You are on page 1of 9

18:08:23.

0062 0884
TDSS rootkit removing tool 2.6.9.0 Oct 14 2011 11:33:24
18:08:23.0859 0884
========================================================
====
18:08:23.0859 0884
Current date / time: 2011/10/15 18:08:23.0859
18:08:23.0859 0884
SystemInfo:
18:08:23.0859 0884
18:08:23.0859 0884
OS Version: 5.1.2600 ServicePack: 2.0
18:08:23.0859 0884
Product type: Workstation
18:08:23.0859 0884
ComputerName: CABINA06
18:08:23.0859 0884
UserName: Windows
18:08:23.0875 0884
Windows directory: C:\WINDOWS
18:08:23.0875 0884
System windows directory: C:\WINDOWS
18:08:23.0875 0884
Processor architecture: Intel x86
18:08:23.0875 0884
Number of processors: 1
18:08:23.0875 0884
Page size: 0x1000
18:08:23.0875 0884
Boot type: Normal boot
18:08:23.0875 0884
========================================================
====
18:08:25.0078 0884
Initialize success
18:08:29.0140 1428
========================================================
====
18:08:29.0140 1428
Scan started
18:08:29.0140 1428
Mode: Manual; SigCheck; TDLFS;
18:08:29.0140 1428
========================================================
====
18:08:30.0078 1428
Abiosdsk - ok
18:08:30.0187 1428
abp480n5 - ok
18:08:30.0250 1428
ACPI
(33d1373ee875ce8b063777f7e77815b7) C:\WI
NDOWS\system32\DRIVERS\ACPI.sys
18:08:31.0750 1428
ACPI - ok
18:08:31.0812 1428
ACPIEC
(1c905333c0b9f3d7c68ddf25e54b00f9) C:\WI
NDOWS\system32\drivers\ACPIEC.sys
18:08:31.0953 1428
ACPIEC - ok
18:08:32.0015 1428
adpu160m - ok
18:08:32.0062 1428
aec
(841f385c6cfaf66b58fbd898722bb4f0) C:\WI
NDOWS\system32\drivers\aec.sys
18:08:32.0203 1428
aec - ok
18:08:32.0281 1428
AFD
(5ac495f4cb807b2b98ad2ad591e6d92e) C:\WI
NDOWS\System32\drivers\afd.sys
18:08:32.0437 1428
AFD - ok
18:08:32.0515 1428
agp440
(2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WI
NDOWS\system32\DRIVERS\agp440.sys
18:08:32.0656 1428
agp440 - ok
18:08:32.0703 1428
Aha154x - ok
18:08:32.0718 1428
aic78u2 - ok
18:08:32.0750 1428
aic78xx - ok
18:08:32.0906 1428
ALCXWDM
(6d3077c3346de5b13835fb859c69a2ea) C:\WI
NDOWS\system32\drivers\ALCXWDM.SYS
18:08:33.0171 1428
ALCXWDM - ok
18:08:33.0234 1428
AliIde - ok
18:08:33.0250 1428
amsint - ok
18:08:33.0359 1428
apf001
(7b4beb577c5d0171f9b66f390ec29284) C:\Ar
chivos de programa\softnyx\GunboundS2\apf001.sys
18:08:33.0421 1428
apf001 - ok
18:08:33.0468 1428
asc - ok
18:08:33.0484 1428
asc3350p - ok
18:08:33.0500 1428
asc3550 - ok
18:08:33.0562 1428
AsyncMac
(02000abf34af4c218c35d257024807d6) C:\WI
NDOWS\system32\DRIVERS\asyncmac.sys
18:08:33.0687 1428
AsyncMac - ok

18:08:33.0765 1428
atapi
(cdfe4411a69c224bd1d11b2da92dac51)
NDOWS\system32\DRIVERS\atapi.sys
18:08:33.0906 1428
atapi - ok
18:08:33.0953 1428
Atdisk - ok
18:08:34.0031 1428
ati2mtag
(9e9529d9e7af3b2e5ce1b55f4c70ee6c)
NDOWS\system32\DRIVERS\ati2mtag.sys
18:08:34.0203 1428
ati2mtag - ok
18:08:34.0281 1428
Atmarpc
(ec88da854ab7d7752ec8be11a741bb7f)
NDOWS\system32\DRIVERS\atmarpc.sys
18:08:34.0421 1428
Atmarpc - ok
18:08:34.0500 1428
audstub
(d9f724aa26c010a217c97606b160ed68)
NDOWS\system32\DRIVERS\audstub.sys
18:08:34.0656 1428
audstub - ok
18:08:34.0718 1428
Beep
(da1f27d85e0d1525f6621372e7b685e9)
NDOWS\system32\drivers\Beep.sys
18:08:34.0875 1428
Beep - ok
18:08:34.0968 1428
cbidf2k
(90a673fc8e12a79afbed2576f6a7aaf9)
NDOWS\system32\drivers\cbidf2k.sys
18:08:35.0125 1428
cbidf2k - ok
18:08:35.0171 1428
cd20xrnt - ok
18:08:35.0187 1428
Cdaudio
(c1b486a7658353d33a10cc15211a873b)
NDOWS\system32\drivers\Cdaudio.sys
18:08:35.0359 1428
Cdaudio - ok
18:08:35.0421 1428
Cdfs
(cd7d5152df32b47f4e36f710b35aae02)
NDOWS\system32\drivers\Cdfs.sys
18:08:35.0578 1428
Cdfs - ok
18:08:35.0656 1428
Cdrom
(af9c19b3100fe010496b1a27181fbf72)
NDOWS\system32\DRIVERS\cdrom.sys
18:08:35.0812 1428
Cdrom - ok
18:08:35.0859 1428
Changer - ok
18:08:35.0890 1428
CmdIde - ok
18:08:35.0937 1428
Cpqarray - ok
18:08:36.0000 1428
d347bus
(5776322f93cdb91086111f5ffbfda2a0)
NDOWS\system32\DRIVERS\d347bus.sys
18:08:36.0015 1428
d347bus ( UnsignedFile.Multi.Generic ) - warning
18:08:36.0015 1428
d347bus - detected UnsignedFile.Multi.Generic (1)
18:08:36.0093 1428
d347prt
(b49f79ace459763f4e0380071be9cb45)
NDOWS\system32\Drivers\d347prt.sys
18:08:36.0109 1428
d347prt ( UnsignedFile.Multi.Generic ) - warning
18:08:36.0109 1428
d347prt - detected UnsignedFile.Multi.Generic (1)
18:08:36.0140 1428
dac2w2k - ok
18:08:36.0171 1428
dac960nt - ok
18:08:36.0218 1428
DeepFrz
(838f4f02228a6e6625fd38d8af8182a3)
NDOWS\system32\drivers\DeepFrz.sys
18:08:36.0234 1428
DeepFrz - ok
18:08:36.0437 1428
Disk
(00ca44e4534865f8a3b64f7c0984bff0)
NDOWS\system32\DRIVERS\disk.sys
18:08:36.0609 1428
Disk - ok
18:08:36.0687 1428
dmboot
(9fb634a0ed429aa64de57c53dd10ccf9)
NDOWS\system32\drivers\dmboot.sys
18:08:36.0875 1428
dmboot - ok
18:08:36.0937 1428
dmio
(67decfaf3b6cdb34b3fa77d965281bb5)
NDOWS\system32\drivers\dmio.sys
18:08:37.0125 1428
dmio - ok
18:08:37.0171 1428
dmload
(e9317282a63ca4d188c0df5e09c6ac5f)
NDOWS\system32\drivers\dmload.sys
18:08:37.0328 1428
dmload - ok
18:08:37.0406 1428
DMusic
(a6f881284ac1150e37d9ae47ff601267)
NDOWS\system32\drivers\DMusic.sys
18:08:37.0562 1428
DMusic - ok

