01:50:28.0968 2644 TDSS rootkit removing tool 2.7.17.0 Feb 29 2012 14:02:24 01:50:29.0109 2644 ============================================================ 01:50:29.0109 2644 Current date / time: 2012/03/02 01:50:29.0109 01:50:29.0109 2644 SystemInfo: 01:50:29.0109 2644 01:50:29.0109 2644 OS Version: 5.1.2600 ServicePack: 3.0 01:50:29.0109 2644 Product type: Workstation 01:50:29.0109 2644 ComputerName: 4-738229A91A604 01:50:29.0109 2644 UserName: 4 01:50:29.0109 2644 Windows directory: C:\WINDOWS 01:50:29.0109 2644 System windows directory: C:\WINDOWS 01:50:29.0109 2644 Processor architecture: Intel x86 01:50:29.0109 2644 Number of processors: 2 01:50:29.0109 2644 Page size: 0x1000 01:50:29.0109 2644 Boot type: Normal boot 01:50:29.0109 2644 ============================================================ 01:50:30.0375 2644 Drive \Device\Harddisk0\DR0 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058 01:50:30.0390 2644 \Device\Harddisk0\DR0: 01:50:30.0390 2644 MBR used 01:50:30.0390 2644 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x5D2A642 01:50:30.0406 2644 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x5D2A6C0, BlocksNum 0x198AA973 01:50:30.0500 2644 Initialize success 01:50:30.0500 2644 ============================================================ 01:50:34.0718 2812 ============================================================ 01:50:34.0718 2812 Scan started 01:50:34.0718 2812 Mode: Manual; 01:50:34.0718 2812 ============================================================ 01:50:35.0531 2812 Aavmker4 (fdba5bb4c8171cda00b2233d5389ee5f) C:\WINDOWS\system32\drivers\Aavmker4.sys 01:50:35.0531 2812 Aavmker4 - ok 01:50:35.0546 2812 Abiosdsk - ok 01:50:35.0546 2812 abp480n5 - ok 01:50:35.0578 2812 ACPI (d31241e64dba17d1642739993e14d2f3) C:\WINDOWS\system32\DRIVERS\ACPI.sys 01:50:35.0578 2812 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ACPI.sys. Real md5: d31241e64dba17d1642739993e14d2f3, Fake md5: 05118282f5d039595a2b92b4a4afe197 01:50:35.0578 2812 ACPI ( Virus.Win32.Rloader.a ) - infected 01:50:35.0578 2812 ACPI - detected Virus.Win32.Rloader.a (0) 01:50:35.0593 2812 ACPIEC (66a42b7db194e24b973bbcce840a0f3f) C:\WINDOWS\system32\drivers\ACPIEC.sys 01:50:35.0593 2812 ACPIEC - ok 01:50:35.0609 2812 adpu160m - ok 01:50:35.0640 2812 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 01:50:35.0640 2812 aec - ok 01:50:35.0656 2812 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 01:50:35.0656 2812 AFD - ok 01:50:35.0671 2812 Aha154x - ok 01:50:35.0687 2812 aic78u2 - ok 01:50:35.0703 2812 aic78xx - ok 01:50:35.0718 2812 AliIde - ok 01:50:35.0781 2812 Ambfilt (267fc636801edc5ab28e14036349e3be) C:\WINDOWS\system32\drivers\Ambfilt.sys 01:50:35.0812 2812 Ambfilt - ok 01:50:35.0828 2812 AmdK8 (b3f7f3d37713293663ce4eaa0f1e4cee) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 01:50:35.0828 2812 AmdK8 - ok 01:50:35.0843 2812 Amfilter (868ae6fa93c29c8a105539f3e6d5a77f) C:\WINDOWS\system32\DRIVERS\Amfilter.sys 01:50:35.0843 2812 Amfilter - ok 01:50:35.0859 2812 amsint - ok 01:50:35.0875 2812 Amusbprt (37646d4559ad45c96225521b44c45d01) C:\WINDOWS\system32\DRIVERS\Amusbprt.sys 01:50:35.0875 2812 Amusbprt - ok 01:50:35.0875 2812 asc - ok 01:50:35.0890 2812 asc3350p - ok 01:50:35.0906 2812 asc3550 - ok 01:50:35.0937 2812 aswFsBlk (581b82df5dbcc1dda6b775fac0d92472) C:\WINDOWS\system32\drivers\aswFsBlk.sys 01:50:35.0937 2812 aswFsBlk - ok 01:50:35.0953 2812 aswMon2 (4310e0977b48ec9bc5cca6931f806e6d) C:\WINDOWS\system32\drivers\aswMon2.sys 01:50:35.0953 2812 aswMon2 - ok 01:50:35.0968 2812 aswRdr (0b44ee90b3db93582b260a80b28b7ffd) C:\WINDOWS\system32\drivers\aswRdr.sys 01:50:35.0984 2812 aswRdr - ok 01:50:36.0000 2812 aswSnx (ca9601cd277a1e510b80422a40240a95) C:\WINDOWS\system32\drivers\aswSnx.sys 01:50:36.0015 2812 aswSnx - ok 01:50:36.0031 2812 aswSP (05ea22dde5ca7ee3a865046aff2f0229) C:\WINDOWS\system32\drivers\aswSP.sys 01:50:36.0031 2812 aswSP - ok 01:50:36.0046 2812 aswTdi (3ac73a9e7378848d1bde174b4bb39212) C:\WINDOWS\system32\drivers\aswTdi.sys 01:50:36.0046 2812 aswTdi - ok 01:50:36.0062 2812 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 01:50:36.0062 2812 AsyncMac - ok 01:50:36.0078 2812 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 01:50:36.0078 2812 atapi - ok 01:50:36.0093 2812 Atdisk - ok 01:50:36.0125 2812 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 01:50:36.0125 2812 Atmarpc - ok 01:50:36.0156 2812 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 01:50:36.0156 2812 audstub - ok 01:50:36.0171 2812 avgntflt - ok 01:50:36.0187 2812 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 01:50:36.0203 2812 Beep - ok 01:50:36.0234 2812 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 01:50:36.0234 2812 cbidf2k - ok 01:50:36.0265 2812 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 01:50:36.0265 2812 CCDECODE - ok 01:50:36.0265 2812 cd20xrnt - ok 01:50:36.0296 2812 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 01:50:36.0296 2812 Cdaudio - ok 01:50:36.0312 2812 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 01:50:36.0312 2812 Cdfs - ok 01:50:36.0328 2812 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 01:50:36.0328 2812 Cdrom - ok 01:50:36.0328 2812 Changer - ok 01:50:36.0359 2812 CmdIde - ok 01:50:36.0375 2812 Cpqarray - ok 01:50:36.0437 2812 cpuz134 - ok 01:50:36.0453 2812 dac2w2k - ok 01:50:36.0453 2812 dac960nt - ok 01:50:36.0484 2812 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 01:50:36.0484 2812 Disk - ok 01:50:36.0531 2812 dmboot (bc9219abc5696942e6f9ac8a9b28670f) C:\WINDOWS\system32\drivers\dmboot.sys 01:50:36.0546 2812 dmboot - ok 01:50:36.0546 2812 dmio (5fa232e3ba6e1346f9f5a7e519320cb0) C:\WINDOWS\system32\drivers\dmio.sys 01:50:36.0562 2812 dmio - ok 01:50:36.0578 2812 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 01:50:36.0593 2812 dmload - ok 01:50:36.0609 2812 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 01:50:36.0609 2812 DMusic - ok 01:50:36.0625 2812 dpti2o - ok 01:50:36.0703 2812 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 01:50:36.0703 2812 drmkaud - ok 01:50:36.0734 2812 dtsoftbus01 (fb38473835476a6fb272215a1d972af9) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys 01:50:36.0734 2812 dtsoftbus01 - ok 01:50:36.0750 2812 dwshd - ok 01:50:36.0765 2812 EagleNT - ok 01:50:36.0765 2812 EagleXNt - ok 01:50:36.0796 2812 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 01:50:36.0812 2812 Fastfat - ok 01:50:36.0828 2812 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 01:50:36.0828 2812 Fdc - ok 01:50:36.0843 2812 Fips (09e2a4d33f81a06a8aab2ba0a0b5d235) C:\WINDOWS\system32\drivers\Fips.sys 01:50:36.0843 2812 Fips - ok 01:50:36.0859 2812 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 01:50:36.0859 2812 Flpydisk - ok 01:50:36.0890 2812 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 01:50:36.0890 2812 FltMgr - ok 01:50:36.0906 2812 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 01:50:36.0906 2812 Fs_Rec - ok 01:50:36.0937 2812 Ftdisk (ed6d921d8ab423138fb35beee6d6a6cb) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 01:50:36.0937 2812 Ftdisk - ok 01:50:36.0953 2812 GearAspiWDM - ok 01:50:36.0968 2812 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 01:50:36.0968 2812 Gpc - ok 01:50:37.0000 2812 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 01:50:37.0000 2812 HDAudBus - ok 01:50:37.0015 2812 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 01:50:37.0015 2812 HidUsb - ok 01:50:37.0078 2812 hpn - ok 01:50:37.0140 2812 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 01:50:37.0140 2812 HTTP - ok 01:50:37.0156 2812 i2omgmt - ok 01:50:37.0156 2812 i2omp - ok 01:50:37.0187 2812 i8042prt (177b372af55c4460d0968b5f1d02aa1c) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 01:50:37.0187 2812 i8042prt - ok 01:50:37.0218 2812 imagedrv (25edd75e23c5ef6b33d0fbcce125a601) C:\WINDOWS\system32\Drivers\imagedrv.sys 01:50:37.0218 2812 imagedrv - ok 01:50:37.0234 2812 imagesrv (9c4bbacf4e9b9543c3ce23f1fe556941) C:\WINDOWS\system32\DRIVERS\imagesrv.sys 01:50:37.0234 2812 imagesrv - ok 01:50:37.0250 2812 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 01:50:37.0250 2812 Imapi - ok 01:50:37.0265 2812 ini910u - ok 01:50:37.0390 2812 IntcAzAudAddService (db01625d8e286cd17b94dcf088713d7f) C:\WINDOWS\system32\drivers\RtkHDAud.sys 01:50:37.0421 2812 IntcAzAudAddService - ok 01:50:37.0437 2812 IntelIde - ok 01:50:37.0468 2812 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 01:50:37.0468 2812 Ip6Fw - ok 01:50:37.0500 2812 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 01:50:37.0500 2812 IpFilterDriver - ok 01:50:37.0515 2812 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 01:50:37.0515 2812 IpInIp - ok 01:50:37.0546 2812 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 01:50:37.0546 2812 IpNat - ok 01:50:37.0562 2812 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 01:50:37.0562 2812 IPSec - ok 01:50:37.0578 2812 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 01:50:37.0578 2812 IRENUM - ok 01:50:37.0609 2812 isapnp (c8eef2e93835b81bd335de2123121283) C:\WINDOWS\system32\DRIVERS\isapnp.sys 01:50:37.0609 2812 isapnp - ok 01:50:37.0625 2812 Kbdclass (2aeca45d4aeaacbdcb77ad11184e4601) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 01:50:37.0625 2812 Kbdclass - ok 01:50:37.0656 2812 kbdhid (f718dcddac2544bc693f22977d06f78b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 01:50:37.0656 2812 kbdhid - ok 01:50:37.0671 2812 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 01:50:37.0687 2812 kmixer - ok 01:50:37.0718 2812 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 01:50:37.0718 2812 KSecDD - ok 01:50:37.0734 2812 lbrtfdc - ok 01:50:37.0750 2812 LgBttPort - ok 01:50:37.0750 2812 lgbusenum - ok 01:50:37.0765 2812 LGVMODEM - ok 01:50:37.0796 2812 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys 01:50:37.0796 2812 MBAMProtector - ok 01:50:37.0828 2812 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 01:50:37.0828 2812 mnmdd - ok 01:50:37.0843 2812 Modem (4a068db7dc37d5afedb6512d2931d7b3) C:\WINDOWS\system32\drivers\Modem.sys 01:50:37.0843 2812 Modem - ok 01:50:37.0890 2812 Monfilt (c7d9f9717916b34c1b00dd4834af485c) C:\WINDOWS\system32\drivers\Monfilt.sys 01:50:37.0921 2812 Monfilt - ok 01:50:37.0937 2812 motccgp - ok 01:50:37.0937 2812 motccgpfl - ok 01:50:37.0953 2812 motmodem - ok 01:50:37.0968 2812 MotoSwitchService - ok 01:50:37.0984 2812 Mouclass (fbed3df6b884f8cf00447b73507f2c48) C:\WINDOWS\system32\DRIVERS\mouclass.sys 01:50:37.0984 2812 Mouclass - ok 01:50:38.0000 2812 mouhid (ecec1e6cd558ab80f944f31326e9d3b5) C:\WINDOWS\system32\DRIVERS\mouhid.sys 01:50:38.0000 2812 mouhid - ok 01:50:38.0015 2812 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 01:50:38.0015 2812 MountMgr - ok 01:50:38.0031 2812 mraid35x - ok 01:50:38.0046 2812 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 01:50:38.0046 2812 MRxDAV - ok 01:50:38.0093 2812 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 01:50:38.0093 2812 MRxSmb - ok 01:50:38.0109 2812 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 01:50:38.0109 2812 Msfs - ok 01:50:38.0125 2812 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 01:50:38.0140 2812 MSKSSRV - ok 01:50:38.0140 2812 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 01:50:38.0140 2812 MSPCLOCK - ok 01:50:38.0156 2812 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 01:50:38.0156 2812 MSPQM - ok 01:50:38.0187 2812 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 01:50:38.0187 2812 mssmbios - ok 01:50:38.0203 2812 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 01:50:38.0203 2812 MSTEE - ok 01:50:38.0234 2812 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 01:50:38.0234 2812 Mup - ok 01:50:38.0265 2812 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 01:50:38.0265 2812 NABTSFEC - ok 01:50:38.0281 2812 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 01:50:38.0281 2812 NDIS - ok 01:50:38.0312 2812 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 01:50:38.0312 2812 NdisIP - ok 01:50:38.0343 2812 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 01:50:38.0343 2812 NdisTapi - ok 01:50:38.0359 2812 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 01:50:38.0375 2812 Ndisuio - ok 01:50:38.0390 2812 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 01:50:38.0390 2812 NdisWan - ok 01:50:38.0437 2812 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 01:50:38.0437 2812 NDProxy - ok 01:50:38.0453 2812 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 01:50:38.0453 2812 NetBIOS - ok 01:50:38.0484 2812 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 01:50:38.0484 2812 NetBT - ok 01:50:38.0531 2812 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys 01:50:38.0531 2812 NPF - ok 01:50:38.0546 2812 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 01:50:38.0546 2812 Npfs - ok 01:50:38.0562 2812 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 01:50:38.0578 2812 Ntfs - ok 01:50:38.0593 2812 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 01:50:38.0609 2812 Null - ok 01:50:38.0718 2812 nv (61bf339927f7a02c395f89fd8ad7ccfb) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 01:50:38.0828 2812 nv - ok 01:50:38.0859 2812 nvata (947c4a0e7b25bcecc3b40f0f1070378b) C:\WINDOWS\system32\DRIVERS\nvata.sys 01:50:38.0875 2812 nvata - ok 01:50:38.0875 2812 NVENETFD (c61927d27b75ed56723f2508f1a6b1be) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 01:50:38.0890 2812 NVENETFD - ok 01:50:38.0906 2812 nvgts (52dce3b30c9d61c8e20fe3c6da4bdfb7) C:\WINDOWS\system32\DRIVERS\nvgts.sys 01:50:38.0921 2812 nvgts - ok 01:50:38.0921 2812 nvnetbus (c529b614ef88be0f62b886c67b516550) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 01:50:38.0937 2812 nvnetbus - ok 01:50:38.0953 2812 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 01:50:38.0953 2812 NwlnkFlt - ok 01:50:38.0984 2812 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 01:50:38.0984 2812 NwlnkFwd - ok 01:50:39.0000 2812 Parport (2d4cdaebced17743aa9e25d3016dc229) C:\WINDOWS\system32\DRIVERS\parport.sys 01:50:39.0015 2812 Parport - ok 01:50:39.0031 2812 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 01:50:39.0031 2812 PartMgr - ok 01:50:39.0062 2812 ParVdm (453ec2c2a20a1382f564541918520eeb) C:\WINDOWS\system32\drivers\ParVdm.sys 01:50:39.0062 2812 ParVdm - ok 01:50:39.0062 2812 pavboot - ok 01:50:39.0078 2812 pccsmcfd - ok 01:50:39.0109 2812 PCI (6862c69168d787b85a7d95ccd33c694e) C:\WINDOWS\system32\DRIVERS\pci.sys 01:50:39.0109 2812 PCI - ok 01:50:39.0109 2812 PCIDump - ok 01:50:39.0140 2812 PCIIde (548cf2d6369eae441a4c6baa75bc4f0a) C:\WINDOWS\system32\DRIVERS\pciide.sys 01:50:39.0140 2812 PCIIde - ok 01:50:39.0171 2812 Pcmcia (8db27f1ae9593c94095485305a583862) C:\WINDOWS\system32\drivers\Pcmcia.sys 01:50:39.0171 2812 Pcmcia - ok 01:50:39.0171 2812 PDCOMP - ok 01:50:39.0187 2812 PDFRAME - ok 01:50:39.0203 2812 PDRELI - ok 01:50:39.0203 2812 PDRFRAME - ok 01:50:39.0218 2812 perc2 - ok 01:50:39.0234 2812 perc2hib - ok 01:50:39.0265 2812 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 01:50:39.0265 2812 PptpMiniport - ok 01:50:39.0281 2812 Processor (7a1367d250502c6416a4d3a19ef155f5) C:\WINDOWS\system32\DRIVERS\processr.sys 01:50:39.0281 2812 Processor - ok 01:50:39.0296 2812 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 01:50:39.0296 2812 PSched - ok 01:50:39.0328 2812 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 01:50:39.0328 2812 Ptilink - ok 01:50:39.0343 2812 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 01:50:39.0343 2812 PxHelp20 - ok 01:50:39.0359 2812 ql1080 - ok 01:50:39.0359 2812 Ql10wnt - ok 01:50:39.0375 2812 ql12160 - ok 01:50:39.0390 2812 ql1240 - ok 01:50:39.0390 2812 ql1280 - ok 01:50:39.0406 2812 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 01:50:39.0406 2812 RasAcd - ok 01:50:39.0437 2812 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 01:50:39.0437 2812 Rasl2tp - ok 01:50:39.0437 2812 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 01:50:39.0453 2812 RasPppoe - ok 01:50:39.0453 2812 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 01:50:39.0453 2812 Raspti - ok 01:50:39.0468 2812 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 01:50:39.0484 2812 Rdbss - ok 01:50:39.0500 2812 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 01:50:39.0500 2812 RDPCDD - ok 01:50:39.0531 2812 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 01:50:39.0531 2812 rdpdr - ok 01:50:39.0562 2812 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 01:50:39.0562 2812 RDPWD - ok 01:50:39.0593 2812 redbook (e0c7bbd18040b58651bac700c804861d) C:\WINDOWS\system32\DRIVERS\redbook.sys 01:50:39.0593 2812 redbook - ok 01:50:39.0625 2812 s0016bus (59509ad6cbc28f2c73056268985b3e48) C:\WINDOWS\system32\DRIVERS\s0016bus.sys 01:50:39.0625 2812 s0016bus - ok 01:50:39.0656 2812 s0016mdfl (b98c3a6f91f4fba285af9606a240c6b4) C:\WINDOWS\system32\DRIVERS\s0016mdfl.sys 01:50:39.0656 2812 s0016mdfl - ok 01:50:39.0671 2812 s0016mdm (8a83426f4fb7b5212825d9de76368b1a) C:\WINDOWS\system32\DRIVERS\s0016mdm.sys 01:50:39.0671 2812 s0016mdm - ok 01:50:39.0703 2812 s0016mgmt (7a78bba97feb5e6d24c49e93a3bf7287) C:\WINDOWS\system32\DRIVERS\s0016mgmt.sys 01:50:39.0703 2812 s0016mgmt - ok 01:50:39.0750 2812 s0016nd5 (34ef7b5f611957b73e7219dd5a222ad1) C:\WINDOWS\system32\DRIVERS\s0016nd5.sys 01:50:39.0750 2812 s0016nd5 - ok 01:50:39.0765 2812 s0016obex (36792935847143e4a3cda0dc87248487) C:\WINDOWS\system32\DRIVERS\s0016obex.sys 01:50:39.0765 2812 s0016obex - ok 01:50:39.0796 2812 s0016unic (927208754fb27fc3e7a659e77500c5d1) C:\WINDOWS\system32\DRIVERS\s0016unic.sys 01:50:39.0796 2812 s0016unic - ok 01:50:39.0812 2812 SASKUTIL - ok 01:50:39.0859 2812 SCREAMINGBDRIVER (a643d6df1b7546256b11fb5d6b5d1375) C:\WINDOWS\system32\drivers\ScreamingBAudio.sys 01:50:39.0859 2812 SCREAMINGBDRIVER - ok 01:50:39.0875 2812 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 01:50:39.0875 2812 Secdrv - ok 01:50:39.0906 2812 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 01:50:39.0906 2812 serenum - ok 01:50:39.0921 2812 Serial (d07b02f88165e69b9f17162cf592c8a6) C:\WINDOWS\system32\DRIVERS\serial.sys 01:50:39.0921 2812 Serial - ok 01:50:39.0953 2812 sfhlp02 (64b9ab76f1b16eb059cb6cdd906c067a) C:\WINDOWS\system32\drivers\sfhlp02.sys 01:50:39.0968 2812 sfhlp02 - ok 01:50:39.0968 2812 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 01:50:39.0984 2812 Sfloppy - ok 01:50:39.0984 2812 Simbad - ok 01:50:40.0015 2812 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 01:50:40.0015 2812 SLIP - ok 01:50:40.0234 2812 SNP2STD (01b4b8b721345692d53f10b584b3d5d8) C:\WINDOWS\system32\DRIVERS\snp2sxp.sys 01:50:40.0421 2812 SNP2STD - ok 01:50:40.0421 2812 Sparrow - ok 01:50:40.0453 2812 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 01:50:40.0453 2812 splitter - ok 01:50:40.0468 2812 sptd - ok 01:50:40.0484 2812 sr (eb032822be406ef220d546ddffcf0002) C:\WINDOWS\system32\DRIVERS\sr.sys 01:50:40.0484 2812 sr - ok 01:50:40.0531 2812 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 01:50:40.0531 2812 Srv - ok 01:50:40.0562 2812 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys 01:50:40.0562 2812 StarOpen - ok 01:50:40.0593 2812 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 01:50:40.0593 2812 streamip - ok 01:50:40.0625 2812 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 01:50:40.0625 2812 swenum - ok 01:50:40.0640 2812 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 01:50:40.0640 2812 swmidi - ok 01:50:40.0656 2812 symc810 - ok 01:50:40.0671 2812 symc8xx - ok 01:50:40.0687 2812 sym_hi - ok 01:50:40.0703 2812 sym_u3 - ok 01:50:40.0734 2812 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 01:50:40.0734 2812 sysaudio - ok 01:50:40.0781 2812 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 01:50:40.0796 2812 Tcpip - ok 01:50:40.0812 2812 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 01:50:40.0812 2812 TDPIPE - ok 01:50:40.0828 2812 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 01:50:40.0828 2812 TDTCP - ok 01:50:40.0843 2812 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 01:50:40.0843 2812 TermDD - ok 01:50:40.0875 2812 tffsport (d9d5e4ca72270e9f3eca97da0983ab87) C:\WINDOWS\system32\DRIVERS\tffsport.sys 01:50:40.0890 2812 tffsport - ok 01:50:40.0906 2812 TosIde - ok 01:50:40.0921 2812 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 01:50:40.0937 2812 Udfs - ok 01:50:40.0937 2812 ultra - ok 01:50:40.0984 2812 UnlockerDriver5 (d0cb75386d9e89c864d808d64ec9160f) C:\Program Files\Unlocker\UnlockerDriver5.sys 01:50:40.0984 2812 UnlockerDriver5 - ok 01:50:41.0015 2812 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 01:50:41.0031 2812 Update - ok 01:50:41.0031 2812 USBAAPL - ok 01:50:41.0062 2812 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 01:50:41.0078 2812 usbaudio - ok 01:50:41.0078 2812 usbbus - ok 01:50:41.0109 2812 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 01:50:41.0109 2812 usbccgp - ok 01:50:41.0125 2812 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 01:50:41.0125 2812 usbehci - ok 01:50:41.0156 2812 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 01:50:41.0156 2812 usbhub - ok 01:50:41.0171 2812 USBModem - ok 01:50:41.0203 2812 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 01:50:41.0203 2812 usbohci - ok 01:50:41.0218 2812 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 01:50:41.0218 2812 usbscan - ok 01:50:41.0250 2812 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 01:50:41.0250 2812 USBSTOR - ok 01:50:41.0281 2812 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 01:50:41.0281 2812 VgaSave - ok 01:50:41.0281 2812 ViaIde - ok 01:50:41.0312 2812 VolSnap (56b191ac5fc0df219949c95a6c87afe7) C:\WINDOWS\system32\drivers\VolSnap.sys 01:50:41.0312 2812 VolSnap - ok 01:50:41.0343 2812 vulfnths (c0f55cc0903cfdc819f6d857402b697c) C:\WINDOWS\System32\Drivers\vulfnth.sys 01:50:41.0343 2812 vulfnths - ok 01:50:41.0359 2812 vulfntrs (545d98a7f61af1c7c4ad38b8f333e0b7) C:\WINDOWS\System32\Drivers\vulfntr.sys 01:50:41.0359 2812 vulfntrs - ok 01:50:41.0390 2812 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 01:50:41.0406 2812 Wanarp - ok 01:50:41.0437 2812 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\Drivers\wdf01000.sys 01:50:41.0453 2812 Wdf01000 - ok 01:50:41.0468 2812 WDICA - ok 01:50:41.0500 2812 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 01:50:41.0500 2812 wdmaud - ok 01:50:41.0546 2812 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 01:50:41.0546 2812 WpdUsb - ok 01:50:41.0578 2812 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 01:50:41.0578 2812 WSTCODEC - ok 01:50:41.0625 2812 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 01:50:41.0625 2812 WudfPf - ok 01:50:41.0640 2812 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 01:50:41.0640 2812 WudfRd - ok 01:50:41.0656 2812 zlportio - ok 01:50:41.0671 2812 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 01:50:41.0812 2812 \Device\Harddisk0\DR0 - ok 01:50:41.0812 2812 Boot (0x1200) (5f6120d77c5421f67427daa508cac75b) \Device\Harddisk0\DR0\Partition0 01:50:41.0812 2812 \Device\Harddisk0\DR0\Partition0 - ok 01:50:41.0859 2812 Boot (0x1200) (7cfe7cb7cb2088dd093ca0fa6307cd3e) \Device\Harddisk0\DR0\Partition1 01:50:41.0859 2812 \Device\Harddisk0\DR0\Partition1 - ok 01:50:41.0859 2812 ============================================================ 01:50:41.0859 2812 Scan finished 01:50:41.0859 2812 ============================================================ 01:50:41.0875 2772 Detected object count: 1 01:50:41.0875 2772 Actual detected object count: 1 01:51:31.0812 2772 C:\WINDOWS\system32\DRIVERS\ACPI.sys - copied to quarantine 01:51:35.0703 2772 Backup copy found, using it.. 01:51:35.0718 2772 C:\WINDOWS\system32\DRIVERS\ACPI.sys - will be cured on reboot 01:51:35.0718 2772 ACPI ( Virus.Win32.Rloader.a ) - User select action: Cure 01:51:48.0593 2640 Deinitialize success