Fake AntiVirus Program 2012

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by VeryScary, Jan 19, 2012.

  1. VeryScary

    VeryScary Private E-2

    The fake antivirus came up yesterday, so I ran Malwarebytes. It seemed to work, everything was clear and working fine. Now the virus has completely taken over my computer. I can no longer run Malwarebytes. I even tried changing the name. I get this error message:
    Run-time error 372: Failed to load control 'vbalGrid" from vbalsgrid6.ocx. Your version of vbalsgrid6.ocx may be outdated.
    So there's no log from Malwarebytes.

    The fake program doesn't show up anymore. I can not connect to the internet. The start menu is gone. My background has been changed. I can move or copy files. Nothing shows up in the services folder. I can't use system restore, not even with the command line. I get this error message:
    System Restore is not able to protect your computer. Please restart your computer, and then run System restore again.

    I can get to the run prompt by using ctrl alt del
    I've been moving files around by right clicking, and then click ad to **** .rar, then unzip to location
     

    Attached Files:

  2. VeryScary

    VeryScary Private E-2

    I forgot to mention that I ran TDSSKILLER before all of this
     

    Attached Files:

  3. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, VeryScary!

    I'm afraid I have some bad news :(
    One of your TDSSKiller logs shows the below:

    TDSSKiller.2.7.5.0_18.01.2012_22.46.19_log.txt
    Code:
    22:47:10.0015 0916	Detected object count: [B][COLOR="Red"]134[/COLOR][/B]
    22:47:10.0015 0916	Actual detected object count: [B][COLOR="Red"]134[/COLOR][/B]
    22:47:47.0984 0916	C:\WINDOWS\system32\DRIVERS\ACPI.sys - copied to quarantine
    22:47:47.0984 0916	ACPI ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0062 0916	C:\WINDOWS\system32\drivers\ACPIEC.sys - copied to quarantine
    22:47:48.0062 0916	ACPIEC ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0171 0916	C:\WINDOWS\system32\drivers\aec.sys - copied to quarantine
    22:47:48.0171 0916	aec ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0250 0916	C:\WINDOWS\system32\DRIVERS\AegisP.sys - copied to quarantine
    22:47:48.0250 0916	AegisP ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0359 0916	C:\WINDOWS\System32\drivers\afd.sys - copied to quarantine
    22:47:48.0359 0916	AFD ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0515 0916	C:\WINDOWS\system32\DRIVERS\asyncmac.sys - copied to quarantine
    22:47:48.0515 0916	AsyncMac ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0562 0916	C:\WINDOWS\system32\DRIVERS\atapi.sys - copied to quarantine
    22:47:48.0562 0916	atapi ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0625 0916	C:\WINDOWS\system32\DRIVERS\atmarpc.sys - copied to quarantine
    22:47:48.0625 0916	Atmarpc ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0703 0916	C:\WINDOWS\system32\DRIVERS\audstub.sys - copied to quarantine
    22:47:48.0703 0916	audstub ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0796 0916	C:\WINDOWS\system32\drivers\Beep.sys - copied to quarantine
    22:47:48.0796 0916	Beep ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0828 0916	C:\WINDOWS\system32\drivers\cbidf2k.sys - copied to quarantine
    22:47:48.0828 0916	cbidf2k ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0906 0916	C:\WINDOWS\system32\DRIVERS\CCDECODE.sys - copied to quarantine
    22:47:48.0906 0916	CCDECODE ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:48.0968 0916	C:\WINDOWS\system32\drivers\Cdaudio.sys - copied to quarantine
    22:47:48.0968 0916	Cdaudio ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0000 0916	C:\WINDOWS\system32\drivers\Cdfs.sys - copied to quarantine
    22:47:49.0000 0916	Cdfs ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0046 0916	C:\WINDOWS\system32\DRIVERS\cdrom.sys - copied to quarantine
    22:47:49.0046 0916	Cdrom ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0109 0916	C:\WINDOWS\system32\DRIVERS\disk.sys - copied to quarantine
    22:47:49.0109 0916	Disk ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0218 0916	C:\WINDOWS\system32\drivers\dmboot.sys - copied to quarantine
    22:47:49.0218 0916	dmboot ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0296 0916	C:\WINDOWS\system32\drivers\dmio.sys - copied to quarantine
    22:47:49.0296 0916	dmio ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0328 0916	C:\WINDOWS\system32\drivers\dmload.sys - copied to quarantine
    22:47:49.0328 0916	dmload ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0468 0916	C:\WINDOWS\system32\drivers\DMusic.sys - copied to quarantine