C:\WI

C:\WI
C:\WI
C:\WI
C:\WI
C:\WI

C:\WI
C:\WI
C:\WI

C:\WI

C:\WI

C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI

18:08:37.0609 1428
dpti2o - ok
18:08:37.0656 1428
drmkaud
NDOWS\system32\drivers\drmkaud.sys
18:08:37.0812 1428
drmkaud - ok
18:08:37.0906 1428
E100B
NDOWS\system32\DRIVERS\e100b325.sys
18:08:37.0937 1428
E100B - ok
18:08:38.0015 1428
Fastfat
NDOWS\system32\drivers\Fastfat.sys
18:08:38.0171 1428
Fastfat - ok
18:08:38.0250 1428
Fdc
NDOWS\system32\DRIVERS\fdc.sys
18:08:38.0406 1428
Fdc - ok
18:08:38.0468 1428
Fips
NDOWS\system32\drivers\Fips.sys
18:08:38.0625 1428
Fips - ok
18:08:38.0703 1428
Flpydisk
NDOWS\system32\DRIVERS\flpydisk.sys
18:08:38.0859 1428
Flpydisk - ok
18:08:38.0937 1428
FltMgr
NDOWS\system32\DRIVERS\fltMgr.sys
18:08:39.0093 1428
FltMgr - ok
18:08:39.0140 1428
Fs_Rec
NDOWS\system32\drivers\Fs_Rec.sys
18:08:39.0281 1428
Fs_Rec - ok
18:08:39.0359 1428
Ftdisk
NDOWS\system32\DRIVERS\ftdisk.sys
18:08:39.0500 1428
Ftdisk - ok
18:08:39.0578 1428
Gpc
NDOWS\system32\DRIVERS\msgpc.sys
18:08:39.0734 1428
Gpc - ok
18:08:39.0781 1428
hpn - ok
18:08:39.0843 1428
HTTP
NDOWS\system32\Drivers\HTTP.sys
18:08:39.0984 1428
HTTP - ok
18:08:40.0031 1428
i2omgmt - ok
18:08:40.0062 1428
i2omp - ok
18:08:40.0109 1428
i8042prt
NDOWS\system32\DRIVERS\i8042prt.sys
18:08:40.0250 1428
i8042prt - ok
18:08:40.0359 1428
Imapi
NDOWS\system32\DRIVERS\imapi.sys
18:08:40.0500 1428
Imapi - ok
18:08:40.0546 1428
ini910u - ok
18:08:40.0609 1428
IntelIde
NDOWS\system32\DRIVERS\intelide.sys
18:08:40.0750 1428
IntelIde - ok
18:08:40.0828 1428
intelppm
NDOWS\system32\DRIVERS\intelppm.sys
18:08:40.0968 1428
intelppm - ok
18:08:41.0046 1428
Ip6Fw
NDOWS\system32\DRIVERS\Ip6Fw.sys
18:08:41.0187 1428
Ip6Fw - ok
18:08:41.0265 1428
IpFilterDriver
NDOWS\system32\DRIVERS\ipfltdrv.sys
18:08:41.0421 1428
IpFilterDriver
18:08:41.0484 1428
IpInIp
NDOWS\system32\DRIVERS\ipinip.sys
18:08:41.0640 1428
IpInIp - ok
18:08:41.0718 1428
IpNat

(1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WI
(fae8b6b311f898df3d19bc638e980ca5) C:\WI
(3117f595e9615e04f05a54fc15a03b20) C:\WI
(ced2e8396a8838e59d8fd529c680e02c) C:\WI
(6e9d149cfae2af4783f85dbd6cedf7a1) C:\WI
(0dd1de43115b93f4d85e889d7a86f548) C:\WI
(157754f0df355a9e0a6f54721914f9c6) C:\WI
(3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WI
(cc5f3af5711a1c7c8fa1d43bb16b401a) C:\WI
(c0f1d4a21de5a415df8170616703debf) C:\WI

(c19b522a9ae0bbc3293397f3055e80a1) C:\WI

(0cab3ee361cfeab260b3906c8b6fb2be) C:\WI
(f8aa320c6a0409c0380e5d8a99d76ec6) C:\WI

(161b54c8200663ada2c145d87e8d4340) C:\WI
(98bbc0e8efa90fff1ec9456ee7b0b1f1) C:\WI
(4448006b6bc60e6c027932cfc38d6855) C:\WI
(731f22ba402ee4b62748adaf6363c182) C:\WI
- ok
(e1ec7f5da720b640cd8fb8424f1b14bb) C:\WI
(b5a8e215ac29d24d60b4d1250ef05ace) C:\WI

