Advertisement
Guest User

Untitled

a guest
Oct 31st, 2011
102
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 46.83 KB | None | 0 0
  1. 16:06:10.0265 2524 TDSS rootkit removing tool 2.6.14.0 Oct 28 2011 11:11:01
  2. 16:06:10.0890 2524 ============================================================
  3. 16:06:10.0890 2524 Current date / time: 2011/10/31 16:06:10.0890
  4. 16:06:10.0890 2524 SystemInfo:
  5. 16:06:10.0890 2524
  6. 16:06:10.0890 2524 OS Version: 5.1.2600 ServicePack: 3.0
  7. 16:06:10.0890 2524 Product type: Workstation
  8. 16:06:10.0890 2524 ComputerName:
  9. 16:06:10.0890 2524 UserName: Admin
  10. 16:06:10.0890 2524 Windows directory: C:\WINDOWS
  11. 16:06:10.0890 2524 System windows directory: C:\WINDOWS
  12. 16:06:10.0890 2524 Processor architecture: Intel x86
  13. 16:06:10.0890 2524 Number of processors: 2
  14. 16:06:10.0890 2524 Page size: 0x1000
  15. 16:06:10.0890 2524 Boot type: Normal boot
  16. 16:06:10.0890 2524 ============================================================
  17. 16:06:14.0343 2524 Initialize success
  18. 16:06:15.0171 2596 ============================================================
  19. 16:06:15.0171 2596 Scan started
  20. 16:06:15.0171 2596 Mode: Manual;
  21. 16:06:15.0171 2596 ============================================================
  22. 16:06:16.0203 2596 867a66ca (8f2bb1827cac01aee6a16e30a1260199) C:\WINDOWS\3395713670:2038798645.exe
  23. 16:06:16.0218 2596 Suspicious file (Hidden): C:\WINDOWS\3395713670:2038798645.exe. md5: 8f2bb1827cac01aee6a16e30a1260199
  24. 16:06:16.0218 2596 867a66ca ( Rootkit.Win32.PMax.gen ) - infected
  25. 16:06:16.0218 2596 867a66ca - detected Rootkit.Win32.PMax.gen (0)
  26. 16:06:16.0265 2596 Abiosdsk - ok
  27. 16:06:16.0281 2596 abp480n5 - ok
  28. 16:06:16.0328 2596 ACPI (e28afa761d7ecaa705a00b4a86f68da9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
  29. 16:06:16.0328 2596 ACPI - ok
  30. 16:06:16.0359 2596 ACPIEC (cea8d1da7696acbfc69a3823bcf1c738) C:\WINDOWS\system32\drivers\ACPIEC.sys
  31. 16:06:16.0359 2596 ACPIEC - ok
  32. 16:06:16.0375 2596 adpu160m - ok
  33. 16:06:16.0406 2596 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
  34. 16:06:16.0406 2596 aec - ok
  35. 16:06:16.0437 2596 AFD (f6b7b1ecd7b41736bdb6ff4b092bcb79) C:\WINDOWS\System32\drivers\afd.sys
  36. 16:06:16.0437 2596 AFD - ok
  37. 16:06:16.0453 2596 Aha154x - ok
  38. 16:06:16.0453 2596 aic78u2 - ok
  39. 16:06:16.0468 2596 aic78xx - ok
  40. 16:06:16.0484 2596 AliIde - ok
  41. 16:06:16.0484 2596 amsint - ok
  42. 16:06:16.0500 2596 asc - ok
  43. 16:06:16.0515 2596 asc3350p - ok
  44. 16:06:16.0515 2596 asc3550 - ok
  45. 16:06:16.0562 2596 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
  46. 16:06:16.0562 2596 AsyncMac - ok
  47. 16:06:16.0578 2596 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
  48. 16:06:16.0578 2596 atapi - ok
  49. 16:06:16.0578 2596 Atdisk - ok
  50. 16:06:16.0718 2596 ati2mtag (7a95a5f3ed40a3b6f1275821553f3f4f) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
  51. 16:06:16.0750 2596 ati2mtag - ok
  52. 16:06:16.0796 2596 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
  53. 16:06:16.0796 2596 Atmarpc - ok
  54. 16:06:16.0812 2596 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
  55. 16:06:16.0812 2596 audstub - ok
  56. 16:06:16.0843 2596 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
  57. 16:06:16.0843 2596 Beep - ok
  58. 16:06:16.0890 2596 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
  59. 16:06:16.0890 2596 BrScnUsb - ok
  60. 16:06:16.0937 2596 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
  61. 16:06:16.0937 2596 cbidf2k - ok
  62. 16:06:16.0937 2596 cd20xrnt - ok
  63. 16:06:16.0937 2596 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
  64. 16:06:16.0953 2596 Cdaudio - ok
  65. 16:06:16.0968 2596 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
  66. 16:06:16.0968 2596 Cdfs - ok
  67. 16:06:17.0015 2596 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
  68. 16:06:17.0015 2596 Cdrom - ok
  69. 16:06:17.0015 2596 Changer - ok
  70. 16:06:17.0031 2596 CmdIde - ok
  71. 16:06:17.0046 2596 Cpqarray - ok
  72. 16:06:17.0062 2596 dac2w2k - ok
  73. 16:06:17.0062 2596 dac960nt - ok
  74. 16:06:17.0093 2596 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
  75. 16:06:17.0093 2596 Disk - ok
  76. 16:06:17.0140 2596 dmboot (d71be7c02b8b147e85456238d0660478) C:\WINDOWS\system32\drivers\dmboot.sys
  77. 16:06:17.0140 2596 dmboot - ok
  78. 16:06:17.0156 2596 dmio (5f25de6f05c986dcc36adaf532c3ce0d) C:\WINDOWS\system32\drivers\dmio.sys
  79. 16:06:17.0156 2596 dmio - ok
  80. 16:06:17.0171 2596 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
  81. 16:06:17.0171 2596 dmload - ok
  82. 16:06:17.0203 2596 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
  83. 16:06:17.0203 2596 DMusic - ok
  84. 16:06:17.0218 2596 dpti2o - ok
  85. 16:06:17.0218 2596 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
  86. 16:06:17.0218 2596 drmkaud - ok
  87. 16:06:17.0281 2596 exFat (4d893323dae445e34a4c9038b0551bc9) C:\WINDOWS\system32\drivers\exFat.sys
  88. 16:06:17.0281 2596 exFat - ok
  89. 16:06:17.0296 2596 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
  90. 16:06:17.0312 2596 Fastfat - ok
  91. 16:06:17.0343 2596 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
  92. 16:06:17.0343 2596 Fdc - ok
  93. 16:06:17.0359 2596 Fips (1541a3a7a460decd6a2221065794a0de) C:\WINDOWS\system32\drivers\Fips.sys
  94. 16:06:17.0359 2596 Fips - ok
  95. 16:06:17.0359 2596 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
