You are on page 1of 6

2011/02/02 03:05:04.0484 2968 TDSS rootkit removing tool 2.4.16.

0 Feb 1 2011
10:34:03
2011/02/02 03:05:05.0437 2968 ================================================
================================
2011/02/02 03:05:05.0437 2968 SystemInfo:
2011/02/02 03:05:05.0437 2968
2011/02/02 03:05:05.0437 2968 OS Version: 5.1.2600 ServicePack: 2.0
2011/02/02 03:05:05.0437 2968 Product type: Workstation
2011/02/02 03:05:05.0437 2968 ComputerName: INNOA7LP00449
2011/02/02 03:05:05.0437 2968 UserName: Administrator
2011/02/02 03:05:05.0437 2968 Windows directory: C:\WINDOWS
2011/02/02 03:05:05.0437 2968 System windows directory: C:\WINDOWS
2011/02/02 03:05:05.0437 2968 Processor architecture: Intel x86
2011/02/02 03:05:05.0437 2968 Number of processors: 2
2011/02/02 03:05:05.0437 2968 Page size: 0x1000
2011/02/02 03:05:05.0437 2968 Boot type: Normal boot
2011/02/02 03:05:05.0437 2968 ================================================
================================
2011/02/02 03:05:06.0656 2968 Initialize success
2011/02/02 03:05:12.0171 3248 ================================================
================================
2011/02/02 03:05:12.0171 3248 Scan started
2011/02/02 03:05:12.0171 3248 Mode: Manual;
2011/02/02 03:05:12.0171 3248 ================================================
================================
2011/02/02 03:05:14.0093 3248 ACPI (a10c7534f7223f4a73a948967d00e69
b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/02/02 03:05:14.0109 3248 ACPIEC (9859c0f6936e723e4892d7141b1327d
5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/02/02 03:05:14.0187 3248 aec (841f385c6cfaf66b58fbd898722bb4f
0) C:\WINDOWS\system32\drivers\aec.sys
2011/02/02 03:05:14.0250 3248 AFD (55e6e1c51b6d30e5433575095545370
2) C:\WINDOWS\System32\drivers\afd.sys
2011/02/02 03:05:14.0421 3248 AsyncMac (02000abf34af4c218c35d257024807d
6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/02/02 03:05:14.0437 3248 atapi (cdfe4411a69c224bd1d11b2da92dac5
1) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/02/02 03:05:14.0484 3248 Atmarpc (ec88da854ab7d7752ec8be11a741bb7
f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/02/02 03:05:14.0531 3248 audstub (d9f724aa26c010a217c97606b160ed6
8) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/02/02 03:05:14.0578 3248 Beep (da1f27d85e0d1525f6621372e7b685e
9) C:\WINDOWS\system32\drivers\Beep.sys
2011/02/02 03:05:14.0656 3248 btaudio (b6e16da77eafe84a8c5bc44784feeae
a) C:\WINDOWS\system32\drivers\btaudio.sys
2011/02/02 03:05:14.0718 3248 BTDriver (58a49bd10e08d3d4333a60dedcb1ced
8) C:\WINDOWS\system32\DRIVERS\btport.sys
2011/02/02 03:05:14.0781 3248 BTKRNL (ef5e0de0a7ca2977a9255f36f4d915a
b) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
2011/02/02 03:05:14.0843 3248 BTWDNDIS (80f61de965c116051614ac2f04222ff
7) C:\WINDOWS\system32\DRIVERS\btwdndis.sys
2011/02/02 03:05:14.0875 3248 btwhid (e48668b4a6a5cf68b33aecad18ee8e1
e) C:\WINDOWS\system32\DRIVERS\btwhid.sys
2011/02/02 03:05:14.0921 3248 BTWUSB (053dc5be74621b63bb48c2b86bafc7b
0) C:\WINDOWS\system32\Drivers\btwusb.sys
2011/02/02 03:05:14.0953 3248 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf
9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/02/02 03:05:15.0000 3248 CCDECODE (6163ed60b684bab19d3352ab22fc48b
2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/02/02 03:05:15.0062 3248 Cdaudio (c1b486a7658353d33a10cc15211a873
b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/02/02 03:05:15.0109 3248 Cdfs (cd7d5152df32b47f4e36f710b35aae0
2) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/02/02 03:05:15.0156 3248 Cdrom (af9c19b3100fe010496b1a27181fbf7
2) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/02/02 03:05:15.0218 3248 CmBatt (4266be808f85826aedf3c64c1e24020
3) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/02/02 03:05:15.0250 3248 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f5
0) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/02/02 03:05:15.0312 3248 CVirtA (b5ecadf7708960f1818c7fa015f4c23
9) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
2011/02/02 03:05:15.0359 3248 CVPNDRVA (26deef07394624247d1f549bd94f0b1
5) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
2011/02/02 03:05:15.0421 3248 Disk (00ca44e4534865f8a3b64f7c0984bff
0) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/02/02 03:05:15.0468 3248 dmboot (c0fbb516e06e243f0cf31f597e7ebf7
d) C:\WINDOWS\system32\drivers\dmboot.sys
2011/02/02 03:05:15.0531 3248 dmio (f5e7b358a732d09f4bcf2824b88b9e2
8) C:\WINDOWS\system32\drivers\dmio.sys
2011/02/02 03:05:15.0578 3248 dmload (e9317282a63ca4d188c0df5e09c6ac5
f) C:\WINDOWS\system32\drivers\dmload.sys
2011/02/02 03:05:15.0625 3248 DMusic (a6f881284ac1150e37d9ae47ff60126
7) C:\WINDOWS\system32\drivers\DMusic.sys
2011/02/02 03:05:15.0656 3248 DNE (7b4fdfbe97c047175e613aa96f3de98
7) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/02/02 03:05:15.0703 3248 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2
e) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/02/02 03:05:15.0734 3248 EuMusDesignVirtualAudioCableWdm (c775f891e540b41
f96009d42ff205778) C:\WINDOWS\system32\DRIVERS\vrtaucbl.sys
2011/02/02 03:05:15.0796 3248 evudbus (63c8fc96b4fa09c035f23009902c7d8
d) C:\WINDOWS\system32\DRIVERS\evudbus.sys
2011/02/02 03:05:15.0828 3248 evuddiag (406f8ade42701a4e7d20d93aa7425ff
5) C:\WINDOWS\system32\DRIVERS\evuddiag.sys
2011/02/02 03:05:15.0859 3248 evudmdfl (d50fc63ca05b39438d315972ff6e825
f) C:\WINDOWS\system32\DRIVERS\evudmdfl.sys
2011/02/02 03:05:15.0890 3248 evudmdm (48b3bfb8367ed893ab374c5540e4dde
f) C:\WINDOWS\system32\DRIVERS\evudmdm.sys
2011/02/02 03:05:15.0921 3248 evudserd (e355768b4b646efb1003a5d9183be54
a) C:\WINDOWS\system32\DRIVERS\evudserd.sys
2011/02/02 03:05:15.0953 3248 Fastfat (3117f595e9615e04f05a54fc15a03b2
0) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/02/02 03:05:16.0000 3248 Fdc (ced2e8396a8838e59d8fd529c680e02
c) C:\WINDOWS\system32\drivers\Fdc.sys
2011/02/02 03:05:16.0062 3248 Fips (e153ab8a11de5452bcf5ac7652dbf3e
d) C:\WINDOWS\system32\drivers\Fips.sys
2011/02/02 03:05:16.0093 3248 Flpydisk (0dd1de43115b93f4d85e889d7a86f54
8) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/02/02 03:05:16.0140 3248 FltMgr (157754f0df355a9e0a6f54721914f9c
6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
2011/02/02 03:05:16.0187 3248 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779
a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/02/02 03:05:16.0218 3248 Ftdisk (6ac26732762483366c3969c9e4d2259
d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/02/02 03:05:16.0281 3248 Gpc (c0f1d4a21de5a415df8170616703deb
f) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/02/02 03:05:16.0328 3248 HDAudBus (3fcc124b6e08ee0e9351f717dd13693
9) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/02/02 03:05:16.0390 3248 HTTP (9f8b0f4276f618964fd118be4289b7c
d) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/02/02 03:05:16.0453 3248 i8042prt (5502b58eef7486ee6f93f3f164dcb80
8) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/02/02 03:05:16.0671 3248 ialm (1312e0141a7bd409afadd52fa565927
e) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
2011/02/02 03:05:17.0140 3248 Imapi (f8aa320c6a0409c0380e5d8a99d76ec
6) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/02/02 03:05:17.0312 3248 IntcAzAudAddService (004c80b1bdc4dd5303c89482e03
153c0) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/02/02 03:05:17.0500 3248 intelppm (279fb78702454dff2bb445f238c048d
2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/02/02 03:05:17.0531 3248 Ip6Fw (4448006b6bc60e6c027932cfc38d685
5) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
2011/02/02 03:05:17.0593 3248 IpFilterDriver (731f22ba402ee4b62748adaf6363c18
2) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/02/02 03:05:17.0625 3248 IpInIp (e1ec7f5da720b640cd8fb8424f1b14b
b) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/02/02 03:05:17.0671 3248 IpNat (b5a8e215ac29d24d60b4d1250ef05ac
e) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/02/02 03:05:17.0703 3248 IPSec (64537aa5c003a6afeee1df819062d0d
1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/02/02 03:05:17.0765 3248 IRENUM (50708daa1b1cbb7d6ac1cf8f56a2441
0) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/02/02 03:05:17.0843 3248 isapnp (e504f706ccb699c2596e9a3da1596e8
7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/02/02 03:05:17.0906 3248 Kbdclass (ebdee8a2ee5393890a1acee971c4c24
6) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/02/02 03:05:17.0953 3248 kmixer (d93cad07c5683db066b0b2d2d3790ea
d) C:\WINDOWS\system32\drivers\kmixer.sys
2011/02/02 03:05:17.0984 3248 KSecDD (674d3e5a593475915dc664331719240
3) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/02/02 03:05:18.0062 3248 mnmdd (4ae068242760a1fb6e1a44bf4e16afa
6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/02/02 03:05:18.0109 3248 Modem (6fc6f9d7acc36dca9b914565a3aeda0
5) C:\WINDOWS\system32\drivers\Modem.sys
2011/02/02 03:05:18.0140 3248 Mouclass (34e1f0031153e491910e12551400192
c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/02/02 03:05:18.0171 3248 MountMgr (65653f3b4477f3c63e68a9659f85ee2
e) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/02/02 03:05:18.0218 3248 MRxDAV (46edcc8f2db2f322c24f48785cb4636
6) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/02/02 03:05:18.0296 3248 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c3
9) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/02/02 03:05:18.0421 3248 Msfs (561b3a4333ca2dbdba28b5b95682251
9) C:\WINDOWS\system32\drivers\Msfs.sys
2011/02/02 03:05:18.0484 3248 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad
0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/02/02 03:05:18.0531 3248 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f44
8) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/02/02 03:05:18.0562 3248 MSPQM (1988a33ff19242576c3d0ef9ce785da
7) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/02/02 03:05:18.0593 3248 mssmbios (469541f8bfd2b32659d5d463a6714bc
e) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/02/02 03:05:18.0625 3248 MSTEE (bf13612142995096ab084f2db7f40f7
7) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/02/02 03:05:18.0640 3248 Mup (82035e0f41c2dd05ae41d27fe6cf7de
1) C:\WINDOWS\system32\drivers\Mup.sys
2011/02/02 03:05:18.0687 3248 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1
a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/02/02 03:05:18.0718 3248 NDIS (558635d3af1c7546d26067d5d9b6959
e) C:\WINDOWS\system32\drivers\NDIS.sys
2011/02/02 03:05:18.0750 3248 NdisIP (520ce427a8b298f54112857bcf6bde1
5) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/02/02 03:05:18.0781 3248 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4
c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/02/02 03:05:18.0843 3248 Ndisuio (34d6cd56409da9a7ed573e1c90a308b
f) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/02/02 03:05:18.0859 3248 NdisWan (0b90e255a9490166ab368cd55a52989
3) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/02/02 03:05:18.0890 3248 NDProxy (59fc3fb44d2669bc144fd87826bb571
f) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/02/02 03:05:18.0906 3248 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb
4) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/02/02 03:05:18.0968 3248 NetBT (0c80e410cd2f47134407ee7dd19cc86
b) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/02/02 03:05:19.0046 3248 nmwcd (9a908a9bb857c2cceb2907eb9dcaeb8
b) C:\WINDOWS\system32\drivers\ccdcmb.sys
2011/02/02 03:05:19.0140 3248 nmwcdc (68ec3ee2348e475ea62c66e6aafcfc9
b) C:\WINDOWS\system32\drivers\ccdcmbo.sys
2011/02/02 03:05:19.0171 3248 Npfs (4f601bcb8f64ea3ac0994f98fed03f8
e) C:\WINDOWS\system32\drivers\Npfs.sys
2011/02/02 03:05:19.0250 3248 Ntfs (b78be402c3f63dd55521f73876951cd
d) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/02/02 03:05:19.0328 3248 Null (73c1e1f395918bc2c6dd67af7591a3a
d) C:\WINDOWS\system32\drivers\Null.sys
2011/02/02 03:05:19.0359 3248 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc5
7) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/02/02 03:05:19.0390 3248 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b
9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/02/02 03:05:19.0453 3248 Parport (29744eb4ce659dfe3b4122deb45bc47
8) C:\WINDOWS\system32\drivers\Parport.sys
2011/02/02 03:05:19.0484 3248 PartMgr (3334430c29dc338092f79c38ef7b4cd
0) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/02/02 03:05:19.0515 3248 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea
1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/02/02 03:05:19.0562 3248 pccsmcfd (fd2041e9ba03db7764b2248f0247507
9) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
2011/02/02 03:05:19.0609 3248 PCI (8086d9979234b603ad5bc2f5d890b23
4) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/02/02 03:05:19.0656 3248 PCIIde (ccf5f451bb1a5a2a522a76e670000ff
0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/02/02 03:05:19.0687 3248 Pcmcia (82a087207decec8456fbe8537947d57
9) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/02/02 03:05:19.0828 3248 PptpMiniport (1c5cc65aac0783c344f16353e60b72a
c) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/02/02 03:05:19.0859 3248 PSched (48671f327553dcf1d27f6197f622a66
8) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/02/02 03:05:19.0890 3248 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cad
d) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/02/02 03:05:19.0984 3248 RasAcd (fe0d99d6f31e4fad8159f690d68ded9
c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/02/02 03:05:20.0015 3248 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115
c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/02/02 03:05:20.0046 3248 RasPppoe (7306eeed8895454cbed4669be9f79fa
a) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/02/02 03:05:20.0062 3248 Raspti (fdbb1d60066fcfbb7452fd8f9829b24
2) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/02/02 03:05:20.0125 3248 Rdbss (29d66245adba878fff574cd66abd288
4) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/02/02 03:05:20.0156 3248 RDPCDD (4912d5b403614ce99c28420f7535333
2) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/02/02 03:05:20.0203 3248 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4a
d) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/02/02 03:05:20.0281 3248 RDPWD (d4f5643d7714ef499ae9527fdcd5089
4) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/02/02 03:05:20.0343 3248 redbook (b31b4588e4086d8d84adbf9845c2402
b) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/02/02 03:05:20.0421 3248 RTLE8023xp (b52b25f41bf3511071a0e7d10d659c5
6) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
2011/02/02 03:05:20.0500 3248 Secdrv (d26e26ea516450af9d072635c60387f
4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/02/02 03:05:20.0546 3248 Serial (cd9404d115a00d249f70a371b46d5a2
6) C:\WINDOWS\system32\drivers\Serial.sys
2011/02/02 03:05:20.0609 3248 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe
0) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/02/02 03:05:20.0656 3248 SLIP (5caeed86821fa2c6139e32e9e05ccdc
9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/02/02 03:05:20.0734 3248 splitter (8e186b8f23295d1e42c573b82b80d54
8) C:\WINDOWS\system32\drivers\splitter.sys
2011/02/02 03:05:20.0765 3248 sr (e41b6d037d6cd08461470af04500dc2
4) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/02/02 03:05:20.0828 3248 Srv (7a4f147cc6b133f905f6e65e2f8669f
b) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/02/02 03:05:20.0921 3248 streamip (284c57df5dc7abca656bc2b96a667af
b) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/02/02 03:05:20.0953 3248 swenum (03c1bae4766e2450219d20b993d6e04
6) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/02/02 03:05:20.0984 3248 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4
d) C:\WINDOWS\system32\drivers\swmidi.sys
2011/02/02 03:05:21.0203 3248 SynTP (d7b9ad3abd0f7f9f694d71f38b5c7b7
2) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/02/02 03:05:21.0312 3248 sysaudio (650ad082d46bac0e64c9c0e0928492f
d) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/02/02 03:05:21.0390 3248 Tcpip (2a5554fc5b1e04e131230e3ce035c3f
9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/02/02 03:05:21.0468 3248 TDPIPE (38d437cf2d98965f239b0abcd66dcb0
f) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/02/02 03:05:21.0500 3248 TDTCP (ed0580af02502d00ad8c4c066b156be
9) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/02/02 03:05:21.0546 3248 TermDD (a540a99c281d933f3d69d55e48727f4
7) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/02/02 03:05:21.0609 3248 tmactmon (b5ec8e61d853608c1bffc91d30c41e2
4) C:\WINDOWS\system32\drivers\tmactmon.sys
2011/02/02 03:05:21.0656 3248 tmcomm (d07ec8864cb7a64c4b10eff73b1220e
a) C:\WINDOWS\system32\drivers\tmcomm.sys
2011/02/02 03:05:21.0671 3248 tmevtmgr (041ddb7cd256edaa24aa6327fd5a1b2
e) C:\WINDOWS\system32\drivers\tmevtmgr.sys
2011/02/02 03:05:21.0781 3248 TmFilter (ac940a15959be57958b91cdb914aaa6
c) C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys
2011/02/02 03:05:21.0812 3248 TmPreFilter (8651a867c78bd2b69f1d5f982138a07
4) C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys
2011/02/02 03:05:21.0859 3248 tmtdi (50453bc5ba46c6ae2f85fa124a59da2
e) C:\WINDOWS\system32\DRIVERS\tmtdi.sys
2011/02/02 03:05:21.0921 3248 Udfs (12f70256f140cd7d52c58c7048fde65
7) C:\WINDOWS\system32\drivers\Udfs.sys
2011/02/02 03:05:21.0968 3248 Update (aff2e5045961bbc0a602bb6f95eb134
5) C:\WINDOWS\system32\DRIVERS\update.sys
2011/02/02 03:05:22.0031 3248 upperdev (a34560a5d516a2f5240180370866b99
d) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
2011/02/02 03:05:22.0093 3248 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f7
9) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/02/02 03:05:22.0125 3248 usbehci (15e993ba2f6946b2bfbbfcd30398621
e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/02/02 03:05:22.0156 3248 usbhub (c72f40947f92cea56a8fb532edf025f
1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/02/02 03:05:22.0218 3248 usbser (49106ee29074e6a3d3ac9e24c6d791d
8) C:\WINDOWS\system32\drivers\usbser.sys
2011/02/02 03:05:22.0265 3248 UsbserFilt (6410eebd6e0427466812858ee84c846
7) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
2011/02/02 03:05:22.0296 3248 usbstor (6cd7b22193718f1d17a47a1cd6d37e7
5) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/02/02 03:05:22.0359 3248 usbuhci (f8fd1400092e23c8f2f31406ef06167
b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/02/02 03:05:22.0390 3248 usbvideo (8968ff3973a883c49e8b564200f565b
9) C:\WINDOWS\system32\Drivers\usbvideo.sys
2011/02/02 03:05:22.0453 3248 VgaSave (8a60edd72b4ea5aea8202daf0e42792
5) C:\WINDOWS\System32\drivers\vga.sys
2011/02/02 03:05:22.0515 3248 VolSnap (ee4660083deba849ff6c485d944b379
b) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/02/02 03:05:22.0656 3248 VSApiNt (71a53597bfb4bad7218ad2beaba5c56
4) C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys
2011/02/02 03:05:22.0750 3248 vsdatant (27b3dd12a19eec50220df15b64913dd
a) C:\WINDOWS\system32\vsdatant.sys
2011/02/02 03:05:22.0828 3248 Wanarp (984ef0b9788abf89974cfed4bfbaacb
c) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/02/02 03:05:22.0890 3248 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fd
c) C:\WINDOWS\system32\Drivers\wdf01000.sys
2011/02/02 03:05:23.0000 3248 wdmaud (2797f33ebf50466020c430ee4f03793
3) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/02/02 03:05:23.0093 3248 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce
8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/02/02 03:05:23.0156 3248 WSTCODEC (d5842484f05e12121c511aa93f6439e
c) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/02/02 03:05:23.0218 3248 WudfPf (50eb9e21963b4f06fd010d007d54351
b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/02/02 03:05:23.0281 3248 WudfRd (6e209664bdea8a15b5e8e480d6c607c
2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/02/02 03:05:23.0359 3248 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0
)
2011/02/02 03:05:23.0359 3248 ================================================
================================
2011/02/02 03:05:23.0359 3248 Scan finished
2011/02/02 03:05:23.0359 3248 ================================================
================================
2011/02/02 03:05:23.0375 1748 Detected object count: 1
2011/02/02 03:05:36.0718 1748 \HardDisk0 - will be cured after reboot
2011/02/02 03:05:36.0718 1748 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User selec
t action: Cure
2011/02/02 03:05:40.0859 0548 Deinitialize success