You are on page 1of 10

2011/03/27 15:27:25.0710 4304 TDSS rootkit removing tool 2.4.21.

0 Mar 10 2011
12:26:28
2011/03/27 15:27:26.0209 4304 ================================================
================================
2011/03/27 15:27:26.0209 4304 SystemInfo:
2011/03/27 15:27:26.0209 4304
2011/03/27 15:27:26.0209 4304 OS Version: 6.1.7600 ServicePack: 0.0
2011/03/27 15:27:26.0209 4304 Product type: Workstation
2011/03/27 15:27:26.0209 4304 ComputerName: SUSAN-PC
2011/03/27 15:27:26.0209 4304 UserName: Susan
2011/03/27 15:27:26.0209 4304 Windows directory: C:\windows
2011/03/27 15:27:26.0209 4304 System windows directory: C:\windows
2011/03/27 15:27:26.0209 4304 Running under WOW64
2011/03/27 15:27:26.0209 4304 Processor architecture: Intel x64
2011/03/27 15:27:26.0209 4304 Number of processors: 2
2011/03/27 15:27:26.0209 4304 Page size: 0x1000
2011/03/27 15:27:26.0209 4304 Boot type: Normal boot
2011/03/27 15:27:26.0209 4304 ================================================
================================
2011/03/27 15:27:26.0568 4304 Initialize success
2011/03/27 15:27:28.0783 2504 ================================================
================================
2011/03/27 15:27:28.0783 2504 Scan started
2011/03/27 15:27:28.0783 2504 Mode: Manual;
2011/03/27 15:27:28.0783 2504 ================================================
================================
2011/03/27 15:27:29.0438 2504 1394ohci
(1b00662092f9f9568b995902f0cc40d
5) C:\windows\system32\DRIVERS\1394ohci.sys
2011/03/27 15:27:29.0812 2504 ACPI
(6f11e88748cdefd2f76aa215f97ddfe
5) C:\windows\system32\DRIVERS\ACPI.sys
2011/03/27 15:27:30.0187 2504 AcpiPmi
(63b05a0420ce4bf0e4af6dcc7cada25
4) C:\windows\system32\DRIVERS\acpipmi.sys
2011/03/27 15:27:30.0577 2504 adp94xx
(2f6b34b83843f0c5118b63ac634f5bf
4) C:\windows\system32\DRIVERS\adp94xx.sys
2011/03/27 15:27:30.0951 2504 adpahci
(597f78224ee9224ea1a13d6350ced96
2) C:\windows\system32\DRIVERS\adpahci.sys
2011/03/27 15:27:31.0310 2504 adpu320
(e109549c90f62fb570b9540c4b148e5
4) C:\windows\system32\DRIVERS\adpu320.sys
2011/03/27 15:27:31.0747 2504 AFD
(b9384e03479d2506bc924c16a3db87b
c) C:\windows\system32\drivers\afd.sys
2011/03/27 15:27:32.0137 2504 agp440
(608c14dba7299d8cb6ed035a68a1579
9) C:\windows\system32\DRIVERS\agp440.sys
2011/03/27 15:27:32.0511 2504 aliide
(5812713a477a3ad7363c7438ca2ee03
8) C:\windows\system32\DRIVERS\aliide.sys
2011/03/27 15:27:33.0104 2504 amdide
(1ff8b4431c353ce385c875f194924c0
c) C:\windows\system32\DRIVERS\amdide.sys
2011/03/27 15:27:33.0478 2504 AmdK8
(7024f087cff1833a806193ef9d22cda
9) C:\windows\system32\DRIVERS\amdk8.sys
2011/03/27 15:27:33.0837 2504 AmdPPM
(1e56388b3fe0d031c44144eb8c4d621
7) C:\windows\system32\DRIVERS\amdppm.sys
2011/03/27 15:27:34.0196 2504 amdsata
(7a4b413614c055935567cf88a9734d3
8) C:\windows\system32\DRIVERS\amdsata.sys
2011/03/27 15:27:34.0570 2504 amdsbs
(f67f933e79241ed32ff46a4f29b5120
b) C:\windows\system32\DRIVERS\amdsbs.sys
2011/03/27 15:27:34.0945 2504 amdxata
(b4ad0cacbab298671dd6f6ef7e20679
d) C:\windows\system32\DRIVERS\amdxata.sys
2011/03/27 15:27:35.0335 2504 AppID
(42fd751b27fa0e9c69bb39f39e40959
4) C:\windows\system32\drivers\appid.sys
2011/03/27 15:27:35.0740 2504 arc
(c484f8ceb1717c540242531db7845c4
e) C:\windows\system32\DRIVERS\arc.sys

