10:53:46.0973 0x05b0 TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12 10:53:50.0768 0x05b0 ============================================================ 10:53:50.0768 0x05b0 Current date / time: 2018/11/08 10:53:50.0768 10:53:50.0768 0x05b0 SystemInfo: 10:53:50.0768 0x05b0 10:53:50.0768 0x05b0 OS Version: 5.1.2600 ServicePack: 3.0 10:53:50.0768 0x05b0 Product type: Workstation 10:53:50.0768 0x05b0 ComputerName: DOM 10:53:50.0768 0x05b0 UserName: Administrator 10:53:50.0768 0x05b0 Windows directory: C:\WINDOWS 10:53:50.0768 0x05b0 System windows directory: C:\WINDOWS 10:53:50.0768 0x05b0 Processor architecture: Intel x86 10:53:50.0768 0x05b0 Number of processors: 1 10:53:50.0768 0x05b0 Page size: 0x1000 10:53:50.0768 0x05b0 Boot type: Normal boot 10:53:50.0768 0x05b0 ============================================================ 10:53:56.0456 0x05b0 KLMD registered as C:\WINDOWS\system32\drivers\38263296.sys 10:53:56.0697 0x05b0 System UUID: {26F2B55E-7073-FE67-35A9-6DE0D223465E} 10:53:57.0568 0x05b0 Drive \Device\Harddisk0\DR0 - Size: 0x6FC7C8000 ( 27.95 Gb ), SectorSize: 0x200, Cylinders: 0xE40, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 10:53:57.0568 0x05b0 ============================================================ 10:53:57.0568 0x05b0 \Device\Harddisk0\DR0: 10:53:57.0568 0x05b0 MBR partitions: 10:53:57.0568 0x05b0 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1B58F7A 10:53:57.0578 0x05b0 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xB, StartLBA 0x1B58FF8, BlocksNum 0x1C86F87 10:53:57.0578 0x05b0 ============================================================ 10:53:57.0638 0x05b0 C: <-> \Device\Harddisk0\DR0\Partition1 10:53:57.0638 0x05b0 D: <-> \Device\Harddisk0\DR0\Partition2 10:53:57.0638 0x05b0 ============================================================ 10:53:57.0638 0x05b0 Initialize success 10:53:57.0638 0x05b0 ============================================================ 10:55:18.0464 0x05dc ============================================================ 10:55:18.0464 0x05dc Scan started 10:55:18.0464 0x05dc Mode: Manual; 10:55:18.0464 0x05dc ============================================================ 10:55:18.0464 0x05dc KSN ping started 10:55:18.0625 0x05dc KSN ping finished: false 10:55:19.0476 0x05dc ================ Scan system memory ======================== 10:55:19.0476 0x05dc System memory - ok 10:55:19.0486 0x05dc ================ Scan services ============================= 10:55:20.0457 0x05dc Abiosdsk - ok 10:55:20.0477 0x05dc abp480n5 - ok 10:55:20.0527 0x05dc [ 05118282F5D039595A2B92B4A4AFE197, 390EBD6088E96571636CE0925E4899D58893D9E5DF2389C09BABBD47A5838B52 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 10:55:20.0557 0x05dc ACPI - ok 10:55:20.0627 0x05dc [ 66A42B7DB194E24B973BBCCE840A0F3F, 2550F8E5B5ACD88E4191656194E46FB8EC8CCC65AFD4B5E6D5CED9FE297B573F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 10:55:20.0637 0x05dc ACPIEC - ok 10:55:20.0647 0x05dc adpu160m - ok 10:55:20.0708 0x05dc [ EABCB9C1420341AB4B468DE317A1DA96, 3718DF95B200A99DA6F6423A73221EC2AA8172B953330877D45DB314A6630A26 ] aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys 10:55:20.0708 0x05dc aeaudio - ok 10:55:20.0778 0x05dc [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys 10:55:20.0788 0x05dc aec - ok 10:55:20.0838 0x05dc [ 129467B226EF8CCF90EA78A93D6E770A, C1B6A94790F46A470810BBBAC78E6A0342C11C76A34DB433A7DA76E6D22B617F ] AFD C:\WINDOWS\System32\drivers\afd.sys 10:55:20.0838 0x05dc Suspicious file ( Forged ): C:\WINDOWS\System32\drivers\afd.sys. Real md5: 129467B226EF8CCF90EA78A93D6E770A, sha256: C1B6A94790F46A470810BBBAC78E6A0342C11C76A34DB433A7DA76E6D22B617F, fake md5: D6EE6014241D034E63C49A50CB2B442A, fake sha256: BBFB093F4881E18F2DA5F76DD34B8558DD9B8883408667678B72CF504BBD0E74 10:55:20.0848 0x05dc AFD - detected Virus.Win32.ZAccess.c ( 0 ) 10:55:20.0878 0x05dc AFD ( Virus.Win32.ZAccess.c ) - infected 10:55:20.0878 0x05dc Force sending object to P2P due to detect: AFD 10:55:20.0898 0x05dc Object send P2P result: false 10:55:21.0028 0x05dc [ E66AE825C42B668A90E67E7E41EEEEE7, 6A8D1B84796EE78E09E659F985B5581D286DE09A5D81B586CAEA8D4ABE1054B5 ] AgereSoftModem C:\WINDOWS\system32\DRIVERS\AGRSM.sys 10:55:21.0128 0x05dc AgereSoftModem - ok 10:55:21.0148 0x05dc Aha154x - ok 10:55:21.0168 0x05dc aic78u2 - ok 10:55:21.0188 0x05dc aic78xx - ok 10:55:21.0228 0x05dc [ D1738DDDFF196C5CEE6D867C136AF745, DD4780276465CB18D14B4DDBB4E70117B374B3A61C618D68B5290714330DB91F ] ALG C:\WINDOWS\System32\alg.exe 10:55:21.0238 0x05dc ALG - ok 10:55:21.0258 0x05dc AliIde - ok 10:55:21.0278 0x05dc amsint - ok 10:55:21.0318 0x05dc [ 1561430DA2F2AB81CC0CE71AF95A778D, 1EFD6F9FCD7A00DA6B4AFEC1E04E3DDF4147B7DF1CF021430B31F821E48395A0 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 10:55:21.0388 0x05dc AppMgmt - ok 10:55:21.0429 0x05dc asc - ok 10:55:21.0439 0x05dc asc3350p - ok 10:55:21.0459 0x05dc asc3550 - ok 10:55:21.0729 0x05dc [ E1633440859F9A1B3CEAF73BA85225CA, 281679A65055F03B617E55ABCADCF9D050F22AF250991D95A543D10F620D8780 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 10:55:21.0809 0x05dc aspnet_state - ok 10:55:21.0859 0x05dc [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 10:55:21.0859 0x05dc AsyncMac - ok 10:55:21.0919 0x05dc [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 10:55:21.0929 0x05dc atapi - ok 10:55:21.0959 0x05dc Atdisk - ok 10:55:21.0999 0x05dc [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 10:55:22.0009 0x05dc Atmarpc - ok 10:55:22.0029 0x05dc [ 3A28D3E7BAD0EED3810CD918B2525B54, EFC7CEF39D58E846613E419E78ECBD300DFB18630B70110AB2936737EB2B19C1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 10:55:22.0029 0x05dc AudioSrv - ok 10:55:22.0069 0x05dc [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 10:55:22.0069 0x05dc audstub - ok 10:55:22.0130 0x05dc [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys 10:55:22.0130 0x05dc Beep - ok 10:55:22.0220 0x05dc [ 78200FAA6FD9C69394134C238C87FB7F, 4E70BD89BB40222CB0647E8F73DBBAB1020594AEC313848C911048D080D0F26A ] BITS C:\WINDOWS\system32\qmgr.dll 10:55:22.0330 0x05dc BITS - ok 10:55:22.0390 0x05dc [ B98ED6D85339A66A73F32FB569EB6C01, 08DF27984060C55F8CDF5F8F9FF73816163B659030B9098F62027FE7303EEDEC ] Browser C:\WINDOWS\System32\browser.dll 10:55:22.0390 0x05dc Browser - ok 10:55:22.0440 0x05dc [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 10:55:22.0440 0x05dc cbidf2k - ok 10:55:22.0460 0x05dc cd20xrnt - ok 10:55:22.0480 0x05dc [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 10:55:22.0490 0x05dc Cdaudio - ok 10:55:22.0530 0x05dc [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 10:55:22.0530 0x05dc Cdfs - ok 10:55:22.0570 0x05dc [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 10:55:22.0570 0x05dc Cdrom - ok 10:55:22.0590 0x05dc Changer - ok 10:55:22.0660 0x05dc [ 3D560AF01BDC50B4A1E1BFB5CDC06D63, 873B3A8271B8D25D54C35A50A4C4B9FA494C72F32C9C1FA3B63D89BAC4D421DB ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 10:55:22.0811 0x05dc clr_optimization_v2.0.50727_32 - ok 10:55:22.0861 0x05dc [ 0F6C187D38D98F8DF904589A5F94D411, DB987093446216CEE913AC27503BF7E23E5A62DF169B355730285DAB64F6ED28 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 10:55:22.0871 0x05dc CmBatt - ok 10:55:22.0881 0x05dc CmdIde - ok 10:55:22.0911 0x05dc [ 6E4C9F21F0FAE8940661144F41B13203, 731202A0DD021FCF9287FEA631212603AAAC23F9E7F76B2882F913B18A971F1C ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 10:55:22.0911 0x05dc Compbatt - ok 10:55:22.0931 0x05dc COMSysApp - ok 10:55:22.0961 0x05dc Cpqarray - ok 10:55:23.0021 0x05dc [ 6B105FE95F2E9F0B6346044BA59D41C9, DC41FC89E6C4F4219015856AEE9D9CE365094D3C8012AFFC188C129DC3B6A9A8 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 10:55:23.0031 0x05dc CryptSvc - ok 10:55:23.0041 0x05dc dac2w2k - ok 10:55:23.0061 0x05dc dac960nt - ok 10:55:23.0141 0x05dc [ 02396DAB9DD407B06539981F477F3FEC, 02909411C763FE75A66AD31A0C3B4492FBB00F9AF3D2BE8478A444861A086B2A ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 10:55:23.0181 0x05dc DcomLaunch - ok 10:55:23.0231 0x05dc [ 6B4AFE7C676CFF3EFF2DC06A4EE945F7, 9771808A033C781758AC1356F9F51B198A0750081424F4F7A937CE0D7408CEE1 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 10:55:23.0241 0x05dc Dhcp - ok 10:55:23.0271 0x05dc [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 10:55:23.0271 0x05dc Disk - ok 10:55:23.0291 0x05dc dmadmin - ok 10:55:23.0431 0x05dc [ BC9219ABC5696942E6F9AC8A9B28670F, DEDD84A5FC12664C7767EC5210E3B4D311664EF8BCE01C9DCF16CC98BE16EDE1 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 10:55:23.0512 0x05dc dmboot - ok 10:55:23.0572 0x05dc [ 5FA232E3BA6E1346F9F5A7E519320CB0, 1C7EEC415C291D3C5FFD479A8454347528AF4FF88F81011EF65EFA8FE8199973 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 10:55:23.0592 0x05dc dmio - ok 10:55:23.0632 0x05dc [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys 10:55:23.0632 0x05dc dmload - ok 10:55:23.0662 0x05dc [ D858920A05076914D34B0388E8D96CC0, A8F231BA9022F6AEBB24C9DCC1898923F85B79DE3C8E90B696CA0B295B9C99B7 ] dmserver C:\WINDOWS\System32\dmserver.dll 10:55:23.0682 0x05dc dmserver - ok 10:55:23.0712 0x05dc [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 10:55:23.0722 0x05dc DMusic - ok 10:55:23.0752 0x05dc [ 4F7E82841ED3CF026BD8D5CE7C7379DB, EE216CCF13C78ED5BE30F21347A04E8EA3FB6AE016F7C88B67891DF8A49CB031 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 10:55:23.0762 0x05dc Dnscache - ok 10:55:23.0812 0x05dc [ E0B7D66CF29D9ADCCF873C77821CD4CA, 09A3D28585B62FC541EF4F2CB4D749DA119BB5F98739393CFD4D745060217C65 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 10:55:23.0822 0x05dc Dot3svc - ok 10:55:23.0832 0x05dc dpti2o - ok 10:55:23.0862 0x05dc [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 10:55:23.0872 0x05dc drmkaud - ok 10:55:23.0922 0x05dc [ AC9CF17EE2AE003C98EB4F5336C38058, 40618641B6B2DD71A8C284EB25AF81CA219A82AE7AA91C4BB2B4A3D44A2B3BBF ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys 10:55:23.0932 0x05dc E100B - ok 10:55:23.0972 0x05dc [ 5F256C1AD50FEFDC442CD5AAB58C7DD8, 0FC1F2590195AE4B7CAA802D84CD391B56D73B99CB100BDEBD4D7C002946D06B ] EapHost C:\WINDOWS\System32\eapsvc.dll 10:55:23.0982 0x05dc EapHost - ok 10:55:24.0022 0x05dc [ 3E3AE424E27C4CEFE4CAB368C7B570EA, 95A3B2758662D9EB803BA8D0A294881451EEA9F1033978C4C60810317A703C5C ] Eventlog C:\WINDOWS\system32\services.exe 10:55:24.0032 0x05dc Eventlog - ok 10:55:24.0082 0x05dc [ BE1B1412A3D488C50B8F67F792196108, 5F7A3CE16D35FAA7D69752320C427DEF907B6B70BAFFF9B64827E5C82D2B008C ] EventSystem C:\WINDOWS\system32\es.dll 10:55:24.0112 0x05dc EventSystem - ok 10:55:24.0183 0x05dc [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 10:55:24.0203 0x05dc Fastfat - ok 10:55:24.0243 0x05dc [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 10:55:24.0253 0x05dc FastUserSwitchingCompatibility - ok 10:55:24.0293 0x05dc [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 10:55:24.0303 0x05dc Fdc - ok 10:55:24.0343 0x05dc [ 09E2A4D33F81A06A8AAB2BA0A0B5D235, D71C2D4212C7ABB1D8EE08B21C59CA25D7195F1A0E92E5BDA1DC5226A0E62CB0 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 10:55:24.0343 0x05dc Fips - ok 10:55:24.0363 0x05dc [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 10:55:24.0363 0x05dc Flpydisk - ok 10:55:24.0443 0x05dc [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 10:55:24.0453 0x05dc FltMgr - ok 10:55:24.0483 0x05dc [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 10:55:24.0483 0x05dc Fs_Rec - ok 10:55:24.0533 0x05dc [ AAE37F0F2F613218DCE17B42A18C38DB, 3C235370054E1AB3EFD6E59825B38F63F6B861025ABFE05CAC940B56D17D25BC ] FTDIBUS C:\WINDOWS\system32\drivers\ftdibus.sys 10:55:24.0543 0x05dc FTDIBUS - ok 10:55:24.0593 0x05dc [ ED6D921D8AB423138FB35BEEE6D6A6CB, CF133B76960207595C44181A235E63B84C5A5A4E7BDDDC2E6A01DA837E55832D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 10:55:24.0603 0x05dc Ftdisk - ok 10:55:24.0653 0x05dc [ 48BFD1BA45C9C9E7AB339E25ABFBA1D2, 950F5C1A6FD00E0AABD090753781729EFFF8157525D0DD127864C27E0F7F21FA ] FTSER2K C:\WINDOWS\system32\drivers\ftser2k.sys 10:55:24.0653 0x05dc FTSER2K - ok 10:55:24.0703 0x05dc [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 10:55:24.0703 0x05dc Gpc - ok 10:55:24.0743 0x05dc [ 1776C3B6069EEECC8042535296C1866A, 57B516B7E0C12EF16568647B069441731C0484C0D0E87900D1F2E895BD67FF18 ] HidServ C:\WINDOWS\System32\hidserv.dll 10:55:24.0743 0x05dc HidServ - ok 10:55:24.0783 0x05dc [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 10:55:24.0793 0x05dc HidUsb - ok 10:55:24.0843 0x05dc [ F0273916DA6FB64CC88E0BD77619554F, C6E3B5C367CE52174251B1CE548F0DF8708AEDD228D5AD74D3F6F31FC3857460 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 10:55:24.0843 0x05dc hkmsvc - ok 10:55:24.0863 0x05dc hpn - ok 10:55:24.0944 0x05dc [ F6AACF5BCE2893E0C1754AFEB672E5C9, 62A7A70515B5570A649DC30A3A122B1302F6839A63927C8B29EBE04ABA654892 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 10:55:24.0974 0x05dc HTTP - ok 10:55:25.0004 0x05dc [ AA268079AC119F3A596E5E27AEE4BD17, 2FD9B52A0627B3ECE618BAC855C19002CA6F5339636D11DF9F998E588027292A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 10:55:25.0014 0x05dc HTTPFilter - ok 10:55:25.0034 0x05dc i2omgmt - ok 10:55:25.0054 0x05dc i2omp - ok 10:55:25.0104 0x05dc [ 177B372AF55C4460D0968B5F1D02AA1C, 39406139B0D42C650F2C1986D85DB2260107D427963BC2C85A11D71561986DEB ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 10:55:25.0104 0x05dc i8042prt - ok 10:55:25.0264 0x05dc [ DA91F5385CFC8BA0F110F2FDE112B563, B20175A621476ADD31EA6C79278AE481B6DE99FC5F03E959BE3E93937B374557 ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 10:55:25.0374 0x05dc ialm - ok 10:55:25.0424 0x05dc [ B89CFBE8CB247B57D8C10ADAA66B462B, 458B56BBBD3CD478E04390ED5FFD08CA4F3709B37851E64CD9EACB2F749DFBF4 ] ikfileflt C:\WINDOWS\system32\umpusbxp.dll 10:55:25.0424 0x05dc ikfileflt - detected Backdoor.Multi.ZAccess.gen ( 0 ) 10:55:25.0554 0x05dc ikfileflt ( Backdoor.Multi.ZAccess.gen ) - infected 10:55:25.0554 0x05dc Force sending object to P2P due to detect: ikfileflt 10:55:25.0554 0x05dc Object send P2P result: false 10:55:25.0605 0x05dc [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 10:55:25.0605 0x05dc Imapi - ok 10:55:25.0645 0x05dc [ 9125AF650608A921F98A789E5C5BA864, E530C4FE52EB66549D91490B3039EF8DBC6866E4F9B55213F21E3757892B06CE ] ImapiService C:\WINDOWS\system32\imapi.exe 10:55:25.0675 0x05dc ImapiService - ok 10:55:25.0695 0x05dc ini910u - ok 10:55:25.0725 0x05dc IntelIde - ok 10:55:25.0745 0x05dc [ DA153EDC09DE8C4F846C085CAA39D1CC, 7669572FDCC2B458A8DCBA910D0260806E6DD7845221B81C509E627AB82ED7B4 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 10:55:25.0745 0x05dc intelppm - ok 10:55:25.0775 0x05dc [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 10:55:25.0775 0x05dc Ip6Fw - ok 10:55:25.0835 0x05dc [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 10:55:25.0835 0x05dc IpFilterDriver - ok 10:55:25.0865 0x05dc [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 10:55:25.0865 0x05dc IpInIp - ok 10:55:25.0925 0x05dc [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 10:55:25.0945 0x05dc IpNat - ok 10:55:25.0975 0x05dc [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 10:55:25.0975 0x05dc IPSec - ok 10:55:26.0025 0x05dc [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 10:55:26.0025 0x05dc IRENUM - ok 10:55:26.0085 0x05dc [ C8EEF2E93835B81BD335DE2123121283, DF7CCA1141CE15050D5EA516C75BF677B095EABA9E08828880E8917EBDEB2418 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 10:55:26.0085 0x05dc isapnp - ok 10:55:26.0135 0x05dc [ 2AECA45D4AEAACBDCB77AD11184E4601, 58724D00A0D6FA17CCAF69DC069EF59E535F08C870C199BF2C9269BC22273A63 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 10:55:26.0145 0x05dc Kbdclass - ok 10:55:26.0185 0x05dc [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 10:55:26.0215 0x05dc kmixer - ok 10:55:26.0266 0x05dc [ 1705745D900DABF2D89F90EBADDC7517, FE90589415BDB3BA482D3EBE1A87A7BF1429791E8F18BCB66BF8874631CC8B2C ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 10:55:26.0276 0x05dc KSecDD - ok 10:55:26.0346 0x05dc [ 427F50A24AA35597A9A5E8FBF029590F, 561060473E4AB11A1450CCC1C6B7A1D9C8284E4935C165EA2FFD9571D462F70C ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 10:55:26.0356 0x05dc LanmanServer - ok 10:55:26.0406 0x05dc [ 92C7C0C7F4248F1B9F6872BAB9053523, B81EF5B5884818811EACA1469C49483E1670157A26275D431438288490CE5B99 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 10:55:26.0416 0x05dc lanmanworkstation - ok 10:55:26.0436 0x05dc lbrtfdc - ok 10:55:26.0476 0x05dc [ 437AA83D68F9FAC234CA68DBD40DB705, 49B4A9E30778FB6D08AA7F9D66AF173572B86F74863477FFE7A66BBF2E6BCE93 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 10:55:26.0476 0x05dc LmHosts - ok 10:55:26.0636 0x05dc [ 3820B6308175C3A90F113F00DF320A83, AFCC71BA1736859891FFC044121C67E42748011F6422679CB0510365F4B0A8E2 ] Mobile Broadband HL Service C:\Documents and Settings\All Users\Dane aplikacji\MobileBrServ\mbbservice.exe 10:55:26.0656 0x05dc Mobile Broadband HL Service - ok 10:55:26.0706 0x05dc [ 4A068DB7DC37D5AFEDB6512D2931D7B3, 491F58509188054EE35962B66A13F0029BDF66CC59ED3B5E4058393146CE001C ] Modem C:\WINDOWS\system32\drivers\Modem.sys 10:55:26.0706 0x05dc Modem - ok 10:55:26.0736 0x05dc [ FBED3DF6B884F8CF00447B73507F2C48, 2CAA78DF3DB8BB19C10FD046B6EDC34167D8CA67EF137912703FE751D70803A2 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 10:55:26.0736 0x05dc Mouclass - ok 10:55:26.0786 0x05dc [ ECEC1E6CD558AB80F944F31326E9D3B5, E61B7124FDFE36D7C9081ABA7745F87F83592CE683AB49F7C31359D393B2E691 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 10:55:26.0786 0x05dc mouhid - ok 10:55:26.0826 0x05dc [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 10:55:26.0836 0x05dc MountMgr - ok 10:55:26.0846 0x05dc mraid35x - ok 10:55:26.0886 0x05dc [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 10:55:26.0916 0x05dc MRxDAV - ok 10:55:26.0977 0x05dc [ 68755F0FF16070178B54674FE5B847B0, 2FFBCE3A67FA7E30E373624521C602E5510C5565F04381C6C9F961253DA928A6 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 10:55:27.0017 0x05dc MRxSmb - ok 10:55:27.0067 0x05dc [ C61CAC560CE5351FB74A3B1BC00A3932, 3F2111FEF2702CE49DEA66F307617942913CB1E43D3EAAF830BED69567D176BD ] MSDTC C:\WINDOWS\system32\msdtc.exe 10:55:27.0077 0x05dc MSDTC - ok 10:55:27.0117 0x05dc [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 10:55:27.0117 0x05dc Msfs - ok 10:55:27.0137 0x05dc MSIServer - ok 10:55:27.0197 0x05dc [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 10:55:27.0197 0x05dc MSKSSRV - ok 10:55:27.0207 0x05dc [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 10:55:27.0207 0x05dc MSPCLOCK - ok 10:55:27.0227 0x05dc [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 10:55:27.0227 0x05dc MSPQM - ok 10:55:27.0277 0x05dc [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 10:55:27.0277 0x05dc mssmbios - ok 10:55:27.0307 0x05dc [ 2F625D11385B1A94360BFC70AAEFDEE1, 23E4974120233CF1A7BEE48977706A0A55418699379D1450502ABEB24191AC80 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 10:55:27.0317 0x05dc Mup - ok 10:55:27.0387 0x05dc [ 14CB8528E17D1221C50FC8CA88B1795F, E908EAE9A0E606084926941B1802E9F48AE1AC4AE6C6136345DD5699B8B9B526 ] napagent C:\WINDOWS\System32\qagentrt.dll 10:55:27.0427 0x05dc napagent - ok 10:55:27.0497 0x05dc [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 10:55:27.0527 0x05dc NDIS - ok 10:55:27.0547 0x05dc [ 1AB3D00C991AB086E69DB84B6C0ED78F, 1F881FCCF5557C44C078D99CA2DD38D635413D6212DBEDC06A428EDAC7F8B04E ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 10:55:27.0547 0x05dc NdisTapi - ok 10:55:27.0567 0x05dc [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 10:55:27.0567 0x05dc Ndisuio - ok 10:55:27.0597 0x05dc [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 10:55:27.0597 0x05dc NdisWan - ok 10:55:27.0617 0x05dc [ 6215023940CFD3702B46ABC304E1D45A, C767F3A349B365F6E7566C0738E2F62D8FFF8CB4457347E3614BD403BC6CADCB ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 10:55:27.0627 0x05dc NDProxy - ok 10:55:27.0668 0x05dc [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 10:55:27.0668 0x05dc NetBIOS - ok 10:55:27.0698 0x05dc [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 10:55:27.0718 0x05dc NetBT - ok 10:55:27.0798 0x05dc [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] Netlogon C:\WINDOWS\system32\lsass.exe 10:55:27.0798 0x05dc Netlogon - ok 10:55:27.0868 0x05dc [ 4FE97D0B1B182DF2A9BDD4C02155EF5E, 46F3F4FEB501E1987B49AB1595AADC06432B70E39CA6E9CC67C6410B13DA7B7A ] Netman C:\WINDOWS\System32\netman.dll 10:55:27.0888 0x05dc Netman - ok 10:55:27.0938 0x05dc [ BF80D884E1C60DED1C7CEA3EC6F9DC28, F202CC6D27A0AC107C52E5BD77F9624BC0C02ED295040FD2E7CB4B850309AE80 ] Nla C:\WINDOWS\System32\mswsock.dll 10:55:27.0968 0x05dc Nla - ok 10:55:27.0998 0x05dc [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 10:55:27.0998 0x05dc Npfs - ok 10:55:28.0078 0x05dc [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 10:55:28.0138 0x05dc Ntfs - ok 10:55:28.0168 0x05dc [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] NtLmSsp C:\WINDOWS\system32\lsass.exe 10:55:28.0168 0x05dc NtLmSsp - ok 10:55:28.0258 0x05dc [ 3FB5399DBB7001A80D58EDAD64C98225, A790DB873DAADB2B241F2C2426B51C0B73D4E13AC4D804B8EBBF5A74B4A41797 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 10:55:28.0298 0x05dc NtmsSvc - ok 10:55:28.0349 0x05dc [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys 10:55:28.0349 0x05dc Null - ok 10:55:28.0389 0x05dc [ 2D4CDAEBCED17743AA9E25D3016DC229, F5D138644F114861DD045975136904325304081221B85FB2C151CD9A411097CE ] Parport C:\WINDOWS\system32\drivers\Parport.sys 10:55:28.0389 0x05dc Parport - ok 10:55:28.0409 0x05dc [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 10:55:28.0409 0x05dc PartMgr - ok 10:55:28.0429 0x05dc [ 453EC2C2A20A1382F564541918520EEB, 797ED3127131BAE255AE793B8327D0E3BB6D054421F8D90511B315937BEBB6B0 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 10:55:28.0439 0x05dc ParVdm - ok 10:55:28.0479 0x05dc [ 6862C69168D787B85A7D95CCD33C694E, 6B7912156A0BAB6AED4F00FE37034488D10646B17435E86DE0D7DBD5951E8FB9 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 10:55:28.0489 0x05dc PCI - ok 10:55:28.0499 0x05dc PCIDump - ok 10:55:28.0529 0x05dc [ 548CF2D6369EAE441A4C6BAA75BC4F0A, C659E9E8A16DD4CBEC97FFB50784D8585E02F20FA360D2280D322D975F00A994 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 10:55:28.0529 0x05dc PCIIde - ok 10:55:28.0589 0x05dc [ 8DB27F1AE9593C94095485305A583862, 4FDB24BA306944743B50C3B0E39EFC75BD196A4DA1B0A3C859B974E8599B5128 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 10:55:28.0599 0x05dc Pcmcia - ok 10:55:28.0639 0x05dc PDCOMP - ok 10:55:28.0649 0x05dc PDFRAME - ok 10:55:28.0669 0x05dc PDRELI - ok 10:55:28.0689 0x05dc PDRFRAME - ok 10:55:28.0699 0x05dc perc2 - ok 10:55:28.0719 0x05dc perc2hib - ok 10:55:28.0799 0x05dc [ 3E3AE424E27C4CEFE4CAB368C7B570EA, 95A3B2758662D9EB803BA8D0A294881451EEA9F1033978C4C60810317A703C5C ] PlugPlay C:\WINDOWS\system32\services.exe 10:55:28.0809 0x05dc PlugPlay - ok 10:55:28.0839 0x05dc [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] PolicyAgent C:\WINDOWS\system32\lsass.exe 10:55:28.0839 0x05dc PolicyAgent - ok 10:55:28.0859 0x05dc [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 10:55:28.0869 0x05dc PptpMiniport - ok 10:55:28.0879 0x05dc [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 10:55:28.0889 0x05dc ProtectedStorage - ok 10:55:28.0939 0x05dc [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 10:55:28.0949 0x05dc Ptilink - ok 10:55:28.0999 0x05dc [ D86B4A68565E444D76457F14172C875A, 06B1CF81A62B3DAA8D0C5A8B88C56A504DE8E9278C520F754AF363A6676C58B0 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 10:55:28.0999 0x05dc PxHelp20 - ok 10:55:29.0019 0x05dc ql1080 - ok 10:55:29.0029 0x05dc Ql10wnt - ok 10:55:29.0050 0x05dc ql12160 - ok 10:55:29.0070 0x05dc ql1240 - ok 10:55:29.0080 0x05dc ql1280 - ok 10:55:29.0100 0x05dc [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 10:55:29.0100 0x05dc RasAcd - ok 10:55:29.0170 0x05dc [ BC22C5E1238D4D36D65679E249C483C3, 9B01F8D9541F3558F7D6A3E079580EC87DC748EFCA43E10682C83953B8885C3B ] RasAuto C:\WINDOWS\System32\rasauto.dll 10:55:29.0180 0x05dc RasAuto - ok 10:55:29.0220 0x05dc [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 10:55:29.0220 0x05dc Rasl2tp - ok 10:55:29.0260 0x05dc [ 0C392E397B8D34AAAF19EC6119CBB788, 843C0B52A92A7F62E0D503A62FE56A020655AD98BC287AE8669ACE93B6A02ECA ] RasMan C:\WINDOWS\System32\rasmans.dll 10:55:29.0290 0x05dc RasMan - ok 10:55:29.0320 0x05dc [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 10:55:29.0320 0x05dc RasPppoe - ok 10:55:29.0370 0x05dc [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 10:55:29.0370 0x05dc Raspti - ok 10:55:29.0420 0x05dc [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 10:55:29.0450 0x05dc Rdbss - ok 10:55:29.0460 0x05dc [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 10:55:29.0470 0x05dc RDPCDD - ok 10:55:29.0530 0x05dc [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 10:55:29.0560 0x05dc rdpdr - ok 10:55:29.0620 0x05dc [ 6728E45B66F93C08F11DE2E316FC70DD, EA63ECD4F84CAE08BD2BF843C48AF505B1B9D7B61349A63536C9C6FEBEF23452 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 10:55:29.0630 0x05dc RDPWD - ok 10:55:29.0680 0x05dc [ F83907A9A038DB2E35329B039628D293, 683D478C9EC30102BB5A4CB6D200C4772C8BF5DF7BFC757AFA0B5B44DA1F8961 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 10:55:29.0741 0x05dc RDSessMgr - ok 10:55:29.0801 0x05dc [ E0C7BBD18040B58651BAC700C804861D, 91AE8D3C7D9FB391725664996479DAFDA91CB91C31E446BFE9ECF0C4FC86BE2F ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 10:55:29.0801 0x05dc redbook - ok 10:55:29.0861 0x05dc [ B3F57E6115BCD4DBADE9874F300655E3, DFF4D6AEA1B22C531216ED5A94B01C88D2C61D0EC3BB34744B4572C672EF89E6 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 10:55:29.0861 0x05dc RemoteAccess - ok 10:55:29.0931 0x05dc [ 6BC4D5A70F46EA27DDC14E5414C862A5, D78921FF982CFF26A012A413F19331AACA4F66E53D38C626FE712B4108744E31 ] RpcLocator C:\WINDOWS\system32\locator.exe 10:55:29.0931 0x05dc RpcLocator - ok 10:55:30.0001 0x05dc [ 02396DAB9DD407B06539981F477F3FEC, 02909411C763FE75A66AD31A0C3B4492FBB00F9AF3D2BE8478A444861A086B2A ] RpcSs C:\WINDOWS\system32\rpcss.dll 10:55:30.0021 0x05dc RpcSs - ok 10:55:30.0081 0x05dc [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] SamSs C:\WINDOWS\system32\lsass.exe 10:55:30.0081 0x05dc SamSs - ok 10:55:30.0141 0x05dc [ C6F479218E94896738C06AF5BA6AB3D3, 4077BDDE1A44E2A415FF76A8BB3EAD226D7A29696C0218E81381B81E750CD0BA ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 10:55:30.0151 0x05dc SCardSvr - ok 10:55:30.0241 0x05dc [ DD73C11A5C4D14945846384B90A61A4B, C3C6BD62FB976E27C9E2C4C239D01B5458B7D270E9563A90EFBC9801B5DC55EA ] Schedule C:\WINDOWS\system32\schedsvc.dll 10:55:30.0271 0x05dc Schedule - ok 10:55:30.0301 0x05dc [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 10:55:30.0301 0x05dc Secdrv - ok 10:55:30.0321 0x05dc [ 2AAD9026648120FFFE2A8D871BB2BBC7, 8F9B35717CBE8B1C30FF15992DA8A857470A96F1A043CDA42CB89E4C6723B4A4 ] seclogon C:\WINDOWS\System32\seclogon.dll 10:55:30.0331 0x05dc seclogon - ok 10:55:30.0361 0x05dc [ 9D01E29D59723EB73B72107B208DAFE6, D334E807C6B41CF08EB64DCF8B2C8F68FA553971130FAB2E14C3EEE4D3B968F7 ] SENS C:\WINDOWS\system32\sens.dll 10:55:30.0361 0x05dc SENS - ok 10:55:30.0381 0x05dc [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] Serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 10:55:30.0391 0x05dc Serenum - ok 10:55:30.0411 0x05dc [ D07B02F88165E69B9F17162CF592C8A6, B494941FC05FC2439F54D4D999B1A65F9709BC296D5AC470C8F73ACFC5DC4729 ] Serial C:\WINDOWS\system32\drivers\Serial.sys 10:55:30.0411 0x05dc Serial - ok 10:55:30.0452 0x05dc [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 10:55:30.0452 0x05dc Sfloppy - ok 10:55:30.0522 0x05dc [ DA5C015911F68F22ED821E9EE49AB233, 53694B0E70F77C775CE936F5DB458F724F051314704B6F69E5C2728180F0DC2C ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 10:55:30.0552 0x05dc SharedAccess - ok 10:55:30.0602 0x05dc [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 10:55:30.0612 0x05dc ShellHWDetection - ok 10:55:30.0672 0x05dc [ 3EAD8E1668CE42A0AFE41D56E7157BCF, 90A1AA6372356046B28C079954458F42849779FFC48C93AF0549A7673B276EB3 ] silabenm C:\WINDOWS\system32\DRIVERS\silabenm.sys 10:55:30.0672 0x05dc silabenm - ok 10:55:30.0702 0x05dc [ B77C60B4A7848057BDCD0AA07299E8F3, B59F9C0459DADC1D5DD90541B9D4BE69855C16E3ADCD46ACFFAC622347E1F51E ] silabser C:\WINDOWS\system32\DRIVERS\silabser.sys 10:55:30.0702 0x05dc silabser - ok 10:55:30.0722 0x05dc Simbad - ok 10:55:30.0812 0x05dc [ CB66F528258A605B993DEB51FB1C71BD, 42AA8E3ED78D14B4DA8F5ACE0C0A7C07D9DF340FC98AB686B77BF5AB712635BB ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys 10:55:30.0862 0x05dc smwdm - ok 10:55:30.0992 0x05dc [ 45C0D390542C389DFE5393F174349A36, BE5F021C8C095C846E49BA45D801EB8414A7CC26C2AC4732B0C2D4F797833C40 ] SoundMAX Agent Service (default) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 10:55:30.0992 0x05dc SoundMAX Agent Service (default) - ok 10:55:31.0012 0x05dc Sparrow - ok 10:55:31.0042 0x05dc [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys 10:55:31.0042 0x05dc splitter - ok 10:55:31.0092 0x05dc [ DD69EC597AB942C39B950D9C3CE1375D, D09185C8ED73FF04945FDB0B40009E0FCC31A73E80B03D397A1436CC3A373AF5 ] Spooler C:\WINDOWS\system32\spoolsv.exe 10:55:31.0102 0x05dc Spooler - ok 10:55:31.0143 0x05dc [ EB032822BE406EF220D546DDFFCF0002, 916299B409925AB7326CB5F744799B34FD08CA4C4B447215DA5060FF446FEEBE ] Sr C:\WINDOWS\system32\DRIVERS\sr.sys 10:55:31.0163 0x05dc Sr - ok 10:55:31.0243 0x05dc [ 316D0E66074AE4CDE641C50D3A1C5148, 8429F815AFB4B39F6C1C56FB1CA009E5338C1467A4A02DD8E7E35BADBB8D5221 ] srservice C:\WINDOWS\system32\srsvc.dll 10:55:31.0253 0x05dc srservice - ok 10:55:31.0323 0x05dc [ 5252605079810904E31C332E241CD59B, 039DD965DE2137219168F95CA3BF1CA7353957026BDD0481F7964E2578DF2128 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 10:55:31.0363 0x05dc Srv - ok 10:55:31.0443 0x05dc [ 2C0B1224AA36B4CA1753302BAA855882, F8C90ECBF5BD7C3984E7C82EB00042DFD85A62F263C0205E6790205B6D64E101 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 10:55:31.0453 0x05dc SSDPSRV - ok 10:55:31.0523 0x05dc [ 41508EA375C97DC2B56E5F1AFC067187, 94D8D49AE3634E861DE501E72813C5320F059C49CC61FA01B2867C99E8B36DB4 ] stisvc C:\WINDOWS\system32\wiaservc.dll 10:55:31.0563 0x05dc stisvc - ok 10:55:31.0613 0x05dc [ 3C593D68AD0B65D6A4710A419CFE4D25, A726DCB89785ECD244F83C72170E5C8F09C4BCCA403CD0E31D42610270C9A1FF ] svclocks C:\WINDOWS\system32\drivers\svclocks.exe 10:55:31.0623 0x05dc svclocks - ok 10:55:31.0683 0x05dc [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 10:55:31.0693 0x05dc swenum - ok 10:55:31.0743 0x05dc [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 10:55:31.0743 0x05dc swmidi - ok 10:55:31.0763 0x05dc SwPrv - ok 10:55:31.0793 0x05dc symc810 - ok 10:55:31.0813 0x05dc symc8xx - ok 10:55:31.0834 0x05dc sym_hi - ok 10:55:31.0844 0x05dc sym_u3 - ok 10:55:31.0884 0x05dc [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 10:55:31.0894 0x05dc sysaudio - ok 10:55:31.0934 0x05dc [ E42048198518F9162027A9984CBB7B5C, 2634DE2B1AE9D856966F40BFB41AD951A41E11C557C4B27E61CFF63288B53D52 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 10:55:31.0954 0x05dc SysmonLog - ok 10:55:32.0014 0x05dc [ 2340E6977548038C88E39A9ECBB3FADC, B8992F5E0689B307B8CC162032B398950FB07C4B4EF997431F7B344351406586 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 10:55:32.0044 0x05dc TapiSrv - ok 10:55:32.0124 0x05dc [ E88631E21A9CACA06104802F9E915115, 930C518D6B238CF85DE610C06C025C255A684A87D064ECF0E5003E37CAC69F4D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 10:55:32.0174 0x05dc Tcpip - ok 10:55:32.0214 0x05dc [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 10:55:32.0214 0x05dc TDPIPE - ok 10:55:32.0254 0x05dc [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 10:55:32.0254 0x05dc TDTCP - ok 10:55:32.0314 0x05dc [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 10:55:32.0314 0x05dc TermDD - ok 10:55:32.0404 0x05dc [ 52E0505408EDD4AB5CCC7F83B67B4299, 93DBA3282025C81DC43D4B43861A6CB30C9557CD0108D4D7E0C3B1269699CF22 ] TermService C:\WINDOWS\System32\termsrv.dll 10:55:32.0434 0x05dc TermService - ok 10:55:32.0484 0x05dc [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] Themes C:\WINDOWS\System32\shsvcs.dll 10:55:32.0494 0x05dc Themes - ok 10:55:32.0514 0x05dc TosIde - ok 10:55:32.0555 0x05dc [ 9E70EB419D7785C286DC458A019BAB9B, 3901C6B9C9C197FED9C1039F2EBE0C5ACE240512ABBFECB388CAD201CE032760 ] TrkWks C:\WINDOWS\system32\trkwks.dll 10:55:32.0575 0x05dc TrkWks - ok 10:55:32.0615 0x05dc [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 10:55:32.0615 0x05dc Udfs - ok 10:55:32.0635 0x05dc ultra - ok 10:55:32.0715 0x05dc [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 10:55:32.0755 0x05dc Update - ok 10:55:32.0825 0x05dc [ E96A6BAEE0B2A14A38B45830D6E30697, 12314B1D96E025718F965C091E3CAD2865EDDAACA2E60A1A0DAF25630AE66B72 ] upnphost C:\WINDOWS\System32\upnphost.dll 10:55:32.0875 0x05dc upnphost - ok 10:55:32.0915 0x05dc [ EB90E28B28541EC845E5345609355CA7, 60C8DF04EB5839AB1B8625C385F4B2089C63FE613463026F779B331D9BC4D4D6 ] UPS C:\WINDOWS\System32\ups.exe 10:55:32.0915 0x05dc UPS - ok 10:55:32.0965 0x05dc [ C18D6C74953621346DF6B0A11F80C1CC, 4C1B3E8F3F658E356A955108FF84FB5C95244CB2A9D323AA0DFAEF92927C66C5 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 10:55:32.0965 0x05dc usbccgp - ok 10:55:32.0995 0x05dc [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 10:55:32.0995 0x05dc usbehci - ok 10:55:33.0025 0x05dc [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 10:55:33.0025 0x05dc usbhub - ok 10:55:33.0105 0x05dc [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 10:55:33.0105 0x05dc USBSTOR - ok 10:55:33.0155 0x05dc [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 10:55:33.0155 0x05dc usbuhci - ok 10:55:33.0205 0x05dc [ B6CC50279D6CD28E090A5D33244ADC9A, 1A861FBC6215A281EB66A0B63F39913EB2F5F39A70306943C4D4BE404B59E0F0 ] usb_rndisx C:\WINDOWS\system32\DRIVERS\usb8023x.sys 10:55:33.0205 0x05dc usb_rndisx - ok 10:55:33.0266 0x05dc [ BFA4AE30B3AC10E9223830BF103F5A3F, B576A00FF42574B7247FF9D92FF12B2AE7D525769F964C0E0411799982A2BD11 ] vcdrom C:\Program Files\System\CPL Bonus\Vcdrom.sys 10:55:33.0266 0x05dc vcdrom - ok 10:55:33.0316 0x05dc [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 10:55:33.0326 0x05dc VgaSave - ok 10:55:33.0336 0x05dc ViaIde - ok 10:55:33.0356 0x05dc [ 56B191AC5FC0DF219949C95A6C87AFE7, 5DCD42BD686869B394CFB9EFD727DCEEEAE239326DDE3D1655C456FCAE949D9F ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 10:55:33.0366 0x05dc VolSnap - ok 10:55:33.0406 0x05dc [ 7F2D7BFFC4554E1C742DD3629FD1FB1B, 4BFFC8A67F98AF69039DF0AFF1FDA11CFAD6464066E8ED92090D48392C43B6ED ] VSS C:\WINDOWS\System32\vssvc.exe 10:55:33.0436 0x05dc VSS - ok 10:55:33.0476 0x05dc [ A672CA3981352F8E9C30FEA056E80A62, 9AD34EFEB11EFEB234A246639FADF036F49FC67E542C4DE78D7C01E75BC62B59 ] W32Time C:\WINDOWS\system32\w32time.dll 10:55:33.0506 0x05dc W32Time - ok 10:55:33.0526 0x05dc [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 10:55:33.0536 0x05dc Wanarp - ok 10:55:33.0616 0x05dc [ D918617B46457B9AC28027722E30F647, 407284D3055DC11944D4EE7E4357E7CF9CAF8CA40CA50633AB6FD4A82CB7EEA6 ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys 10:55:33.0656 0x05dc Wdf01000 - ok 10:55:33.0676 0x05dc WDICA - ok 10:55:33.0726 0x05dc [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 10:55:33.0736 0x05dc wdmaud - ok 10:55:33.0776 0x05dc [ 81FB88B975E25D76E00B69879D8A434C, 2340CEE200CA3F0A546F88AAD3AFDCFD0805DB027E8480B4280D92E14F6C1F69 ] WebClient C:\WINDOWS\System32\webclnt.dll 10:55:33.0796 0x05dc WebClient - ok 10:55:33.0987 0x05dc [ 70C22297534A88B0AD0568900AB5A6D9, 2457D9B21CD8633D6A59FC053B70B9282A64066789EC020A9F2C937141E95C61 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 10:55:33.0997 0x05dc winmgmt - ok 10:55:34.0067 0x05dc [ C51B4A5C05A5475708E3C81C7765B71D, F776D2680BD3407307B7072626F78460361FC5BC38623C9E16F394D300AB25DE ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 10:55:34.0077 0x05dc WmdmPmSN - ok 10:55:34.0157 0x05dc [ 968C967F8A9B96E7D63FDD5664C896E7, 0DEF56F110C2C2ED633B4CC1295E70224D9D7F62FAD7921EFF16B99D5AC654F4 ] Wmi C:\WINDOWS\System32\advapi32.dll 10:55:34.0237 0x05dc Wmi - ok 10:55:34.0327 0x05dc [ A2B12D80A1670511B047A7D8BB647598, BDE141A77034608D926624583D252650D01B64EC2B3E8156A61D735C79E2A0E6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 10:55:34.0337 0x05dc WmiApSrv - ok 10:55:34.0467 0x05dc [ CDFA647AA82FDBA6C9C7A06155AFCB40, 4ACF2E90E4A933A5C662AFECFFB52997BED865953E452C80A772DF1B049060FD ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 10:55:34.0547 0x05dc WMPNetworkSvc - ok 10:55:34.0628 0x05dc [ 727F02F3B19BAB3639E9358FFDD295E0, 6BA9EF4794E45D46CE7F1E4571A5F15C6B5663659BBAFAB8B114DD9BA9273BE0 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 10:55:34.0638 0x05dc wuauserv - ok 10:55:34.0738 0x05dc [ C2842273AAA77AC031EDB87FA19A2147, 8542392E337C543BCD9EDC7A15DC6E8DE8E9B8041CC7A8D707217C9FF0446882 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 10:55:34.0778 0x05dc WZCSVC - ok 10:55:34.0818 0x05dc [ 24ED6935771359A5AEF1FE8BF0C56F39, F0C3B781853714F48DE4F42533A7236CE11076208F190E79500F8A77C9CF9849 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 10:55:34.0848 0x05dc xmlprov - ok 10:55:34.0878 0x05dc ================ Scan global =============================== 10:55:34.0908 0x05dc [ 65C782F8CFC1BEBCC58E1532F44B6408, D5EB7357F37AC9CEF96BC1BCACE765B2897E502D699E64145EFA4DD62BCCE80B ] C:\WINDOWS\system32\basesrv.dll 10:55:34.0988 0x05dc [ 3DA6293977416933EC37C5B7D9C77188, 9B7ECC4B3376DDDD8B57F91767482C59A47336DE527FAE85B49AE1F96BC67FC9 ] C:\WINDOWS\system32\winsrv.dll 10:55:35.0058 0x05dc [ 3DA6293977416933EC37C5B7D9C77188, 9B7ECC4B3376DDDD8B57F91767482C59A47336DE527FAE85B49AE1F96BC67FC9 ] C:\WINDOWS\system32\winsrv.dll 10:55:35.0098 0x05dc [ 3E3AE424E27C4CEFE4CAB368C7B570EA, 95A3B2758662D9EB803BA8D0A294881451EEA9F1033978C4C60810317A703C5C ] C:\WINDOWS\system32\services.exe 10:55:35.0108 0x05dc [ Global ] - ok 10:55:35.0108 0x05dc ================ Scan MBR ================================== 10:55:35.0138 0x05dc [ 32052574BF9F325AE309ABC7BFD04460 ] \Device\Harddisk0\DR0 10:55:35.0409 0x05dc \Device\Harddisk0\DR0 - ok 10:55:35.0419 0x05dc ================ Scan VBR ================================== 10:55:35.0429 0x05dc [ 0F5C8334D212EF9B14CE8737AB679153 ] \Device\Harddisk0\DR0\Partition1 10:55:35.0429 0x05dc \Device\Harddisk0\DR0\Partition1 - ok 10:55:35.0439 0x05dc [ 178E5B7C31F30F765EECC32D30E1A407 ] \Device\Harddisk0\DR0\Partition2 10:55:35.0439 0x05dc \Device\Harddisk0\DR0\Partition2 - ok 10:55:35.0439 0x05dc ================ Scan generic autorun ====================== 10:55:35.0499 0x05dc [ FA680935110ECE1BF93E9AADEBDC865B, 33F36D626BF480DA885FC462FAD73FA359FE80D6BFF1F50EF2AFB16292D2CAED ] C:\WINDOWS\system32\igfxtray.exe 10:55:35.0499 0x05dc igfxtray - ok 10:55:35.0519 0x05dc [ FBC32DBF9E460E9CAA516BBABB730925, D0C4B1FD3BC06CFBEBF7A7C27F73F1D8F6860D5FBF76F28C7E77F41A2D913294 ] C:\WINDOWS\system32\hkcmd.exe 10:55:35.0519 0x05dc igfxhkcmd - ok 10:55:35.0569 0x05dc [ F302148C7BD644206181E208E7C31447, A0EE23F32FFF75E69D91BD33633491987EA8AD1ECFA7C1FE9D971A620242F8EC ] C:\WINDOWS\system32\igfxpers.exe 10:55:35.0569 0x05dc igfxpers - ok 10:55:35.0649 0x05dc [ F66637592E2EFECD777E8A83F56F43BF, 4A23BB884A8DDB5BB7C8205280622F8003CB5E11AB3C22B5D465B25ECE01E0BC ] C:\Program Files\Drive Space Indicator\DrvSpace.exe 10:55:35.0679 0x05dc DriveSpace - ok 10:55:35.0729 0x05dc [ DD3030410B3310DD5085444B5A27AD4B, 2B0491CF97FB294A3F4A63D017F69C630C4E53844A17710E148A34B5611F7DF6 ] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe 10:55:35.0729 0x05dc PmProxy - ok 10:55:35.0789 0x05dc [ FF1FEF8D3CCB479D1476AD9357505314, 89E99CA0C3287054289E9B4CF5F64A1C0AE2C5835AC513CEA58DF846E1539636 ] C:\Program Files\ltmoh\Ltmoh.exe 10:55:35.0799 0x05dc LtMoh - ok 10:55:35.0849 0x05dc [ 5EC78CA9B6DEB482211C39EAF32F4C8D, 4635D2322044AB05411D54C517D92413FA59E86A567F15F4E9E7CF30AE1A23C4 ] C:\WINDOWS\AGRSMMSG.exe 10:55:35.0849 0x05dc AGRSMMSG - ok 10:55:35.0899 0x05dc [ 1EC2489A3AE8C6CAF407547F8183061B, 86C2B40197BC1FEB2FD2F4478597A612A3CCB67AD7B143BC4E4FBB92CC8634AE ] C:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe 10:55:35.0899 0x05dc VisualTaskTips - ok 10:55:35.0919 0x05dc nltide_3 - ok 10:55:35.0939 0x05dc [ 1EC2489A3AE8C6CAF407547F8183061B, 86C2B40197BC1FEB2FD2F4478597A612A3CCB67AD7B143BC4E4FBB92CC8634AE ] C:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe 10:55:35.0949 0x05dc VisualTaskTips - ok 10:55:35.0959 0x05dc nltide_3 - ok 10:55:35.0989 0x05dc [ 1EC2489A3AE8C6CAF407547F8183061B, 86C2B40197BC1FEB2FD2F4478597A612A3CCB67AD7B143BC4E4FBB92CC8634AE ] C:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe 10:55:35.0989 0x05dc VisualTaskTips - ok 10:55:36.0040 0x05dc [ FA1D6F0AE5F51A4BA81A95F6A390CEE8, C810919D0B596A13C4607306E8650781F3B9FF5EE7F44EB6DF40C788D503B99D ] C:\win32date\5B4BC3FE452.exe 10:55:36.0040 0x05dc 5V4VWDZYZA1VZXWBFRQBHQMXOAA - ok 10:55:36.0080 0x05dc Win FW state via NFM: enabled 10:55:36.0080 0x05dc ============================================================ 10:55:36.0080 0x05dc Scan finished 10:55:36.0080 0x05dc ============================================================ 10:55:36.0110 0x0130 Detected object count: 2 10:55:36.0110 0x0130 Actual detected object count: 2 10:56:44.0208 0x0130 C:\WINDOWS\System32\drivers\afd.sys - copied to quarantine 10:56:44.0678 0x0130 C:\WINDOWS\system32\c_31930.nls - copied to quarantine 10:56:45.0109 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\@ - copied to quarantine 10:56:45.0149 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\L\wqwpkime - copied to quarantine 10:56:45.0149 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\loader.tlb - copied to quarantine 10:56:45.0169 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@00000001 - copied to quarantine 10:56:45.0179 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@000000c0 - copied to quarantine 10:56:45.0179 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@000000cb - copied to quarantine 10:56:45.0189 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@000000cf - copied to quarantine 10:56:45.0219 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@80000000 - copied to quarantine 10:56:45.0249 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@800000c0 - copied to quarantine 10:56:45.0269 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@800000cb - copied to quarantine 10:56:45.0289 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@800000cf - copied to quarantine 10:56:45.0379 0x0130 C:\WINDOWS\assembly\GAC_MSIL\desktop.ini - copied to quarantine 10:56:45.0379 0x0130 C:\WINDOWS\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - copied to quarantine 10:56:45.0379 0x0130 C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - copied to quarantine 10:56:46.0561 0x0130 Backup copy found, using it.. 10:56:46.0982 0x0130 C:\WINDOWS\System32\drivers\afd.sys - will be cured on reboot 10:56:46.0992 0x0130 C:\WINDOWS\system32\c_31930.nls - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\@ - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\loader.tlb - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@00000001 - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@000000c0 - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@000000cb - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@000000cf - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@80000000 - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@800000c0 - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@800000cb - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1311981148\U\@800000cf - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\$NtUninstallKB36752$\1482286989 - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\assembly\GAC_MSIL\desktop.ini - will be deleted on reboot 10:56:47.0022 0x0130 C:\WINDOWS\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - will be deleted on reboot 10:56:47.0022 0x0130 C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - will be deleted on reboot 10:56:47.0022 0x0130 AFD ( Virus.Win32.ZAccess.c ) - User select action: Cure 10:56:47.0072 0x0130 C:\WINDOWS\system32\umpusbxp.dll - copied to quarantine 10:56:47.0072 0x0130 HKLM\SYSTEM\ControlSet001\services\ikfileflt - will be deleted on reboot 10:56:47.0092 0x0130 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - will be cured on reboot 10:56:47.0102 0x0130 C:\WINDOWS\system32\umpusbxp.dll - will be deleted on reboot 10:56:47.0102 0x0130 ikfileflt ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete 10:56:48.0163 0x0130 KLMD registered as C:\WINDOWS\system32\drivers\75681431.sys 10:56:54.0262 0x0578 Deinitialize success