2011/07/18 12:22:42.0078 3428 TDSS rootkit removing tool 2.5.11.0 Jul 11 2011 16:56:56 2011/07/18 12:22:42.0890 3428 ================================================================================ 2011/07/18 12:22:42.0890 3428 SystemInfo: 2011/07/18 12:22:42.0890 3428 2011/07/18 12:22:42.0890 3428 OS Version: 5.1.2600 ServicePack: 2.0 2011/07/18 12:22:42.0890 3428 Product type: Workstation 2011/07/18 12:22:42.0890 3428 ComputerName: XP-SPECIAL 2011/07/18 12:22:42.0890 3428 UserName: Administrator 2011/07/18 12:22:42.0890 3428 Windows directory: C:\WINDOWS 2011/07/18 12:22:42.0890 3428 System windows directory: C:\WINDOWS 2011/07/18 12:22:42.0890 3428 Processor architecture: Intel x86 2011/07/18 12:22:42.0890 3428 Number of processors: 2 2011/07/18 12:22:42.0890 3428 Page size: 0x1000 2011/07/18 12:22:42.0890 3428 Boot type: Normal boot 2011/07/18 12:22:42.0890 3428 ================================================================================ 2011/07/18 12:22:43.0906 3428 Initialize success 2011/07/18 12:22:57.0500 3192 ================================================================================ 2011/07/18 12:22:57.0500 3192 Scan started 2011/07/18 12:22:57.0500 3192 Mode: Manual; 2011/07/18 12:22:57.0500 3192 ================================================================================ 2011/07/18 12:22:57.0796 3192 ACPI (a966410ecf83b81f3b0b8e07a71957d4) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/07/18 12:22:57.0828 3192 ACPIEC (66a42b7db194e24b973bbcce840a0f3f) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/07/18 12:22:57.0875 3192 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 2011/07/18 12:22:57.0921 3192 AegisP (2c5c22990156a1063e19ad162191dc1d) C:\WINDOWS\system32\DRIVERS\AegisP.sys 2011/07/18 12:22:57.0953 3192 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys 2011/07/18 12:22:58.0046 3192 AR5211 (69645f795bbc22f05bea8b8734e3ee82) C:\WINDOWS\system32\DRIVERS\ar5211.sys 2011/07/18 12:22:58.0078 3192 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/07/18 12:22:58.0109 3192 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/07/18 12:22:58.0140 3192 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/07/18 12:22:58.0156 3192 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/07/18 12:22:58.0187 3192 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/07/18 12:22:58.0203 3192 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/07/18 12:22:58.0234 3192 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/07/18 12:22:58.0265 3192 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/07/18 12:22:58.0265 3192 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/07/18 12:22:58.0343 3192 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/07/18 12:22:58.0359 3192 dmboot (3b809ffad55dcebdb156d5ca1bd3da65) C:\WINDOWS\system32\drivers\dmboot.sys 2011/07/18 12:22:58.0390 3192 dmio (27725b6501201c3080ba73048bce389a) C:\WINDOWS\system32\drivers\dmio.sys 2011/07/18 12:22:58.0390 3192 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/07/18 12:22:58.0406 3192 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2011/07/18 12:22:58.0453 3192 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/07/18 12:22:58.0484 3192 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/07/18 12:22:58.0500 3192 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/07/18 12:22:58.0515 3192 Fips (c5fb298257c0a6514ea17835e774ea0a) C:\WINDOWS\system32\drivers\Fips.sys 2011/07/18 12:22:58.0515 3192 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/07/18 12:22:58.0546 3192 FltMgr (5a85cd3d07273e3f6fe72ee9c6431632) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2011/07/18 12:22:58.0562 3192 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/07/18 12:22:58.0578 3192 Ftdisk (ed6d921d8ab423138fb35beee6d6a6cb) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/07/18 12:22:58.0593 3192 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/07/18 12:22:58.0625 3192 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/07/18 12:22:58.0656 3192 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/07/18 12:22:58.0687 3192 HTTP (909d110c9634b0f1487eaaea837317d9) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/07/18 12:22:58.0734 3192 i8042prt (2656fdfe0a7916c3a16f374454c55dd9) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/07/18 12:22:58.0750 3192 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/07/18 12:22:58.0843 3192 IntcAzAudAddService (cbddab14249b2f05407fc09ab8fffb88) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2011/07/18 12:22:58.0890 3192 intelppm (78a353438791c6d04c64013a5abec6bd) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/07/18 12:22:58.0906 3192 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2011/07/18 12:22:58.0937 3192 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/07/18 12:22:58.0937 3192 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/07/18 12:22:58.0953 3192 IpNat (5191673215c91ff13ceaa83ef8e9653f) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/07/18 12:22:58.0953 3192 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/07/18 12:22:58.0984 3192 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/07/18 12:22:59.0000 3192 isapnp (01a9e68528f4f34e5702123d27c67bd4) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/07/18 12:22:59.0015 3192 Kbdclass (cc13db862f929ae33f64c3bedc01cd31) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/07/18 12:22:59.0031 3192 kmixer (8531438246ce9474e41ee1599904c0c7) C:\WINDOWS\system32\drivers\kmixer.sys 2011/07/18 12:22:59.0046 3192 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/07/18 12:22:59.0093 3192 MBAMSwissArmy (b309912717c29fc67e1ba4730a82b6dd) C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2011/07/18 12:22:59.0109 3192 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/07/18 12:22:59.0125 3192 Modem (15f33d12d604d0198ce5561f102cd9c5) C:\WINDOWS\system32\drivers\Modem.sys 2011/07/18 12:22:59.0140 3192 Mouclass (69c12b99ae8b6b99ec314e9b99833728) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/07/18 12:22:59.0140 3192 mouhid (ecec1e6cd558ab80f944f31326e9d3b5) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/07/18 12:22:59.0156 3192 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/07/18 12:22:59.0171 3192 MRxDAV (9921d9df98f266560ec28b3bdb580180) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/07/18 12:22:59.0203 3192 MRxSmb (7412ce77c6fd823f8889b4df420c680b) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/07/18 12:22:59.0218 3192 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2011/07/18 12:22:59.0250 3192 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/07/18 12:22:59.0265 3192 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/07/18 12:22:59.0281 3192 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/07/18 12:22:59.0296 3192 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/07/18 12:22:59.0312 3192 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys 2011/07/18 12:22:59.0328 3192 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2011/07/18 12:22:59.0343 3192 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2011/07/18 12:22:59.0359 3192 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/07/18 12:22:59.0390 3192 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/07/18 12:22:59.0406 3192 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/07/18 12:22:59.0406 3192 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/07/18 12:22:59.0421 3192 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/07/18 12:22:59.0421 3192 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/07/18 12:22:59.0453 3192 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/07/18 12:22:59.0453 3192 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2011/07/18 12:22:59.0484 3192 Ntfs (05ab81909514bfd69cbb1f2c147cf6b9) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/07/18 12:22:59.0484 3192 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/07/18 12:22:59.0609 3192 nv (83780f3a86d2804912f22f6e37cd2254) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/07/18 12:22:59.0656 3192 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/07/18 12:22:59.0671 3192 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/07/18 12:22:59.0687 3192 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/07/18 12:22:59.0718 3192 Parport (2ff48d8fdc815a8492fb2bd81e6999c2) C:\WINDOWS\system32\drivers\Parport.sys 2011/07/18 12:22:59.0718 3192 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/07/18 12:22:59.0750 3192 ParVdm (453ec2c2a20a1382f564541918520eeb) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/07/18 12:22:59.0765 3192 PCI (72113c8e81255659fd1aea98599fd226) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/07/18 12:22:59.0765 3192 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\pci.sys. Real md5: 72113c8e81255659fd1aea98599fd226, Fake md5: 5fd05c92ec56f696eaa50b68cef1b84a 2011/07/18 12:22:59.0765 3192 PCI - detected Rootkit.Win32.TDSS.tdl3 (0) 2011/07/18 12:22:59.0781 3192 PCIIde (548cf2d6369eae441a4c6baa75bc4f0a) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/07/18 12:22:59.0796 3192 Pcmcia (2849812217ecec059cb45f80eb6e52d4) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/07/18 12:22:59.0906 3192 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/07/18 12:22:59.0906 3192 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/07/18 12:22:59.0921 3192 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/07/18 12:22:59.0984 3192 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/07/18 12:22:59.0984 3192 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/07/18 12:23:00.0000 3192 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/07/18 12:23:00.0015 3192 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/07/18 12:23:00.0031 3192 Rdbss (ed375ce745c42a14f10753f7022ecd6a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/07/18 12:23:00.0046 3192 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/07/18 12:23:00.0078 3192 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/07/18 12:23:00.0125 3192 RDPWD (047bea21274c8a4a233674a76c958c2c) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/07/18 12:23:00.0125 3192 redbook (bddcece9acdad26841c987d10376f6f7) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/07/18 12:23:00.0171 3192 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/07/18 12:23:00.0187 3192 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/07/18 12:23:00.0187 3192 Serial (859bc6f8c3d58cfda9181e9926c7ddb9) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/07/18 12:23:00.0203 3192 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/07/18 12:23:00.0234 3192 splitter (9bb1dd670cb7505a90fc4e61d4aa8227) C:\WINDOWS\system32\drivers\splitter.sys 2011/07/18 12:23:00.0265 3192 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys 2011/07/18 12:23:00.0265 3192 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 2011/07/18 12:23:00.0265 3192 sptd - detected LockedFile.Multi.Generic (1) 2011/07/18 12:23:00.0296 3192 sr (6145ca23bccda679a772ec0af42d6eb5) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/07/18 12:23:00.0312 3192 Srv (5230953c21c811b5fc1ff31ae2b48097) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/07/18 12:23:00.0312 3192 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/07/18 12:23:00.0343 3192 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2011/07/18 12:23:00.0390 3192 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/07/18 12:23:00.0406 3192 Tcpip (64af914216535bc450f85253462d6f24) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/07/18 12:23:00.0437 3192 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/07/18 12:23:00.0453 3192 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/07/18 12:23:00.0453 3192 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/07/18 12:23:00.0484 3192 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2011/07/18 12:23:00.0515 3192 Update (7b2170ee3d858ce8fbe503904cc9b663) C:\WINDOWS\system32\DRIVERS\update.sys 2011/07/18 12:23:00.0546 3192 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/07/18 12:23:00.0546 3192 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/07/18 12:23:00.0578 3192 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/07/18 12:23:00.0593 3192 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/07/18 12:23:00.0593 3192 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/07/18 12:23:00.0625 3192 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2011/07/18 12:23:00.0640 3192 VolSnap (ecd173739b8ec10a814cc18653df5a36) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/07/18 12:23:00.0656 3192 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/07/18 12:23:00.0687 3192 wdmaud (0bfa8203b8148fb4e54bc212c41ce497) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/07/18 12:23:00.0734 3192 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/07/18 12:23:00.0765 3192 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/07/18 12:23:00.0796 3192 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/07/18 12:23:00.0812 3192 MBR (0x1B8) (32052574bf9f325ae309abc7bfd04460) \Device\Harddisk0\DR0 2011/07/18 12:23:00.0968 3192 Boot (0x1200) (a22ee78097bd78d86f55f57dcd09e2c4) \Device\Harddisk0\DR0\Partition0 2011/07/18 12:23:00.0984 3192 Boot (0x1200) (682aa93cf9419e5e54fcb8fabe6ce52b) \Device\Harddisk0\DR0\Partition1 2011/07/18 12:23:01.0000 3192 Boot (0x1200) (1c541abdb254bb919bf3259df643e5bf) \Device\Harddisk0\DR0\Partition2 2011/07/18 12:23:01.0000 3192 ================================================================================ 2011/07/18 12:23:01.0000 3192 Scan finished 2011/07/18 12:23:01.0000 3192 ================================================================================ 2011/07/18 12:23:01.0015 2080 Detected object count: 2 2011/07/18 12:23:01.0015 2080 Actual detected object count: 2 2011/07/18 12:24:20.0640 2080 PCI (72113c8e81255659fd1aea98599fd226) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/07/18 12:24:20.0640 2080 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\pci.sys. Real md5: 72113c8e81255659fd1aea98599fd226, Fake md5: 5fd05c92ec56f696eaa50b68cef1b84a 2011/07/18 12:24:21.0546 2080 Backup copy found, using it.. 2011/07/18 12:24:21.0578 2080 C:\WINDOWS\system32\DRIVERS\pci.sys - will be cured after reboot 2011/07/18 12:24:21.0578 2080 Rootkit.Win32.TDSS.tdl3(PCI) - User select action: Cure 2011/07/18 12:24:21.0578 2080 LockedFile.Multi.Generic(sptd) - User select action: Skip 2011/07/18 12:24:31.0515 3216 Deinitialize success