17:33:13.0177 4124 TDSS rootkit removing tool 2.6.17.0 Nov 9 2011 16:48:26 17:33:15.0081 4124 ============================================================ 17:33:15.0081 4124 Current date / time: 2011/11/10 17:33:15.0081 17:33:15.0081 4124 SystemInfo: 17:33:15.0081 4124 17:33:15.0081 4124 OS Version: 6.1.7601 ServicePack: 1.0 17:33:15.0081 4124 Product type: Workstation 17:33:15.0081 4124 ComputerName: BROOMSTICK 17:33:15.0081 4124 UserName: Magical 17:33:15.0081 4124 Windows directory: C:\Windows 17:33:15.0081 4124 System windows directory: C:\Windows 17:33:15.0081 4124 Running under WOW64 17:33:15.0081 4124 Processor architecture: Intel x64 17:33:15.0081 4124 Number of processors: 8 17:33:15.0081 4124 Page size: 0x1000 17:33:15.0081 4124 Boot type: Normal boot 17:33:15.0081 4124 ============================================================ 17:33:15.0549 4124 Initialize success 17:33:19.0199 2708 ============================================================ 17:33:19.0199 2708 Scan started 17:33:19.0199 2708 Mode: Manual; 17:33:19.0199 2708 ============================================================ 17:33:19.0246 2708 1394ohci - ok 17:33:19.0261 2708 ACPI - ok 17:33:19.0277 2708 AcpiPmi - ok 17:33:19.0308 2708 adp94xx - ok 17:33:19.0308 2708 adpahci - ok 17:33:19.0324 2708 adpu320 - ok 17:33:19.0339 2708 AFD - ok 17:33:19.0339 2708 agp440 - ok 17:33:19.0355 2708 aliide - ok 17:33:19.0371 2708 amdide - ok 17:33:19.0371 2708 AmdK8 - ok 17:33:19.0371 2708 amdkmdag - ok 17:33:19.0371 2708 amdkmdap - ok 17:33:19.0386 2708 AmdPPM - ok 17:33:19.0386 2708 amdsata - ok 17:33:19.0386 2708 amdsbs - ok 17:33:19.0386 2708 amdxata - ok 17:33:19.0433 2708 AppID - ok 17:33:19.0433 2708 arc - ok 17:33:19.0433 2708 arcsas - ok 17:33:19.0449 2708 aswFsBlk - ok 17:33:19.0449 2708 aswMonFlt - ok 17:33:19.0464 2708 aswRdr - ok 17:33:19.0464 2708 aswSnx - ok 17:33:19.0464 2708 aswSP - ok 17:33:19.0464 2708 aswTdi - ok 17:33:19.0464 2708 AsyncMac - ok 17:33:19.0480 2708 atapi - ok 17:33:19.0480 2708 AtiHDAudioService - ok 17:33:19.0480 2708 b06bdrv - ok 17:33:19.0480 2708 b57nd60a - ok 17:33:19.0480 2708 Beep - ok 17:33:19.0511 2708 blbdrive - ok 17:33:19.0511 2708 bowser - ok 17:33:19.0511 2708 BrFiltLo - ok 17:33:19.0511 2708 BrFiltUp - ok 17:33:19.0511 2708 Brserid - ok 17:33:19.0511 2708 BrSerWdm - ok 17:33:19.0511 2708 BrUsbMdm - ok 17:33:19.0511 2708 BrUsbSer - ok 17:33:19.0527 2708 BTHMODEM - ok 17:33:19.0573 2708 catchme - ok 17:33:19.0573 2708 cdfs - ok 17:33:19.0573 2708 cdrom - ok 17:33:19.0573 2708 circlass - ok 