15:32:52.0031 1080 TDSS rootkit removing tool 2.7.9.0 Feb 1 2012 09:28:49 15:32:52.0296 1080 ============================================================ 15:32:52.0296 1080 Current date / time: 2012/02/03 15:32:52.0296 15:32:52.0296 1080 SystemInfo: 15:32:52.0296 1080 15:32:52.0296 1080 OS Version: 5.1.2600 ServicePack: 2.0 15:32:52.0296 1080 Product type: Workstation 15:32:52.0296 1080 ComputerName: JA 15:32:52.0296 1080 UserName: JA 15:32:52.0296 1080 Windows directory: D:\WINDOWS 15:32:52.0296 1080 System windows directory: D:\WINDOWS 15:32:52.0296 1080 Processor architecture: Intel x86 15:32:52.0296 1080 Number of processors: 1 15:32:52.0296 1080 Page size: 0x1000 15:32:52.0296 1080 Boot type: Normal boot 15:32:52.0296 1080 ============================================================ 15:32:54.0406 1080 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 15:32:54.0406 1080 \Device\Harddisk0\DR0: 15:32:54.0406 1080 MBR used 15:32:54.0421 1080 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x9C267C, BlocksNum 0x6A6B063 15:32:54.0421 1080 \Device\Harddisk0\DR0\Partition1: MBR, Type 0xC, StartLBA 0x742D6DF, BlocksNum 0x6B660E2 15:32:54.0468 1080 Initialize success 15:32:54.0468 1080 ============================================================ 15:33:08.0546 1776 ============================================================ 15:33:08.0546 1776 Scan started 15:33:08.0546 1776 Mode: Manual; 15:33:08.0546 1776 ============================================================ 15:33:09.0421 1776 Abiosdsk - ok 15:33:10.0109 1776 ACPI (56922f51dde99b23a9c61fd5ac25fd7f) D:\WINDOWS\system32\DRIVERS\ACPI.sys 15:33:10.0109 1776 Suspicious file (Forged): D:\WINDOWS\system32\DRIVERS\ACPI.sys. Real md5: 56922f51dde99b23a9c61fd5ac25fd7f, Fake md5: a966410ecf83b81f3b0b8e07a71957d4 15:33:10.0109 1776 ACPI ( Virus.Win32.Rloader.a ) - infected 15:33:10.0109 1776 ACPI - detected Virus.Win32.Rloader.a (0) 15:33:10.0781 1776 ACPIEC (66a42b7db194e24b973bbcce840a0f3f) D:\WINDOWS\system32\DRIVERS\ACPIEC.sys 15:33:10.0781 1776 ACPIEC - ok 15:33:11.0468 1776 aec (1ee7b434ba961ef845de136224c30fec) D:\WINDOWS\system32\drivers\aec.sys 15:33:11.0468 1776 aec - ok 15:33:12.0140 1776 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) D:\WINDOWS\System32\drivers\afd.sys 15:33:12.0156 1776 AFD - ok 15:33:12.0828 1776 alcan5wn (0940030d5a5869067ccc03e3b0b8dec7) D:\WINDOWS\system32\DRIVERS\alcan5wn.sys 15:33:12.0828 1776 alcan5wn - ok 15:33:13.0500 1776 alcaudsl (4c9577888c53243e2991456f510488a1) D:\WINDOWS\system32\DRIVERS\alcaudsl.sys 15:33:13.0515 1776 alcaudsl - ok 15:33:14.0171 1776 AliIde - ok 15:33:14.0890 1776 AR5211 (78e15866befe8b940046c36ba92f9eb6) D:\WINDOWS\system32\DRIVERS\ar5211.sys 15:33:14.0906 1776 AR5211 - ok 15:33:15.0578 1776 Aspi32 (5b01af89d16d562825c4db4530f20cbb) D:\WINDOWS\system32\drivers\Aspi32.sys 15:33:15.0578 1776 Aspi32 - ok 15:33:16.0296 1776 AsyncMac (02000abf34af4c218c35d257024807d6) D:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:33:16.0296 1776 AsyncMac - ok 15:33:16.0984 1776 atapi (cdfe4411a69c224bd1d11b2da92dac51) D:\WINDOWS\system32\DRIVERS\atapi.sys 15:33:16.0984 1776 atapi - ok 15:33:17.0640 1776 Atdisk - ok 15:33:18.0312 1776 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) D:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:33:18.0328 1776 Atmarpc - ok 15:33:19.0015 1776 audstub (d9f724aa26c010a217c97606b160ed68) D:\WINDOWS\system32\DRIVERS\audstub.sys 15:33:19.0015 1776 audstub - ok 15:33:19.0687 1776 bcm4sbxp (cd4646067cc7dcba1907fa0acf7e3966) D:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 15:33:19.0687 1776 bcm4sbxp - ok 15:33:20.0375 1776 Beep (da1f27d85e0d1525f6621372e7b685e9) D:\WINDOWS\system32\drivers\Beep.sys 15:33:20.0375 1776 Beep - ok 15:33:21.0046 1776 Cdaudio (c1b486a7658353d33a10cc15211a873b) D:\WINDOWS\system32\drivers\Cdaudio.sys 15:33:21.0062 1776 Cdaudio - ok 15:33:21.0734 1776 Cdfs (cd7d5152df32b47f4e36f710b35aae02) D:\WINDOWS\system32\drivers\Cdfs.sys 15:33:21.0734 1776 Cdfs - ok 15:33:22.0421 1776 Cdrom (af9c19b3100fe010496b1a27181fbf72) D:\WINDOWS\system32\DRIVERS\cdrom.sys 15:33:22.0421 1776 Cdrom - ok 15:33:23.0046 1776 Changer - ok 15:33:23.0734 1776 CmBatt (4266be808f85826aedf3c64c1e240203) D:\WINDOWS\system32\DRIVERS\CmBatt.sys 15:33:23.0750 1776 CmBatt - ok 15:33:24.0390 1776 CmdIde - ok 15:33:25.0062 1776 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) D:\WINDOWS\system32\DRIVERS\compbatt.sys 15:33:25.0062 1776 Compbatt - ok 15:33:25.0765 1776 Disk (00ca44e4534865f8a3b64f7c0984bff0) D:\WINDOWS\system32\DRIVERS\disk.sys 15:33:25.0765 1776 Disk - ok 15:33:26.0453 1776 dmboot (3b809ffad55dcebdb156d5ca1bd3da65) D:\WINDOWS\system32\drivers\dmboot.sys 15:33:26.0468 1776 dmboot - ok 15:33:27.0171 1776 dmio (27725b6501201c3080ba73048bce389a) D:\WINDOWS\system32\drivers\dmio.sys 15:33:27.0171 1776 dmio - ok 15:33:27.0859 1776 dmload (e9317282a63ca4d188c0df5e09c6ac5f) D:\WINDOWS\system32\drivers\dmload.sys 15:33:27.0859 1776 dmload - ok 15:33:28.0546 1776 DMusic (a6f881284ac1150e37d9ae47ff601267) D:\WINDOWS\system32\drivers\DMusic.sys 15:33:28.0546 1776 DMusic - ok 15:33:29.0234 1776 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) D:\WINDOWS\system32\drivers\drmkaud.sys 15:33:29.0234 1776 drmkaud - ok 15:33:29.0937 1776 Fastfat (3117f595e9615e04f05a54fc15a03b20) D:\WINDOWS\system32\drivers\Fastfat.sys 15:33:29.0937 1776 Fastfat - ok 15:33:30.0656 1776 Fdc (ced2e8396a8838e59d8fd529c680e02c) D:\WINDOWS\system32\drivers\Fdc.sys 15:33:30.0656 1776 Fdc - ok 15:33:31.0328 1776 Fips (c5fb298257c0a6514ea17835e774ea0a) D:\WINDOWS\system32\drivers\Fips.sys 15:33:31.0328 1776 Fips - ok 15:33:32.0000 1776 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) D:\WINDOWS\system32\drivers\Flpydisk.sys 15:33:32.0000 1776 Flpydisk - ok 15:33:32.0703 1776 FltMgr (5a85cd3d07273e3f6fe72ee9c6431632) D:\WINDOWS\system32\DRIVERS\fltMgr.sys 15:33:32.0703 1776 FltMgr - ok 15:33:33.0656 1776 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) D:\WINDOWS\system32\drivers\Fs_Rec.sys 15:33:33.0671 1776 Fs_Rec - ok 15:33:34.0343 1776 Ftdisk (ed6d921d8ab423138fb35beee6d6a6cb) D:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:33:34.0359 1776 Ftdisk - ok 15:33:35.0015 1776 ggflt - ok 15:33:35.0656 1776 ggsemc - ok 15:33:36.0343 1776 Gpc (c0f1d4a21de5a415df8170616703debf) D:\WINDOWS\system32\DRIVERS\msgpc.sys 15:33:36.0343 1776 Gpc - ok 15:33:37.0062 1776 hamachi (833051c6c6c42117191935f734cfbd97) D:\WINDOWS\system32\DRIVERS\hamachi.sys 15:33:37.0062 1776 hamachi - ok 15:33:37.0750 1776 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) D:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:33:37.0750 1776 HDAudBus - ok 15:33:38.0437 1776 hidusb (1de6783b918f540149aa69943bdfeba8) D:\WINDOWS\system32\DRIVERS\hidusb.sys 15:33:38.0437 1776 hidusb - ok 15:33:39.0125 1776 HTTP (909d110c9634b0f1487eaaea837317d9) D:\WINDOWS\system32\Drivers\HTTP.sys 15:33:39.0125 1776 HTTP - ok 15:33:39.0828 1776 i8042prt (2656fdfe0a7916c3a16f374454c55dd9) D:\WINDOWS\system32\DRIVERS\i8042prt.sys 15:33:39.0828 1776 i8042prt - ok 15:33:40.0703 1776 ialm (bffa387180121df1e4646c4ced3e16ca) D:\WINDOWS\system32\DRIVERS\igxpmp32.sys 15:33:40.0890 1776 ialm - ok 15:33:41.0625 1776 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) D:\WINDOWS\system32\DRIVERS\imapi.sys 15:33:41.0625 1776 Imapi - ok 15:33:42.0468 1776 IntcAzAudAddService (613a2b00da1d4a80de1ec8cfb52c0d89) D:\WINDOWS\system32\drivers\RtkHDAud.sys 15:33:42.0625 1776 IntcAzAudAddService - ok 15:33:43.0281 1776 IntelIde - ok 15:33:43.0968 1776 intelppm (78a353438791c6d04c64013a5abec6bd) D:\WINDOWS\system32\DRIVERS\intelppm.sys 15:33:43.0968 1776 intelppm - ok 15:33:44.0640 1776 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) D:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 15:33:44.0640 1776 Ip6Fw - ok 15:33:45.0312 1776 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) D:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:33:45.0312 1776 IpFilterDriver - ok 15:33:45.0984 1776 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) D:\WINDOWS\system32\DRIVERS\ipinip.sys 15:33:45.0984 1776 IpInIp - ok 15:33:46.0656 1776 IpNat (5191673215c91ff13ceaa83ef8e9653f) D:\WINDOWS\system32\DRIVERS\ipnat.sys 15:33:46.0656 1776 IpNat - ok 15:33:47.0328 1776 IPSec (64537aa5c003a6afeee1df819062d0d1) D:\WINDOWS\system32\DRIVERS\ipsec.sys 15:33:47.0328 1776 IPSec - ok 15:33:48.0000 1776 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) D:\WINDOWS\system32\DRIVERS\irenum.sys 15:33:48.0000 1776 IRENUM - ok 15:33:48.0671 1776 isapnp (01a9e68528f4f34e5702123d27c67bd4) D:\WINDOWS\system32\DRIVERS\isapnp.sys 15:33:48.0671 1776 isapnp - ok 15:33:49.0359 1776 Kbdclass (cc13db862f929ae33f64c3bedc01cd31) D:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:33:49.0359 1776 Kbdclass - ok 15:33:50.0031 1776 kmixer (8531438246ce9474e41ee1599904c0c7) D:\WINDOWS\system32\drivers\kmixer.sys 15:33:50.0031 1776 kmixer - ok 15:33:50.0703 1776 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) D:\WINDOWS\system32\drivers\KSecDD.sys 15:33:50.0703 1776 KSecDD - ok 15:33:51.0343 1776 lbrtfdc - ok 15:33:52.0031 1776 Modem (15f33d12d604d0198ce5561f102cd9c5) D:\WINDOWS\system32\drivers\Modem.sys 15:33:52.0031 1776 Modem - ok 15:33:52.0718 1776 Mouclass (69c12b99ae8b6b99ec314e9b99833728) D:\WINDOWS\system32\DRIVERS\mouclass.sys 15:33:52.0734 1776 Mouclass - ok 15:33:53.0406 1776 mouhid (ecec1e6cd558ab80f944f31326e9d3b5) D:\WINDOWS\system32\DRIVERS\mouhid.sys 15:33:53.0406 1776 mouhid - ok 15:33:54.0078 1776 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) D:\WINDOWS\system32\drivers\MountMgr.sys 15:33:54.0078 1776 MountMgr - ok 15:33:54.0765 1776 MRxSmb (7412ce77c6fd823f8889b4df420c680b) D:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:33:54.0781 1776 MRxSmb - ok 15:33:55.0453 1776 Msfs (561b3a4333ca2dbdba28b5b956822519) D:\WINDOWS\system32\drivers\Msfs.sys 15:33:55.0453 1776 Msfs - ok 15:33:56.0109 1776 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) D:\WINDOWS\system32\drivers\MSKSSRV.sys 15:33:56.0125 1776 MSKSSRV - ok 15:33:56.0796 1776 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) D:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:33:56.0796 1776 MSPCLOCK - ok 15:33:57.0468 1776 MSPQM (1988a33ff19242576c3d0ef9ce785da7) D:\WINDOWS\system32\drivers\MSPQM.sys 15:33:57.0468 1776 MSPQM - ok 15:33:58.0171 1776 mssmbios (469541f8bfd2b32659d5d463a6714bce) D:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:33:58.0171 1776 mssmbios - ok 15:33:58.0843 1776 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) D:\WINDOWS\system32\drivers\Mup.sys 15:33:58.0843 1776 Mup - ok 15:33:59.0546 1776 NDIS (558635d3af1c7546d26067d5d9b6959e) D:\WINDOWS\system32\drivers\NDIS.sys 15:33:59.0562 1776 NDIS - ok 15:34:00.0250 1776 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) D:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:34:00.0250 1776 NdisTapi - ok 15:34:00.0937 1776 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) D:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:34:00.0937 1776 Ndisuio - ok 15:34:01.0625 1776 NdisWan (0b90e255a9490166ab368cd55a529893) D:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:34:01.0625 1776 NdisWan - ok 15:34:02.0296 1776 NDProxy (59fc3fb44d2669bc144fd87826bb571f) D:\WINDOWS\system32\drivers\NDProxy.sys 15:34:02.0312 1776 NDProxy - ok 15:34:02.0984 1776 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) D:\WINDOWS\system32\DRIVERS\netbios.sys 15:34:02.0984 1776 NetBIOS - ok 15:34:03.0656 1776 NetBT (0c80e410cd2f47134407ee7dd19cc86b) D:\WINDOWS\system32\DRIVERS\netbt.sys 15:34:03.0656 1776 NetBT - ok 15:34:04.0390 1776 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) D:\WINDOWS\system32\drivers\Npfs.sys 15:34:04.0406 1776 Npfs - ok 15:34:05.0093 1776 Ntfs (05ab81909514bfd69cbb1f2c147cf6b9) D:\WINDOWS\system32\drivers\Ntfs.sys 15:34:05.0109 1776 Ntfs - ok 15:34:05.0781 1776 Null (73c1e1f395918bc2c6dd67af7591a3ad) D:\WINDOWS\system32\drivers\Null.sys 15:34:05.0781 1776 Null - ok 15:34:06.0468 1776 papycpu2 (f5cf06754ae54d9d3353fc9c59bc4e04) D:\WINDOWS\System32\DRIVERS\papycpu2.sys 15:34:06.0484 1776 papycpu2 - ok 15:34:07.0156 1776 papyjoy (b09a71e8e1e127455f3a2fe83d38851f) D:\WINDOWS\System32\DRIVERS\papyjoy.sys 15:34:07.0156 1776 papyjoy - ok 15:34:07.0828 1776 Parport (2ff48d8fdc815a8492fb2bd81e6999c2) D:\WINDOWS\system32\drivers\Parport.sys 15:34:07.0843 1776 Parport - ok 15:34:08.0515 1776 PartMgr (3334430c29dc338092f79c38ef7b4cd0) D:\WINDOWS\system32\drivers\PartMgr.sys 15:34:08.0515 1776 PartMgr - ok 15:34:09.0203 1776 ParVdm (453ec2c2a20a1382f564541918520eeb) D:\WINDOWS\system32\drivers\ParVdm.sys 15:34:09.0203 1776 ParVdm - ok 15:34:09.0953 1776 PCAMPR5 - ok 15:34:10.0796 1776 PCANDIS5 (ceef86cb35abe95c40a88784f5b631ad) D:\WINDOWS\system32\PCANDIS5.SYS 15:34:10.0812 1776 PCANDIS5 - ok 15:34:11.0515 1776 PCI (5fd05c92ec56f696eaa50b68cef1b84a) D:\WINDOWS\system32\DRIVERS\pci.sys 15:34:11.0515 1776 PCI - ok 15:34:12.0187 1776 PCIDump - ok 15:34:12.0875 1776 PCIIde (548cf2d6369eae441a4c6baa75bc4f0a) D:\WINDOWS\system32\DRIVERS\pciide.sys 15:34:12.0875 1776 PCIIde - ok 15:34:13.0578 1776 Pcmcia (2849812217ecec059cb45f80eb6e52d4) D:\WINDOWS\system32\DRIVERS\pcmcia.sys 15:34:13.0578 1776 Pcmcia - ok 15:34:14.0265 1776 PDCOMP - ok 15:34:14.0937 1776 PDFRAME - ok 15:34:15.0593 1776 PDRELI - ok 15:34:16.0234 1776 PDRFRAME - ok 15:34:16.0921 1776 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) D:\WINDOWS\system32\DRIVERS\raspptp.sys 15:34:16.0921 1776 PptpMiniport - ok 15:34:17.0625 1776 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) D:\WINDOWS\system32\DRIVERS\ptilink.sys 15:34:17.0625 1776 Ptilink - ok 15:34:18.0343 1776 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) D:\WINDOWS\system32\DRIVERS\rasacd.sys 15:34:18.0343 1776 RasAcd - ok 15:34:19.0015 1776 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) D:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:34:19.0015 1776 Rasl2tp - ok 15:34:19.0671 1776 RasPppoe (7306eeed8895454cbed4669be9f79faa) D:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:34:19.0671 1776 RasPppoe - ok 15:34:20.0343 1776 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) D:\WINDOWS\system32\DRIVERS\raspti.sys 15:34:20.0343 1776 Raspti - ok 15:34:21.0031 1776 Rdbss (ed375ce745c42a14f10753f7022ecd6a) D:\WINDOWS\system32\DRIVERS\rdbss.sys 15:34:21.0031 1776 Rdbss - ok 15:34:21.0718 1776 RDPCDD (4912d5b403614ce99c28420f75353332) D:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:34:21.0718 1776 RDPCDD - ok 15:34:22.0406 1776 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) D:\WINDOWS\system32\DRIVERS\rdpdr.sys 15:34:22.0421 1776 rdpdr - ok 15:34:23.0203 1776 RDPWD (047bea21274c8a4a233674a76c958c2c) D:\WINDOWS\system32\drivers\RDPWD.sys 15:34:23.0218 1776 RDPWD - ok 15:34:23.0921 1776 redbook (029f83cfddd09abceb4fe3496af6175e) D:\WINDOWS\system32\DRIVERS\redbook.sys 15:34:23.0921 1776 redbook ( Virus.Win32.ZAccess.g ) - infected 15:34:23.0921 1776 redbook - detected Virus.Win32.ZAccess.g (0) 15:34:24.0671 1776 RT73 - ok 15:34:25.0343 1776 sdbus (02fc71b020ec8700ee8a46c58bc6f276) D:\WINDOWS\system32\DRIVERS\sdbus.sys 15:34:25.0343 1776 sdbus - ok 15:34:26.0046 1776 Secdrv (90a3935d05b494a5a39d37e71f09a677) D:\WINDOWS\system32\DRIVERS\secdrv.sys 15:34:26.0046 1776 Secdrv - ok 15:34:26.0750 1776 Serial (859bc6f8c3d58cfda9181e9926c7ddb9) D:\WINDOWS\system32\drivers\Serial.sys 15:34:26.0765 1776 Serial - ok 15:34:27.0468 1776 sfdrv01 (fca5dd901ed19b56b7ffca6fe1627edc) D:\WINDOWS\system32\drivers\sfdrv01.sys 15:34:27.0468 1776 sfdrv01 - ok 15:34:28.0187 1776 sfhlp02 (3ad2b15ccc03febfbaf5ff057822aa75) D:\WINDOWS\system32\drivers\sfhlp02.sys 15:34:28.0187 1776 sfhlp02 - ok 15:34:28.0859 1776 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) D:\WINDOWS\system32\drivers\Sfloppy.sys 15:34:28.0859 1776 Sfloppy - ok 15:34:29.0531 1776 sfsync02 (798d918d8f20380008277ce3ce5319d1) D:\WINDOWS\system32\drivers\sfsync02.sys 15:34:29.0531 1776 sfsync02 - ok 15:34:30.0328 1776 Simbad - ok 15:34:31.0000 1776 splitter (9bb1dd670cb7505a90fc4e61d4aa8227) D:\WINDOWS\system32\drivers\splitter.sys 15:34:31.0000 1776 splitter - ok 15:34:31.0718 1776 sptd (cdddec541bc3c96f91ecb48759673505) D:\WINDOWS\system32\Drivers\sptd.sys 15:34:31.0718 1776 Suspicious file (NoAccess): D:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 15:34:31.0718 1776 sptd ( LockedFile.Multi.Generic ) - warning 15:34:31.0718 1776 sptd - detected LockedFile.Multi.Generic (1) 15:34:32.0562 1776 Srv (5230953c21c811b5fc1ff31ae2b48097) D:\WINDOWS\system32\DRIVERS\srv.sys 15:34:32.0578 1776 Srv - ok 15:34:33.0265 1776 swenum (03c1bae4766e2450219d20b993d6e046) D:\WINDOWS\system32\DRIVERS\swenum.sys 15:34:33.0265 1776 swenum - ok 15:34:33.0937 1776 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) D:\WINDOWS\system32\drivers\swmidi.sys 15:34:33.0937 1776 swmidi - ok 15:34:34.0625 1776 sysaudio (650ad082d46bac0e64c9c0e0928492fd) D:\WINDOWS\system32\drivers\sysaudio.sys 15:34:34.0625 1776 sysaudio - ok 15:34:35.0328 1776 Tcpip (ea3d7525f41beb321c3f6e2162277e92) D:\WINDOWS\system32\DRIVERS\tcpip.sys 15:34:35.0343 1776 Tcpip - ok 15:34:36.0171 1776 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) D:\WINDOWS\system32\drivers\TDPIPE.sys 15:34:36.0171 1776 TDPIPE - ok 15:34:37.0000 1776 TDTCP (ed0580af02502d00ad8c4c066b156be9) D:\WINDOWS\system32\drivers\TDTCP.sys 15:34:37.0000 1776 TDTCP - ok 15:34:37.0703 1776 TermDD (a540a99c281d933f3d69d55e48727f47) D:\WINDOWS\system32\DRIVERS\termdd.sys 15:34:37.0703 1776 TermDD - ok 15:34:38.0421 1776 TosIde - ok 15:34:39.0125 1776 Udfs (12f70256f140cd7d52c58c7048fde657) D:\WINDOWS\system32\drivers\Udfs.sys 15:34:39.0125 1776 Udfs - ok 15:34:39.0828 1776 Update (1f03139b77b21c6d84c688798808bc28) D:\WINDOWS\system32\DRIVERS\update.sys 15:34:39.0859 1776 Update - ok 15:34:40.0546 1776 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) D:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:34:40.0546 1776 usbccgp - ok 15:34:41.0281 1776 usbehci (15e993ba2f6946b2bfbbfcd30398621e) D:\WINDOWS\system32\DRIVERS\usbehci.sys 15:34:41.0281 1776 usbehci - ok 15:34:42.0140 1776 usbhub (c72f40947f92cea56a8fb532edf025f1) D:\WINDOWS\system32\DRIVERS\usbhub.sys 15:34:42.0156 1776 usbhub - ok 15:34:42.0890 1776 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:34:42.0890 1776 USBSTOR - ok 15:34:43.0734 1776 usbuhci (f8fd1400092e23c8f2f31406ef06167b) D:\WINDOWS\system32\DRIVERS\usbuhci.sys 15:34:43.0734 1776 usbuhci - ok 15:34:44.0421 1776 VgaSave (8a60edd72b4ea5aea8202daf0e427925) D:\WINDOWS\System32\drivers\vga.sys 15:34:44.0437 1776 VgaSave - ok 15:34:45.0078 1776 ViaIde - ok 15:34:45.0781 1776 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) D:\WINDOWS\system32\DRIVERS\wanarp.sys 15:34:45.0781 1776 Wanarp - ok 15:34:46.0546 1776 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) D:\WINDOWS\system32\Drivers\wdf01000.sys 15:34:46.0562 1776 Wdf01000 - ok 15:34:47.0296 1776 WDICA - ok 15:34:48.0187 1776 wdmaud (0bfa8203b8148fb4e54bc212c41ce497) D:\WINDOWS\system32\drivers\wdmaud.sys 15:34:48.0187 1776 wdmaud - ok 15:34:48.0937 1776 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) D:\WINDOWS\system32\DRIVERS\wmiacpi.sys 15:34:48.0937 1776 WmiAcpi - ok 15:34:49.0656 1776 WudfPf (f15feafffbb3644ccc80c5da584e6311) D:\WINDOWS\system32\DRIVERS\WudfPf.sys 15:34:49.0656 1776 WudfPf - ok 15:34:50.0375 1776 WudfRd (28b524262bce6de1f7ef9f510ba3985b) D:\WINDOWS\system32\DRIVERS\wudfrd.sys 15:34:50.0375 1776 WudfRd - ok 15:34:50.0437 1776 MBR (0x1B8) (32052574bf9f325ae309abc7bfd04460) \Device\Harddisk0\DR0 15:34:50.0609 1776 \Device\Harddisk0\DR0 - ok 15:34:50.0640 1776 Boot (0x1200) (4028dc3067badc8988b0b53c660fc6f0) \Device\Harddisk0\DR0\Partition0 15:34:50.0640 1776 \Device\Harddisk0\DR0\Partition0 - ok 15:34:50.0656 1776 Boot (0x1200) (827ed5512096af4018fe7e25555d259d) \Device\Harddisk0\DR0\Partition1 15:34:50.0656 1776 \Device\Harddisk0\DR0\Partition1 - ok 15:34:50.0656 1776 ============================================================ 15:34:50.0656 1776 Scan finished 15:34:50.0656 1776 ============================================================ 15:34:50.0671 0492 Detected object count: 3 15:34:50.0671 0492 Actual detected object count: 3 15:37:58.0343 0492 ACPI ( Virus.Win32.Rloader.a ) - skipped by user 15:37:58.0343 0492 ACPI ( Virus.Win32.Rloader.a ) - User select action: Skip 15:37:58.0343 0492 redbook ( Virus.Win32.ZAccess.g ) - skipped by user 15:37:58.0343 0492 redbook ( Virus.Win32.ZAccess.g ) - User select action: Skip 15:37:58.0343 0492 sptd ( LockedFile.Multi.Generic ) - skipped by user 15:37:58.0343 0492 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 15:38:01.0875 2032 Deinitialize success