NDOWS\system32\DRIVERS\ipnat.sys
18:08:41.0859 1428
IpNat - ok
18:08:41.0937 1428
IPSec
NDOWS\system32\DRIVERS\ipsec.sys
18:08:42.0093 1428
IPSec - ok
18:08:42.0171 1428
IRENUM
NDOWS\system32\DRIVERS\irenum.sys
18:08:42.0234 1428
IRENUM - ok
18:08:42.0359 1428
isapnp
NDOWS\system32\DRIVERS\isapnp.sys
18:08:42.0484 1428
isapnp - ok
18:08:42.0562 1428
Kbdclass
NDOWS\system32\DRIVERS\kbdclass.sys
18:08:42.0718 1428
Kbdclass - ok
18:08:42.0796 1428
kmixer
NDOWS\system32\drivers\kmixer.sys
18:08:42.0937 1428
kmixer - ok
18:08:43.0015 1428
KSecDD
NDOWS\system32\drivers\KSecDD.sys
18:08:43.0171 1428
KSecDD - ok
18:08:43.0250 1428
lbrtfdc - ok
18:08:43.0312 1428
mnmdd
NDOWS\system32\drivers\mnmdd.sys
18:08:43.0453 1428
mnmdd - ok
18:08:43.0515 1428
Modem
NDOWS\system32\drivers\Modem.sys
18:08:43.0671 1428
Modem - ok
18:08:43.0734 1428
Mouclass
NDOWS\system32\DRIVERS\mouclass.sys
18:08:43.0859 1428
Mouclass - ok
18:08:43.0937 1428
MountMgr
NDOWS\system32\drivers\MountMgr.sys
18:08:44.0078 1428
MountMgr - ok
18:08:44.0125 1428
mraid35x - ok
18:08:44.0187 1428
MRxDAV
NDOWS\system32\DRIVERS\mrxdav.sys
18:08:44.0312 1428
MRxDAV - ok
18:08:44.0406 1428
MRxSmb
NDOWS\system32\DRIVERS\mrxsmb.sys
18:08:44.0578 1428
MRxSmb - ok
18:08:44.0656 1428
Msfs
NDOWS\system32\drivers\Msfs.sys
18:08:44.0796 1428
Msfs - ok
18:08:44.0875 1428
MSKSSRV
NDOWS\system32\drivers\MSKSSRV.sys
18:08:45.0015 1428
MSKSSRV - ok
18:08:45.0093 1428
MSPCLOCK
NDOWS\system32\drivers\MSPCLOCK.sys
18:08:45.0218 1428
MSPCLOCK - ok
18:08:45.0296 1428
MSPQM
NDOWS\system32\drivers\MSPQM.sys
18:08:45.0437 1428
MSPQM - ok
18:08:45.0500 1428
mssmbios
NDOWS\system32\DRIVERS\mssmbios.sys
18:08:45.0625 1428
mssmbios - ok
18:08:45.0718 1428
Mup
NDOWS\system32\drivers\Mup.sys
18:08:45.0859 1428
Mup - ok
18:08:45.0937 1428
NAL
NDOWS\system32\Drivers\iqvw32.sys

(64537aa5c003a6afeee1df819062d0d1) C:\WI
(50708daa1b1cbb7d6ac1cf8f56a24410) C:\WI
(90bc6118193b4e8a76f0fc0d4a3572de) C:\WI
(71bfdda7b3006b45b18d8bac92bc9993) C:\WI
(d93cad07c5683db066b0b2d2d3790ead) C:\WI
(eb7ffe87fd367ea8fca0506f74a87fbb) C:\WI

(4ae068242760a1fb6e1a44bf4e16afa6) C:\WI
(b65f57d37e8d43089b701ed16e22d0e9) C:\WI
(05e9c75c6797145a4983e9d0a4778bc3) C:\WI
(65653f3b4477f3c63e68a9659f85ee2e) C:\WI

(46edcc8f2db2f322c24f48785cb46366) C:\WI
(1fd607fc67f7f7c633c3da65bfc53d18) C:\WI
(561b3a4333ca2dbdba28b5b956822519) C:\WI
(ae431a8dd3c1d0d0610cdbac16057ad0) C:\WI
(13e75fef9dfeb08eeded9d0246e1f448) C:\WI
(1988a33ff19242576c3d0ef9ce785da7) C:\WI
(469541f8bfd2b32659d5d463a6714bce) C:\WI
(82035e0f41c2dd05ae41d27fe6cf7de1) C:\WI
(ab7cc5ddfa1557bab312e12abb6a5158) C:\WI

18:08:45.0937 1428
NAL ( UnsignedFile.Multi.Generic ) - warning
18:08:45.0937 1428
NAL - detected UnsignedFile.Multi.Generic (1)
18:08:46.0031 1428
NDIS
(558635d3af1c7546d26067d5d9b6959e)
NDOWS\system32\drivers\NDIS.sys
18:08:46.0156 1428
NDIS - ok
18:08:46.0218 1428
NdisTapi
(08d43bbdacdf23f34d79e44ed35c1b4c)
NDOWS\system32\DRIVERS\ndistapi.sys
18:08:46.0359 1428
NdisTapi - ok
18:08:46.0437 1428
Ndisuio
(34d6cd56409da9a7ed573e1c90a308bf)
NDOWS\system32\DRIVERS\ndisuio.sys
18:08:46.0578 1428
Ndisuio - ok
18:08:46.0640 1428
NdisWan
(0b90e255a9490166ab368cd55a529893)
NDOWS\system32\DRIVERS\ndiswan.sys
18:08:46.0781 1428
NdisWan - ok
18:08:46.0843 1428
NDProxy
(59fc3fb44d2669bc144fd87826bb571f)
NDOWS\system32\drivers\NDProxy.sys
18:08:46.0984 1428
NDProxy - ok
18:08:47.0078 1428
NetBIOS
(3a2aca8fc1d7786902ca434998d7ceb4)
NDOWS\system32\DRIVERS\netbios.sys
18:08:47.0203 1428
NetBIOS - ok
18:08:47.0296 1428
NetBT
(0c80e410cd2f47134407ee7dd19cc86b)
NDOWS\system32\DRIVERS\netbt.sys
18:08:47.0437 1428
NetBT - ok
18:08:47.0562 1428
Npfs
(4f601bcb8f64ea3ac0994f98fed03f8e)
NDOWS\system32\drivers\Npfs.sys
18:08:47.0687 1428
Npfs - ok
18:08:47.0781 1428
Ntfs
(b78be402c3f63dd55521f73876951cdd)
NDOWS\system32\drivers\Ntfs.sys
18:08:47.0937 1428
Ntfs - ok
18:08:48.0015 1428
Null
(73c1e1f395918bc2c6dd67af7591a3ad)
NDOWS\system32\drivers\Null.sys
18:08:48.0156 1428
Null - ok
18:08:48.0234 1428
NwlnkFlt
(b305f3fad35083837ef46a0bbce2fc57)
NDOWS\system32\DRIVERS\nwlnkflt.sys
18:08:48.0375 1428
NwlnkFlt - ok
18:08:48.0437 1428
NwlnkFwd
(c99b3415198d1aab7227f2c88fd664b9)
NDOWS\system32\DRIVERS\nwlnkfwd.sys
18:08:48.0578 1428
NwlnkFwd - ok
18:08:48.0656 1428
NwlnkIpx
(79ea3fcda7067977625b3363a2657c80)
NDOWS\system32\DRIVERS\nwlnkipx.sys
18:08:48.0781 1428
NwlnkIpx - ok
18:08:48.0875 1428
NwlnkNb
(56d34a67c05e94e16377c60609741ff8)
NDOWS\system32\DRIVERS\nwlnknb.sys
18:08:49.0000 1428
NwlnkNb - ok
18:08:49.0078 1428
NwlnkSpx
(c0bb7d1615e1acbdc99757f6ceaf8cf0)
NDOWS\system32\DRIVERS\nwlnkspx.sys
18:08:49.0234 1428
NwlnkSpx - ok
18:08:49.0468 1428
Parport
(0df0b83c90473ccfdc3dc882cbb6e4a9)
NDOWS\system32\DRIVERS\parport.sys
18:08:49.0609 1428
Parport - ok
18:08:49.0671 1428
PartMgr
(3334430c29dc338092f79c38ef7b4cd0)
NDOWS\system32\drivers\PartMgr.sys
18:08:49.0781 1428
PartMgr - ok
18:08:49.0859 1428
ParVdm
(fad44d704ecd7d39ad01415b8bb34204)
NDOWS\system32\drivers\ParVdm.sys
18:08:49.0984 1428
ParVdm - ok
18:08:50.0062 1428
PCI
(a566b8da5e70b3237274d418853a87e0)
NDOWS\system32\DRIVERS\pci.sys
18:08:50.0218 1428
PCI - ok
18:08:50.0265 1428
PCIDump - ok

C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI
C:\WI

18:08:50.0328 1428
PCIIde
NDOWS\system32\drivers\PCIIde.sys
18:08:50.0468 1428
PCIIde - ok
18:08:50.0531 1428
Pcmcia
NDOWS\system32\drivers\Pcmcia.sys
18:08:50.0671 1428
Pcmcia - ok
18:08:50.0718 1428
PDCOMP - ok
18:08:50.0734 1428
PDFRAME - ok
18:08:50.0765 1428
PDRELI - ok
18:08:50.0781 1428
PDRFRAME - ok
18:08:50.0812 1428
perc2 - ok
18:08:50.0828 1428
perc2hib - ok
18:08:50.0906 1428
PptpMiniport
NDOWS\system32\DRIVERS\raspptp.sys
18:08:51.0031 1428
PptpMiniport 18:08:51.0109 1428
PSched
NDOWS\system32\DRIVERS\psched.sys
18:08:51.0265 1428
PSched - ok
18:08:51.0390 1428
Ptilink
NDOWS\system32\DRIVERS\ptilink.sys
18:08:51.0515 1428
Ptilink - ok
18:08:51.0546 1428
ql1080 - ok
18:08:51.0578 1428
Ql10wnt - ok
18:08:51.0593 1428
ql12160 - ok
18:08:51.0625 1428
ql1240 - ok
18:08:51.0640 1428
ql1280 - ok
18:08:51.0671 1428
RasAcd
NDOWS\system32\DRIVERS\rasacd.sys
18:08:51.0812 1428
RasAcd - ok
18:08:51.0890 1428
Rasl2tp
NDOWS\system32\DRIVERS\rasl2tp.sys
18:08:52.0031 1428
Rasl2tp - ok
18:08:52.0109 1428
RasPppoe
NDOWS\system32\DRIVERS\raspppoe.sys
18:08:52.0250 1428
RasPppoe - ok
18:08:52.0343 1428
Raspti
NDOWS\system32\DRIVERS\raspti.sys
18:08:52.0484 1428
Raspti - ok
18:08:52.0562 1428
Rdbss
NDOWS\system32\DRIVERS\rdbss.sys
18:08:52.0703 1428
Rdbss - ok
18:08:52.0765 1428
RDPCDD
NDOWS\system32\DRIVERS\RDPCDD.sys
18:08:52.0906 1428
RDPCDD - ok
18:08:53.0000 1428
rdpdr
NDOWS\system32\DRIVERS\rdpdr.sys
18:08:53.0125 1428
rdpdr - ok
18:08:53.0203 1428
RDPWD
NDOWS\system32\drivers\RDPWD.sys
18:08:53.0343 1428
RDPWD - ok
18:08:53.0437 1428
redbook
NDOWS\system32\DRIVERS\redbook.sys
18:08:53.0578 1428
redbook - ok
18:08:53.0703 1428
Secdrv
NDOWS\system32\DRIVERS\secdrv.sys
18:08:53.0765 1428
Secdrv - ok
18:08:53.0859 1428
serenum
NDOWS\system32\DRIVERS\serenum.sys
18:08:54.0000 1428
serenum - ok
18:08:54.0078 1428
Serial

(33d63f0a9021acb4d75d83b646b93a30) C:\WI
(6374a34b03aea7971c976982a391ad07) C:\WI

(1c5cc65aac0783c344f16353e60b72ac) C:\WI
ok
(48671f327553dcf1d27f6197f622a668) C:\WI
(80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WI

(fe0d99d6f31e4fad8159f690d68ded9c) C:\WI
(98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WI
(7306eeed8895454cbed4669be9f79faa) C:\WI
(fdbb1d60066fcfbb7452fd8f9829b242) C:\WI
(29d66245adba878fff574cd66abd2884) C:\WI
(4912d5b403614ce99c28420f75353332) C:\WI
(a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WI
(d4f5643d7714ef499ae9527fdcd50894) C:\WI
(28531a950381da67fc6412dfebcc8c5c) C:\WI
(d26e26ea516450af9d072635c60387f4) C:\WI
(a2d868aeeff612e70e213c451a70cafb) C:\WI
(fa9c4c4ac544301fa13c5c00a270399f) C:\WI

NDOWS\system32\DRIVERS\serial.sys
18:08:54.0218 1428
Serial - ok
18:08:54.0312 1428
Sfloppy
NDOWS\system32\drivers\Sfloppy.sys
18:08:54.0453 1428
Sfloppy - ok
18:08:54.0515 1428
Simbad - ok
18:08:54.0531 1428
Sparrow - ok
18:08:54.0578 1428
splitter
NDOWS\system32\drivers\splitter.sys
18:08:54.0718 1428
splitter - ok
18:08:54.0796 1428
sr
NDOWS\system32\DRIVERS\sr.sys
18:08:54.0875 1428
sr - ok
18:08:54.0953 1428
Srv
NDOWS\system32\DRIVERS\srv.sys
18:08:55.0125 1428
Srv - ok
18:08:55.0218 1428
swenum
NDOWS\system32\DRIVERS\swenum.sys
18:08:55.0359 1428
swenum - ok
18:08:55.0437 1428
swmidi
NDOWS\system32\drivers\swmidi.sys
18:08:55.0593 1428
swmidi - ok
18:08:55.0640 1428
symc810 - ok
18:08:55.0656 1428
symc8xx - ok
18:08:55.0687 1428
sym_hi - ok
18:08:55.0703 1428
sym_u3 - ok
18:08:55.0750 1428
sysaudio
NDOWS\system32\drivers\sysaudio.sys
18:08:55.0890 1428
sysaudio - ok
18:08:56.0000 1428
Tcpip
NDOWS\system32\DRIVERS\tcpip.sys
18:08:56.0156 1428
Tcpip - ok
18:08:56.0234 1428
TDPIPE
NDOWS\system32\drivers\TDPIPE.sys
18:08:56.0375 1428
TDPIPE - ok
18:08:56.0453 1428
TDTCP
NDOWS\system32\drivers\TDTCP.sys
18:08:56.0609 1428
TDTCP - ok
18:08:56.0687 1428
TermDD
NDOWS\system32\DRIVERS\termdd.sys
18:08:56.0828 1428
TermDD - ok
18:08:56.0906 1428
TosIde - ok
18:08:56.0953 1428
Udfs
NDOWS\system32\drivers\Udfs.sys
18:08:57.0109 1428
Udfs - ok
18:08:57.0156 1428
ultra - ok
18:08:57.0218 1428
Update
NDOWS\system32\DRIVERS\update.sys
18:08:57.0359 1428
Update - ok
18:08:57.0453 1428
usbehci
NDOWS\system32\DRIVERS\usbehci.sys
18:08:57.0578 1428
usbehci - ok
18:08:57.0656 1428
usbhub
NDOWS\system32\DRIVERS\usbhub.sys
18:08:57.0796 1428
usbhub - ok
18:08:57.0859 1428
USBSTOR
NDOWS\system32\DRIVERS\USBSTOR.SYS
18:08:58.0015 1428
USBSTOR - ok
18:08:58.0093 1428
usbuhci
NDOWS\system32\DRIVERS\usbuhci.sys

(0d13b6df6e9e101013a7afb0ce629fe0) C:\WI

(8e186b8f23295d1e42c573b82b80d548) C:\WI
(3c151d50cf3ae1683c6e3ec201b2ad3d) C:\WI
(20b7e396720353e4117d64d9dcb926ca) C:\WI
(03c1bae4766e2450219d20b993d6e046) C:\WI
(94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WI

(650ad082d46bac0e64c9c0e0928492fd) C:\WI
(9f4b36614a0fc234525ba224957de55c) C:\WI
(38d437cf2d98965f239b0abcd66dcb0f) C:\WI
(ed0580af02502d00ad8c4c066b156be9) C:\WI
(a540a99c281d933f3d69d55e48727f47) C:\WI

(12f70256f140cd7d52c58c7048fde657) C:\WI

(aff2e5045961bbc0a602bb6f95eb1345) C:\WI
(15e993ba2f6946b2bfbbfcd30398621e) C:\WI
(c72f40947f92cea56a8fb532edf025f1) C:\WI
(6cd7b22193718f1d17a47a1cd6d37e75) C:\WI
(f8fd1400092e23c8f2f31406ef06167b) C:\WI

18:08:58.0203 1428
usbuhci - ok
18:08:58.0296 1428
VgaSave
(8a60edd72b4ea5aea8202daf0e427925) C:\WI
NDOWS\System32\drivers\vga.sys
18:08:58.0437 1428
VgaSave - ok
18:08:58.0484 1428
ViaIde - ok
18:08:58.0531 1428
VolSnap
(d6ec4aff061665a10f0b1a9517d338e3) C:\WI
NDOWS\system32\drivers\VolSnap.sys
18:08:58.0687 1428
VolSnap - ok
18:08:58.0781 1428
Wanarp
(984ef0b9788abf89974cfed4bfbaacbc) C:\WI
NDOWS\system32\DRIVERS\wanarp.sys
18:08:58.0921 1428
Wanarp - ok
18:08:58.0984 1428
WDICA - ok
18:08:59.0031 1428
wdmaud
(2797f33ebf50466020c430ee4f037933) C:\WI
NDOWS\system32\drivers\wdmaud.sys
18:08:59.0171 1428
wdmaud - ok
18:08:59.0343 1428
WudfPf
(729f76cd53af1685ca4c4c058519c58c) C:\WI
NDOWS\system32\DRIVERS\WudfPf.sys
18:08:59.0375 1428
WudfPf - ok
18:08:59.0453 1428
WudfRd
(a2aafcc8a204736296d937c7c545b53f) C:\WI
NDOWS\system32\DRIVERS\wudfrd.sys
18:08:59.0468 1428
WudfRd - ok
18:08:59.0531 1428
XDva365 - ok
18:08:59.0546 1428
XDva375 - ok
18:08:59.0578 1428
XDva377 - ok
18:08:59.0593 1428
XDva380 - ok
18:08:59.0625 1428
XDva382 - ok
18:08:59.0640 1428
XDva383 - ok
18:08:59.0656 1428
XDva385 - ok
18:08:59.0687 1428
XDva386 - ok
18:08:59.0703 1428
XDva388 - ok
18:08:59.0718 1428
XDva389 - ok
18:08:59.0750 1428
XDva390 - ok
18:08:59.0781 1428
MBR (0x1B8)
(8f558eb6672622401da993e1e865c861) \Devi
ce\Harddisk0\DR0
18:08:59.0921 1428
\Device\Harddisk0\DR0 ( TDSS File System ) - warning
18:08:59.0921 1428
\Device\Harddisk0\DR0 - detected TDSS File System (1)
18:08:59.0953 1428
Boot (0x1200) (ca84123fcab1f5e439125f40e15312b1) \Devi
ce\Harddisk0\DR0\Partition0
18:08:59.0953 1428
\Device\Harddisk0\DR0\Partition0 - ok
18:08:59.0968 1428
Boot (0x1200) (cf123595a2b3b4560709f60adfaf17b9) \Devi
ce\Harddisk0\DR0\Partition1
18:08:59.0968 1428
\Device\Harddisk0\DR0\Partition1 - ok
18:09:00.0000 1428
Boot (0x1200) (7d66ed73ccb2faa4c9c2292f78f2a28f) \Devi
ce\Harddisk0\DR0\Partition2
18:09:00.0000 1428
\Device\Harddisk0\DR0\Partition2 - ok
18:09:00.0015 1428
Boot (0x1200) (a678b689e9fdc3a6c6ff8a4bdf74fcf2) \Devi
ce\Harddisk0\DR0\Partition3
18:09:00.0031 1428
\Device\Harddisk0\DR0\Partition3 - ok
18:09:00.0031 1428
========================================================
====
18:09:00.0031 1428
Scan finished
18:09:00.0031 1428
========================================================
====
18:09:00.0156 1280
Detected object count: 4
18:09:00.0156 1280
Actual detected object count: 4
18:11:02.0593 1280
HKLM\SYSTEM\ControlSet001\services\d347bus - will be del
eted on reboot
18:11:02.0593 1280
HKLM\SYSTEM\ControlSet002\services\d347bus - will be del
eted on reboot
18:11:02.0593 1280
C:\WINDOWS\system32\DRIVERS\d347bus.sys - will be delete

d on reboot
18:11:02.0593 1280
ion: Delete
18:11:02.0609 1280
eted on reboot
18:11:02.0609 1280
eted on reboot
18:11:02.0609 1280
d on reboot
18:11:02.0609 1280
ion: Delete
18:11:02.0625 1280
on reboot
18:11:02.0625 1280
on reboot
18:11:02.0625 1280
on reboot
18:11:02.0625 1280
Delete
18:11:02.0625 1280
18:11:02.0625 1280
action: Delete
18:11:04.0578 1792

d347bus ( UnsignedFile.Multi.Generic ) - User select act


HKLM\SYSTEM\ControlSet001\services\d347prt - will be del
HKLM\SYSTEM\ControlSet002\services\d347prt - will be del
C:\WINDOWS\system32\Drivers\d347prt.sys - will be delete
d347prt ( UnsignedFile.Multi.Generic ) - User select act
HKLM\SYSTEM\ControlSet001\services\NAL - will be deleted
HKLM\SYSTEM\ControlSet002\services\NAL - will be deleted
C:\WINDOWS\system32\Drivers\iqvw32.sys - will be deleted
NAL ( UnsignedFile.Multi.Generic ) - User select action:
\Device\Harddisk0\DR0\TDLFS - deleted
\Device\Harddisk0\DR0 ( TDSS File System ) - User select
Deinitialize success

You might also like