 3 time(s).
12/18/2010 3:13:32 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Server service to connect.
12/18/2010 3:13:32 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
12/18/2010 3:13:32 AM, Error: Service Control Manager [7000] - The Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/18/2010 3:11:02 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 22 time(s).
12/18/2010 3:11:02 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 22 time(s).
12/18/2010 3:11:02 AM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/18/2010 3:11:02 AM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
12/18/2010 3:11:02 AM, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/18/2010 2:30:04 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 25 time(s).
12/18/2010 2:30:04 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 25 time(s).
12/17/2010 9:30:38 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 17 time(s).
12/17/2010 9:30:38 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 17 time(s).
12/17/2010 6:42:30 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 16 time(s).
12/17/2010 6:42:30 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 16 time(s).
12/17/2010 5:41:41 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error: An instance of the service is already running.
12/17/2010 5:39:41 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 21 time(s).
12/17/2010 5:39:41 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 21 time(s).
12/17/2010 5:39:41 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/17/2010 5:39:41 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/17/2010 5:39:41 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/17/2010 3:16:31 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 15 time(s).
12/17/2010 3:16:31 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 15 time(s).
12/17/2010 11:31:16 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 19 time(s).
12/17/2010 11:31:16 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 19 time(s).
12/17/2010 10:32:47 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 18 time(s).
12/17/2010 10:32:47 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 18 time(s).
12/17/2010 1:24:24 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 20 time(s).
12/17/2010 1:24:24 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 20 time(s).
12/16/2010 9:18:56 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 13 time(s).
12/16/2010 9:18:56 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 13 time(s).
12/16/2010 7:35:25 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 12 time(s).
12/16/2010 7:35:25 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 12 time(s).
12/16/2010 5:59:03 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 8 time(s).
12/16/2010 5:59:03 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 8 time(s).
12/16/2010 5:59:03 AM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 9 time(s).
12/16/2010 5:28:23 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 11 time(s).
12/16/2010 5:28:23 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 11 time(s).
12/16/2010 3:17:47 AM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 8 time(s).
12/16/2010 3:10:47 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 10 time(s).
12/16/2010 3:10:47 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 10 time(s).
12/16/2010 2:29:43 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 7 time(s).
12/16/2010 2:29:43 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 7 time(s).
12/16/2010 2:29:43 AM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 7 time(s).
12/16/2010 10:21:41 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 14 time(s).
12/16/2010 10:21:41 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 14 time(s).
12/16/2010 1:54:38 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 9 time(s).
12/16/2010 1:54:37 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 9 time(s).
12/16/2010 1:54:37 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 10 time(s).
12/16/2010 1:47:52 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 6 time(s).
12/16/2010 1:47:52 AM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 6 time(s).
12/16/2010 1:47:52 AM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 6 time(s).
12/15/2010 9:58:33 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 5 time(s).
12/15/2010 9:58:33 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 5 time(s).
12/15/2010 9:58:33 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 5 time(s).
12/15/2010 9:06:01 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 4 time(s).
12/15/2010 9:06:01 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 4 time(s).
12/15/2010 9:06:01 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 4 time(s).
12/15/2010 6:33:27 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
12/15/2010 6:33:27 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the IKE and AuthIP IPsec Keying Modules service, but this action failed with the following error: An instance of the service is already running.
12/15/2010 6:30:27 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
12/15/2010 6:30:27 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error: An instance of the service is already running.
12/15/2010 6:30:27 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Background Intelligent Transfer Service service, but this action failed with the following error: An instance of the service is already running.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 2 time(s).
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/15/2010 6:28:27 AM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/15/2010 4:29:40 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user INSPIRONMINI\Henry Coolidge SID (S-1-5-21-4069033729-2100760198-3202855817-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
12/15/2010 2:15:44 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:44 PM, Error: Service Control Manager [7034] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:44 PM, Error: Service Control Manager [7034] - The Themes service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:44 PM, Error: Service Control Manager [7034] - The Task Scheduler service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:44 PM, Error: Service Control Manager [7034] - The System Event Notification Service service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:43 PM, Error: Service Control Manager [7034] - The User Profile Service service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:43 PM, Error: Service Control Manager [7034] - The IP Helper service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:43 PM, Error: Service Control Manager [7034] - The Group Policy Client service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:43 PM, Error: Service Control Manager [7034] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 3 time(s).
12/15/2010 2:15:43 PM, Error: Service Control Manager [7034] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 3 time(s).
12/14/2010 9:26:48 PM, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/14/2010 9:26:48 PM, Error: Service Control Manager [7000] - The Application Experience service failed to start due to the following error: The pipe has been ended.
12/14/2010 6:45:16 AM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 11 time(s).