  96. 16:06:17.0359 2596 Flpydisk - ok
  97. 16:06:17.0390 2596 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
  98. 16:06:17.0390 2596 FltMgr - ok
  99. 16:06:17.0406 2596 Fs_Rec (30d42943a54704ef13e2562911dbfcea) C:\WINDOWS\system32\drivers\Fs_Rec.sys
  100. 16:06:17.0406 2596 Fs_Rec - ok
  101. 16:06:17.0406 2596 Ftdisk (fdd9e4cf0c558f64a58115cb2fc197ac) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
  102. 16:06:17.0421 2596 Ftdisk - ok
  103. 16:06:17.0453 2596 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
  104. 16:06:17.0453 2596 Gpc - ok
  105. 16:06:17.0500 2596 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
  106. 16:06:17.0500 2596 HDAudBus - ok
  107. 16:06:17.0515 2596 hpn - ok
  108. 16:06:17.0546 2596 HTTP (937031c085718c1c04a9c0864625ec6b) C:\WINDOWS\system32\Drivers\HTTP.sys
  109. 16:06:17.0546 2596 HTTP - ok
  110. 16:06:17.0562 2596 i2omgmt - ok
  111. 16:06:17.0562 2596 i2omp - ok
  112. 16:06:17.0609 2596 i8042prt (f9850bdd47dffd2797e984fe60c8b3b6) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
  113. 16:06:17.0609 2596 i8042prt - ok
  114. 16:06:17.0609 2596 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
  115. 16:06:17.0609 2596 Imapi - ok
  116. 16:06:17.0625 2596 ini910u - ok
  117. 16:06:17.0656 2596 IntelIde (256a679e08285cafeacc94ae34fd2b79) C:\WINDOWS\system32\DRIVERS\intelide.sys
  118. 16:06:17.0656 2596 IntelIde - ok
  119. 16:06:17.0671 2596 intelppm (5151dff0faa3cccc38a9de9b4001d09b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
  120. 16:06:17.0671 2596 intelppm - ok
  121. 16:06:17.0703 2596 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
  122. 16:06:17.0703 2596 Ip6Fw - ok
  123. 16:06:17.0734 2596 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
  124. 16:06:17.0734 2596 IpFilterDriver - ok
  125. 16:06:17.0750 2596 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
  126. 16:06:17.0750 2596 IpInIp - ok
  127. 16:06:17.0765 2596 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
  128. 16:06:17.0765 2596 IpNat - ok
  129. 16:06:17.0781 2596 IPSec (c3b55c9f04b8b9214b26659c56ec3e04) C:\WINDOWS\system32\DRIVERS\ipsec.sys
  130. 16:06:17.0781 2596 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ipsec.sys. Real md5: c3b55c9f04b8b9214b26659c56ec3e04, Fake md5: 23c74d75e36e7158768dd63d92789a91
  131. 16:06:17.0781 2596 IPSec ( Rootkit.Win32.ZAccess.e ) - infected
  132. 16:06:17.0781 2596 IPSec - detected Rootkit.Win32.ZAccess.e (0)
  133. 16:06:17.0812 2596 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
  134. 16:06:17.0812 2596 IRENUM - ok
  135. 16:06:17.0828 2596 isapnp (1c93959977cad7168b4c816e8b29fe9b) C:\WINDOWS\system32\DRIVERS\isapnp.sys
  136. 16:06:17.0828 2596 isapnp - ok
  137. 16:06:17.0843 2596 Kbdclass (2b0018de01bfb628d0a49a301f34b46f) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
  138. 16:06:17.0843 2596 Kbdclass - ok
  139. 16:06:17.0875 2596 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
  140. 16:06:17.0875 2596 kmixer - ok
  141. 16:06:17.0921 2596 KSecDD (c6ebf1d6ad71df30db49b8d3287e1368) C:\WINDOWS\system32\drivers\KSecDD.sys
  142. 16:06:17.0921 2596 KSecDD - ok
  143. 16:06:17.0937 2596 L1e (a934bb9b5225a9579f5b52e0ddc10163) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys
  144. 16:06:17.0937 2596 L1e - ok
  145. 16:06:17.0937 2596 lbrtfdc - ok
  146. 16:06:18.0000 2596 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
  147. 16:06:18.0000 2596 mnmdd - ok
  148. 16:06:18.0015 2596 Modem (5bced2c68331a18534ab8dbae71d93fc) C:\WINDOWS\system32\drivers\Modem.sys
  149. 16:06:18.0015 2596 Modem - ok
  150. 16:06:18.0031 2596 Mouclass (cbb891fda0c5ec9f557abba86ca5cb76) C:\WINDOWS\system32\DRIVERS\mouclass.sys
  151. 16:06:18.0031 2596 Mouclass - ok
  152. 16:06:18.0031 2596 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
  153. 16:06:18.0031 2596 MountMgr - ok
  154. 16:06:18.0062 2596 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
  155. 16:06:18.0062 2596 MpFilter - ok
  156. 16:06:18.0062 2596 mraid35x - ok
  157. 16:06:18.0093 2596 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
  158. 16:06:18.0093 2596 MRxDAV - ok
  159. 16:06:18.0140 2596 MRxSmb (fb2fccc70f7174c7bf64f48e96d3adf4) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
  160. 16:06:18.0140 2596 MRxSmb - ok
  161. 16:06:18.0156 2596 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
  162. 16:06:18.0156 2596 Msfs - ok
  163. 16:06:18.0187 2596 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
  164. 16:06:18.0187 2596 MSKSSRV - ok
  165. 16:06:18.0203 2596 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
  166. 16:06:18.0203 2596 MSPCLOCK - ok
  167. 16:06:18.0218 2596 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
  168. 16:06:18.0218 2596 MSPQM - ok
  169. 16:06:18.0234 2596 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
  170. 16:06:18.0250 2596 mssmbios - ok
  171. 16:06:18.0250 2596 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
  172. 16:06:18.0250 2596 MTsensor - ok
  173. 16:06:18.0281 2596 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
  174. 16:06:18.0281 2596 Mup - ok
  175. 16:06:18.0312 2596 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
  176. 16:06:18.0312 2596 NDIS - ok
  177. 16:06:18.0343 2596 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
  178. 16:06:18.0343 2596 NdisTapi - ok
  179. 16:06:18.0359 2596 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
  180. 16:06:18.0359 2596 Ndisuio - ok
  181. 16:06:18.0375 2596 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
