Professional Documents
Culture Documents
AppMgmt
C:\WIND
aspnet_state
C:\WIND
AsyncMac
C:\WIND
atapi
C:\WIND
Atmarpc
C:\WIND
AudioSrv
C:\WIND
audstub
C:\WIND
Beep
C:\WIND
BESClient
C:\Prog
BITS
C:\WIND
Browser
C:\WIND
cbidf2k
C:\WIND
Cdaudio
C:\WIND
Cdfs
C:\WIND
Cdrom
C:\WIND
CiSvc
C:\WIND
ClipSrv
C:\WIND
clr_optimization_v2.0.5
0727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:29:02.0061 3636 clr_optimization_v2.0.50727_32 - ok
08:29:02.0108 3636 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.3
0319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:29:02.0123 3636 clr_optimization_v4.0.30319_32 - ok
08:29:02.0139 3636 CmdIde - ok
08:29:02.0186 3636 COMSysApp - ok
08:29:02.0311 3636 Cpqarray - ok
08:29:02.0358 3636 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc
C:\WIND
OWS\System32\cryptsvc.dll
08:29:02.0358 3636 CryptSvc - ok
08:29:02.0373 3636 dac2w2k - ok
08:29:02.0389 3636 dac960nt - ok
08:29:02.0436 3636 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch
C:\WIND
OWS\system32\rpcss.dll
08:29:02.0436 3636 DcomLaunch - ok
08:29:02.0467 3636 [ B592AE8E6BF0F4A6E696B514D7D7008B ] DeepFrz
C:\WIND
OWS\system32\drivers\DeepFrz.sys
08:29:02.0483 3636 DeepFrz - ok
08:29:02.0483 3636 [ F9EF60B3DB03C4B8D7167D8DE5392F69 ] DfDiskLow
C:\WIND
OWS\system32\drivers\DfDiskLow.sys
08:29:02.0483 3636 DfDiskLow - ok
08:29:02.0514 3636 [ ADAAC9D42A5F8120D7F77147F773B76B ] DFFilter
C:\WIND
OWS\system32\drivers\DFFilter.sys
08:29:02.0514 3636 DFFilter - ok
08:29:02.0608 3636 [ 0E8BA855AE529B546683BCC0E3511318 ] DFServ
C:\Prog
ram Files\Faronics\Deep Freeze\Install C-0\DFServ.exe
08:29:02.0608 3636 DFServ - ok
08:29:02.0639 3636 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp
C:\WIND
OWS\System32\dhcpcsvc.dll
08:29:02.0639 3636 Dhcp - ok
08:29:02.0655 3636 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk
C:\WIND
OWS\system32\DRIVERS\disk.sys
08:29:02.0655 3636 Disk - ok
08:29:02.0701 3636 [ A53723176D0002FEB486EFF8E17812F2 ] DLABMFSM
C:\WIND
OWS\system32\DLA\DLABMFSM.SYS
08:29:02.0733 3636 DLABMFSM - ok
08:29:02.0733 3636 [ D4587063ACEA776699251E177D719586 ] DLABOIOM
C:\WIND
OWS\system32\DLA\DLABOIOM.SYS
08:29:02.0748 3636 DLABOIOM - ok
08:29:02.0764 3636 [ 5230CDB7E715F3A3B4A882E254CDD35D ] DLACDBHM
C:\WIND
OWS\system32\Drivers\DLACDBHM.SYS
08:29:02.0764 3636 DLACDBHM - ok
08:29:02.0780 3636 [ C950C2E7B9ED1A4FC4A2AC7EC044F1D6 ] DLADResM
C:\WIND
OWS\system32\DLA\DLADResM.SYS
08:29:02.0795 3636 DLADResM - ok
08:29:02.0811 3636 [ 24400137E387A24410C52A591F3CFB4D ] DLAIFS_M
C:\WIND
OWS\system32\DLA\DLAIFS_M.SYS
08:29:02.0858 3636 DLAIFS_M - ok
08:29:02.0873 3636 [ 29A303FECEB28641ECEBDAE89EB71C63 ] DLAOPIOM
C:\WIND
OWS\system32\DLA\DLAOPIOM.SYS
08:29:02.0905 3636 DLAOPIOM - ok
08:29:02.0905 3636 [ C93E33A22A1AE0C5508F3FB1F6D0A50C ] DLAPoolM
C:\WIND
OWS\system32\DLA\DLAPoolM.SYS
08:29:02.0920 3636 DLAPoolM - ok
08:29:02.0936 3636 [ 77FE51F0F8D86804CB81F6EF6BFB86DD ] DLARTL_M
C:\WIND
OWS\system32\Drivers\DLARTL_M.SYS
08:29:02.0936 3636 DLARTL_M - ok
08:29:02.0952 3636 [ B953498C35A31E5AC98F49ADBCF3E627 ] DLAUDFAM
C:\WIND
OWS\system32\DLA\DLAUDFAM.SYS
] DLAUDF_M
C:\WIND
] dmboot
C:\WIND
] dmio
C:\WIND
] dmload
C:\WIND
] dmserver
C:\WIND
] DMusic
C:\WIND
] Dnscache
C:\WIND
] Dot3svc
C:\WIND
] drmkaud
C:\WIND
] DRVMCDB
C:\WIND
] DRVNDDM
C:\WIND
] e1express
C:\WIND
] EapHost
C:\WIND
] ERSvc
C:\WIND
] Eventlog
C:\WIND
] EventSystem
C:\WIND
] FarDisk
C:\WIND
] FarSpace
C:\WIND
] Fastfat
C:\WIND
lanmanworkstation C:\WI
LightScribeService C:\P
LmHosts
C:\WIND
MDM
C:\Prog
Messenger
C:\WIND
mnmdd
C:\WIND
mnmsrvc
C:\WIND
Modem
C:\WIND
Mouclass
C:\WIND
mouhid
C:\WIND
MountMgr
C:\WIND
MpFilter
C:\WIND
MRxDAV
C:\WIND
MRxSmb
C:\WIND
MSDTC
C:\WIND
Msfs
C:\WIND
MSKSSRV
C:\WIND
MSPCLOCK
C:\WIND
MSPQM
C:\WIND
OWS\system32\drivers\MSPQM.sys
08:29:09.0217 3636 MSPQM - ok
08:29:09.0311 3636 [ AF5F4F3F14A8EA2C26DE30F7A1E17136
OWS\system32\DRIVERS\mssmbios.sys
08:29:09.0311 3636 mssmbios - ok
08:29:09.0389 3636 [ DE6A75F5C270E756C5508D94B6CF68F5
OWS\system32\drivers\Mup.sys
08:29:09.0389 3636 Mup - ok
08:29:09.0436 3636 [ 1E59AAED42A5E3A5ED86EC403F9C0776
OWS\system32\Drivers\iqvw32.sys
08:29:09.0436 3636 NAL - ok
08:29:09.0514 3636 [ 0102140028FAD045756796E1C685D695
OWS\System32\qagentrt.dll
08:29:09.0577 3636 napagent - ok
08:29:09.0608 3636 [ 1DF7F42665C94B825322FAE71721130D
OWS\system32\drivers\NDIS.sys
08:29:09.0608 3636 NDIS - ok
08:29:09.0717 3636 [ 0109C4F3850DFBAB279542515386AE22
OWS\system32\DRIVERS\ndistapi.sys
08:29:09.0717 3636 NdisTapi - ok
08:29:09.0748 3636 [ F927A4434C5028758A842943EF1A3849
OWS\system32\DRIVERS\ndisuio.sys
08:29:09.0748 3636 Ndisuio - ok
08:29:09.0795 3636 [ EDC1531A49C80614B2CFDA43CA8659AB
OWS\system32\DRIVERS\ndiswan.sys
08:29:09.0795 3636 NdisWan - ok
08:29:09.0873 3636 [ 9282BD12DFB069D3889EB3FCC1000A9B
OWS\system32\drivers\NDProxy.sys
08:29:09.0873 3636 NDProxy - ok
08:29:09.0936 3636 [ 5D81CF9A2F1A3A756B66CF684911CDF0
OWS\system32\DRIVERS\netbios.sys
08:29:09.0936 3636 NetBIOS - ok
08:29:09.0983 3636 [ 74B2B2F5BEA5E9A3DC021D685551BD3D
OWS\system32\DRIVERS\netbt.sys
08:29:09.0983 3636 NetBT - ok
08:29:10.0092 3636 [ B857BA82860D7FF85AE29B095645563B
OWS\system32\netdde.exe
08:29:10.0155 3636 NetDDE - ok
08:29:10.0186 3636 [ B857BA82860D7FF85AE29B095645563B
OWS\system32\netdde.exe
08:29:10.0186 3636 NetDDEdsdm - ok
08:29:10.0264 3636 [ BF2466B3E18E970D8A976FB95FC1CA85
OWS\system32\lsass.exe
08:29:10.0264 3636 Netlogon - ok
08:29:10.0342 3636 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE
OWS\System32\netman.dll
08:29:10.0342 3636 Netman - ok
08:29:10.0436 3636 [ D22CD77D4F0D63D1169BB35911BFF12D
NDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:29:10.0483 3636 NetTcpPortSharing - ok
08:29:10.0514 3636 [ 943337D786A56729263071623BBB9DE5
OWS\System32\mswsock.dll
08:29:10.0530 3636 Nla - ok
08:29:10.0639 3636 [ 3182D64AE053D6FB034F44B6DEF8034A
OWS\system32\drivers\Npfs.sys
08:29:10.0639 3636 Npfs - ok
08:29:10.0686 3636 [ 78A08DD6A8D65E697C18E1DB01C5CDCA
OWS\system32\drivers\Ntfs.sys
08:29:10.0686 3636 Ntfs - ok
08:29:10.0748 3636 [ BF2466B3E18E970D8A976FB95FC1CA85
] mssmbios
C:\WIND
] Mup
C:\WIND
] NAL
C:\WIND
] napagent
C:\WIND
] NDIS
C:\WIND
] NdisTapi
C:\WIND
] Ndisuio
C:\WIND
] NdisWan
C:\WIND
] NDProxy
C:\WIND
] NetBIOS
C:\WIND
] NetBT
C:\WIND
] NetDDE
C:\WIND
] NetDDEdsdm
C:\WIND
] Netlogon
C:\WIND
] Netman
C:\WIND
] NetTcpPortSharing c:\WI
] Nla
C:\WIND
] Npfs
C:\WIND
] Ntfs
C:\WIND
] NtLmSsp
C:\WIND
OWS\system32\lsass.exe
08:29:10.0748 3636 NtLmSsp - ok
08:29:10.0858 3636 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc
C:\WIND
OWS\system32\ntmssvc.dll
08:29:10.0905 3636 NtmsSvc - ok
08:29:10.0936 3636 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null
C:\WIND
OWS\system32\drivers\Null.sys
08:29:10.0936 3636 Null - ok
08:29:11.0030 3636 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt
C:\WIND
OWS\system32\DRIVERS\nwlnkflt.sys
08:29:11.0030 3636 NwlnkFlt - ok
08:29:11.0061 3636 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd
C:\WIND
OWS\system32\DRIVERS\nwlnkfwd.sys
08:29:11.0061 3636 NwlnkFwd - ok
08:29:11.0217 3636 [ 1F0E05DFF4F5A833168E49BE1256F002 ] odserv
C:\Prog
ram Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
08:29:11.0327 3636 odserv - ok
08:29:11.0358 3636 [ 5A432A042DAE460ABE7199B758E8606C ] ose
C:\Prog
ram Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:29:11.0452 3636 ose - ok
08:29:11.0514 3636 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport
C:\WIND
OWS\system32\DRIVERS\parport.sys
08:29:11.0514 3636 Parport - ok
08:29:11.0561 3636 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr
C:\WIND
OWS\system32\drivers\PartMgr.sys
08:29:11.0561 3636 PartMgr - ok
08:29:11.0655 3636 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm
C:\WIND
OWS\system32\drivers\ParVdm.sys
08:29:11.0655 3636 ParVdm - ok
08:29:11.0702 3636 [ A219903CCF74233761D92BEF471A07B1 ] PCI
C:\WIND
OWS\system32\DRIVERS\pci.sys
08:29:11.0702 3636 PCI - ok
08:29:11.0764 3636 PCIDump - ok
08:29:11.0827 3636 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde
C:\WIND
OWS\system32\DRIVERS\pciide.sys
08:29:11.0827 3636 PCIIde - ok
08:29:11.0889 3636 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia
C:\WIND
OWS\system32\drivers\Pcmcia.sys
08:29:11.0889 3636 Pcmcia - ok
08:29:11.0952 3636 PDCOMP - ok
08:29:12.0014 3636 PDFRAME - ok
08:29:12.0077 3636 PDRELI - ok
08:29:12.0139 3636 PDRFRAME - ok
08:29:12.0170 3636 perc2 - ok
08:29:12.0248 3636 perc2hib - ok
08:29:12.0467 3636 [ 3C86141E8B85694A8A23BFC6DAF46E1E ] Pharos Systems ComTaskM
aster C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
08:29:12.0467 3636 Pharos Systems ComTaskMaster - ok
08:29:12.0483 3636 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay
C:\WIND
OWS\system32\services.exe
08:29:12.0483 3636 PlugPlay - ok
08:29:12.0530 3636 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent
C:\WIND
OWS\system32\lsass.exe
08:29:12.0545 3636 PolicyAgent - ok
08:29:12.0624 3636 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport
C:\WIND
OWS\system32\DRIVERS\raspptp.sys
08:29:12.0624 3636 PptpMiniport - ok
08:29:12.0670 3636 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WIN
DOWS\system32\lsass.exe
08:29:12.0670 3636 ProtectedStorage - ok
] PSched
C:\WIND
] PSDistributionAgent C:\
] Ptilink
C:\WIND
] PxHelp20
C:\WIND
] RasAcd
C:\WIND
] RasAuto
C:\WIND
] Rasl2tp
C:\WIND
] RasMan
C:\WIND
] RasPppoe
C:\WIND
] Raspti
C:\WIND
] Rdbss
C:\WIND
] RDPCDD
C:\WIND
] rdpdr
C:\WIND
] RDPWD
C:\WIND
] RDSessMgr
C:\WIND
] redbook
C:\WIND
] RemoteAccess
C:\WIND
] RemoteRegistry C:\WIND
] RoxMediaDB9
C:\Prog
08:29:16.0405 3636 sr - ok
08:29:16.0499 3636 [ 3805DF0AC4296A34BA4BF93B346CC378
OWS\system32\srsvc.dll
08:29:16.0499 3636 srservice - ok
08:29:16.0545 3636 [ 47DDFC2F003F7F9F0592C6874962A2E7
OWS\system32\DRIVERS\srv.sys
08:29:16.0545 3636 Srv - ok
08:29:16.0624 3636 [ 0A5679B3714EDAB99E357057EE88FCA6
OWS\System32\ssdpsrv.dll
08:29:16.0655 3636 SSDPSRV - ok
08:29:16.0702 3636 [ 8BAD69CBAC032D4BBACFCE0306174C30
OWS\system32\wiaservc.dll
08:29:16.0702 3636 stisvc - ok
08:29:16.0795 3636 [ B254B1434208F280EDF3785613DCC41B
ram Files\Common Files\SureThing Shared\stllssvr.exe
08:29:16.0858 3636 stllssvr - ok
08:29:16.0905 3636 [ 3941D127AEF12E93ADDF6FE6EE027E0F
OWS\system32\DRIVERS\swenum.sys
08:29:16.0905 3636 swenum - ok
08:29:16.0983 3636 [ 8CE882BCC6CF8A62F2B2323D95CB3D01
OWS\system32\drivers\swmidi.sys
08:29:16.0983 3636 swmidi - ok
08:29:17.0014 3636 SwPrv - ok
08:29:17.0124 3636 symc810 - ok
08:29:17.0186 3636 symc8xx - ok
08:29:17.0249 3636 sym_hi - ok
08:29:17.0311 3636 sym_u3 - ok
08:29:17.0374 3636 [ 8B83F3ED0F1688B4958F77CD6D2BF290
OWS\system32\drivers\sysaudio.sys
08:29:17.0374 3636 sysaudio - ok
08:29:17.0452 3636 [ C7ABBC59B43274B1109DF6B24D617051
OWS\system32\smlogsvc.exe
08:29:17.0499 3636 SysmonLog - ok
08:29:17.0561 3636 [ 3CB78C17BB664637787C9A1C98F79C38
OWS\System32\tapisrv.dll
08:29:17.0577 3636 TapiSrv - ok
08:29:17.0639 3636 [ 9AEFA14BD6B182D61E3119FA5F436D3D
OWS\system32\DRIVERS\tcpip.sys
08:29:17.0639 3636 Tcpip - ok
08:29:17.0702 3636 [ 6471A66807F5E104E4885F5B67349397
OWS\system32\drivers\TDPIPE.sys
08:29:17.0702 3636 TDPIPE - ok
08:29:17.0780 3636 [ C56B6D0402371CF3700EB322EF3AAF61
OWS\system32\drivers\TDTCP.sys
08:29:17.0780 3636 TDTCP - ok
08:29:17.0842 3636 [ 88155247177638048422893737429D9E
OWS\system32\DRIVERS\termdd.sys
08:29:17.0842 3636 TermDD - ok
08:29:17.0920 3636 [ FF3477C03BE7201C294C35F684B3479F
OWS\System32\termsrv.dll
08:29:17.0920 3636 TermService - ok
08:29:17.0952 3636 [ 99BC0B50F511924348BE19C7C7313BBF
OWS\System32\shsvcs.dll
08:29:17.0952 3636 Themes - ok
08:29:18.0061 3636 [ DB7205804759FF62C34E3EFD8A4CC76A
OWS\system32\tlntsvr.exe
08:29:18.0092 3636 TlntSvr - ok
08:29:18.0108 3636 TosIde - ok
08:29:18.0217 3636 [ 55BCA12F7F523D35CA3CB833C725F54E
OWS\system32\trkwks.dll
] srservice
C:\WIND
] Srv
C:\WIND
] SSDPSRV
C:\WIND
] stisvc
C:\WIND
] stllssvr
C:\Prog
] swenum
C:\WIND
] swmidi
C:\WIND
] sysaudio
C:\WIND
] SysmonLog
C:\WIND
] TapiSrv
C:\WIND
] Tcpip
C:\WIND
] TDPIPE
C:\WIND
] TDTCP
C:\WIND
] TermDD
C:\WIND
] TermService
C:\WIND
] Themes
C:\WIND
] TlntSvr
C:\WIND
] TrkWks
C:\WIND
] Udfs
C:\WIND
] Update
C:\WIND
] upnphost
C:\WIND
] UPS
C:\WIND
] usbehci
C:\WIND
] usbhub
C:\WIND
] usbscan
C:\WIND
] USBSTOR
C:\WIND
] usbuhci
C:\WIND
] VgaSave
C:\WIND
] vncmirror
C:\WIND
] VolSnap
C:\WIND
] VSS
C:\WIND
] W32Time
C:\WIND
] Wanarp
C:\WIND
] wdmaud
C:\WIND
] WebClient
C:\WIND
] winmgmt
C:\WIND
] WinVNC4
C:\Prog
artition1
08:29:22.0061 3636
08:29:22.0108 3636
08:29:22.0108 3636
08:29:22.0108 3636
08:29:22.0233 3628
08:29:22.0233 3628
08:29:26.0046 3628
08:29:26.0280 3628
08:29:26.0436 3628
ured on reboot
08:29:26.0436 3628
08:29:26.0436 3628
ct action: Cure
08:29:31.0889 3308
\Device\Harddisk0\DR0\Partition1 - ok
============================================================
Scan finished
============================================================
Detected object count: 1
Actual detected object count: 1
\Device\Harddisk0\DR0\# - copied to quarantine
\Device\Harddisk0\DR0 - copied to quarantine
\Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.a ) - will be c
\Device\Harddisk0\DR0 - ok
\Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.a ) - User sele
Deinitialize success