12/14/2010 3:19:03 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 14 time(s).
12/14/2010 2:31:59 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 13 time(s).
12/14/2010 1:31:07 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 12 time(s).
12/13/2010 5:21:17 AM, Error: Service Control Manager [7034] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 4 time(s).
12/13/2010 4:15:56 PM, Error: Service Control Manager [7034] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 5 time(s).
12/12/2010 5:38:52 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BITS service.
12/12/2010 5:38:22 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MMCSS service.
12/12/2010 5:38:22 PM, Error: Service Control Manager [7000] - The Multimedia Class Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/12/2010 5:37:52 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Winmgmt service.
12/12/2010 2:47:12 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
12/12/2010 1:56:51 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ProfSvc service.
12/12/2010 1:56:51 PM, Error: Service Control Manager [7000] - The User Profile Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/12/2010 1:56:21 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SENS service.
12/12/2010 1:56:21 PM, Error: Service Control Manager [7000] - The System Event Notification Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/12/2010 1:55:21 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Windows Management Instrumentation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
12/12/2010 1:54:51 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
12/12/2010 1:54:51 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: After starting, the service hung in a start-pending state.
12/12/2010 1:54:49 PM, Error: Service Control Manager [7022] - The Themes service hung on starting.
12/12/2010 1:54:47 PM, Error: Service Control Manager [7022] - The Task Scheduler service hung on starting.
12/12/2010 1:54:16 PM, Error: Service Control Manager [7022] - The Server service hung on starting.
12/12/2010 1:52:26 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the EapHost service.
12/12/2010 1:52:26 PM, Error: Service Control Manager [7000] - The Extensible Authentication Protocol service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/12/2010 1:51:56 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IKEEXT service.
12/12/2010 1:51:56 PM, Error: Service Control Manager [7000] - The IKE and AuthIP IPsec Keying Modules service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/12/2010 1:51:26 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the gpsvc service.
12/12/2010 1:51:26 PM, Error: Service Control Manager [7000] - The Group Policy Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/12/2010 1:48:56 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
==== End Of File ===========================
Upon transmitting this post, I will complete and terminate Step 2, then proceed to Step 3.
Hytec
45 Posts
0
December 19th, 2010 18:00
MBRCheck,txt follows...
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Inspiron 1012
Logical Drives Mask: 0x00000004
Kernel Drivers (total 187):
0x81A52000 \SystemRoot\system32\ntkrnlpa.exe
0x81A1B000 \SystemRoot\system32\halmacpi.dll
0x8435D000 \SystemRoot\system32\kdcom.dll
0x85C13000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x85C8B000 \SystemRoot\system32\PSHED.dll
0x85C9C000 \SystemRoot\system32\BOOTVID.dll
0x85CA4000 \SystemRoot\system32\CLFS.SYS
0x85CE6000 \SystemRoot\system32\CI.dll
0x85E38000 \SystemRoot\system32\drivers\Wdf01000.sys
0x85EA9000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x85EB7000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x85EFF000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x85F08000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x85F10000 \SystemRoot\system32\DRIVERS\pci.sys
0x85F3A000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x85F45000 \SystemRoot\System32\drivers\partmgr.sys
0x85F56000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x85F5E000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x85F69000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x85F79000 \SystemRoot\System32\drivers\volmgrx.sys
0x85FC4000 \SystemRoot\System32\drivers\mountmgr.sys
0x85FDA000 \SystemRoot\system32\DRIVERS\atapi.sys
0x85E00000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x85E23000 \SystemRoot\system32\DRIVERS\msahci.sys
0x85FE3000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x85FF1000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x85D91000 \SystemRoot\system32\drivers\fltmgr.sys
0x85DC5000 \SystemRoot\system32\drivers\fileinfo.sys
0x8601F000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8614E000 \SystemRoot\System32\Drivers\msrpc.sys
0x86179000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8618C000 \SystemRoot\System32\Drivers\cng.sys
0x861E9000 \SystemRoot\System32\drivers\pcw.sys
0x861F7000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8620D000 \SystemRoot\system32\drivers\ndis.sys
0x862C4000 \SystemRoot\system32\drivers\NETIO.SYS
0x86302000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x86327000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x86366000 \SystemRoot\System32\Drivers\spldr.sys