17:33:19.0573 2708 CLFS - ok 17:33:19.0589 2708 CmBatt - ok 17:33:19.0589 2708 cmdide - ok 17:33:19.0605 2708 CNG - ok 17:33:19.0605 2708 Compbatt - ok 17:33:19.0605 2708 CompositeBus - ok 17:33:19.0605 2708 crcdisk - ok 17:33:19.0620 2708 DfsC - ok 17:33:19.0620 2708 discache - ok 17:33:19.0636 2708 Disk - ok 17:33:19.0636 2708 drmkaud - ok 17:33:19.0651 2708 DXGKrnl - ok 17:33:19.0651 2708 e1cexpress - ok 17:33:19.0651 2708 ebdrv - ok 17:33:19.0667 2708 ElbyCDIO - ok 17:33:19.0667 2708 elxstor - ok 17:33:19.0667 2708 ErrDev - ok 17:33:19.0683 2708 exfat - ok 17:33:19.0683 2708 fastfat - ok 17:33:19.0683 2708 fdc - ok 17:33:19.0683 2708 FileInfo - ok 17:33:19.0683 2708 Filetrace - ok 17:33:19.0683 2708 flpydisk - ok 17:33:19.0683 2708 FltMgr - ok 17:33:19.0698 2708 FsDepends - ok 17:33:19.0698 2708 Fs_Rec - ok 17:33:19.0698 2708 fvevol - ok 17:33:19.0698 2708 gagp30kx - ok 17:33:19.0698 2708 hcw85cir - ok 17:33:19.0698 2708 HdAudAddService - ok 17:33:19.0698 2708 HDAudBus - ok 17:33:19.0698 2708 HidBatt - ok 17:33:19.0698 2708 HidBth - ok 17:33:19.0714 2708 HidIr - ok 17:33:19.0714 2708 HidUsb - ok 17:33:19.0714 2708 HpSAMD - ok 17:33:19.0714 2708 HTTP - ok 17:33:19.0714 2708 hwpolicy - ok 17:33:19.0714 2708 i8042prt - ok 17:33:19.0714 2708 iaStor - ok 17:33:19.0776 2708 iaStorV - ok 17:33:19.0776 2708 iirsp - ok 17:33:19.0792 2708 IntcAzAudAddService - ok 17:33:19.0792 2708 intelide - ok 17:33:19.0792 2708 intelppm - ok 17:33:19.0792 2708 IpFilterDriver - ok 17:33:19.0807 2708 IPMIDRV - ok 17:33:19.0807 2708 IPNAT - ok 17:33:19.0807 2708 IRENUM - ok 17:33:19.0807 2708 isapnp - ok 17:33:19.0807 2708 iScsiPrt - ok 17:33:19.0823 2708 kbdclass - ok 17:33:19.0823 2708 kbdhid - ok 17:33:19.0823 2708 KSecDD - ok 17:33:19.0823 2708 KSecPkg - ok 17:33:19.0823 2708 ksthunk - ok 17:33:19.0839 2708 Lbd - ok 17:33:19.0839 2708 lltdio - ok 17:33:19.0854 2708 LSI_FC - ok 17:33:19.0854 2708 LSI_SAS - ok 17:33:19.0854 2708 LSI_SAS2 - ok 17:33:19.0854 2708 LSI_SCSI - ok 17:33:19.0870 2708 luafv - ok 17:33:19.0870 2708 LVUSBS64 - ok 17:33:19.0870 2708 MBAMProtector - ok 17:33:19.0885 2708 megasas - ok 17:33:19.0885 2708 MegaSR - ok 17:33:19.0885 2708 MEIx64 - ok 17:33:19.0885 2708 Modem - ok 17:33:19.0885 2708 monitor - ok 17:33:19.0885 2708 mouclass - ok 17:33:19.0885 2708 mouhid - ok 17:33:19.0885 2708 mountmgr - ok 17:33:19.0901 2708 mpio - ok 17:33:19.0901 2708 mpsdrv - ok 17:33:19.0901 2708 MRxDAV - ok 17:33:19.0901 2708 mrxsmb - ok 17:33:19.0901 2708 mrxsmb10 - ok 17:33:19.0901 2708 mrxsmb20 - ok 17:33:19.0901 2708 msahci - ok 17:33:19.0901 2708 msdsm - ok 17:33:19.0917 2708 Msfs - ok 17:33:19.0917 2708 mshidkmdf - ok 17:33:19.0917 2708 msisadrv - ok 17:33:19.0917 2708 MSKSSRV - ok 17:33:19.0917 2708 MSPCLOCK - ok 17:33:19.0917 2708 MSPQM - ok 17:33:19.0917 2708 MsRPC - ok 17:33:19.0917 2708 mssmbios - ok 17:33:19.0917 2708 MSTEE - ok 17:33:19.0932 2708 MTConfig - ok 17:33:19.0932 2708 Mup - ok 17:33:19.0932 2708 mwlPSDFilter - ok 17:33:19.0932 2708 mwlPSDNServ - ok 17:33:19.0932 2708 mwlPSDVDisk - ok 17:33:19.0932 2708 NativeWifiP - ok 17:33:19.0932 2708 NDIS - ok 17:33:19.0932 2708 NdisCap - ok 17:33:19.0948 2708 NdisTapi - ok 17:33:19.0948 2708 Ndisuio - ok 17:33:19.0948 2708 NdisWan - ok 17:33:19.0948 2708 NDProxy - ok 17:33:19.0948 2708 NetBIOS - ok 17:33:19.0948 2708 NetBT - ok 17:33:19.0948 2708 netr28x - ok 17:33:19.0948 2708 nfrd960 - ok 17:33:19.0963 2708 Npfs - ok 17:33:19.0963 2708 nsiproxy - ok 17:33:19.0963 2708 Ntfs - ok 17:33:19.0963 2708 Null - ok 17:33:19.0963 2708 nvraid - ok 17:33:19.0963 2708 nvstor - ok 17:33:19.0979 2708 nv_agp - ok 17:33:19.0979 2708 ohci1394 - ok 17:33:19.0995 2708 Parport - ok 17:33:19.0995 2708 partmgr - ok 17:33:20.0010 2708 pci - ok 17:33:20.0010 2708 pciide - ok 17:33:20.0010 2708 pcmcia - ok 17:33:20.0010 2708 pcw - ok 17:33:20.0026 2708 PEAUTH - ok 17:33:20.0026 2708 PID_PEPI - ok 17:33:20.0041 2708 PptpMiniport - ok 17:33:20.0057 2708 Processor - ok 17:33:20.0057 2708 Psched - ok 17:33:20.0057 2708 ql2300 - ok 17:33:20.0073 2708 ql40xx - ok 17:33:20.0073 2708 QWAVEdrv - ok 17:33:20.0073 2708 RasAcd - ok 17:33:20.0073 2708 RasAgileVpn - ok 17:33:20.0088 2708 Rasl2tp - ok 17:33:20.0088 2708 RasPppoe - ok 17:33:20.0088 2708 RasSstp - ok 17:33:20.0104 2708 rdbss - ok 17:33:20.0104 2708 rdpbus - ok 17:33:20.0104 2708 RDPCDD - ok 17:33:20.0104 2708 RDPENCDD - ok 17:33:20.0119 2708 RDPREFMP - ok 17:33:20.0119 2708 RDPWD - ok 17:33:20.0119 2708 rdyboost - ok 17:33:20.0119 2708 rspndr - ok 17:33:20.0119 2708 sbp2port - ok 17:33:20.0135 2708 scfilter - ok 17:33:20.0135 2708 secdrv - ok 17:33:20.0135 2708 Serenum - ok 17:33:20.0135 2708 Serial - ok 17:33:20.0135 2708 sermouse - ok 17:33:20.0151 2708 sffdisk - ok 17:33:20.0151 2708 sffp_mmc - ok 17:33:20.0151 2708 sffp_sd - ok 17:33:20.0151 2708 sfloppy - ok 17:33:20.0151 2708 Sftfs - ok 17:33:20.0151 2708 Sftplay - ok 17:33:20.0151 2708 Sftredir - ok 17:33:20.0166 2708 Sftvol - ok 17:33:20.0166 2708 SiSRaid2 - ok 17:33:20.0166 2708 SiSRaid4 - ok 17:33:20.0166 2708 Smb - ok 17:33:20.0166 2708 spldr - ok 17:33:20.0182 