We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
PC problem
Comments
-
07:38:05.0046 3564 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
07:38:05.0046 3564 NDIS - ok
07:38:05.0078 3564 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
07:38:05.0078 3564 NdisIP - ok
07:38:05.0125 3564 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
07:38:05.0125 3564 NdisTapi - ok
07:38:05.0156 3564 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
07:38:05.0156 3564 Ndisuio - ok
07:38:05.0171 3564 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
07:38:05.0171 3564 NdisWan - ok
07:38:05.0218 3564 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
07:38:05.0218 3564 NDProxy - ok
07:38:05.0343 3564 [ A081CB6FB9A12668F233EB5414BE3A0E ] Net Driver HPZ12 C:\WINDOWS\system32\HPZinw12.dll
07:38:05.0343 3564 Net Driver HPZ12 - ok
07:38:05.0390 3564 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
07:38:05.0390 3564 NetBIOS - ok
07:38:05.0421 3564 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
07:38:05.0421 3564 NetBT - ok
07:38:05.0453 3564 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
07:38:05.0453 3564 NetDDE - ok
07:38:05.0468 3564 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
07:38:05.0468 3564 NetDDEdsdm - ok
07:38:05.0515 3564 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
07:38:05.0515 3564 Netlogon - ok
07:38:05.0562 3564 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
07:38:05.0562 3564 Netman - ok
07:38:05.0625 3564 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
07:38:05.0625 3564 NetTcpPortSharing - ok
07:38:05.0671 3564 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
07:38:05.0671 3564 NIC1394 - ok
07:38:05.0734 3564 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
07:38:05.0734 3564 Nla - ok
07:38:05.0781 3564 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
07:38:05.0781 3564 Npfs - ok
07:38:05.0812 3564 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
07:38:05.0828 3564 Ntfs - ok
07:38:05.0859 3564 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
07:38:05.0859 3564 NtLmSsp - ok
07:38:05.0906 3564 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
07:38:05.0921 3564 NtmsSvc - ok
07:38:05.0953 3564 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
07:38:05.0953 3564 Null - ok
07:38:06.0125 3564 [ 2282AD3B19B00967C6E48531C25BFE01 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
07:38:06.0156 3564 nv - ok
07:38:06.0203 3564 [ BE4A98439A5E26CBC70DB20E996938DC ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
07:38:06.0218 3564 NVSvc - ok
07:38:06.0250 3564 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
07:38:06.0250 3564 NwlnkFlt - ok
07:38:06.0281 3564 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
07:38:06.0281 3564 NwlnkFwd - ok
07:38:06.0312 3564 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
07:38:06.0312 3564 ohci1394 - ok
07:38:06.0359 3564 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
07:38:06.0359 3564 ose - ok
07:38:06.0578 3564 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
07:38:06.0718 3564 osppsvc - ok
07:38:06.0781 3564 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
07:38:06.0781 3564 Parport - ok
07:38:06.0828 3564 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
07:38:06.0828 3564 PartMgr - ok
07:38:06.0875 3564 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
07:38:06.0875 3564 ParVdm - ok
07:38:06.0921 3564 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
07:38:06.0921 3564 PCI - ok
07:38:06.0937 3564 PCIDump - ok
07:38:06.0968 3564 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
07:38:06.0968 3564 PCIIde - ok
07:38:07.0000 3564 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
07:38:07.0000 3564 Pcmcia - ok
07:38:07.0015 3564 PDCOMP - ok
07:38:07.0031 3564 PDFRAME - ok
07:38:07.0046 3564 PDRELI - ok
07:38:07.0062 3564 PDRFRAME - ok
07:38:07.0078 3564 perc2 - ok
07:38:07.0093 3564 perc2hib - ok
07:38:07.0156 3564 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
07:38:07.0156 3564 PlugPlay - ok
07:38:07.0234 3564 [ 65BC271F337637731D3C71455AE1F476 ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.dll
07:38:07.0250 3564 Pml Driver HPZ12 - ok
07:38:07.0281 3564 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
07:38:07.0281 3564 PolicyAgent - ok
07:38:07.0312 3564 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
07:38:07.0312 3564 PptpMiniport - ok
07:38:07.0328 3564 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
07:38:07.0343 3564 ProtectedStorage - ok
07:38:07.0343 3564 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
07:38:07.0343 3564 PSched - ok
07:38:07.0375 3564 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
07:38:07.0375 3564 Ptilink - ok
07:38:07.0390 3564 ql1080 - ok
07:38:07.0390 3564 Ql10wnt - ok
07:38:07.0406 3564 ql12160 - ok
07:38:07.0421 3564 ql1240 - ok
07:38:07.0437 3564 ql1280 - ok
07:38:07.0468 3564 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
07:38:07.0468 3564 RasAcd - ok
07:38:07.0531 3564 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
07:38:07.0531 3564 RasAuto - ok
07:38:07.0578 3564 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
07:38:07.0578 3564 Rasl2tp - ok
07:38:07.0656 3564 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
07:38:07.0656 3564 RasMan - ok
07:38:07.0703 3564 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
07:38:07.0703 3564 RasPppoe - ok
07:38:07.0734 3564 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
07:38:07.0734 3564 Raspti - ok
07:38:07.0765 3564 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
07:38:07.0765 3564 Rdbss - ok
07:38:07.0812 3564 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
07:38:07.0812 3564 RDPCDD - ok
07:38:07.0859 3564 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
07:38:07.0859 3564 rdpdr - ok
07:38:07.0906 3564 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
07:38:07.0906 3564 RDPWD - ok
07:38:07.0953 3564 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
07:38:07.0953 3564 RDSessMgr - ok
07:38:08.0000 3564 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
07:38:08.0000 3564 redbook - ok
07:38:08.0046 3564 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
07:38:08.0046 3564 RemoteAccess - ok
07:38:08.0109 3564 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
07:38:08.0109 3564 RemoteRegistry - ok
07:38:08.0156 3564 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
07:38:08.0156 3564 RpcLocator - ok
07:38:08.0234 3564 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll
07:38:08.0234 3564 RpcSs - ok
07:38:08.0281 3564 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
07:38:08.0281 3564 RSVP - ok
07:38:08.0343 3564 [ 815445F4676CC96BC9AEEC303C727E19 ] s116bus C:\WINDOWS\system32\DRIVERS\s116bus.sys
07:38:08.0343 3564 s116bus - ok
07:38:08.0375 3564 [ 333D1E0743E6DE1779C3C418AC601C3A ] s116mdfl C:\WINDOWS\system32\DRIVERS\s116mdfl.sys
07:38:08.0375 3564 s116mdfl - ok
07:38:08.0406 3564 [ 50D6E5B021E9EC7553AB8A3553CC1B6B ] s116mdm C:\WINDOWS\system32\DRIVERS\s116mdm.sys
07:38:08.0406 3564 s116mdm - ok
07:38:08.0453 3564 [ 1589AA53E43F8D193A7D4D580D3FFA95 ] s116mgmt C:\WINDOWS\system32\DRIVERS\s116mgmt.sys
07:38:08.0453 3564 s116mgmt - ok
07:38:08.0484 3564 [ EC32601F04A5A5DE89315D0F55E73D66 ] s116obex C:\WINDOWS\system32\DRIVERS\s116obex.sys
07:38:08.0484 3564 s116obex - ok
07:38:08.0531 3564 [ 32E3ECB4B2B5887426EAF241A8149CDE ] s116unic C:\WINDOWS\system32\DRIVERS\s116unic.sys
07:38:08.0531 3564 s116unic - ok
07:38:08.0562 3564 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
07:38:08.0562 3564 SamSs - ok
07:38:08.0593 3564 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
07:38:08.0609 3564 SCardSvr - ok
07:38:08.0656 3564 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
07:38:08.0671 3564 Schedule - ok
07:38:08.0718 3564 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
07:38:08.0718 3564 Secdrv - ok
07:38:08.0765 3564 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
07:38:08.0765 3564 seclogon - ok
07:38:08.0796 3564 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
07:38:08.0796 3564 SENS - ok
07:38:08.0859 3564 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] Serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
07:38:08.0859 3564 Serenum - ok
07:38:08.0890 3564 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
07:38:08.0890 3564 Serial - ok
07:38:08.0953 3564 [ 019AB047B932AD277A4DA2673E5CC19C ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
07:38:08.0953 3564 ServiceLayer - ok
07:38:09.0015 3564 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
07:38:09.0015 3564 Sfloppy - ok
07:38:09.0062 3564 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
07:38:09.0078 3564 SharedAccess - ok
07:38:09.0125 3564 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
07:38:09.0125 3564 ShellHWDetection - ok
07:38:09.0140 3564 Simbad - ok
07:38:09.0187 3564 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
07:38:09.0187 3564 SLIP - ok
07:38:09.0218 3564 Sparrow - ok
07:38:09.0265 3564 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
07:38:09.0265 3564 splitter - ok
07:38:09.0328 3564 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
07:38:09.0328 3564 Spooler - ok
07:38:09.0359 3564 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
07:38:09.0359 3564 sr - ok
07:38:09.0406 3564 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
07:38:09.0421 3564 srservice - ok
07:38:09.0484 3564 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
07:38:09.0484 3564 Srv - ok
07:38:09.0531 3564 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
07:38:09.0546 3564 SSDPSRV - ok
07:38:09.0625 3564 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
07:38:09.0640 3564 stisvc - ok
07:38:09.0687 3564 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
07:38:09.0687 3564 streamip - ok
07:38:09.0734 3564 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
07:38:09.0734 3564 swenum - ok
07:38:09.0765 3564 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
07:38:09.0765 3564 swmidi - ok
07:38:09.0796 3564 SwPrv - ok
07:38:09.0843 3564 symc810 - ok
07:38:09.0859 3564 symc8xx - ok
07:38:09.0875 3564 sym_hi - ok
07:38:09.0890 3564 sym_u3 - ok
07:38:09.0937 3564 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
07:38:09.0937 3564 sysaudio - ok
07:38:09.0937 3564 Suspicious service (NoAccess): syshost32
07:38:10.0031 3564 [ 4EB27021D2C108C352B0AA7FAE44E0FA ] syshost32 C:\WINDOWS\Installer\{DF5D9716-6B4E-BFB2-601C-01B43FCA134E}\syshost.exe
07:38:10.0046 3564 Suspicious file (NoAccess): C:\WINDOWS\Installer\{DF5D9716-6B4E-BFB2-601C-01B43FCA134E}\syshost.exe. md5: 4EB27021D2C108C352B0AA7FAE44E0FA
07:38:10.0140 3564 syshost32 ( Rootkit.Win32.Necurs.gen ) - infected
07:38:10.0140 3564 syshost32 - detected Rootkit.Win32.Necurs.gen (0)
07:38:10.0187 3564 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
07:38:10.0187 3564 SysmonLog - ok
07:38:10.0265 3564 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
07:38:10.0265 3564 TapiSrv - ok
07:38:10.0328 3564 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
07:38:10.0328 3564 Tcpip - ok
07:38:10.0359 3564 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
07:38:10.0359 3564 TDPIPE - ok
07:38:10.0390 3564 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
07:38:10.0390 3564 TDTCP - ok
07:38:10.0406 3564 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
07:38:10.0406 3564 TermDD - ok
07:38:10.0484 3564 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
07:38:10.0500 3564 TermService - ok
07:38:10.0562 3564 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
07:38:10.0562 3564 Themes - ok
07:38:10.0625 3564 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
07:38:10.0625 3564 TlntSvr - ok
07:38:10.0640 3564 TosIde - ok
07:38:10.0703 3564 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
07:38:10.0703 3564 TrkWks - ok
07:38:10.0750 3564 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
07:38:10.0750 3564 Udfs - ok
07:38:10.0765 3564 ultra - ok
07:38:10.0812 3564 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
07:38:10.0812 3564 Update - ok
07:38:10.0859 3564 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
07:38:10.0859 3564 upnphost - ok
07:38:10.0906 3564 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
07:38:10.0921 3564 UPS - ok
07:38:10.0984 3564 [ 66276112DC7089D2D9E58C7CBF0855C1 ] usb2vcom C:\WINDOWS\system32\Drivers\usb2vcom.sys
07:38:10.0984 3564 usb2vcom - ok
07:38:11.0093 3564 [ 5C2BDC152BBAB34F36473DEAF7713F22 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys
07:38:11.0093 3564 USBAAPL - ok
07:38:11.0187 3564 [ 9419FAAC6552A51542DBBA02971C841C ] usbbus C:\WINDOWS\system32\DRIVERS\lgusbbus.sys
07:38:11.0187 3564 usbbus - ok
07:38:11.0234 3564 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
07:38:11.0234 3564 usbccgp - ok
07:38:11.0281 3564 [ C0A466FA4FFEC464320E159BC1BBDC0C ] UsbDiag C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys
07:38:11.0281 3564 UsbDiag - ok
07:38:11.0312 3564 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
07:38:11.0328 3564 usbehci - ok
07:38:11.0359 3564 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
07:38:11.0359 3564 usbhub - ok
07:38:11.0406 3564 [ F74A54774A9B0AFEB3C40ADEC68AA600 ] USBModem C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys
07:38:11.0406 3564 USBModem - ok
07:38:11.0500 3564 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
07:38:11.0500 3564 usbprint - ok
07:38:11.0562 3564 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
07:38:11.0562 3564 usbscan - ok
07:38:11.0609 3564 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
07:38:11.0609 3564 USBSTOR - ok
07:38:11.0640 3564 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
07:38:11.0640 3564 usbuhci - ok
07:38:11.0671 3564 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
07:38:11.0671 3564 VgaSave - ok
07:38:11.0703 3564 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
07:38:11.0703 3564 ViaIde - ok
07:38:11.0750 3564 [ C8EE49FA76EB7C41A9CDDFE58151A74E ] videX32 C:\WINDOWS\system32\DRIVERS\videX32.sys
07:38:11.0750 3564 videX32 - ok
07:38:11.0796 3564 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
07:38:11.0796 3564 VolSnap - ok
07:38:11.0859 3564 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
07:38:11.0859 3564 VSS - ok
07:38:11.0906 3564 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
07:38:11.0906 3564 W32Time - ok
07:38:11.0937 3564 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
07:38:11.0937 3564 Wanarp - ok
07:38:11.0953 3564 WDICA - ok
07:38:11.0968 3564 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
07:38:11.0968 3564 wdmaud - ok
07:38:12.0031 3564 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
07:38:12.0031 3564 WebClient - ok
07:38:12.0125 3564 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
07:38:12.0125 3564 winmgmt - ok
07:38:12.0203 3564 [ 051B1BDECD6DEE18C771B5D5EC7F044D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
07:38:12.0218 3564 WmdmPmSN - ok
07:38:12.0281 3564 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
07:38:12.0312 3564 Wmi - ok
07:38:12.0359 3564 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
07:38:12.0359 3564 WmiApSrv - ok
07:38:12.0468 3564 [ 6BAB4DC65515A098505F8B3D01FB6FE5 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
07:38:12.0500 3564 WMPNetworkSvc - ok
07:38:12.0578 3564 [ C60DC16D4E406810FAD54B98DC92D5EC ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys
07:38:12.0578 3564 WpdUsb - ok
07:38:12.0656 3564 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
07:38:12.0671 3564 wscsvc - ok
07:38:12.0718 3564 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
07:38:12.0718 3564 WSTCODEC - ok
07:38:12.0843 3564 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
07:38:12.0859 3564 wuauserv - ok
07:38:12.0953 3564 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
07:38:12.0953 3564 WudfPf - ok
07:38:13.0000 3564 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
07:38:13.0000 3564 WudfRd - ok
07:38:13.0046 3564 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
07:38:13.0046 3564 WudfSvc - ok
07:38:13.0109 3564 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
07:38:13.0125 3564 WZCSVC - ok
07:38:13.0156 3564 [ FCBC27869092850CDB75139F3818653A ] xfilt C:\WINDOWS\system32\DRIVERS\xfilt.sys
07:38:13.0156 3564 xfilt - ok
07:38:13.0187 3564 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
07:38:13.0203 3564 xmlprov - ok
07:38:13.0234 3564 ================ Scan global ===============================
07:38:13.0312 3564 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
07:38:13.0328 3564 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
07:38:13.0375 3564 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
07:38:13.0390 3564 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
07:38:13.0390 3564 [Global] - ok
07:38:13.0390 3564 ================ Scan MBR ==================================
07:38:13.0390 3564 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
07:38:13.0390 3564 Suspicious mbr (Forged): \Device\Harddisk0\DR0
07:38:13.0468 3564 \Device\Harddisk0\DR0 - ok
07:38:13.0468 3564 ================ Scan VBR ==================================
07:38:13.0468 3564 [ 424897D6C6B3E3F9EE68DECF0B3D0F05 ] \Device\Harddisk0\DR0\Partition1
07:38:13.0468 3564 \Device\Harddisk0\DR0\Partition1 - ok
07:38:13.0468 3564 ============================================================
07:38:13.0468 3564 Scan finished
07:38:13.0468 3564 ============================================================
07:38:13.0484 3672 Detected object count: 2
07:38:13.0484 3672 Actual detected object count: 2
07:39:14.0171 3672 C:\WINDOWS\System32\Drivers\6d926cb3c7f34037.sys - copied to quarantine
07:39:14.0203 3672 HKLM\SYSTEM\ControlSet001\services\6d926cb3c7f34037 - will be deleted on reboot
07:39:14.0250 3672 HKLM\SYSTEM\ControlSet003\services\6d926cb3c7f34037 - will be deleted on reboot
07:39:14.0437 3672 C:\WINDOWS\System32\Drivers\6d926cb3c7f34037.sys - will be deleted on reboot
07:39:14.0437 3672 6d926cb3c7f34037 ( Rootkit.Win32.Necurs.gen ) - User select action: Delete
07:39:14.0531 3672 C:\WINDOWS\Installer\{DF5D9716-6B4E-BFB2-601C-01B43FCA134E}\syshost.exe - copied to quarantine
07:39:14.0593 3672 HKLM\SYSTEM\ControlSet001\services\syshost32 - will be deleted on reboot
07:39:14.0656 3672 HKLM\SYSTEM\ControlSet003\services\syshost32 - will be deleted on reboot
07:39:14.0828 3672 C:\WINDOWS\Installer\{DF5D9716-6B4E-BFB2-601C-01B43FCA134E}\syshost.exe - will be deleted on reboot
07:39:14.0828 3672 syshost32 ( Rootkit.Win32.Necurs.gen ) - User select action: Delete
07:39:41.0531 1596 Deinitialize success0 -
have you now rebooted ?......Gettin' There, Wherever There is......
I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple0 -
I'd be inclined to run aswmbr:-
http://www.bleepingcomputer.com/download/aswmbr/ do not download definitions when run, post the log
then quick scan with malwayebytes:-
http://www.filehippo.com/download_malwarebytes_anti_malware/......Gettin' There, Wherever There is......
I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple0 -
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-27 09:03:17
09:03:17.265 OS Version: Windows 5.1.2600 Service Pack 3
09:03:17.265 Number of processors: 2 586 0xF02
09:03:17.265 ComputerName: USER-2167439A17 UserName: Wareham
09:03:18.312 Initialize success
09:05:37.421 AVAST engine defs: 12082601
09:12:25.875 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-12
09:12:25.875 Disk 0 Vendor: Maxtor_6Y080L0 YAR41BW0 Size: 78167MB BusType: 3
09:12:25.890 Disk 0 MBR read successfully
09:12:25.890 Disk 0 MBR scan
09:12:25.921 Disk 0 Windows XP default MBR code
09:12:25.921 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 78152 MB offset 63
09:12:25.937 Disk 0 scanning sectors +160055595
09:12:25.984 Disk 0 scanning C:\WINDOWS\system32\drivers
09:12:35.546 Service scanning
09:12:54.390 Modules scanning
09:13:15.062 Disk 0 trace - called modules:
09:13:15.078 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys videX32.sys PCIIDEX.SYS
09:13:15.078 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a256ab8]
09:13:15.078 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\0000006d[0x8a30a9e8]
09:13:15.078 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-12[0x8a255d98]
09:13:15.421 AVAST engine scan C:\WINDOWS
09:13:42.203 AVAST engine scan C:\WINDOWS\system32
09:16:48.296 AVAST engine scan C:\WINDOWS\system32\drivers
09:17:02.937 AVAST engine scan C:\Documents and Settings\Wareham
09:29:30.109 AVAST engine scan C:\Documents and Settings\All Users
09:33:32.328 Scan finished successfully
09:34:23.250 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Wareham\Desktop\MBR.dat"
09:34:23.359 The log file has been saved successfully to "C:\Documents and Settings\Wareham\Desktop\aswMBR.txt"0 -
The aswMBR log looks good. It was the Necurs rootkit that was active. TDSSkiller got it, aswMBR would report it if it was still there.07:37:56.0328 3564 Suspicious service (NoAccess): 6d926cb3c7f34037
07:37:56.0390 3564 [ 6328BE727FD766F0F818222DE92A1D64] 6d926cb3c7f34037 C:\WINDOWS\System32\Drivers\6d926cb3c7f34037.sys
07:37:56.0390 3564 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\6d926cb3c7f34037.sys. md5: 6328BE727FD766F0F818222DE92A1D64
07:37:56.0593 3564 6d926cb3c7f34037 ( Rootkit.Win32.Necurs.gen ) - infected
07:37:56.0593 3564 6d926cb3c7f34037 - detected Rootkit.Win32.Necurs.gen (0)0 -
How's it behaving now ??......Gettin' There, Wherever There is......
I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple0 -
Oh well, looks like they've bogged off......Gettin' There, Wherever There is......
I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple0 -
They might be back later.
The important part was getting rid of the rootkit - There is still some other minor stuff though.0 -
My desktop still has a blue screen.
The Favourites file is still empty.
But I can come direct to this site without being redirected to other silly sites.
What now, please?
Ps - Sorry for the delay, I've been doing some cooking.0 -
Download and run this file.
http://www.bleepingcomputer.com/download/unhide/
Have you run Malwarebytes (quick scan) as suggested by GunJack?0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350.3K Banking & Borrowing
- 252.8K Reduce Debt & Boost Income
- 453.2K Spending & Discounts
- 243.2K Work, Benefits & Business
- 597.7K Mortgages, Homes & Bills
- 176.6K Life & Family
- 256.3K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards