Microsoft
Software
Hardware
Network
Question : HP printer won't print, Dell printer will - This is after being attacked by TDSS
About two weeks ago about 10 of my computers were attacked by TDSS. I used the Kapersky removal tool and thought everything was fine. Now I have the following problem:
HP 2055 dn printer will not print - This is only from the machines that were attacked by TDSS. The other non-infected machines print just fine.
Dell printer - still works just fine. (Even on the machines that were attacked with TDSS).
My first thought was to uninstall / reinstall software and drives for the HP 2055 dn. Did that, no go. During installation the printer is detected by nothing ever prints. Test page, notepad, wordpad, Office everything fails. I'm including the scan logs from TDSSkiller, and the Combo Fix log. I have run Malwarebytes and Ccleaner with no additional detections. Any help would be appreciated!! Much thanks!
Combo Fix log
ComboFix 10-08-17.03 - Hulk 08/18/2010 10:54:40.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.
1023.576 [GMT -4:00]
Running from: c:\documents and settings\Administrator\Des
ktop\Combo
Fix.exe
.
((((((((((((((((((((((((((
((((((((((
((( Other Deletions ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
.
C:\dfinstall.log
.
((((((((((((((((((((((((( Files Created from 2010-07-18 to 2010-08-18 ))))))))))))))))))))))))))
)))))
.
2010-08-13 22:42 . 2010-08-13 22:42 -------- d-sh--w- c:\documents and settings\LocalService\IETl
dCache
2010-08-09 13:13 . 2010-08-09 13:13 -------- d-----w- c:\program files\ACW
2010-08-06 20:21 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcac
he\helpsvc
.exe
2010-08-06 20:21 . 2010-06-24 12:21 743424 -c----w- c:\windows\system32\dllcac
he\iedvtoo
l.dll
2010-08-05 19:57 . 2010-08-05 19:57 -------- d-----w- c:\documents and settings\Administrator\App
lication Data\Malwarebytes
2010-08-05 19:56 . 2010-08-05 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-05 14:13 . 2010-08-05 14:13 -------- d-----w- c:\program files\Common Files\Java
2010-08-04 21:40 . 2010-08-04 21:40 503808 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\4\7ec
4bf04-4dc3
b1a5-n\msv
cp71.dll
2010-08-04 21:40 . 2010-08-04 21:40 499712 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\4\7ec
4bf04-4dc3
b1a5-n\jmc
.dll
2010-08-04 21:40 . 2010-08-04 21:40 348160 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\4\7ec
4bf04-4dc3
b1a5-n\msv
cr71.dll
2010-08-04 21:40 . 2010-08-04 21:40 61440 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\42\44
88892a-50e
45845-n\de
cora-sse.d
ll
2010-08-04 21:40 . 2010-08-04 21:40 12800 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\42\44
88892a-50e
45845-n\de
cora-d3d.d
ll
2010-08-04 21:24 . 2010-08-04 21:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-08-04 21:24 . 2010-08-04 21:24 -------- d-----w- c:\documents and settings\Administrator\App
lication Data\Office Genuine Advantage
.
((((((((((((((((((((((((((
((((((((((
(((( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
))))))
.
2010-08-09 13:09 . 2009-09-16 19:22 64368 ----a-w- c:\documents and settings\Administrator\Loc
al Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-06 19:20 . 2004-08-04 12:00 75264 ----a-w- c:\windows\system32\driver
s\ipsec.sy
s
2010-08-05 14:13 . 2009-09-22 21:04 -------- d-----w- c:\program files\Java
2010-08-04 18:29 . 2009-10-04 05:21 -------- d-----w- c:\documents and settings\Administrator\App
lication Data\U3
2010-07-17 09:00 . 2010-06-20 00:01 423656 ----a-w- c:\windows\system32\deploy
Java1.dll
2010-06-30 12:31 . 2004-08-04 12:00 149504 ----a-w- c:\windows\system32\schann
el.dll
2010-06-28 01:17 . 2010-06-28 01:17 16336546 ------w- C:\Persi0.sys
2010-06-28 01:16 . 2009-09-15 21:43 2048 --s-a-w- c:\windows\bootstet.dat
2010-06-28 01:13 . 2010-06-28 01:13 -------- d-----w- c:\documents and settings\Administrator\App
lication Data\TeamViewer
2010-06-28 01:13 . 2010-06-28 01:13 -------- d-----w- c:\program files\TeamViewer
2010-06-24 12:22 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\winine
t.dll
2010-06-23 13:44 . 2004-08-04 12:00 1851904 ----a-w- c:\windows\system32\win32k
.sys
2010-06-21 15:27 . 2004-08-04 12:00 354304 ----a-w- c:\windows\system32\driver
s\srv.sys
2010-06-19 23:51 . 2010-06-19 23:51 503808 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\46\f8
4c6ae-1de0
1dff-n\msv
cp71.dll
2010-06-19 23:51 . 2010-06-19 23:51 499712 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\46\f8
4c6ae-1de0
1dff-n\jmc
.dll
2010-06-19 23:51 . 2010-06-19 23:51 348160 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\46\f8
4c6ae-1de0
1dff-n\msv
cr71.dll
2010-06-19 23:51 . 2010-06-19 23:51 61440 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\50\55
35ab32-584
e2f9e-n\de
cora-sse.d
ll
2010-06-19 23:51 . 2010-06-19 23:51 12800 ----a-w- c:\documents and settings\Administrator\App
lication Data\Sun\Java\Deployment\S
ystemCache
\6.0\50\55
35ab32-584
e2f9e-n\de
cora-d3d.d
ll
2010-06-19 17:33 . 2010-06-19 17:33 764288 ----a-w- c:\windows\system32\DFC.ex
e
2010-06-19 17:33 . 2010-06-19 17:33 748928 ----a-w- c:\windows\system32\LDK.ex
e
2010-06-17 14:03 . 2004-08-04 12:00 80384 ----a-w- c:\windows\system32\iccvid
.dll
2010-06-14 14:31 . 2009-09-15 21:36 744448 ----a-w- c:\windows\pchealth\helpct
r\binaries
\helpsvc.e
xe
2010-06-14 07:41 . 2004-08-04 12:00 1172480 ----a-w- c:\windows\system32\msxml3
.dll
2010-05-20 15:19 . 2010-05-20 15:19 76312 ----a-w- c:\windows\system32\driver
s\ThwSpace
.sys
2010-05-20 15:19 . 2010-05-20 15:19 153240 ----a-w- c:\windows\system32\driver
s\DeepFrz.
sys
2010-05-20 15:17 . 2010-06-28 01:17 65536 ----a-w- c:\windows\system32\LogonD
ll.dll
.
((((((((((((((((((((((((((
((((((((((
( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Run]
"SunJavaUpdateSched"="c:\p
rogram files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
PCReservation Client Module.LNK - c:\pcres\PCRes_Client.exe [2009-10-4 614400]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\winlogon
\notify\Df
Logon]
2010-05-20 15:17 65536 ----a-w- c:\windows\system32\LogonD
ll.dll
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\c
ontrol\ses
sion manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C *
[HKLM\~\startupfolder\C:^D
ocuments and Settings^All Users^Start Menu^Programs^Startup^Blue
tooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Blue
tooth Manager.lnk
backup=c:\windows\pss\Blue
tooth Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
Adobe Reader Speed Launcher]
2009-02-27 21:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
Alcmtr]
2009-06-26 14:09 57344 ----a-w- c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
ASUS Easy Update]
2008-10-16 20:07 188416 ----a-w- c:\program files\ASUS\ASUS Easy Update\ALU.exe
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
ctfmon.exe
]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon
.exe
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
RTHDCPL]
2009-06-26 14:09 18084864 ----a-w- c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
StartCCC]
2009-02-25 19:38 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-
Static\CLI
Start.exe
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Auth
orizedAppl
ications\L
ist]
"%windir%\\system32\\sessm
gr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
=
"c:\\HP_P2055_Network_Expr
ess_Instal
l\\setup\\
hppnet01.e
xe"=
"c:\\PCRes\\PCRes_Client.e
xe"=
"c:\\Program Files\\TeamViewer\\Version
5\\TeamVie
wer.exe"=
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Glob
allyOpenPo
rts\List]
"135:TCP"= 135:TCP:DCOM_TCP135
R0 DeepFrz;DeepFrz;c:\windows
\system32\
drivers\De
epFrz.sys [5/20/2010 11:19 AM 153240]
R2 DFServ;DFServ;c:\program files\Faronics\Deep Freeze\Install C-0\DFServ.exe [6/19/2010 1:33 PM 1074048]
R2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\
TeamViewer
_Service.e
xe [5/21/2010 7:27 AM 173352]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32
\drivers\g
flmouhid.s
ys [4/19/2004 3:01 PM 6656]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32
\drivers\R
TS5121.sys
[9/16/2009 2:50 PM 157696]
--- Other Services/Drivers In Memory ---
*Deregistered* - klmd24
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFIC
E11\EXCEL.