2708 srv - ok 17:33:20.0182 2708 srv2 - ok 17:33:20.0182 2708 srvnet - ok 17:33:20.0182 2708 stexstor - ok 17:33:20.0182 2708 swenum - ok 17:33:20.0197 2708 Tcpip - ok 17:33:20.0197 2708 TCPIP6 - ok 17:33:20.0197 2708 tcpipreg - ok 17:33:20.0197 2708 TDPIPE - ok 17:33:20.0197 2708 TDTCP - ok 17:33:20.0197 2708 tdx - ok 17:33:20.0197 2708 TermDD - ok 17:33:20.0213 2708 tssecsrv - ok 17:33:20.0213 2708 TsUsbFlt - ok 17:33:20.0213 2708 tunnel - ok 17:33:20.0213 2708 uagp35 - ok 17:33:20.0213 2708 udfs - ok 17:33:20.0229 2708 uliagpkx - ok 17:33:20.0229 2708 umbus - ok 17:33:20.0229 2708 UmPass - ok 17:33:20.0229 2708 usbaudio - ok 17:33:20.0229 2708 usbccgp - ok 17:33:20.0229 2708 usbcir - ok 17:33:20.0244 2708 usbehci - ok 17:33:20.0244 2708 usbhub - ok 17:33:20.0244 2708 usbohci - ok 17:33:20.0244 2708 usbprint - ok 17:33:20.0244 2708 usbscan - ok 17:33:20.0244 2708 USBSTOR - ok 17:33:20.0244 2708 usbuhci - ok 17:33:20.0244 2708 VClone - ok 17:33:20.0260 2708 vdrvroot - ok 17:33:20.0260 2708 vga - ok 17:33:20.0260 2708 VgaSave - ok 17:33:20.0260 2708 vhdmp - ok 17:33:20.0260 2708 viaide - ok 17:33:20.0260 2708 volmgr - ok 17:33:20.0260 2708 volmgrx - ok 17:33:20.0260 2708 volsnap - ok 17:33:20.0275 2708 Vsdatant - ok 17:33:20.0275 2708 vsmraid - ok 17:33:20.0275 2708 vwifibus - ok 17:33:20.0275 2708 vwififlt - ok 17:33:20.0275 2708 WacomPen - ok 17:33:20.0275 2708 WANARP - ok 17:33:20.0291 2708 Wanarpv6 - ok 17:33:20.0291 2708 Wd - ok 17:33:20.0291 2708 Wdf01000 - ok 17:33:20.0307 2708 WfpLwf - ok 17:33:20.0307 2708 WIMMount - ok 17:33:20.0322 2708 WmiAcpi - ok 17:33:20.0322 2708 ws2ifsl - ok 17:33:20.0322 2708 WudfPf - ok 17:33:20.0322 2708 WUDFRd - ok 17:33:20.0338 2708 MBR (0x1B8) (3051207086651214e435112e51817dc5) \Device\Harddisk0\DR0 17:33:20.0431 2708 \Device\Harddisk0\DR0 - ok 17:33:20.0431 2708 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1 17:33:20.0447 2708 \Device\Harddisk1\DR1 - ok 17:33:20.0447 2708 Boot (0x1200) (58328132cfd65b63c2f87dec0f4708ed) \Device\Harddisk0\DR0\Partition0 17:33:20.0463 2708 \Device\Harddisk0\DR0\Partition0 - ok 17:33:20.0463 2708 Boot (0x1200) (dffaefe058448a39e60bb62427798534) \Device\Harddisk0\DR0\Partition1 17:33:20.0463 2708 \Device\Harddisk0\DR0\Partition1 - ok 17:33:20.0463 2708 ============================================================ 17:33:20.0463 2708 Scan finished 17:33:20.0463 2708 ============================================================ 17:33:20.0463 5456 Detected object count: 0 17:33:20.0463 5456 Actual detected object count: 0