First up, TDSSKiller:
10:00:52.0415 2036 TDSS rootkit removing tool 2.7.24.0 Apr 2 2012 10:31:48
10:00:53.0383 2036 ============================================================
10:00:53.0383 2036 Current date / time: 2012/04/03 10:00:53.0383
10:00:53.0383 2036 SystemInfo:
10:00:53.0383 2036
10:00:53.0383 2036 OS Version: 5.2.3790 ServicePack: 2.0
10:00:53.0383 2036 Product type: Server
10:00:53.0383 2036 ComputerName: xxxxx
10:00:53.0383 2036 UserName: administrator
10:00:53.0383 2036 Windows directory: C:\WINDOWS
10:00:53.0383 2036 System windows directory: C:\WINDOWS
10:00:53.0383 2036 Processor architecture: Intel x86
10:00:53.0383 2036 Number of processors: 8
10:00:53.0383 2036 Page size: 0x1000
10:00:53.0383 2036 Boot type: Safe boot with network
10:00:53.0383 2036 ============================================================
10:00:54.0524 2036 Drive \Device\Harddisk0\DR0 - Size: 0x21FE400000 (135.97 Gb), SectorSize: 0x200, Cylinders: 0x4556, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
10:00:54.0540 2036 Drive \Device\Harddisk1\DR1 - Size: 0x459DC00000 (278.46 Gb), SectorSize: 0x200, Cylinders: 0x8DFF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
10:00:54.0540 2036 Drive \Device\Harddisk2\DR4 - Size: 0x7470C05E00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:00:54.0555 2036 \Device\Harddisk0\DR0:
10:00:54.0555 2036 MBR used
10:00:54.0555 2036 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x10FEDAD6
10:00:54.0555 2036 \Device\Harddisk1\DR1:
10:00:54.0555 2036 MBR used
10:00:54.0555 2036 \Device\Harddisk2\DR4:
10:00:54.0555 2036 MBR used
10:00:54.0555 2036 \Device\Harddisk2\DR4\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
10:00:54.0571 2036 Initialize success
10:00:54.0571 2036 ============================================================
10:00:57.0165 1312 ============================================================
10:00:57.0165 1312 Scan started
10:00:57.0165 1312 Mode: Manual;
10:00:57.0165 1312 ============================================================
10:01:03.0227 1312 Abiosdsk - ok
10:01:03.0336 1312 ACPI - ok
10:01:03.0399 1312 ACPIEC - ok
10:01:03.0524 1312 adpu160m - ok
10:01:03.0649 1312 adpu320 - ok
10:01:03.0774 1312 AeLookupSvc (d01968edebf1dc11e4c93517c98cdf7c) C:\WINDOWS\System32\aelupsvc.dll
10:01:03.0774 1312 AeLookupSvc - ok
10:01:03.0883 1312 afcnt - ok
10:01:04.0008 1312 AFD (317e75d96065ac6af5ef8857ce2e399b) C:\WINDOWS\System32\drivers\afd.sys
10:01:04.0008 1312 AFD - ok
10:01:04.0133 1312 aic78u2 - ok
10:01:04.0180 1312 aic78xx - ok
10:01:04.0321 1312 Alerter (055318e373b45ad6c3f518732809ef4e) C:\WINDOWS\system32\alrsvc.dll
10:01:04.0321 1312 Alerter - ok
10:01:04.0430 1312 ALG (8e89cb0283d7ded092d76ae53d123c40) C:\WINDOWS\System32\alg.exe
10:01:04.0430 1312 ALG - ok
10:01:04.0555 1312 AliIde - ok
10:01:04.0680 1312 AmdIde (d175d3c400a412b9cb2095e452afbbb0) C:\WINDOWS\system32\drivers\AmdIde.sys
10:01:04.0680 1312 AmdIde - ok
10:01:04.0805 1312 Amsp (a119a4aeb0e23884c4a92be3f5f5ab12) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
10:01:04.0805 1312 Amsp - ok
10:01:04.0930 1312 AppMgmt (8a5ad4cfe2d84371abadfcf9e21954f6) C:\WINDOWS\System32\appmgmts.dll
10:01:04.0930 1312 AppMgmt - ok
10:01:05.0040 1312 arc (a9c7273645a06a01ac2ca070d7d7ec87) C:\WINDOWS\system32\drivers\arc.sys
10:01:05.0040 1312 arc - ok
10:01:05.0399 1312 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
10:01:05.0430 1312 aspnet_state - ok
10:01:05.0524 1312 AsyncMac (a35b971f631d4dfdeb68d71e770d2ce9) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:01:05.0524 1312 AsyncMac - ok
10:01:05.0649 1312 atapi (ff953a8f08ca3f822127654375786bbe) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:01:05.0649 1312 atapi - ok
10:01:05.0758 1312 Atdisk - ok
10:01:05.0899 1312 Atmarpc (d12dad5032285343ce3aa4906f661181) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:01:05.0899 1312 Atmarpc - ok
10:01:06.0008 1312 AudioSrv (754a448d5b87cbede41a0f0e0b237b03) C:\WINDOWS\System32\audiosrv.dll
10:01:06.0008 1312 AudioSrv - ok
10:01:06.0133 1312 audstub (5bfd980c2107d88101d1dc14055526fc) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:01:06.0133 1312 audstub - ok
10:01:06.0305 1312 Beep (99572503e15a3d10239b7b9887cbaf89) C:\WINDOWS\system32\drivers\Beep.sys
10:01:06.0321 1312 Beep - ok
10:01:06.0430 1312 BITS (9d7a318b2c7ae51e9d5374f8eede856c) C:\WINDOWS\system32\qmgr.dll
10:01:06.0446 1312 BITS - ok
10:01:06.0555 1312 Browser (f750a96d7478d435f5ac9ece6698f81e) C:\WINDOWS\System32\browser.dll
10:01:06.0555 1312 Browser - ok
10:01:06.0680 1312 cbidf2k (1342877de604a5a6bff986e288e3a8a7) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:01:06.0680 1312 cbidf2k - ok
10:01:06.0790 1312 cd20xrnt - ok