2011/03/27 15:27:36.0130 2504 arcsas


(019af6924aefe7839f61c830227fe79
c) C:\windows\system32\DRIVERS\arcsas.sys
2011/03/27 15:27:36.0520 2504 AsyncMac
(769765ce2cc62867468cea93969b224
2) C:\windows\system32\DRIVERS\asyncmac.sys
2011/03/27 15:27:36.0895 2504 atapi
(02062c0b390b7729edc9e69c680a6f3
c) C:\windows\system32\DRIVERS\atapi.sys
2011/03/27 15:27:37.0316 2504 b06bdrv
(3e5b191307609f7514148c6832bb084
2) C:\windows\system32\DRIVERS\bxvbda.sys
2011/03/27 15:27:37.0706 2504 b57nd60a
(b5ace6968304a3900eeb1ebfd9622df
2) C:\windows\system32\DRIVERS\b57nd60a.sys
2011/03/27 15:27:38.0096 2504 Beep
(16a47ce2decc9b099349a5f84065474
6) C:\windows\system32\drivers\Beep.sys
2011/03/27 15:27:38.0517 2504 blbdrive
(61583ee3c3a17003c4acd0475646b4d
3) C:\windows\system32\DRIVERS\blbdrive.sys
2011/03/27 15:27:38.0860 2504 bowser
(91ce0d3dc57dd377e690a2d324022b0
8) C:\windows\system32\DRIVERS\bowser.sys
2011/03/27 15:27:39.0235 2504 BrFiltLo
(f09eee9edc320b5e1501f749fde686c
8) C:\windows\system32\DRIVERS\BrFiltLo.sys
2011/03/27 15:27:39.0578 2504 BrFiltUp
(b114d3098e9bdb8bea8b053685831be
6) C:\windows\system32\DRIVERS\BrFiltUp.sys
2011/03/27 15:27:39.0952 2504 Brserid
(43bea8d483bf1870f018e2d02e06a5b
d) C:\windows\System32\Drivers\Brserid.sys
2011/03/27 15:27:40.0296 2504 BrSerWdm
(a6eca2151b08a09caceca35c07f05b4
2) C:\windows\System32\Drivers\BrSerWdm.sys
2011/03/27 15:27:40.0670 2504 BrUsbMdm
(b79968002c277e869cf38bd22cd6152
4) C:\windows\System32\Drivers\BrUsbMdm.sys
2011/03/27 15:27:41.0013 2504 BrUsbSer
(a87528880231c54e75ea7a44943b38b
f) C:\windows\System32\Drivers\BrUsbSer.sys
2011/03/27 15:27:41.0388 2504 BTHMODEM
(9da669f11d1f894ab4eb69bf546a42e
8) C:\windows\system32\DRIVERS\bthmodem.sys
2011/03/27 15:27:41.0793 2504 CAXHWAZL
(d1787e11c6a0078ddeaf8cf3ee2ab29
3) C:\windows\system32\DRIVERS\CAXHWAZL.sys
2011/03/27 15:27:42.0136 2504 cdfs
(b8bd2bb284668c84865658c77574381
a) C:\windows\system32\DRIVERS\cdfs.sys
2011/03/27 15:27:42.0526 2504 cdrom
(83d2d75e1efb81b3450c18131443f7d
b) C:\windows\system32\DRIVERS\cdrom.sys
2011/03/27 15:27:42.0916 2504 cfwids
(e02c9cdb15f13de4eb2ff67660e6231
7) C:\windows\system32\drivers\cfwids.sys
2011/03/27 15:27:43.0291 2504 circlass
(d7cd5c4e1b71fa62050515314cfb52c
f) C:\windows\system32\DRIVERS\circlass.sys
2011/03/27 15:27:43.0556 2504 CLFS
(fe1ec06f2253f691fe36217c592a020
6) C:\windows\system32\CLFS.sys
2011/03/27 15:27:43.0962 2504 CmBatt
(0840155d0bddf1190f84a663c284bd3
3) C:\windows\system32\DRIVERS\CmBatt.sys
2011/03/27 15:27:44.0320 2504 cmdide
(e19d3f095812725d88f9001985b94ed
d) C:\windows\system32\DRIVERS\cmdide.sys
2011/03/27 15:27:44.0679 2504 CNG
(f95fd4cb7da00ba2a63ce9f6b5c053e
1) C:\windows\system32\Drivers\cng.sys
2011/03/27 15:27:45.0069 2504 CnxtHdAudService (25c58ee97be0416a373e3e4f855206
b5) C:\windows\system32\drivers\CHDRT64.sys
2011/03/27 15:27:45.0459 2504 Compbatt
(102de219c3f61415f964c88e9085ad1
4) C:\windows\system32\DRIVERS\compbatt.sys
2011/03/27 15:27:45.0818 2504 CompositeBus
(f26b3a86f6fa87ca360b879581ab412
3) C:\windows\system32\DRIVERS\CompositeBus.sys
2011/03/27 15:27:46.0192 2504 crcdisk
(1c827878a998c18847245fe1f34ee59
7) C:\windows\system32\DRIVERS\crcdisk.sys
2011/03/27 15:27:46.0629 2504 DfsC
(3f1dc527070acb87e40afe46ef6da74
9) C:\windows\system32\Drivers\dfsc.sys
2011/03/27 15:27:46.0988 2504 discache
(13096b05847ec78f0977f2c0f79e9ab
3) C:\windows\system32\drivers\discache.sys

2011/03/27 15:27:47.0378 2504 Disk


c) C:\windows\system32\DRIVERS\disk.sys
2011/03/27 15:27:47.0784 2504 drmkaud
4) C:\windows\system32\drivers\drmkaud.sys
2011/03/27 15:27:48.0174 2504 DXGKrnl
f) C:\windows\System32\drivers\dxgkrnl.sys
2011/03/27 15:27:48.0595 2504 ebdrv
f) C:\windows\system32\DRIVERS\evbda.sys
2011/03/27 15:27:49.0016 2504 elxstor
4) C:\windows\system32\DRIVERS\elxstor.sys
2011/03/27 15:27:49.0359 2504 ErrDev
b) C:\windows\system32\DRIVERS\errdev.sys
2011/03/27 15:27:49.0749 2504 exfat
b) C:\windows\system32\drivers\exfat.sys
2011/03/27 15:27:50.0092 2504 fastfat
d) C:\windows\system32\drivers\fastfat.sys
2011/03/27 15:27:50.0467 2504 fdc
b) C:\windows\system32\DRIVERS\fdc.sys
2011/03/27 15:27:50.0857 2504 FileInfo
0) C:\windows\system32\drivers\fileinfo.sys
2011/03/27 15:27:51.0200 2504 Filetrace
7) C:\windows\system32\drivers\filetrace.sys
2011/03/27 15:27:51.0559 2504 flpydisk
5) C:\windows\system32\DRIVERS\flpydisk.sys
2011/03/27 15:27:51.0933 2504 FltMgr
9) C:\windows\system32\drivers\fltmgr.sys
2011/03/27 15:27:52.0292 2504 FsDepends
c) C:\windows\system32\drivers\FsDepends.sys
2011/03/27 15:27:52.0635 2504 Fs_Rec
2) C:\windows\system32\drivers\Fs_Rec.sys
2011/03/27 15:27:53.0010 2504 fvevol
d) C:\windows\system32\DRIVERS\fvevol.sys
2011/03/27 15:27:53.0353 2504 gagp30kx
6) C:\windows\system32\DRIVERS\gagp30kx.sys
2011/03/27 15:27:53.0696 2504 hcw85cir
0) C:\windows\system32\drivers\hcw85cir.sys
2011/03/27 15:27:54.0070 2504 HdAudAddService
2) C:\windows\system32\drivers\HdAudio.sys
2011/03/27 15:27:54.0460 2504 HDAudBus
b) C:\windows\system32\DRIVERS\HDAudBus.sys
2011/03/27 15:27:54.0819 2504 HidBatt
f) C:\windows\system32\DRIVERS\HidBatt.sys
2011/03/27 15:27:55.0162 2504 HidBth
4) C:\windows\system32\DRIVERS\hidbth.sys
2011/03/27 15:27:55.0521 2504 HidIr
5) C:\windows\system32\DRIVERS\hidir.sys
2011/03/27 15:27:55.0911 2504 HidUsb
f) C:\windows\system32\DRIVERS\hidusb.sys
2011/03/27 15:27:56.0270 2504 HpSAMD
4) C:\windows\system32\DRIVERS\HpSAMD.sys
2011/03/27 15:27:56.0676 2504 HSF_DPV
4) C:\windows\system32\DRIVERS\CAX_DPV.sys
2011/03/27 15:27:57.0050 2504 HTTP
4) C:\windows\system32\drivers\HTTP.sys
2011/03/27 15:27:57.0409 2504 hwpolicy
9) C:\windows\system32\drivers\hwpolicy.sys
2011/03/27 15:27:57.0783 2504 i8042prt
3) C:\windows\system32\DRIVERS\i8042prt.sys
2011/03/27 15:27:58.0158 2504 iaStor
1) C:\windows\system32\DRIVERS\iaStor.sys

(9819eee8b5ea3784ec4af3b137a5244
(9b19f34400d24df84c858a421c20575
(1633b9abf52784a1331476397a48cbe
(dc5d737f51be844d8c82c695eb17372
(0e5da5369a0fcaea12456dd85254518
(34a3c54752046e79a126e15c51db409
(a510c654ec00c1e9bdd91eeb3a59823
(0adc83218b66a6db380c330836f3e36
(d765d19cd8ef61f650c384f62fac00a
(655661be46b5f5f3fd454e2c3095b93
(5f671ab5bc87eea04ec38a6cd5962a4
(c172a0f53008eaeb8ea33fe10e177af
(f7866af72abbaf84b1fa5aa195378c5
(d43703496149971890703b4b1b723ea
(e95ef8547de20cf0603557c0cf7a946
(ae87ba80d0ec3b57126ed2cdc15b24e
(8c778d335c9d272cfd3298ab02abe3b
(f2523ef6460fc42405b12248338ab2f
(6410f6f415b2a5a9037224c41da8bf1
(0a49913402747a0b67de940fb42cbdb
(78e86380454a7b10a5eb255dc44a355
(7fd2a313f7afe5c4dab14798c48dd10
(0a77d29f311b88cfae3b13f9c1a7382
(b3bf6b5b50006def50b66306d99fcf6
(0886d440058f203eba0e1825e435591
(26c5d00321937e49b6bc91029947d09
(cee049cac4efa7f4e1e4ad014414a5d
(f17766a19145f111856378df337a5d7
(fa55c73d4affa7ee23ac4be53b4592d
(be7d72fcf442c26975942007e083124

2011/03/27 15:27:58.0548 2504 iaStorV


0) C:\windows\system32\DRIVERS\iaStorV.sys
2011/03/27 15:27:59.0125 2504 igfx
4) C:\windows\system32\DRIVERS\igdkmd64.sys
2011/03/27 15:27:59.0530 2504 iirsp
1) C:\windows\system32\DRIVERS\iirsp.sys
2011/03/27 15:27:59.0889 2504 intelide
a) C:\windows\system32\DRIVERS\intelide.sys
2011/03/27 15:28:00.0264 2504 intelppm
1) C:\windows\system32\DRIVERS\intelppm.sys
2011/03/27 15:28:00.0622 2504 IpFilterDriver
5) C:\windows\system32\DRIVERS\ipfltdrv.sys
2011/03/27 15:28:00.0981 2504 IPMIDRV
5) C:\windows\system32\DRIVERS\IPMIDrv.sys
2011/03/27 15:28:01.0324 2504 IPNAT
0) C:\windows\system32\drivers\ipnat.sys
2011/03/27 15:28:01.0714 2504 IRENUM
9) C:\windows\system32\drivers\irenum.sys
2011/03/27 15:28:02.0058 2504 isapnp
8) C:\windows\system32\DRIVERS\isapnp.sys
2011/03/27 15:28:02.0416 2504 iScsiPrt
1) C:\windows\system32\DRIVERS\msiscsi.sys
2011/03/27 15:28:02.0791 2504 kbdclass
5) C:\windows\system32\DRIVERS\kbdclass.sys
2011/03/27 15:28:03.0165 2504 kbdhid
3) C:\windows\system32\DRIVERS\kbdhid.sys
2011/03/27 15:28:03.0540 2504 KSecDD
7) C:\windows\system32\Drivers\ksecdd.sys
2011/03/27 15:28:03.0898 2504 KSecPkg
5) C:\windows\system32\Drivers\ksecpkg.sys
2011/03/27 15:28:04.0273 2504 ksthunk
4) C:\windows\system32\drivers\ksthunk.sys
2011/03/27 15:28:04.0647 2504 L1C
1) C:\windows\system32\DRIVERS\L1C62x64.sys
2011/03/27 15:28:05.0037 2504 lltdio
7) C:\windows\system32\DRIVERS\lltdio.sys
2011/03/27 15:28:05.0443 2504 LSI_FC
6) C:\windows\system32\DRIVERS\lsi_fc.sys
2011/03/27 15:28:05.0817 2504 LSI_SAS
0) C:\windows\system32\DRIVERS\lsi_sas.sys
2011/03/27 15:28:06.0192 2504 LSI_SAS2
3) C:\windows\system32\DRIVERS\lsi_sas2.sys
2011/03/27 15:28:06.0582 2504 LSI_SCSI
a) C:\windows\system32\DRIVERS\lsi_scsi.sys
2011/03/27 15:28:06.0956 2504 luafv
e) C:\windows\system32\drivers\luafv.sys
2011/03/27 15:28:07.0330 2504 MBAMProtector
2) C:\windows\system32\drivers\mbam.sys
2011/03/27 15:28:07.0830 2504 mdmxsdk
6) C:\windows\system32\DRIVERS\mdmxsdk.sys
2011/03/27 15:28:08.0173 2504 megasas
4) C:\windows\system32\DRIVERS\megasas.sys
2011/03/27 15:28:08.0547 2504 MegaSR
3) C:\windows\system32\DRIVERS\MegaSR.sys
2011/03/27 15:28:08.0922 2504 mfeapfk
d) C:\windows\system32\drivers\mfeapfk.sys
2011/03/27 15:28:09.0265 2504 mfeavfk
6) C:\windows\system32\drivers\mfeavfk.sys
2011/03/27 15:28:10.0029 2504 mfefirek
0) C:\windows\system32\drivers\mfefirek.sys

(d83efb6fd45df9d55e9a1afc63640d5
(898ab5bfed7040d7ab07af01885eb94
(5c18831c61933628f5bb0ea2675b9d2
(f00f20e70c6ec3aa366910083a0518a
(ada036632c664caa754079041cf1f8c
(722dd294df62483cecaae6e094b4d69
(e2b4a4494db7cb9b89b55ca268c337c
(af9b39a7e7b6caa203b3862582e9f2d
(3abf5e7213eb28966d55d58b515d5ce
(2f7b28dc3e1183e5eb418df55c204f3
(fa4d2557de56d45b0a346f93564be6e
(bc02336f1cba7dcc7d1213bb588a68a
(6def98f8541e1b5dceb2c822a11f732
(e8b6fcc9c83535c67f835d407620bd2
(a8c63880ef6f4d3fec7b616b9c06021
(6869281e78cb31a43e969f06b57347c
(55480b9c63f3f91a8ebbadcbf28fe58
(1538831cf8ad2979a04c42377946582
(1a93e54eb0ece102495a51266dcdb6a
(1047184a9fdc8bdbff857175875ee81
(30f5c0de1ee8b5bc9306c1f0e4a75f9
(0504eacaff0d3c8aed161c4b0d369d4
(43d0f98e1d56ccddb0d5254cff7b356
(3d3c4b63f11f63f50253e734f0ace9f
(e4f44ec214b3e381e1fc844a0292666
(a55805f747c6edb6a9080d7c633bd0f
(baf74ce0072480c3b6b7c13b2a94d6b
(c1556ca9695fcd6bbd23d75d402fd43
(8857ee8b49f3338fc1fad476bfcca14
(19c44295f6bf085c83352d48397f787

2011/03/27 15:28:10.0388 2504 mfehidk


a) C:\windows\system32\drivers\mfehidk.sys
2011/03/27 15:28:10.0778 2504 mfenlfk
1) C:\windows\system32\DRIVERS\mfenlfk.sys
2011/03/27 15:28:11.0168 2504 mferkdet
a) C:\windows\system32\drivers\mferkdet.sys
2011/03/27 15:28:11.0542 2504 mfewfpk
0) C:\windows\system32\drivers\mfewfpk.sys
2011/03/27 15:28:11.0932 2504 Modem
7) C:\windows\system32\drivers\modem.sys
2011/03/27 15:28:12.0291 2504 monitor
a) C:\windows\system32\DRIVERS\monitor.sys
2011/03/27 15:28:12.0681 2504 mouclass
9) C:\windows\system32\DRIVERS\mouclass.sys
2011/03/27 15:28:13.0040 2504 mouhid
6) C:\windows\system32\DRIVERS\mouhid.sys
2011/03/27 15:28:13.0383 2504 mountmgr
1) C:\windows\system32\drivers\mountmgr.sys
2011/03/27 15:28:13.0742 2504 mpio
a) C:\windows\system32\DRIVERS\mpio.sys
2011/03/27 15:28:14.0101 2504 mpsdrv
f) C:\windows\system32\drivers\mpsdrv.sys
2011/03/27 15:28:14.0460 2504 MRxDAV
c) C:\windows\system32\drivers\mrxdav.sys
2011/03/27 15:28:14.0787 2504 mrxsmb
8) C:\windows\system32\DRIVERS\mrxsmb.sys
2011/03/27 15:28:15.0146 2504 mrxsmb10
c) C:\windows\system32\DRIVERS\mrxsmb10.sys
2011/03/27 15:28:15.0489 2504 mrxsmb20
1) C:\windows\system32\DRIVERS\mrxsmb20.sys
2011/03/27 15:28:15.0832 2504 msahci
7) C:\windows\system32\DRIVERS\msahci.sys
2011/03/27 15:28:16.0191 2504 msdsm
0) C:\windows\system32\DRIVERS\msdsm.sys
2011/03/27 15:28:16.0581 2504 Msfs
6) C:\windows\system32\drivers\Msfs.sys
2011/03/27 15:28:16.0924 2504 mshidkmdf
6) C:\windows\System32\drivers\mshidkmdf.sys
2011/03/27 15:28:17.0268 2504 msisadrv
d) C:\windows\system32\DRIVERS\msisadrv.sys
2011/03/27 15:28:17.0704 2504 MSKSSRV
6) C:\windows\system32\drivers\MSKSSRV.sys
2011/03/27 15:28:18.0079 2504 MSPCLOCK
3) C:\windows\system32\drivers\MSPCLOCK.sys
2011/03/27 15:28:18.0453 2504 MSPQM
0) C:\windows\system32\drivers\MSPQM.sys
2011/03/27 15:28:18.0812 2504 MsRPC
4) C:\windows\system32\drivers\MsRPC.sys
2011/03/27 15:28:19.0171 2504 mssmbios
8) C:\windows\system32\DRIVERS\mssmbios.sys
2011/03/27 15:28:19.0545 2504 MSTEE
9) C:\windows\system32\drivers\MSTEE.sys
2011/03/27 15:28:19.0888 2504 MTConfig
d) C:\windows\system32\DRIVERS\MTConfig.sys
2011/03/27 15:28:20.0247 2504 Mup
8) C:\windows\system32\Drivers\mup.sys
2011/03/27 15:28:20.0637 2504 NativeWifiP
3) C:\windows\system32\DRIVERS\nwifi.sys
2011/03/27 15:28:21.0090 2504 NDIS
c) C:\windows\system32\drivers\ndis.sys

(5f915e20ab56121c41c6bf9a91a83bd
(23ae332e32ff615ca5e5224c8d91af1
(9c7a9273e345f8d653394b5c542bf86
(3140b2c56d7119ba314f68fc785683f
(800ba92f7010378b09f9ed9270f0713
(b03d591dc7da45ece20b3b467e6aada
(7d27ea49f3c1f687d357e77a470aea9
(d3bf052c40b0c4166d9fd86a4288c1e
(791af66c4d0e7c90a3646066386fb57
(609d1d87649ecc19796f4d76d4c15ce
(6c38c9e45ae0ea2fa5e551f2ed5e978
(30524261bb51d96d6fcbac20c810183
(767a4c3bcf9410c286ced15a2db1710
(920ee0ff995fcfdeb08c41605a959e1
(740d7ea9d72c981510a5292cf6adc94
(5c37497276e3b3a5488b23a326a754b
(8d27b597229aed79430fb9db3bcbfbd
(aa3fb40e17ce1388fa1bedab50ea8f9
(f9d215a46a8b9753f61767fa72a2032
(d916874bbd4f8b07bfb7fa9b3ccae29
(49ccf2c4fea34ffad8b1b59d4943936
(bdd71ace35a232104ddd349ee70e1ab
(4ed981241db27c3383d72092b618a1d
(89cb141aa8616d8c6a4610fa26c6096
(0eed230e37515a0eaee3c2e1bc97b28
(2e66f9ecb30b4221a318c92ac225077
(7ea404308934e675bffde8edf0757bc
(f9a18612fd3526fe473c1bda678d61c
(1ea3749c4114db3e3161156ffffa6b3
(cad515dbd07d082bb317d9928ce8962

2011/03/27 15:28:21.0448 2504 NdisCap


c) C:\windows\system32\DRIVERS\ndiscap.sys
2011/03/27 15:28:21.0807 2504 NdisTapi
5) C:\windows\system32\DRIVERS\ndistapi.sys
2011/03/27 15:28:22.0182 2504 Ndisuio
c) C:\windows\system32\DRIVERS\ndisuio.sys
2011/03/27 15:28:22.0540 2504 NdisWan
3) C:\windows\system32\DRIVERS\ndiswan.sys
2011/03/27 15:28:22.0915 2504 NDProxy
f) C:\windows\system32\drivers\NDProxy.sys
2011/03/27 15:28:23.0289 2504 NetBIOS
4) C:\windows\system32\DRIVERS\netbios.sys
2011/03/27 15:28:23.0648 2504 NetBT
a) C:\windows\system32\DRIVERS\netbt.sys
2011/03/27 15:28:24.0038 2504 nfrd960
2) C:\windows\system32\DRIVERS\nfrd960.sys
2011/03/27 15:28:24.0428 2504 Npfs
7) C:\windows\system32\drivers\Npfs.sys
2011/03/27 15:28:24.0771 2504 nsiproxy
1) C:\windows\system32\drivers\nsiproxy.sys
2011/03/27 15:28:25.0177 2504 Ntfs
6) C:\windows\system32\drivers\Ntfs.sys
2011/03/27 15:28:25.0551 2504 Null
1) C:\windows\system32\drivers\Null.sys
2011/03/27 15:28:25.0941 2504 nvraid
d) C:\windows\system32\DRIVERS\nvraid.sys
2011/03/27 15:28:26.0331 2504 nvstor
1) C:\windows\system32\DRIVERS\nvstor.sys
2011/03/27 15:28:26.0659 2504 nv_agp
5) C:\windows\system32\DRIVERS\nv_agp.sys
2011/03/27 15:28:27.0033 2504 ohci1394
0) C:\windows\system32\DRIVERS\ohci1394.sys
2011/03/27 15:28:27.0439 2504 Parport
7) C:\windows\system32\DRIVERS\parport.sys
2011/03/27 15:28:27.0782 2504 partmgr
0) C:\windows\system32\drivers\partmgr.sys
2011/03/27 15:28:28.0156 2504 pci
b) C:\windows\system32\DRIVERS\pci.sys
2011/03/27 15:28:28.0515 2504 pciide
a) C:\windows\system32\DRIVERS\pciide.sys
2011/03/27 15:28:28.0858 2504 pcmcia
f) C:\windows\system32\DRIVERS\pcmcia.sys
2011/03/27 15:28:29.0202 2504 pcw
3) C:\windows\system32\drivers\pcw.sys
2011/03/27 15:28:29.0560 2504 PEAUTH
e) C:\windows\system32\drivers\peauth.sys
2011/03/27 15:28:29.0966 2504 PGEffect
a) C:\windows\system32\DRIVERS\pgeffect.sys
2011/03/27 15:28:30.0387 2504 PptpMiniport
7) C:\windows\system32\DRIVERS\raspptp.sys
2011/03/27 15:28:30.0730 2504 Processor
f) C:\windows\system32\DRIVERS\processr.sys
2011/03/27 15:28:31.0120 2504 Psched
9) C:\windows\system32\DRIVERS\pacer.sys
2011/03/27 15:28:31.0495 2504 QIOMem
c) C:\windows\system32\DRIVERS\QIOMem.sys
2011/03/27 15:28:31.0900 2504 ql2300
0) C:\windows\system32\DRIVERS\ql2300.sys
2011/03/27 15:28:32.0259 2504 ql40xx
8) C:\windows\system32\DRIVERS\ql40xx.sys

(9f9a1f53aad7da4d6fef5bb73ab811a
(30639c932d9fef22b31268fe25a1b6e
(f105ba1e22bf1f2ee8f005d4305e4be
(557dfab9ca1fcb036ac77564c010dad
(659b74fb74b86228d6338d643cd3e3c
(86743d9f5d2b1048062b14b1d84501c
(9162b273a44ab9dce5b44362731d062
(77889813be4d166cdab78ddba990da9
(1e4c4ab5c9b8dd13179bbdc75a2a01f
(e7f5ae18af4168178a642a9247c6300
(356698a13c4630d5b31c37378d46919
(9899284589f75fa8724ff3d16aed75c
(3e38712941e9bb4ddbee00affe3fed3
(477dc4d6deb99be37084c9ac6d013da
(270d7cd42d6e3979f6dd0146650f0e0
(3589478e4b22ce21b41fa1bfc0b8b8a
(0086431c29c35be1dbc43f52cc27388
(7daa117143316c4a1537e074a5a9eaf
(5aab2b170536885de70a6cba8d7ce52
(b5b8b5ef2e5cb34df8dcf8831e3534f
(b2e81d4e87ce48589f98cb8c05b01f2
(d6b9c2e1a11a3a4b26a182ffef18f60
(68769c3356b3be5d1c732c97b9a80d6
(663962900e7fea522126ba287715bb4
(27cc19e81ba5e3403c48302127bda71
(0d922e23c041efb1c3fac2a6f943c9b
(ee992183bd8eaefd9973f352e587a29
(c8fcb4899f8b70cc34e0d9876a80963
(a53a15a11ebfd21077463ee2c7afeef
(4f6d12b51de1aaeff7dc58c4d75423c

2011/03/27 15:28:32.0602 2504 QWAVEdrv


c) C:\windows\system32\drivers\qwavedrv.sys
2011/03/27 15:28:32.0961 2504 RasAcd
4) C:\windows\system32\DRIVERS\rasacd.sys
2011/03/27 15:28:33.0336 2504 RasAgileVpn
0) C:\windows\system32\DRIVERS\AgileVpn.sys
2011/03/27 15:28:33.0726 2504 Rasl2tp
3) C:\windows\system32\DRIVERS\rasl2tp.sys
2011/03/27 15:28:34.0116 2504 RasPppoe
5) C:\windows\system32\DRIVERS\raspppoe.sys
2011/03/27 15:28:34.0506 2504 RasSstp
b) C:\windows\system32\DRIVERS\rassstp.sys
2011/03/27 15:28:34.0864 2504 rdbss
5) C:\windows\system32\DRIVERS\rdbss.sys
2011/03/27 15:28:35.0208 2504 rdpbus
d) C:\windows\system32\DRIVERS\rdpbus.sys
2011/03/27 15:28:35.0582 2504 RDPCDD
4) C:\windows\system32\DRIVERS\RDPCDD.sys
2011/03/27 15:28:35.0956 2504 RDPENCDD
5) C:\windows\system32\drivers\rdpencdd.sys
2011/03/27 15:28:36.0315 2504 RDPREFMP
a) C:\windows\system32\drivers\rdprefmp.sys
2011/03/27 15:28:36.0690 2504 RDPWD
7) C:\windows\system32\drivers\RDPWD.sys
2011/03/27 15:28:37.0080 2504 rdyboost
b) C:\windows\system32\drivers\rdyboost.sys
2011/03/27 15:28:37.0485 2504 rspndr
f) C:\windows\system32\DRIVERS\rspndr.sys
2011/03/27 15:28:37.0906 2504 RSUSBSTOR
e) C:\windows\system32\Drivers\RtsUStor.sys
2011/03/27 15:28:38.0312 2504 rtl8192se
4) C:\windows\system32\DRIVERS\rtl8192se.sys
2011/03/27 15:28:38.0671 2504 sbp2port
7) C:\windows\system32\DRIVERS\sbp2port.sys
2011/03/27 15:28:39.0030 2504 scfilter
7) C:\windows\system32\DRIVERS\scfilter.sys
2011/03/27 15:28:39.0420 2504 secdrv
6) C:\windows\system32\drivers\secdrv.sys
2011/03/27 15:28:39.0810 2504 Serenum
b) C:\windows\system32\DRIVERS\serenum.sys
2011/03/27 15:28:40.0153 2504 Serial
6) C:\windows\system32\DRIVERS\serial.sys
2011/03/27 15:28:40.0496 2504 sermouse
3) C:\windows\system32\DRIVERS\sermouse.sys
2011/03/27 15:28:40.0870 2504 sffdisk
f) C:\windows\system32\DRIVERS\sffdisk.sys
2011/03/27 15:28:41.0214 2504 sffp_mmc
f) C:\windows\system32\DRIVERS\sffp_mmc.sys
2011/03/27 15:28:41.0557 2504 sffp_sd
4) C:\windows\system32\DRIVERS\sffp_sd.sys
2011/03/27 15:28:41.0916 2504 sfloppy
4) C:\windows\system32\DRIVERS\sfloppy.sys
2011/03/27 15:28:42.0274 2504 SiSRaid2
1) C:\windows\system32\DRIVERS\SiSRaid2.sys
2011/03/27 15:28:42.0618 2504 SiSRaid4
4) C:\windows\system32\DRIVERS\sisraid4.sys
2011/03/27 15:28:42.0976 2504 Smb
4) C:\windows\system32\DRIVERS\smb.sys
2011/03/27 15:28:43.0382 2504 spldr
9) C:\windows\system32\drivers\spldr.sys

(76707bb36430888d9ce9d705398adb6
(5a0da8ad5762fa2d91678a8a0131170
(7ecff9b22276b73f43a99a15a6094e9
(87a6e852a22991580d6d39adc479046
(855c9b1cd4756c5e9a2aa58a15f58c2
(e8b1e447b008d07ff47d016c2b0eeec
(3bac8142102c15d59a87757c1d41dce
(302da2a0539f2cf54d7c6cc30c1f2d8
(cea6cc257fc9b7715f1c2b4849286d2
(bb5971a4f00659529a5c44831af2236
(216f3fa57533d98e1f74ded70113177
(8a3e6bea1c53ea6177fe2b6eba2c80d
(634b9a2181d98f15941236886164ec8
(ddc86e4f8e7456261e637e3552e804f
(3ceee53bbf8ba284ff44585cec0162f
(a8ed9726734d403217a4861a6788b14
(e3bbb89983daf5622c1d50cf49f2822
(c94da20c7e3ba1dca269bc8460d9838
(3ea8a16169c26afbeb544e0e4842118
(cb624c0035412af0debec78c41f5ca1
(c1d8e28b2c2adfaec4ba89e9fda69bd
(1c545a7d0691cc4a027396535691c3e
(a554811bcd09279536440c964ae35bb
(ff414f0baefeba59bc6c04b3db0b87b
(178298f767fe638c9fedcbdef58bb5e
(a9d601643a1647211a1ee2ec4e433ff
(843caf1e5fde1ffd5ff768f23a51e2e
(6a6c106d42e9ffff8b9fcb4f754f6da
(548260a7b8654e024dc30bf8a7c5baa
(b9e31e5cacdfe584f34f730a677803f

2011/03/27 15:28:43.0756 2504 srv


f) C:\windows\system32\DRIVERS\srv.sys
2011/03/27 15:28:44.0115 2504 srv2
2) C:\windows\system32\DRIVERS\srv2.sys
2011/03/27 15:28:44.0490 2504 SrvHsfHDA
8) C:\windows\system32\DRIVERS\VSTAZL6.SYS
2011/03/27 15:28:44.0864 2504 SrvHsfV92
4) C:\windows\system32\DRIVERS\VSTDPV6.SYS
2011/03/27 15:28:45.0223 2504 SrvHsfWinac
6) C:\windows\system32\DRIVERS\VSTCNXT6.SYS
2011/03/27 15:28:45.0566 2504 srvnet
b) C:\windows\system32\DRIVERS\srvnet.sys
2011/03/27 15:28:45.0956 2504 ssmirrdr
1) C:\windows\system32\DRIVERS\ssmirrdr.sys
2011/03/27 15:28:46.0362 2504 stexstor
a) C:\windows\system32\DRIVERS\stexstor.sys
2011/03/27 15:28:46.0752 2504 swenum
0) C:\windows\system32\DRIVERS\swenum.sys
2011/03/27 15:28:47.0157 2504 SynTP
5) C:\windows\system32\DRIVERS\SynTP.sys
2011/03/27 15:28:47.0610 2504 Tcpip
d) C:\windows\system32\drivers\tcpip.sys
2011/03/27 15:28:48.0031 2504 TCPIP6
d) C:\windows\system32\DRIVERS\tcpip.sys
2011/03/27 15:28:48.0390 2504 tcpipreg
d) C:\windows\system32\drivers\tcpipreg.sys
2011/03/27 15:28:48.0780 2504 tdcmdpst
9) C:\windows\system32\DRIVERS\tdcmdpst.sys
2011/03/27 15:28:49.0123 2504 TDPIPE
c) C:\windows\system32\drivers\tdpipe.sys
2011/03/27 15:28:49.0482 2504 TDTCP
9) C:\windows\system32\drivers\tdtcp.sys
2011/03/27 15:28:49.0872 2504 tdx
f) C:\windows\system32\DRIVERS\tdx.sys
2011/03/27 15:28:50.0215 2504 TermDD
2) C:\windows\system32\DRIVERS\termdd.sys
2011/03/27 15:28:50.0776 2504 tssecsrv
5) C:\windows\system32\DRIVERS\tssecsrv.sys
2011/03/27 15:28:51.0151 2504 tunnel
0) C:\windows\system32\DRIVERS\tunnel.sys
2011/03/27 15:28:51.0510 2504 TVALZ
2) C:\windows\system32\DRIVERS\TVALZ_O.SYS
2011/03/27 15:28:51.0853 2504 TVALZFL
a) C:\windows\system32\DRIVERS\TVALZFL.sys
2011/03/27 15:28:52.0212 2504 uagp35
7) C:\windows\system32\DRIVERS\uagp35.sys
2011/03/27 15:28:52.0555 2504 udfs
b) C:\windows\system32\DRIVERS\udfs.sys
2011/03/27 15:28:52.0945 2504 uliagpkx
0) C:\windows\system32\DRIVERS\uliagpkx.sys
2011/03/27 15:28:53.0319 2504 umbus
7) C:\windows\system32\DRIVERS\umbus.sys
2011/03/27 15:28:53.0678 2504 UmPass
d) C:\windows\system32\DRIVERS\umpass.sys
2011/03/27 15:28:54.0037 2504 usbccgp
6) C:\windows\system32\DRIVERS\usbccgp.sys
2011/03/27 15:28:54.0411 2504 usbcir
7) C:\windows\system32\DRIVERS\usbcir.sys
2011/03/27 15:28:54.0770 2504 usbehci
6) C:\windows\system32\DRIVERS\usbehci.sys

(de6f5658da951c4bc8e498570b5b0d5
(4d33d59c0b930c523d29f9bd40cda9d
(0c4540311e11664b245a263e1154cef
(02071d207a9858fbe3a48cbfd59c4a0
(18e40c245dbfaf36fd0134a7ef2df39
(5a663fd67049267bc5c3f3279e631ff
(1100066057fbf612b573efd3b21383f
(f3817967ed533d08327dc73bc4d5542
(d01ec09b6711a5f8e7e6564a4d0fbc9
(470c47daba9ca3966f0ab3f835d7d13
(90a2d722cf64d911879d6c4a4f802a4
(90a2d722cf64d911879d6c4a4f802a4
(76d078af6f587b162d50210f761eb9e
(fd542b661bd22fa69ca789ad0ac58c2
(3371d21011695b16333a3934340c4e7
(e4245bda3190a582d55ed09e137401a
(079125c4b17b01fcaeebce0bcb290c0
(c448651339196c0e869a35517187552
(61b96c26131e37b24e93327a0bd1fb9
(3836171a2cdf3af8ef10856db9835a7
(550b567f9364d8f7684c3fb3ea665a7
(9c7191f4b2e49bff47a6c1144b5923f
(b4dd609bd7e282bfc683cec7eaaaad6
(d47baead86c65d4f4069d7ce0a4edce
(4bfe1bc28391222894cbf1e7d0e4232
(eab6c35e62b1b0db0d1b48b671d3a11
(b2e8e8cb557b156da5493bbddcc1474
(b26afb54a534d634523c4fb66765b02
(af0892a803fdda7492f595368e3b68e
(cb490987a7f6928a04bb838e3bd8a93

2011/03/27 15:28:55.0160 2504 usbhub


0) C:\windows\system32\DRIVERS\usbhub.sys
2011/03/27 15:28:55.0519 2504 usbohci
9) C:\windows\system32\DRIVERS\usbohci.sys
2011/03/27 15:28:55.0862 2504 usbprint
d) C:\windows\system32\DRIVERS\usbprint.sys
2011/03/27 15:28:56.0221 2504 USBSTOR
3) C:\windows\system32\DRIVERS\USBSTOR.SYS
2011/03/27 15:28:56.0580 2504 usbuhci
d) C:\windows\system32\DRIVERS\usbuhci.sys
2011/03/27 15:28:56.0954 2504 usbvideo
e) C:\windows\System32\Drivers\usbvideo.sys
2011/03/27 15:28:57.0344 2504 vdrvroot
d) C:\windows\system32\DRIVERS\vdrvroot.sys
2011/03/27 15:28:57.0734 2504 vga
d) C:\windows\system32\DRIVERS\vgapnp.sys
2011/03/27 15:28:58.0077 2504 VgaSave
c) C:\windows\System32\drivers\vga.sys
2011/03/27 15:28:58.0436 2504 vhdmp
4) C:\windows\system32\DRIVERS\vhdmp.sys
2011/03/27 15:28:58.0779 2504 viaide
4) C:\windows\system32\DRIVERS\viaide.sys
2011/03/27 15:28:59.0123 2504 volmgr
3) C:\windows\system32\DRIVERS\volmgr.sys
2011/03/27 15:28:59.0481 2504 volmgrx
b) C:\windows\system32\drivers\volmgrx.sys
2011/03/27 15:28:59.0840 2504 volsnap
c) C:\windows\system32\DRIVERS\volsnap.sys
2011/03/27 15:29:00.0199 2504 vsmraid
7) C:\windows\system32\DRIVERS\vsmraid.sys
2011/03/27 15:29:00.0558 2504 vwifibus
1) C:\windows\system32\DRIVERS\vwifibus.sys
2011/03/27 15:29:00.0932 2504 vwififlt
f) C:\windows\system32\DRIVERS\vwififlt.sys
2011/03/27 15:29:01.0291 2504 WacomPen
e) C:\windows\system32\DRIVERS\wacompen.sys
2011/03/27 15:29:01.0665 2504 WANARP
4) C:\windows\system32\DRIVERS\wanarp.sys
2011/03/27 15:29:01.0697 2504 Wanarpv6
4) C:\windows\system32\DRIVERS\wanarp.sys
2011/03/27 15:29:02.0102 2504 Wd
c) C:\windows\system32\DRIVERS\wd.sys
2011/03/27 15:29:02.0477 2504 Wdf01000
0) C:\windows\system32\drivers\Wdf01000.sys
2011/03/27 15:29:02.0898 2504 WfpLwf
5) C:\windows\system32\DRIVERS\wfplwf.sys
2011/03/27 15:29:03.0241 2504 WIMMount
c) C:\windows\system32\drivers\wimmount.sys
2011/03/27 15:29:03.0615 2504 winachsf
d) C:\windows\system32\DRIVERS\CAX_CNXT.sys
2011/03/27 15:29:04.0052 2504 WmiAcpi
8) C:\windows\system32\DRIVERS\wmiacpi.sys
2011/03/27 15:29:04.0442 2504 ws2ifsl
2) C:\windows\system32\drivers\ws2ifsl.sys
2011/03/27 15:29:04.0832 2504 WudfPf
8) C:\windows\system32\drivers\WudfPf.sys
2011/03/27 15:29:05.0207 2504 WUDFRd
4) C:\windows\system32\DRIVERS\WUDFRd.sys
2011/03/27 15:29:05.0581 2504 XAudio
6) C:\windows\system32\DRIVERS\XAudio64.sys

(18124ef0a881a00ee222d02a3ee3027
(58e546bbaf87664fc57e0f6081e4f60
(73188f58fb384e75c4063d29413cee3
(080d3820da6c046be82fc8b45a893e8
(81fb2216d3a60d1284455d511797db3
(7cb8c573c6e4a2714402cc0a36eab4f
(c5c876ccfc083ff3b128f933823e87b
(da4da3f5e02943c2dc8c6ed875de68d
(53e92a310193cb3c03bea963de7d9cf
(c82e748660f62a242b2dfac1442f22a
(e5689d93ffe4e5d66c0178761240dd5
(2b1a3dae2b4e70dbba822b7a03fbd4a
(99b0cbb569ca79acaed8c91461d765f
(58f82eed8ca24b461441f9c3e4f0bf5
(5e2016ea6ebaca03c04feac5f330d99
(36d4720b72b5c5d9cb2b9c29e9df67a
(6a3d66263414ff0d6fa754c646612f3
(4e9440f4f152a7b944cb1663d3935a3
(47ca49400643effd3f1c9a27e1d6932
(47ca49400643effd3f1c9a27e1d6932
(72889e16ff12ba0f235467d6091b17d
(441bd2d7b4f98134c3a4f9fa570fd25
(611b23304bf067451a9fdee01fbdd72
(05ecaec3e4529a7153b3136ceb49f0e
(a6ea7a3fc4b00f48535b506db1e86ef
(f6ff8944478594d0e414d3f048f0d77
(6bcc1d7d2fd2453957c5479a32364e5
(7cadc74271dd6461c452c271b30bd37
(3b197af0fff08aa66b6b2241ca538d6
(e8f3fa126a06f8e7088f63757112a18

2011/03/27 15:29:05.0659 2504 ================================================


================================
2011/03/27 15:29:05.0659 2504 Scan finished
2011/03/27 15:29:05.0659 2504 ================================================
================================
2011/03/27 15:31:19.0741 5068 Deinitialize success

You might also like