Você está na página 1de 10

2011/05/16 16:30:31.0636 5964 TDSS rootkit removing tool 2.5.1.

0 May 13 2011 1
3:20:29
2011/05/16 16:30:31.0692 5964 ================================================
================================
2011/05/16 16:30:31.0692 5964 SystemInfo:
2011/05/16 16:30:31.0692 5964
2011/05/16 16:30:31.0692 5964 OS Version: 6.0.6001 ServicePack: 1.0
2011/05/16 16:30:31.0692 5964 Product type: Workstation
2011/05/16 16:30:31.0692 5964 ComputerName: PC-FABIO
2011/05/16 16:30:31.0693 5964 UserName: fabio
2011/05/16 16:30:31.0693 5964 Windows directory: C:\Windows
2011/05/16 16:30:31.0693 5964 System windows directory: C:\Windows
2011/05/16 16:30:31.0693 5964 Processor architecture: Intel x86
2011/05/16 16:30:31.0693 5964 Number of processors: 4
2011/05/16 16:30:31.0693 5964 Page size: 0x1000
2011/05/16 16:30:31.0693 5964 Boot type: Normal boot
2011/05/16 16:30:31.0693 5964 ================================================
================================
2011/05/16 16:30:32.0406 5964 Initialize success
2011/05/16 16:30:36.0052 4704 ================================================
================================
2011/05/16 16:30:36.0052 4704 Scan started
2011/05/16 16:30:36.0052 4704 Mode: Manual;
2011/05/16 16:30:36.0052 4704 ================================================
================================
2011/05/16 16:30:39.0544 4704 ACPI
(fcb8c7210f0135e24c6580f7f649c73
c) C:\Windows\system32\drivers\acpi.sys
2011/05/16 16:30:39.0843 4704 adp94xx
(04f0fcac69c7c71a3ac4eb97fafc830
3) C:\Windows\system32\drivers\adp94xx.sys
2011/05/16 16:30:40.0118 4704 adpahci
(60505e0041f7751bdbb80f88bf45c2c
e) C:\Windows\system32\drivers\adpahci.sys
2011/05/16 16:30:40.0259 4704 adpu160m
(8a42779b02aec986eab64ecfc98f8bd
7) C:\Windows\system32\drivers\adpu160m.sys
2011/05/16 16:30:40.0456 4704 adpu320
(241c9e37f8ce45ef51c3de27515ca4e
5) C:\Windows\system32\drivers\adpu320.sys
2011/05/16 16:30:40.0548 4704 AFD
(763e172a55177e478cb419f88fd0ba0
3) C:\Windows\system32\drivers\afd.sys
2011/05/16 16:30:40.0595 4704 aic78xx
(ae1fdf7bf7bb6c6a70f67699d880592
a) C:\Windows\system32\drivers\djsvs.sys
2011/05/16 16:30:40.0633 4704 aliide
(9eaef5fc9b8e351afa7e78a6fae91f9
1) C:\Windows\system32\drivers\aliide.sys
2011/05/16 16:30:40.0677 4704 amdagp
(c47344bc706e5f0b9dce36951666157
8) C:\Windows\system32\drivers\amdagp.sys
2011/05/16 16:30:40.0926 4704 amdide
(9b78a39a4c173fdbc1321e0dd659b34
c) C:\Windows\system32\drivers\amdide.sys
2011/05/16 16:30:41.0070 4704 AmdK7
(18f29b49ad23ecee3d2a826c725c8d4
8) C:\Windows\system32\drivers\amdk7.sys
2011/05/16 16:30:41.0204 4704 AmdK8
(93ae7f7dd54ab986a6f1a1b37be7442
d) C:\Windows\system32\drivers\amdk8.sys
2011/05/16 16:30:41.0329 4704 arc
(5d2888182fb46632511acee92fdad52
2) C:\Windows\system32\drivers\arc.sys
2011/05/16 16:30:41.0375 4704 arcsas
(5e2a321bd7c8b3624e41fdec3e24494
5) C:\Windows\system32\drivers\arcsas.sys
2011/05/16 16:30:41.0449 4704 AsyncMac
(53b202abee6455406254444303e87be
1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/16 16:30:41.0492 4704 atapi
(2d9c903dc76a66813d350a562de40ed
9) C:\Windows\system32\drivers\atapi.sys
2011/05/16 16:30:41.0698 4704 Beep
(67e506b75bd5326a3ec7b70bd014dfb
6) C:\Windows\system32\drivers\Beep.sys
2011/05/16 16:30:41.0837 4704 blbdrive
(d4df28447741fd3d953526e33a61739

7) C:\Windows\system32\drivers\blbdrive.sys
2011/05/16 16:30:41.0883 4704 bowser
6) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/16 16:30:41.0995 4704 BrFiltLo
9) C:\Windows\system32\drivers\brfiltlo.sys
2011/05/16 16:30:42.0117 4704 BrFiltUp
a) C:\Windows\system32\drivers\brfiltup.sys
2011/05/16 16:30:42.0243 4704 Brserid
3) C:\Windows\system32\drivers\brserid.sys
2011/05/16 16:30:42.0339 4704 BrSerWdm
b) C:\Windows\system32\drivers\brserwdm.sys
2011/05/16 16:30:42.0443 4704 BrUsbMdm
b) C:\Windows\system32\drivers\brusbmdm.sys
2011/05/16 16:30:42.0484 4704 BrUsbSer
e) C:\Windows\system32\drivers\brusbser.sys
2011/05/16 16:30:42.0524 4704 BTHMODEM
8) C:\Windows\system32\drivers\bthmodem.sys
2011/05/16 16:30:42.0571 4704 cdfs
a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/16 16:30:42.0616 4704 cdrom
7) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/16 16:30:42.0677 4704 circlass
d) C:\Windows\system32\drivers\circlass.sys
2011/05/16 16:30:42.0746 4704 CLFS
2) C:\Windows\system32\CLFS.sys
2011/05/16 16:30:42.0835 4704 cmdide
9) C:\Windows\system32\drivers\cmdide.sys
2011/05/16 16:30:42.0891 4704 Compbatt
a) C:\Windows\system32\drivers\compbatt.sys
2011/05/16 16:30:42.0925 4704 crcdisk
1) C:\Windows\system32\drivers\crcdisk.sys
2011/05/16 16:30:42.0980 4704 Crusoe
0) C:\Windows\system32\drivers\crusoe.sys
2011/05/16 16:30:43.0040 4704 DfsC
7) C:\Windows\system32\Drivers\dfsc.sys
2011/05/16 16:30:43.0124 4704 disk
7) C:\Windows\system32\drivers\disk.sys
2011/05/16 16:30:43.0203 4704 drmkaud
0) C:\Windows\system32\drivers\drmkaud.sys
2011/05/16 16:30:43.0276 4704 DXGKrnl
a) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/16 16:30:43.0400 4704 E1G60
c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/05/16 16:30:43.0459 4704 Ecache
8) C:\Windows\system32\drivers\ecache.sys
2011/05/16 16:30:43.0543 4704 elxstor
6) C:\Windows\system32\drivers\elxstor.sys
2011/05/16 16:30:43.0641 4704 ErrDev
1) C:\Windows\system32\drivers\errdev.sys
2011/05/16 16:30:43.0714 4704 exfat
d) C:\Windows\system32\drivers\exfat.sys
2011/05/16 16:30:43.0776 4704 ezplay
8) C:\Windows\system32\Drivers\ezplay.sys
2011/05/16 16:30:43.0857 4704 fastfat
e) C:\Windows\system32\drivers\fastfat.sys
2011/05/16 16:30:43.0895 4704 fdc
a) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/16 16:30:43.0935 4704 FileInfo
f) C:\Windows\system32\drivers\fileinfo.sys
2011/05/16 16:30:43.0979 4704 Filetrace

(8153396d5551276227fa146900f734e
(9f9acc7f7ccde8a15c282d3f88b4330
(56801ad62213a41f6497f96dee83755
(b304e75cff293029eddf09424674711
(203f0b1e73adadbbb7b7b1fabd901f6
(bd456606156ba17e60a04e18016ae54
(af72ed54503f717a43268b3cc5faec2
(ad07c1ec6665b8b35741ab91200c6b6
(7add03e75beb9e6dd102c3081d29840
(1ec25cea0de6ac4718bf89f9e1778b5
(e5d4133f37219dbcfe102bc61072589
(465745561c832b29f7c48b488aab384
(0ca25e686a4928484e9fdabd168ab62
(6afef0b60fa25de07c0968983ee4f60
(741e9dff4f42d2d8477d0fc1dc0df87
(1f07becdca750766a96cda811ba8641
(9e635ae5e8ad93e2b5989e2e23679f9
(64109e623abd6955c8fb110b592e68b
(97fef831ab90bee128c9af390e243f8
(85f33880b8cfb554bd3d9ccdb486845
(5425f74ac0c1dbd96a1e04f17d63f94
(dd2cd259d83d8b72c02c5f2331ff9d6
(23b62471681a124889978f6295b3f4c
(3db974f3935483555d7148663f726c6
(0d858eb20589a34efb25695acaa6aa2
(96dad6e55739d96a6b24d26fa077dad
(3c489390c2e2064563727752af8eab9
(afe1e8b9782a0dd7fb46bbd88e43f89
(a8c0139a884861e3aae9cfe73b208a9
(0ae429a696aecbc5970e3cf2c62635a

e) C:\Windows\system32\drivers\filetrace.sys
2011/05/16 16:30:44.0014 4704 flpydisk
(85b7cf99d532820495d68d747fda9eb
d) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/16 16:30:44.0048 4704 FltMgr
(05ea53afe985443011e36dab07343b4
6) C:\Windows\system32\drivers\fltmgr.sys
2011/05/16 16:30:44.0091 4704 Fs_Rec
(65ea8b77b5851854f0c55c43fa51a19
8) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/16 16:30:44.0129 4704 gagp30kx
(34582a6e6573d54a07ece5fe24a126b
5) C:\Windows\system32\drivers\gagp30kx.sys
2011/05/16 16:30:44.0254 4704 hamachi
(833051c6c6c42117191935f734cfbd9
7) C:\Windows\system32\DRIVERS\hamachi.sys
2011/05/16 16:30:44.0306 4704 HdAudAddService (cb04c744be0a61b1d648faed182c3b5
9) C:\Windows\system32\drivers\HdAudio.sys
2011/05/16 16:30:44.0343 4704 HDAudBus
(c87b1ee051c0464491c1a7b03fa0bc9
9) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/16 16:30:44.0382 4704 HidBth
(1338520e78d90154ed6be8f84de5fce
b) C:\Windows\system32\drivers\hidbth.sys
2011/05/16 16:30:44.0420 4704 HidIr
(ff3160c3a2445128c5a6d9b076da519
e) C:\Windows\system32\drivers\hidir.sys
2011/05/16 16:30:44.0457 4704 HidUsb
(854ca287ab7faf949617a788306d967
e) C:\Windows\system32\DRIVERS\hidusb.sys
2011/05/16 16:30:44.0494 4704 HpCISSs
(16ee7b23a009e00d835cdb79574a91a
6) C:\Windows\system32\drivers\hpcisss.sys
2011/05/16 16:30:44.0578 4704 HTTP
(96e241624c71211a79c84f50a8e71ca
b) C:\Windows\system32\drivers\HTTP.sys
2011/05/16 16:30:44.0632 4704 hwdatacard
(19e6885a061011d8dabe8f64498423f
a) C:\Windows\system32\DRIVERS\ewusbmdm.sys
2011/05/16 16:30:44.0676 4704 i2omp
(c6b032d69650985468160fc9937cf5b
4) C:\Windows\system32\drivers\i2omp.sys
2011/05/16 16:30:44.0707 4704 i8042prt
(22d56c8184586b7a1f6fa60be5f5a2b
d) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/16 16:30:44.0771 4704 iaStor
(580bfec487c55264bfe3d60c3c24eee
1) C:\Windows\system32\drivers\iastor.sys
2011/05/16 16:30:44.0809 4704 iaStorV
(54155ea1b0df185878e0fc9ec3ac3a1
4) C:\Windows\system32\drivers\iastorv.sys
2011/05/16 16:30:44.0854 4704 iirsp
(2d077bf86e843f901d8db709c95b49a
5) C:\Windows\system32\drivers\iirsp.sys
2011/05/16 16:30:44.0945 4704 int15
(c6e5276c00ebdeb096bb5ef4b797d1b
6) C:\Acer\Empowering Technology\eRecovery\int15.sys
2011/05/16 16:30:45.0073 4704 IntcAzAudAddService (4c01298060cf930d26a75a86b87
4b6ae) C:\Windows\system32\drivers\RTKVHDA.sys
2011/05/16 16:30:45.0121 4704 intelide
(83aa759f3189e6370c30de5dc559071
8) C:\Windows\system32\drivers\intelide.sys
2011/05/16 16:30:45.0138 4704 intelppm
(224191001e78c89dfa78924c3ea595f
f) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/16 16:30:45.0174 4704 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c
3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/16 16:30:45.0245 4704 IPMIDRV
(b25aaf203552b7b3491139d582b39ad
1) C:\Windows\system32\drivers\ipmidrv.sys
2011/05/16 16:30:45.0279 4704 IPNAT
(8793643a67b42cec66490b2a0cf92d6
8) C:\Windows\system32\DRIVERS\ipnat.sys
2011/05/16 16:30:45.0340 4704 irda
(e50a95179211b12946f7e035d60af56
0) C:\Windows\system32\DRIVERS\irda.sys
2011/05/16 16:30:45.0396 4704 IRENUM
(109c0dfb82c3632fbd11949b73aeeac
9) C:\Windows\system32\drivers\irenum.sys
2011/05/16 16:30:45.0428 4704 isapnp
(6c70698a3e5c4376c6ab5c7c17fb061
4) C:\Windows\system32\drivers\isapnp.sys
2011/05/16 16:30:45.0461 4704 iScsiPrt
(f247eec28317f6c739c16de42009730
1) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/16 16:30:45.0497 4704 iteatapi
(bced60d16156e428f8df8cf27b0df15

0) C:\Windows\system32\drivers\iteatapi.sys
2011/05/16 16:30:45.0528 4704 iteraid
e) C:\Windows\system32\drivers\iteraid.sys
2011/05/16 16:30:45.0568 4704 kbdclass
e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/16 16:30:45.0631 4704 kbdhid
0) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/05/16 16:30:45.0844 4704 kl1
8) C:\Windows\system32\DRIVERS\kl1.sys
2011/05/16 16:30:45.0915 4704 kl2
b) C:\Windows\system32\DRIVERS\kl2.sys
2011/05/16 16:30:45.0996 4704 KLIF
6) C:\Windows\system32\DRIVERS\klif.sys
2011/05/16 16:30:46.0067 4704 KLIM6
2) C:\Windows\system32\DRIVERS\klim6.sys
2011/05/16 16:30:46.0112 4704 klmouflt
a) C:\Windows\system32\DRIVERS\klmouflt.sys
2011/05/16 16:30:46.0172 4704 KSecDD
a) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/16 16:30:46.0224 4704 lltdio
6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/16 16:30:46.0281 4704 LSI_FC
5) C:\Windows\system32\drivers\lsi_fc.sys
2011/05/16 16:30:46.0328 4704 LSI_SAS
a) C:\Windows\system32\drivers\lsi_sas.sys
2011/05/16 16:30:46.0376 4704 LSI_SCSI
c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/05/16 16:30:46.0422 4704 luafv
c) C:\Windows\system32\drivers\luafv.sys
2011/05/16 16:30:46.0469 4704 megasas
9) C:\Windows\system32\drivers\megasas.sys
2011/05/16 16:30:46.0509 4704 MegaSR
9) C:\Windows\system32\drivers\megasr.sys
2011/05/16 16:30:46.0547 4704 Modem
a) C:\Windows\system32\drivers\modem.sys
2011/05/16 16:30:46.0584 4704 monitor
8) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/16 16:30:46.0606 4704 mouclass
3) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/16 16:30:46.0643 4704 mouhid
f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/16 16:30:46.0676 4704 MountMgr
0) C:\Windows\system32\drivers\mountmgr.sys
2011/05/16 16:30:46.0709 4704 mpio
6) C:\Windows\system32\drivers\mpio.sys
2011/05/16 16:30:46.0789 4704 mpsdrv
e) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/16 16:30:46.0831 4704 Mraid35x
e) C:\Windows\system32\drivers\mraid35x.sys
2011/05/16 16:30:46.0865 4704 MRxDAV
9) C:\Windows\system32\drivers\mrxdav.sys
2011/05/16 16:30:46.0912 4704 mrxsmb
9) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/16 16:30:46.0949 4704 mrxsmb10
4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/16 16:30:46.0969 4704 mrxsmb20
e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/16 16:30:47.0030 4704 msahci
d) C:\Windows\system32\drivers\msahci.sys
2011/05/16 16:30:47.0067 4704 msdsm

(06fa654504a498c30adca8bec4e87e7
(37605e0a8cf00cbba538e753e4344c6
(18247836959ba67e3511b62846b9c2e
(94d67d49bd9503bb1d838405d80f205
(713576569667ac9e0f8556076004a96
(39920d69eaedb51757527aa54fe2521
(cf88b4985d957eee45c9939092e87c9
(3de1771c135328420315e21dde229bb
(7a0cf7908b6824d6a2a1d313e5ae3dc
(d1c5883087a0c3f1344d9d55a44901f
(c7e15e82879bf3235b559563d418536
(ee01ebae8c9bf0fa072e0ff68718920
(912a04696e9ca30146a62afa1463dd5
(8f5c7426567798e62a3b3614965d62c
(0001ce609d66632fa17b84705f65887
(c252f32cd9a49dbfc25ecf26ebd51a9
(e13b5ea0f51ba5b1512ec671393d09b
(0a9bb33b56e294f686abb7c1e4e2d8a
(5bf6a1326a335c5298477754a506d26
(93b8d4869e12cfbe663915502900876
(bdafc88aa6b92f7842416ea6a48e160
(511d011289755dd9f9a7579fb0b064e
(22241feba9b2defa669c8cb0a8dd7d2
(4fbbb70d30fd20ec51f80061703b001
(ae3de84536b6799d2267443cec8edbb
(cc752d233ef39875ca6885d9415ba86
(9049dddd4bd27d43d82f5968f1da76e
(91dc069b6831ef564e7d8c97eaf0343
(28023e86f17001f7cd9b15a5bc9ae07
(4468b0f385a86ecddaf8d3ca662ec0e

7) C:\Windows\system32\drivers\msdsm.sys
2011/05/16 16:30:47.0117 4704 Msfs
5) C:\Windows\system32\drivers\Msfs.sys
2011/05/16 16:30:47.0176 4704 MSIRCOMM
8) C:\Windows\system32\DRIVERS\MSIRCOMM.sys
2011/05/16 16:30:47.0207 4704 msisadrv
2) C:\Windows\system32\drivers\msisadrv.sys
2011/05/16 16:30:47.0259 4704 MSKSSRV
7) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/16 16:30:47.0289 4704 MSPCLOCK
e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/16 16:30:47.0318 4704 MSPQM
b) C:\Windows\system32\drivers\MSPQM.sys
2011/05/16 16:30:47.0369 4704 MsRPC
3) C:\Windows\system32\drivers\MsRPC.sys
2011/05/16 16:30:47.0399 4704 mssmbios
c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/16 16:30:47.0459 4704 MSTEE
a) C:\Windows\system32\drivers\MSTEE.sys
2011/05/16 16:30:47.0490 4704 Mup
c) C:\Windows\system32\Drivers\mup.sys
2011/05/16 16:30:47.0546 4704 NativeWifiP
5) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/16 16:30:47.0611 4704 NDIS
1) C:\Windows\system32\drivers\ndis.sys
2011/05/16 16:30:47.0650 4704 NdisTapi
1) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/16 16:30:47.0695 4704 Ndisuio
9) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/16 16:30:47.0728 4704 NdisWan
1) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/16 16:30:47.0763 4704 NDProxy
3) C:\Windows\system32\drivers\NDProxy.sys
2011/05/16 16:30:47.0929 4704 NetBIOS
8) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/16 16:30:47.0964 4704 netbt
2) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/16 16:30:48.0030 4704 nfrd960
e) C:\Windows\system32\drivers\nfrd960.sys
2011/05/16 16:30:48.0113 4704 nmwcd
c) C:\Windows\system32\drivers\ccdcmb.sys
2011/05/16 16:30:48.0167 4704 nmwcdc
2) C:\Windows\system32\drivers\ccdcmbo.sys
2011/05/16 16:30:48.0307 4704 nmwcdnsu
0) C:\Windows\system32\drivers\nmwcdnsu.sys
2011/05/16 16:30:48.0364 4704 nmwcdnsuc
5) C:\Windows\system32\drivers\nmwcdnsuc.sys
2011/05/16 16:30:48.0392 4704 Npfs
b) C:\Windows\system32\drivers\Npfs.sys
2011/05/16 16:30:48.0435 4704 nsiproxy
f) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/16 16:30:48.0534 4704 Ntfs
d) C:\Windows\system32\drivers\Ntfs.sys
2011/05/16 16:30:48.0588 4704 NTIDrvr
d) C:\Windows\system32\DRIVERS\NTIDrvr.sys
2011/05/16 16:30:48.0624 4704 ntrigdigi
2) C:\Windows\system32\drivers\ntrigdigi.sys
2011/05/16 16:30:48.0643 4704 Null
e) C:\Windows\system32\drivers\Null.sys
2011/05/16 16:30:48.0772 4704 NVENETFD

(a9927f4a46b816c92f461acb90cf851
(11756768993106dd07861096fb97cdb
(0f400e306f385c56317357d6dea56f6
(d8c63d34d9c9e56c059e24ec7185cc0
(1d373c90d62ddb641d50e55b9e78d65
(b572da05bf4e098d4bba3a4734fb505
(b5614aecb05a9340aa0fb55bf561cc6
(e384487cb84be41d09711c30ca79646
(7199c1eec1e4993caf96b8c0a26bd58
(6dfd1d322de55b0b7db7d21b90bec49
(3c21ce48ff529bb73dadb98770b5402
(9bdc71790fa08f0a0b5f10462b1bd0b
(0e186e90404980569fb449ba7519ae6
(d6973aa34c4d5d76c0430b181c3cd38
(3d14c3b3496f88890d431e8aa022a41
(71dab552b41936358f3b541ae5997fb
(bcd093a5a6777cf626434568dc7dba7
(7c5fee5b1c5728507cd96fb4a13e7a0
(2e7fb731d4790a1bc6270accefacb36
(48fb907b069524f2dc7ba62a0762850
(2914ceb789964141ac6e22c6bc980c4
(28d40797bcb050321fa6674b08a620c
(7804e9747bc27eddc6a8382bbf35cf2
(ecb5003f484f9ed6c608d6d6c7886cb
(609773e344a97410ce4ebf74a8914fc
(b4effe29eb4f15538fd8a9681108492
(7f1c1f78d709c4a54cbb46ede7e0b48
(e875c093aec0c978a90f30c9e0dfbb7
(c5dbbcda07d780bda9b685df333bb41
(b896fb556b4dc1e1d2943559ea79c5c

5) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2011/05/16 16:30:48.0827 4704 NVHDA
e) C:\Windows\system32\drivers\nvhda32v.sys
2011/05/16 16:30:49.0070 4704 nvlddmkm
1) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/05/16 16:30:49.0276 4704 nvraid
1) C:\Windows\system32\drivers\nvraid.sys
2011/05/16 16:30:49.0331 4704 nvrd32
1) C:\Windows\system32\drivers\nvrd32.sys
2011/05/16 16:30:49.0373 4704 nvsmu
8) C:\Windows\system32\DRIVERS\nvsmu.sys
2011/05/16 16:30:49.0423 4704 nvstor
7) C:\Windows\system32\drivers\nvstor.sys
2011/05/16 16:30:49.0494 4704 nvstor32
8) C:\Windows\system32\drivers\nvstor32.sys
2011/05/16 16:30:49.0614 4704 nv_agp
b) C:\Windows\system32\drivers\nv_agp.sys
2011/05/16 16:30:49.0790 4704 ohci1394
9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/05/16 16:30:49.0917 4704 Parport
d) C:\Windows\system32\drivers\parport.sys
2011/05/16 16:30:49.0948 4704 partmgr
f) C:\Windows\system32\drivers\partmgr.sys
2011/05/16 16:30:49.0990 4704 Parvdm
2) C:\Windows\system32\drivers\parvdm.sys
2011/05/16 16:30:50.0082 4704 pccsmcfd
9) C:\Windows\system32\DRIVERS\pccsmcfd.sys
2011/05/16 16:30:50.0110 4704 pci
4) C:\Windows\system32\drivers\pci.sys
2011/05/16 16:30:50.0163 4704 pciide
f) C:\Windows\system32\drivers\pciide.sys
2011/05/16 16:30:50.0210 4704 pcmcia
5) C:\Windows\system32\drivers\pcmcia.sys
2011/05/16 16:30:50.0258 4704 pcouffin
f) C:\Windows\system32\Drivers\pcouffin.sys
2011/05/16 16:30:50.0293 4704 PEAUTH
2) C:\Windows\system32\drivers\peauth.sys
2011/05/16 16:30:50.0379 4704 pfc
0) C:\Windows\system32\drivers\pfc.sys
2011/05/16 16:30:50.0457 4704 PptpMiniport
1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/16 16:30:50.0521 4704 PrecSim
4) C:\Windows\system32\DRIVERS\precsim.sys
2011/05/16 16:30:50.0561 4704 Processor
d) C:\Windows\system32\drivers\processr.sys
2011/05/16 16:30:50.0629 4704 PSched
b) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/16 16:30:50.0657 4704 PSDFilter
4) C:\Windows\system32\DRIVERS\psdfilter.sys
2011/05/16 16:30:50.0683 4704 PSDNServ
c) C:\Windows\system32\DRIVERS\PSDNServ.sys
2011/05/16 16:30:50.0714 4704 psdvdisk
f) C:\Windows\system32\DRIVERS\PSDVdisk.sys
2011/05/16 16:30:50.0871 4704 ql2300
6) C:\Windows\system32\drivers\ql2300.sys
2011/05/16 16:30:51.0020 4704 ql40xx
b) C:\Windows\system32\drivers\ql40xx.sys
2011/05/16 16:30:51.0068 4704 QWAVEdrv
7) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/16 16:30:51.0110 4704 RasAcd

(57945c4c155a79cf3e0f463e3cc9923
(0a19680ca54d262534f8a2f4cf79e27
(2edf9e7751554b42cbb60116de72710
(73f84853274c0f633425b102b4edd63
(7ec12a73067baca25a8e3e2a58ae83d
(abed0c09758d1d97db0042dbb268817
(a136ba7eb1eebe4b2469f123f460751
(18bbdf913916b71bd54575bdb6eeac0
(790e27c3db53410b40ff9ef2fd10a1d
(0fa9b5055484649d63c303fe404e5f4
(3b38467e7c3daed009dfe359e17f139
(4f9a6a8a31413180d0fcb279ad5d811
(fd2041e9ba03db7764b2248f0247507
(01b94418deb235dff777cc80076354b
(fc175f5ddab666d7f4d17449a547626
(e6f3fb1b86aa519e7698ad05e58b04e
(5b6c11de7e839c05248ced8825470fe
(6349f6ed9c623b44b52ea3c63c831a9
(f2b3785d7282bac66d4b644fc88749f
(ecfffaec0c1ecd8dbc77f39070ea1db
(85fa71e8c3a0ef5bf301f1e0f7e5002
(2027293619dd0f047c584cf2e7df4ff
(bfef604508a0ed1eae2a73e872555ff
(ab94285ff6c6bc5433407d8d182a4bb
(2aaf9a5d7a63d26bfaea853c5f2292b
(0eb8cec99855beae5b0d02c2302619e
(0a6db55afb7820c99aa1f3a1d270f4f
(81a7e5c076e59995d54bc1ed3a16e60
(9f5e0e1926014d17486901c88eca2db
(147d7f9c556d259924351feb0de606c

3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/16 16:30:51.0160 4704 Rasl2tp
(a214adbaf4cb47dd2728859ef31f26b
0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/16 16:30:51.0192 4704 RasPppoe
(3e9d9b048107b40d87b97df2e48e074
4) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/16 16:30:51.0226 4704 RasSstp
(a7d141684e9500ac928a772ed8e6b67
1) C:\Windows\system32\DRIVERS\rassstp.sys
2011/05/16 16:30:51.0249 4704 rdbss
(6e1c5d0457622f9ee35f683110e93d1
4) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/16 16:30:51.0283 4704 RDPCDD
(89e59be9a564262a3fb6c4f4f1cd989
9) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/16 16:30:51.0321 4704 rdpdr
(fbc0bacd9c3d7f6956853f64a66e252
d) C:\Windows\system32\drivers\rdpdr.sys
2011/05/16 16:30:51.0350 4704 RDPENCDD
(9d91fe5286f748862ecffa05f8a0710
c) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/16 16:30:51.0427 4704 RDPWD
(e1c18f4097a5abcec941dc4b2f99db7
e) C:\Windows\system32\drivers\RDPWD.sys
2011/05/16 16:30:51.0526 4704 rspndr
(9c508f4074a39e8b4b31d27198146fa
d) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/16 16:30:51.0576 4704 sbp2port
(3ce8f073a557e172b330109436984e3
0) C:\Windows\system32\drivers\sbp2port.sys
2011/05/16 16:30:51.0624 4704 secdrv
(90a3935d05b494a5a39d37e71f09a67
7) C:\Windows\system32\drivers\secdrv.sys
2011/05/16 16:30:51.0790 4704 Serenum
(ce9ec966638ef0b10b864ddedf62a09
9) C:\Windows\system32\DRIVERS\serenum.sys
2011/05/16 16:30:51.0814 4704 Serial
(6d663022db3e7058907784ae14b6989
8) C:\Windows\system32\DRIVERS\serial.sys
2011/05/16 16:30:51.0852 4704 sermouse
(8af3d28a879bf75db53a0ee7a428962
4) C:\Windows\system32\drivers\sermouse.sys
2011/05/16 16:30:51.0901 4704 sffdisk
(3efa810bdca87f6ecc24f9832243fe8
6) C:\Windows\system32\drivers\sffdisk.sys
2011/05/16 16:30:51.0932 4704 sffp_mmc
(e95d451f7ea3e583aec75f3b3ee42dc
5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/05/16 16:30:51.0973 4704 sffp_sd
(3d0ea348784b7ac9ea9bd9f31798097
9) C:\Windows\system32\drivers\sffp_sd.sys
2011/05/16 16:30:52.0012 4704 sfloppy
(c33bfbd6e9e41fcd9ffef9729e9faed
6) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/05/16 16:30:52.0051 4704 sisagp
(1d76624a09a054f682d746b924e2dbc
3) C:\Windows\system32\drivers\sisagp.sys
2011/05/16 16:30:52.0089 4704 SiSRaid2
(43cb7aa756c7db280d01da9b676cfde
2) C:\Windows\system32\drivers\sisraid2.sys
2011/05/16 16:30:52.0120 4704 SiSRaid4
(a99c6c8b0baa970d8aa59ddc50b57f9
4) C:\Windows\system32\drivers\sisraid4.sys
2011/05/16 16:30:52.0156 4704 Smb
(031e6bcd53c9b2b9ace111eafec347b
6) C:\Windows\system32\DRIVERS\smb.sys
2011/05/16 16:30:52.0199 4704 spldr
(7aebdeef071fe28b0eef2cdd69102bf
f) C:\Windows\system32\drivers\spldr.sys
2011/05/16 16:30:52.0268 4704 sptd
(71e276f6d189413266ea22171806597
b) C:\Windows\system32\Drivers\sptd.sys
2011/05/16 16:30:52.0269 4704 Suspicious file (NoAccess): C:\Windows\system32\
Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
2011/05/16 16:30:52.0277 4704 sptd - detected LockedFile.Multi.Generic (1)
2011/05/16 16:30:52.0359 4704 srv
(2252aef839b1093d16761189f45af88
5) C:\Windows\system32\DRIVERS\srv.sys
2011/05/16 16:30:52.0425 4704 srv2
(96512f4a30b741e7d33a7936b9abbc2
0) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/16 16:30:52.0466 4704 srvnet
(1c69e33e0e23626da5a34ca5ba0dd99
0) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/16 16:30:52.0518 4704 sscdbus
(d6870895fe46a464a19141440eb6cc1
e) C:\Windows\system32\DRIVERS\sscdbus.sys

2011/05/16 16:30:52.0567 4704 sscdmdfl


(0fe167362e4689b716cdc8d93adedda
8) C:\Windows\system32\DRIVERS\sscdmdfl.sys
2011/05/16 16:30:52.0627 4704 sscdmdm
(55a15707e32b6709242ad127e62ca55
a) C:\Windows\system32\DRIVERS\sscdmdm.sys
2011/05/16 16:30:52.0707 4704 StarOpen
(306521935042fc0a6988d528643619b
3) C:\Windows\system32\drivers\StarOpen.sys
2011/05/16 16:30:52.0830 4704 STIrUsb
(2fd8d04caea633365564324282056ab
c) C:\Windows\system32\DRIVERS\irstusb.sys
2011/05/16 16:30:52.0879 4704 swenum
(7ba58ecf0c0a9a69d44b3dca62becf5
6) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/16 16:30:52.0914 4704 Symc8xx
(192aa3ac01df071b541094f251deed1
0) C:\Windows\system32\drivers\symc8xx.sys
2011/05/16 16:30:52.0947 4704 Sym_hi
(8c8eb8c76736ebaf3b13b633b2e6412
5) C:\Windows\system32\drivers\sym_hi.sys
2011/05/16 16:30:52.0990 4704 Sym_u3
(8072af52b5fd103bbba387a1e49f62c
b) C:\Windows\system32\drivers\sym_u3.sys
2011/05/16 16:30:53.0155 4704 Tcpip
(782568ab6a43160a159b6215b70bcce
9) C:\Windows\system32\drivers\tcpip.sys
2011/05/16 16:30:53.0464 4704 Tcpip6
(782568ab6a43160a159b6215b70bcce
9) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/16 16:30:53.0803 4704 tcpipreg
(d4a2e4a4b011f3a883af77315a5ae76
b) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/16 16:30:53.0856 4704 TDPIPE
(5dcf5e267be67a1ae926f2df77fbcc5
6) C:\Windows\system32\drivers\tdpipe.sys
2011/05/16 16:30:53.0883 4704 TDTCP
(389c63e32b3cefed425b61ed92d3f02
1) C:\Windows\system32\drivers\tdtcp.sys
2011/05/16 16:30:53.0917 4704 tdx
(d09276b1fab033ce1d40dcbdf303d10
f) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/16 16:30:53.0977 4704 TermDD
(a048056f5e1a96a9bf3071b91741a5a
a) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/16 16:30:54.0102 4704 tssecsrv
(dcf0f056a2e4f52287264f5ab29cf20
6) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/16 16:30:54.0294 4704 tunmp
(caecc0120ac49e3d2f758b9169872d3
8) C:\Windows\system32\DRIVERS\tunmp.sys
2011/05/16 16:30:54.0576 4704 tunnel
(6042505ff6fa9ac1ef7684d0e03b694
0) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/16 16:30:54.0657 4704 tvicport
(97dd70feca64fb4f63de7bb7e66a80b
1) C:\Windows\system32\drivers\tvicport.sys
2011/05/16 16:30:54.0688 4704 uagp35
(7d33c4db2ce363c8518d2dfcf533941
f) C:\Windows\system32\drivers\uagp35.sys
2011/05/16 16:30:54.0869 4704 udfs
(8b5088058fa1d1cd897a2113ccff6c5
8) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/16 16:30:54.0928 4704 uliagpkx
(b0acfdc9e4af279e9116c03e014b2b2
7) C:\Windows\system32\drivers\uliagpkx.sys
2011/05/16 16:30:54.0997 4704 uliahci
(9224bb254f591de4ca8d572a5f0d635
c) C:\Windows\system32\drivers\uliahci.sys
2011/05/16 16:30:55.0037 4704 UlSata
(8514d0e5cd0534467c5fc61be94a569
f) C:\Windows\system32\drivers\ulsata.sys
2011/05/16 16:30:55.0067 4704 ulsata2
(38c3c6e62b157a6bc46594fada45c62
b) C:\Windows\system32\drivers\ulsata2.sys
2011/05/16 16:30:55.0113 4704 umbus
(32cff9f809ae9aed85464492bf3e32d
2) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/16 16:30:55.0172 4704 upperdev
(e526a166e6acafd0a9b3841d3941669
e) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
2011/05/16 16:30:55.0230 4704 usbccgp
(caf811ae4c147ffcd5b51750c7f0914
2) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/16 16:30:55.0281 4704 usbcir
(e9476e6c486e76bc4898074768fb713
1) C:\Windows\system32\drivers\usbcir.sys
2011/05/16 16:30:55.0309 4704 usbehci
(cebe90821810e76320155beba722fcf
9) C:\Windows\system32\DRIVERS\usbehci.sys

2011/05/16 16:30:55.0380 4704 usbhub


(cc6b28e4ce39951357963119ce47b14
3) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/16 16:30:55.0465 4704 usbohci
(7bdb7b0e7d45ac0402d78b90789ef47
c) C:\Windows\system32\DRIVERS\usbohci.sys
2011/05/16 16:30:55.0514 4704 usbprint
(e75c4b5269091d15a2e7dc0b6d35f2f
5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/05/16 16:30:55.0557 4704 usbscan
(a508c9bd8724980512136b039bba65e
9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/05/16 16:30:55.0599 4704 usbser
(a96191470581a7091420d25ecd44450
2) C:\Windows\system32\DRIVERS\usbser.sys
2011/05/16 16:30:55.0652 4704 UsbserFilt
(6f3e3c6811b930d2414552a2e4a40f3
6) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
2011/05/16 16:30:55.0698 4704 USBSTOR
(87ba6b83c5d19b69160968d07d6e298
2) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/05/16 16:30:55.0766 4704 usbuhci
(814d653efc4d48be3b04a307eceff56
f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/16 16:30:55.0801 4704 vga
(87b06e1f30b749a114f74622d013f8d
4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/16 16:30:55.0828 4704 VgaSave
(2e93ac0a1d8c79d019db6c51f036636
c) C:\Windows\System32\drivers\vga.sys
2011/05/16 16:30:55.0861 4704 viaagp
(5d7159def58a800d5781ba3a879627b
c) C:\Windows\system32\drivers\viaagp.sys
2011/05/16 16:30:55.0904 4704 ViaC7
(c4f3a691b5bad343e6249bd8c2d45de
e) C:\Windows\system32\drivers\viac7.sys
2011/05/16 16:30:55.0941 4704 viaide
(aadf5587a4063f52c2c3fed7887426f
c) C:\Windows\system32\drivers\viaide.sys
2011/05/16 16:30:55.0970 4704 volmgr
(69503668ac66c77c6cd7af86fbdf8c4
3) C:\Windows\system32\drivers\volmgr.sys
2011/05/16 16:30:56.0008 4704 volmgrx
(98f5ffe6316bd74e9e2c97206c19019
6) C:\Windows\system32\drivers\volmgrx.sys
2011/05/16 16:30:56.0057 4704 volsnap
(d8b4a53dd2769f226b3eb374374987c
9) C:\Windows\system32\drivers\volsnap.sys
2011/05/16 16:30:56.0098 4704 vsmraid
(587253e09325e6bf226b299774b728a
9) C:\Windows\system32\drivers\vsmraid.sys
2011/05/16 16:30:56.0150 4704 WacomPen
(48dfee8f1af7c8235d4e626f0c4fe03
1) C:\Windows\system32\drivers\wacompen.sys
2011/05/16 16:30:56.0182 4704 Wanarp
(55201897378cca7af8b5efd874374a2
6) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/16 16:30:56.0196 4704 Wanarpv6
(55201897378cca7af8b5efd874374a2
6) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/16 16:30:56.0232 4704 Wd
(78fe9542363f297b18c027b2d7e7c07
f) C:\Windows\system32\drivers\wd.sys
2011/05/16 16:30:56.0308 4704 Wdf01000
(9950e3d0f08141c7e89e64456ae7dc7
3) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/16 16:30:56.0550 4704 WmiAcpi
(2e7255d172df0b8283cdfb7b433b864
e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/05/16 16:30:56.0663 4704 WpdUsb
(0cec23084b51b8288099eb710224e95
5) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/05/16 16:30:56.0719 4704 ws2ifsl
(e3a3cb253c0ec2494d4a61f5e43a389
c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/16 16:30:56.0772 4704 WSVD
(0d0367919d12143739cd7ec67a65b6e
b) C:\Windows\system32\drivers\WSVD.sys
2011/05/16 16:30:56.0798 4704 WUDFRd
(ac13cb789d93412106b0fb6c7eb2bcb
6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/16 16:30:56.0836 4704 zntport
(40ac8590cc9006dbb99ffcb37879d4c
6) C:\Windows\system32\drivers\zntport.sys
2011/05/16 16:30:56.0918 4704 \HardDisk1 - detected Rootkit.Win32.TDSS.tdl4 (0
)
2011/05/16 16:30:56.0955 4704 ================================================
================================

2011/05/16 16:30:56.0955 4704 Scan finished


2011/05/16 16:30:56.0955 4704 ================================================
================================
2011/05/16 16:30:56.0969 3992 Detected object count: 2
2011/05/16 16:31:11.0854 3992 LockedFile.Multi.Generic(sptd) - User select act
ion: Skip
2011/05/16 16:31:12.0062 3992 \HardDisk1 (Rootkit.Win32.TDSS.tdl4) - will be c
ured after reboot
2011/05/16 16:31:12.0093 3992 \HardDisk1 - ok
2011/05/16 16:31:12.0095 3992 Rootkit.Win32.TDSS.tdl4(\HardDisk1) - User selec
t action: Cure
2011/05/16 16:31:17.0983 5668 Deinitialize success

Você também pode gostar