  182. 16:06:18.0375 2596 NdisWan - ok
  183. 16:06:18.0406 2596 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
  184. 16:06:18.0406 2596 NDProxy - ok
  185. 16:06:18.0421 2596 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
  186. 16:06:18.0421 2596 NetBIOS - ok
  187. 16:06:18.0437 2596 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
  188. 16:06:18.0437 2596 NetBT - ok
  189. 16:06:18.0484 2596 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\WINDOWS\system32\drivers\ccdcmb.sys
  190. 16:06:18.0484 2596 nmwcd - ok
  191. 16:06:18.0500 2596 nmwcdc (3859c69a77793180548802dac9f34a38) C:\WINDOWS\system32\drivers\ccdcmbo.sys
  192. 16:06:18.0500 2596 nmwcdc - ok
  193. 16:06:18.0531 2596 nmwcdnsu (338f83ee9cb9e15eeacf0cbb90218cbf) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
  194. 16:06:18.0531 2596 nmwcdnsu - ok
  195. 16:06:18.0546 2596 nmwcdnsuc (d15bac979144fb69ed28f97b2dd84d48) C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
  196. 16:06:18.0546 2596 nmwcdnsuc - ok
  197. 16:06:18.0562 2596 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
  198. 16:06:18.0562 2596 Npfs - ok
  199. 16:06:18.0609 2596 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
  200. 16:06:18.0609 2596 Ntfs - ok
  201. 16:06:18.0625 2596 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
  202. 16:06:18.0625 2596 Null - ok
  203. 16:06:18.0671 2596 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
  204. 16:06:18.0671 2596 NwlnkFlt - ok
  205. 16:06:18.0671 2596 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
  206. 16:06:18.0671 2596 NwlnkFwd - ok
  207. 16:06:18.0718 2596 Parport (fa3a44ade1d355be8e29d3b6bf0ba702) C:\WINDOWS\system32\drivers\Parport.sys
  208. 16:06:18.0718 2596 Parport - ok
  209. 16:06:18.0718 2596 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
  210. 16:06:18.0718 2596 PartMgr - ok
  211. 16:06:18.0750 2596 ParVdm (f6167f46184c50a9bc2feb87067d1b97) C:\WINDOWS\system32\drivers\ParVdm.sys
  212. 16:06:18.0750 2596 ParVdm - ok
  213. 16:06:18.0765 2596 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
  214. 16:06:18.0765 2596 pccsmcfd - ok
  215. 16:06:18.0781 2596 PCI (f9b93d158c4d9f54fbdf1a9c807a1a5a) C:\WINDOWS\system32\DRIVERS\pci.sys
  216. 16:06:18.0796 2596 PCI - ok
  217. 16:06:18.0796 2596 PCIDump - ok
  218. 16:06:18.0796 2596 PCIIde (0d5ea82e0b16fa4c162635fa78e2ddc3) C:\WINDOWS\system32\DRIVERS\pciide.sys
  219. 16:06:18.0796 2596 PCIIde - ok
  220. 16:06:18.0812 2596 Pcmcia (b266a636c370476f25d307b30894d990) C:\WINDOWS\system32\drivers\Pcmcia.sys
  221. 16:06:18.0812 2596 Pcmcia - ok
  222. 16:06:18.0828 2596 PDCOMP - ok
  223. 16:06:18.0828 2596 PDFRAME - ok
  224. 16:06:18.0843 2596 PDRELI - ok
  225. 16:06:18.0843 2596 PDRFRAME - ok
  226. 16:06:18.0859 2596 perc2 - ok
  227. 16:06:18.0859 2596 perc2hib - ok
  228. 16:06:18.0890 2596 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
  229. 16:06:18.0890 2596 PptpMiniport - ok
  230. 16:06:18.0906 2596 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
  231. 16:06:18.0906 2596 PSched - ok
  232. 16:06:18.0921 2596 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
  233. 16:06:18.0921 2596 Ptilink - ok
  234. 16:06:18.0921 2596 ql1080 - ok
  235. 16:06:18.0921 2596 Ql10wnt - ok
  236. 16:06:18.0937 2596 ql12160 - ok
  237. 16:06:18.0937 2596 ql1240 - ok
  238. 16:06:18.0953 2596 ql1280 - ok
  239. 16:06:18.0968 2596 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
  240. 16:06:18.0968 2596 RasAcd - ok
  241. 16:06:18.0968 2596 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
  242. 16:06:18.0984 2596 Rasl2tp - ok
  243. 16:06:18.0984 2596 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
  244. 16:06:18.0984 2596 RasPppoe - ok
  245. 16:06:19.0000 2596 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
  246. 16:06:19.0000 2596 Raspti - ok
  247. 16:06:19.0015 2596 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
  248. 16:06:19.0015 2596 Rdbss - ok
  249. 16:06:19.0015 2596 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
  250. 16:06:19.0015 2596 RDPCDD - ok
  251. 16:06:19.0031 2596 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
  252. 16:06:19.0046 2596 rdpdr - ok
  253. 16:06:19.0093 2596 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
  254. 16:06:19.0093 2596 RDPWD - ok
  255. 16:06:19.0109 2596 redbook (868c8de05325f3b250f806666de18f0d) C:\WINDOWS\system32\DRIVERS\redbook.sys
  256. 16:06:19.0109 2596 redbook - ok
  257. 16:06:19.0171 2596 rspndr (743d7d59767073a617b1dcc6c546f234) C:\WINDOWS\system32\DRIVERS\rspndr.sys
  258. 16:06:19.0171 2596 rspndr - ok
  259. 16:06:19.0687 2596 RTHDMIAzAudService (1eacb3bfede4e2f5a584fa4e8031729b) C:\WINDOWS\system32\drivers\RtKHDMI.sys
  260. 16:06:20.0000 2596 RTHDMIAzAudService - ok
  261. 16:06:20.0156 2596 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
  262. 16:06:20.0156 2596 Secdrv - ok
  263. 16:06:20.0265 2596 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
  264. 16:06:20.0265 2596 serenum - ok
  265. 16:06:20.0390 2596 Serial (27645ae9dcc60be467f3c92ddabed1b0) C:\WINDOWS\system32\DRIVERS\serial.sys
  266. 16:06:20.0390 2596 Serial - ok
  267. 16:06:20.0609 2596 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
  268. 16:06:20.0609 2596 Sfloppy - ok
  269. 16:06:20.0703 2596 Simbad - ok
  270. 16:06:20.0781 2596 Sparrow - ok
  271. 16:06:20.0859 2596 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
  272. 16:06:20.0890 2596 splitter - ok
  273. 16:06:21.0015 2596 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
  274. 16:06:21.0015 2596 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
  275. 16:06:21.0015 2596 sptd ( LockedFile.Multi.Generic ) - warning
  276. 16:06:21.0015 2596 sptd - detected LockedFile.Multi.Generic (1)
  277. 16:06:21.0156 2596 sr (4a7b3b22c87f0897a68821734afe9528) C:\WINDOWS\system32\DRIVERS\sr.sys
  278. 16:06:21.0187 2596 sr - ok
  279. 16:06:21.0296 2596 Srv (9b390283569ea58d43d2586032b892f5) C:\WINDOWS\system32\DRIVERS\srv.sys
  280. 16:06:21.0359 2596 Srv - ok
  281. 16:06:21.0500 2596 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
  282. 16:06:21.0531 2596 swenum - ok
  283. 16:06:21.0578 2596 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
  284. 16:06:21.0578 2596 swmidi - ok
  285. 16:06:21.0593 2596 symc810 - ok
  286. 16:06:21.0593 2596 symc8xx - ok
  287. 16:06:21.0609 2596 sym_hi - ok
  288. 16:06:21.0609 2596 sym_u3 - ok
  289. 16:06:21.0640 2596 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
  290. 16:06:21.0640 2596 sysaudio - ok
  291. 16:06:21.0687 2596 Tcpip (ad978a1b783b5719720cff204b666c8e) C:\WINDOWS\system32\DRIVERS\tcpip.sys
  292. 16:06:21.0687 2596 Tcpip - ok
  293. 16:06:21.0734 2596 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
  294. 16:06:21.0734 2596 TDPIPE - ok
  295. 16:06:21.0734 2596 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
  296. 16:06:21.0734 2596 TDTCP - ok
  297. 16:06:21.0750 2596 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
  298. 16:06:21.0750 2596 TermDD - ok
  299. 16:06:21.0765 2596 TosIde - ok
  300. 16:06:21.0796 2596 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
  301. 16:06:21.0796 2596 Udfs - ok
  302. 16:06:21.0812 2596 ultra - ok
  303. 16:06:21.0843 2596 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
  304. 16:06:21.0859 2596 Update - ok
  305. 16:06:21.0890 2596 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
  306. 16:06:21.0890 2596 upperdev - ok
  307. 16:06:21.0921 2596 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
  308. 16:06:21.0921 2596 usbccgp - ok
  309. 16:06:21.0953 2596 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
  310. 16:06:21.0953 2596 usbehci - ok
  311. 16:06:21.0968 2596 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
  312. 16:06:21.0984 2596 usbhub - ok
  313. 16:06:21.0984 2596 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
  314. 16:06:21.0984 2596 usbprint - ok
  315. 16:06:22.0031 2596 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
  316. 16:06:22.0031 2596 usbscan - ok
  317. 16:06:22.0062 2596 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys
  318. 16:06:22.0062 2596 usbser - ok
  319. 16:06:22.0078 2596 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
  320. 16:06:22.0078 2596 UsbserFilt - ok
  321. 16:06:22.0109 2596 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
  322. 16:06:22.0109 2596 USBSTOR - ok
  323. 16:06:22.0125 2596 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
  324. 16:06:22.0125 2596 usbuhci - ok
  325. 16:06:22.0171 2596 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
  326. 16:06:22.0171 2596 VgaSave - ok
  327. 16:06:22.0250 2596 VIAHdAudAddService (3cf5faf72b43bc9bc196a98946f53a0e) C:\WINDOWS\system32\drivers\viahduaa.sys
  328. 16:06:22.0265 2596 VIAHdAudAddService - ok
  329. 16:06:22.0265 2596 ViaIde - ok
  330. 16:06:22.0281 2596 VolSnap (a79d899dfd0467c4df29af19902ecd18) C:\WINDOWS\system32\drivers\VolSnap.sys
  331. 16:06:22.0296 2596 VolSnap - ok
  332. 16:06:22.0312 2596 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
  333. 16:06:22.0312 2596 Wanarp - ok
  334. 16:06:22.0343 2596 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
  335. 16:06:22.0359 2596 Wdf01000 - ok
  336. 16:06:22.0359 2596 WDICA - ok
  337. 16:06:22.0406 2596 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
  338. 16:06:22.0406 2596 wdmaud - ok
  339. 16:06:22.0468 2596 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
  340. 16:06:22.0468 2596 WpdUsb - ok
  341. 16:06:22.0515 2596 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
  342. 16:06:22.0515 2596 WS2IFSL - ok
  343. 16:06:22.0531 2596 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
  344. 16:06:22.0531 2596 WudfPf - ok
  345. 16:06:22.0546 2596 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
  346. 16:06:22.0546 2596 WudfRd - ok
  347. 16:06:22.0593 2596 ZTEusbmdm6k (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys
  348. 16:06:22.0593 2596 ZTEusbmdm6k - ok
  349. 16:06:22.0609 2596 ZTEusbnmea (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys
  350. 16:06:22.0609 2596 ZTEusbnmea - ok
  351. 16:06:22.0625 2596 ZTEusbser6k (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys
  352. 16:06:22.0625 2596 ZTEusbser6k - ok
  353. 16:06:22.0640 2596 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
  354. 16:06:22.0750 2596 \Device\Harddisk0\DR0 - ok
  355. 16:06:22.0750 2596 Boot (0x1200) (c56d3caee2a2a8776890d561812e31ee) \Device\Harddisk0\DR0\Partition0
  356. 16:06:22.0765 2596 \Device\Harddisk0\DR0\Partition0 - ok
  357. 16:06:22.0765 2596 ============================================================
  358. 16:06:22.0765 2596 Scan finished
  359. 16:06:22.0765 2596 ============================================================
  360. 16:06:22.0765 2588 Detected object count: 3
  361. 16:06:22.0765 2588 Actual detected object count: 3
  362. 16:07:28.0312 2588 C:\WINDOWS\3395713670:2038798645.exe - copied to quarantine
  363. 16:07:28.0328 2588 867a66ca ( Rootkit.Win32.PMax.gen ) - User select action: Quarantine
  364. 16:07:28.0421 2588 C:\WINDOWS\system32\DRIVERS\ipsec.sys - copied to quarantine
  365. 16:07:28.0421 2588 IPSec ( Rootkit.Win32.ZAccess.e ) - User select action: Quarantine
  366. 16:07:28.0500 2588 C:\WINDOWS\system32\Drivers\sptd.sys - copied to quarantine
  367. 16:07:28.0500 2588 sptd ( LockedFile.Multi.Generic ) - User select action: Quarantine
  368. 16:07:36.0859 2908 ============================================================
  369. 16:07:36.0859 2908 Scan started
  370. 16:07:36.0859 2908 Mode: Manual; SigCheck; TDLFS;
  371. 16:07:36.0859 2908 ============================================================
  372. 16:07:37.0062 2908 867a66ca (8f2bb1827cac01aee6a16e30a1260199) C:\WINDOWS\3395713670:2038798645.exe
  373. 16:07:37.0062 2908 Suspicious file (Hidden): C:\WINDOWS\3395713670:2038798645.exe. md5: 8f2bb1827cac01aee6a16e30a1260199
  374. 16:07:37.0062 2908 867a66ca ( Rootkit.Win32.PMax.gen ) - infected
  375. 16:07:37.0062 2908 867a66ca - detected Rootkit.Win32.PMax.gen (0)
  376. 16:07:37.0078 2908 Abiosdsk - ok
  377. 16:07:37.0093 2908 abp480n5 - ok
  378. 16:07:37.0140 2908 ACPI (e28afa761d7ecaa705a00b4a86f68da9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
  379. 16:07:38.0328 2908 ACPI - ok
  380. 16:07:38.0421 2908 ACPIEC (cea8d1da7696acbfc69a3823bcf1c738) C:\WINDOWS\system32\drivers\ACPIEC.sys
  381. 16:07:38.0578 2908 ACPIEC - ok
  382. 16:07:38.0578 2908 adpu160m - ok
  383. 16:07:38.0625 2908 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
  384. 16:07:38.0718 2908 aec - ok
  385. 16:07:38.0781 2908 AFD (f6b7b1ecd7b41736bdb6ff4b092bcb79) C:\WINDOWS\System32\drivers\afd.sys
  386. 16:07:38.0828 2908 AFD - ok
  387. 16:07:38.0843 2908 Aha154x - ok
  388. 16:07:38.0843 2908 aic78u2 - ok
  389. 16:07:38.0859 2908 aic78xx - ok
  390. 16:07:38.0859 2908 AliIde - ok
  391. 16:07:38.0875 2908 amsint - ok
  392. 16:07:38.0875 2908 asc - ok
  393. 16:07:38.0890 2908 asc3350p - ok
  394. 16:07:38.0890 2908 asc3550 - ok
  395. 16:07:38.0937 2908 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
  396. 16:07:39.0046 2908 AsyncMac - ok
  397. 16:07:39.0093 2908 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
  398. 16:07:39.0187 2908 atapi - ok
  399. 16:07:39.0203 2908 Atdisk - ok
  400. 16:07:39.0328 2908 ati2mtag (7a95a5f3ed40a3b6f1275821553f3f4f) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
  401. 16:07:39.0515 2908 ati2mtag - ok
  402. 16:07:39.0578 2908 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
  403. 16:07:39.0703 2908 Atmarpc - ok
  404. 16:07:39.0718 2908 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
  405. 16:07:39.0843 2908 audstub - ok
  406. 16:07:39.0875 2908 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
  407. 16:07:40.0000 2908 Beep - ok
  408. 16:07:40.0046 2908 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
  409. 16:07:40.0109 2908 BrScnUsb - ok
  410. 16:07:40.0140 2908 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
  411. 16:07:40.0234 2908 cbidf2k - ok
  412. 16:07:40.0250 2908 cd20xrnt - ok
  413. 16:07:40.0250 2908 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
  414. 16:07:40.0359 2908 Cdaudio - ok
  415. 16:07:40.0375 2908 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
  416. 16:07:40.0484 2908 Cdfs - ok
  417. 16:07:40.0531 2908 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
  418. 16:07:40.0578 2908 Cdrom - ok
  419. 16:07:40.0593 2908 Changer - ok
  420. 16:07:40.0593 2908 CmdIde - ok
  421. 16:07:40.0609 2908 Cpqarray - ok
  422. 16:07:40.0625 2908 dac2w2k - ok
  423. 16:07:40.0625 2908 dac960nt - ok
  424. 16:07:40.0656 2908 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
  425. 16:07:40.0765 2908 Disk - ok
  426. 16:07:40.0812 2908 dmboot (d71be7c02b8b147e85456238d0660478) C:\WINDOWS\system32\drivers\dmboot.sys
  427. 16:07:40.0937 2908 dmboot - ok
  428. 16:07:40.0968 2908 dmio (5f25de6f05c986dcc36adaf532c3ce0d) C:\WINDOWS\system32\drivers\dmio.sys
  429. 16:07:41.0078 2908 dmio - ok
  430. 16:07:41.0093 2908 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
  431. 16:07:41.0218 2908 dmload - ok
  432. 16:07:41.0250 2908 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
  433. 16:07:41.0375 2908 DMusic - ok
  434. 16:07:41.0375 2908 dpti2o - ok
  435. 16:07:41.0406 2908 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
  436. 16:07:41.0500 2908 drmkaud - ok
  437. 16:07:41.0531 2908 exFat (4d893323dae445e34a4c9038b0551bc9) C:\WINDOWS\system32\drivers\exFat.sys
  438. 16:07:41.0562 2908 exFat - ok
  439. 16:07:41.0593 2908 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
  440. 16:07:41.0687 2908 Fastfat - ok
  441. 16:07:41.0734 2908 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
  442. 16:07:41.0843 2908 Fdc - ok
  443. 16:07:41.0859 2908 Fips (1541a3a7a460decd6a2221065794a0de) C:\WINDOWS\system32\drivers\Fips.sys
  444. 16:07:41.0968 2908 Fips - ok
  445. 16:07:41.0968 2908 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
  446. 16:07:42.0078 2908 Flpydisk - ok
  447. 16:07:42.0093 2908 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
  448. 16:07:42.0203 2908 FltMgr - ok
  449. 16:07:42.0203 2908 Fs_Rec (30d42943a54704ef13e2562911dbfcea) C:\WINDOWS\system32\drivers\Fs_Rec.sys
  450. 16:07:42.0218 2908 Fs_Rec - ok
  451. 16:07:42.0250 2908 Ftdisk (fdd9e4cf0c558f64a58115cb2fc197ac) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
  452. 16:07:42.0343 2908 Ftdisk - ok
  453. 16:07:42.0390 2908 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
  454. 16:07:42.0484 2908 Gpc - ok
  455. 16:07:42.0546 2908 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
  456. 16:07:42.0640 2908 HDAudBus - ok
  457. 16:07:42.0656 2908 hpn - ok
  458. 16:07:42.0687 2908 HTTP (937031c085718c1c04a9c0864625ec6b) C:\WINDOWS\system32\Drivers\HTTP.sys
  459. 16:07:42.0765 2908 HTTP - ok
  460. 16:07:42.0765 2908 i2omgmt - ok
  461. 16:07:42.0781 2908 i2omp - ok
  462. 16:07:42.0812 2908 i8042prt (f9850bdd47dffd2797e984fe60c8b3b6) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
  463. 16:07:42.0921 2908 i8042prt - ok
  464. 16:07:42.0953 2908 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
  465. 16:07:43.0046 2908 Imapi - ok
  466. 16:07:43.0062 2908 ini910u - ok
  467. 16:07:43.0093 2908 IntelIde (256a679e08285cafeacc94ae34fd2b79) C:\WINDOWS\system32\DRIVERS\intelide.sys
  468. 16:07:43.0203 2908 IntelIde - ok
  469. 16:07:43.0218 2908 intelppm (5151dff0faa3cccc38a9de9b4001d09b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
  470. 16:07:43.0328 2908 intelppm - ok
  471. 16:07:43.0359 2908 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
  472. 16:07:43.0468 2908 Ip6Fw - ok
  473. 16:07:43.0484 2908 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
  474. 16:07:43.0609 2908 IpFilterDriver - ok
  475. 16:07:43.0609 2908 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
  476. 16:07:43.0718 2908 IpInIp - ok
  477. 16:07:43.0734 2908 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
  478. 16:07:43.0843 2908 IpNat - ok
  479. 16:07:43.0875 2908 IPSec (c3b55c9f04b8b9214b26659c56ec3e04) C:\WINDOWS\system32\DRIVERS\ipsec.sys
  480. 16:07:43.0875 2908 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ipsec.sys. Real md5: c3b55c9f04b8b9214b26659c56ec3e04, Fake md5: 23c74d75e36e7158768dd63d92789a91
  481. 16:07:43.0875 2908 IPSec ( Rootkit.Win32.ZAccess.e ) - infected
  482. 16:07:43.0875 2908 IPSec - detected Rootkit.Win32.ZAccess.e (0)
  483. 16:07:43.0906 2908 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
  484. 16:07:43.0953 2908 IRENUM - ok
  485. 16:07:43.0968 2908 isapnp (1c93959977cad7168b4c816e8b29fe9b) C:\WINDOWS\system32\DRIVERS\isapnp.sys
  486. 16:07:44.0062 2908 isapnp - ok
  487. 16:07:44.0078 2908 Kbdclass (2b0018de01bfb628d0a49a301f34b46f) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
  488. 16:07:44.0187 2908 Kbdclass - ok
  489. 16:07:44.0203 2908 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
  490. 16:07:44.0312 2908 kmixer - ok
  491. 16:07:44.0328 2908 KSecDD (c6ebf1d6ad71df30db49b8d3287e1368) C:\WINDOWS\system32\drivers\KSecDD.sys
  492. 16:07:44.0421 2908 KSecDD - ok
  493. 16:07:44.0437 2908 L1e (a934bb9b5225a9579f5b52e0ddc10163) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys
  494. 16:07:44.0515 2908 L1e - ok
  495. 16:07:44.0531 2908 lbrtfdc - ok
  496. 16:07:44.0578 2908 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
  497. 16:07:44.0671 2908 mnmdd - ok
  498. 16:07:44.0703 2908 Modem (5bced2c68331a18534ab8dbae71d93fc) C:\WINDOWS\system32\drivers\Modem.sys
  499. 16:07:44.0796 2908 Modem - ok
  500. 16:07:44.0796 2908 Mouclass (cbb891fda0c5ec9f557abba86ca5cb76) C:\WINDOWS\system32\DRIVERS\mouclass.sys
  501. 16:07:44.0906 2908 Mouclass - ok
  502. 16:07:44.0921 2908 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
  503. 16:07:45.0031 2908 MountMgr - ok
  504. 16:07:45.0062 2908 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
  505. 16:07:45.0078 2908 MpFilter - ok
  506. 16:07:45.0093 2908 mraid35x - ok
  507. 16:07:45.0093 2908 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
  508. 16:07:45.0218 2908 MRxDAV - ok
  509. 16:07:45.0265 2908 MRxSmb (fb2fccc70f7174c7bf64f48e96d3adf4) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
  510. 16:07:45.0328 2908 MRxSmb - ok
  511. 16:07:45.0343 2908 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
  512. 16:07:45.0453 2908 Msfs - ok
  513. 16:07:45.0484 2908 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
  514. 16:07:45.0593 2908 MSKSSRV - ok
  515. 16:07:45.0625 2908 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
  516. 16:07:45.0718 2908 MSPCLOCK - ok
  517. 16:07:45.0734 2908 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
  518. 16:07:45.0843 2908 MSPQM - ok
  519. 16:07:45.0875 2908 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
  520. 16:07:45.0984 2908 mssmbios - ok
  521. 16:07:46.0000 2908 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
  522. 16:07:46.0031 2908 MTsensor - ok
  523. 16:07:46.0046 2908 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
  524. 16:07:46.0093 2908 Mup - ok
  525. 16:07:46.0125 2908 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
  526. 16:07:46.0234 2908 NDIS - ok
  527. 16:07:46.0281 2908 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
  528. 16:07:46.0328 2908 NdisTapi - ok
  529. 16:07:46.0375 2908 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
  530. 16:07:46.0484 2908 Ndisuio - ok
  531. 16:07:46.0500 2908 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
  532. 16:07:46.0593 2908 NdisWan - ok
  533. 16:07:46.0625 2908 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
  534. 16:07:46.0687 2908 NDProxy - ok
  535. 16:07:46.0703 2908 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
  536. 16:07:46.0812 2908 NetBIOS - ok
  537. 16:07:46.0843 2908 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
  538. 16:07:46.0953 2908 NetBT - ok
  539. 16:07:47.0000 2908 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\WINDOWS\system32\drivers\ccdcmb.sys
  540. 16:07:47.0140 2908 nmwcd - ok
  541. 16:07:47.0156 2908 nmwcdc (3859c69a77793180548802dac9f34a38) C:\WINDOWS\system32\drivers\ccdcmbo.sys
  542. 16:07:47.0234 2908 nmwcdc - ok
  543. 16:07:47.0265 2908 nmwcdnsu (338f83ee9cb9e15eeacf0cbb90218cbf) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
  544. 16:07:47.0343 2908 nmwcdnsu - ok
  545. 16:07:47.0375 2908 nmwcdnsuc (d15bac979144fb69ed28f97b2dd84d48) C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
  546. 16:07:47.0437 2908 nmwcdnsuc - ok
  547. 16:07:47.0453 2908 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
  548. 16:07:47.0562 2908 Npfs - ok
  549. 16:07:47.0609 2908 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
  550. 16:07:47.0718 2908 Ntfs - ok
  551. 16:07:47.0781 2908 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
  552. 16:07:47.0875 2908 Null - ok
  553. 16:07:47.0906 2908 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
  554. 16:07:48.0015 2908 NwlnkFlt - ok
  555. 16:07:48.0031 2908 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
  556. 16:07:48.0140 2908 NwlnkFwd - ok
  557. 16:07:48.0156 2908 Parport (fa3a44ade1d355be8e29d3b6bf0ba702) C:\WINDOWS\system32\drivers\Parport.sys
  558. 16:07:48.0265 2908 Parport - ok
  559. 16:07:48.0281 2908 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
  560. 16:07:48.0390 2908 PartMgr - ok
  561. 16:07:48.0406 2908 ParVdm (f6167f46184c50a9bc2feb87067d1b97) C:\WINDOWS\system32\drivers\ParVdm.sys
  562. 16:07:48.0531 2908 ParVdm - ok
  563. 16:07:48.0578 2908 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
  564. 16:07:48.0609 2908 pccsmcfd - ok
  565. 16:07:48.0640 2908 PCI (f9b93d158c4d9f54fbdf1a9c807a1a5a) C:\WINDOWS\system32\DRIVERS\pci.sys
  566. 16:07:48.0750 2908 PCI - ok
  567. 16:07:48.0765 2908 PCIDump - ok
  568. 16:07:48.0765 2908 PCIIde (0d5ea82e0b16fa4c162635fa78e2ddc3) C:\WINDOWS\system32\DRIVERS\pciide.sys
  569. 16:07:48.0875 2908 PCIIde - ok
  570. 16:07:48.0906 2908 Pcmcia (b266a636c370476f25d307b30894d990) C:\WINDOWS\system32\drivers\Pcmcia.sys
  571. 16:07:49.0000 2908 Pcmcia - ok
  572. 16:07:49.0015 2908 PDCOMP - ok
  573. 16:07:49.0015 2908 PDFRAME - ok
  574. 16:07:49.0031 2908 PDRELI - ok
  575. 16:07:49.0031 2908 PDRFRAME - ok
  576. 16:07:49.0031 2908 perc2 - ok
  577. 16:07:49.0046 2908 perc2hib - ok
  578. 16:07:49.0093 2908 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
  579. 16:07:49.0187 2908 PptpMiniport - ok
  580. 16:07:49.0203 2908 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
  581. 16:07:49.0312 2908 PSched - ok
  582. 16:07:49.0328 2908 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
  583. 16:07:49.0453 2908 Ptilink - ok
  584. 16:07:49.0453 2908 ql1080 - ok
  585. 16:07:49.0468 2908 Ql10wnt - ok
  586. 16:07:49.0468 2908 ql12160 - ok
  587. 16:07:49.0484 2908 ql1240 - ok
  588. 16:07:49.0484 2908 ql1280 - ok
  589. 16:07:49.0515 2908 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
  590. 16:07:49.0625 2908 RasAcd - ok
  591. 16:07:49.0640 2908 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
  592. 16:07:49.0750 2908 Rasl2tp - ok
  593. 16:07:49.0750 2908 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
  594. 16:07:49.0859 2908 RasPppoe - ok
  595. 16:07:49.0859 2908 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
  596. 16:07:49.0968 2908 Raspti - ok
  597. 16:07:50.0000 2908 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
  598. 16:07:50.0109 2908 Rdbss - ok
  599. 16:07:50.0109 2908 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
  600. 16:07:50.0218 2908 RDPCDD - ok
  601. 16:07:50.0250 2908 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
  602. 16:07:50.0359 2908 rdpdr - ok
  603. 16:07:50.0406 2908 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
  604. 16:07:50.0453 2908 RDPWD - ok
  605. 16:07:50.0484 2908 redbook (868c8de05325f3b250f806666de18f0d) C:\WINDOWS\system32\DRIVERS\redbook.sys
  606. 16:07:50.0609 2908 redbook - ok
  607. 16:07:50.0656 2908 rspndr (743d7d59767073a617b1dcc6c546f234) C:\WINDOWS\system32\DRIVERS\rspndr.sys
  608. 16:07:50.0703 2908 rspndr - ok
  609. 16:07:50.0859 2908 RTHDMIAzAudService (1eacb3bfede4e2f5a584fa4e8031729b) C:\WINDOWS\system32\drivers\RtKHDMI.sys
  610. 16:07:51.0046 2908 RTHDMIAzAudService - ok
  611. 16:07:51.0109 2908 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
  612. 16:07:51.0156 2908 Secdrv - ok
  613. 16:07:51.0187 2908 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
  614. 16:07:51.0312 2908 serenum - ok
  615. 16:07:51.0328 2908 Serial (27645ae9dcc60be467f3c92ddabed1b0) C:\WINDOWS\system32\DRIVERS\serial.sys
  616. 16:07:51.0453 2908 Serial - ok
  617. 16:07:51.0468 2908 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
  618. 16:07:51.0593 2908 Sfloppy - ok
  619. 16:07:51.0609 2908 Simbad - ok
  620. 16:07:51.0625 2908 Sparrow - ok
  621. 16:07:51.0656 2908 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
  622. 16:07:51.0750 2908 splitter - ok
  623. 16:07:51.0812 2908 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
  624. 16:07:51.0812 2908 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
  625. 16:07:51.0812 2908 sptd ( LockedFile.Multi.Generic ) - warning
  626. 16:07:51.0812 2908 sptd - detected LockedFile.Multi.Generic (1)
  627. 16:07:51.0843 2908 sr (4a7b3b22c87f0897a68821734afe9528) C:\WINDOWS\system32\DRIVERS\sr.sys
  628. 16:07:51.0921 2908 sr - ok
  629. 16:07:51.0937 2908 Srv (9b390283569ea58d43d2586032b892f5) C:\WINDOWS\system32\DRIVERS\srv.sys
  630. 16:07:51.0968 2908 Srv - ok
  631. 16:07:52.0000 2908 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
  632. 16:07:52.0093 2908 swenum - ok
  633. 16:07:52.0125 2908 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
  634. 16:07:52.0234 2908 swmidi - ok
  635. 16:07:52.0234 2908 symc810 - ok
  636. 16:07:52.0250 2908 symc8xx - ok
  637. 16:07:52.0250 2908 sym_hi - ok
  638. 16:07:52.0265 2908 sym_u3 - ok
  639. 16:07:52.0281 2908 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
  640. 16:07:52.0390 2908 sysaudio - ok
  641. 16:07:52.0406 2908 Tcpip (ad978a1b783b5719720cff204b666c8e) C:\WINDOWS\system32\DRIVERS\tcpip.sys
  642. 16:07:52.0484 2908 Tcpip - ok
  643. 16:07:52.0515 2908 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
  644. 16:07:52.0625 2908 TDPIPE - ok
  645. 16:07:52.0640 2908 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
  646. 16:07:52.0750 2908 TDTCP - ok
  647. 16:07:52.0781 2908 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
  648. 16:07:52.0875 2908 TermDD - ok
  649. 16:07:52.0890 2908 TosIde - ok
  650. 16:07:52.0937 2908 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
  651. 16:07:53.0046 2908 Udfs - ok
  652. 16:07:53.0062 2908 ultra - ok
  653. 16:07:53.0125 2908 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
  654. 16:07:53.0218 2908 Update - ok
  655. 16:07:53.0250 2908 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
  656. 16:07:53.0312 2908 upperdev - ok
  657. 16:07:53.0359 2908 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
  658. 16:07:53.0453 2908 usbccgp - ok
  659. 16:07:53.0531 2908 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
  660. 16:07:53.0656 2908 usbehci - ok
  661. 16:07:53.0687 2908 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
  662. 16:07:53.0781 2908 usbhub - ok
  663. 16:07:53.0812 2908 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
  664. 16:07:53.0921 2908 usbprint - ok
  665. 16:07:53.0968 2908 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
  666. 16:07:54.0062 2908 usbscan - ok
  667. 16:07:54.0093 2908 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys
  668. 16:07:54.0203 2908 usbser - ok
  669. 16:07:54.0234 2908 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
  670. 16:07:54.0312 2908 UsbserFilt - ok
  671. 16:07:54.0343 2908 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
  672. 16:07:54.0453 2908 USBSTOR - ok
  673. 16:07:54.0468 2908 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
  674. 16:07:54.0578 2908 usbuhci - ok
  675. 16:07:54.0609 2908 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
  676. 16:07:54.0718 2908 VgaSave - ok
  677. 16:07:54.0796 2908 VIAHdAudAddService (3cf5faf72b43bc9bc196a98946f53a0e) C:\WINDOWS\system32\drivers\viahduaa.sys
  678. 16:07:54.0890 2908 VIAHdAudAddService - ok
  679. 16:07:54.0906 2908 ViaIde - ok
  680. 16:07:54.0953 2908 VolSnap (a79d899dfd0467c4df29af19902ecd18) C:\WINDOWS\system32\drivers\VolSnap.sys
  681. 16:07:55.0062 2908 VolSnap - ok
  682. 16:07:55.0093 2908 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
  683. 16:07:55.0203 2908 Wanarp - ok
  684. 16:07:55.0250 2908 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
  685. 16:07:55.0265 2908 Wdf01000 - ok
  686. 16:07:55.0265 2908 WDICA - ok
  687. 16:07:55.0312 2908 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
  688. 16:07:55.0421 2908 wdmaud - ok
  689. 16:07:55.0484 2908 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
  690. 16:07:55.0562 2908 WpdUsb - ok
  691. 16:07:55.0593 2908 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
  692. 16:07:55.0687 2908 WS2IFSL - ok
  693. 16:07:55.0718 2908 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
  694. 16:07:55.0734 2908 WudfPf - ok
  695. 16:07:55.0750 2908 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
  696. 16:07:55.0765 2908 WudfRd - ok
  697. 16:07:55.0812 2908 ZTEusbmdm6k (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys
  698. 16:07:55.0875 2908 ZTEusbmdm6k - ok
  699. 16:07:55.0906 2908 ZTEusbnmea (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys
  700. 16:07:55.0921 2908 ZTEusbnmea - ok
  701. 16:07:55.0921 2908 ZTEusbser6k (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys
  702. 16:07:55.0937 2908 ZTEusbser6k - ok
  703. 16:07:55.0968 2908 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
  704. 16:07:56.0187 2908 \Device\Harddisk0\DR0 - ok
  705. 16:07:56.0187 2908 Boot (0x1200) (c56d3caee2a2a8776890d561812e31ee) \Device\Harddisk0\DR0\Partition0
  706. 16:07:56.0187 2908 \Device\Harddisk0\DR0\Partition0 - ok
  707. 16:07:56.0187 2908 ============================================================
  708. 16:07:56.0187 2908 Scan finished
  709. 16:07:56.0187 2908 ============================================================
  710. 16:07:56.0296 2900 Detected object count: 3
  711. 16:07:56.0296 2900 Actual detected object count: 3
  712. 16:08:43.0359 2900 HKLM\SYSTEM\ControlSet002\services\867a66ca - will be deleted on reboot
  713. 16:08:43.0359 2900 HKLM\SYSTEM\ControlSet003\services\867a66ca - will be deleted on reboot
  714. 16:08:43.0359 2900 C:\WINDOWS\3395713670:2038798645.exe - will be deleted on reboot
  715. 16:08:43.0359 2900 867a66ca ( Rootkit.Win32.PMax.gen ) - User select action: Delete
  716. 16:08:43.0546 2900 Backup copy found, using it..
  717. 16:08:43.0546 2900 C:\WINDOWS\system32\DRIVERS\ipsec.sys - will be cured on reboot
  718. 16:08:43.0546 2900 IPSec ( Rootkit.Win32.ZAccess.e ) - User select action: Cure
  719. 16:08:43.0546 2900 sptd ( LockedFile.Multi.Generic ) - skipped by user
  720. 16:08:43.0546 2900 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
  721.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement