12:05:55.0714 1968 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50 12:05:55.0714 1968 ============================================================ 12:05:55.0714 1968 Current date / time: 2011/11/22 12:05:55.0714 12:05:55.0714 1968 SystemInfo: 12:05:55.0714 1968 12:05:55.0714 1968 OS Version: 6.0.6002 ServicePack: 2.0 12:05:55.0714 1968 Product type: Workstation 12:05:55.0714 1968 ComputerName: X-PC 12:05:55.0714 1968 UserName: x 12:05:55.0714 1968 Windows directory: C:\Windows 12:05:55.0714 1968 System windows directory: C:\Windows 12:05:55.0714 1968 Processor architecture: Intel x86 12:05:55.0714 1968 Number of processors: 2 12:05:55.0714 1968 Page size: 0x1000 12:05:55.0714 1968 Boot type: Safe boot with network 12:05:55.0714 1968 ============================================================ 12:05:56.0744 1968 Initialize success 12:06:08.0195 0224 ============================================================ 12:06:08.0195 0224 Scan started 12:06:08.0195 0224 Mode: Manual; 12:06:08.0195 0224 ============================================================ 12:06:09.0458 0224 3e3851e3 (8f2bb1827cac01aee6a16e30a1260199) C:\Windows\3813750846:3251088924.exe 12:06:09.0521 0224 Suspicious file (Hidden): C:\Windows\3813750846:3251088924.exe. md5: 8f2bb1827cac01aee6a16e30a1260199 12:06:09.0521 0224 3e3851e3 ( Rootkit.Win32.PMax.gen ) - infected 12:06:09.0521 0224 3e3851e3 - detected Rootkit.Win32.PMax.gen (0) 12:06:09.0614 0224 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 12:06:09.0630 0224 ACPI - ok 12:06:09.0739 0224 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 12:06:09.0739 0224 adp94xx - ok 12:06:09.0786 0224 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 12:06:09.0786 0224 adpahci - ok 12:06:09.0801 0224 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 12:06:09.0801 0224 adpu160m - ok 12:06:09.0833 0224 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 12:06:09.0833 0224 adpu320 - ok 12:06:09.0879 0224 adusbser - ok 12:06:09.0911 0224 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 12:06:09.0911 0224 agp440 - ok 12:06:09.0942 0224 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 12:06:09.0942 0224 aic78xx - ok 12:06:09.0973 0224 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 12:06:09.0973 0224 aliide - ok 12:06:10.0004 0224 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 12:06:10.0004 0224 amdagp - ok 12:06:10.0035 0224 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 12:06:10.0035 0224 amdide - ok 12:06:10.0067 0224 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 12:06:10.0067 0224 AmdK7 - ok 12:06:10.0082 0224 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 12:06:10.0082 0224 AmdK8 - ok 12:06:10.0145 0224 ApfiltrService (0f83cb9bcb247869bcad28026b8f134b) C:\Windows\system32\DRIVERS\Apfiltr.sys 12:06:10.0145 0224 ApfiltrService - ok 12:06:10.0207 0224 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 12:06:10.0207 0224 arc - ok 12:06:10.0238 0224 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 12:06:10.0238 0224 arcsas - ok 12:06:10.0285 0224 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 12:06:10.0285 0224 AsyncMac - ok 12:06:10.0332 0224 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 12:06:10.0332 0224 atapi - ok 12:06:10.0394 0224 Axtmvflt (59629edd214c35a01e2527ac3b8a7fb3) C:\Windows\system32\DRIVERS\Axtmvflt.sys 12:06:10.0410 0224 Axtmvflt - ok 12:06:10.0441 0224 Axtmvmdm (37e23b1756eca768656097f72c0b458d) C:\Windows\system32\DRIVERS\Axtmvmdm.sys 12:06:10.0441 0224 Axtmvmdm - ok 12:06:10.0488 0224 Axtmvprt (2c7170be24eacc0b432eb1832fee0ddc) C:\Windows\system32\Drivers\Axtmvprt.sys 12:06:10.0488 0224 Axtmvprt - ok 12:06:10.0535 0224 b57nd60x (f17463eddb3b6a988f939ff403e067c3) C:\Windows\system32\DRIVERS\b57nd60x.sys 12:06:10.0535 0224 b57nd60x - ok 12:06:10.0613 0224 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 12:06:10.0613 0224 Beep - ok 12:06:10.0675 0224 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 12:06:10.0675 0224 blbdrive - ok 12:06:10.0737 0224 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 12:06:10.0737 0224 bowser - ok 12:06:10.0784 0224 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 12:06:10.0784 0224 BrFiltLo - ok 12:06:10.0800 0224 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 12:06:10.0800 0224 BrFiltUp - ok 12:06:10.0847 0224 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 12:06:10.0847 0224 Brserid - ok 12:06:10.0862 0224 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 12:06:10.0862 0224 BrSerWdm - ok 12:06:10.0893 0224 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 12:06:10.0893 0224 BrUsbMdm - ok 12:06:10.0925 0224 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 12:06:10.0925 0224 BrUsbSer - ok 12:06:10.0987 0224 BthEnum (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys 12:06:10.0987 0224 BthEnum - ok 12:06:11.0049 0224 BTHMODEM (9a966a8e86d1771911ae34a20d11bff3) C:\Windows\system32\DRIVERS\bthmodem.sys 12:06:11.0049 0224 BTHMODEM - ok 12:06:11.0096 0224 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys 12:06:11.0096 0224 BthPan - ok 12:06:11.0143 0224 BTHPORT (611ff3f2f095c8d4a6d4cfd9dcc09793) C:\Windows\system32\Drivers\BTHport.sys 12:06:11.0143 0224 BTHPORT - ok 12:06:11.0174 0224 BTHUSB (d330803eab2a15caec7f011f1d4cb30e) C:\Windows\system32\Drivers\BTHUSB.sys 12:06:11.0174 0224 BTHUSB - ok 12:06:11.0237 0224 btwaudio (463483285b2d2d345443aaee7b9391e7) C:\Windows\system32\drivers\btwaudio.sys 12:06:11.0237 0224 btwaudio - ok 12:06:11.0252 0224 btwavdt (4f82b6173ef8637cb26cf4e73b90f172) C:\Windows\system32\drivers\btwavdt.sys 12:06:11.0252 0224 btwavdt - ok 12:06:11.0299 0224 btwl2cap (ecb98391c756a7b9cfbae89d9d1235e1) C:\Windows\system32\DRIVERS\btwl2cap.sys 12:06:11.0299 0224 btwl2cap - ok 12:06:11.0346 0224 btwrchid (f771034f5b59a4a5054a2fa6f4e9f28b) C:\Windows\system32\DRIVERS\btwrchid.sys 12:06:11.0346 0224 btwrchid - ok 12:06:11.0393 0224 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 12:06:11.0393 0224 cdfs - ok 12:06:11.0424 0224 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 12:06:11.0424 0224 circlass - ok 12:06:11.0455 0224 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 12:06:11.0471 0224 CLFS - ok 12:06:11.0517 0224 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 12:06:11.0517 0224 CmBatt - ok 12:06:11.0533 0224 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 12:06:11.0533 0224 cmdide - ok 12:06:11.0580 0224 CnxtHdAudService (8b7a0ce6613f991359ff95212900396c) C:\Windows\system32\drivers\CHDRT32.sys 12:06:11.0580 0224 CnxtHdAudService - ok 12:06:11.0627 0224 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 12:06:11.0627 0224 Compbatt - ok 12:06:11.0642 0224 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 12:06:11.0642 0224 crcdisk - ok 12:06:11.0673 0224 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 12:06:11.0673 0224 Crusoe - ok 12:06:11.0751 0224 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 12:06:11.0751 0224 disk - ok 12:06:11.0829 0224 DLABMFSM (5b149ccfe275f4de0b4b8ec6b9f6821e) C:\Windows\system32\DLA\DLABMFSM.SYS 12:06:11.0829 0224 DLABMFSM - ok 12:06:11.0861 0224 DLABOIOM (ad4cb3d783634c90a9d0ce360933a63c) C:\Windows\system32\DLA\DLABOIOM.SYS 12:06:11.0861 0224 DLABOIOM - ok 12:06:11.0876 0224 DLACDBHM (5230cdb7e715f3a3b4a882e254cdd35d) C:\Windows\system32\Drivers\DLACDBHM.SYS 12:06:11.0876 0224 DLACDBHM - ok 12:06:11.0892 0224 DLADResM (93d03238cc3f0ee3c0b3985d110ec575) C:\Windows\system32\DLA\DLADResM.SYS 12:06:11.0892 0224 DLADResM - ok 12:06:11.0923 0224 DLAIFS_M (6a82f77c4a6f5235bf352f0028e2ef52) C:\Windows\system32\DLA\DLAIFS_M.SYS 12:06:11.0923 0224 DLAIFS_M - ok 12:06:11.0954 0224 DLAOPIOM (0e6052c0ada37504896a847231a3907d) C:\Windows\system32\DLA\DLAOPIOM.SYS 12:06:11.0954 0224 DLAOPIOM - ok 12:06:11.0970 0224 DLAPoolM (29670bb4e2b973c5b55a76107d4910b2) C:\Windows\system32\DLA\DLAPoolM.SYS 12:06:11.0970 0224 DLAPoolM - ok 12:06:11.0985 0224 DLARTL_M (77fe51f0f8d86804cb81f6ef6bfb86dd) C:\Windows\system32\Drivers\DLARTL_M.SYS 12:06:11.0985 0224 DLARTL_M - ok 12:06:12.0017 0224 DLAUDFAM (6b087732b86c1d866d69dbbe463ea90a) C:\Windows\system32\DLA\DLAUDFAM.SYS 12:06:12.0017 0224 DLAUDFAM - ok 12:06:12.0048 0224 DLAUDF_M (bbeecb95f2841ae4a3e3690d46d7153d) C:\Windows\system32\DLA\DLAUDF_M.SYS 12:06:12.0048 0224 DLAUDF_M - ok 12:06:12.0110 0224 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 12:06:12.0110 0224 drmkaud - ok 12:06:12.0141 0224 DRVMCDB (83106585494d5eb96f59187200c144bd) C:\Windows\system32\Drivers\DRVMCDB.SYS 12:06:12.0141 0224 DRVMCDB - ok 12:06:12.0173 0224 DRVNDDM (ffc371525aa55d1bae18715ebcb8797c) C:\Windows\system32\Drivers\DRVNDDM.SYS 12:06:12.0173 0224 DRVNDDM - ok 12:06:12.0219 0224 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 12:06:12.0235 0224 DXGKrnl - ok 12:06:12.0282 0224 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys 12:06:12.0282 0224 e1express - ok 12:06:12.0313 0224 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 12:06:12.0313 0224 E1G60 - ok 12:06:12.0375 0224 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 12:06:12.0375 0224 Ecache - ok 12:06:12.0407 0224 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 12:06:12.0422 0224 elxstor - ok 12:06:12.0438 0224 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 12:06:12.0438 0224 ErrDev - ok 12:06:12.0500 0224 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 12:06:12.0516 0224 exfat - ok 12:06:12.0547 0224 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 12:06:12.0563 0224 fastfat - ok 12:06:12.0609 0224 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 12:06:12.0609 0224 fdc - ok 12:06:12.0672 0224 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 12:06:12.0672 0224 FileInfo - ok 12:06:12.0703 0224 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 12:06:12.0703 0224 Filetrace - ok 12:06:12.0719 0224 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 12:06:12.0734 0224 flpydisk - ok 12:06:12.0781 0224 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 12:06:12.0781 0224 FltMgr - ok 12:06:12.0843 0224 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 12:06:12.0843 0224 Fs_Rec - ok 12:06:12.0875 0224 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 12:06:12.0875 0224 gagp30kx - ok 12:06:12.0921 0224 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 12:06:12.0921 0224 GEARAspiWDM - ok 12:06:12.0953 0224 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 12:06:12.0953 0224 HdAudAddService - ok 12:06:12.0999 0224 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 12:06:12.0999 0224 HDAudBus - ok 12:06:13.0031 0224 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 12:06:13.0031 0224 HidBth - ok 12:06:13.0062 0224 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 12:06:13.0062 0224 HidIr - ok 12:06:13.0109 0224 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 12:06:13.0109 0224 HidUsb - ok 12:06:13.0140 0224 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 12:06:13.0140 0224 HpCISSs - ok 12:06:13.0202 0224 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 12:06:13.0202 0224 HSFHWAZL - ok 12:06:13.0265 0224 HSF_DPV (fadd7095163cb3cb4073793ebb50fe75) C:\Windows\system32\DRIVERS\HSX_DPV.sys 12:06:13.0280 0224 HSF_DPV - ok 12:06:13.0327 0224 HSXHWAZL (058783bedd17615d1fece09f77960436) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 12:06:13.0327 0224 HSXHWAZL - ok 12:06:13.0374 0224 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys 12:06:13.0374 0224 HTTP - ok 12:06:13.0436 0224 hwdatacard (63b3eff36272787619c1e773ed581693) C:\Windows\system32\DRIVERS\ewusbmdm.sys 12:06:13.0436 0224 hwdatacard - ok 12:06:13.0483 0224 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 12:06:13.0483 0224 i2omp - ok 12:06:13.0530 0224 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 12:06:13.0530 0224 i8042prt - ok 12:06:13.0577 0224 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 12:06:13.0577 0224 iaStorV - ok 12:06:13.0857 0224 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys 12:06:13.0920 0224 igfx - ok 12:06:13.0951 0224 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 12:06:13.0951 0224 iirsp - ok 12:06:13.0998 0224 IntcHdmiAddService (c7e7e43cbd34d3b0a0156b51b917dfcc) C:\Windows\system32\drivers\IntcHdmi.sys 12:06:13.0998 0224 IntcHdmiAddService - ok 12:06:14.0029 0224 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 12:06:14.0029 0224 intelide - ok 12:06:14.0060 0224 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 12:06:14.0060 0224 intelppm - ok 12:06:14.0091 0224 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 12:06:14.0091 0224 IpFilterDriver - ok 12:06:14.0107 0224 IpInIp - ok 12:06:14.0154 0224 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 12:06:14.0154 0224 IPMIDRV - ok 12:06:14.0185 0224 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 12:06:14.0185 0224 IPNAT - ok 12:06:14.0216 0224 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 12:06:14.0216 0224 IRENUM - ok 12:06:14.0247 0224 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 12:06:14.0247 0224 isapnp - ok 12:06:14.0294 0224 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 12:06:14.0294 0224 iScsiPrt - ok 12:06:14.0325 0224 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 12:06:14.0325 0224 iteatapi - ok 12:06:14.0372 0224 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 12:06:14.0372 0224 iteraid - ok 12:06:14.0435 0224 JMCR (a69a1b991824b98f744913555f665893) C:\Windows\system32\DRIVERS\jmcr.sys 12:06:14.0435 0224 JMCR - ok 12:06:14.0450 0224 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 12:06:14.0450 0224 kbdclass - ok 12:06:14.0481 0224 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys 12:06:14.0481 0224 kbdhid - ok 12:06:14.0544 0224 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 12:06:14.0544 0224 KSecDD - ok 12:06:14.0637 0224 Lbd (336abe8721cbc3110f1c6426da633417) C:\Windows\system32\DRIVERS\Lbd.sys 12:06:14.0637 0224 Lbd - ok 12:06:14.0684 0224 lenovo.smi (3c3f7f424e324c6971632c5de5ff458f) C:\Windows\system32\DRIVERS\smiif32.sys 12:06:14.0684 0224 lenovo.smi - ok 12:06:14.0747 0224 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 12:06:14.0747 0224 lltdio - ok 12:06:14.0762 0224 LPCFilter (31f74d5d47eea83e5e89447586917774) C:\Windows\system32\DRIVERS\LPCFilter.sys 12:06:14.0778 0224 LPCFilter - ok 12:06:14.0809 0224 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 12:06:14.0809 0224 LSI_FC - ok 12:06:14.0840 0224 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 12:06:14.0840 0224 LSI_SAS - ok 12:06:14.0871 0224 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 12:06:14.0871 0224 LSI_SCSI - ok 12:06:14.0903 0224 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 12:06:14.0903 0224 luafv - ok 12:06:14.0934 0224 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 12:06:14.0934 0224 mdmxsdk - ok 12:06:14.0965 0224 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 12:06:14.0965 0224 megasas - ok 12:06:15.0012 0224 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 12:06:15.0012 0224 MegaSR - ok 12:06:15.0043 0224 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 12:06:15.0043 0224 Modem - ok 12:06:15.0090 0224 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 12:06:15.0090 0224 monitor - ok 12:06:15.0121 0224 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 12:06:15.0121 0224 mouclass - ok 12:06:15.0152 0224 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 12:06:15.0152 0224 mouhid - ok 12:06:15.0183 0224 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 12:06:15.0183 0224 MountMgr - ok 12:06:15.0215 0224 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 12:06:15.0215 0224 mpio - ok 12:06:15.0230 0224 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 12:06:15.0230 0224 mpsdrv - ok 12:06:15.0261 0224 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 12:06:15.0277 0224 Mraid35x - ok 12:06:15.0308 0224 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 12:06:15.0308 0224 MRxDAV - ok 12:06:15.0339 0224 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 12:06:15.0339 0224 mrxsmb - ok 12:06:15.0386 0224 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 12:06:15.0386 0224 mrxsmb10 - ok 12:06:15.0402 0224 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 12:06:15.0402 0224 mrxsmb20 - ok 12:06:15.0464 0224 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 12:06:15.0464 0224 msahci - ok 12:06:15.0495 0224 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 12:06:15.0495 0224 msdsm - ok 12:06:15.0527 0224 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 12:06:15.0527 0224 Msfs - ok 12:06:15.0573 0224 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 12:06:15.0573 0224 msisadrv - ok 12:06:15.0605 0224 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 12:06:15.0605 0224 MSKSSRV - ok 12:06:15.0636 0224 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 12:06:15.0636 0224 MSPCLOCK - ok 12:06:15.0667 0224 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 12:06:15.0667 0224 MSPQM - ok 12:06:15.0714 0224 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 12:06:15.0714 0224 MsRPC - ok 12:06:15.0745 0224 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 12:06:15.0745 0224 mssmbios - ok 12:06:15.0792 0224 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 12:06:15.0792 0224 MSTEE - ok 12:06:15.0823 0224 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 12:06:15.0823 0224 Mup - ok 12:06:15.0854 0224 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 12:06:15.0854 0224 NativeWifiP - ok 12:06:15.0917 0224 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 12:06:15.0917 0224 NDIS - ok 12:06:15.0963 0224 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 12:06:15.0963 0224 NdisTapi - ok 12:06:15.0979 0224 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 12:06:15.0979 0224 Ndisuio - ok 12:06:15.0995 0224 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 12:06:15.0995 0224 NdisWan - ok 12:06:16.0026 0224 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 12:06:16.0026 0224 NDProxy - ok 12:06:16.0057 0224 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 12:06:16.0057 0224 NetBIOS - ok 12:06:16.0088 0224 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 12:06:16.0088 0224 netbt - ok 12:06:16.0244 0224 NETw5v32 (e559ea9138c77b5d1fda8c558764a25f) C:\Windows\system32\DRIVERS\NETw5v32.sys 12:06:16.0260 0224 NETw5v32 - ok 12:06:16.0291 0224 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 12:06:16.0291 0224 nfrd960 - ok 12:06:16.0338 0224 nmwcd (65ac8baa2f916ee9203ee48d7fcee605) C:\Windows\system32\drivers\ccdcmb.sys 12:06:16.0338 0224 nmwcd - ok 12:06:16.0369 0224 nmwcdc (29af182734a247240d89a0fe63dbef03) C:\Windows\system32\drivers\ccdcmbo.sys 12:06:16.0369 0224 nmwcdc - ok 12:06:16.0416 0224 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 12:06:16.0416 0224 Npfs - ok 12:06:16.0431 0224 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 12:06:16.0431 0224 nsiproxy - ok 12:06:16.0509 0224 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 12:06:16.0509 0224 Ntfs - ok 12:06:16.0525 0224 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 12:06:16.0525 0224 ntrigdigi - ok 12:06:16.0541 0224 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 12:06:16.0541 0224 Null - ok 12:06:16.0572 0224 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 12:06:16.0587 0224 nvraid - ok 12:06:16.0603 0224 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 12:06:16.0603 0224 nvstor - ok 12:06:16.0619 0224 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 12:06:16.0619 0224 nv_agp - ok 12:06:16.0634 0224 NwlnkFlt - ok 12:06:16.0650 0224 NwlnkFwd - ok 12:06:16.0681 0224 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys 12:06:16.0681 0224 ohci1394 - ok 12:06:16.0728 0224 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 12:06:16.0728 0224 Parport - ok 12:06:16.0759 0224 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 12:06:16.0759 0224 partmgr - ok 12:06:16.0790 0224 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 12:06:16.0790 0224 Parvdm - ok 12:06:16.0837 0224 PCAMp50 (1bf91f352d746ad7469fa71783b5fae8) C:\Windows\system32\Drivers\PCAMp50.sys 12:06:16.0837 0224 PCAMp50 - ok 12:06:16.0868 0224 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\Windows\system32\Drivers\PCASp50.sys 12:06:16.0868 0224 PCASp50 - ok 12:06:16.0899 0224 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\Windows\system32\DRIVERS\pccsmcfd.sys 12:06:16.0899 0224 pccsmcfd - ok 12:06:16.0931 0224 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 12:06:16.0931 0224 pci - ok 12:06:16.0962 0224 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 12:06:16.0962 0224 pciide - ok 12:06:17.0009 0224 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys 12:06:17.0009 0224 pcmcia - ok 12:06:17.0071 0224 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 12:06:17.0071 0224 PEAUTH - ok 12:06:17.0133 0224 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 12:06:17.0133 0224 PptpMiniport - ok 12:06:17.0165 0224 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 12:06:17.0165 0224 Processor - ok 12:06:17.0227 0224 psadd (f8a25f1dd8b2c332cbc663e3579566e7) C:\Windows\system32\DRIVERS\psadd.sys 12:06:17.0227 0224 psadd - ok 12:06:17.0274 0224 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 12:06:17.0274 0224 PSched - ok 12:06:17.0289 0224 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys 12:06:17.0289 0224 PxHelp20 - ok 12:06:17.0367 0224 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 12:06:17.0367 0224 ql2300 - ok 12:06:17.0399 0224 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 12:06:17.0399 0224 ql40xx - ok 12:06:17.0414 0224 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 12:06:17.0414 0224 QWAVEdrv - ok 12:06:17.0445 0224 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 12:06:17.0445 0224 RasAcd - ok 12:06:17.0477 0224 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 12:06:17.0477 0224 Rasl2tp - ok 12:06:17.0523 0224 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 12:06:17.0523 0224 RasPppoe - ok 12:06:17.0555 0224 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 12:06:17.0555 0224 RasSstp - ok 12:06:17.0617 0224 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 12:06:17.0617 0224 rdbss - ok 12:06:17.0633 0224 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 12:06:17.0633 0224 RDPCDD - ok 12:06:17.0679 0224 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 12:06:17.0679 0224 rdpdr - ok 12:06:17.0695 0224 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 12:06:17.0695 0224 RDPENCDD - ok 12:06:17.0726 0224 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 12:06:17.0742 0224 RDPWD - ok 12:06:17.0804 0224 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys 12:06:17.0804 0224 RFCOMM - ok 12:06:17.0851 0224 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 12:06:17.0851 0224 rspndr - ok 12:06:17.0898 0224 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 12:06:17.0898 0224 sbp2port - ok 12:06:17.0929 0224 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys 12:06:17.0929 0224 sdbus - ok 12:06:17.0976 0224 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 12:06:17.0976 0224 secdrv - ok 12:06:18.0023 0224 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 12:06:18.0023 0224 Serenum - ok 12:06:18.0054 0224 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 12:06:18.0054 0224 Serial - ok 12:06:18.0085 0224 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 12:06:18.0085 0224 sermouse - ok 12:06:18.0132 0224 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 12:06:18.0132 0224 sffdisk - ok 12:06:18.0163 0224 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 12:06:18.0163 0224 sffp_mmc - ok 12:06:18.0179 0224 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 12:06:18.0179 0224 sffp_sd - ok 12:06:18.0194 0224 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 12:06:18.0194 0224 sfloppy - ok 12:06:18.0225 0224 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 12:06:18.0225 0224 sisagp - ok 12:06:18.0257 0224 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 12:06:18.0257 0224 SiSRaid2 - ok 12:06:18.0288 0224 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 12:06:18.0288 0224 SiSRaid4 - ok 12:06:18.0335 0224 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 12:06:18.0335 0224 Smb - ok 12:06:18.0366 0224 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 12:06:18.0366 0224 spldr - ok 12:06:18.0413 0224 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 12:06:18.0428 0224 srv - ok 12:06:18.0459 0224 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 12:06:18.0459 0224 srv2 - ok 12:06:18.0506 0224 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 12:06:18.0506 0224 srvnet - ok 12:06:18.0553 0224 StillCam (ef70b3d22b4bffda6ea851ecb063efaa) C:\Windows\system32\DRIVERS\serscan.sys 12:06:18.0553 0224 StillCam - ok 12:06:18.0615 0224 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 12:06:18.0615 0224 swenum - ok 12:06:18.0647 0224 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 12:06:18.0647 0224 Symc8xx - ok 12:06:18.0662 0224 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 12:06:18.0662 0224 Sym_hi - ok 12:06:18.0693 0224 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 12:06:18.0693 0224 Sym_u3 - ok 12:06:18.0771 0224 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys 12:06:18.0771 0224 Tcpip - ok 12:06:18.0818 0224 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys 12:06:18.0818 0224 Tcpip6 - ok 12:06:18.0865 0224 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 12:06:18.0865 0224 tcpipreg - ok 12:06:18.0896 0224 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 12:06:18.0896 0224 TDPIPE - ok 12:06:18.0912 0224 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 12:06:18.0912 0224 TDTCP - ok 12:06:18.0943 0224 tdx (352ee245831c8cc021e0499981dc9e70) C:\Windows\system32\DRIVERS\tdx.sys 12:06:18.0943 0224 Suspicious file (Forged): C:\Windows\system32\DRIVERS\tdx.sys. Real md5: 352ee245831c8cc021e0499981dc9e70, Fake md5: 76b06eb8a01fc8624d699e7045303e54 12:06:18.0943 0224 tdx ( Rootkit.Win32.ZAccess.e ) - infected 12:06:18.0943 0224 tdx - detected Rootkit.Win32.ZAccess.e (0) 12:06:18.0990 0224 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 12:06:18.0990 0224 TermDD - ok 12:06:19.0052 0224 TPM (cb258c2f726f1be73c507022be33ebb3) C:\Windows\system32\drivers\tpm.sys 12:06:19.0052 0224 TPM - ok 12:06:19.0068 0224 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 12:06:19.0068 0224 tssecsrv - ok 12:06:19.0115 0224 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 12:06:19.0115 0224 tunmp - ok 12:06:19.0161 0224 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 12:06:19.0161 0224 tunnel - ok 12:06:19.0193 0224 tvtfilter (49258a02a1e8d304ed88b0f1c56b1738) C:\Windows\system32\DRIVERS\tvtfilter.sys 12:06:19.0193 0224 tvtfilter - ok 12:06:19.0224 0224 TVTI2C (7e66dda1ef146bfc3a6e36e08e036602) C:\Windows\system32\DRIVERS\Tvti2c.sys 12:06:19.0239 0224 TVTI2C - ok 12:06:19.0271 0224 tvtumon (2d1ec233c89416ba8187c9d7d49a075a) C:\Windows\system32\DRIVERS\tvtumon.sys 12:06:19.0271 0224 tvtumon - ok 12:06:19.0302 0224 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 12:06:19.0302 0224 uagp35 - ok 12:06:19.0349 0224 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 12:06:19.0349 0224 udfs - ok 12:06:19.0395 0224 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 12:06:19.0395 0224 uliagpkx - ok 12:06:19.0427 0224 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 12:06:19.0427 0224 uliahci - ok 12:06:19.0458 0224 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 12:06:19.0458 0224 UlSata - ok 12:06:19.0489 0224 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 12:06:19.0489 0224 ulsata2 - ok 12:06:19.0520 0224 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 12:06:19.0520 0224 umbus - ok 12:06:19.0551 0224 upperdev (2522747ba661514e3770e508cce45b64) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 12:06:19.0551 0224 upperdev - ok 12:06:19.0598 0224 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\Windows\system32\Drivers\usbaapl.sys 12:06:19.0598 0224 USBAAPL - ok 12:06:19.0629 0224 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 12:06:19.0629 0224 usbccgp - ok 12:06:19.0661 0224 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 12:06:19.0661 0224 usbcir - ok 12:06:19.0707 0224 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 12:06:19.0707 0224 usbehci - ok 12:06:19.0739 0224 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 12:06:19.0739 0224 usbhub - ok 12:06:19.0770 0224 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 12:06:19.0785 0224 usbohci - ok 12:06:19.0817 0224 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys 12:06:19.0817 0224 usbprint - ok 12:06:19.0863 0224 usbser (d575246188f63de0accf6eac5fb59e6a) C:\Windows\system32\DRIVERS\usbser.sys 12:06:19.0863 0224 usbser - ok 12:06:19.0895 0224 UsbserFilt (8aa5f86a6c3b3234beed9556d145bfac) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 12:06:19.0895 0224 UsbserFilt - ok 12:06:19.0926 0224 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 12:06:19.0926 0224 USBSTOR - ok 12:06:19.0957 0224 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 12:06:19.0957 0224 usbuhci - ok 12:06:19.0988 0224 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 12:06:19.0988 0224 usbvideo - ok 12:06:20.0035 0224 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 12:06:20.0035 0224 vga - ok 12:06:20.0051 0224 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 12:06:20.0051 0224 VgaSave - ok 12:06:20.0066 0224 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 12:06:20.0066 0224 viaagp - ok 12:06:20.0097 0224 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 12:06:20.0097 0224 ViaC7 - ok 12:06:20.0113 0224 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 12:06:20.0129 0224 viaide - ok 12:06:20.0207 0224 vm331avs (b9dfda5510fffb6c8b825271e3e3d2e0) C:\Windows\system32\Drivers\vm331avs.sys 12:06:20.0207 0224 vm331avs - ok 12:06:20.0238 0224 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 12:06:20.0238 0224 volmgr - ok 12:06:20.0285 0224 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 12:06:20.0285 0224 volmgrx - ok 12:06:20.0331 0224 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 12:06:20.0347 0224 volsnap - ok 12:06:20.0363 0224 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 12:06:20.0363 0224 vsmraid - ok 12:06:20.0441 0224 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 12:06:20.0441 0224 WacomPen - ok 12:06:20.0456 0224 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 12:06:20.0456 0224 Wanarp - ok 12:06:20.0487 0224 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 12:06:20.0487 0224 Wanarpv6 - ok 12:06:20.0519 0224 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 12:06:20.0519 0224 Wd - ok 12:06:20.0550 0224 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 12:06:20.0550 0224 Wdf01000 - ok 12:06:20.0628 0224 WimFltr (f9ad3a5e3fd7e0bdb18b8202b0fdd4e4) C:\Windows\system32\DRIVERS\wimfltr.sys 12:06:20.0628 0224 WimFltr - ok 12:06:20.0690 0224 winachsf (bb9cbaf6ac20452b245c324f1f50ee81) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 12:06:20.0690 0224 winachsf - ok 12:06:20.0753 0224 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 12:06:20.0753 0224 WmiAcpi - ok 12:06:20.0799 0224 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 12:06:20.0799 0224 WpdUsb - ok 12:06:20.0831 0224 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 12:06:20.0831 0224 ws2ifsl - ok 12:06:20.0893 0224 WSDPrintDevice (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys 12:06:20.0893 0224 WSDPrintDevice - ok 12:06:20.0940 0224 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 12:06:20.0940 0224 WUDFRd - ok 12:06:20.0971 0224 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys 12:06:20.0971 0224 XAudio - ok 12:06:20.0987 0224 ygxnsuvd - ok 12:06:21.0033 0224 MBR (0x1B8) (16bf62655def3fee3f9a3919918db341) \Device\Harddisk0\DR0 12:06:21.0033 0224 \Device\Harddisk0\DR0 - ok 12:06:21.0049 0224 MBR (0x1B8) (65e858a8a0293be11a920b0bc99d695e) \Device\Harddisk1\DR1 12:06:21.0205 0224 \Device\Harddisk1\DR1 - ok 12:06:21.0252 0224 Boot (0x1200) (257b0d1a9519f9df26dc4414d05a4457) \Device\Harddisk0\DR0\Partition0 12:06:21.0252 0224 \Device\Harddisk0\DR0\Partition0 - ok 12:06:21.0267 0224 Boot (0x1200) (e6400e86c90b2f3ebca6195730c5cd53) \Device\Harddisk0\DR0\Partition1 12:06:21.0267 0224 \Device\Harddisk0\DR0\Partition1 - ok 12:06:21.0299 0224 Boot (0x1200) (1cdce5d2256d333d8d42bf03956ec327) \Device\Harddisk0\DR0\Partition2 12:06:21.0299 0224 \Device\Harddisk0\DR0\Partition2 - ok 12:06:21.0299 0224 Boot (0x1200) (263ebc0532d9c343e3344a62f903137f) \Device\Harddisk1\DR1\Partition0 12:06:21.0299 0224 \Device\Harddisk1\DR1\Partition0 - ok 12:06:21.0299 0224 ============================================================ 12:06:21.0299 0224 Scan finished 12:06:21.0299 0224 ============================================================ 12:06:21.0330 1956 Detected object count: 2 12:06:21.0330 1956 Actual detected object count: 2 12:07:26.0413 1956 HKLM\SYSTEM\ControlSet001\services\3e3851e3 - will be deleted on reboot 12:07:26.0788 1956 C:\Windows\3813750846:3251088924.exe - will be deleted on reboot 12:07:26.0788 1956 3e3851e3 ( Rootkit.Win32.PMax.gen ) - User select action: Delete 12:07:27.0037 1956 Backup copy found, using it.. 12:07:27.0053 1956 C:\Windows\system32\DRIVERS\tdx.sys - will be cured on reboot 12:07:30.0017 1956 C:\Windows\System32\c_93881.nls - will be deleted on reboot 12:07:30.0064 1956 C:\Windows\System32\c_93881.nl_ - will be deleted on reboot 12:07:30.0267 1956 tdx ( Rootkit.Win32.ZAccess.e ) - User select action: Cure 12:07:55.0180 2024 Deinitialize success