2011/02/28 20:45:39.0281 2832 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08 2011/02/28 20:45:40.0015 2832 ================================================================================ 2011/02/28 20:45:40.0015 2832 SystemInfo: 2011/02/28 20:45:40.0015 2832 2011/02/28 20:45:40.0015 2832 OS Version: 5.1.2600 ServicePack: 2.0 2011/02/28 20:45:40.0015 2832 Product type: Workstation 2011/02/28 20:45:40.0015 2832 ComputerName: TORESSIK 2011/02/28 20:45:40.0015 2832 UserName: DJ 2011/02/28 20:45:40.0015 2832 Windows directory: C:\WINDOWS 2011/02/28 20:45:40.0015 2832 System windows directory: C:\WINDOWS 2011/02/28 20:45:40.0015 2832 Processor architecture: Intel x86 2011/02/28 20:45:40.0015 2832 Number of processors: 2 2011/02/28 20:45:40.0015 2832 Page size: 0x1000 2011/02/28 20:45:40.0015 2832 Boot type: Normal boot 2011/02/28 20:45:40.0015 2832 ================================================================================ 2011/02/28 20:45:40.0343 2832 Initialize success 2011/02/28 20:45:41.0828 3036 ================================================================================ 2011/02/28 20:45:41.0828 3036 Scan started 2011/02/28 20:45:41.0828 3036 Mode: Manual; 2011/02/28 20:45:41.0828 3036 ================================================================================ 2011/02/28 20:45:43.0203 3036 ACPI (a966410ecf83b81f3b0b8e07a71957d4) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/02/28 20:45:43.0234 3036 ACPIEC (66a42b7db194e24b973bbcce840a0f3f) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/02/28 20:45:43.0296 3036 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 2011/02/28 20:45:43.0359 3036 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 2011/02/28 20:45:43.0500 3036 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 2011/02/28 20:45:43.0593 3036 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/02/28 20:45:43.0625 3036 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/02/28 20:45:43.0671 3036 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/02/28 20:45:43.0718 3036 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/02/28 20:45:44.0000 3036 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys 2011/02/28 20:45:44.0062 3036 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys 2011/02/28 20:45:44.0093 3036 avipbb (da39805e2bad99d37fce9477dd94e7f2) C:\WINDOWS\system32\DRIVERS\avipbb.sys 2011/02/28 20:45:44.0156 3036 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/02/28 20:45:44.0250 3036 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/02/28 20:45:44.0281 3036 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/02/28 20:45:44.0328 3036 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/02/28 20:45:44.0375 3036 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/02/28 20:45:44.0468 3036 cmpci (e5842ccf0953d3d46d5e26427b67e901) C:\WINDOWS\system32\drivers\cmaudio.sys 2011/02/28 20:45:44.0609 3036 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/02/28 20:45:44.0671 3036 dmboot (3b809ffad55dcebdb156d5ca1bd3da65) C:\WINDOWS\system32\drivers\dmboot.sys 2011/02/28 20:45:44.0718 3036 dmio (27725b6501201c3080ba73048bce389a) C:\WINDOWS\system32\DRIVERS\dmio.sys 2011/02/28 20:45:44.0750 3036 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/02/28 20:45:44.0781 3036 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2011/02/28 20:45:44.0859 3036 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/02/28 20:45:44.0890 3036 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2011/02/28 20:45:44.0937 3036 e4usbaw (86952e9267fa2506f435a982656d774b) C:\WINDOWS\system32\DRIVERS\e4usbaw.sys 2011/02/28 20:45:44.0984 3036 es1371 (a55dd7d8ced5d2624a9ee2dda7be0319) C:\WINDOWS\system32\drivers\es1371mp.sys 2011/02/28 20:45:45.0015 3036 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/02/28 20:45:45.0062 3036 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/02/28 20:45:45.0093 3036 Fips (c5fb298257c0a6514ea17835e774ea0a) C:\WINDOWS\system32\drivers\Fips.sys 2011/02/28 20:45:45.0250 3036 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/02/28 20:45:45.0359 3036 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2011/02/28 20:45:45.0406 3036 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\WINDOWS\system32\FsUsbExDisk.SYS 2011/02/28 20:45:45.0468 3036 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/02/28 20:45:45.0484 3036 Ftdisk (ed6d921d8ab423138fb35beee6d6a6cb) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/02/28 20:45:45.0546 3036 gameenum (5f92fd09e5610a5995da7d775eadcd12) C:\WINDOWS\system32\DRIVERS\gameenum.sys 2011/02/28 20:45:45.0578 3036 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/02/28 20:45:45.0625 3036 HdAudAddService (2a013e7530beab6e569faa83f517e836) C:\WINDOWS\system32\drivers\HdAudio.sys 2011/02/28 20:45:45.0687 3036 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/02/28 20:45:45.0718 3036 hidgame (923ee4eef2582909a056904ca8026015) C:\WINDOWS\system32\DRIVERS\hidgame.sys 2011/02/28 20:45:45.0765 3036 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/02/28 20:45:45.0828 3036 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/02/28 20:45:45.0921 3036 i8042prt (2656fdfe0a7916c3a16f374454c55dd9) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/02/28 20:45:45.0984 3036 ialm (2858e04751178a47223e0c5ce495478a) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 2011/02/28 20:45:46.0062 3036 IKANLOADER2 (539003575ea479a32e63e9d0a73bb78c) C:\WINDOWS\system32\Drivers\e4ldr.sys 2011/02/28 20:45:46.0109 3036 IKFileSec (03319a0e088b42836f3cfccb3d9966f7) C:\WINDOWS\system32\drivers\ikfilesec.sys 2011/02/28 20:45:46.0156 3036 IKSysFlt (7583e2211097d273fca4e3fce04f639f) C:\WINDOWS\system32\drivers\iksysflt.sys 2011/02/28 20:45:46.0187 3036 IKSysSec (2402f65f1eca5159c8f0f16066f4bded) C:\WINDOWS\system32\drivers\iksyssec.sys 2011/02/28 20:45:46.0218 3036 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/02/28 20:45:46.0468 3036 IntcAzAudAddService (41ef008d7b089ce6f5f2e4a61d5638e6) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2011/02/28 20:45:46.0593 3036 IntelIde (dc6c33fd296a037556f87d3b923c02b3) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/02/28 20:45:46.0656 3036 intelppm (78a353438791c6d04c64013a5abec6bd) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/02/28 20:45:46.0687 3036 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2011/02/28 20:45:46.0734 3036 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/02/28 20:45:46.0765 3036 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/02/28 20:45:46.0796 3036 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/02/28 20:45:46.0843 3036 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/02/28 20:45:46.0890 3036 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/02/28 20:45:46.0921 3036 isapnp (01a9e68528f4f34e5702123d27c67bd4) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/02/28 20:45:47.0156 3036 Kbdclass (cc13db862f929ae33f64c3bedc01cd31) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/02/28 20:45:47.0203 3036 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 2011/02/28 20:45:47.0265 3036 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/02/28 20:45:47.0343 3036 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/02/28 20:45:47.0390 3036 Modem (15f33d12d604d0198ce5561f102cd9c5) C:\WINDOWS\system32\drivers\Modem.sys 2011/02/28 20:45:47.0437 3036 Mouclass (69c12b99ae8b6b99ec314e9b99833728) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/02/28 20:45:47.0484 3036 mouhid (ecec1e6cd558ab80f944f31326e9d3b5) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/02/28 20:45:47.0515 3036 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/02/28 20:45:47.0593 3036 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/02/28 20:45:47.0656 3036 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/02/28 20:45:47.0718 3036 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2011/02/28 20:45:47.0765 3036 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/02/28 20:45:47.0843 3036 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/02/28 20:45:47.0890 3036 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/02/28 20:45:47.0937 3036 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/02/28 20:45:47.0968 3036 MtxDma0 (56eff572573e66bae3599b3c615c3853) C:\WINDOWS\system32\drivers\MtxDma0.sys 2011/02/28 20:45:48.0000 3036 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2011/02/28 20:45:48.0031 3036 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2011/02/28 20:45:48.0062 3036 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/02/28 20:45:48.0093 3036 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/02/28 20:45:48.0109 3036 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/02/28 20:45:48.0140 3036 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/02/28 20:45:48.0156 3036 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/02/28 20:45:48.0203 3036 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/02/28 20:45:48.0234 3036 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2011/02/28 20:45:48.0296 3036 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/02/28 20:45:48.0343 3036 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/02/28 20:45:48.0375 3036 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/02/28 20:45:48.0406 3036 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/02/28 20:45:48.0453 3036 Parport (2ff48d8fdc815a8492fb2bd81e6999c2) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/02/28 20:45:48.0531 3036 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/02/28 20:45:48.0562 3036 ParVdm (453ec2c2a20a1382f564541918520eeb) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/02/28 20:45:48.0656 3036 PCANDIS5 (ceef86cb35abe95c40a88784f5b631ad) C:\WINDOWS\system32\PCANDIS5.SYS 2011/02/28 20:45:48.0718 3036 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 2011/02/28 20:45:48.0765 3036 PCI (5fd05c92ec56f696eaa50b68cef1b84a) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/02/28 20:45:48.0812 3036 PCIIde (548cf2d6369eae441a4c6baa75bc4f0a) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/02/28 20:45:48.0843 3036 Pcmcia (2849812217ecec059cb45f80eb6e52d4) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/02/28 20:45:49.0015 3036 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/02/28 20:45:49.0046 3036 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/02/28 20:45:49.0078 3036 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/02/28 20:45:49.0109 3036 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/02/28 20:45:49.0218 3036 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/02/28 20:45:49.0265 3036 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/02/28 20:45:49.0281 3036 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/02/28 20:45:49.0312 3036 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/02/28 20:45:49.0390 3036 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/02/28 20:45:49.0484 3036 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/02/28 20:45:49.0562 3036 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/02/28 20:45:49.0656 3036 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/02/28 20:45:49.0750 3036 redbook (bddcece9acdad26841c987d10376f6f7) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/02/28 20:45:49.0890 3036 s115bus (e1ab463b36a7ef31d8a73a97a9b57afa) C:\WINDOWS\system32\DRIVERS\s115bus.sys 2011/02/28 20:45:49.0937 3036 s115mdfl (e24113fc13b8737c94cf4e3415488c76) C:\WINDOWS\system32\DRIVERS\s115mdfl.sys 2011/02/28 20:45:50.0000 3036 s115mdm (4029e49e7c673aa0670bd206b0af1b5b) C:\WINDOWS\system32\DRIVERS\s115mdm.sys 2011/02/28 20:45:50.0078 3036 s115mgmt (eb02ab4ca8bccecfde236cad8fc6e135) C:\WINDOWS\system32\DRIVERS\s115mgmt.sys 2011/02/28 20:45:50.0125 3036 s115obex (089869db9ffd2ac807fa87fe82ac7761) C:\WINDOWS\system32\DRIVERS\s115obex.sys 2011/02/28 20:45:50.0234 3036 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/02/28 20:45:50.0328 3036 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/02/28 20:45:50.0375 3036 Serial (9d123fbd4432e7f0426f76dfedf620f2) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/02/28 20:45:50.0390 3036 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\serial.sys. Real md5: 9d123fbd4432e7f0426f76dfedf620f2, Fake md5: 859bc6f8c3d58cfda9181e9926c7ddb9 2011/02/28 20:45:50.0390 3036 Serial - detected Rootkit.Win32.TDSS.tdl3 (0) 2011/02/28 20:45:50.0453 3036 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/02/28 20:45:50.0531 3036 SMBios (d72a21424ca66c7a745bd995eca6a710) C:\WINDOWS\system32\DRIVERS\SMBios.sys 2011/02/28 20:45:50.0656 3036 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 2011/02/28 20:45:50.0765 3036 sr (6145ca23bccda679a772ec0af42d6eb5) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/02/28 20:45:50.0890 3036 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/02/28 20:45:51.0015 3036 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 2011/02/28 20:45:51.0109 3036 ss_bbus (3f0164fbc0bd1adbd02df9759181451a) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys 2011/02/28 20:45:51.0171 3036 ss_bmdfl (b89d62206034e5fe573c80a24dd55675) C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys 2011/02/28 20:45:51.0218 3036 ss_bmdm (1ed0fcea586fe2a416ee15196e5631dd) C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys 2011/02/28 20:45:51.0265 3036 ss_bserd (994d2e5378cc337ec7dd73c1e04fcaa4) C:\WINDOWS\system32\DRIVERS\ss_bserd.sys 2011/02/28 20:45:51.0343 3036 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/02/28 20:45:51.0421 3036 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2011/02/28 20:45:51.0734 3036 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/02/28 20:45:51.0875 3036 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/02/28 20:45:51.0984 3036 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/02/28 20:45:52.0093 3036 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/02/28 20:45:52.0125 3036 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/02/28 20:45:52.0250 3036 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2011/02/28 20:45:52.0390 3036 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys 2011/02/28 20:45:52.0500 3036 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/02/28 20:45:52.0609 3036 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/02/28 20:45:52.0671 3036 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/02/28 20:45:52.0734 3036 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/02/28 20:45:52.0812 3036 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/02/28 20:45:52.0906 3036 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/02/28 20:45:52.0968 3036 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/02/28 20:45:53.0125 3036 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/02/28 20:45:53.0203 3036 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2011/02/28 20:45:53.0328 3036 VolSnap (ecd173739b8ec10a814cc18653df5a36) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/02/28 20:45:53.0421 3036 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/02/28 20:45:53.0515 3036 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys 2011/02/28 20:45:53.0796 3036 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/02/28 20:45:53.0921 3036 WpdUsb (1385e5aa9c9821790d33a9563b8d2dd0) C:\WINDOWS\system32\Drivers\wpdusb.sys 2011/02/28 20:45:53.0968 3036 Wtm_01 (d48e34c918cf53a8c90699bfd40094a2) C:\WINDOWS\system32\drivers\Wtmwdm.sys 2011/02/28 20:45:54.0000 3036 Wtm_AA (0b8ac7476e8f184233c68498064d33de) C:\WINDOWS\system32\drivers\Wtm.sys 2011/02/28 20:45:54.0046 3036 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/02/28 20:45:54.0109 3036 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/02/28 20:45:54.0281 3036 ================================================================================ 2011/02/28 20:45:54.0281 3036 Scan finished 2011/02/28 20:45:54.0281 3036 ================================================================================ 2011/02/28 20:45:54.0296 2580 Detected object count: 1 2011/02/28 20:46:35.0953 2580 Serial (9d123fbd4432e7f0426f76dfedf620f2) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/02/28 20:46:35.0953 2580 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\serial.sys. Real md5: 9d123fbd4432e7f0426f76dfedf620f2, Fake md5: 859bc6f8c3d58cfda9181e9926c7ddb9 2011/02/28 20:46:37.0734 2580 Backup copy found, using it.. 2011/02/28 20:46:37.0765 2580 C:\WINDOWS\system32\DRIVERS\serial.sys - will be cured after reboot 2011/02/28 20:46:37.0765 2580 Rootkit.Win32.TDSS.tdl3(Serial) - User select action: Cure 2011/02/28 20:46:43.0312 2660 Deinitialize success