EXE/3000
TCP: {215ABC43-EE40-40EE-AE87-9
D154CC84B2
A} = 131.144.4.10,205.152.0.5
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-klmdb.sys
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-SunJavaUpd
ateSched - c:\program files\Java\jre6\bin\jusche
d.exe
**************************
**********
**********
**********
**********
********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-18 10:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
**********
**********
**********
**********
********
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-22052
3388-11760
9710-68200
3330-500\S
oftware\Mi
crosoft\In
ternet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A80
5A34F98AFF
34F5977"=h
ex:01,00,0
0,00,d0,8c
,9d,df,01,
15,
d1,11,8c,7a,00,c0,4f,c2,97
,eb,01,00,
00,00,eb,d
8,53,7e,f7
,b9,13,48,
bc,2c,fd,\
"2D53CFFC5C1A3DD2E97B7979A
C2A92BD59B
C839E81"=h
ex:01,00,0
0,00,d0,8c
,9d,df,01,
15,
d1,11,8c,7a,00,c0,4f,c2,97
,eb,01,00,
00,00,eb,d
8,53,7e,f7
,b9,13,48,
bc,2c,fd,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(868)
c:\windows\system32\Ati2ev
xx.dll
c:\windows\system32\LogonD
ll.dll
c:\program files\TeamViewer\Version5\
tv.dll
.
Completion time: 2010-08-18 11:00:55
ComboFix-quarantined-files
.txt 2010-08-18 15:00
Pre-Run: 151,265,144,832 bytes free
Post-Run: 151,345,844,224 bytes free
WindowsXP-KB310994-SP2-Pro
-BootDisk-
ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdi
sk(0)parti
tion(1)\WI
NDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="M
icrosoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)par
tition(1)\
WINDOWS="M
icrosoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - E218D1037D7E4718661E49A3AA
090369
First TDSS Killer log file where it cleaned
2010/08/06 15:18:34.0140 TDSS rootkit removing tool 2.4.1.0 Aug 4 2010 15:06:41
2010/08/06 15:18:34.0140 ==========================
==========
==========
==========
==========
==========
====
2010/08/06 15:18:34.0140 SystemInfo:
2010/08/06 15:18:34.0140
2010/08/06 15:18:34.0140 OS Version: 5.1.2600 ServicePack: 3.0
2010/08/06 15:18:34.0140 Product type: Workstation
2010/08/06 15:18:34.0140 ComputerName: HULK
2010/08/06 15:18:34.0140 UserName: Hulk
2010/08/06 15:18:34.0140 Windows directory: C:\WINDOWS
2010/08/06 15:18:34.0140 System windows directory: C:\WINDOWS
2010/08/06 15:18:34.0140 Processor architecture: Intel x86
2010/08/06 15:18:34.0140 Number of processors: 2
2010/08/06 15:18:34.0140 Page size: 0x1000
2010/08/06 15:18:34.0140 Boot type: Normal boot
2010/08/06 15:18:34.0140 ==========================
==========
==========
==========
==========
==========
====
2010/08/06 15:18:34.0515 Initialize success
2010/08/06 15:18:36.0984 ==========================
==========
==========
==========
==========
==========
====
2010/08/06 15:18:36.0984 Scan started
2010/08/06 15:18:36.0984 Mode: Manual;
2010/08/06 15:18:36.0984 ==========================
==========
==========
==========
==========
==========
====
2010/08/06 15:18:38.0984 ACPI (8fd99680a539792a30e97944f
daecf17) C:\WINDOWS\system32\DRIVER
S\ACPI.sys
2010/08/06 15:18:39.0031 ACPIEC (9859c0f6936e723e4892d7141
b1327d5) C:\WINDOWS\system32\DRIVER
S\ACPIEC.s
ys
2010/08/06 15:18:39.0093 aec (8bed39e3c35d6a489438b8141
717a557) C:\WINDOWS\system32\driver
s\aec.sys
2010/08/06 15:18:39.0187 AFD (7e775010ef291da96ad17ca4b
17137d7) C:\WINDOWS\System32\driver
s\afd.sys
2010/08/06 15:18:39.0687 AR5416 (7d53e5646ba23fd51296f7ef8
979a000) C:\WINDOWS\system32\DRIVER
S\athw.sys
2010/08/06 15:18:39.0968 AsyncMac (b153affac761e7f5fcfa822b9
c4e97bc) C:\WINDOWS\system32\DRIVER
S\asyncmac
.sys
2010/08/06 15:18:40.0046 atapi (9f3a2f5aa6875c72bf062c712
cfa2674) C:\WINDOWS\system32\DRIVER
S\atapi.sy
s
2010/08/06 15:18:40.0250 ati2mtag (8763ede3e0cd40f5c3450571a
c57f205) C:\WINDOWS\system32\DRIVER
S\ati2mtag
.sys
2010/08/06 15:18:40.0312 Atmarpc (9916c1225104ba14794209cfa
8012159) C:\WINDOWS\system32\DRIVER
S\atmarpc.
sys
2010/08/06 15:18:40.0390 audstub (d9f724aa26c010a217c97606b
160ed68) C:\WINDOWS\system32\DRIVER
S\audstub.
sys
2010/08/06 15:18:40.0421 Beep (da1f27d85e0d1525f6621372e
7b685e9) C:\WINDOWS\system32\driver
s\Beep.sys
2010/08/06 15:18:40.0500 cbidf2k (90a673fc8e12a79afbed2576f
6a7aaf9) C:\WINDOWS\system32\driver
s\cbidf2k.
sys
2010/08/06 15:18:40.0578 Cdaudio (c1b486a7658353d33a10cc152
11a873b) C:\WINDOWS\system32\driver
s\Cdaudio.
sys
2010/08/06 15:18:40.0671 Cdfs (c885b02847f5d2fd45a24e219
ed93b32) C:\WINDOWS\system32\driver
s\Cdfs.sys
2010/08/06 15:18:40.0687 Cdrom (1f4260cc5b42272d71f79e570
a27a4fe) C:\WINDOWS\system32\DRIVER
S\cdrom.sy
s
2010/08/06 15:18:40.0750 cercsr6 (84853b3fd012251690570e9e7
e43343f) C:\WINDOWS\system32\driver
s\cercsr6.
sys
2010/08/06 15:18:41.0000 DeepFrz (4e81e22588a6cd946a1f4378c
791a336) C:\WINDOWS\system32\driver
s\DeepFrz.
sys
2010/08/06 15:18:41.0062 Disk (044452051f3e02e7963599fc8
f4f3e25) C:\WINDOWS\system32\DRIVER
S\disk.sys
2010/08/06 15:18:41.0125 dmboot (d992fe1274bde0f84ad826aca
e022a41) C:\WINDOWS\system32\driver
s\dmboot.s
ys
2010/08/06 15:18:41.0140 dmio (7c824cf7bbde77d95c0800571
7a95f6f) C:\WINDOWS\system32\driver
s\dmio.sys
2010/08/06 15:18:41.0156 dmload (e9317282a63ca4d188c0df5e0
9c6ac5f) C:\WINDOWS\system32\driver
s\dmload.s
ys
2010/08/06 15:18:41.0203 DMusic (8a208dfcf89792a484e76c40e
5f50b45) C:\WINDOWS\system32\driver
s\DMusic.s
ys
2010/08/06 15:18:41.0281 drmkaud (8f5fcff8e8848afac920905fb
d9d33c8) C:\WINDOWS\system32\driver
s\drmkaud.
sys
2010/08/06 15:18:41.0437 Fastfat (38d332a6d56af32635675f132
548343e) C:\WINDOWS\system32\driver
s\Fastfat.
sys
2010/08/06 15:18:41.0468 Fdc (92cdd60b6730b9f50f6a1a0c1
f8cdc81) C:\WINDOWS\system32\driver
s\Fdc.sys
2010/08/06 15:18:41.0500 Fips (d45926117eb9fa946a6af572f
be1caa3) C:\WINDOWS\system32\driver
s\Fips.sys
2010/08/06 15:18:41.0515 Flpydisk (9d27e7b80bfcdf1cdd9b55586
2d5e7f0) C:\WINDOWS\system32\driver
s\Flpydisk
.sys
2010/08/06 15:18:41.0578 FltMgr (b2cf4b0786f8212cb92ed2b50
c6db6b0) C:\WINDOWS\system32\driver
s\fltmgr.s
ys
2010/08/06 15:18:41.0625 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2b
cc2779a) C:\WINDOWS\system32\driver
s\Fs_Rec.s
ys
2010/08/06 15:18:41.0640 Ftdisk (6ac26732762483366c3969c9e
4d2259d) C:\WINDOWS\system32\DRIVER
S\ftdisk.s
ys
2010/08/06 15:18:41.0718 genmcmnUSB (86f732d2995ada73fd307539e
c266d3a) C:\WINDOWS\system32\DRIVER
S\gflmouhi
d.sys
2010/08/06 15:18:41.0796 Gpc (0a02c63c8b144bd8c86b103de
e7c86a2) C:\WINDOWS\system32\DRIVER
S\msgpc.sy
s
2010/08/06 15:18:41.0890 HDAudBus (573c7d0a32852b48f3058cfd8
026f511) C:\WINDOWS\system32\DRIVER
S\HDAudBus
.sys
2010/08/06 15:18:41.0953 hidusb (ccf82c5ec8a7326c3066de870
c06daf1) C:\WINDOWS\system32\DRIVER
S\hidusb.s
ys
2010/08/06 15:18:42.0062 HTTP (f80a415ef82cd06ffaf0d9715
28ead38) C:\WINDOWS\system32\Driver
s\HTTP.sys
2010/08/06 15:18:42.0109 i8042prt (4a0b06aa8943c1e332520f744
0c0aa30) C:\WINDOWS\system32\DRIVER
S\i8042prt
.sys
2010/08/06 15:18:42.0156 Imapi (083a052659f5310dd8b6a6cb0
5edcf8e) C:\WINDOWS\system32\DRIVER
S\imapi.sy
s
2010/08/06 15:18:42.0421 IntcAzAudAddService (2b7ce5e35c5e279b77cc10a4c
70f24df) C:\WINDOWS\system32\driver
s\RtkHDAud
.sys
2010/08/06 15:18:42.0531 intelppm (8c953733d8f36eb2133f5bb58
808b66b) C:\WINDOWS\system32\DRIVER
S\intelppm
.sys
2010/08/06 15:18:42.0593 Ip6Fw (3bb22519a194418d5fec05d80
0a19ad0) C:\WINDOWS\system32\driver
s\ip6fw.sy
s
2010/08/06 15:18:42.0687 IpFilterDriver (731f22ba402ee4b62748adaf6
363c182) C:\WINDOWS\system32\DRIVER
S\ipfltdrv
.sys
2010/08/06 15:18:42.0765 IpInIp (b87ab476dcf76e72010632b55
50955f5) C:\WINDOWS\system32\DRIVER
S\ipinip.s
ys
2010/08/06 15:18:42.0828 IpNat (cc748ea12c6effde940ee9809
8bf96bb) C:\WINDOWS\system32\DRIVER
S\ipnat.sy
s
2010/08/06 15:18:42.0859 IPSec (dfab325d623a1952d00182b19
3c9940a) C:\WINDOWS\system32\DRIVER
S\ipsec.sy
s
2010/08/06 15:18:42.0859 Suspicious file (Forged): C:\WINDOWS\system32\DRIVER
S\ipsec.sy
s. Real md5: dfab325d623a1952d00182b193
c9940a, Fake md5: 23c74d75e36e7158768dd63d92
789a91
2010/08/06 15:18:42.0859 IPSec - detected Rootkit.Win32.TDSS.tdl3 (0)
2010/08/06 15:18:42.0906 IRENUM (c93c9ff7b04d772627a3646d8
9f7bf89) C:\WINDOWS\system32\DRIVER
S\irenum.s
ys
2010/08/06 15:18:42.0953 isapnp (05a299ec56e52649b1cf2fc52
d20f2d7) C:\WINDOWS\system32\DRIVER
S\isapnp.s
ys
2010/08/06 15:18:42.0984 Kbdclass (463c1ec80cd17420a542b7f36
a36f128) C:\WINDOWS\system32\DRIVER
S\kbdclass
.sys
2010/08/06 15:18:43.0015 kbdhid (9ef487a186dea361aa06913a7
5b3fa99) C:\WINDOWS\system32\DRIVER
S\kbdhid.s
ys
2010/08/06 15:18:43.0046 kmixer (692bcf44383d056aed41b045a
323d378) C:\WINDOWS\system32\driver
s\kmixer.s
ys
2010/08/06 15:18:43.0125 KSecDD (b467646c54cc746128904e165
4c750c1) C:\WINDOWS\system32\driver
s\KSecDD.s
ys
2010/08/06 15:18:43.0343 mnmdd (4ae068242760a1fb6e1a44bf4
e16afa6) C:\WINDOWS\system32\driver
s\mnmdd.sy
s
2010/08/06 15:18:43.0406 Modem (dfcbad3cec1c5f964962ae10e
0bcc8e1) C:\WINDOWS\system32\driver
s\Modem.sy
s
2010/08/06 15:18:43.0453 Mouclass (35c9e97194c8cfb8430125f8d
bc34d04) C:\WINDOWS\system32\DRIVER
S\mouclass
.sys
2010/08/06 15:18:43.0468 mouhid (b1c303e17fb9d46e87a98e4ba
6769685) C:\WINDOWS\system32\DRIVER
S\mouhid.s
ys
2010/08/06 15:18:43.0578 MountMgr (a80b9a0bad1b73637dbcbba7d
f72d3fd) C:\WINDOWS\system32\driver
s\MountMgr
.sys
2010/08/06 15:18:43.0609 MRxDAV (11d42bb6206f33fbb3ba0288d
3ef81bd) C:\WINDOWS\system32\DRIVER
S\mrxdav.s
ys
2010/08/06 15:18:43.0671 MRxSmb (421f7b922cec5a5f340e7574a
98f7b7c) C:\WINDOWS\system32\DRIVER
S\mrxsmb.s
ys
2010/08/06 15:18:43.0718 Msfs (c941ea2454ba8350021d774da
f0f1027) C:\WINDOWS\system32\driver
s\Msfs.sys
2010/08/06 15:18:43.0750 MSKSSRV (d1575e71568f4d9e14ca56b7b
0453bf1) C:\WINDOWS\system32\driver
s\MSKSSRV.
sys
2010/08/06 15:18:43.0781 MSPCLOCK (325bb26842fc7ccc1fcce2c45
7317f3e) C:\WINDOWS\system32\driver
s\MSPCLOCK
.sys
2010/08/06 15:18:43.0796 MSPQM (bad59648ba099da4a17680b39
730cb3d) C:\WINDOWS\system32\driver
s\MSPQM.sy
s
2010/08/06 15:18:43.0859 mssmbios (af5f4f3f14a8ea2c26de30f7a
1e17136) C:\WINDOWS\system32\DRIVER
S\mssmbios
.sys
2010/08/06 15:18:43.0937 MTsensor (d48659bb24c48345d926ecb45
c1ebdf5) C:\WINDOWS\system32\DRIVER
S\ASACPI.s
ys
2010/08/06 15:18:43.0968 Mup (2f625d11385b1a94360bfc70a
aefdee1) C:\WINDOWS\system32\driver
s\Mup.sys
2010/08/06 15:18:44.0000 NDIS (1df7f42665c94b825322fae71
721130d) C:\WINDOWS\system32\driver
s\NDIS.sys
2010/08/06 15:18:44.0015 NdisTapi (1ab3d00c991ab086e69db84b6
c0ed78f) C:\WINDOWS\system32\DRIVER
S\ndistapi
.sys
2010/08/06 15:18:44.0031 Ndisuio (f927a4434c5028758a842943e
f1a3849) C:\WINDOWS\system32\DRIVER
S\ndisuio.