    22:47:49.0468 0916	DMusic ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0562 0916	C:\WINDOWS\system32\DNINDIS5.SYS - copied to quarantine
    22:47:49.0562 0916	DNINDIS5 ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0625 0916	C:\WINDOWS\system32\drivers\drmkaud.sys - copied to quarantine
    22:47:49.0625 0916	drmkaud ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0687 0916	C:\WINDOWS\system32\drivers\Fastfat.sys - copied to quarantine
    22:47:49.0687 0916	Fastfat ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0750 0916	C:\WINDOWS\system32\DRIVERS\fdc.sys - copied to quarantine
    22:47:49.0750 0916	Fdc ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0843 0916	C:\WINDOWS\system32\drivers\Fips.sys - copied to quarantine
    22:47:49.0843 0916	Fips ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0875 0916	C:\WINDOWS\system32\DRIVERS\flpydisk.sys - copied to quarantine
    22:47:49.0875 0916	Flpydisk ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:49.0937 0916	C:\WINDOWS\system32\DRIVERS\fltMgr.sys - copied to quarantine
    22:47:49.0937 0916	FltMgr ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0062 0916	C:\WINDOWS\system32\drivers\Fs_Rec.sys - copied to quarantine
    22:47:50.0062 0916	Fs_Rec ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0093 0916	C:\WINDOWS\system32\DRIVERS\ftdisk.sys - copied to quarantine
    22:47:50.0093 0916	Ftdisk ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0140 0916	C:\WINDOWS\system32\DRIVERS\msgpc.sys - copied to quarantine
    22:47:50.0140 0916	Gpc ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0171 0916	C:\WINDOWS\system32\DRIVERS\HDAudBus.sys - copied to quarantine
    22:47:50.0171 0916	HDAudBus ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0250 0916	C:\WINDOWS\system32\DRIVERS\hidusb.sys - copied to quarantine
    22:47:50.0250 0916	hidusb ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0453 0916	C:\WINDOWS\system32\Drivers\HTTP.sys - copied to quarantine
    22:47:50.0453 0916	HTTP ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0500 0916	C:\WINDOWS\system32\drivers\i8042prt.sys - copied to quarantine
    22:47:50.0500 0916	i8042prt ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0562 0916	C:\WINDOWS\system32\DRIVERS\imapi.sys - copied to quarantine
    22:47:50.0562 0916	Imapi ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0640 0916	C:\WINDOWS\system32\DRIVERS\intelppm.sys - copied to quarantine
    22:47:50.0640 0916	intelppm ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0687 0916	C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys - copied to quarantine
    22:47:50.0687 0916	Ip6Fw ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0781 0916	C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys - copied to quarantine
    22:47:50.0781 0916	IpFilterDriver ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0875 0916	C:\WINDOWS\system32\DRIVERS\ipinip.sys - copied to quarantine
    22:47:50.0875 0916	IpInIp ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:50.0937 0916	C:\WINDOWS\system32\DRIVERS\ipnat.sys - copied to quarantine
    22:47:50.0937 0916	IpNat ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0000 0916	C:\WINDOWS\system32\DRIVERS\ipsec.sys - copied to quarantine
    22:47:51.0000 0916	IPSec ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0078 0916	C:\WINDOWS\system32\DRIVERS\irenum.sys - copied to quarantine
    22:47:51.0078 0916	IRENUM ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0203 0916	C:\WINDOWS\system32\DRIVERS\isapnp.sys - copied to quarantine
    22:47:51.0203 0916	isapnp ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0437 0916	C:\WINDOWS\system32\DRIVERS\kbdclass.sys - copied to quarantine
    22:47:51.0437 0916	Kbdclass ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0515 0916	C:\WINDOWS\system32\DRIVERS\kbdhid.sys - copied to quarantine
    22:47:51.0515 0916	kbdhid ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0640 0916	C:\WINDOWS\system32\drivers\kmixer.sys - copied to quarantine
    22:47:51.0640 0916	kmixer ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0718 0916	C:\WINDOWS\system32\drivers\KSecDD.sys - copied to quarantine
    22:47:51.0718 0916	KSecDD ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0812 0916	C:\WINDOWS\system32\drivers\mnmdd.sys - copied to quarantine
    22:47:51.0812 0916	mnmdd ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0875 0916	C:\WINDOWS\system32\drivers\Modem.sys - copied to quarantine
    22:47:51.0875 0916	Modem ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0921 0916	C:\WINDOWS\system32\DRIVERS\mouclass.sys - copied to quarantine