10:01:06.0915 1312 Cdfs (e6d72780c957b69c48bfc66bc3ecdad4) C:\WINDOWS\system32\drivers\Cdfs.sys
10:01:06.0915 1312 Cdfs - ok
10:01:07.0040 1312 Cdrom (825aa877a852ecc731fa0c39c8c37744) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:01:07.0040 1312 Cdrom - ok
10:01:07.0149 1312 Changer - ok
10:01:07.0305 1312 CiSvc (934ee973e9ee6ac414e9a0f07ab73d6e) C:\WINDOWS\system32\cisvc.exe
10:01:07.0321 1312 CiSvc - ok
10:01:07.0430 1312 ClipSrv (e53196ba56081f154e2d7a9e50a1d33f) C:\WINDOWS\system32\clipsrv.exe
10:01:07.0430 1312 ClipSrv - ok
10:01:07.0555 1312 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:01:07.0633 1312 clr_optimization_v2.0.50727_32 - ok
10:01:07.0696 1312 ClusDisk (54308cdf97622fae1620bb1ec39ef014) C:\WINDOWS\system32\DRIVERS\ClusDisk.sys
10:01:07.0696 1312 ClusDisk - ok
10:01:07.0805 1312 CmdIde - ok
10:01:07.0930 1312 COMSysApp - ok
10:01:08.0180 1312 Cpqarray - ok
10:01:08.0290 1312 cpqarry2 - ok
10:01:08.0415 1312 cpqcissm - ok
10:01:08.0540 1312 cpqfcalm - ok
10:01:08.0665 1312 cpqftbl (f54ef6ecdc0feafb28451b1067ca5e9f) C:\DOCUME~1\ADMINI~1.ECO\LOCALS~1\Temp\{9C96D555-3303-4E28-BD50-7540BF1FF61E}\cpqftbl.sys
10:01:08.0665 1312 cpqftbl - ok
10:01:08.0805 1312 cpqsrhmo (e346559d69e9f621bfe0db87b4c0f38a) C:\hp\hpsmh\data\cgi-bin\vcrepository\cpqsrhmo.exe
10:01:08.0821 1312 cpqsrhmo - ok
10:01:08.0915 1312 cpqsysio (c2d9aaec3101826a37343d39422d6c53) C:\DOCUME~1\ADMINI~1.ECO\LOCALS~1\Temp\{9C96D555-3303-4E28-BD50-7540BF1FF61E}\cpqsysio.sys
10:01:08.0915 1312 cpqsysio - ok
10:01:09.0040 1312 CPQTeam (74eff53a61cbc78560bdde295bc2b9d8) C:\WINDOWS\system32\DRIVERS\cpqteam.sys
10:01:09.0040 1312 CPQTeam - ok
10:01:09.0165 1312 cpqvcagent (a2911c0f087b2252394a2abf3e38fe46) C:\hp\hpsmh\data\cgi-bin\vcagent\vcagent.exe
10:01:09.0180 1312 cpqvcagent - ok
10:01:09.0321 1312 crcdisk (0ee27d9dbb208c13314f3c60f66aed26) C:\WINDOWS\system32\DRIVERS\crcdisk.sys
10:01:09.0321 1312 crcdisk - ok
10:01:09.0915 1312 CryptSvc (feb85da744dd3f41a427cf6d2bc04fe4) C:\WINDOWS\System32\cryptsvc.dll
10:01:09.0915 1312 CryptSvc - ok
10:01:10.0040 1312 dac2w2k - ok
10:01:10.0149 1312 dac960nt - ok
10:01:10.0290 1312 DcomLaunch (305a8757d66b5d416b47c497c27a01fe) C:\WINDOWS\system32\rpcss.dll
10:01:10.0305 1312 DcomLaunch - ok
10:01:10.0399 1312 dellcerc - ok
10:01:10.0524 1312 Dfs (6217aa084ef7e052f3b5d7c3f67f68af) C:\WINDOWS\system32\Dfssvc.exe
10:01:10.0540 1312 Dfs - ok
10:01:10.0649 1312 DfsDriver (444726b01c31d29c70e60f7c35de43e5) C:\WINDOWS\system32\drivers\Dfs.sys
10:01:10.0649 1312 DfsDriver - ok
10:01:10.0774 1312 Dhcp (1201df9a11fbb0f69ebd22e503d3bc87) C:\WINDOWS\System32\dhcpcsvc.dll
10:01:10.0774 1312 Dhcp - ok
10:01:10.0883 1312 DhcpListenDriver - ok
10:01:11.0055 1312 DialComService (3ccf97a963fa6ea21c215744480bf349) C:\Program Files\DIAL GmbH\DIAL Communication Framework\DialComService.exe
10:01:11.0086 1312 DialComService - ok
10:01:11.0196 1312 Disk (bbd23b7414a3852ce0e9018d7c566ffa) C:\WINDOWS\system32\DRIVERS\disk.sys
10:01:11.0196 1312 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\disk.sys. Real md5: bbd23b7414a3852ce0e9018d7c566ffa, Fake md5: 98433302c02f1168efb7364f8111a179
10:01:11.0196 1312 Disk ( Rootkit.Win32.TDSS.tdl3 ) - infected
10:01:11.0196 1312 Disk - detected Rootkit.Win32.TDSS.tdl3 (0)
10:01:11.0305 1312 dmadmin - ok
10:01:11.0446 1312 dmboot (89fa376d83042f6f1aed505106a5719d) C:\WINDOWS\system32\drivers\dmboot.sys
10:01:11.0446 1312 dmboot - ok
10:01:11.0555 1312 dmio (15081421ee62dc1c95abb387d9081571) C:\WINDOWS\system32\drivers\dmio.sys
10:01:11.0555 1312 dmio - ok
10:01:11.0680 1312 dmload (3d9bfa13b6f1cd2d91c50c52b32e91a2) C:\WINDOWS\system32\drivers\dmload.sys
10:01:11.0680 1312 dmload - ok
10:01:11.0805 1312 dmserver (78a11666307820af94b5712d53decc55) C:\WINDOWS\System32\dmserver.dll
10:01:11.0805 1312 dmserver - ok
10:01:11.0915 1312 Dnscache (e927f3b46f85d934c8f420fe08593d1b) C:\WINDOWS\System32\dnsrslvr.dll
10:01:11.0915 1312 Dnscache - ok
10:01:12.0040 1312 dpti2o - ok
10:01:12.0227 1312 elxstor - ok
10:01:12.0415 1312 Eventlog (cf500580cdd83b145646a4dcfce1cf3c) C:\WINDOWS\system32\services.exe
10:01:12.0415 1312 Eventlog - ok
10:01:12.0586 1312 EventSystem (c17c56e91045e14df45d62dd89aed50c) C:\WINDOWS\system32\es.dll
10:01:12.0602 1312 EventSystem - ok
10:01:12.0821 1312 Fastfat (e792a18abdc32286212dce8e75baa124) C:\WINDOWS\system32\drivers\Fastfat.sys
10:01:12.0836 1312 Fastfat - ok
10:01:13.0071 1312 Fdc (5090cd3f6ab1d71ad507953cff556ea9) C:\WINDOWS\system32\DRIVERS\fdc.sys
10:01:13.0086 1312 Fdc - ok
10:01:13.0180 1312 Fips (b485ac2edc466c538bdff32bc3f2e506) C:\WINDOWS\system32\drivers\Fips.sys
10:01:13.0196 1312 Fips - ok