0x8636E000 \SystemRoot\System32\drivers\rdyboost.sys
0x8639B000 \SystemRoot\System32\Drivers\mup.sys
0x863AB000 \SystemRoot\System32\drivers\hwpolicy.sys
0x863B3000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x863E5000 \SystemRoot\system32\DRIVERS\EMSC.SYS
0x863ED000 \SystemRoot\system32\DRIVERS\disk.sys
0x85DD6000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x89616000 \SystemRoot\system32\DRIVERS\klif.sys
0x89664000 \SystemRoot\System32\Drivers\Null.SYS
0x8966B000 \SystemRoot\System32\Drivers\Beep.SYS
0x89672000 \SystemRoot\System32\drivers\vga.sys
0x8967E000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8969F000 \SystemRoot\System32\drivers\watchdog.sys
0x896AC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x896B4000 \SystemRoot\system32\drivers\rdpencdd.sys
0x896BC000 \SystemRoot\system32\drivers\rdprefmp.sys
0x896C4000 \SystemRoot\System32\Drivers\Msfs.SYS
0x896CF000 \SystemRoot\System32\Drivers\Npfs.SYS
0x89C0B000 \SystemRoot\System32\drivers\tcpip.sys
0x89D54000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x89D85000 \SystemRoot\system32\DRIVERS\tdx.sys
0x89D9C000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x89E04000 \SystemRoot\system32\DRIVERS\kl1.sys
0x8A324000 \SystemRoot\system32\drivers\afd.sys
0x8A37E000 \SystemRoot\System32\DRIVERS\netbt.sys
0x896DD000 \SystemRoot\system32\DRIVERS\vsdatant.sys
0x8A3B0000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8A3B7000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8A3D6000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x8A3E7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x89DA7000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x89DBA000 \SystemRoot\system32\DRIVERS\termdd.sys
0x89767000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x89DCA000 \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys
0x8A3F5000 \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys
0x89DF3000 \SystemRoot\system32\drivers\nsiproxy.sys
0x89C00000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x897A8000 \SystemRoot\System32\drivers\discache.sys
0x897B4000 \SystemRoot\System32\Drivers\dfsc.sys
0x897CC000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x897DA000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8AA26000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8AF2E000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8B23F000 \SystemRoot\System32\drivers\dxgmms1.sys
0x8B278000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8B297000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x8EC0F000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x8EE76000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x8EE80000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8EE8B000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8EED6000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8EEE5000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8EEE9000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EF01000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EF0E000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8EF48000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8EF4A000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EF57000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x8EF64000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x8EF76000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EF8E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8EF99000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8EFBB000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8EFD3000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8B2C9000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8EFEA000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8B2E0000 \SystemRoot\system32\DRIVERS\ks.sys
0x8EFEC000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8B314000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8B358000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8B369000 \SystemRoot\system32\drivers\HdAudio.sys
0x8B3B9000 \SystemRoot\system32\drivers\portcls.sys
0x8B200000 \SystemRoot\system32\drivers\drmk.sys
0x8EC00000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8B219000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8B224000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x8B22E000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x8D6F0000 \SystemRoot\System32\win32k.sys
0x8B3E8000 \SystemRoot\System32\drivers\Dxapi.sys
0x8AFE5000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8AA00000 \SystemRoot\System32\Drivers\usbvideo.sys
0x8C231000 \SystemRoot\system32\DRIVERS\CtClsFlt.sys
0x8C255000 \SystemRoot\system32\DRIVERS\monitor.sys
0x8D950000 \SystemRoot\System32\TSDDD.dll
0x8D980000 \SystemRoot\System32\cdd.dll
0x8C260000 \SystemRoot\system32\drivers\luafv.sys
0x8C27B000 \SystemRoot\system32\drivers\WudfPf.sys
0x8C295000 \SystemRoot\system32\DRIVERS\RMCAST.sys
0x8C2C6000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x8C2D6000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x8C31C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x8C32C000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x8C33F000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x8C348000 \SystemRoot\system32\drivers\HTTP.sys