    22:47:51.0921 0916	Mouclass ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:51.0968 0916	C:\WINDOWS\system32\DRIVERS\mouhid.sys - copied to quarantine
    22:47:51.0968 0916	mouhid ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0000 0916	C:\WINDOWS\system32\drivers\MountMgr.sys - copied to quarantine
    22:47:52.0000 0916	MountMgr ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0046 0916	C:\WINDOWS\system32\DRIVERS\mrxdav.sys - copied to quarantine
    22:47:52.0046 0916	MRxDAV ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0125 0916	C:\WINDOWS\system32\DRIVERS\mrxsmb.sys - copied to quarantine
    22:47:52.0125 0916	MRxSmb ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0203 0916	C:\WINDOWS\system32\drivers\Msfs.sys - copied to quarantine
    22:47:52.0203 0916	Msfs ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0265 0916	C:\WINDOWS\system32\drivers\MSKSSRV.sys - copied to quarantine
    22:47:52.0265 0916	MSKSSRV ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0453 0916	C:\WINDOWS\system32\drivers\MSPCLOCK.sys - copied to quarantine
    22:47:52.0453 0916	MSPCLOCK ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0734 0916	C:\WINDOWS\system32\drivers\MSPQM.sys - copied to quarantine
    22:47:52.0734 0916	MSPQM ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:52.0953 0916	C:\WINDOWS\system32\DRIVERS\mssmbios.sys - copied to quarantine
    22:47:52.0953 0916	mssmbios ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0140 0916	C:\WINDOWS\system32\drivers\MSTEE.sys - copied to quarantine
    22:47:53.0140 0916	MSTEE ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0265 0916	C:\WINDOWS\system32\drivers\Mup.sys - copied to quarantine
    22:47:53.0265 0916	Mup ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0328 0916	C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys - copied to quarantine
    22:47:53.0328 0916	NABTSFEC ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0515 0916	C:\WINDOWS\system32\drivers\NDIS.sys - copied to quarantine
    22:47:53.0515 0916	NDIS ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0609 0916	C:\WINDOWS\system32\DRIVERS\NdisIP.sys - copied to quarantine
    22:47:53.0609 0916	NdisIP ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0718 0916	C:\WINDOWS\system32\DRIVERS\ndistapi.sys - copied to quarantine
    22:47:53.0718 0916	NdisTapi ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0765 0916	C:\WINDOWS\system32\DRIVERS\ndisuio.sys - copied to quarantine
    22:47:53.0765 0916	Ndisuio ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0812 0916	C:\WINDOWS\system32\DRIVERS\ndiswan.sys - copied to quarantine
    22:47:53.0812 0916	NdisWan ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0875 0916	C:\WINDOWS\system32\drivers\NDProxy.sys - copied to quarantine
    22:47:53.0875 0916	NDProxy ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0937 0916	C:\WINDOWS\system32\DRIVERS\netbios.sys - copied to quarantine
    22:47:53.0937 0916	NetBIOS ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:53.0984 0916	C:\WINDOWS\system32\DRIVERS\netbt.sys - copied to quarantine
    22:47:54.0000 0916	NetBT ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:54.0031 0916	C:\WINDOWS\system32\drivers\Npfs.sys - copied to quarantine
    22:47:54.0031 0916	Npfs ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:54.0093 0916	C:\WINDOWS\system32\drivers\Ntfs.sys - copied to quarantine
    22:47:54.0093 0916	Ntfs ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:54.0234 0916	C:\WINDOWS\system32\drivers\Null.sys - copied to quarantine
    22:47:54.0234 0916	Null ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0093 0916	C:\WINDOWS\system32\DRIVERS\nv4_mini.sys - copied to quarantine
    22:47:55.0093 0916	nv ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0421 0916	C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys - copied to quarantine
    22:47:55.0421 0916	NwlnkFlt ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0500 0916	C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys - copied to quarantine
    22:47:55.0500 0916	NwlnkFwd ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0640 0916	C:\WINDOWS\system32\drivers\Parport.sys - copied to quarantine
    22:47:55.0640 0916	Parport ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0703 0916	C:\WINDOWS\system32\drivers\PartMgr.sys - copied to quarantine
    22:47:55.0703 0916	PartMgr ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0828 0916	C:\WINDOWS\system32\drivers\ParVdm.sys - copied to quarantine
    22:47:55.0828 0916	ParVdm ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0906 0916	C:\WINDOWS\system32\DRIVERS\pci.sys - copied to quarantine
