Hoop echt dat het goed is gegaan
gr Betsie
22:47:12.0406 3256 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
22:47:12.0406 3256 ============================================================
22:47:12.0406 3256 Current date / time: 2012/09/09 22:47:12.0406
22:47:12.0406 3256 SystemInfo:
22:47:12.0406 3256
22:47:12.0406 3256 OS Version: 5.1.2600 ServicePack: 3.0
22:47:12.0406 3256 Product type: Workstation
22:47:12.0406 3256 ComputerName: COMPUTER_MCE
22:47:12.0406 3256 UserName: Gebruiker
22:47:12.0406 3256 Windows directory: C:\WINDOWS
22:47:12.0406 3256 System windows directory: C:\WINDOWS
22:47:12.0406 3256 Processor architecture: Intel x86
22:47:12.0406 3256 Number of processors: 2
22:47:12.0406 3256 Page size: 0x1000
22:47:12.0406 3256 Boot type: Normal boot
22:47:12.0406 3256 ============================================================
22:47:13.0531 3256 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type ‘K0’, Flags 0x00000054
22:47:13.0546 3256 ============================================================
22:47:13.0546 3256 \Device\Harddisk0\DR0:
22:47:13.0546 3256 MBR partitions:
22:47:13.0546 3256 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A380D41
22:47:13.0546 3256 ============================================================
22:47:13.0578 3256 C: <-> \Device\Harddisk0\DR0\Partition1
22:47:13.0578 3256 ============================================================
22:47:13.0578 3256 Initialize success
22:47:13.0578 3256 ============================================================
22:47:13.0625 2116 ============================================================
22:47:13.0625 2116 Scan started
22:47:13.0625 2116 Mode: Auto (DCExact ); SigCheck; TDLFS; Silent;
22:47:13.0625 2116 ============================================================
22:47:14.0375 2116 ================ Scan system memory ========================
22:47:14.0375 2116 ================ Scan services =============================
22:47:14.0500 2116 ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:47:14.0765 2116 ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
22:47:14.0937 2116 AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:47:14.0968 2116 aec C:\WINDOWS\system32\drivers\aec.sys
22:47:15.0109 2116 AFD C:\WINDOWS\System32\drivers\afd.sys
22:47:15.0171 2116 Alerter C:\WINDOWS\system32\alrsvc.dll
22:47:15.0312 2116 ALG C:\WINDOWS\System32\alg.exe
22:47:15.0421 2116 AppMgmt C:\WINDOWS\System32\appmgmts.dll
22:47:15.0484 2116 Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
22:47:15.0671 2116 aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
22:47:15.0703 2116 ASTSRV C:\WINDOWS\system32\ASTSRV.EXE
22:47:15.0703 2116 ASTSRV ( UnsignedFile.Multi.Generic ) - warning
22:47:15.0703 2116 ASTSRV - detected UnsignedFile.Multi.Generic (1)
22:47:15.0718 2116 AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:47:15.0828 2116 atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
22:47:15.0953 2116 AtcL001 C:\WINDOWS\system32\DRIVERS\atl01_xp.sys
22:47:15.0953 2116 AtcL001 ( UnsignedFile.Multi.Generic ) - warning
22:47:15.0953 2116 AtcL001 - detected UnsignedFile.Multi.Generic (1)
22:47:15.0968 2116 Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:47:16.0093 2116 AudioSrv C:\WINDOWS\System32\audiosrv.dll
22:47:16.0250 2116 audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
22:47:16.0500 2116 AVGIDSAgent C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
22:47:16.0656 2116 AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys
22:47:16.0687 2116 AVGIDSFilter C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys
22:47:16.0734 2116 AVGIDSHX C:\WINDOWS\system32\DRIVERS\avgidshx.sys
22:47:16.0750 2116 AVGIDSShim C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys
22:47:16.0796 2116 Avgldx86 C:\WINDOWS\system32\DRIVERS\avgldx86.sys
22:47:16.0828 2116 Avgmfx86 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
22:47:16.0859 2116 Avgrkx86 C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
22:47:16.0890 2116 Avgtdix C:\WINDOWS\system32\DRIVERS\avgtdix.sys
22:47:16.0937 2116 avgwd C:\Program Files\AVG\AVG2012\avgwdsvc.exe
22:47:16.0968 2116 Beep C:\WINDOWS\system32\drivers\Beep.sys
22:47:17.0125 2116 BITS C:\WINDOWS\system32\qmgr.dll
22:47:17.0281 2116 Browser C:\WINDOWS\System32\browser.dll
22:47:17.0328 2116 cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
22:47:17.0468 2116 CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:47:17.0609 2116 Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
22:47:17.0734 2116 Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
22:47:17.0875 2116 Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:47:18.0000 2116 CiSvc C:\WINDOWS\system32\cisvc.exe
22:47:18.0109 2116 ClipSrv C:\WINDOWS\system32\clipsrv.exe
22:47:18.0265 2116 clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:47:18.0296 2116 CryptSvc C:\WINDOWS\System32\cryptsvc.dll
22:47:18.0453 2116 DcomLaunch C:\WINDOWS\system32\rpcss.dll
22:47:18.0500 2116 Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
22:47:18.0656 2116 Disk C:\WINDOWS\system32\DRIVERS\disk.sys
22:47:18.0796 2116 dmboot C:\WINDOWS\system32\drivers\dmboot.sys
22:47:18.0968 2116 dmio C:\WINDOWS\system32\drivers\dmio.sys
22:47:19.0093 2116 dmload C:\WINDOWS\system32\drivers\dmload.sys
22:47:19.0218 2116 dmserver C:\WINDOWS\System32\dmserver.dll
22:47:19.0328 2116 DMusic C:\WINDOWS\system32\drivers\DMusic.sys
22:47:19.0484 2116 Dnscache C:\WINDOWS\System32\dnsrslvr.dll
22:47:19.0546 2116 Dot3svc C:\WINDOWS\System32\dot3svc.dll
22:47:19.0687 2116 drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
22:47:19.0812 2116 EapHost C:\WINDOWS\System32\eapsvc.dll
22:47:19.0984 2116 ehRecvr C:\WINDOWS\eHome\ehRecvr.exe
22:47:20.0015 2116 ehRecvr ( UnsignedFile.Multi.Generic ) - warning
22:47:20.0015 2116 ehRecvr - detected UnsignedFile.Multi.Generic (1)
22:47:20.0015 2116 ehSched C:\WINDOWS\eHome\ehSched.exe
22:47:20.0031 2116 ehSched ( UnsignedFile.Multi.Generic ) - warning
22:47:20.0031 2116 ehSched - detected UnsignedFile.Multi.Generic (1)
22:47:20.0062 2116 ERSvc C:\WINDOWS\System32\ersvc.dll
22:47:20.0218 2116 Eventlog C:\WINDOWS\system32\services.exe
22:47:20.0281 2116 EventSystem C:\WINDOWS\system32\es.dll
22:47:20.0328 2116 Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
22:47:20.0468 2116 FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
22:47:20.0500 2116 Fdc C:\WINDOWS\system32\drivers\Fdc.sys
22:47:20.0625 2116 Fips C:\WINDOWS\system32\drivers\Fips.sys
22:47:20.0750 2116 Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
22:47:20.0890 2116 FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
22:47:21.0109 2116 FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
22:47:21.0140 2116 Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:47:21.0250 2116 Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:47:21.0406 2116 Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:47:21.0562 2116 HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:47:21.0625 2116 helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
22:47:21.0734 2116 HidServ C:\WINDOWS\System32\hidserv.dll
22:47:21.0890 2116 HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:47:22.0031 2116 hkmsvc C:\WINDOWS\System32\kmsvc.dll
22:47:22.0156 2116 HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
22:47:22.0218 2116 HTTPFilter C:\WINDOWS\System32\w3ssl.dll
22:47:22.0328 2116 i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:47:22.0484 2116 idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:47:22.0546 2116 Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
22:47:22.0671 2116 ImapiService C:\WINDOWS\system32\imapi.exe
22:47:22.0875 2116 IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:47:23.0062 2116 intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:47:23.0187 2116 Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
22:47:23.0328 2116 IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:47:23.0437 2116 IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:47:23.0546 2116 IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:47:23.0687 2116 IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:47:23.0796 2116 IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
22:47:23.0875 2116 isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:47:24.0093 2116 JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
22:47:24.0125 2116 Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:47:24.0234 2116 kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:47:24.0359 2116 kmixer C:\WINDOWS\system32\drivers\kmixer.sys
22:47:24.0484 2116 KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
22:47:24.0546 2116 lanmanserver C:\WINDOWS\System32\srvsvc.dll
22:47:24.0593 2116 lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
22:47:24.0640 2116 LmHosts C:\WINDOWS\System32\lmhsvc.dll
22:47:24.0750 2116 Messenger C:\WINDOWS\System32\msgsvc.dll
22:47:24.0875 2116 MHN C:\WINDOWS\System32\mhn.dll
22:47:24.0890 2116 MHN ( UnsignedFile.Multi.Generic ) - warning
22:47:24.0890 2116 MHN - detected UnsignedFile.Multi.Generic (1)
22:47:24.0890 2116 MHNDRV C:\WINDOWS\system32\DRIVERS\mhndrv.sys
22:47:24.0906 2116 MHNDRV ( UnsignedFile.Multi.Generic ) - warning
22:47:24.0906 2116 MHNDRV - detected UnsignedFile.Multi.Generic (1)
22:47:24.0937 2116 mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
22:47:25.0078 2116 mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
22:47:25.0218 2116 Modem C:\WINDOWS\system32\drivers\Modem.sys
22:47:25.0343 2116 Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:47:25.0453 2116 MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
22:47:25.0609 2116 MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:47:25.0750 2116 MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:47:25.0828 2116 MSCamSvc C:\Program Files\Microsoft LifeCam\MSCamS32.exe
22:47:25.0843 2116 MSDTC C:\WINDOWS\system32\msdtc.exe
22:47:25.0968 2116 Msfs C:\WINDOWS\system32\drivers\Msfs.sys
22:47:26.0093 2116 MSHUSBVideo C:\WINDOWS\system32\Drivers\nx6000.sys
22:47:26.0109 2116 MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:47:26.0218 2116 MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:47:26.0328 2116 MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
22:47:26.0484 2116 mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:47:26.0609 2116 MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
22:47:26.0734 2116 MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
22:47:26.0750 2116 Mup C:\WINDOWS\system32\drivers\Mup.sys
22:47:26.0781 2116 NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:47:26.0921 2116 napagent C:\WINDOWS\System32\qagentrt.dll
22:47:27.0046 2116 NDIS C:\WINDOWS\system32\drivers\NDIS.sys
22:47:27.0171 2116 NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:47:27.0296 2116 NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:47:27.0312 2116 Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:47:27.0421 2116 NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:47:27.0546 2116 NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
22:47:27.0578 2116 NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
22:47:27.0734 2116 NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
22:47:27.0859 2116 NetDDE C:\WINDOWS\system32\netdde.exe
22:47:28.0000 2116 NetDDEdsdm C:\WINDOWS\system32\netdde.exe
22:47:28.0109 2116 Netlogon C:\WINDOWS\system32\lsass.exe
22:47:28.0234 2116 Netman C:\WINDOWS\System32\netman.dll
22:47:28.0375 2116 NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:47:28.0390 2116 NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
22:47:28.0546 2116 Nla C:\WINDOWS\System32\mswsock.dll
22:47:28.0593 2116 Npfs C:\WINDOWS\system32\drivers\Npfs.sys
22:47:28.0734 2116 Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
22:47:28.0859 2116 NtLmSsp C:\WINDOWS\system32\lsass.exe
22:47:28.0984 2116 NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
22:47:29.0156 2116 Null C:\WINDOWS\system32\drivers\Null.sys
22:47:29.0421 2116 nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:47:29.0609 2116 NVSvc C:\WINDOWS\system32\nvsvc32.exe
22:47:29.0671 2116 NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:47:29.0796 2116 NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:47:30.0015 2116 odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:47:30.0046 2116 ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
22:47:30.0187 2116 ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:47:30.0234 2116 Parport C:\WINDOWS\system32\DRIVERS\parport.sys
22:47:30.0343 2116 PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
22:47:30.0484 2116 ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
22:47:30.0593 2116 PCI C:\WINDOWS\system32\DRIVERS\pci.sys
22:47:30.0734 2116 PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
22:47:30.0875 2116 Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
22:47:31.0015 2116 PlugPlay C:\WINDOWS\system32\services.exe
22:47:31.0031 2116 PolicyAgent C:\WINDOWS\system32\lsass.exe
22:47:31.0156 2116 PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:47:31.0250 2116 ProtectedStorage C:\WINDOWS\system32\lsass.exe
22:47:31.0390 2116 ProtexisLicensing C:\WINDOWS\system32\PSIService.exe
22:47:31.0421 2116 PSched C:\WINDOWS\system32\DRIVERS\psched.sys
22:47:31.0546 2116 PSI_SVC_2 c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
22:47:31.0578 2116 Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:47:31.0718 2116 PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
22:47:31.0765 2116 RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:47:31.0906 2116 RasAuto C:\WINDOWS\System32\rasauto.dll
22:47:32.0031 2116 Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:47:32.0171 2116 RasMan C:\WINDOWS\System32\rasmans.dll
22:47:32.0281 2116 RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:47:32.0375 2116 Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
22:47:32.0515 2116 Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:47:32.0656 2116 RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:47:32.0765 2116 rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:47:32.0906 2116 RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
22:47:32.0953 2116 RDSessMgr C:\WINDOWS\system32\sessmgr.exe
22:47:33.0062 2116 redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
22:47:33.0187 2116 RemoteAccess C:\WINDOWS\System32\mprdim.dll
22:47:33.0343 2116 RemoteRegistry C:\WINDOWS\system32\regsvc.dll
22:47:33.0468 2116 RpcLocator C:\WINDOWS\system32\locator.exe
22:47:33.0593 2116 RpcSs C:\WINDOWS\system32\rpcss.dll
22:47:33.0625 2116 RSVP C:\WINDOWS\system32\rsvp.exe
22:47:33.0750 2116 SamSs C:\WINDOWS\system32\lsass.exe
22:47:33.0859 2116 SCardSvr C:\WINDOWS\System32\SCardSvr.exe
22:47:33.0984 2116 Schedule C:\WINDOWS\system32\schedsvc.dll
22:47:34.0125 2116 Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:47:34.0187 2116 seclogon C:\WINDOWS\System32\seclogon.dll
22:47:34.0296 2116 SENS C:\WINDOWS\system32\sens.dll
22:47:34.0421 2116 serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
22:47:34.0546 2116 Serial C:\WINDOWS\system32\DRIVERS\serial.sys
22:47:34.0687 2116 Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
22:47:34.0843 2116 SharedAccess C:\WINDOWS\System32\ipnathlp.dll
22:47:34.0968 2116 ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:47:35.0140 2116 Skype C2C Service C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:47:35.0296 2116 SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
22:47:35.0343 2116 SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
22:47:35.0468 2116 splitter C:\WINDOWS\system32\drivers\splitter.sys
22:47:35.0593 2116 Spooler C:\WINDOWS\system32\spoolsv.exe
22:47:35.0656 2116 sr C:\WINDOWS\system32\DRIVERS\sr.sys
22:47:35.0750 2116 srservice C:\WINDOWS\system32\srsvc.dll
22:47:35.0843 2116 Srv C:\WINDOWS\system32\DRIVERS\srv.sys
22:47:35.0875 2116 SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
22:47:35.0953 2116 stisvc C:\WINDOWS\system32\wiaservc.dll
22:47:36.0062 2116 streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:47:36.0171 2116 swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
22:47:36.0281 2116 swmidi C:\WINDOWS\system32\drivers\swmidi.sys
22:47:36.0406 2116 sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
22:47:36.0531 2116 SysmonLog C:\WINDOWS\system32\smlogsvc.exe
22:47:36.0640 2116 TapiSrv C:\WINDOWS\System32\tapisrv.dll
22:47:36.0781 2116 Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:47:36.0828 2116 TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
22:47:36.0953 2116 TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
22:47:37.0062 2116 TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
22:47:37.0171 2116 TermService C:\WINDOWS\System32\termsrv.dll
22:47:37.0296 2116 Themes C:\WINDOWS\System32\shsvcs.dll
22:47:37.0328 2116 TlntSvr C:\WINDOWS\system32\tlntsvr.exe
22:47:37.0406 2116 TrkWks C:\WINDOWS\system32\trkwks.dll
22:47:37.0515 2116 Udfs C:\WINDOWS\system32\drivers\Udfs.sys
22:47:37.0640 2116 UMWdf C:\WINDOWS\system32\wdfmgr.exe
22:47:37.0671 2116 Update C:\WINDOWS\system32\DRIVERS\update.sys
22:47:37.0796 2116 upnphost C:\WINDOWS\System32\upnphost.dll
22:47:37.0859 2116 UPS C:\WINDOWS\System32\ups.exe
22:47:38.0000 2116 usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
22:47:38.0140 2116 usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:47:38.0250 2116 usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:47:38.0375 2116 usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:47:38.0468 2116 usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:47:38.0593 2116 usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:47:38.0718 2116 usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys
22:47:38.0828 2116 VgaSave C:\WINDOWS\System32\drivers\vga.sys
22:47:38.0953 2116 VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
22:47:39.0078 2116 VSS C:\WINDOWS\System32\vssvc.exe
22:47:39.0156 2116 W32Time C:\WINDOWS\system32\w32time.dll
22:47:39.0265 2116 Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:47:39.0390 2116 wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
22:47:39.0515 2116 WebClient C:\WINDOWS\System32\webclnt.dll
22:47:39.0687 2116 winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
22:47:39.0812 2116 WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
22:47:39.0875 2116 Wmi C:\WINDOWS\System32\advapi32.dll
22:47:39.0906 2116 WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:47:40.0078 2116 WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
22:47:40.0140 2116 wscsvc C:\WINDOWS\system32\wscsvc.dll
22:47:40.0250 2116 WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:47:40.0375 2116 wuauserv C:\WINDOWS\system32\wuauserv.dll
22:47:40.0406 2116 WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:47:40.0437 2116 WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:47:40.0453 2116 WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
22:47:40.0500 2116 WZCSVC C:\WINDOWS\System32\wzcsvc.dll
22:47:40.0625 2116 xmlprov C:\WINDOWS\System32\xmlprov.dll
22:47:40.0734 2116 ================ Scan global ===============================
22:47:40.0750 2116 C:\WINDOWS\system32\basesrv.dll
22:47:40.0781 2116 C:\WINDOWS\system32\winsrv.dll
22:47:40.0781 2116 C:\WINDOWS\system32\winsrv.dll
22:47:40.0812 2116 C:\WINDOWS\system32\services.exe
22:47:40.0812 2116 ================ Scan MBR ==================================
22:47:40.0828 2116 \Device\Harddisk0\DR0
22:47:41.0000 2116 ================ Scan VBR ==================================
22:47:41.0000 2116 \Device\Harddisk0\DR0\Partition1
22:47:41.0000 2116 ================ Scan UEFI extensions ======================
22:47:41.0000 2116 ================ Scan active images ========================
22:47:41.0000 2116 ============================================================
22:47:41.0000 2116 Scan finished
22:47:41.0000 2116 ============================================================
22:47:41.0890 3604 Deinitialize success
.
==============================================
System Restore Point Check:
.
TDSSKiller Starter Restore Point Created Succesfully
==============================================
.
==============================================
C:\TDSSStarter\Report.log
==============================================
Registry Export
.
22:46:00.0359 3640 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
22:46:00.0359 3640 ============================================================
22:46:00.0359 3640 Current date / time: 2012/09/09 22:46:00.0359
22:46:00.0359 3640 SystemInfo:
22:46:00.0359 3640
22:46:00.0359 3640 OS Version: 5.1.2600 ServicePack: 3.0
22:46:00.0359 3640 Product type: Workstation
22:46:00.0359 3640 ComputerName: COMPUTER_MCE
22:46:00.0359 3640 UserName: Gebruiker
22:46:00.0359 3640 Windows directory: C:\WINDOWS
22:46:00.0359 3640 System windows directory: C:\WINDOWS
22:46:00.0359 3640 Processor architecture: Intel x86
22:46:00.0359 3640 Number of processors: 2
22:46:00.0359 3640 Page size: 0x1000
22:46:00.0359 3640 Boot type: Normal boot
22:46:00.0359 3640 ============================================================
22:46:01.0781 3640 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type ‘K0’, Flags 0x00000054
22:46:01.0796 3640 ============================================================
22:46:01.0796 3640 \Device\Harddisk0\DR0:
22:46:01.0796 3640 MBR partitions:
22:46:01.0796 3640 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A380D41
22:46:01.0796 3640 ============================================================
22:46:01.0812 3640 C: <-> \Device\Harddisk0\DR0\Partition1
22:46:01.0812 3640 ============================================================
22:46:01.0812 3640 Initialize success
22:46:01.0812 3640 ============================================================
22:46:01.0890 1520 ============================================================
22:46:01.0890 1520 Scan started
22:46:01.0890 1520 Mode: Auto (DCExact ); SigCheck; TDLFS; Silent;
22:46:01.0890 1520 ============================================================
22:46:03.0187 1520 ================ Scan system memory ========================
22:46:03.0187 1520 ================ Scan services =============================
22:46:03.0312 1520 ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:46:04.0062 1520 ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
22:46:04.0265 1520 AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:46:04.0328 1520 aec C:\WINDOWS\system32\drivers\aec.sys
22:46:04.0515 1520 AFD C:\WINDOWS\System32\drivers\afd.sys
22:46:04.0593 1520 Alerter C:\WINDOWS\system32\alrsvc.dll
22:46:04.0734 1520 ALG C:\WINDOWS\System32\alg.exe
22:46:04.0843 1520 AppMgmt C:\WINDOWS\System32\appmgmts.dll
22:46:04.0937 1520 Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
22:46:05.0156 1520 aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
22:46:05.0187 1520 ASTSRV C:\WINDOWS\system32\ASTSRV.EXE
22:46:05.0203 1520 ASTSRV ( UnsignedFile.Multi.Generic ) - warning
22:46:05.0203 1520 ASTSRV - detected UnsignedFile.Multi.Generic (1)
22:46:05.0203 1520 AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:46:05.0328 1520 atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
22:46:05.0468 1520 AtcL001 C:\WINDOWS\system32\DRIVERS\atl01_xp.sys
22:46:05.0500 1520 AtcL001 ( UnsignedFile.Multi.Generic ) - warning
22:46:05.0500 1520 AtcL001 - detected UnsignedFile.Multi.Generic (1)
22:46:05.0500 1520 Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:46:05.0656 1520 AudioSrv C:\WINDOWS\System32\audiosrv.dll
22:46:05.0781 1520 audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
22:46:06.0046 1520 AVGIDSAgent C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
22:46:06.0218 1520 AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys
22:46:06.0578 1520 AVGIDSFilter C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys
22:46:06.0609 1520 AVGIDSHX C:\WINDOWS\system32\DRIVERS\avgidshx.sys
22:46:06.0625 1520 AVGIDSShim C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys
22:46:06.0671 1520 Avgldx86 C:\WINDOWS\system32\DRIVERS\avgldx86.sys
22:46:06.0703 1520 Avgmfx86 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
22:46:06.0734 1520 Avgrkx86 C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
22:46:06.0765 1520 Avgtdix C:\WINDOWS\system32\DRIVERS\avgtdix.sys
22:46:06.0828 1520 avgwd C:\Program Files\AVG\AVG2012\avgwdsvc.exe
22:46:06.0890 1520 Beep C:\WINDOWS\system32\drivers\Beep.sys
22:46:07.0125 1520 BITS C:\WINDOWS\system32\qmgr.dll
22:46:07.0296 1520 Browser C:\WINDOWS\System32\browser.dll
22:46:07.0375 1520 cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
22:46:07.0531 1520 CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:46:07.0656 1520 Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
22:46:07.0796 1520 Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
22:46:07.0937 1520 Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:46:08.0062 1520 CiSvc C:\WINDOWS\system32\cisvc.exe
22:46:08.0203 1520 ClipSrv C:\WINDOWS\system32\clipsrv.exe
22:46:08.0359 1520 clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:46:08.0406 1520 CryptSvc C:\WINDOWS\System32\cryptsvc.dll
22:46:08.0562 1520 DcomLaunch C:\WINDOWS\system32\rpcss.dll
22:46:08.0671 1520 Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
22:46:08.0828 1520 Disk C:\WINDOWS\system32\DRIVERS\disk.sys
22:46:08.0968 1520 dmboot C:\WINDOWS\system32\drivers\dmboot.sys
22:46:09.0140 1520 dmio C:\WINDOWS\system32\drivers\dmio.sys
22:46:09.0265 1520 dmload C:\WINDOWS\system32\drivers\dmload.sys
22:46:09.0390 1520 dmserver C:\WINDOWS\System32\dmserver.dll
22:46:09.0500 1520 DMusic C:\WINDOWS\system32\drivers\DMusic.sys
22:46:09.0656 1520 Dnscache C:\WINDOWS\System32\dnsrslvr.dll
22:46:09.0750 1520 Dot3svc C:\WINDOWS\System32\dot3svc.dll
22:46:09.0875 1520 drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
22:46:10.0000 1520 EapHost C:\WINDOWS\System32\eapsvc.dll
22:46:10.0187 1520 ehRecvr C:\WINDOWS\eHome\ehRecvr.exe
22:46:10.0203 1520 ehRecvr ( UnsignedFile.Multi.Generic ) - warning
22:46:10.0203 1520 ehRecvr - detected UnsignedFile.Multi.Generic (1)
22:46:10.0218 1520 ehSched C:\WINDOWS\eHome\ehSched.exe
22:46:10.0234 1520 ehSched ( UnsignedFile.Multi.Generic ) - warning
22:46:10.0234 1520 ehSched - detected UnsignedFile.Multi.Generic (1)
22:46:10.0265 1520 ERSvc C:\WINDOWS\System32\ersvc.dll
22:46:10.0421 1520 Eventlog C:\WINDOWS\system32\services.exe
22:46:10.0468 1520 EventSystem C:\WINDOWS\system32\es.dll
22:46:10.0562 1520 Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
22:46:10.0703 1520 FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
22:46:10.0796 1520 Fdc C:\WINDOWS\system32\drivers\Fdc.sys
22:46:10.0906 1520 Fips C:\WINDOWS\system32\drivers\Fips.sys
22:46:11.0031 1520 Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
22:46:11.0171 1520 FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
22:46:11.0375 1520 FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
22:46:11.0406 1520 Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:46:11.0515 1520 Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:46:11.0671 1520 Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:46:11.0812 1520 HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:46:11.0921 1520 helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
22:46:12.0062 1520 HidServ C:\WINDOWS\System32\hidserv.dll
22:46:12.0234 1520 HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:46:12.0375 1520 hkmsvc C:\WINDOWS\System32\kmsvc.dll
22:46:12.0531 1520 HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
22:46:12.0609 1520 HTTPFilter C:\WINDOWS\System32\w3ssl.dll
22:46:12.0750 1520 i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:46:12.0890 1520 idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:46:12.0953 1520 Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
22:46:13.0093 1520 ImapiService C:\WINDOWS\system32\imapi.exe
22:46:13.0328 1520 IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:46:13.0515 1520 intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:46:13.0656 1520 Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
22:46:13.0796 1520 IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:46:13.0921 1520 IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:46:14.0031 1520 IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:46:14.0156 1520 IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:46:14.0281 1520 IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
22:46:14.0375 1520 isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:46:14.0593 1520 JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
22:46:14.0625 1520 Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:46:14.0750 1520 kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:46:14.0890 1520 kmixer C:\WINDOWS\system32\drivers\kmixer.sys
22:46:15.0031 1520 KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
22:46:15.0140 1520 lanmanserver C:\WINDOWS\System32\srvsvc.dll
22:46:15.0203 1520 lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
22:46:15.0296 1520 LmHosts C:\WINDOWS\System32\lmhsvc.dll
22:46:15.0421 1520 Messenger C:\WINDOWS\System32\msgsvc.dll
22:46:15.0546 1520 MHN C:\WINDOWS\System32\mhn.dll
22:46:15.0546 1520 MHN ( UnsignedFile.Multi.Generic ) - warning
22:46:15.0546 1520 MHN - detected UnsignedFile.Multi.Generic (1)
22:46:15.0562 1520 MHNDRV C:\WINDOWS\system32\DRIVERS\mhndrv.sys
22:46:15.0578 1520 MHNDRV ( UnsignedFile.Multi.Generic ) - warning
22:46:15.0578 1520 MHNDRV - detected UnsignedFile.Multi.Generic (1)
22:46:15.0625 1520 mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
22:46:15.0765 1520 mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
22:46:15.0906 1520 Modem C:\WINDOWS\system32\drivers\Modem.sys
22:46:16.0046 1520 Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:46:16.0156 1520 MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
22:46:16.0296 1520 MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:46:16.0437 1520 MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:46:16.0531 1520 MSCamSvc C:\Program Files\Microsoft LifeCam\MSCamS32.exe
22:46:16.0546 1520 MSDTC C:\WINDOWS\system32\msdtc.exe
22:46:16.0687 1520 Msfs C:\WINDOWS\system32\drivers\Msfs.sys
22:46:16.0828 1520 MSHUSBVideo C:\WINDOWS\system32\Drivers\nx6000.sys
22:46:16.0843 1520 MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:46:16.0968 1520 MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:46:17.0078 1520 MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
22:46:17.0234 1520 mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:46:17.0375 1520 MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
22:46:17.0515 1520 MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
22:46:17.0546 1520 Mup C:\WINDOWS\system32\drivers\Mup.sys
22:46:17.0593 1520 NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:46:17.0734 1520 napagent C:\WINDOWS\System32\qagentrt.dll
22:46:17.0859 1520 NDIS C:\WINDOWS\system32\drivers\NDIS.sys
22:46:17.0984 1520 NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:46:18.0093 1520 NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:46:18.0156 1520 Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:46:18.0281 1520 NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:46:18.0406 1520 NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
22:46:18.0484 1520 NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
22:46:18.0625 1520 NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
22:46:18.0781 1520 NetDDE C:\WINDOWS\system32\netdde.exe
22:46:18.0906 1520 NetDDEdsdm C:\WINDOWS\system32\netdde.exe
22:46:19.0046 1520 Netlogon C:\WINDOWS\system32\lsass.exe
22:46:19.0187 1520 Netman C:\WINDOWS\System32\netman.dll
22:46:19.0328 1520 NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:46:19.0375 1520 NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
22:46:19.0515 1520 Nla C:\WINDOWS\System32\mswsock.dll
22:46:19.0562 1520 Npfs C:\WINDOWS\system32\drivers\Npfs.sys
22:46:19.0703 1520 Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
22:46:19.0828 1520 NtLmSsp C:\WINDOWS\system32\lsass.exe
22:46:19.0968 1520 NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
22:46:20.0140 1520 Null C:\WINDOWS\system32\drivers\Null.sys
22:46:20.0437 1520 nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:46:20.0640 1520 NVSvc C:\WINDOWS\system32\nvsvc32.exe
22:46:20.0734 1520 NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:46:20.0859 1520 NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:46:21.0093 1520 odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:46:21.0140 1520 ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
22:46:21.0281 1520 ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:46:21.0312 1520 Parport C:\WINDOWS\system32\DRIVERS\parport.sys
22:46:21.0437 1520 PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
22:46:21.0609 1520 ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
22:46:21.0718 1520 PCI C:\WINDOWS\system32\DRIVERS\pci.sys
22:46:21.0875 1520 PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
22:46:22.0031 1520 Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
22:46:22.0187 1520 PlugPlay C:\WINDOWS\system32\services.exe
22:46:22.0218 1520 PolicyAgent C:\WINDOWS\system32\lsass.exe
22:46:22.0343 1520 PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:46:22.0468 1520 ProtectedStorage C:\WINDOWS\system32\lsass.exe
22:46:22.0609 1520 ProtexisLicensing C:\WINDOWS\system32\PSIService.exe
22:46:22.0640 1520 PSched C:\WINDOWS\system32\DRIVERS\psched.sys
22:46:22.0765 1520 PSI_SVC_2 c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
22:46:22.0781 1520 Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:46:22.0921 1520 PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
22:46:22.0984 1520 RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:46:23.0125 1520 RasAuto C:\WINDOWS\System32\rasauto.dll
22:46:23.0281 1520 Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:46:23.0406 1520 RasMan C:\WINDOWS\System32\rasmans.dll
22:46:23.0515 1520 RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:46:23.0640 1520 Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
22:46:23.0781 1520 Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:46:23.0921 1520 RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:46:24.0093 1520 rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:46:24.0281 1520 RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
22:46:24.0375 1520 RDSessMgr C:\WINDOWS\system32\sessmgr.exe
22:46:24.0500 1520 redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
22:46:24.0640 1520 RemoteAccess C:\WINDOWS\System32\mprdim.dll
22:46:24.0796 1520 RemoteRegistry C:\WINDOWS\system32\regsvc.dll
22:46:24.0921 1520 RpcLocator C:\WINDOWS\system32\locator.exe
22:46:25.0062 1520 RpcSs C:\WINDOWS\system32\rpcss.dll
22:46:25.0140 1520 RSVP C:\WINDOWS\system32\rsvp.exe
22:46:25.0281 1520 SamSs C:\WINDOWS\system32\lsass.exe
22:46:25.0406 1520 SCardSvr C:\WINDOWS\System32\SCardSvr.exe
22:46:25.0546 1520 Schedule C:\WINDOWS\system32\schedsvc.dll
22:46:25.0687 1520 Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:46:25.0781 1520 seclogon C:\WINDOWS\System32\seclogon.dll
22:46:25.0937 1520 SENS C:\WINDOWS\system32\sens.dll
22:46:26.0078 1520 serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
22:46:26.0203 1520 Serial C:\WINDOWS\system32\DRIVERS\serial.sys
22:46:26.0328 1520 Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
22:46:26.0468 1520 SharedAccess C:\WINDOWS\System32\ipnathlp.dll
22:46:26.0609 1520 ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:46:26.0796 1520 Skype C2C Service C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:46:26.0968 1520 SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
22:46:27.0031 1520 SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
22:46:27.0156 1520 splitter C:\WINDOWS\system32\drivers\splitter.sys
22:46:27.0296 1520 Spooler C:\WINDOWS\system32\spoolsv.exe
22:46:27.0390 1520 sr C:\WINDOWS\system32\DRIVERS\sr.sys
22:46:27.0500 1520 srservice C:\WINDOWS\system32\srsvc.dll
22:46:27.0609 1520 Srv C:\WINDOWS\system32\DRIVERS\srv.sys
22:46:27.0781 1520 SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
22:46:27.0906 1520 stisvc C:\WINDOWS\system32\wiaservc.dll
22:46:28.0046 1520 streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:46:28.0187 1520 swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
22:46:28.0343 1520 swmidi C:\WINDOWS\system32\drivers\swmidi.sys
22:46:28.0781 1520 sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
22:46:28.0984 1520 SysmonLog C:\WINDOWS\system32\smlogsvc.exe
22:46:29.0156 1520 TapiSrv C:\WINDOWS\System32\tapisrv.dll
22:46:29.0375 1520 Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:46:29.0453 1520 TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
22:46:29.0593 1520 TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
22:46:29.0750 1520 TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
22:46:29.0875 1520 TermService C:\WINDOWS\System32\termsrv.dll
22:46:30.0031 1520 Themes C:\WINDOWS\System32\shsvcs.dll
22:46:30.0078 1520 TlntSvr C:\WINDOWS\system32\tlntsvr.exe
22:46:30.0171 1520 TrkWks C:\WINDOWS\system32\trkwks.dll
22:46:30.0328 1520 Udfs C:\WINDOWS\system32\drivers\Udfs.sys
22:46:30.0500 1520 UMWdf C:\WINDOWS\system32\wdfmgr.exe
22:46:30.0640 1520 Update C:\WINDOWS\system32\DRIVERS\update.sys
22:46:30.0828 1520 upnphost C:\WINDOWS\System32\upnphost.dll
22:46:30.0921 1520 UPS C:\WINDOWS\System32\ups.exe
22:46:31.0093 1520 usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
22:46:31.0265 1520 usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:46:31.0453 1520 usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:46:31.0671 1520 usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:46:31.0828 1520 usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:46:31.0968 1520 usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:46:32.0203 1520 usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys
22:46:32.0390 1520 VgaSave C:\WINDOWS\System32\drivers\vga.sys
22:46:32.0515 1520 VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
22:46:32.0656 1520 VSS C:\WINDOWS\System32\vssvc.exe
22:46:32.0750 1520 W32Time C:\WINDOWS\system32\w32time.dll
22:46:32.0906 1520 Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:46:33.0046 1520 wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
22:46:33.0187 1520 WebClient C:\WINDOWS\System32\webclnt.dll
22:46:33.0390 1520 winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
22:46:33.0609 1520 WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
22:46:33.0828 1520 Wmi C:\WINDOWS\System32\advapi32.dll
22:46:33.0937 1520 WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:46:34.0265 1520 WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
22:46:34.0468 1520 wscsvc C:\WINDOWS\system32\wscsvc.dll
22:46:34.0609 1520 WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:46:34.0765 1520 wuauserv C:\WINDOWS\system32\wuauserv.dll
22:46:34.0828 1520 WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:46:34.0875 1520 WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:46:34.0906 1520 WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
22:46:34.0984 1520 WZCSVC C:\WINDOWS\System32\wzcsvc.dll
22:46:35.0140 1520 xmlprov C:\WINDOWS\System32\xmlprov.dll
22:46:35.0250 1520 ================ Scan global ===============================
22:46:35.0281 1520 C:\WINDOWS\system32\basesrv.dll
22:46:35.0312 1520 C:\WINDOWS\system32\winsrv.dll
22:46:35.0312 1520 C:\WINDOWS\system32\winsrv.dll
22:46:35.0359 1520 C:\WINDOWS\system32\services.exe
22:46:35.0359 1520 ================ Scan MBR ==================================
22:46:35.0375 1520 \Device\Harddisk0\DR0
22:46:35.0562 1520 ================ Scan VBR ==================================
22:46:35.0562 1520 \Device\Harddisk0\DR0\Partition1
22:46:35.0578 1520 ================ Scan UEFI extensions ======================
22:46:35.0578 1520 ================ Scan active images ========================
22:46:35.0578 1520 ============================================================
22:46:35.0578 1520 Scan finished
22:46:35.0578 1520 ============================================================
22:46:36.0468 0240 Deinitialize success
????????????????????????????????????????????????????????????????????????????????????????????????
==============================================
EOF