0x8C3CD000 \SystemRoot\system32\DRIVERS\bowser.sys
0x8C3E6000 \SystemRoot\System32\drivers\mpsdrv.sys
0x8C200000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA8E2F000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xA8E6A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xA8E9D000 \SystemRoot\system32\drivers\peauth.sys
0xA8F34000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA8F3E000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xA8F5F000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA8F6C000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA923D000 \SystemRoot\System32\DRIVERS\srv.sys
0xA928E000 \SystemRoot\system32\drivers\BCM42RLY.sys
0xA9296000 \SystemRoot\System32\Drivers\fastfat.SYS
0xA932A000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xA9333000 \??\C:\Users\HENRYC~1\AppData\Local\Temp\mbr.sys
0x77D70000 \Windows\System32\ntdll.dll
0x47E90000 \Windows\System32\smss.exe
0x77FB0000 \Windows\System32\apisetschema.dll
0x00BB0000 \Windows\System32\autochk.exe
0x77C70000 \Windows\System32\wininet.dll
0x77F10000 \Windows\System32\oleaut32.dll
0x77B90000 \Windows\System32\kernel32.dll
0x77AE0000 \Windows\System32\msvcrt.dll
0x77F00000 \Windows\System32\normaliz.dll
0x77EF0000 \Windows\System32\psapi.dll
0x77A40000 \Windows\System32\usp10.dll
0x778A0000 \Windows\System32\setupapi.dll
0x776A0000 \Windows\System32\iertutil.dll
0x77EE0000 \Windows\System32\lpk.dll
0x77640000 \Windows\System32\shlwapi.dll
0x77570000 \Windows\System32\user32.dll
0x77510000 \Windows\System32\difxapi.dll
0x774C0000 \Windows\System32\Wldap32.dll
0x77440000 \Windows\System32\comdlg32.dll
0x772E0000 \Windows\System32\ole32.dll
0x77240000 \Windows\System32\advapi32.dll
0x77100000 \Windows\System32\urlmon.dll
0x77EC0000 \Windows\System32\sechost.dll
0x770D0000 \Windows\System32\imagehlp.dll
0x77020000 \Windows\System32\rpcrt4.dll
0x77000000 \Windows\System32\imm32.dll
0x77EB0000 \Windows\System32\nsi.dll
0x763B0000 \Windows\System32\shell32.dll
0x76360000 \Windows\System32\gdi32.dll
0x762D0000 \Windows\System32\clbcatq.dll
0x76200000 \Windows\System32\msctf.dll
0x761C0000 \Windows\System32\ws2_32.dll
0x76190000 \Windows\System32\cfgmgr32.dll
0x76100000 \Windows\System32\comctl32.dll
0x75FE0000 \Windows\System32\crypt32.dll
0x75FB0000 \Windows\System32\wintrust.dll
0x75F90000 \Windows\System32\devobj.dll
0x75F40000 \Windows\System32\KernelBase.dll
0x75F30000 \Windows\System32\msasn1.dll
Processes (total 53):
0 System Idle Process
4 System
272 C:\Windows\System32\smss.exe
364 csrss.exe
420 C:\Windows\System32\wininit.exe
428 csrss.exe
476 C:\Windows\System32\winlogon.exe
504 C:\Windows\System32\services.exe
512 C:\Windows\System32\lsass.exe
520 C:\Windows\System32\lsm.exe
656 C:\Windows\System32\svchost.exe
732 C:\Windows\System32\svchost.exe
784 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
912 C:\Windows\System32\svchost.exe
944 C:\Windows\System32\svchost.exe
988 C:\Windows\System32\svchost.exe
1132 C:\Windows\System32\svchost.exe
1188 C:\Program Files\Dell\DellDock\DockLogin.exe
1276 C:\Windows\System32\svchost.exe
1476 C:\Windows\System32\wlanext.exe
1504 C:\Windows\System32\conhost.exe
1652 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
1660 C:\Windows\System32\dwm.exe
1684 C:\Windows\explorer.exe
1980 C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
2036 C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
1308 C:\Windows\System32\spoolsv.exe
1388 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1628 C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
1780 C:\Windows\System32\taskhost.exe
1260 C:\Windows\System32\svchost.exe
2228 C:\Windows\System32\svchost.exe
2300 C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
2404 C:\Program Files\QUALCOMM\QDLService2k\QDLService2kDell.exe
2532 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2608 C:\Windows\System32\svchost.exe
2716 C:\Windows\System32\svchost.exe
2772 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2808 C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe
2884 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
3192 C:\Windows\System32\SearchIndexer.exe
3312 C:\Windows\System32\svchost.exe
3752 C:\Program Files\WSED\WSED.exe
3760 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
3880 C:\Windows\System32\hkcmd.exe
3912 C:\Windows\System32\igfxpers.exe
4028 C:\Windows\System32\igfxsrvc.exe
2392 C:\Program Files\Windows Media Player\wmpnetwk.exe
3284 C:\Windows\System32\ZoneLabs\vsmon.exe
636 C:\Windows\System32\audiodg.exe
4156 C:\Users\Henry Coolidge\Desktop\MBRCheck.exe
5388 C:\Windows\System32\conhost.exe
5028 C:\Windows\System32\dllhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000003`ac000000 (NTFS)
PhysicalDrive0 Model Number: TOSHIBAMK1655GSX, Rev: FG010D
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
Done!
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
December 20th, 2010 00:00
Proceed as follows please :-
Step 1
Please read carefully and follow these steps.
Step 2
Run ESET Online Scan
You can refer to this animation by neomage if needed.
Frequently asked questions available Here Please read them before running the scan.
Also be aware this scan can take several hours to complete depending on the size of your
system.
Post the logs from TDSSKiller and ESET in your reply please,
Kevin
Hytec
45 Posts
0
December 20th, 2010 06:00
2010/12/20 08:27:48.0357 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
2010/12/20 08:27:48.0357 ================================================================================
2010/12/20 08:27:48.0357 SystemInfo:
2010/12/20 08:27:48.0357
2010/12/20 08:27:48.0357 OS Version: 6.1.7600 ServicePack: 0.0
2010/12/20 08:27:48.0357 Product type: Workstation
2010/12/20 08:27:48.0357 ComputerName: INSPIRONMINI
2010/12/20 08:27:48.0357 UserName: Henry Coolidge
2010/12/20 08:27:48.0357 Windows directory: C:\Windows
2010/12/20 08:27:48.0357 System windows directory: C:\Windows
2010/12/20 08:27:48.0357 Processor architecture: Intel x86
2010/12/20 08:27:48.0357 Number of processors: 2
2010/12/20 08:27:48.0357 Page size: 0x1000
2010/12/20 08:27:48.0357 Boot type: Normal boot
2010/12/20 08:27:48.0357 ================================================================================
2010/12/20 08:27:51.0071 Initialize success
2010/12/20 08:28:03.0739 ================================================================================
2010/12/20 08:28:03.0739 Scan started
2010/12/20 08:28:03.0739 Mode: Manual;
2010/12/20 08:28:03.0739 ================================================================================
2010/12/20 08:28:05.0689 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2010/12/20 08:28:06.0063 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2010/12/20 08:28:06.0313 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2010/12/20 08:28:06.0703 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2010/12/20 08:28:07.0061 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2010/12/20 08:28:07.0327 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2010/12/20 08:28:07.0763 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2010/12/20 08:28:08.0060 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2010/12/20 08:28:08.0419 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2010/12/20 08:28:08.0777 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2010/12/20 08:28:09.0089 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2010/12/20 08:28:09.0511 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2010/12/20 08:28:09.0698 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2010/12/20 08:28:09.0901 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2010/12/20 08:28:10.0135 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2010/12/20 08:28:10.0478 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2010/12/20 08:28:10.0743 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2010/12/20 08:28:10.0930 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2010/12/20 08:28:11.0133 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2010/12/20 08:28:11.0336 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2010/12/20 08:28:11.0601 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/12/20 08:28:11.0897 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2010/12/20 08:28:12.0256 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2010/12/20 08:28:12.0475 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2010/12/20 08:28:12.0693 BCM42RLY (eb4434444e2721d721a8ac8d5d2ad26b) C:\Windows\system32\drivers\BCM42RLY.sys
2010/12/20 08:28:12.0958 BCM43XX (5245ebbe39ed9010240c20d21f5a26a9) C:\Windows\system32\DRIVERS\bcmwl6.sys
2010/12/20 08:28:13.0317 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2010/12/20 08:28:13.0645 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2010/12/20 08:28:13.0832 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
2010/12/20 08:28:14.0035 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2010/12/20 08:28:14.0237 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2010/12/20 08:28:14.0581 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2010/12/20 08:28:14.0924 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2010/12/20 08:28:15.0189 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2010/12/20 08:28:15.0423 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2010/12/20 08:28:15.0657 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2010/12/20 08:28:15.0969 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2010/12/20 08:28:16.0219 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2010/12/20 08:28:16.0484 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2010/12/20 08:28:16.0655 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2010/12/20 08:28:17.0030 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/12/20 08:28:17.0279 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2010/12/20 08:28:17.0966 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2010/12/20 08:28:18.0340 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2010/12/20 08:28:18.0621 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2010/12/20 08:28:19.0042 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2010/12/20 08:28:19.0417 CtClsFlt (b27d15c551a6678137c6b751b160756d) C:\Windows\system32\DRIVERS\CtClsFlt.sys
2010/12/20 08:28:19.0682 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
2010/12/20 08:28:20.0009 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2010/12/20 08:28:20.0275 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2010/12/20 08:28:20.0602 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2010/12/20 08:28:20.0789 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
2010/12/20 08:28:21.0226 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2010/12/20 08:28:21.0757 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2010/12/20 08:28:21.0991 EMSC (cf460f454a0473e6c7ad846b94d8382a) C:\Windows\system32\DRIVERS\EMSC.SYS
2010/12/20 08:28:22.0256 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2010/12/20 08:28:22.0599 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2010/12/20 08:28:22.0880 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2010/12/20 08:28:23.0114 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2010/12/20 08:28:23.0441 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2010/12/20 08:28:23.0738 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2010/12/20 08:28:24.0112 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/12/20 08:28:24.0346 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2010/12/20 08:28:24.0549 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2010/12/20 08:28:24.0783 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2010/12/20 08:28:25.0064 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2010/12/20 08:28:25.0438 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2010/12/20 08:28:25.0844 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2010/12/20 08:28:26.0078 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2010/12/20 08:28:26.0296 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/12/20 08:28:26.0639 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2010/12/20 08:28:26.0811 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2010/12/20 08:28:26.0983 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2010/12/20 08:28:27.0248 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2010/12/20 08:28:27.0591 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2010/12/20 08:28:27.0841 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2010/12/20 08:28:28.0028 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2010/12/20 08:28:28.0293 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/12/20 08:28:28.0527 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2010/12/20 08:28:29.0089 igfx (ba41e1bba410212ce6d30e0dac47972b) C:\Windows\system32\DRIVERS\igdkmd32.sys
2010/12/20 08:28:29.0541 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2010/12/20 08:28:30.0025 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2010/12/20 08:28:30.0274 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2010/12/20 08:28:30.0508 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/12/20 08:28:30.0680 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2010/12/20 08:28:30.0836 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2010/12/20 08:28:31.0023 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2010/12/20 08:28:31.0257 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2010/12/20 08:28:31.0819 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/12/20 08:28:32.0006 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/12/20 08:28:32.0193 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/12/20 08:28:32.0427 kl1 (7dd41b7ac1fbb1dbf20bb1f4e4fbe58c) C:\Windows\system32\DRIVERS\kl1.sys
2010/12/20 08:28:32.0708 KLIF (7dde660590c459aae9caa3b84ff6549f) C:\Windows\system32\DRIVERS\klif.sys
2010/12/20 08:28:33.0004 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2010/12/20 08:28:33.0285 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2010/12/20 08:28:33.0628 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/12/20 08:28:33.0940 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2010/12/20 08:28:34.0205 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2010/12/20 08:28:34.0424 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2010/12/20 08:28:34.0642 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2010/12/20 08:28:34.0892 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2010/12/20 08:28:35.0110 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2010/12/20 08:28:35.0375 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2010/12/20 08:28:35.0687 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2010/12/20 08:28:35.0890 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2010/12/20 08:28:36.0062 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2010/12/20 08:28:36.0296 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2010/12/20 08:28:36.0483 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2010/12/20 08:28:36.0686 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2010/12/20 08:28:36.0904 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2010/12/20 08:28:37.0154 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2010/12/20 08:28:37.0497 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/12/20 08:28:37.0715 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/12/20 08:28:37.0934 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/12/20 08:28:38.0090 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2010/12/20 08:28:38.0293 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2010/12/20 08:28:38.0620 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2010/12/20 08:28:38.0854 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2010/12/20 08:28:39.0026 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2010/12/20 08:28:39.0275 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2010/12/20 08:28:39.0572 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/12/20 08:28:39.0790 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2010/12/20 08:28:39.0977 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2010/12/20 08:28:40.0258 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/12/20 08:28:40.0430 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2010/12/20 08:28:40.0633 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2010/12/20 08:28:40.0820 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2010/12/20 08:28:41.0069 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2010/12/20 08:28:41.0366 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2010/12/20 08:28:41.0693 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2010/12/20 08:28:41.0896 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/12/20 08:28:42.0099 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/12/20 08:28:42.0271 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/12/20 08:28:42.0442 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2010/12/20 08:28:42.0817 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2010/12/20 08:28:42.0988 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2010/12/20 08:28:43.0347 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2010/12/20 08:28:43.0659 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2010/12/20 08:28:43.0846 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2010/12/20 08:28:44.0143 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2010/12/20 08:28:44.0314 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2010/12/20 08:28:44.0533 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2010/12/20 08:28:44.0798 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2010/12/20 08:28:45.0079 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2010/12/20 08:28:45.0266 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/12/20 08:28:45.0640 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2010/12/20 08:28:45.0859 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2010/12/20 08:28:46.0061 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2010/12/20 08:28:46.0264 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2010/12/20 08:28:46.0561 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2010/12/20 08:28:46.0857 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/12/20 08:28:47.0044 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2010/12/20 08:28:47.0247 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2010/12/20 08:28:47.0840 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2010/12/20 08:28:48.0121 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2010/12/20 08:28:48.0370 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2010/12/20 08:28:48.0667 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2010/12/20 08:28:48.0885 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2010/12/20 08:28:49.0150 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2010/12/20 08:28:49.0540 RapportCerberus_19917 (539fbdcff37a24102c507092b333ec2b) C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys
2010/12/20 08:28:49.0868 RapportPG (c9b8a131aaf77d969cbc3987537b319d) C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys
2010/12/20 08:28:50.0008 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2010/12/20 08:28:50.0195 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2010/12/20 08:28:50.0398 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/12/20 08:28:50.0617 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/12/20 08:28:50.0882 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2010/12/20 08:28:51.0053 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2010/12/20 08:28:51.0350 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2010/12/20 08:28:51.0537 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/12/20 08:28:51.0724 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2010/12/20 08:28:52.0036 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2010/12/20 08:28:52.0255 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2010/12/20 08:28:52.0489 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2010/12/20 08:28:52.0754 RMCAST (b4090006a82eeb608c358ab5d37de85a) C:\Windows\system32\DRIVERS\RMCAST.sys
2010/12/20 08:28:53.0066 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2010/12/20 08:28:53.0269 RSUSBSTOR (83f7a29b659771e60cd71999ef57aa0c) C:\Windows\system32\Drivers\RtsUStor.sys
2010/12/20 08:28:53.0503 RTL8167 (05c2613f661584190c752f6184d1c8ef) C:\Windows\system32\DRIVERS\Rt86win7.sys
2010/12/20 08:28:53.0737 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2010/12/20 08:28:53.0939 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2010/12/20 08:28:54.0220 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/12/20 08:28:54.0563 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2010/12/20 08:28:54.0751 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2010/12/20 08:28:54.0969 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2010/12/20 08:28:55.0375 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/12/20 08:28:55.0515 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2010/12/20 08:28:55.0811 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/12/20 08:28:56.0077 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2010/12/20 08:28:56.0342 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2010/12/20 08:28:56.0529 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2010/12/20 08:28:56.0701 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2010/12/20 08:28:56.0872 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2010/12/20 08:28:57.0215 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2010/12/20 08:28:57.0605 srv (2dbedfb1853f06110ec2aa7f3213c89f) C:\Windows\system32\DRIVERS\srv.sys
2010/12/20 08:28:57.0839 srv2 (db37131d1027c50ea7ee21c8bb4536aa) C:\Windows\system32\DRIVERS\srv2.sys
2010/12/20 08:28:58.0042 srvnet (f5980b74124db9233b33f86fc5ebbb4f) C:\Windows\system32\DRIVERS\srvnet.sys
2010/12/20 08:28:58.0261 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2010/12/20 08:28:58.0448 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2010/12/20 08:28:58.0713 SynTP (5cdd124913e91c7f79b4d5cae1c7c4de) C:\Windows\system32\DRIVERS\SynTP.sys
2010/12/20 08:28:59.0150 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2010/12/20 08:28:59.0431 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2010/12/20 08:28:59.0633 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2010/12/20 08:28:59.0836 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2010/12/20 08:29:00.0023 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2010/12/20 08:29:00.0242 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2010/12/20 08:29:00.0429 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2010/12/20 08:29:00.0803 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/12/20 08:29:00.0991 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2010/12/20 08:29:01.0178 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2010/12/20 08:29:01.0396 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2010/12/20 08:29:01.0786 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2010/12/20 08:29:02.0005 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2010/12/20 08:29:02.0239 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2010/12/20 08:29:02.0488 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/12/20 08:29:02.0831 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2010/12/20 08:29:03.0159 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2010/12/20 08:29:03.0471 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
2010/12/20 08:29:03.0674 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2010/12/20 08:29:03.0908 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2010/12/20 08:29:04.0064 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2010/12/20 08:29:04.0282 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/12/20 08:29:04.0594 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/12/20 08:29:04.0781 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\Windows\System32\Drivers\usbvideo.sys
2010/12/20 08:29:05.0000 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2010/12/20 08:29:05.0187 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/12/20 08:29:05.0421 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2010/12/20 08:29:05.0702 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2010/12/20 08:29:05.0983 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2010/12/20 08:29:06.0217 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2010/12/20 08:29:06.0419 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2010/12/20 08:29:06.0622 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2010/12/20 08:29:06.0778 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2010/12/20 08:29:06.0950 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2010/12/20 08:29:07.0184 Vsdatant (e7aba26a028a78c1aa759bb794f6e9ee) C:\Windows\system32\DRIVERS\vsdatant.sys
2010/12/20 08:29:07.0543 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2010/12/20 08:29:07.0823 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
2010/12/20 08:29:08.0057 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
TDSSKiller Log follows......
2010/12/20 08:29:08.0245 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys
2010/12/20 08:29:08.0510 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2010/12/20 08:29:08.0759 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/12/20 08:29:08.0884 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/12/20 08:29:09.0181 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2010/12/20 08:29:09.0446 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2010/12/20 08:29:09.0914 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2010/12/20 08:29:10.0132 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2010/12/20 08:29:10.0585 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2010/12/20 08:29:10.0881 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/12/20 08:29:11.0333 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/12/20 08:29:11.0645 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2010/12/20 08:29:11.0833 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/12/20 08:29:12.0129 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2010/12/20 08:29:12.0160 ================================================================================
2010/12/20 08:29:12.0160 Scan finished
2010/12/20 08:29:12.0160 ================================================================================
2010/12/20 08:29:12.0223 Detected object count: 1
2010/12/20 08:29:28.0665 \HardDisk0 - will be cured after reboot
2010/12/20 08:29:28.0727 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2010/12/20 08:29:35.0748 Deinitialize success
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
December 20th, 2010 06:00
looks promising, you got the ESET log?
Hytec
45 Posts
0
December 20th, 2010 07:00
ESET running now, 66%.
As instructed...Patience, Patience. :emotion-2:
Hank
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
December 20th, 2010 12:00
Hiya Hank,
Yep, like your humor my friend.
ESET has flagged your Java cache as exploited, also your version of Java is showing as outdated. I`m confident that is how you became infected, very common yet easily avoided by keeping Java up to date. If the re-directs have stopped continue as follows, if not let me know :-
Step 1
Step 2
To remove the ESET Online Scanner components from your computer, start the Uninstall a Program applet from Control Panel, select the ESET Online Scanner entry and click Uninstall. Only re-bootif requested.
Step 3
We need the Java cahe emptied, full instructions available Here if required. The instructions tell you to navigate to Start > Control Panel > Java. For Windows 7 or Vista it may be Start > Control Panel > Programs > Java.
Step 4
You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version.
For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system.
The most current version of Sun Java is: Java Runtime Environment Version 6 Update 23.
Step 5
Your Adobe Acrobat Reader is out of date. Older versions are vulnerable to attack and exploitation.
Please go to the link below to update, the new version removes the old one.
Adobe Reader Untick the Free McAfee® Security Scan Plus (optional) unless you want it.
Step 6
Download and scan with CCleaner
1. Use either one of the two free links below the Premium version.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 24 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
In the Applications Tab:
4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.
Step 7
Create a new restore point:
1. Right-click on Computer and go to Properties.
2. Next click on the System Protection link.
3. The System Properties dialog screen opens up and you will want to click on Create.
4. Type in a description for the restore point which will help you remember the point at which is was created. Click on create.
5. You should see the message "The restore point was created successfully
To remove all but the most recent restore point do the following:
1. Open Disk Cleanup by clicking the Start button
2. If prompted, select the drive that you want to clean up, and then click OK.
3. In the Disk Cleanup for (drive letter) dialog box, click Clean up system files. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
4. If prompted, select the drive that you want to clean up, and then click OK.
5. Click the More Options tab, under System Restore and Shadow Copies, click Clean up.
6. In the Disk Cleanup dialog box, click Delete.
7. Click Delete Files, and then click OK.
Let me know if the above steps completed, also any remaining issues...
Kevin..
Hytec
45 Posts
0
December 20th, 2010 12:00
Your patience is rewarded, the ESET Log follows.....
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\575d3075-2110e856 multiple threats
I await further orders, err...assistance.
Hank
Hytec
45 Posts
0
December 20th, 2010 14:00
Kevin, everything appears to be operating normally now.
I certainly appreciate your help, thank you.
It also is interesting that Microsoft Update is now operating correctly. Update installations had been blocked since 12/5, apparently when the system became infected.
Thank you again, and thank you also to BugBatter for coordinating this forum.
Hank
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
December 20th, 2010 14:00
Good to hear all is back to normal. Here are some tips to reduce the potential for malware infection in the future:
Make proper use of your antivirus and firewall
Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.
You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.
Install and use WinPatrol This will inform you of any attempted unauthorized changes to your system.
WinPatrol features explained Here
You will have several programs installed, these maybe outdated and vulnerable to exploits also. To be certain, please run the free online scan by Secunia, available Here Before clicking the Start scan button, please check the box for the option Enable thorough system inspection. Just below the "Scan Options:" section, you'll see the status of what's currently processing....
...when the scan completes, the message "Detection completed successfully" will appear in the Programs/Result section. For each problem detected, Secunia will offer a "Solution" option. Please follow those instructions to download updated versions of the programs as recommended by Secunia.
Use a safer web browser
Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
Firefox,
Opera, and
Chrome.
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.
These browser add-ons will help to make your browser safer:
Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:
Available for Firefox and Internet Explorer.
Green to go,
Yellow for caution, and
Red to stop.
Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.
These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.
Here a couple of links by two security experts that will give some excellent tips and advice.
So how did I get infected in the first place by Tony Klein
How to prevent Malware by Miekiemoes
Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.
Let me know if you have any remaining issues or questions. Don`t forget, the best form of defense is common sense. If you don`t recognize it, don`t open it. If something looks to good to be true, then it aint.
It was a pleasure to work with you take care,
Kevin