02:26:28.0937 3432 TDSS rootkit removing tool 2.7.15.0 Feb 27 2012 12:59:02 02:26:29.0140 3432 ============================================================ 02:26:29.0140 3432 Current date / time: 2012/02/28 02:26:29.0140 02:26:29.0140 3432 SystemInfo: 02:26:29.0140 3432 02:26:29.0140 3432 OS Version: 5.1.2600 ServicePack: 2.0 02:26:29.0140 3432 Product type: Workstation 02:26:29.0140 3432 ComputerName: RADEK 02:26:29.0140 3432 UserName: Admin 02:26:29.0140 3432 Windows directory: C:\WINDOWS 02:26:29.0140 3432 System windows directory: C:\WINDOWS 02:26:29.0140 3432 Processor architecture: Intel x86 02:26:29.0140 3432 Number of processors: 1 02:26:29.0140 3432 Page size: 0x1000 02:26:29.0140 3432 Boot type: Normal boot 02:26:29.0140 3432 ============================================================ 02:26:30.0453 3432 Drive \Device\Harddisk0\DR0 - Size: 0x12A3F92000 (74.56 Gb), SectorSize: 0x200, Cylinders: 0x2605, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 02:26:30.0468 3432 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 02:26:30.0468 3432 \Device\Harddisk0\DR0: 02:26:30.0468 3432 MBR used 02:26:30.0468 3432 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x951A0C5 02:26:30.0468 3432 \Device\Harddisk1\DR1: 02:26:30.0468 3432 MBR used 02:26:30.0468 3432 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82 02:26:30.0703 3432 Initialize success 02:26:30.0703 3432 ============================================================ 02:26:34.0453 3520 ============================================================ 02:26:34.0453 3520 Scan started 02:26:34.0453 3520 Mode: Manual; 02:26:34.0453 3520 ============================================================ 02:26:35.0906 3520 Aavmker4 (95d1de2a6613494e853a9738d5d9acd4) C:\WINDOWS\system32\drivers\Aavmker4.sys 02:26:35.0906 3520 Aavmker4 - ok 02:26:36.0031 3520 Abiosdsk - ok 02:26:36.0125 3520 abp480n5 - ok 02:26:36.0250 3520 ACPI (56922f51dde99b23a9c61fd5ac25fd7f) C:\WINDOWS\system32\DRIVERS\ACPI.sys 02:26:36.0250 3520 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ACPI.sys. Real md5: 56922f51dde99b23a9c61fd5ac25fd7f, Fake md5: a966410ecf83b81f3b0b8e07a71957d4 02:26:36.0250 3520 ACPI ( Virus.Win32.Rloader.a ) - infected 02:26:36.0250 3520 ACPI - detected Virus.Win32.Rloader.a (0) 02:26:36.0343 3520 ACPIEC (66a42b7db194e24b973bbcce840a0f3f) C:\WINDOWS\system32\drivers\ACPIEC.sys 02:26:36.0343 3520 ACPIEC - ok 02:26:36.0406 3520 adpu160m - ok 02:26:36.0515 3520 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 02:26:36.0515 3520 aec - ok 02:26:36.0609 3520 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 02:26:36.0609 3520 AFD - ok 02:26:36.0671 3520 Aha154x - ok 02:26:36.0718 3520 aic78u2 - ok 02:26:36.0796 3520 aic78xx - ok 02:26:36.0921 3520 alcan5wn (c7e217cd964d0067f18263429c87ec1b) C:\WINDOWS\system32\DRIVERS\alcan5wn.sys 02:26:36.0921 3520 alcan5wn - ok 02:26:37.0031 3520 alcaudsl (8080b5ea17a763bbce6c92bbc6ceefe8) C:\WINDOWS\system32\DRIVERS\alcaudsl.sys 02:26:37.0031 3520 alcaudsl - ok 02:26:37.0109 3520 AliIde - ok 02:26:37.0234 3520 AmdK7 (2efcb57ddfb0aeda0751c29f844e3298) C:\WINDOWS\system32\DRIVERS\amdk7.sys 02:26:37.0234 3520 AmdK7 - ok 02:26:37.0312 3520 Amps2prt (44209326d6435ce6da046808f89b945f) C:\WINDOWS\system32\DRIVERS\Amps2prt.sys 02:26:37.0312 3520 Amps2prt - ok 02:26:37.0375 3520 amsint - ok 02:26:37.0453 3520 asc - ok 02:26:37.0531 3520 asc3350p - ok 02:26:37.0593 3520 asc3550 - ok 02:26:37.0718 3520 Aspi32 (eb62fa6d7da4e774e47d376e4d19ca5f) C:\WINDOWS\system32\drivers\aspi32.sys 02:26:37.0718 3520 Aspi32 - ok 02:26:37.0843 3520 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\WINDOWS\system32\drivers\aswFsBlk.sys 02:26:37.0843 3520 aswFsBlk - ok 02:26:38.0000 3520 aswMon2 (fff2dbb17a3c89f87f78d5fa72ca47fd) C:\WINDOWS\system32\drivers\aswMon2.sys 02:26:38.0000 3520 aswMon2 - ok 02:26:38.0093 3520 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\WINDOWS\system32\drivers\aswRdr.sys 02:26:38.0109 3520 aswRdr - ok 02:26:38.0234 3520 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\WINDOWS\system32\drivers\aswSnx.sys 02:26:38.0234 3520 aswSnx - ok 02:26:38.0359 3520 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\WINDOWS\system32\drivers\aswSP.sys 02:26:38.0359 3520 aswSP - ok 02:26:38.0484 3520 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\WINDOWS\system32\drivers\aswTdi.sys 02:26:38.0484 3520 aswTdi - ok 02:26:38.0578 3520 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 02:26:38.0578 3520 AsyncMac - ok 02:26:38.0671 3520 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 02:26:38.0671 3520 atapi - ok 02:26:38.0734 3520 Atdisk - ok 02:26:38.0890 3520 ati2mtag (d1333ac9ec252997bc3a19dd432dc42d) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 02:26:38.0906 3520 ati2mtag - ok 02:26:39.0015 3520 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 02:26:39.0015 3520 Atmarpc - ok 02:26:39.0125 3520 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 02:26:39.0125 3520 audstub - ok 02:26:39.0234 3520 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 02:26:39.0250 3520 Beep - ok 02:26:39.0375 3520 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 02:26:39.0390 3520 cbidf2k - ok 02:26:39.0453 3520 cd20xrnt - ok 02:26:39.0562 3520 CdaC15BA (f76cb7259aa575cc53f3996bc6b68c18) C:\WINDOWS\System32\drivers\CDAC15BA.SYS 02:26:39.0578 3520 CdaC15BA - ok 02:26:39.0671 3520 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 02:26:39.0671 3520 Cdaudio - ok 02:26:39.0781 3520 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 02:26:39.0781 3520 Cdfs - ok 02:26:39.0875 3520 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 02:26:39.0875 3520 Cdrom - ok 02:26:39.0937 3520 Changer - ok 02:26:40.0046 3520 CmdIde - ok 02:26:40.0187 3520 cmuda (e5adeef2c0db43964223f408f1fcc97e) C:\WINDOWS\system32\drivers\cmuda.sys 02:26:40.0218 3520 cmuda - ok 02:26:40.0312 3520 Cpqarray - ok 02:26:40.0421 3520 dac2w2k - ok 02:26:40.0484 3520 dac960nt - ok 02:26:40.0625 3520 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 02:26:40.0625 3520 Disk - ok 02:26:40.0750 3520 dmboot (3b809ffad55dcebdb156d5ca1bd3da65) C:\WINDOWS\system32\drivers\dmboot.sys 02:26:40.0765 3520 dmboot - ok 02:26:40.0875 3520 dmio (27725b6501201c3080ba73048bce389a) C:\WINDOWS\system32\DRIVERS\dmio.sys 02:26:40.0890 3520 dmio - ok 02:26:40.0937 3520 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 02:26:40.0937 3520 dmload - ok 02:26:41.0078 3520 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 02:26:41.0078 3520 DMusic - ok 02:26:41.0140 3520 dpti2o - ok 02:26:41.0218 3520 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 02:26:41.0218 3520 drmkaud - ok 02:26:41.0359 3520 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 02:26:41.0359 3520 Fastfat - ok 02:26:41.0468 3520 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 02:26:41.0484 3520 Fdc - ok 02:26:41.0515 3520 FETNDIS - ok 02:26:41.0593 3520 Fips (c5fb298257c0a6514ea17835e774ea0a) C:\WINDOWS\system32\drivers\Fips.sys 02:26:41.0609 3520 Fips - ok 02:26:41.0687 3520 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 02:26:41.0687 3520 Flpydisk - ok 02:26:41.0765 3520 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys 02:26:41.0765 3520 FltMgr - ok 02:26:41.0843 3520 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 02:26:41.0843 3520 Fs_Rec - ok 02:26:41.0890 3520 Ftdisk (ed6d921d8ab423138fb35beee6d6a6cb) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 02:26:41.0890 3520 Ftdisk - ok 02:26:41.0968 3520 gagp30kx (4216cd545e5c30807b560c5dcaa812e6) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys 02:26:41.0968 3520 gagp30kx - ok 02:26:42.0046 3520 gameenum (5f92fd09e5610a5995da7d775eadcd12) C:\WINDOWS\system32\DRIVERS\gameenum.sys 02:26:42.0062 3520 gameenum - ok 02:26:42.0125 3520 gmer (2ee3d781962bf3149451f118ffcbc634) C:\WINDOWS\system32\DRIVERS\gmer.sys 02:26:42.0125 3520 gmer - ok 02:26:42.0218 3520 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 02:26:42.0218 3520 Gpc - ok 02:26:42.0312 3520 GVCplDrv (f2b0226cc180ad1d64b27015d52182df) C:\WINDOWS\system32\drivers\GVCplDrv.sys 02:26:42.0312 3520 GVCplDrv - ok 02:26:42.0421 3520 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 02:26:42.0421 3520 HidUsb - ok 02:26:42.0453 3520 hpn - ok 02:26:42.0531 3520 HTTP (cb77bb47e67e84deb17ba29632501730) C:\WINDOWS\system32\Drivers\HTTP.sys 02:26:42.0546 3520 HTTP - ok 02:26:42.0593 3520 i2omgmt - ok 02:26:42.0640 3520 i2omp - ok 02:26:42.0734 3520 i8042prt (2656fdfe0a7916c3a16f374454c55dd9) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 02:26:42.0734 3520 i8042prt - ok 02:26:42.0828 3520 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 02:26:42.0828 3520 Imapi - ok 02:26:42.0906 3520 ini910u - ok 02:26:42.0968 3520 IntelIde - ok 02:26:43.0062 3520 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys 02:26:43.0062 3520 Ip6Fw - ok 02:26:43.0156 3520 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 02:26:43.0156 3520 IpFilterDriver - ok 02:26:43.0250 3520 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 02:26:43.0250 3520 IpInIp - ok 02:26:43.0343 3520 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 02:26:43.0343 3520 IpNat - ok 02:26:43.0421 3520 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 02:26:43.0437 3520 IPSec - ok 02:26:43.0515 3520 irda (86c204836feec22510d434982d4221b8) C:\WINDOWS\system32\DRIVERS\irda.sys 02:26:43.0515 3520 irda - ok 02:26:43.0609 3520 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 02:26:43.0609 3520 IRENUM - ok 02:26:43.0671 3520 irsir - ok 02:26:43.0750 3520 isapnp (01a9e68528f4f34e5702123d27c67bd4) C:\WINDOWS\system32\DRIVERS\isapnp.sys 02:26:43.0750 3520 isapnp - ok 02:26:43.0875 3520 Kbdclass (cc13db862f929ae33f64c3bedc01cd31) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 02:26:43.0875 3520 Kbdclass - ok 02:26:43.0953 3520 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 02:26:43.0953 3520 kmixer - ok 02:26:44.0046 3520 KS-959 (2ae47a0b7e05e9695f8c19b7d4e3f4c0) C:\WINDOWS\system32\DRIVERS\KS-959.sys 02:26:44.0046 3520 KS-959 - ok 02:26:44.0171 3520 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys 02:26:44.0171 3520 KSecDD - ok 02:26:44.0250 3520 lbrtfdc - ok 02:26:44.0406 3520 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 02:26:44.0406 3520 mnmdd - ok 02:26:44.0515 3520 Modem (15f33d12d604d0198ce5561f102cd9c5) C:\WINDOWS\system32\drivers\Modem.sys 02:26:44.0531 3520 Modem - ok 02:26:44.0609 3520 Mouclass (69c12b99ae8b6b99ec314e9b99833728) C:\WINDOWS\system32\DRIVERS\mouclass.sys 02:26:44.0609 3520 Mouclass - ok 02:26:44.0671 3520 mouhid (ecec1e6cd558ab80f944f31326e9d3b5) C:\WINDOWS\system32\DRIVERS\mouhid.sys 02:26:44.0671 3520 mouhid - ok 02:26:44.0765 3520 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 02:26:44.0765 3520 MountMgr - ok 02:26:44.0812 3520 mraid35x - ok 02:26:44.0890 3520 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 02:26:44.0906 3520 MRxDAV - ok 02:26:44.0984 3520 MRxSmb (6f2d483b97b395544e59749c47963c6a) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 02:26:45.0000 3520 MRxSmb - ok 02:26:45.0093 3520 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 02:26:45.0093 3520 Msfs - ok 02:26:45.0187 3520 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 02:26:45.0187 3520 MSKSSRV - ok 02:26:45.0265 3520 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 02:26:45.0281 3520 MSPCLOCK - ok 02:26:45.0390 3520 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 02:26:45.0390 3520 MSPQM - ok 02:26:45.0468 3520 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 02:26:45.0468 3520 mssmbios - ok 02:26:45.0546 3520 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys 02:26:45.0546 3520 ms_mpu401 - ok 02:26:45.0640 3520 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 02:26:45.0640 3520 Mup - ok 02:26:45.0718 3520 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 02:26:45.0718 3520 NDIS - ok 02:26:45.0796 3520 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 02:26:45.0812 3520 NdisTapi - ok 02:26:45.0890 3520 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 02:26:45.0890 3520 Ndisuio - ok 02:26:45.0984 3520 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 02:26:45.0984 3520 NdisWan - ok 02:26:46.0031 3520 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 02:26:46.0031 3520 NDProxy - ok 02:26:46.0109 3520 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 02:26:46.0109 3520 NetBIOS - ok 02:26:46.0203 3520 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 02:26:46.0203 3520 NetBT - ok 02:26:46.0328 3520 NetworkX (4ce3be79566c107ce84d944ba570aaa5) C:\WINDOWS\system32\ckldrv.sys 02:26:46.0343 3520 NetworkX - ok 02:26:46.0437 3520 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 02:26:46.0437 3520 Npfs - ok 02:26:46.0515 3520 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 02:26:46.0531 3520 Ntfs - ok 02:26:46.0640 3520 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 02:26:46.0640 3520 Null - ok 02:26:46.0781 3520 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 02:26:46.0812 3520 nv - ok 02:26:46.0906 3520 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 02:26:46.0906 3520 NwlnkFlt - ok 02:26:46.0968 3520 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 02:26:46.0984 3520 NwlnkFwd - ok 02:26:47.0078 3520 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 02:26:47.0078 3520 ohci1394 - ok 02:26:47.0156 3520 Parport (2ff48d8fdc815a8492fb2bd81e6999c2) C:\WINDOWS\system32\DRIVERS\parport.sys 02:26:47.0156 3520 Parport - ok 02:26:47.0234 3520 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 02:26:47.0250 3520 PartMgr - ok 02:26:47.0343 3520 ParVdm (453ec2c2a20a1382f564541918520eeb) C:\WINDOWS\system32\drivers\ParVdm.sys 02:26:47.0359 3520 ParVdm - ok 02:26:47.0437 3520 PCI (5fd05c92ec56f696eaa50b68cef1b84a) C:\WINDOWS\system32\DRIVERS\pci.sys 02:26:47.0437 3520 PCI - ok 02:26:47.0484 3520 PCIDump - ok 02:26:47.0562 3520 PCIIde (548cf2d6369eae441a4c6baa75bc4f0a) C:\WINDOWS\system32\DRIVERS\pciide.sys 02:26:47.0562 3520 PCIIde - ok 02:26:47.0640 3520 Pcmcia (2849812217ecec059cb45f80eb6e52d4) C:\WINDOWS\system32\drivers\Pcmcia.sys 02:26:47.0640 3520 Pcmcia - ok 02:26:47.0687 3520 PDCOMP - ok 02:26:47.0734 3520 PDFRAME - ok 02:26:47.0765 3520 PDRELI - ok 02:26:47.0812 3520 PDRFRAME - ok 02:26:47.0875 3520 perc2 - ok 02:26:47.0906 3520 perc2hib - ok 02:26:48.0093 3520 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 02:26:48.0109 3520 PptpMiniport - ok 02:26:48.0218 3520 Processor (0914733fb2fc58f69cda0e929bf2df22) C:\WINDOWS\system32\DRIVERS\processr.sys 02:26:48.0234 3520 Processor - ok 02:26:48.0312 3520 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 02:26:48.0328 3520 PSched - ok 02:26:48.0406 3520 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 02:26:48.0406 3520 Ptilink - ok 02:26:48.0437 3520 ql1080 - ok 02:26:48.0500 3520 Ql10wnt - ok 02:26:48.0531 3520 ql12160 - ok 02:26:48.0578 3520 ql1240 - ok 02:26:48.0625 3520 ql1280 - ok 02:26:48.0703 3520 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 02:26:48.0703 3520 RasAcd - ok 02:26:48.0796 3520 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys 02:26:48.0796 3520 Rasirda - ok 02:26:48.0890 3520 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 02:26:48.0890 3520 Rasl2tp - ok 02:26:48.0984 3520 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 02:26:48.0984 3520 RasPppoe - ok 02:26:49.0046 3520 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 02:26:49.0046 3520 Raspti - ok 02:26:49.0125 3520 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 02:26:49.0140 3520 Rdbss - ok 02:26:49.0203 3520 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 02:26:49.0218 3520 RDPCDD - ok 02:26:49.0312 3520 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 02:26:49.0312 3520 rdpdr - ok 02:26:49.0406 3520 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 02:26:49.0406 3520 RDPWD - ok 02:26:49.0500 3520 redbook (bddcece9acdad26841c987d10376f6f7) C:\WINDOWS\system32\DRIVERS\redbook.sys 02:26:49.0500 3520 redbook - ok 02:26:49.0625 3520 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 02:26:49.0640 3520 rtl8139 - ok 02:26:49.0765 3520 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 02:26:49.0781 3520 Secdrv - ok 02:26:49.0875 3520 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 02:26:49.0875 3520 serenum - ok 02:26:49.0953 3520 Serial (859bc6f8c3d58cfda9181e9926c7ddb9) C:\WINDOWS\system32\DRIVERS\serial.sys 02:26:49.0953 3520 Serial - ok 02:26:50.0062 3520 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\DRIVERS\sfloppy.sys 02:26:50.0062 3520 Sfloppy - ok 02:26:50.0140 3520 Simbad - ok 02:26:50.0250 3520 SISNIC (3fbb6ef8b5a71a2fa11f5f461bb73219) C:\WINDOWS\system32\DRIVERS\sisnic.sys 02:26:50.0250 3520 SISNIC - ok 02:26:50.0312 3520 Sparrow - ok 02:26:50.0390 3520 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 02:26:50.0390 3520 splitter - ok 02:26:50.0484 3520 sr (6145ca23bccda679a772ec0af42d6eb5) C:\WINDOWS\system32\DRIVERS\sr.sys 02:26:50.0500 3520 sr - ok 02:26:50.0578 3520 Srv (ab9c79ed12d65e800aaad3d72a04792f) C:\WINDOWS\system32\DRIVERS\srv.sys 02:26:50.0593 3520 Srv - ok 02:26:50.0687 3520 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 02:26:50.0703 3520 swenum - ok 02:26:50.0781 3520 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 02:26:50.0781 3520 swmidi - ok 02:26:50.0843 3520 symc810 - ok 02:26:50.0875 3520 symc8xx - ok 02:26:50.0953 3520 SYMDNS (b0715be7e6acfbb1f8d2a9dbb6fa7c0a) C:\WINDOWS\System32\Drivers\SYMDNS.SYS 02:26:50.0968 3520 SYMDNS - ok 02:26:51.0015 3520 SymEvent - ok 02:26:51.0078 3520 SYMFW (1625f724cab061f95a843a4102d65757) C:\WINDOWS\System32\Drivers\SYMFW.SYS 02:26:51.0093 3520 SYMFW - ok 02:26:51.0171 3520 SYMIDS (d7e576e98a4ef5d8393370511205c2aa) C:\WINDOWS\System32\Drivers\SYMIDS.SYS 02:26:51.0187 3520 SYMIDS - ok 02:26:51.0359 3520 SYMIDSCO (ec7976981b56dfae608cfb0c6bac0d2b) C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20060807.097\symidsco.sys 02:26:51.0359 3520 SYMIDSCO - ok 02:26:51.0484 3520 SYMNDIS (b4c16ae203fa815cae4005b0e7ff8b68) C:\WINDOWS\System32\Drivers\SYMNDIS.SYS 02:26:51.0484 3520 SYMNDIS - ok 02:26:51.0593 3520 SYMREDRV (f26e71125da173d57caba3457c5e48cf) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 02:26:51.0593 3520 SYMREDRV - ok 02:26:51.0671 3520 SYMTDI (23b6adbaa7026c53b5ef102e56750b13) C:\WINDOWS\System32\Drivers\SYMTDI.SYS 02:26:51.0687 3520 SYMTDI - ok 02:26:51.0750 3520 sym_hi - ok 02:26:51.0828 3520 sym_u3 - ok 02:26:51.0937 3520 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 02:26:51.0953 3520 sysaudio - ok 02:26:52.0125 3520 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 02:26:52.0125 3520 Tcpip - ok 02:26:52.0218 3520 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 02:26:52.0234 3520 TDPIPE - ok 02:26:52.0312 3520 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 02:26:52.0312 3520 TDTCP - ok 02:26:52.0390 3520 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 02:26:52.0390 3520 TermDD - ok 02:26:52.0484 3520 TosIde - ok 02:26:52.0609 3520 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 02:26:52.0609 3520 Udfs - ok 02:26:52.0687 3520 ultra - ok 02:26:52.0796 3520 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 02:26:52.0812 3520 Update - ok 02:26:52.0937 3520 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 02:26:52.0937 3520 usbehci - ok 02:26:53.0031 3520 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 02:26:53.0046 3520 usbhub - ok 02:26:53.0156 3520 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys 02:26:53.0156 3520 usbohci - ok 02:26:53.0234 3520 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 02:26:53.0250 3520 usbscan - ok 02:26:53.0328 3520 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 02:26:53.0328 3520 USBSTOR - ok 02:26:53.0421 3520 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 02:26:53.0421 3520 usbuhci - ok 02:26:53.0531 3520 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 02:26:53.0531 3520 VgaSave - ok 02:26:53.0625 3520 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys 02:26:53.0625 3520 viaagp - ok 02:26:53.0718 3520 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 02:26:53.0718 3520 ViaIde - ok 02:26:53.0781 3520 VolSnap (ecd173739b8ec10a814cc18653df5a36) C:\WINDOWS\system32\drivers\VolSnap.sys 02:26:53.0781 3520 VolSnap - ok 02:26:53.0890 3520 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 02:26:53.0890 3520 Wanarp - ok 02:26:53.0937 3520 WDICA - ok 02:26:54.0015 3520 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 02:26:54.0015 3520 wdmaud - ok 02:26:54.0218 3520 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 02:26:54.0218 3520 WS2IFSL - ok 02:26:54.0406 3520 MBR (0x1B8) (32052574bf9f325ae309abc7bfd04460) \Device\Harddisk0\DR0 02:26:54.0562 3520 \Device\Harddisk0\DR0 - ok 02:26:54.0593 3520 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 02:26:54.0968 3520 \Device\Harddisk1\DR1 - ok 02:26:55.0000 3520 Boot (0x1200) (1a140b2ebb0a5653bf33b327ee2b2024) \Device\Harddisk0\DR0\Partition0 02:26:55.0000 3520 \Device\Harddisk0\DR0\Partition0 - ok 02:26:55.0015 3520 Boot (0x1200) (3fcdcc6bef0762fb3a915f9b6291bd2a) \Device\Harddisk1\DR1\Partition0 02:26:55.0031 3520 \Device\Harddisk1\DR1\Partition0 - ok 02:26:55.0046 3520 ============================================================ 02:26:55.0046 3520 Scan finished 02:26:55.0046 3520 ============================================================ 02:26:55.0078 3512 Detected object count: 1 02:26:55.0078 3512 Actual detected object count: 1 02:27:06.0562 3512 ACPI ( Virus.Win32.Rloader.a ) - skipped by user 02:27:06.0562 3512 ACPI ( Virus.Win32.Rloader.a ) - User select action: Skip