    22:47:55.0906 0916	PCI ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:55.0984 0916	C:\WINDOWS\system32\DRIVERS\pciide.sys - copied to quarantine
    22:47:55.0984 0916	PCIIde ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0046 0916	C:\WINDOWS\system32\drivers\Pcmcia.sys - copied to quarantine
    22:47:56.0046 0916	Pcmcia ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0218 0916	C:\WINDOWS\system32\Drivers\pcouffin.sys - copied to quarantine
    22:47:56.0218 0916	pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0281 0916	C:\WINDOWS\system32\DRIVERS\raspptp.sys - copied to quarantine
    22:47:56.0281 0916	PptpMiniport ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0328 0916	C:\WINDOWS\system32\DRIVERS\psched.sys - copied to quarantine
    22:47:56.0328 0916	PSched ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0468 0916	C:\WINDOWS\system32\DRIVERS\ptilink.sys - copied to quarantine
    22:47:56.0468 0916	Ptilink ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0515 0916	C:\WINDOWS\system32\DRIVERS\rasacd.sys - copied to quarantine
    22:47:56.0515 0916	RasAcd ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0703 0916	C:\WINDOWS\system32\DRIVERS\rasl2tp.sys - copied to quarantine
    22:47:56.0703 0916	Rasl2tp ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0750 0916	C:\WINDOWS\system32\DRIVERS\raspppoe.sys - copied to quarantine
    22:47:56.0750 0916	RasPppoe ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0812 0916	C:\WINDOWS\system32\DRIVERS\raspti.sys - copied to quarantine
    22:47:56.0828 0916	Raspti ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0906 0916	C:\WINDOWS\system32\DRIVERS\rdbss.sys - copied to quarantine
    22:47:56.0906 0916	Rdbss ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:56.0968 0916	C:\WINDOWS\system32\DRIVERS\RDPCDD.sys - copied to quarantine
    22:47:56.0968 0916	RDPCDD ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:57.0046 0916	C:\WINDOWS\system32\DRIVERS\rdpdr.sys - copied to quarantine
    22:47:57.0046 0916	rdpdr ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:57.0171 0916	C:\WINDOWS\system32\drivers\RDPWD.sys - copied to quarantine
    22:47:57.0171 0916	RDPWD ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:57.0234 0916	C:\WINDOWS\system32\DRIVERS\redbook.sys - copied to quarantine
    22:47:57.0234 0916	redbook ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:57.0515 0916	C:\WINDOWS\system32\DRIVERS\RTL8192su.sys - copied to quarantine
    22:47:57.0515 0916	RTL8192su ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:57.0734 0916	C:\WINDOWS\system32\DRIVERS\secdrv.sys - copied to quarantine
    22:47:57.0734 0916	Secdrv ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:57.0812 0916	C:\WINDOWS\system32\drivers\Serial.sys - copied to quarantine
    22:47:57.0812 0916	Serial ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:58.0031 0916	C:\WINDOWS\system32\drivers\Sfloppy.sys - copied to quarantine
    22:47:58.0031 0916	Sfloppy ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:58.0218 0916	C:\WINDOWS\system32\DRIVERS\SLIP.sys - copied to quarantine
    22:47:58.0218 0916	SLIP ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:58.0343 0916	C:\WINDOWS\system32\drivers\splitter.sys - copied to quarantine
    22:47:58.0343 0916	splitter ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:58.0531 0916	C:\WINDOWS\system32\DRIVERS\sr.sys - copied to quarantine
    22:47:58.0531 0916	sr ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:58.0656 0916	C:\WINDOWS\system32\DRIVERS\srv.sys - copied to quarantine
    22:47:58.0656 0916	Srv ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:58.0781 0916	C:\WINDOWS\system32\drivers\StarOpen.sys - copied to quarantine
    22:47:58.0781 0916	StarOpen ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:58.0984 0916	C:\WINDOWS\system32\drivers\sthda.sys - copied to quarantine
    22:47:58.0984 0916	STHDA ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:59.0093 0916	C:\WINDOWS\system32\DRIVERS\StreamIP.sys - copied to quarantine
    22:47:59.0093 0916	streamip ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:59.0250 0916	C:\WINDOWS\system32\DRIVERS\swenum.sys - copied to quarantine
    22:47:59.0250 0916	swenum ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:59.0500 0916	C:\WINDOWS\system32\drivers\swmidi.sys - copied to quarantine
    22:47:59.0500 0916	swmidi ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:59.0562 0916	C:\WINDOWS\system32\drivers\sysaudio.sys - copied to quarantine
    22:47:59.0562 0916	sysaudio ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:59.0656 0916	C:\WINDOWS\system32\DRIVERS\tap0901.sys - copied to quarantine
    22:47:59.0656 0916	tap0901 ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:59.0812 0916	C:\WINDOWS\system32\DRIVERS\tcpip.sys - copied to quarantine
    22:47:59.0812 0916	Tcpip ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:47:59.0937 0916	C:\WINDOWS\system32\drivers\TDPIPE.sys - copied to quarantine
    22:47:59.0937 0916	TDPIPE ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0015 0916	C:\WINDOWS\system32\drivers\TDTCP.sys - copied to quarantine
    22:48:00.0015 0916	TDTCP ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0125 0916	C:\WINDOWS\system32\DRIVERS\termdd.sys - copied to quarantine
    22:48:00.0125 0916	TermDD ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0218 0916	C:\WINDOWS\system32\drivers\Udfs.sys - copied to quarantine
    22:48:00.0218 0916	Udfs ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0296 0916	C:\WINDOWS\system32\DRIVERS\update.sys - copied to quarantine
    22:48:00.0296 0916	Update ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0562 0916	C:\WINDOWS\system32\Drivers\usbaapl.sys - copied to quarantine
    22:48:00.0578 0916	USBAAPL ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0687 0916	C:\WINDOWS\system32\drivers\usbaudio.sys - copied to quarantine
    22:48:00.0687 0916	usbaudio ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0859 0916	C:\WINDOWS\system32\DRIVERS\usbccgp.sys - copied to quarantine
    22:48:00.0859 0916	usbccgp ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:00.0984 0916	C:\WINDOWS\system32\DRIVERS\usbehci.sys - copied to quarantine
    22:48:00.0984 0916	usbehci ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0062 0916	C:\WINDOWS\system32\DRIVERS\usbhub.sys - copied to quarantine
    22:48:01.0062 0916	usbhub ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0187 0916	C:\WINDOWS\system32\DRIVERS\usbprint.sys - copied to quarantine
    22:48:01.0187 0916	usbprint ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0312 0916	C:\WINDOWS\system32\DRIVERS\usbscan.sys - copied to quarantine
    22:48:01.0312 0916	usbscan ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0453 0916	C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - copied to quarantine
    22:48:01.0453 0916	usbstor ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0671 0916	C:\WINDOWS\system32\DRIVERS\usbuhci.sys - copied to quarantine
    22:48:01.0671 0916	usbuhci ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0781 0916	C:\WINDOWS\System32\drivers\vga.sys - copied to quarantine
    22:48:01.0781 0916	VgaSave ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0859 0916	C:\WINDOWS\system32\drivers\VolSnap.sys - copied to quarantine
    22:48:01.0859 0916	VolSnap ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:01.0953 0916	C:\WINDOWS\system32\DRIVERS\wanarp.sys - copied to quarantine
    22:48:01.0953 0916	Wanarp ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:02.0093 0916	C:\WINDOWS\system32\drivers\wdmaud.sys - copied to quarantine
    22:48:02.0093 0916	wdmaud ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:02.0218 0916	C:\WINDOWS\system32\DRIVERS\wlndis50.sys - copied to quarantine
    22:48:02.0218 0916	WLNdis50 ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:02.0421 0916	C:\WINDOWS\System32\drivers\ws2ifsl.sys - copied to quarantine
    22:48:02.0421 0916	WS2IFSL ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:02.0546 0916	C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS - copied to quarantine
    22:48:02.0562 0916	WSTCODEC ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:02.0671 0916	C:\WINDOWS\system32\DRIVERS\WudfPf.sys - copied to quarantine
    22:48:02.0671 0916	WudfPf ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:02.0765 0916	C:\WINDOWS\system32\DRIVERS\wudfrd.sys - copied to quarantine
    22:48:02.0765 0916	WudfRd ( UnsignedFile.Multi.Generic ) - User select action: Quarantine 
    22:48:05.0859 0668	Deinitialize success
    These are all necessary drivers and services for your PC to function properly. TDSSKiller reported that they were all unsigned, as in, they did not pass Microsoft's digital signature check. This would be a first time that I've seen this type of report from TDSSKiller.

    And according to your logs from MGtools, they are indeed all gone:
    You have/had a nasty ZeroAccess infection. I'm afraid the best solution here would be to backup any important data that you can (minus software) and reformat with a clean install of Windows XP.

    You may find this article by Microsoft helpful for the backing up process: How to back up or transfer your data on a Windows-based computer

    All the best,
    thisisu
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds