2011/05/26 21:45:47.0375 16200 TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24 2011/05/26 21:45:48.0046 16200 ================================================================================ 2011/05/26 21:45:48.0046 16200 SystemInfo: 2011/05/26 21:45:48.0046 16200 2011/05/26 21:45:48.0046 16200 OS Version: 5.1.2600 ServicePack: 2.0 2011/05/26 21:45:48.0046 16200 Product type: Workstation 2011/05/26 21:45:48.0046 16200 ComputerName: MANIEK 2011/05/26 21:45:48.0046 16200 UserName: Monia 2011/05/26 21:45:48.0046 16200 Windows directory: C:\WINDOWS 2011/05/26 21:45:48.0046 16200 System windows directory: C:\WINDOWS 2011/05/26 21:45:48.0046 16200 Processor architecture: Intel x86 2011/05/26 21:45:48.0046 16200 Number of processors: 2 2011/05/26 21:45:48.0046 16200 Page size: 0x1000 2011/05/26 21:45:48.0046 16200 Boot type: Normal boot 2011/05/26 21:45:48.0046 16200 ================================================================================ 2011/05/26 21:45:50.0281 16200 Initialize success 2011/05/26 21:49:28.0625 24100 ================================================================================ 2011/05/26 21:49:28.0625 24100 Scan started 2011/05/26 21:49:28.0625 24100 Mode: Manual; 2011/05/26 21:49:28.0625 24100 ================================================================================ 2011/05/26 21:49:30.0312 24100 Aavmker4 (d301f57713a0f6f8a3295ae6ebb69617) C:\WINDOWS\system32\drivers\Aavmker4.sys 2011/05/26 21:49:30.0406 24100 ACPI (a966410ecf83b81f3b0b8e07a71957d4) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/05/26 21:49:30.0437 24100 ACPIEC (66a42b7db194e24b973bbcce840a0f3f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 2011/05/26 21:49:30.0500 24100 ADIHdAudAddService (be4beb3fde3edfad4ef2760722717b0f) C:\WINDOWS\system32\drivers\ADIHdAud.sys 2011/05/26 21:49:30.0609 24100 AEAudio (358063ab6c1c4173b735525cdfa65f94) C:\WINDOWS\system32\drivers\AEAudio.sys 2011/05/26 21:49:30.0671 24100 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 2011/05/26 21:49:30.0734 24100 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 2011/05/26 21:49:31.0062 24100 Aspi32 (20d04091eba710f6988f710507d85868) C:\WINDOWS\system32\drivers\Aspi32.sys 2011/05/26 21:49:31.0187 24100 aswMon2 (71785f529c7b251b188245843bbf85db) C:\WINDOWS\system32\drivers\aswMon2.sys 2011/05/26 21:49:31.0218 24100 aswRdr (7bab4923cabb4404bf05fd111e75e49b) C:\WINDOWS\system32\drivers\aswRdr.sys 2011/05/26 21:49:31.0234 24100 aswTdi (e8a2678eab78c2060d5eb26803667dc2) C:\WINDOWS\system32\drivers\aswTdi.sys 2011/05/26 21:49:31.0281 24100 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/05/26 21:49:31.0296 24100 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/05/26 21:49:31.0390 24100 ati2mtag (4fbbe3d1d0732d09138b484335fcd542) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/05/26 21:49:31.0437 24100 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ati2mtag.sys. Real md5: 4fbbe3d1d0732d09138b484335fcd542, Fake md5: a1789368b4a31d2111af7aeda0c8d3fc 2011/05/26 21:49:31.0453 24100 ati2mtag - detected ForgedFile.Multi.Generic (1) 2011/05/26 21:49:31.0593 24100 atksgt (3c4b9850a2631c2263507400d029057b) C:\WINDOWS\system32\DRIVERS\atksgt.sys 2011/05/26 21:49:31.0640 24100 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/05/26 21:49:31.0687 24100 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/05/26 21:49:31.0828 24100 b57w2k (133ad3794572bce689763a8356c7ed06) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 2011/05/26 21:49:31.0906 24100 BCM43XX (b89bcf0a25aeb3b47030ac83287f894a) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 2011/05/26 21:49:32.0015 24100 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/05/26 21:49:32.0062 24100 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/05/26 21:49:32.0140 24100 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/05/26 21:49:32.0171 24100 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/05/26 21:49:32.0296 24100 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2011/05/26 21:49:32.0359 24100 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2011/05/26 21:49:32.0515 24100 DgiVecp (a5034f77b278f07e224fe07cf98a8b76) C:\WINDOWS\system32\Drivers\DgiVecp.sys 2011/05/26 21:49:32.0640 24100 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/05/26 21:49:32.0703 24100 dmboot (3b809ffad55dcebdb156d5ca1bd3da65) C:\WINDOWS\system32\drivers\dmboot.sys 2011/05/26 21:49:32.0796 24100 dmio (27725b6501201c3080ba73048bce389a) C:\WINDOWS\system32\drivers\dmio.sys 2011/05/26 21:49:32.0828 24100 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/05/26 21:49:32.0875 24100 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2011/05/26 21:49:32.0937 24100 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/05/26 21:49:32.0984 24100 eabfiltr (e88b0cfcecf745211bba87f44f85d0dd) C:\WINDOWS\system32\DRIVERS\eabfiltr.sys 2011/05/26 21:49:33.0109 24100 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/05/26 21:49:33.0140 24100 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 2011/05/26 21:49:33.0171 24100 Fips (c5fb298257c0a6514ea17835e774ea0a) C:\WINDOWS\system32\drivers\Fips.sys 2011/05/26 21:49:33.0203 24100 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/05/26 21:49:33.0328 24100 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/05/26 21:49:33.0375 24100 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/05/26 21:49:33.0406 24100 Ftdisk (ed6d921d8ab423138fb35beee6d6a6cb) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/05/26 21:49:33.0453 24100 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/05/26 21:49:33.0562 24100 HBtnKey (de15777902a5d9121857d155873a1d1b) C:\WINDOWS\system32\DRIVERS\cpqbttn.sys 2011/05/26 21:49:33.0625 24100 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/05/26 21:49:33.0671 24100 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/05/26 21:49:33.0765 24100 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/05/26 21:49:33.0906 24100 i8042prt (2656fdfe0a7916c3a16f374454c55dd9) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/05/26 21:49:33.0984 24100 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/05/26 21:49:34.0171 24100 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/05/26 21:49:34.0218 24100 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/05/26 21:49:34.0250 24100 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/05/26 21:49:34.0375 24100 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/05/26 21:49:34.0406 24100 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/05/26 21:49:34.0453 24100 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/05/26 21:49:34.0500 24100 isapnp (01a9e68528f4f34e5702123d27c67bd4) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/05/26 21:49:34.0625 24100 Kbdclass (cc13db862f929ae33f64c3bedc01cd31) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/05/26 21:49:34.0656 24100 kbdhid (831be9197bdace6bdcac1bfdbe1c380f) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/05/26 21:49:34.0703 24100 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 2011/05/26 21:49:34.0765 24100 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/05/26 21:49:34.0953 24100 LHidFilt (3fa98339e8d9e007726be62f231e2015) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys 2011/05/26 21:49:35.0000 24100 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\WINDOWS\system32\DRIVERS\lirsgt.sys 2011/05/26 21:49:35.0031 24100 LMouFilt (f259f758e04d8fb8d48c6cdbe45223e8) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys 2011/05/26 21:49:35.0046 24100 LUsbFilt (ca26e46ec8891058c9e10363df4e4650) C:\WINDOWS\system32\Drivers\LUsbFilt.Sys 2011/05/26 21:49:35.0093 24100 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/05/26 21:49:35.0218 24100 Modem (15f33d12d604d0198ce5561f102cd9c5) C:\WINDOWS\system32\drivers\Modem.sys 2011/05/26 21:49:35.0265 24100 Mouclass (69c12b99ae8b6b99ec314e9b99833728) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/05/26 21:49:35.0312 24100 mouhid (ecec1e6cd558ab80f944f31326e9d3b5) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/05/26 21:49:35.0328 24100 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/05/26 21:49:35.0484 24100 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/05/26 21:49:35.0562 24100 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/05/26 21:49:35.0796 24100 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2011/05/26 21:49:35.0843 24100 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/05/26 21:49:35.0875 24100 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/05/26 21:49:35.0906 24100 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/05/26 21:49:36.0000 24100 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/05/26 21:49:36.0062 24100 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2011/05/26 21:49:36.0093 24100 MxlW2k (31509f505fea9b37f9e59a10adcfe8f5) C:\WINDOWS\system32\drivers\MxlW2k.sys 2011/05/26 21:49:36.0125 24100 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2011/05/26 21:49:36.0171 24100 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/05/26 21:49:36.0281 24100 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/05/26 21:49:36.0296 24100 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/05/26 21:49:36.0328 24100 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/05/26 21:49:36.0375 24100 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/05/26 21:49:36.0484 24100 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/05/26 21:49:36.0578 24100 netr73 (2dd6bb85c8bdae6116565ab5beca4f7c) C:\WINDOWS\system32\DRIVERS\netr73.sys 2011/05/26 21:49:36.0687 24100 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2011/05/26 21:49:36.0765 24100 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/05/26 21:49:36.0875 24100 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/05/26 21:49:36.0921 24100 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/05/26 21:49:36.0953 24100 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/05/26 21:49:37.0015 24100 Parport (2ff48d8fdc815a8492fb2bd81e6999c2) C:\WINDOWS\system32\drivers\Parport.sys 2011/05/26 21:49:37.0093 24100 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/05/26 21:49:37.0125 24100 ParVdm (453ec2c2a20a1382f564541918520eeb) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/05/26 21:49:37.0156 24100 PCI (5fd05c92ec56f696eaa50b68cef1b84a) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/05/26 21:49:37.0218 24100 PCIIde (548cf2d6369eae441a4c6baa75bc4f0a) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/05/26 21:49:37.0312 24100 Pcmcia (2849812217ecec059cb45f80eb6e52d4) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 2011/05/26 21:49:37.0562 24100 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/05/26 21:49:37.0578 24100 Processor (0914733fb2fc58f69cda0e929bf2df22) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/05/26 21:49:37.0687 24100 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/05/26 21:49:37.0718 24100 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/05/26 21:49:37.0843 24100 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/05/26 21:49:37.0890 24100 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/05/26 21:49:37.0906 24100 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/05/26 21:49:37.0937 24100 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/05/26 21:49:37.0984 24100 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/05/26 21:49:38.0062 24100 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/05/26 21:49:38.0125 24100 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/05/26 21:49:38.0203 24100 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/05/26 21:49:38.0234 24100 redbook (bddcece9acdad26841c987d10376f6f7) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/05/26 21:49:38.0375 24100 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/05/26 21:49:38.0437 24100 Sentinel (cd8f847a75a974d7aa723a23dfb7d004) C:\WINDOWS\System32\Drivers\SENTINEL.SYS 2011/05/26 21:49:38.0515 24100 Serial (859bc6f8c3d58cfda9181e9926c7ddb9) C:\WINDOWS\system32\drivers\Serial.sys 2011/05/26 21:49:38.0656 24100 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys 2011/05/26 21:49:38.0671 24100 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys 2011/05/26 21:49:38.0718 24100 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/05/26 21:49:38.0750 24100 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\WINDOWS\system32\drivers\sfvfs02.sys 2011/05/26 21:49:38.0921 24100 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 2011/05/26 21:49:38.0984 24100 sr (6145ca23bccda679a772ec0af42d6eb5) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/05/26 21:49:39.0078 24100 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/05/26 21:49:39.0171 24100 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/05/26 21:49:39.0218 24100 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2011/05/26 21:49:39.0375 24100 SynTP (1de40024679cde0e573465253519730e) C:\WINDOWS\system32\DRIVERS\SynTP.sys 2011/05/26 21:49:39.0453 24100 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/05/26 21:49:39.0546 24100 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/05/26 21:49:39.0656 24100 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/05/26 21:49:39.0703 24100 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/05/26 21:49:39.0734 24100 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/05/26 21:49:39.0828 24100 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2011/05/26 21:49:39.0906 24100 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 2011/05/26 21:49:39.0984 24100 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/05/26 21:49:40.0062 24100 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/05/26 21:49:40.0078 24100 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys 2011/05/26 21:49:40.0125 24100 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/05/26 21:49:40.0171 24100 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/05/26 21:49:40.0234 24100 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/05/26 21:49:40.0312 24100 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2011/05/26 21:49:40.0375 24100 VolSnap (ecd173739b8ec10a814cc18653df5a36) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/05/26 21:49:40.0453 24100 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/05/26 21:49:40.0531 24100 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 2011/05/26 21:49:40.0703 24100 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/05/26 21:49:40.0750 24100 WIBUKEY (afcea7939925378f867dde6af76f3924) C:\WINDOWS\system32\DRIVERS\WibuKey.sys 2011/05/26 21:49:40.0828 24100 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 2011/05/26 21:49:40.0953 24100 MBR (0x1B8) (6d16556bad153ed1661ac09df9f59375) \Device\Harddisk0\DR0 2011/05/26 21:49:40.0953 24100 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/05/26 21:49:40.0968 24100 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR3 2011/05/26 21:49:41.0046 24100 ================================================================================ 2011/05/26 21:49:41.0046 24100 Scan finished 2011/05/26 21:49:41.0046 24100 ================================================================================ 2011/05/26 21:49:41.0078 24092 Detected object count: 2 2011/05/26 21:49:41.0078 24092 Actual detected object count: 2 2011/05/26 21:50:48.0281 24092 ForgedFile.Multi.Generic(ati2mtag) - User select action: Skip 2011/05/26 21:50:48.0296 24092 \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot 2011/05/26 21:50:48.0296 24092 \Device\Harddisk0\DR0 - ok 2011/05/26 21:50:48.0296 24092 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure 2011/05/26 21:52:41.0468 19252 Deinitialize success