2011/07/27 22:52:16.0765 1596 TDSS rootkit removing tool 2.5.11.0 Jul 11 2011 16:56:56 2011/07/27 22:52:16.0953 1596 ================================================================================ 2011/07/27 22:52:16.0953 1596 SystemInfo: 2011/07/27 22:52:16.0953 1596 2011/07/27 22:52:16.0953 1596 OS Version: 5.1.2600 ServicePack: 3.0 2011/07/27 22:52:16.0953 1596 Product type: Workstation 2011/07/27 22:52:16.0953 1596 ComputerName: CHRIS-COMPUTER 2011/07/27 22:52:16.0953 1596 UserName: my comp 2011/07/27 22:52:16.0953 1596 Windows directory: C:\WINDOWS 2011/07/27 22:52:16.0953 1596 System windows directory: C:\WINDOWS 2011/07/27 22:52:16.0953 1596 Processor architecture: Intel x86 2011/07/27 22:52:16.0953 1596 Number of processors: 1 2011/07/27 22:52:16.0953 1596 Page size: 0x1000 2011/07/27 22:52:16.0953 1596 Boot type: Normal boot 2011/07/27 22:52:16.0953 1596 ================================================================================ 2011/07/27 22:52:18.0828 1596 Initialize success 2011/07/27 22:52:29.0375 3912 ================================================================================ 2011/07/27 22:52:29.0375 3912 Scan started 2011/07/27 22:52:29.0375 3912 Mode: Manual; 2011/07/27 22:52:29.0375 3912 ================================================================================ 2011/07/27 22:52:30.0453 3912 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/07/27 22:52:30.0609 3912 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/07/27 22:52:31.0000 3912 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/07/27 22:52:31.0140 3912 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys 2011/07/27 22:52:31.0453 3912 ALCXWDM (bcd805eec4f621cbda15b33053d83ac7) C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2011/07/27 22:52:31.0828 3912 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/07/27 22:52:32.0312 3912 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/07/27 22:52:32.0578 3912 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/07/27 22:52:32.0765 3912 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/07/27 22:52:32.0921 3912 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/07/27 22:52:33.0078 3912 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/07/27 22:52:33.0234 3912 BootScreen (d1d86841a78837ab81716170e389ea86) C:\WINDOWS\System32\drivers\vidstub.sys 2011/07/27 22:52:33.0375 3912 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 2011/07/27 22:52:33.0437 3912 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 2011/07/27 22:52:33.0578 3912 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys 2011/07/27 22:52:33.0734 3912 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys 2011/07/27 22:52:33.0890 3912 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys 2011/07/27 22:52:34.0078 3912 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys 2011/07/27 22:52:34.0234 3912 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys 2011/07/27 22:52:34.0390 3912 BVRPMPR5 (da2dc84e2d14ec6dac1132caa286118d) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS 2011/07/27 22:52:34.0578 3912 CamDrL (0f5ca31bb3fdb5c1e63c170cfbecc93b) C:\WINDOWS\system32\DRIVERS\Camdrl.sys 2011/07/27 22:52:34.0796 3912 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/07/27 22:52:34.0984 3912 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/07/27 22:52:35.0187 3912 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/07/27 22:52:35.0359 3912 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/07/27 22:52:35.0531 3912 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/07/27 22:52:35.0703 3912 Ch2kPS2 (87ec185b1ac9862afe34891d98584815) C:\WINDOWS\system32\DRIVERS\Ch2kPS2.sys 2011/07/27 22:52:35.0859 3912 Ch2kPS2M (164db5acee617be6f4b6709dc2f0d4e1) C:\WINDOWS\system32\DRIVERS\Ch2kPS2M.sys 2011/07/27 22:52:36.0015 3912 Ch2kUSB (fc5f1e32ae4927b719342ddf2da07f28) C:\WINDOWS\system32\drivers\Ch2kUSB.sys 2011/07/27 22:52:36.0171 3912 Ch2kUSBM (3cc1ba2b0981ca07992fe2cb728e4a52) C:\WINDOWS\system32\drivers\Ch2kUSBm.sys 2011/07/27 22:52:36.0468 3912 cmpci (e5842ccf0953d3d46d5e26427b67e901) C:\WINDOWS\system32\drivers\cmaudio.sys 2011/07/27 22:52:36.0703 3912 cmuda (53f4cc55f3c255439c5973e31f0adce7) C:\WINDOWS\system32\drivers\cmuda.sys 2011/07/27 22:52:36.0984 3912 cmuda3 (a0f7d6b070f15ead9f4231b51b246e4c) C:\WINDOWS\system32\drivers\cmudax3.sys 2011/07/27 22:52:37.0515 3912 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/07/27 22:52:37.0703 3912 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/07/27 22:52:37.0890 3912 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/07/27 22:52:38.0156 3912 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/07/27 22:52:38.0390 3912 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/07/27 22:52:38.0656 3912 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/07/27 22:52:38.0890 3912 eamon (7a25ad652a3003b8854e873a3324e672) C:\WINDOWS\system32\DRIVERS\eamon.sys 2011/07/27 22:52:39.0015 3912 easdrv (c7c17bc80b7264322207abc31f20ea84) C:\WINDOWS\system32\DRIVERS\easdrv.sys 2011/07/27 22:52:39.0140 3912 ElbyCDIO (28cb0b64134ad62c2acf77db8501a619) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys 2011/07/27 22:52:39.0281 3912 epfwtdir (74051da749e5e89a14ddab5ba4a03a7f) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys 2011/07/27 22:52:39.0437 3912 FA312 (aa855fb8a866281aacb393c1feab91ae) C:\WINDOWS\system32\DRIVERS\FA312nd5.sys 2011/07/27 22:52:39.0640 3912 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/07/27 22:52:39.0828 3912 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/07/27 22:52:39.0968 3912 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/07/27 22:52:40.0109 3912 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/07/27 22:52:40.0265 3912 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/07/27 22:52:40.0406 3912 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS 2011/07/27 22:52:40.0703 3912 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/07/27 22:52:40.0937 3912 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/07/27 22:52:41.0093 3912 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys 2011/07/27 22:52:41.0203 3912 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 2011/07/27 22:52:41.0343 3912 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/07/27 22:52:41.0515 3912 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys 2011/07/27 22:52:41.0656 3912 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/07/27 22:52:41.0906 3912 HSFHWBS2 (2e218fe7c528ef9671fb5544092a6679) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 2011/07/27 22:52:42.0125 3912 HSF_DP (08e4a38abcf2af10079b94e550e82bb3) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 2011/07/27 22:52:42.0390 3912 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/07/27 22:52:42.0750 3912 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/07/27 22:52:42.0953 3912 ialm (44b7d5a4f2bd9fe21aea0bb0bace38c4) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 2011/07/27 22:52:43.0203 3912 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/07/27 22:52:43.0390 3912 InCDfs (580a81790cd0a48d85da322267da7ac4) C:\WINDOWS\system32\drivers\InCDFs.sys 2011/07/27 22:52:43.0562 3912 InCDPass (aaa2789d2ce21b31be9406ba1ceb7285) C:\WINDOWS\system32\drivers\InCDPass.sys 2011/07/27 22:52:43.0703 3912 InCDrec (4d022577e9072b5d22e0a383a7806bbb) C:\WINDOWS\system32\drivers\InCDrec.sys 2011/07/27 22:52:43.0828 3912 incdrm (c258e57321a3c3737f4fa815fa69ee0b) C:\WINDOWS\system32\drivers\InCDRm.sys 2011/07/27 22:52:44.0062 3912 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/07/27 22:52:44.0187 3912 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/07/27 22:52:44.0328 3912 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/07/27 22:52:44.0578 3912 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/07/27 22:52:44.0812 3912 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/07/27 22:52:44.0968 3912 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/07/27 22:52:45.0140 3912 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/07/27 22:52:45.0312 3912 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/07/27 22:52:45.0515 3912 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/07/27 22:52:46.0437 3912 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/07/27 22:52:46.0593 3912 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/07/27 22:52:46.0750 3912 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/07/27 22:52:46.0890 3912 KMWDFILTER (566c5fd480fdbce3ba5cf9fbcffaea9a) C:\WINDOWS\system32\DRIVERS\KMWDFILTER.sys 2011/07/27 22:52:47.0031 3912 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/07/27 22:52:47.0359 3912 LVcKap (8113133ec42dd6c566908008ce913edd) C:\WINDOWS\system32\DRIVERS\LVcKap.sys 2011/07/27 22:52:47.0718 3912 LVMVDrv (0dd5b8af4917a2821047450195c511b3) C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys 2011/07/27 22:52:47.0859 3912 LVPr2Mon (12866641284ebb41e627bb53c04da959) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys 2011/07/27 22:52:47.0984 3912 LVUSBSta (64bc29c3a0388bfc580bb8b1346f7659) C:\WINDOWS\system32\drivers\LVUSBSta.sys 2011/07/27 22:52:48.0093 3912 ManyCam (c6d085c7045200143528136a43a65fde) C:\WINDOWS\system32\DRIVERS\ManyCam.sys 2011/07/27 22:52:48.0265 3912 MBAMSwissArmy (b18225739ed9caa83ba2df966e9f43e8) C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2011/07/27 22:52:48.0421 3912 mdmxsdk (a1e9d936eac07ee9386e87bac1377fad) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 2011/07/27 22:52:48.0671 3912 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/07/27 22:52:48.0812 3912 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/07/27 22:52:48.0984 3912 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/07/27 22:52:49.0125 3912 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/07/27 22:52:49.0312 3912 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/07/27 22:52:49.0546 3912 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/07/27 22:52:49.0765 3912 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/07/27 22:52:49.0906 3912 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/07/27 22:52:50.0046 3912 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/07/27 22:52:50.0203 3912 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/07/27 22:52:50.0343 3912 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/07/27 22:52:50.0468 3912 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/07/27 22:52:50.0625 3912 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys 2011/07/27 22:52:50.0781 3912 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 2011/07/27 22:52:50.0921 3912 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/07/27 22:52:51.0093 3912 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/07/27 22:52:51.0390 3912 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/07/27 22:52:51.0828 3912 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/07/27 22:52:52.0000 3912 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/07/27 22:52:52.0125 3912 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/07/27 22:52:52.0296 3912 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/07/27 22:52:52.0453 3912 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/07/27 22:52:52.0640 3912 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/07/27 22:52:52.0843 3912 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/07/27 22:52:52.0984 3912 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/07/27 22:52:53.0140 3912 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/07/27 22:52:53.0343 3912 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/07/27 22:52:53.0703 3912 nv (9f4384aa43548ddd438f7b7825d11699) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/07/27 22:52:54.0125 3912 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/07/27 22:52:54.0281 3912 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/07/27 22:52:54.0500 3912 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/07/27 22:52:54.0625 3912 oreans32 (b99575d16f887883b821d372ff292c20) C:\WINDOWS\system32\drivers\oreans32.sys 2011/07/27 22:52:54.0781 3912 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/07/27 22:52:54.0984 3912 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/07/27 22:52:55.0125 3912 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/07/27 22:52:55.0296 3912 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/07/27 22:52:55.0515 3912 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/07/27 22:52:55.0671 3912 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/07/27 22:52:55.0859 3912 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys 2011/07/27 22:52:56.0500 3912 PhilCam8116 (15670c1686c51b68e58b8e31569f524f) C:\WINDOWS\system32\DRIVERS\CamDrL21.sys 2011/07/27 22:52:56.0734 3912 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/07/27 22:52:56.0906 3912 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/07/27 22:52:57.0046 3912 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/07/27 22:52:57.0234 3912 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/07/27 22:52:58.0046 3912 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/07/27 22:52:58.0203 3912 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/07/27 22:52:58.0343 3912 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/07/27 22:52:58.0531 3912 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/07/27 22:52:58.0765 3912 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/07/27 22:52:58.0984 3912 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/07/27 22:52:59.0156 3912 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/07/27 22:52:59.0359 3912 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/07/27 22:52:59.0531 3912 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys 2011/07/27 22:52:59.0687 3912 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 2011/07/27 22:52:59.0968 3912 s115bus (e1ab463b36a7ef31d8a73a97a9b57afa) C:\WINDOWS\system32\DRIVERS\s115bus.sys 2011/07/27 22:53:00.0500 3912 s115mdfl (e24113fc13b8737c94cf4e3415488c76) C:\WINDOWS\system32\DRIVERS\s115mdfl.sys 2011/07/27 22:53:00.0734 3912 s115mdm (4029e49e7c673aa0670bd206b0af1b5b) C:\WINDOWS\system32\DRIVERS\s115mdm.sys 2011/07/27 22:53:00.0953 3912 s115mgmt (eb02ab4ca8bccecfde236cad8fc6e135) C:\WINDOWS\system32\DRIVERS\s115mgmt.sys 2011/07/27 22:53:01.0093 3912 s115obex (089869db9ffd2ac807fa87fe82ac7761) C:\WINDOWS\system32\DRIVERS\s115obex.sys 2011/07/27 22:53:01.0406 3912 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/07/27 22:53:01.0578 3912 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/07/27 22:53:01.0718 3912 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/07/27 22:53:01.0921 3912 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/07/27 22:53:02.0171 3912 SISNIC (3fbb6ef8b5a71a2fa11f5f461bb73219) C:\WINDOWS\system32\DRIVERS\sisnic.sys 2011/07/27 22:53:02.0312 3912 SISNICXP (a1348a901a44760ccd76043525e851d0) C:\WINDOWS\system32\DRIVERS\sisnicxp.sys 2011/07/27 22:53:02.0421 3912 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/07/27 22:53:02.0593 3912 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 2011/07/27 22:53:02.0765 3912 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/07/27 22:53:02.0953 3912 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/07/27 22:53:03.0156 3912 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/07/27 22:53:03.0390 3912 ss_bbus (eaa66218cd39f5bb1b4853a78c67c787) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys 2011/07/27 22:53:03.0609 3912 ss_bmdfl (91765f99914ed8693d8bc76524f21581) C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys 2011/07/27 22:53:03.0859 3912 ss_bmdm (840e7b738b03c10ee91d9b7d3d6eff15) C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys 2011/07/27 22:53:04.0250 3912 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys 2011/07/27 22:53:04.0593 3912 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/07/27 22:53:04.0968 3912 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/07/27 22:53:05.0265 3912 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/07/27 22:53:06.0453 3912 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/07/27 22:53:06.0937 3912 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/07/27 22:53:07.0531 3912 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/07/27 22:53:07.0796 3912 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/07/27 22:53:08.0125 3912 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/07/27 22:53:09.0171 3912 uagp35 (d85938f272d1bcf3db3a31fc0a048928) C:\WINDOWS\system32\DRIVERS\uagp35.sys 2011/07/27 22:53:09.0312 3912 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/07/27 22:53:09.0625 3912 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/07/27 22:53:09.0921 3912 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/07/27 22:53:10.0078 3912 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/07/27 22:53:10.0296 3912 usbcm (a31c1f4b2448eeeff7c0d4e4d58bd9b3) C:\WINDOWS\system32\DRIVERS\usbcm.sys 2011/07/27 22:53:10.0500 3912 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/07/27 22:53:10.0656 3912 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/07/27 22:53:10.0781 3912 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 2011/07/27 22:53:10.0921 3912 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/07/27 22:53:11.0062 3912 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/07/27 22:53:11.0187 3912 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/07/27 22:53:11.0296 3912 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/07/27 22:53:11.0515 3912 uzi3otqy (d565ad44c6c4d934afad3ca4196b09aa) C:\WINDOWS\system32\Drivers\uzi3otqy.sys 2011/07/27 22:53:11.0625 3912 VClone (9bf2ea54e5ed5acdf96f1dec84c117c4) C:\WINDOWS\system32\DRIVERS\VClone.sys 2011/07/27 22:53:11.0750 3912 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/07/27 22:53:11.0921 3912 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/07/27 22:53:12.0078 3912 w300bus (d4baa1ac8dcea1382e81aa6fe48cdd7c) C:\WINDOWS\system32\DRIVERS\w300bus.sys 2011/07/27 22:53:12.0265 3912 w300mdfl (12d415ab0ddd86c42cdc5f120a381f24) C:\WINDOWS\system32\DRIVERS\w300mdfl.sys 2011/07/27 22:53:12.0406 3912 w300mdm (f470d5e61ee7f951883f70d676551c89) C:\WINDOWS\system32\DRIVERS\w300mdm.sys 2011/07/27 22:53:12.0562 3912 w300mgmt (1b575b7384e22f5b278d3d7fc1bae682) C:\WINDOWS\system32\DRIVERS\w300mgmt.sys 2011/07/27 22:53:12.0734 3912 w300obex (a2bc36924ae02ca1e01ec39c99afea09) C:\WINDOWS\system32\DRIVERS\w300obex.sys 2011/07/27 22:53:12.0890 3912 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/07/27 22:53:13.0281 3912 wandrv (30211add92098d4b5cfadbf3da01e69b) C:\WINDOWS\system32\DRIVERS\wandrv.sys 2011/07/27 22:53:13.0484 3912 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys 2011/07/27 22:53:13.0765 3912 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/07/27 22:53:13.0937 3912 winachsf (43c5d443900d263af3fb44af4c122599) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 2011/07/27 22:53:14.0171 3912 WinDriver6 (94e4312d546048bf31604a8b2ad13fc0) C:\WINDOWS\system32\drivers\windrvr6.sys 2011/07/27 22:53:14.0359 3912 WmBEnum (bc3ecbcb40147bdae3ad2fd0b4b346d8) C:\WINDOWS\system32\drivers\WmBEnum.sys 2011/07/27 22:53:14.0484 3912 WmFilter (19f9881d8b3484fedb605d0216876898) C:\WINDOWS\system32\drivers\WmFilter.sys 2011/07/27 22:53:14.0671 3912 WmVirHid (7a51545a6409a25eedbdbd97d019e8cc) C:\WINDOWS\system32\drivers\WmVirHid.sys 2011/07/27 22:53:14.0843 3912 WmXlCore (1f083b3bc73017e60c3ca85cf4a70753) C:\WINDOWS\system32\drivers\WmXlCore.sys 2011/07/27 22:53:15.0000 3912 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/07/27 22:53:15.0187 3912 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/07/27 22:53:15.0375 3912 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/07/27 22:53:15.0593 3912 xusb21 (a640c90b007762939507c28a021be3b3) C:\WINDOWS\system32\DRIVERS\xusb21.sys 2011/07/27 22:53:16.0046 3912 {6080A529-897E-4629-A488-ABA0C29B635E} (7829319b296adc8a3bd99f4824effda9) C:\WINDOWS\system32\drivers\ialmsbw.sys 2011/07/27 22:53:16.0250 3912 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (b8c99f314372be1425468d844ce45cee) C:\WINDOWS\system32\drivers\ialmkchw.sys 2011/07/27 22:53:16.0343 3912 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 2011/07/27 22:53:16.0578 3912 MBR (0x1B8) (2839639fa37b8353e792a2a30a12ced3) \Device\Harddisk1\DR1 2011/07/27 22:53:16.0593 3912 \Device\Harddisk1\DR1 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/07/27 22:53:16.0593 3912 MBR (0x1B8) (5034302cba936a9c47b4ebc3453dac40) \Device\Harddisk2\DR2 2011/07/27 22:53:16.0703 3912 Boot (0x1200) (820e4764770dde1843dee933dd875f1a) \Device\Harddisk0\DR0\Partition0 2011/07/27 22:53:16.0718 3912 Boot (0x1200) (38adaa282b0fd2d4324061b08e4dfcc9) \Device\Harddisk1\DR1\Partition0 2011/07/27 22:53:16.0734 3912 Boot (0x1200) (da74bcc330217ab778db47865bd3d7fd) \Device\Harddisk2\DR2\Partition0 2011/07/27 22:53:16.0734 3912 ================================================================================ 2011/07/27 22:53:16.0734 3912 Scan finished 2011/07/27 22:53:16.0734 3912 ================================================================================ 2011/07/27 22:53:16.0750 2016 Detected object count: 1 2011/07/27 22:53:16.0750 2016 Actual detected object count: 1 2011/07/27 22:53:17.0109 2016 \Device\Harddisk1\DR1 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot 2011/07/27 22:53:17.0140 2016 \Device\Harddisk1\DR1 - ok 2011/07/27 22:53:17.0140 2016 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk1\DR1) - User select action: Cure 2011/07/27 22:54:23.0750 1364 Deinitialize success