sys
2010/08/06 15:18:44.0062 NdisWan (edc1531a49c80614b2cfda43c
a8659ab) C:\WINDOWS\system32\DRIVER
S\ndiswan.
sys
2010/08/06 15:18:44.0078 NDProxy (6215023940cfd3702b46abc30
4e1d45a) C:\WINDOWS\system32\driver
s\NDProxy.
sys
2010/08/06 15:18:44.0125 NetBIOS (5d81cf9a2f1a3a756b66cf684
911cdf0) C:\WINDOWS\system32\DRIVER
S\netbios.
sys
2010/08/06 15:18:44.0140 NetBT (74b2b2f5bea5e9a3dc021d685
551bd3d) C:\WINDOWS\system32\DRIVER
S\netbt.sy
s
2010/08/06 15:18:44.0218 Npfs (3182d64ae053d6fb034f44b6d
ef8034a) C:\WINDOWS\system32\driver
s\Npfs.sys
2010/08/06 15:18:44.0250 Ntfs (78a08dd6a8d65e697c18e1db0
1c5cdca) C:\WINDOWS\system32\driver
s\Ntfs.sys
2010/08/06 15:18:44.0359 Null (73c1e1f395918bc2c6dd67af7
591a3ad) C:\WINDOWS\system32\driver
s\Null.sys
2010/08/06 15:18:44.0406 NwlnkFlt (b305f3fad35083837ef46a0bb
ce2fc57) C:\WINDOWS\system32\DRIVER
S\nwlnkflt
.sys
2010/08/06 15:18:44.0421 NwlnkFwd (c99b3415198d1aab7227f2c88
fd664b9) C:\WINDOWS\system32\DRIVER
S\nwlnkfwd
.sys
2010/08/06 15:18:44.0500 Parport (5575faf8f97ce5e713d108c2a
58d7c7c) C:\WINDOWS\system32\driver
s\Parport.
sys
2010/08/06 15:18:44.0515 PartMgr (beb3ba25197665d82ec7065b7
24171c6) C:\WINDOWS\system32\driver
s\PartMgr.
sys
2010/08/06 15:18:44.0578 ParVdm (70e98b3fd8e963a6a46a2e624
7e0bea1) C:\WINDOWS\system32\driver
s\ParVdm.s
ys
2010/08/06 15:18:44.0640 PCI (a219903ccf74233761d92bef4
71a07b1) C:\WINDOWS\system32\DRIVER
S\pci.sys
2010/08/06 15:18:44.0750 PCIIde (ccf5f451bb1a5a2a522a76e67
0000ff0) C:\WINDOWS\system32\DRIVER
S\pciide.s
ys
2010/08/06 15:18:44.0796 Pcmcia (9e89ef60e9ee05e3f2eef2da7
397f1c1) C:\WINDOWS\system32\driver
s\Pcmcia.s
ys
2010/08/06 15:18:45.0031 PptpMiniport (efeec01b1d3cf84f16ddd24d9
d9d8f99) C:\WINDOWS\system32\DRIVER
S\raspptp.
sys
2010/08/06 15:18:45.0046 PSched (09298ec810b07e5d582cb3a3f
9255424) C:\WINDOWS\system32\DRIVER
S\psched.s
ys
2010/08/06 15:18:45.0062 Ptilink (80d317bd1c3dbc5d4fe7b1678
c60cadd) C:\WINDOWS\system32\DRIVER
S\ptilink.
sys
2010/08/06 15:18:45.0156 RasAcd (fe0d99d6f31e4fad8159f690d
68ded9c) C:\WINDOWS\system32\DRIVER
S\rasacd.s
ys
2010/08/06 15:18:45.0187 Rasl2tp (11b4a627bc9614b885c4969bf
a5ff8a6) C:\WINDOWS\system32\DRIVER
S\rasl2tp.
sys
2010/08/06 15:18:45.0250 RasPppoe (5bc962f2654137c9909c3d460
3587dee) C:\WINDOWS\system32\DRIVER
S\raspppoe
.sys
2010/08/06 15:18:45.0328 Raspti (fdbb1d60066fcfbb7452fd8f9
829b242) C:\WINDOWS\system32\DRIVER
S\raspti.s
ys
2010/08/06 15:18:45.0343 Rdbss (7ad224ad1a1437fe28d89cf22
b17780a) C:\WINDOWS\system32\DRIVER
S\rdbss.sy
s
2010/08/06 15:18:45.0390 RDPCDD (4912d5b403614ce99c28420f7
5353332) C:\WINDOWS\system32\DRIVER
S\RDPCDD.s
ys
2010/08/06 15:18:45.0406 rdpdr (15cabd0f7c00c47c701249079
16af3f1) C:\WINDOWS\system32\DRIVER
S\rdpdr.sy
s
2010/08/06 15:18:45.0484 RDPWD (6728e45b66f93c08f11de2e31
6fc70dd) C:\WINDOWS\system32\driver
s\RDPWD.sy
s
2010/08/06 15:18:45.0531 redbook (f828dd7e1419b6653894a8f97
a0094c5) C:\WINDOWS\system32\DRIVER
S\redbook.
sys
2010/08/06 15:18:45.0671 RSUSBSTOR (2cb299f6cc04bac8889a52b0f
f48a9d7) C:\WINDOWS\system32\Driver
s\RTS5121.
sys
2010/08/06 15:18:45.0859 RTHDMIAzAudService (a5a9f4b77d7ff2b02633999ff
71a7e9b) C:\WINDOWS\system32\driver
s\RtKHDMI.
sys
2010/08/06 15:18:45.0984 RTLE8023xp (185641ad7e80bfce0aa545d3e
c79d557) C:\WINDOWS\system32\DRIVER
S\Rtenicxp
.sys
2010/08/06 15:18:46.0078 Secdrv (90a3935d05b494a5a39d37e71
f09a677) C:\WINDOWS\system32\DRIVER
S\secdrv.s
ys
2010/08/06 15:18:46.0156 Serial (cca207a8896d4c6a0c9ce29a4
ae411a7) C:\WINDOWS\system32\driver
s\Serial.s
ys
2010/08/06 15:18:46.0203 Sfloppy (8e6b8c671615d126fdc553d1e
2de5562) C:\WINDOWS\system32\driver
s\Sfloppy.
sys
2010/08/06 15:18:46.0328 splitter (ab8b92451ecb048a4d1de7c3f
fcb4a9f) C:\WINDOWS\system32\driver
s\splitter
.sys
2010/08/06 15:18:46.0359 sr (76bb022c2fb6902fd5bdd4f78
fc13a5d) C:\WINDOWS\system32\DRIVER
S\sr.sys
2010/08/06 15:18:46.0453 Srv (89220b427890aa1dffd1a0264
8ae51c3) C:\WINDOWS\system32\DRIVER
S\srv.sys
2010/08/06 15:18:46.0484 swenum (3941d127aef12e93addf6fe6e
e027e0f) C:\WINDOWS\system32\DRIVER
S\swenum.s
ys
2010/08/06 15:18:46.0531 swmidi (8ce882bcc6cf8a62f2b2323d9
5cb3d01) C:\WINDOWS\system32\driver
s\swmidi.s
ys
2010/08/06 15:18:46.0656 sysaudio (8b83f3ed0f1688b4958f77cd6
d2bf290) C:\WINDOWS\system32\driver
s\sysaudio
.sys
2010/08/06 15:18:46.0781 Tcpip (9aefa14bd6b182d61e3119fa5
f436d3d) C:\WINDOWS\system32\DRIVER
S\tcpip.sy
s
2010/08/06 15:18:46.0843 TDPIPE (6471a66807f5e104e4885f5b6
7349397) C:\WINDOWS\system32\driver
s\TDPIPE.s
ys
2010/08/06 15:18:46.0859 TDTCP (c56b6d0402371cf3700eb322e
f3aaf61) C:\WINDOWS\system32\driver
s\TDTCP.sy
s
2010/08/06 15:18:46.0921 TermDD (8815524717763804842289373
7429d9e) C:\WINDOWS\system32\DRIVER
S\termdd.s
ys
2010/08/06 15:18:47.0031 tosporte (8d624d3bd1f2d78bd1c01a2d4
e954b4e) C:\WINDOWS\system32\DRIVER
S\tosporte
.sys
2010/08/06 15:18:47.0093 tosrfbd (73abec184a36239ca0a7dc96c
7e74c44) C:\WINDOWS\system32\DRIVER
S\tosrfbd.
sys
2010/08/06 15:18:47.0109 tosrfbnp (181e217a7a326817d97946d04
5b3cb46) C:\WINDOWS\system32\Driver
s\tosrfbnp
.sys
2010/08/06 15:18:47.0125 Tosrfcom (e90ace3b4fa7a85f992bc21eb
779c407) C:\WINDOWS\system32\Driver
s\tosrfcom
.sys
2010/08/06 15:18:47.0156 Tosrfhid (87700714f25131ed21901d617
b8b321f) C:\WINDOWS\system32\DRIVER
S\Tosrfhid
.sys
2010/08/06 15:18:47.0187 tosrfnds (c52fd27b9adf3a1f22cb90e6b
cf9b0cb) C:\WINDOWS\system32\DRIVER
S\tosrfnds
.sys
2010/08/06 15:18:47.0234 TosRfSnd (156d63f6898e4d95f2962f2b7
2862868) C:\WINDOWS\system32\driver
s\tosrfsnd
.sys
2010/08/06 15:18:47.0281 tosrfusb (01c90086cd37e7e8d9a827e24
167fcb7) C:\WINDOWS\system32\DRIVER
S\tosrfusb
.sys
2010/08/06 15:18:47.0359 Udfs (5787b80c2e3c5e2f56c2a233d
91fa2c9) C:\WINDOWS\system32\driver
s\Udfs.sys
2010/08/06 15:18:47.0421 Update (402ddc88356b1bac0ee3dd158
0c76a31) C:\WINDOWS\system32\DRIVER
S\update.s
ys
2010/08/06 15:18:47.0531 usbccgp (173f317ce0db8e21322e71b7e
60a27e8) C:\WINDOWS\system32\DRIVER
S\usbccgp.
sys
2010/08/06 15:18:47.0562 usbehci (65dcf09d0e37d4c6b11b5b0b7
6d470a7) C:\WINDOWS\system32\DRIVER
S\usbehci.
sys
2010/08/06 15:18:47.0578 usbhub (1ab3cdde553b6e064d2e754ef
e20285c) C:\WINDOWS\system32\DRIVER
S\usbhub.s
ys
2010/08/06 15:18:47.0609 usbstor (a32426d9b14a089eaa1d922e0
c5801a9) C:\WINDOWS\system32\DRIVER
S\USBSTOR.
SYS
2010/08/06 15:18:47.0625 usbuhci (26496f9dee2d787fc3e61ad54
821ffe6) C:\WINDOWS\system32\DRIVER
S\usbuhci.
sys
2010/08/06 15:18:47.0656 VgaSave (0d3a8fafceacd8b7625cd5497
57a7df1) C:\WINDOWS\System32\driver
s\vga.sys
2010/08/06 15:18:47.0703 VolSnap (4c8fcb5cc53aab716d810740f
e59d025) C:\WINDOWS\system32\driver
s\VolSnap.
sys
2010/08/06 15:18:47.0765 Wanarp (e20b95baedb550f32dd489265
c1da1f6) C:\WINDOWS\system32\DRIVER
S\wanarp.s
ys
2010/08/06 15:18:47.0796 wdmaud (6768acf64b18196494413695f
0c3a00f) C:\WINDOWS\system32\driver
s\wdmaud.s
ys
2010/08/06 15:18:48.0078 WudfPf (f15feafffbb3644ccc80c5da5
84e6311) C:\WINDOWS\system32\DRIVER
S\WudfPf.s
ys
2010/08/06 15:18:48.0109 WudfRd (28b524262bce6de1f7ef9f510
ba3985b) C:\WINDOWS\system32\DRIVER
S\wudfrd.s
ys
2010/08/06 15:18:48.0187 ==========================
==========
==========
==========
==========
==========
====
2010/08/06 15:18:48.0187 Scan finished
2010/08/06 15:18:48.0187 ==========================
==========
==========
==========
==========
==========
====
2010/08/06 15:18:48.0250 Detected object count: 1
2010/08/06 15:18:58.0765 IPSec (dfab325d623a1952d00182b19
3c9940a) C:\WINDOWS\system32\DRIVER
S\ipsec.sy
s
2010/08/06 15:18:58.0765 Suspicious file (Forged): C:\WINDOWS\system32\DRIVER
S\ipsec.sy
s. Real md5: dfab325d623a1952d00182b193
c9940a, Fake md5: 23c74d75e36e7158768dd63d92
789a91
2010/08/06 15:19:01.0656 Backup copy found, using it..
2010/08/06 15:19:01.0671 C:\WINDOWS\system32\DRIVER
S\ipsec.sy
s - will be cured after reboot
2010/08/06 15:19:01.0671 Rootkit.Win32.TDSS.tdl3(IP
Sec) - User select action: Cure
2010/08/06 15:19:06.0234 Deinitialize success
2nd TDSSKiller log file where it did not detect anything
2010/08/18 09:27:35.0531 TDSS rootkit removing tool 2.4.1.0 Aug 4 2010 15:06:41
2010/08/18 09:27:35.0531 ==========================
==========
==========
==========
==========
==========
====
2010/08/18 09:27:35.0531 SystemInfo:
2010/08/18 09:27:35.0531
2010/08/18 09:27:35.0531 OS Version: 5.1.2600 ServicePack: 3.0
2010/08/18 09:27:35.0531 Product type: Workstation
2010/08/18 09:27:35.0531 ComputerName: HULK
2010/08/18 09:27:35.0531 UserName: Hulk
2010/08/18 09:27:35.0531 Windows directory: C:\WINDOWS
2010/08/18 09:27:35.0531 System windows directory: C:\WINDOWS
2010/08/18 09:27:35.0546 Processor architecture: Intel x86
2010/08/18 09:27:35.0546 Number of processors: 2
2010/08/18 09:27:35.0546 Page size: 0x1000
2010/08/18 09:27:35.0546 Boot type: Normal boot
2010/08/18 09:27:35.0546 ==========================
==========
==========
==========
==========
==========
====
2010/08/18 09:27:36.0109 Initialize success
2010/08/18 09:27:37.0515 ==========================
==========
==========
==========
==========
==========
====
2010/08/18 09:27:37.0515 Scan started
2010/08/18 09:27:37.0515 Mode: Manual;
2010/08/18 09:27:37.0515 ==========================
==========
==========
==========
==========
==========
====
2010/08/18 09:27:39.0078 ACPI (8fd99680a539792a30e97944f
daecf17) C:\WINDOWS\system32\DRIVER
S\ACPI.sys
2010/08/18 09:27:39.0125 ACPIEC (9859c0f6936e723e4892d7141
b1327d5) C:\WINDOWS\system32\DRIVER
S\ACPIEC.s
ys
2010/08/18 09:27:39.0203 aec (8bed39e3c35d6a489438b8141
717a557) C:\WINDOWS\system32\driver
s\aec.sys
2010/08/18 09:27:39.0281 AFD (7e775010ef291da96ad17ca4b
17137d7) C:\WINDOWS\System32\driver
s\afd.sys
2010/08/18 09:27:39.0515 AR5416 (7d53e5646ba23fd51296f7ef8
979a000) C:\WINDOWS\system32\DRIVER
S\athw.sys
2010/08/18 09:27:39.0703 AsyncMac (b153affac761e7f5fcfa822b9
c4e97bc) C:\WINDOWS\system32\DRIVER
S\asyncmac
.sys
2010/08/18 09:27:39.0750 atapi (9f3a2f5aa6875c72bf062c712
cfa2674) C:\WINDOWS\system32\DRIVER
S\atapi.sy
s
2010/08/18 09:27:39.0937 ati2mtag (8763ede3e0cd40f5c3450571a
c57f205) C:\WINDOWS\system32\DRIVER
S\ati2mtag
.sys
2010/08/18 09:27:40.0031 Atmarpc (9916c1225104ba14794209cfa
8012159) C:\WINDOWS\system32\DRIVER
S\atmarpc.
sys
2010/08/18 09:27:40.0062 audstub (d9f724aa26c010a217c97606b
160ed68) C:\WINDOWS\system32\DRIVER
S\audstub.
sys
2010/08/18 09:27:40.0140 Beep (da1f27d85e0d1525f6621372e
7b685e9) C:\WINDOWS\system32\driver
s\Beep.sys
2010/08/18 09:27:40.0218 cbidf2k (90a673fc8e12a79afbed2576f
6a7aaf9) C:\WINDOWS\system32\driver
s\cbidf2k.
sys
2010/08/18 09:27:40.0281 Cdaudio (c1b486a7658353d33a10cc152
11a873b) C:\WINDOWS\system32\driver
s\Cdaudio.
sys
2010/08/18 09:27:40.0359 Cdfs (c885b02847f5d2fd45a24e219
ed93b32) C:\WINDOWS\system32\driver
s\Cdfs.sys
2010/08/18 09:27:40.0390 Cdrom (1f4260cc5b42272d71f79e570
a27a4fe) C:\WINDOWS\system32\DRIVER
S\cdrom.sy
s
2010/08/18 09:27:40.0453 cercsr6 (84853b3fd012251690570e9e7
e43343f) C:\WINDOWS\system32\driver
s\cercsr6.
sys
2010/08/18 09:27:40.0703 DeepFrz (4e81e22588a6cd946a1f4378c
791a336) C:\WINDOWS\system32\driver
s\DeepFrz.
sys
2010/08/18 09:27:40.0828 Disk (044452051f3e02e7963599fc8
f4f3e25) C:\WINDOWS\system32\DRIVER
S\disk.sys
2010/08/18 09:27:41.0062 dmboot (d992fe1274bde0f84ad826aca
e022a41) C:\WINDOWS\system32\driver
s\dmboot.s
ys
2010/08/18 09:27:41.0296 dmio (7c824cf7bbde77d95c0800571
7a95f6f) C:\WINDOWS\system32\driver
s\dmio.sys
2010/08/18 09:27:41.0312 dmload (e9317282a63ca4d188c0df5e0
9c6ac5f) C:\WINDOWS\system32\driver
s\dmload.s
ys
2010/08/18 09:27:41.0359 DMusic (8a208dfcf89792a484e76c40e
5f50b45) C:\WINDOWS\system32\driver
s\DMusic.s
ys
2010/08/18 09:27:41.0468 drmkaud (8f5fcff8e8848afac920905fb
d9d33c8) C:\WINDOWS\system32\driver
s\drmkaud.
sys
2010/08/18 09:27:41.0640 Fastfat (38d332a6d56af32635675f132
548343e) C:\WINDOWS\system32\driver
s\Fastfat.
sys
2010/08/18 09:27:41.0687 Fdc (92cdd60b6730b9f50f6a1a0c1
f8cdc81) C:\WINDOWS\system32\driver
s\Fdc.sys
2010/08/18 09:27:41.0703 Fips (d45926117eb9fa946a6af572f
be1caa3) C:\WINDOWS\system32\driver
s\Fips.sys
2010/08/18 09:27:41.0734 Flpydisk (9d27e7b80bfcdf1cdd9b55586
2d5e7f0) C:\WINDOWS\system32\driver
s\Flpydisk
.sys
2010/08/18 09:27:41.0765 FltMgr (b2cf4b0786f8212cb92ed2b50
c6db6b0) C:\WINDOWS\system32\driver
s\fltmgr.s
ys
2010/08/18 09:27:41.0843 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2b
cc2779a) C:\WINDOWS\system32\driver
s\Fs_Rec.s
ys
2010/08/18 09:27:41.0859 Ftdisk (6ac26732762483366c3969c9e
4d2259d) C:\WINDOWS\system32\DRIVER
S\ftdisk.s
ys
2010/08/18 09:27:41.0937 genmcmnUSB (86f732d2995ada73fd307539e
c266d3a) C:\WINDOWS\system32\DRIVER
S\gflmouhi
d.sys
2010/08/18 09:27:41.0968 Gpc (0a02c63c8b144bd8c86b103de
e7c86a2) C:\WINDOWS\system32\DRIVER
S\msgpc.sy
s
2010/08/18 09:27:42.0000 HDAudBus (573c7d0a32852b48f3058cfd8
026f511) C:\WINDOWS\system32\DRIVER
S\HDAudBus
.sys
2010/08/18 09:27:42.0046 hidusb (ccf82c5ec8a7326c3066de870
c06daf1) C:\WINDOWS\system32\DRIVER
S\hidusb.s
ys
2010/08/18 09:27:42.0140 HTTP (f80a415ef82cd06ffaf0d9715
28ead38) C:\WINDOWS\system32\Driver
s\HTTP.sys
2010/08/18 09:27:42.0203 i8042prt (4a0b06aa8943c1e332520f744
0c0aa30) C:\WINDOWS\system32\DRIVER
S\i8042prt
.sys
2010/08/18 09:27:42.0265 Imapi (083a052659f5310dd8b6a6cb0
5edcf8e) C:\WINDOWS\system32\DRIVER
S\imapi.sy
s
2010/08/18 09:27:42.0546 IntcAzAudAddService (2b7ce5e35c5e279b77cc10a4c
70f24df) C:\WINDOWS\system32\driver
s\RtkHDAud
.sys
2010/08/18 09:27:42.0640 intelppm (8c953733d8f36eb2133f5bb58
808b66b) C:\WINDOWS\system32\DRIVER
S\intelppm
.sys
2010/08/18 09:27:42.0703 Ip6Fw (3bb22519a194418d5fec05d80
0a19ad0) C:\WINDOWS\system32\driver
s\ip6fw.sy
s
2010/08/18 09:27:42.0734 IpFilterDriver (731f22ba402ee4b62748adaf6
363c182) C:\WINDOWS\system32\DRIVER
S\ipfltdrv
.sys
2010/08/18 09:27:42.0765 IpInIp (b87ab476dcf76e72010632b55
50955f5) C:\WINDOWS\system32\DRIVER
S\ipinip.s
ys
2010/08/18 09:27:42.0812 IpNat (cc748ea12c6effde940ee9809
8bf96bb) C:\WINDOWS\system32\DRIVER
S\ipnat.sy
s
2010/08/18 09:27:42.0843 IPSec (23c74d75e36e7158768dd63d9
2789a91) C:\WINDOWS\system32\DRIVER
S\ipsec.sy
s
2010/08/18 09:27:42.0890 IRENUM (c93c9ff7b04d772627a3646d8
9f7bf89) C:\WINDOWS\system32\DRIVER
S\irenum.s
ys
2010/08/18 09:27:42.0953 isapnp (05a299ec56e52649b1cf2fc52
d20f2d7) C:\WINDOWS\system32\DRIVER
S\isapnp.s
ys
2010/08/18 09:27:42.0968 Kbdclass (463c1ec80cd17420a542b7f36
a36f128) C:\WINDOWS\system32\DRIVER
S\kbdclass
.sys
2010/08/18 09:27:43.0000 kbdhid (9ef487a186dea361aa06913a7
5b3fa99) C:\WINDOWS\system32\DRIVER
S\kbdhid.s
ys
2010/08/18 09:27:43.0031 kmixer (692bcf44383d056aed41b045a
323d378) C:\WINDOWS\system32\driver
s\kmixer.s
ys
2010/08/18 09:27:43.0109 KSecDD (b467646c54cc746128904e165
4c750c1) C:\WINDOWS\system32\driver
s\KSecDD.s
ys
2010/08/18 09:27:43.0250 mnmdd (4ae068242760a1fb6e1a44bf4
e16afa6) C:\WINDOWS\system32\driver
s\mnmdd.sy
s
2010/08/18 09:27:43.0296 Modem (dfcbad3cec1c5f964962ae10e
0bcc8e1) C:\WINDOWS\system32\driver
s\Modem.sy
s
2010/08/18 09:27:43.0343 Mouclass (35c9e97194c8cfb8430125f8d
bc34d04) C:\WINDOWS\system32\DRIVER
S\mouclass
.sys
2010/08/18 09:27:43.0421 mouhid (b1c303e17fb9d46e87a98e4ba
6769685) C:\WINDOWS\system32\DRIVER
S\mouhid.s
ys
2010/08/18 09:27:43.0453 MountMgr (a80b9a0bad1b73637dbcbba7d
f72d3fd) C:\WINDOWS\system32\driver
s\MountMgr
.sys
2010/08/18 09:27:43.0500 MRxDAV (11d42bb6206f33fbb3ba0288d
3ef81bd) C:\WINDOWS\system32\DRIVER
S\mrxdav.s
ys
2010/08/18 09:27:43.0593 MRxSmb (f3aefb11abc521122b6709504
4169e98) C:\WINDOWS\system32\DRIVER
S\mrxsmb.s
ys
2010/08/18 09:27:43.0734 Msfs (c941ea2454ba8350021d774da
f0f1027) C:\WINDOWS\system32\driver
s\Msfs.sys
2010/08/18 09:27:43.0796 MSKSSRV (d1575e71568f4d9e14ca56b7b
0453bf1) C:\WINDOWS\system32\driver
s\MSKSSRV.
sys
2010/08/18 09:27:43.0890 MSPCLOCK (325bb26842fc7ccc1fcce2c45
7317f3e) C:\WINDOWS\system32\driver
s\MSPCLOCK
.sys
2010/08/18 09:27:43.0906 MSPQM (bad59648ba099da4a17680b39
730cb3d) C:\WINDOWS\system32\driver
s\MSPQM.sy
s
2010/08/18 09:27:43.0968 mssmbios (af5f4f3f14a8ea2c26de30f7a
1e17136) C:\WINDOWS\system32\DRIVER
S\mssmbios
.sys
2010/08/18 09:27:44.0046 MTsensor (d48659bb24c48345d926ecb45
c1ebdf5) C:\WINDOWS\system32\DRIVER
S\ASACPI.s
ys
2010/08/18 09:27:44.0078 Mup (2f625d11385b1a94360bfc70a
aefdee1) C:\WINDOWS\system32\driver
s\Mup.sys
2010/08/18 09:27:44.0125 NDIS (1df7f42665c94b825322fae71
721130d) C:\WINDOWS\system32\driver
s\NDIS.sys
2010/08/18 09:27:44.0156 NdisTapi (1ab3d00c991ab086e69db84b6
c0ed78f) C:\WINDOWS\system32\DRIVER
S\ndistapi
.sys
2010/08/18 09:27:44.0187 Ndisuio (f927a4434c5028758a842943e
f1a3849) C:\WINDOWS\system32\DRIVER
S\ndisuio.
sys
2010/08/18 09:27:44.0218 NdisWan (edc1531a49c80614b2cfda43c
a8659ab) C:\WINDOWS\system32\DRIVER
S\ndiswan.
sys
2010/08/18 09:27:44.0250 NDProxy (6215023940cfd3702b46abc30
4e1d45a) C:\WINDOWS\system32\driver
s\NDProxy.
sys
2010/08/18 09:27:44.0296 NetBIOS (5d81cf9a2f1a3a756b66cf684
911cdf0) C:\WINDOWS\system32\DRIVER
S\netbios.
sys
2010/08/18 09:27:44.0328 NetBT (74b2b2f5bea5e9a3dc021d685
551bd3d) C:\WINDOWS\system32\DRIVER
S\netbt.sy
s
2010/08/18 09:27:44.0421 Npfs (3182d64ae053d6fb034f44b6d
ef8034a) C:\WINDOWS\system32\driver
s\Npfs.sys
2010/08/18 09:27:44.0484 Ntfs (78a08dd6a8d65e697c18e1db0
1c5cdca) C:\WINDOWS\system32\driver
s\Ntfs.sys
2010/08/18 09:27:44.0546 Null (73c1e1f395918bc2c6dd67af7
591a3ad) C:\WINDOWS\system32\driver
s\Null.sys
2010/08/18 09:27:44.0656 NwlnkFlt (b305f3fad35083837ef46a0bb
ce2fc57) C:\WINDOWS\system32\DRIVER
S\nwlnkflt
.sys
2010/08/18 09:27:44.0687 NwlnkFwd (c99b3415198d1aab7227f2c88
fd664b9) C:\WINDOWS\system32\DRIVER
S\nwlnkfwd
.sys
2010/08/18 09:27:44.0796 Parport (5575faf8f97ce5e713d108c2a
58d7c7c) C:\WINDOWS\system32\driver
s\Parport.
sys
2010/08/18 09:27:44.0875 PartMgr (beb3ba25197665d82ec7065b7
24171c6) C:\WINDOWS\system32\driver
s\PartMgr.
sys
2010/08/18 09:27:44.0921 ParVdm (70e98b3fd8e963a6a46a2e624
7e0bea1) C:\WINDOWS\system32\driver
s\ParVdm.s
ys
2010/08/18 09:27:44.0937 PCI (a219903ccf74233761d92bef4
71a07b1) C:\WINDOWS\system32\DRIVER
S\pci.sys
2010/08/18 09:27:44.0984 PCIIde (ccf5f451bb1a5a2a522a76e67
0000ff0) C:\WINDOWS\system32\DRIVER
S\pciide.s
ys
2010/08/18 09:27:45.0015 Pcmcia (9e89ef60e9ee05e3f2eef2da7
397f1c1) C:\WINDOWS\system32\driver
s\Pcmcia.s
ys
2010/08/18 09:27:45.0250 PptpMiniport (efeec01b1d3cf84f16ddd24d9
d9d8f99) C:\WINDOWS\system32\DRIVER
S\raspptp.
sys
2010/08/18 09:27:45.0281 PSched (09298ec810b07e5d582cb3a3f
9255424) C:\WINDOWS\system32\DRIVER
S\psched.s
ys
2010/08/18 09:27:45.0312 Ptilink (80d317bd1c3dbc5d4fe7b1678
c60cadd) C:\WINDOWS\system32\DRIVER
S\ptilink.
sys
2010/08/18 09:27:45.0421 RasAcd (fe0d99d6f31e4fad8159f690d
68ded9c) C:\WINDOWS\system32\DRIVER
S\rasacd.s
ys
2010/08/18 09:27:45.0453 Rasl2tp (11b4a627bc9614b885c4969bf
a5ff8a6) C:\WINDOWS\system32\DRIVER
S\rasl2tp.
sys
2010/08/18 09:27:45.0484 RasPppoe (5bc962f2654137c9909c3d460
3587dee) C:\WINDOWS\system32\DRIVER
S\raspppoe
.sys
2010/08/18 09:27:45.0515 Raspti (fdbb1d60066fcfbb7452fd8f9
829b242) C:\WINDOWS\system32\DRIVER
S\raspti.s
ys
2010/08/18 09:27:45.0546 Rdbss (7ad224ad1a1437fe28d89cf22
b17780a) C:\WINDOWS\system32\DRIVER
S\rdbss.sy
s
2010/08/18 09:27:45.0578 RDPCDD (4912d5b403614ce99c28420f7
5353332) C:\WINDOWS\system32\DRIVER
S\RDPCDD.s
ys
2010/08/18 09:27:45.0640 rdpdr (15cabd0f7c00c47c701249079
16af3f1) C:\WINDOWS\system32\DRIVER
S\rdpdr.sy
s
2010/08/18 09:27:45.0703 RDPWD (6728e45b66f93c08f11de2e31
6fc70dd) C:\WINDOWS\system32\driver
s\RDPWD.sy
s
2010/08/18 09:27:45.0765 redbook (f828dd7e1419b6653894a8f97
a0094c5) C:\WINDOWS\system32\DRIVER
S\redbook.
sys
2010/08/18 09:27:46.0000 RSUSBSTOR (2cb299f6cc04bac8889a52b0f
f48a9d7) C:\WINDOWS\system32\Driver
s\RTS5121.
sys
2010/08/18 09:27:46.0218 RTHDMIAzAudService (a5a9f4b77d7ff2b02633999ff
71a7e9b) C:\WINDOWS\system32\driver
s\RtKHDMI.
sys
2010/08/18 09:27:46.0421 RTLE8023xp (185641ad7e80bfce0aa545d3e
c79d557) C:\WINDOWS\system32\DRIVER
S\Rtenicxp
.sys
2010/08/18 09:27:46.0625 Secdrv (90a3935d05b494a5a39d37e71
f09a677) C:\WINDOWS\system32\DRIVER
S\secdrv.s
ys
2010/08/18 09:27:46.0703 Serial (cca207a8896d4c6a0c9ce29a4
ae411a7) C:\WINDOWS\system32\driver
s\Serial.s
ys
2010/08/18 09:27:46.0750 Sfloppy (8e6b8c671615d126fdc553d1e
2de5562) C:\WINDOWS\system32\driver
s\Sfloppy.
sys
2010/08/18 09:27:46.0875 splitter (ab8b92451ecb048a4d1de7c3f
fcb4a9f) C:\WINDOWS\system32\driver
s\splitter
.sys
2010/08/18 09:27:46.0906 sr (76bb022c2fb6902fd5bdd4f78
fc13a5d) C:\WINDOWS\system32\DRIVER
S\sr.sys
2010/08/18 09:27:46.0984 Srv (da852e3e0bf1cea75d756f986
6241e57) C:\WINDOWS\system32\DRIVER
S\srv.sys
2010/08/18 09:27:47.0062 swenum (3941d127aef12e93addf6fe6e
e027e0f) C:\WINDOWS\system32\DRIVER
S\swenum.s
ys
2010/08/18 09:27:47.0093 swmidi (8ce882bcc6cf8a62f2b2323d9
5cb3d01) C:\WINDOWS\system32\driver
s\swmidi.s
ys
2010/08/18 09:27:47.0218 sysaudio (8b83f3ed0f1688b4958f77cd6
d2bf290) C:\WINDOWS\system32\driver
s\sysaudio
.sys
2010/08/18 09:27:47.0328 Tcpip (9aefa14bd6b182d61e3119fa5
f436d3d) C:\WINDOWS\system32\DRIVER
S\tcpip.sy
s
2010/08/18 09:27:47.0406 TDPIPE (6471a66807f5e104e4885f5b6
7349397) C:\WINDOWS\system32\driver
s\TDPIPE.s
ys
2010/08/18 09:27:47.0437 TDTCP (c56b6d0402371cf3700eb322e
f3aaf61) C:\WINDOWS\system32\driver
s\TDTCP.sy
s
2010/08/18 09:27:47.0468 TermDD (8815524717763804842289373
7429d9e) C:\WINDOWS\system32\DRIVER
S\termdd.s
ys
2010/08/18 09:27:47.0656 tosporte (8d624d3bd1f2d78bd1c01a2d4
e954b4e) C:\WINDOWS\system32\DRIVER
S\tosporte
.sys
2010/08/18 09:27:47.0734 tosrfbd (73abec184a36239ca0a7dc96c
7e74c44) C:\WINDOWS\system32\DRIVER
S\tosrfbd.
sys
2010/08/18 09:27:47.0750 tosrfbnp (181e217a7a326817d97946d04
5b3cb46) C:\WINDOWS\system32\Driver
s\tosrfbnp
.sys
2010/08/18 09:27:47.0828 Tosrfcom (e90ace3b4fa7a85f992bc21eb
779c407) C:\WINDOWS\system32\Driver
s\tosrfcom
.sys
2010/08/18 09:27:47.0859 Tosrfhid (87700714f25131ed21901d617
b8b321f) C:\WINDOWS\system32\DRIVER
S\Tosrfhid
.sys
2010/08/18 09:27:47.0890 tosrfnds (c52fd27b9adf3a1f22cb90e6b
cf9b0cb) C:\WINDOWS\system32\DRIVER
S\tosrfnds
.sys
2010/08/18 09:27:47.0937 TosRfSnd (156d63f6898e4d95f2962f2b7
2862868) C:\WINDOWS\system32\driver
s\tosrfsnd
.sys
2010/08/18 09:27:48.0000 tosrfusb (01c90086cd37e7e8d9a827e24
167fcb7) C:\WINDOWS\system32\DRIVER
S\tosrfusb
.sys
2010/08/18 09:27:48.0062 Udfs (5787b80c2e3c5e2f56c2a233d
91fa2c9) C:\WINDOWS\system32\driver
s\Udfs.sys
2010/08/18 09:27:48.0156 Update (402ddc88356b1bac0ee3dd158
0c76a31) C:\WINDOWS\system32\DRIVER
S\update.s
ys
2010/08/18 09:27:48.0250 usbccgp (173f317ce0db8e21322e71b7e
60a27e8) C:\WINDOWS\system32\DRIVER
S\usbccgp.
sys
2010/08/18 09:27:48.0296 usbehci (65dcf09d0e37d4c6b11b5b0b7
6d470a7) C:\WINDOWS\system32\DRIVER
S\usbehci.
sys
2010/08/18 09:27:48.0328 usbhub (1ab3cdde553b6e064d2e754ef
e20285c) C:\WINDOWS\system32\DRIVER
S\usbhub.s
ys
2010/08/18 09:27:48.0359 usbstor (a32426d9b14a089eaa1d922e0
c5801a9) C:\WINDOWS\system32\DRIVER
S\USBSTOR.
SYS
2010/08/18 09:27:48.0375 usbuhci (26496f9dee2d787fc3e61ad54
821ffe6) C:\WINDOWS\system32\DRIVER
S\usbuhci.
sys
2010/08/18 09:27:48.0421 VgaSave (0d3a8fafceacd8b7625cd5497
57a7df1) C:\WINDOWS\System32\driver
s\vga.sys
2010/08/18 09:27:48.0468 VolSnap (4c8fcb5cc53aab716d810740f
e59d025) C:\WINDOWS\system32\driver
s\VolSnap.
sys
2010/08/18 09:27:48.0531 Wanarp (e20b95baedb550f32dd489265
c1da1f6) C:\WINDOWS\system32\DRIVER
S\wanarp.s
ys
2010/08/18 09:27:48.0593 wdmaud (6768acf64b18196494413695f
0c3a00f) C:\WINDOWS\system32\driver
s\wdmaud.s
ys
2010/08/18 09:27:48.0843 WudfPf (f15feafffbb3644ccc80c5da5
84e6311) C:\WINDOWS\system32\DRIVER
S\WudfPf.s
ys
2010/08/18 09:27:48.0859 WudfRd (28b524262bce6de1f7ef9f510
ba3985b) C:\WINDOWS\system32\DRIVER
S\wudfrd.s
ys
2010/08/18 09:27:48.0953 ==========================
==========
==========
==========
==========
==========
====
2010/08/18 09:27:48.0953 Scan finished
2010/08/18 09:27:48.0953 ==========================
==========
==========
==========
==========
==========
====
2010/08/18 09:27:54.0218 Deinitialize success
Thanks again!!
Answer : HP printer won't print, Dell printer will - This is after being attacked by TDSS
If you're server is 64bit get the 64bit, if it's 32bit get the 32bit.
As well as other stuff the following that you mention should be installed for WSUS to work.
ASP.net
.net extensibility
isapi filters
windows authentication
Request Filtering
Here's a great walk through to get it up and running. Print it off and read it over.
http://www.microsoft.com/d
ownloads/d
etails.asp
x?
FamilyID
=df628245-
8449-4b93-
948c-0926d
eb1197a&di
splaylang=
en
If you have more questions/issues feel free to ask, no problem.
-Jeff
Random Solutions
windows 7 home password policy
Connect to exchange using FVS318 VPN Firewall
ASP.Net -- add a ScriptManager and get "Failed to load source for:
http://localhost:63366/pub
Copying the shade of diagram into a table cell
Remove Old AD Computer Account via Command Line
Named anchor tags in IE
Speed of Select query is very slow
ASA 5505 DMZ won't Access Internet
Trying to connect to the server using Microsoft SQL Server Management Studio
FAXCOOLWAREZ037 192.168.1.38 00-1A-73-C3-39-8A