10:01:13.0305 1312 Flpydisk (c621a51f415419a3145a5939abde39fa) C:\WINDOWS\system32\drivers\Flpydisk.sys
10:01:13.0305 1312 Flpydisk - ok
10:01:13.0430 1312 FltMgr (f978277ef786532195cdd9f88e908632) C:\WINDOWS\system32\drivers\fltmgr.sys
10:01:13.0430 1312 FltMgr - ok
10:01:13.0555 1312 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
10:01:13.0555 1312 FontCache3.0.0.0 - ok
10:01:13.0665 1312 Fs_Rec (aebff3d810b74971b91b2b77b289a98b) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:01:13.0665 1312 Fs_Rec - ok
10:01:13.0790 1312 Ftdisk (4c533b70afa917416aec57fcbeecb57d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:01:13.0790 1312 Ftdisk - ok
10:01:13.0915 1312 G200e (1014adf87245e19b6fca51af15b543ba) C:\WINDOWS\system32\DRIVERS\G200em.sys
10:01:13.0930 1312 G200e - ok
10:01:14.0024 1312 getPlusHelper - ok
10:01:14.0149 1312 Gpc (30b1653a955f548352024a5fee203cc3) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:01:14.0165 1312 Gpc - ok
10:01:14.0305 1312 helpsvc (40ca39dba80372ed8ec34c4bece68495) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
10:01:14.0305 1312 helpsvc - ok
10:01:14.0415 1312 HidServ (4828c4244081eb4132868ea3e93456bb) C:\WINDOWS\System32\hidserv.dll
10:01:14.0415 1312 HidServ - ok
10:01:14.0540 1312 hidusb (90a325e14f9b95f17712707b1a7181b5) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:01:14.0540 1312 hidusb - ok
10:01:14.0665 1312 HP Systems Insight Manager (f3aad3d681af9d210e58365466292db5) C:\PROGRA~1\HP\SYSTEM~1\lbin\hpsimsvc.exe
10:01:14.0665 1312 HP Systems Insight Manager - ok
10:01:14.0790 1312 hpcisss (8a445379d6e73731a6a37318dbb0c880) C:\WINDOWS\system32\drivers\hpcisss.sys
10:01:14.0790 1312 hpcisss - ok
10:01:14.0899 1312 hpn - ok
10:01:15.0024 1312 hpt3xx - ok
10:01:15.0149 1312 HTTP (7a5d176c4b43f0a47da4051c96c56439) C:\WINDOWS\system32\Drivers\HTTP.sys
10:01:15.0165 1312 HTTP - ok
10:01:15.0274 1312 HTTPFilter (d4b61a935670c57a0dea81b4f4a12169) C:\WINDOWS\system32\lsass.exe
10:01:15.0290 1312 HTTPFilter - ok
10:01:15.0383 1312 i2omgmt - ok
10:01:15.0508 1312 i2omp - ok
10:01:15.0571 1312 i8042prt (68e8ff9eeaf8b37a66cac2c57835ffbd) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:01:15.0571 1312 i8042prt - ok
10:01:15.0696 1312 IDriverT (6f95324909b502e2651442c1548ab12f) C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
10:01:15.0696 1312 IDriverT - ok
10:01:15.0821 1312 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
10:01:15.0852 1312 idsvc - ok
10:01:15.0930 1312 iirsp - ok
10:01:16.0055 1312 IISADMIN (58ac18bc908a78fba5430d23066d183a) C:\WINDOWS\system32\inetsrv\inetinfo.exe
10:01:16.0071 1312 IISADMIN - ok
10:01:16.0180 1312 imapi (44c132b35921b54b4a9ac64369d86d83) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:01:16.0180 1312 imapi - ok
10:01:16.0305 1312 ImapiService (5da3013244229422c9cbd91a16a477c4) C:\WINDOWS\system32\imapi.exe
10:01:16.0305 1312 ImapiService - ok
10:01:16.0602 1312 IntelIde - ok
10:01:16.0665 1312 Ip6Fw (d7e7e7898a05c53dd862b49828747c1e) C:\WINDOWS\system32\drivers\ip6fw.sys
10:01:16.0665 1312 Ip6Fw - ok
10:01:16.0790 1312 IpFilterDriver (5a41f207b7c39ee4918f7496a4f19b14) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:01:16.0790 1312 IpFilterDriver - ok
10:01:16.0899 1312 IpInIp - ok
10:01:16.0961 1312 IpNat (890e7a14a63aec2ea9257a79a88be784) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:01:16.0977 1312 IpNat - ok
10:01:17.0086 1312 IPSec (1a9aeac49683b32df55b7fb1516f3028) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:01:17.0086 1312 IPSec - ok
10:01:17.0196 1312 ipsraidn - ok
10:01:17.0336 1312 IRENUM (11407ee682a2d5b0248de8af0f1a6996) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:01:17.0336 1312 IRENUM - ok
10:01:17.0508 1312 isapnp (b71ba04a3b5d4404225ccdbf1969078f) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:01:17.0508 1312 isapnp - ok
10:01:17.0633 1312 IsmServ (1b1a2084540cc1f2e9a297a263d69d23) C:\WINDOWS\System32\ismserv.exe
10:01:17.0633 1312 IsmServ - ok
10:01:17.0758 1312 JavaQuickStarterService (a1509ba3a5fdc5366146e92b3d130eb5) C:\Program Files\Java\jre7\bin\jqs.exe
10:01:17.0758 1312 JavaQuickStarterService - ok
10:01:17.0868 1312 Kbdclass (e5097a07e14f36abc21fa18d88f93655) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:01:17.0883 1312 Kbdclass - ok
10:01:17.0993 1312 kbdhid (665f2ae9286dbb05b045ccc02f7bc2f8) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:01:17.0993 1312 kbdhid - ok
10:01:18.0118 1312 kdc (d4b61a935670c57a0dea81b4f4a12169) C:\WINDOWS\System32\lsass.exe
10:01:18.0118 1312 kdc - ok
10:01:18.0243 1312 KSecDD (2e47d8ffe0965d166f962a45302c7edd) C:\WINDOWS\system32\drivers\KSecDD.sys
10:01:18.0243 1312 KSecDD - ok
10:01:18.0321 1312 lanmanserver (dfc5b13f931461acc025d76d39afec0d) C:\WINDOWS\System32\srvsvc.dll
10:01:18.0321 1312 lanmanserver - ok
10:01:18.0446 1312 lanmanworkstation (5e8a9c4673b194dd1181b3f003d4f996) C:\WINDOWS\System32\wkssvc.dll
10:01:18.0446 1312 lanmanworkstation - ok
10:01:18.0680 1312 LicenseService (647945b72994e7b4a07f6da10f1dcd79) C:\WINDOWS\System32\llssrv.exe
10:01:18.0680 1312 LicenseService - ok
10:01:18.0805 1312 LmHosts (1916d44188853a53db93aecc6e6197d0) C:\WINDOWS\System32\lmhsvc.dll
10:01:18.0805 1312 LmHosts - ok
10:01:18.0915 1312 lp6nds35 - ok
10:01:19.0040 1312 lsi_sas (6b594eb941baa898874b4f43afd296ec) C:\WINDOWS\system32\drivers\lsi_sas.sys
10:01:19.0040 1312 lsi_sas - ok
10:01:19.0165 1312 MBAMSwissArmy (0905dc0814d738cff53577a59ccd81e0) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
10:01:19.0165 1312 MBAMSwissArmy - ok
10:01:19.0290 1312 MDM (7cf1b716372b89568ae4c0fe769f5869) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
10:01:19.0290 1312 MDM - ok
10:01:19.0415 1312 MegaMonitorSrv (52cdb0d804111b46c7e6777697e344c9) C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
10:01:19.0430 1312 MegaMonitorSrv - ok
10:01:19.0524 1312 Messenger (7ce5ba9dd4beafa48dd099564046c6de) C:\WINDOWS\System32\msgsvc.dll
10:01:19.0524 1312 Messenger - ok
10:01:19.0649 1312 mnmdd (c35bb38904d843c0465858195b30dab7) C:\WINDOWS\system32\drivers\mnmdd.sys
10:01:19.0649 1312 mnmdd - ok
10:01:19.0774 1312 mnmsrvc (e2d859fa2e90fd1f12ca0806df8a4b3e) C:\WINDOWS\system32\mnmsrvc.exe
10:01:19.0774 1312 mnmsrvc - ok
10:01:19.0899 1312 Modem (81ec1c6d3798b36a92a6d7a355ba2c62) C:\WINDOWS\system32\drivers\Modem.sys
10:01:19.0899 1312 Modem - ok
10:01:20.0008 1312 Mouclass (aa50da5ab638ce0bab5f7d5d633110c2) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:01:20.0024 1312 Mouclass - ok
10:01:20.0133 1312 mouhid (6824b20127716121b53a2ec2bd6739b7) C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:01:20.0133 1312 mouhid - ok
10:01:20.0274 1312 MountMgr (fc43a7a34309c750b9daeadf2f6ec9b9) C:\WINDOWS\system32\drivers\MountMgr.sys
10:01:20.0274 1312 MountMgr - ok
10:01:20.0383 1312 mraid35x - ok
10:01:20.0508 1312 MRxDAV (ab6db63a1791f8e86b085291686464fd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:01:20.0524 1312 MRxDAV - ok
10:01:20.0649 1312 MRxSmb (16936142fa1d989cf63fd22c8b9d4a6d) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:01:20.0680 1312 MRxSmb - ok
10:01:20.0758 1312 MSDTC (2eaa1763a77be385b9a71a843c7f159e) C:\WINDOWS\system32\msdtc.exe
10:01:20.0758 1312 MSDTC - ok
10:01:20.0993 1312 Msfs (8f50b87361585763841c6b603d23260c) C:\WINDOWS\system32\drivers\Msfs.sys
10:01:20.0993 1312 Msfs - ok
10:01:21.0118 1312 msftesql (f7e0900f9a8e3f71f2c16a932f0e03e0) C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
10:01:21.0149 1312 msftesql - ok
10:01:21.0352 1312 MSIServer - ok
10:01:21.0477 1312 MSMFramework (a8bba3aa1d11102ffec5072d8afdb7b3) C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe
10:01:21.0477 1312 MSMFramework - ok
10:01:21.0727 1312 mssmbios (92afab2f216ce8ffbad3bc510fcf4a33) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:01:21.0727 1312 mssmbios - ok
10:01:21.0836 1312 MSSQL$SQLEXPRESS - ok
10:01:21.0961 1312 MSSQLSERVER - ok
10:01:22.0086 1312 MSSQLServerADHelper (c06ea83f6fc2959e897c117255b6b1d5) c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
10:01:22.0102 1312 MSSQLServerADHelper - ok
10:01:22.0227 1312 MSSQLServerADHelper100 (f1761c8fb2b25a32c6d63e36bb88c3ae) C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
10:01:22.0243 1312 MSSQLServerADHelper100 - ok
10:01:22.0352 1312 Mup (834560abee4eae62620f4026263aa051) C:\WINDOWS\system32\drivers\Mup.sys
10:01:22.0352 1312 Mup - ok
10:01:22.0461 1312 NDIS (33739ab31d36184772af1ee132d5c2e2) C:\WINDOWS\system32\drivers\NDIS.sys
10:01:22.0461 1312 NDIS - ok
10:01:22.0586 1312 NdisTapi (888b08f81b7d8428a37439d15c27f419) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:01:22.0586 1312 NdisTapi - ok
10:01:22.0696 1312 Ndisuio (8b8e682b03483092e17ab9dfe70fedff) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:01:22.0711 1312 Ndisuio - ok
10:01:22.0821 1312 NdisWan (1b397eef4614419be5679e0209f7848b) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:01:22.0836 1312 NdisWan - ok
10:01:22.0946 1312 NDProxy (5298ed90bbe5c5eeedc363eed2888a25) C:\WINDOWS\system32\drivers\NDProxy.sys
10:01:22.0946 1312 NDProxy - ok
10:01:23.0071 1312 NetBIOS (a0d5d6ae530ca78a062fc0471f1e6f78) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:01:23.0071 1312 NetBIOS - ok
10:01:23.0196 1312 NetBT (5cd7cca08498ec8753b22e92d367ca11) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:01:23.0196 1312 NetBT - ok
10:01:23.0368 1312 NetDDE (13d9a8b63a2a99a88339c0e00b702c92) C:\WINDOWS\system32\netdde.exe
10:01:23.0368 1312 NetDDE - ok
10:01:23.0477 1312 NetDDEdsdm (13d9a8b63a2a99a88339c0e00b702c92) C:\WINDOWS\system32\netdde.exe
10:01:23.0477 1312 NetDDEdsdm - ok
10:01:23.0602 1312 Netlogon (d4b61a935670c57a0dea81b4f4a12169) C:\WINDOWS\system32\lsass.exe
10:01:23.0602 1312 Netlogon - ok
10:01:23.0727 1312 Netman (12bcfb57162ad17cea545e362cd886a8) C:\WINDOWS\System32\netman.dll
10:01:23.0727 1312 Netman - ok
10:01:23.0852 1312 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
10:01:23.0852 1312 NetTcpPortSharing - ok
10:01:23.0961 1312 nfrd960 - ok
10:01:24.0086 1312 Nla (9c0bf64484e9d297cb3e96dc22765a82) C:\WINDOWS\System32\mswsock.dll
10:01:24.0102 1312 Nla - ok
10:01:24.0274 1312 npdrv (f35135cc422683f3e6dfb2a0600f6fe6) C:\WINDOWS\system32\drivers\npdrv.sys
10:01:24.0290 1312 npdrv - ok
10:01:24.0399 1312 Npfs (d5bb605f6dcbdfe0129670c8de57913e) C:\WINDOWS\system32\drivers\Npfs.sys
10:01:24.0399 1312 Npfs - ok
10:01:24.0524 1312 NtFrs (981756f0532439aa3a1a4ae9da9f930e) C:\WINDOWS\system32\ntfrs.exe
10:01:24.0540 1312 NtFrs - ok
10:01:24.0649 1312 Ntfs (482ea51aadb8763a0f67588c394ec693) C:\WINDOWS\system32\drivers\Ntfs.sys
10:01:24.0665 1312 Ntfs - ok
10:01:24.0758 1312 NtLmSsp (d4b61a935670c57a0dea81b4f4a12169) C:\WINDOWS\system32\lsass.exe
10:01:24.0758 1312 NtLmSsp - ok
10:01:24.0883 1312 NtmsSvc (fea5225ef80d5930b86d7a6570bcbbdf) C:\WINDOWS\system32\ntmssvc.dll
10:01:24.0899 1312 NtmsSvc - ok
10:01:24.0993 1312 Null (5db0ede7aaf3a7bc9110d18c12524be0) C:\WINDOWS\system32\drivers\Null.sys
10:01:24.0993 1312 Null - ok
10:01:25.0211 1312 nv (83780f3a86d2804912f22f6e37cd2254) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:01:25.0321 1312 nv - ok
10:01:25.0383 1312 NVSvc (42321ac5448078131903b272e6c49024) C:\WINDOWS\system32\nvsvc32.exe
10:01:25.0399 1312 NVSvc - ok
10:01:25.0508 1312 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
10:01:25.0540 1312 odserv - ok
10:01:25.0633 1312 OpenSSHd (a61d617f37456d9d32f98bf70eb5d414) C:\Program Files\OpenSSH\bin\cygrunsrv.exe
10:01:25.0633 1312 OpenSSHd - ok
10:01:25.0758 1312 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:01:25.0774 1312 ose - ok
10:01:25.0930 1312 Parport (ee3333b36deb86a0d472f037172da10a) C:\WINDOWS\system32\drivers\Parport.sys
10:01:25.0930 1312 Parport - ok
10:01:26.0055 1312 PartMgr (4eb6f7418959444a06d3c51eb81bff04) C:\WINDOWS\system32\drivers\PartMgr.sys
10:01:26.0055 1312 PartMgr - ok
10:01:26.0180 1312 PCI (8217000e5c53ce823b3111f339e47c41) C:\WINDOWS\system32\DRIVERS\pci.sys
10:01:26.0180 1312 PCI - ok
10:01:26.0336 1312 PCIIde (7e3fb50aa22d4ed883c6abdd40e9c60b) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:01:26.0336 1312 PCIIde - ok
10:01:26.0461 1312 Pcmcia (fc9f4c9c73e9698357c836be4628a299) C:\WINDOWS\system32\drivers\Pcmcia.sys
10:01:26.0461 1312 Pcmcia - ok
10:01:26.0586 1312 PDCOMP - ok
10:01:26.0696 1312 PDFRAME - ok
10:01:26.0821 1312 PDRELI - ok
10:01:26.0946 1312 PDRFRAME - ok
10:01:27.0071 1312 perc2 - ok
10:01:27.0118 1312 perc2hib - ok
10:01:27.0493 1312 PlugPlay (cf500580cdd83b145646a4dcfce1cf3c) C:\WINDOWS\system32\services.exe
10:01:27.0508 1312 PlugPlay - ok
10:01:27.0618 1312 PolicyAgent (d4b61a935670c57a0dea81b4f4a12169) C:\WINDOWS\system32\lsass.exe
10:01:27.0618 1312 PolicyAgent - ok
10:01:27.0743 1312 PptpMiniport (4454f2639bcca93be86a45137e427277) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:01:27.0743 1312 PptpMiniport - ok
10:01:27.0852 1312 ProtectedStorage (d4b61a935670c57a0dea81b4f4a12169) C:\WINDOWS\system32\lsass.exe
10:01:27.0852 1312 ProtectedStorage - ok
10:01:27.0977 1312 Ptilink (0320fd91fb5ed4298355977cecfc0eb4) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:01:27.0977 1312 Ptilink - ok
10:01:28.0102 1312 q57w2k (f10d8d61a60c0a8a38bcaf88b7d75c34) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
10:01:28.0118 1312 q57w2k - ok
10:01:28.0227 1312 QBCFMonitorService (296c2565b69b1d933e65807c0155350c) C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
10:01:28.0243 1312 QBCFMonitorService - ok
10:01:28.0352 1312 QBFCService (77aea3f9383a2690a44ae5496fd0631c) C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
10:01:28.0352 1312 QBFCService - ok
10:01:28.0461 1312 ql1080 - ok
10:01:28.0586 1312 Ql10wnt - ok
10:01:28.0696 1312 ql12160 - ok
10:01:28.0821 1312 ql1240 - ok
10:01:28.0946 1312 ql1280 - ok
10:01:29.0071 1312 ql2100 - ok
10:01:29.0180 1312 ql2200 - ok
10:01:29.0368 1312 ql2300 - ok
10:01:29.0493 1312 QuickBooksDB17 - ok
10:01:29.0618 1312 QuickBooksDB18 - ok
10:01:29.0758 1312 QuickBooksDB19 - ok
10:01:29.0946 1312 QuickBooksDB20 - ok
10:01:30.0165 1312 RasAcd (48ee7b6802c0306f9a66f34db7e9ef75) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:01:30.0180 1312 RasAcd - ok
10:01:30.0383 1312 RasAuto (ed67fa5dc9ce0bfc5ccce4296c684a57) C:\WINDOWS\System32\rasauto.dll
10:01:30.0399 1312 RasAuto - ok
10:01:30.0633 1312 Rasl2tp (3633175613e052ecb41776dee2777a89) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:01:30.0633 1312 Rasl2tp - ok
10:01:30.0821 1312 RasMan (02bc610cc90ca5415eb2c9409e77d583) C:\WINDOWS\System32\rasmans.dll
10:01:30.0836 1312 RasMan - ok
10:01:31.0040 1312 RasPppoe (59842f0a22216a71cade6f89fe84c973) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:01:31.0040 1312 RasPppoe - ok
10:01:31.0196 1312 Raspti (5b11871de804d3ed28bbdcc65fe14ede) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:01:31.0196 1312 Raspti - ok
10:01:31.0321 1312 Rdbss (4496b15c44ccb703fbc54f2cf5b67f15) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:01:31.0321 1312 Rdbss - ok
10:01:31.0446 1312 RDPCDD (ac5bb528ecd2bea4ff4bff9df9baf749) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:01:31.0446 1312 RDPCDD - ok
10:01:31.0618 1312 rdpdr (ff678596b761e1ccba79f49981ef51bc) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:01:31.0633 1312 rdpdr - ok
10:01:31.0805 1312 RDPWD (4e2e9b17a618433d68697a3c6d8ddd6e) C:\WINDOWS\system32\drivers\RDPWD.sys
10:01:31.0805 1312 RDPWD - ok
10:01:31.0930 1312 RDSessMgr (81f1cf0ed96e58a391ff83f792c87f3e) C:\WINDOWS\system32\sessmgr.exe
10:01:31.0930 1312 RDSessMgr - ok
10:01:32.0040 1312 redbook (c6f8751f3263603935866e71629cfae4) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:01:32.0055 1312 redbook - ok
10:01:32.0165 1312 RemoteAccess (d8f172c1ca72666d8193e226da7225f4) C:\WINDOWS\System32\mprdim.dll
10:01:32.0165 1312 RemoteAccess - ok
10:01:32.0290 1312 RemoteRegistry (55efa91d1c0de44c22d2d83413b06510) C:\WINDOWS\system32\regsvc.dll
10:01:32.0290 1312 RemoteRegistry - ok
10:01:32.0415 1312 ReportServer (d13465b5bbb9110c8a0a873ddc09fb8c) C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
10:01:32.0430 1312 ReportServer - ok
10:01:32.0540 1312 RpcLocator (a83414d7a45555274e99793aa22d54ab) C:\WINDOWS\system32\locator.exe
10:01:32.0540 1312 RpcLocator - ok
10:01:32.0665 1312 RpcSs (305a8757d66b5d416b47c497c27a01fe) C:\WINDOWS\system32\rpcss.dll
10:01:32.0665 1312 RpcSs - ok
10:01:32.0774 1312 RsFx0102 (fedd2710b75be3ecf078adace790c423) C:\WINDOWS\system32\DRIVERS\RsFx0102.sys
10:01:32.0774 1312 RsFx0102 - ok
10:01:32.0899 1312 RSoPProv (3357c6edd71e73110c83f54e35ecde4d) C:\WINDOWS\system32\RSoPProv.exe
10:01:32.0899 1312 RSoPProv - ok
10:01:33.0008 1312 sacdrv (34d79729d6e4d1289e08322405045085) C:\WINDOWS\system32\drivers\sacdrv.sys
10:01:33.0024 1312 sacdrv - ok
10:01:33.0133 1312 sacsvr (77919394900dec12c8e65cb35d6272fe) C:\WINDOWS\system32\sacsvr.dll
10:01:33.0133 1312 sacsvr - ok
10:01:33.0258 1312 SamSs (d4b61a935670c57a0dea81b4f4a12169) C:\WINDOWS\system32\lsass.exe
10:01:33.0321 1312 SamSs - ok
10:01:33.0446 1312 SCardSvr (edf6b1852a55581ecc6ba18b4e2c6e8e) C:\WINDOWS\System32\SCardSvr.exe
10:01:33.0446 1312 SCardSvr - ok
10:01:33.0571 1312 Schedule (7e60f04ae424401a14d153ca6e851a85) C:\WINDOWS\system32\schedsvc.dll
10:01:33.0571 1312 Schedule - ok
10:01:33.0743 1312 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:01:33.0743 1312 Secdrv - ok
10:01:33.0868 1312 seclogon (03911d9a5d15a80301e767f787c0b015) C:\WINDOWS\System32\seclogon.dll
10:01:33.0868 1312 seclogon - ok
10:01:33.0993 1312 SENS (97b6172283112af7451e4abe83dd6f24) C:\WINDOWS\system32\sens.dll
10:01:33.0993 1312 SENS - ok
10:01:34.0102 1312 serenum (b261d4597bf9a2723b7020207260c72a) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:01:34.0102 1312 serenum - ok
10:01:34.0227 1312 Serial (95768fde08dd34089aa90dccb5537704) C:\WINDOWS\system32\DRIVERS\serial.sys
10:01:34.0258 1312 Serial - ok
10:01:34.0540 1312 Sfloppy (831826dc54fa225f0b654ef2f1e13af9) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:01:34.0540 1312 Sfloppy - ok
10:01:34.0665 1312 SharedAccess (27c6b8c2afed21c10429a56db95735f6) C:\WINDOWS\system32\ipnathlp.dll
10:01:34.0665 1312 SharedAccess - ok
10:01:34.0790 1312 ShellHWDetection (0af6401bdbd41a8b7aed5c923b8fdf4d) C:\WINDOWS\System32\shsvcs.dll
10:01:34.0790 1312 ShellHWDetection - ok
10:01:34.0899 1312 Simbad - ok
10:01:35.0086 1312 SNMP (e649d2345614e56249ce3f0b64849547) C:\WINDOWS\System32\snmp.exe
10:01:35.0086 1312 SNMP - ok
10:01:35.0211 1312 SNMPTRAP (b2a7b19f00d6dd8671ff5edc142c151b) C:\WINDOWS\System32\snmptrap.exe
10:01:35.0211 1312 SNMPTRAP - ok
10:01:35.0336 1312 Spooler (30b32e3127d9bbaa1e32394134718070) C:\WINDOWS\system32\spoolsv.exe
10:01:35.0336 1312 Spooler - ok
10:01:35.0461 1312 SQLAgent$SQLEXPRESS (eb2fd937449b7aceb39372f875eb8e78) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
10:01:35.0461 1312 SQLAgent$SQLEXPRESS - ok
10:01:35.0571 1312 SQLBrowser (99de6acfa5ca83fad6a765c81c6f129f) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
10:01:35.0586 1312 SQLBrowser - ok
10:01:35.0696 1312 SQLSERVERAGENT (a2b96e2e86e11f9aabf69fb199c28966) C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\SQLAGENT90.EXE
10:01:35.0711 1312 SQLSERVERAGENT - ok
10:01:35.0821 1312 SQLWriter (637a0f23f9012358e92e6f99835494d1) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
10:01:35.0821 1312 SQLWriter - ok
10:01:35.0930 1312 Srv (e8b1a07774a9e4fec3105cbad49bf289) C:\WINDOWS\system32\DRIVERS\srv.sys
10:01:35.0946 1312 Srv - ok
10:01:36.0055 1312 startdss - ok
10:01:36.0118 1312 stisvc (0df3c24094f68a5e5fa77a681e438a46) C:\WINDOWS\system32\wiaservc.dll
10:01:36.0133 1312 stisvc - ok
10:01:36.0243 1312 swenum (93965919785102ba847545ab460ce2df) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:01:36.0243 1312 swenum - ok
10:01:36.0383 1312 swprv (0ba2f4d23d62f7475a70d1988142d6bd) C:\WINDOWS\System32\swprv.dll
10:01:36.0383 1312 swprv - ok
10:01:36.0493 1312 symc810 - ok
10:01:36.0618 1312 symc8xx - ok
10:01:36.0727 1312 symmpi - ok
10:01:36.0852 1312 sym_hi - ok
10:01:36.0977 1312 sym_u3 - ok
10:01:37.0118 1312 SysMgmtHp (e9a79164342b6e25d4717134b227bc23) C:\hp\hpsmh\bin\smhstart.exe
10:01:37.0165 1312 SysMgmtHp - ok
10:01:37.0258 1312 SysmonLog (cc8610d2ffaff19d5c9cf8ce9ffad71a) C:\WINDOWS\system32\smlogsvc.exe
10:01:37.0274 1312 SysmonLog - ok
10:01:37.0352 1312 TapiSrv (ce1fcaf92f06bb8549c9e1b8605b90cc) C:\WINDOWS\System32\tapisrv.dll
10:01:37.0368 1312 TapiSrv - ok
10:01:37.0477 1312 Tcpip (238dc2b879d1b37b91f8d5d44f3815d3) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:01:37.0477 1312 Tcpip - ok
10:01:37.0586 1312 TDPIPE (45d49fb800463de84d1cc2e231319ad5) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:01:37.0586 1312 TDPIPE - ok
10:01:37.0711 1312 TDTCP (d7c31008de209b8b11ced207580e9c91) C:\WINDOWS\system32\drivers\TDTCP.sys
10:01:37.0711 1312 TDTCP - ok
10:01:37.0836 1312 TermDD (a01e46fff445a38d35db188c5458582c) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:01:37.0836 1312 TermDD - ok
10:01:37.0961 1312 TermService (5f0bd29cbd95465a3aa3ca319bc591a9) C:\WINDOWS\System32\termsrv.dll
10:01:37.0961 1312 TermService - ok
10:01:38.0086 1312 TermServLicensing (bc18bee62e7aec10b33c149ca3b64eae) C:\WINDOWS\system32\lserver.exe
10:01:38.0086 1312 TermServLicensing - ok
10:01:38.0196 1312 Themes (0af6401bdbd41a8b7aed5c923b8fdf4d) C:\WINDOWS\System32\shsvcs.dll
10:01:38.0196 1312 Themes - ok
10:01:38.0336 1312 TlntSvr (fe7ff05a90c1a24855b1cdc066b959e0) C:\WINDOWS\system32\tlntsvr.exe
10:01:38.0336 1312 TlntSvr - ok
10:01:38.0461 1312 tmactmon (7131c804d8847b695125bb8d91d64ee0) C:\WINDOWS\system32\DRIVERS\tmactmon.sys
10:01:38.0461 1312 tmactmon - ok
10:01:38.0586 1312 tmcfw (0be90f3fc8ed04554fa3c391ab22f222) C:\WINDOWS\system32\DRIVERS\TM_CFW.sys
10:01:38.0586 1312 tmcfw - ok
10:01:38.0696 1312 tmcomm (09f386a6ec8d6c37bfa0d5394cb186c1) C:\WINDOWS\system32\DRIVERS\tmcomm.sys
10:01:38.0696 1312 tmcomm - ok
10:01:38.0821 1312 tmevtmgr (c75310cbd1bccf3469c834143bc2390c) C:\WINDOWS\system32\DRIVERS\tmevtmgr.sys
10:01:38.0821 1312 tmevtmgr - ok
10:01:38.0946 1312 TmListen (dcd55afb49710a8ccc8183c6ae5e02f4) C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
10:01:38.0961 1312 TmListen - ok
10:01:39.0055 1312 tmtdi (69bf24e2871088115f422d6c7f41c400) C:\WINDOWS\system32\DRIVERS\tmtdi.sys
10:01:39.0055 1312 tmtdi - ok
10:01:39.0180 1312 TosIde - ok
10:01:39.0383 1312 TrkSvr (2ee42aced5fd4e1988116edeced90e93) C:\WINDOWS\system32\trksvr.dll
10:01:39.0383 1312 TrkSvr - ok
10:01:39.0493 1312 TrkWks (671fc35e995ffdbced00202771c6d169) C:\WINDOWS\system32\trkwks.dll
10:01:39.0493 1312 TrkWks - ok
10:01:39.0680 1312 Tssdis (43992245309838eacd05506b474985e5) C:\WINDOWS\System32\tssdis.exe
10:01:39.0680 1312 Tssdis - ok
10:01:39.0805 1312 Udfs (c26024265a7523312a5d06fc33aa57aa) C:\WINDOWS\system32\drivers\Udfs.sys
10:01:39.0805 1312 Udfs - ok
10:01:39.0915 1312 ultra - ok
10:01:40.0040 1312 UMWdf (997fe835c85d0fb0501df6664d6fd072) C:\WINDOWS\system32\wdfmgr.exe
10:01:40.0040 1312 UMWdf - ok
10:01:40.0165 1312 Update (b0e133858e63940755b496761834f334) C:\WINDOWS\system32\DRIVERS\update.sys
10:01:40.0180 1312 Update - ok
10:01:40.0290 1312 UPS (92c3a632e963a8224fe62aa37c9508f6) C:\WINDOWS\System32\ups.exe
10:01:40.0290 1312 UPS - ok
10:01:40.0399 1312 usbccgp (185959a7fccfd38aa71a274ae6252b88) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:01:40.0415 1312 usbccgp - ok
10:01:40.0540 1312 USBDLM (eb52059f51189e99174040f6318236f8) C:\Program Files\USBDLM\USBDLM.exe
10:01:40.0540 1312 USBDLM - ok
10:01:40.0649 1312 usbehci (9dd4aba9462938734bcbf51d8669c884) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:01:40.0649 1312 usbehci - ok
10:01:40.0774 1312 usbhub (17859937740bc0d422fe71a588d6ddf7) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:01:40.0790 1312 usbhub - ok
10:01:40.0883 1312 usbstor (d0740ff9f7e819486e88096826b4dc37) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:01:40.0883 1312 usbstor - ok
10:01:41.0008 1312 usbuhci (cbd3053337bb475f442a892edf671312) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:01:41.0008 1312 usbuhci - ok
10:01:41.0133 1312 vds (5ce9331dc4c9e3b1fa4aaef1b212701f) C:\WINDOWS\System32\vds.exe
10:01:41.0149 1312 vds - ok
10:01:41.0258 1312 vga (2eb062b434792bb6bb614f107dd3a5cf) C:\WINDOWS\system32\DRIVERS\vgapnp.sys
10:01:41.0258 1312 vga - ok
10:01:41.0368 1312 VgaSave (062fbc10147fd837d819f94aa394e661) C:\WINDOWS\System32\drivers\vga.sys
10:01:41.0383 1312 VgaSave - ok
10:01:41.0493 1312 ViaIde - ok
10:01:41.0618 1312 VolSnap (45ae67c387a640ec6e228f30d421f088) C:\WINDOWS\system32\DRIVERS\volsnap.sys
10:01:41.0618 1312 VolSnap - ok
10:01:41.0758 1312 VSS (74a6820792e5bca5ee4d0cc4595c6916) C:\WINDOWS\System32\vssvc.exe
10:01:41.0774 1312 VSS - ok
10:01:41.0868 1312 W32Time (42cdae64da5beabb51c0c0f613658545) C:\WINDOWS\system32\w32time.dll
10:01:41.0868 1312 W32Time - ok
10:01:41.0977 1312 W3SVC (db0e023ee673896ad1780acad3bab393) C:\WINDOWS\system32\inetsrv\iisw3adm.dll
10:01:41.0993 1312 W3SVC - ok
10:01:42.0102 1312 Wanarp (ce030b1d05a01fa012d32f2d25676b1c) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:01:42.0102 1312 Wanarp - ok
10:01:42.0227 1312 WbemConsumer (c009c54547b2786773da6a369ede1099) C:\Program Files\The Open Group\WMI Mapper\bin\WbemCons.exe
10:01:42.0243 1312 WbemConsumer - ok
10:01:42.0336 1312 WDICA - ok
10:01:42.0461 1312 WebClient (6f66e66ab1c25c0bd363f2252db04360) C:\WINDOWS\System32\webclnt.dll
10:01:42.0477 1312 WebClient - ok
10:01:42.0649 1312 WinHttpAutoProxySvc - ok
10:01:42.0774 1312 winmgmt (f8d5b9c1a26c933b9ea7740bab35bcf5) C:\WINDOWS\system32\wbem\WMIsvc.dll
10:01:42.0774 1312 winmgmt - ok
10:01:43.0071 1312 WLBS (d346e2f289f23e557ddfb9132d1dab35) C:\WINDOWS\system32\DRIVERS\wlbs.sys
10:01:43.0071 1312 WLBS - ok
10:01:43.0196 1312 WmdmPmSN (4d32f7bdbf325792ae28d5380ddf6bcf) C:\WINDOWS\system32\mspmsnsv.dll
10:01:43.0196 1312 WmdmPmSN - ok
10:01:43.0321 1312 Wmi (2085b957fb56927a8f3768de740612c4) C:\WINDOWS\System32\advapi32.dll
10:01:43.0336 1312 Wmi - ok
10:01:43.0446 1312 WMI Mapper (44791f9ab35dfcabd569520c6be4426f) C:\Program Files\The Open Group\WMI Mapper\bin\WMIServer.exe
10:01:43.0446 1312 WMI Mapper - ok
10:01:43.0633 1312 WmiApSrv (796d30c693f7b8a717499a9abeb3af39) C:\WINDOWS\system32\wbem\wmiapsrv.exe
10:01:43.0633 1312 WmiApSrv - ok
10:01:43.0743 1312 wqvtpuxyitqfuyc - ok
10:01:43.0915 1312 wuauserv (996cec79b1662044e8462e130a65739e) C:\WINDOWS\system32\wuauserv.dll
10:01:43.0930 1312 wuauserv - ok
10:01:44.0055 1312 WZCSVC (e21b2d0a0d4ab1d2441fe9fcc961c392) C:\WINDOWS\System32\wzcsvc.dll
10:01:44.0071 1312 WZCSVC - ok
10:01:44.0165 1312 xmlprov (c5b83f9a09a3ebfe8a931472f6da4e38) C:\WINDOWS\System32\xmlprov.dll
10:01:44.0165 1312 xmlprov - ok
10:01:44.0352 1312 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
10:01:44.0430 1312 \Device\Harddisk0\DR0 - ok
10:01:44.0524 1312 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
10:01:44.0524 1312 \Device\Harddisk1\DR1 - ok
10:01:44.0883 1312 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk2\DR4
10:01:44.0946 1312 \Device\Harddisk2\DR4 - ok
10:01:45.0008 1312 Boot (0x1200) (bb2cd8525573860114f1c1488ee898f1) \Device\Harddisk0\DR0\Partition0
10:01:45.0008 1312 \Device\Harddisk0\DR0\Partition0 - ok
10:01:45.0118 1312 Boot (0x1200) (9656eff4b74c82fadc1590a2a2f74017) \Device\Harddisk2\DR4\Partition0
10:01:45.0133 1312 \Device\Harddisk2\DR4\Partition0 - ok
10:01:45.0180 1312 ============================================================
10:01:45.0180 1312 Scan finished
10:01:45.0180 1312 ============================================================
10:01:45.0399 1316 Detected object count: 1
10:01:45.0399 1316 Actual detected object count: 1
10:02:10.0493 1316 C:\WINDOWS\system32\DRIVERS\disk.sys - copied to quarantine
10:02:10.0524 1316 \Device\Harddisk0\DR0\TDLFS\tdl - copied to quarantine
10:02:10.0524 1316 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
10:02:10.0540 1316 \Device\Harddisk0\DR0\TDLFS\rsrc.dat - copied to quarantine
10:02:11.0727 1316 Backup copy found, using it..
10:02:11.0836 1316 C:\WINDOWS\system32\DRIVERS\disk.sys - will be cured on reboot
10:02:11.0836 1316 Disk ( Rootkit.Win32.TDSS.tdl3 ) - User select action: Cure
10:02:19.0524 0196 Deinitialize success