Ospravedlnujem sa nedal som na prvykrat delete tak mam logy 2
13:08:42.0701 1028 TDSS rootkit removing tool 2.7.26.0 Apr 4 2012 19:52:02
13:08:42.0792 1028 ============================================================
13:08:42.0792 1028 Current date / time: 2012/04/06 13:08:42.0792
13:08:42.0792 1028 SystemInfo:
13:08:42.0792 1028
13:08:42.0792 1028 OS Version: 5.1.2600 ServicePack: 2.0
13:08:42.0792 1028 Product type: Workstation
13:08:42.0792 1028 ComputerName: USER-8E69AB6B10
13:08:42.0792 1028 UserName: user
13:08:42.0792 1028 Windows directory: C:\WINDOWS
13:08:42.0792 1028 System windows directory: C:\WINDOWS
13:08:42.0792 1028 Processor architecture: Intel x86
13:08:42.0792 1028 Number of processors: 1
13:08:42.0792 1028 Page size: 0x1000
13:08:42.0792 1028 Boot type: Normal boot
13:08:42.0792 1028 ============================================================
13:08:43.0082 1028 Drive \Device\Harddisk0\DR0 - Size: 0x9925B0000 (38.29 Gb), SectorSize: 0x200, Cylinders: 0x1386, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
13:08:43.0092 1028 Drive \Device\Harddisk1\DR9 - Size: 0x787FFE00 (1.88 Gb), SectorSize: 0x200, Cylinders: 0xF5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:08:43.0092 1028 \Device\Harddisk0\DR0:
13:08:43.0092 1028 MBR used
13:08:43.0092 1028 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x11F8A16
13:08:43.0102 1028 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x11F8A94, BlocksNum 0x3A962B1
13:08:43.0102 1028 \Device\Harddisk1\DR9:
13:08:43.0102 1028 MBR used
13:08:43.0102 1028 \Device\Harddisk1\DR9\Partition0: MBR, Type 0x6, StartLBA 0x3F, BlocksNum 0x3C3FC0
13:08:43.0172 1028 Initialize success
13:08:43.0172 1028 ============================================================
13:08:44.0955 3508 ============================================================
13:08:44.0955 3508 Scan started
13:08:44.0955 3508 Mode: Manual;
13:08:44.0955 3508 ============================================================
13:08:45.0716 3508 50819341 (58169ffb207940d4d84b4e85db02cc1e) C:\WINDOWS\system32\drivers\29854925.sys
13:08:45.0786 3508 Abiosdsk - ok
13:08:45.0836 3508 abp480n5 - ok
13:08:45.0896 3508 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
13:08:45.0906 3508 ACPI - ok
13:08:45.0956 3508 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
13:08:45.0966 3508 ACPIEC - ok
13:08:46.0056 3508 AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:08:46.0066 3508 AdobeFlashPlayerUpdateSvc - ok
13:08:46.0126 3508 adpu160m - ok
13:08:46.0196 3508 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys
13:08:46.0196 3508 aec - ok
13:08:46.0317 3508 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
13:08:46.0317 3508 AFD - ok
13:08:46.0397 3508 Aha154x - ok
13:08:46.0437 3508 aic78u2 - ok
13:08:46.0487 3508 aic78xx - ok
13:08:46.0537 3508 Alerter (c7ae0fd3867db0d42b03b73c18f3d671) C:\WINDOWS\system32\alrsvc.dll
13:08:46.0537 3508 Alerter - ok
13:08:46.0607 3508 ALG (f1958fbf86d5c004cf19a5951a9514b7) C:\WINDOWS\System32\alg.exe
13:08:46.0607 3508 ALG - ok
13:08:46.0657 3508 AliIde - ok
13:08:46.0717 3508 AmdK7 (680ad1c1bb16239e28d8f33a54a7a3c7) C:\WINDOWS\system32\DRIVERS\amdk7.sys
13:08:46.0717 3508 AmdK7 - ok
13:08:46.0807 3508 AMService - ok
13:08:46.0897 3508 amsint - ok
13:08:46.0968 3508 AppMgmt (9c3c12975c97119412802b181fbeeffe) C:\WINDOWS\System32\appmgmts.dll
13:08:46.0968 3508 AppMgmt - ok
13:08:47.0048 3508 asc - ok
13:08:47.0088 3508 asc3350p - ok
13:08:47.0118 3508 asc3550 - ok
13:08:47.0168 3508 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
13:08:47.0168 3508 aspnet_state - ok
13:08:47.0238 3508 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
13:08:47.0238 3508 AsyncMac - ok
13:08:47.0308 3508 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
13:08:47.0308 3508 atapi - ok
13:08:47.0348 3508 Atdisk - ok
13:08:47.0408 3508 ATIBTXBAR (11028c6a84a967070cb1286550f2058f) C:\WINDOWS\system32\starwindserviceae.dll
13:08:47.0408 3508 ATIBTXBAR ( Backdoor.Multi.ZAccess.gen ) - infected
13:08:47.0408 3508 ATIBTXBAR - detected Backdoor.Multi.ZAccess.gen (0)
13:08:47.0488 3508 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
13:08:47.0498 3508 Atmarpc - ok
13:08:47.0548 3508 AudioSrv (db66db626e4882ebef55f136f12c1829) C:\WINDOWS\System32\audiosrv.dll
13:08:47.0548 3508 AudioSrv - ok
13:08:47.0628 3508 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
13:08:47.0628 3508 audstub - ok
13:08:47.0959 3508 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
13:08:47.0959 3508 Beep - ok
13:08:48.0049 3508 BITS (2c69ec7e5a311334d10dd95f338fccea) C:\WINDOWS\system32\qmgr.dll
13:08:48.0059 3508 BITS - ok
13:08:48.0079 3508 Scan interrupted by user!
13:08:48.0079 3508 Scan interrupted by user!
13:08:48.0079 3508 Scan interrupted by user!
13:08:48.0079 3508 ============================================================
13:08:48.0079 3508 Scan finished
13:08:48.0079 3508 ============================================================
13:08:48.0119 2576 Detected object count: 1
13:08:48.0119 2576 Actual detected object count: 1
13:08:49.0711 2576 C:\WINDOWS\system32\starwindserviceae.dll - copied to quarantine
13:08:49.0711 2576 HKLM\SYSTEM\ControlSet001\services\ATIBTXBAR - will be deleted on reboot
13:08:49.0732 2576 C:\WINDOWS\system32\starwindserviceae.dll - will be deleted on reboot
13:08:49.0732 2576 ATIBTXBAR ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
13:08:53.0827 2692 Deinitialize success
a ten druhy
13:08:54.0859 1740 TDSS rootkit removing tool 2.7.26.0 Apr 4 2012 19:52:02
13:08:54.0919 1740 ============================================================
13:08:54.0919 1740 Current date / time: 2012/04/06 13:08:54.0919
13:08:54.0919 1740 SystemInfo:
13:08:54.0919 1740
13:08:54.0919 1740 OS Version: 5.1.2600 ServicePack: 2.0
13:08:54.0919 1740 Product type: Workstation
13:08:54.0919 1740 ComputerName: USER-8E69AB6B10
13:08:54.0919 1740 UserName: user
13:08:54.0919 1740 Windows directory: C:\WINDOWS
13:08:54.0919 1740 System windows directory: C:\WINDOWS
13:08:54.0919 1740 Processor architecture: Intel x86
13:08:54.0919 1740 Number of processors: 1
13:08:54.0919 1740 Page size: 0x1000
13:08:54.0919 1740 Boot type: Normal boot
13:08:54.0919 1740 ============================================================
13:08:55.0209 1740 Drive \Device\Harddisk0\DR0 - Size: 0x9925B0000 (38.29 Gb), SectorSize: 0x200, Cylinders: 0x1386, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
13:08:55.0209 1740 Drive \Device\Harddisk1\DR9 - Size: 0x787FFE00 (1.88 Gb), SectorSize: 0x200, Cylinders: 0xF5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:08:55.0209 1740 \Device\Harddisk0\DR0:
13:08:55.0209 1740 MBR used
13:08:55.0209 1740 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x11F8A16
13:08:55.0229 1740 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x11F8A94, BlocksNum 0x3A962B1
13:08:55.0229 1740 \Device\Harddisk1\DR9:
13:08:55.0229 1740 MBR used
13:08:55.0229 1740 \Device\Harddisk1\DR9\Partition0: MBR, Type 0x6, StartLBA 0x3F, BlocksNum 0x3C3FC0
13:08:55.0300 1740 Initialize success
13:08:55.0300 1740 ============================================================
13:08:58.0764 2564 ============================================================
13:08:58.0764 2564 Scan started
13:08:58.0764 2564 Mode: Manual; SigCheck; TDLFS;
13:08:58.0764 2564 ============================================================
13:08:59.0295 2564 24229892 (58169ffb207940d4d84b4e85db02cc1e) C:\WINDOWS\system32\drivers\75733164.sys
13:08:59.0385 2564 50819341 (58169ffb207940d4d84b4e85db02cc1e) C:\WINDOWS\system32\drivers\29854925.sys
13:08:59.0455 2564 Abiosdsk - ok
13:08:59.0506 2564 abp480n5 - ok
13:08:59.0576 2564 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
13:08:59.0826 2564 ACPI - ok
13:08:59.0906 2564 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
13:09:00.0167 2564 ACPIEC - ok
13:09:00.0267 2564 AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:09:00.0277 2564 AdobeFlashPlayerUpdateSvc - ok
13:09:00.0347 2564 adpu160m - ok
13:09:00.0427 2564 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys
13:09:00.0677 2564 aec - ok
13:09:00.0817 2564 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
13:09:00.0827 2564 AFD - ok
13:09:00.0908 2564 Aha154x - ok
13:09:00.0958 2564 aic78u2 - ok
13:09:00.0998 2564 aic78xx - ok
13:09:01.0058 2564 Alerter (c7ae0fd3867db0d42b03b73c18f3d671) C:\WINDOWS\system32\alrsvc.dll
13:09:01.0328 2564 Alerter - ok
13:09:01.0388 2564 ALG (f1958fbf86d5c004cf19a5951a9514b7) C:\WINDOWS\System32\alg.exe
13:09:01.0498 2564 ALG - ok
13:09:01.0569 2564 AliIde - ok
13:09:01.0649 2564 AmdK7 (680ad1c1bb16239e28d8f33a54a7a3c7) C:\WINDOWS\system32\DRIVERS\amdk7.sys
13:09:01.0909 2564 AmdK7 - ok
13:09:01.0989 2564 AMService - ok
13:09:02.0059 2564 amsint - ok
13:09:02.0129 2564 AppMgmt (9c3c12975c97119412802b181fbeeffe) C:\WINDOWS\System32\appmgmts.dll
13:09:02.0239 2564 AppMgmt - ok
13:09:02.0310 2564 asc - ok
13:09:02.0360 2564 asc3350p - ok
13:09:02.0400 2564 asc3550 - ok
13:09:02.0510 2564 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
13:09:02.0530 2564 aspnet_state - ok
13:09:02.0620 2564 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
13:09:02.0880 2564 AsyncMac - ok
13:09:02.0940 2564 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
13:09:03.0181 2564 atapi - ok
13:09:03.0241 2564 Atdisk - ok
13:09:03.0301 2564 ATIBTXBAR (11028c6a84a967070cb1286550f2058f) C:\WINDOWS\system32\starwindserviceae.dll
13:09:03.0311 2564 ATIBTXBAR ( Backdoor.Multi.ZAccess.gen ) - infected
13:09:03.0311 2564 ATIBTXBAR - detected Backdoor.Multi.ZAccess.gen (0)
13:09:03.0401 2564 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
13:09:03.0672 2564 Atmarpc - ok
13:09:03.0742 2564 AudioSrv (db66db626e4882ebef55f136f12c1829) C:\WINDOWS\System32\audiosrv.dll
13:09:03.0992 2564 AudioSrv - ok
13:09:04.0082 2564 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
13:09:04.0363 2564 audstub - ok
13:09:04.0463 2564 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
13:09:04.0693 2564 Beep - ok
13:09:05.0174 2564 BITS (2c69ec7e5a311334d10dd95f338fccea) C:\WINDOWS\system32\qmgr.dll
13:09:05.0434 2564 BITS - ok
13:09:05.0504 2564 Browser (e3cfccdda4edd1d0dc9168b2e18f27b8) C:\WINDOWS\System32\browser.dll
13:09:05.0724 2564 Browser - ok
13:09:05.0815 2564 BthEnum (d24b8d1784c68a25060fffbe8ed34b76) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
13:09:06.0085 2564 BthEnum - ok
13:09:06.0185 2564 BthPan (10355270be12641b9764235da39dcf0f) C:\WINDOWS\system32\DRIVERS\bthpan.sys
13:09:06.0395 2564 BthPan - ok
13:09:06.0476 2564 BTHPORT (95ef6f3f386d93ee1e4d9ca45a50252a) C:\WINDOWS\system32\Drivers\BTHport.sys
13:09:06.0506 2564 BTHPORT - ok
13:09:06.0576 2564 BthServ (a18cc8c9b3890b1b68bed213716fef6b) C:\WINDOWS\System32\bthserv.dll
13:09:06.0896 2564 BthServ - ok
13:09:06.0976 2564 BTHUSB (f06d4cb9918b462a84d9ac00027efc30) C:\WINDOWS\system32\Drivers\BTHUSB.sys
13:09:07.0277 2564 BTHUSB - ok
13:09:07.0357 2564 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
13:09:07.0577 2564 cbidf2k - ok
13:09:07.0677 2564 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
13:09:07.0948 2564 CCDECODE - ok
13:09:08.0028 2564 cd20xrnt - ok
13:09:08.0088 2564 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
13:09:08.0358 2564 Cdaudio - ok
13:09:08.0438 2564 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
13:09:08.0699 2564 Cdfs - ok
13:09:08.0769 2564 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
13:09:09.0029 2564 Cdrom - ok
13:09:09.0079 2564 Changer - ok
13:09:09.0139 2564 CiSvc (3192bd04d032a9c4a85a3278c268a13a) C:\WINDOWS\system32\cisvc.exe
13:09:09.0340 2564 CiSvc - ok
13:09:09.0400 2564 ClipSrv (c8dec22c4137d7a90f8bdf41ca4b82ae) C:\WINDOWS\system32\clipsrv.exe
13:09:09.0630 2564 ClipSrv - ok
13:09:09.0720 2564 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:09:09.0730 2564 clr_optimization_v2.0.50727_32 - ok
13:09:09.0790 2564 CmdIde - ok
13:09:09.0840 2564 COMSysApp - ok
13:09:09.0921 2564 Cpqarray - ok
13:09:09.0971 2564 CryptSvc (10654f9ddcea9c46cfb77554231be73b) C:\WINDOWS\System32\cryptsvc.dll
13:09:10.0211 2564 CryptSvc - ok
13:09:10.0271 2564 dac2w2k - ok
13:09:10.0321 2564 dac960nt - ok
13:09:10.0421 2564 DcomLaunch (01095febf33beea00c2a0730b9b3ec28) C:\WINDOWS\system32\rpcss.dll
13:09:10.0521 2564 DcomLaunch - ok
13:09:10.0602 2564 Dhcp (cb6ca3e5261d65f6f809eed23bf167aa) C:\WINDOWS\System32\dhcpcsvc.dll
13:09:10.0902 2564 Dhcp - ok
13:09:10.0982 2564 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
13:09:11.0252 2564 Disk - ok
13:09:11.0293 2564 dmadmin - ok
13:09:11.0383 2564 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
13:09:11.0643 2564 dmboot - ok
13:09:11.0753 2564 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
13:09:12.0044 2564 dmio - ok
13:09:12.0124 2564 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
13:09:12.0374 2564 dmload - ok
13:09:12.0424 2564 dmserver (1639d9964c9e1b2ecca95c8217d3e70d) C:\WINDOWS\System32\dmserver.dll
13:09:12.0715 2564 dmserver - ok
13:09:12.0795 2564 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
13:09:13.0055 2564 DMusic - ok
13:09:13.0125 2564 Dnscache (7379de06fd196e396a00aa97b990c00d) C:\WINDOWS\System32\dnsrslvr.dll
13:09:13.0386 2564 Dnscache - ok
13:09:13.0456 2564 dpti2o - ok
13:09:13.0506 2564 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
13:09:13.0746 2564 drmkaud - ok
13:09:13.0836 2564 ERSvc (67dff7bbbd0e80aab7b3cf061448db8a) C:\WINDOWS\System32\ersvc.dll
13:09:14.0087 2564 ERSvc - ok
13:09:14.0147 2564 Eventlog (37561f8d4160d62da86d24ae41fae8de) C:\WINDOWS\system32\services.exe
13:09:14.0227 2564 Eventlog - ok
13:09:14.0307 2564 EventSystem (60d1a6342238378bfb7545c81ee3606c) C:\WINDOWS\system32\es.dll
13:09:14.0347 2564 EventSystem - ok
13:09:14.0437 2564 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
13:09:14.0637 2564 Fastfat - ok
13:09:14.0717 2564 FastUserSwitchingCompatibility (e7518dc542d3ebdcb80edd98462c7821) C:\WINDOWS\System32\shsvcs.dll
13:09:14.0938 2564 FastUserSwitchingCompatibility - ok
13:09:14.0998 2564 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
13:09:15.0218 2564 Fdc - ok
13:09:15.0298 2564 FET5X86V (92cbce0913661ff966f9fb696a1775a5) C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
13:09:15.0308 2564 FET5X86V - ok
13:09:15.0378 2564 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
13:09:15.0659 2564 Fips - ok
13:09:15.0749 2564 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
13:09:16.0019 2564 Flpydisk - ok
13:09:16.0099 2564 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
13:09:16.0350 2564 FltMgr - ok
13:09:16.0480 2564 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
13:09:16.0490 2564 FontCache3.0.0.0 - ok
13:09:16.0560 2564 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
13:09:16.0840 2564 Fs_Rec - ok
13:09:16.0921 2564 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
13:09:17.0151 2564 Ftdisk - ok
13:09:17.0231 2564 gameenum (5f92fd09e5610a5995da7d775eadcd12) C:\WINDOWS\system32\DRIVERS\gameenum.sys
13:09:17.0511 2564 gameenum - ok
13:09:17.0582 2564 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
13:09:17.0862 2564 Gpc - ok
13:09:17.0942 2564 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
13:09:17.0952 2564 gupdate - ok
13:09:17.0982 2564 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
13:09:17.0992 2564 gupdatem - ok
13:09:18.0072 2564 helpsvc (8827911a8c37e40c027cbfc88e69d967) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
13:09:18.0373 2564 helpsvc - ok
13:09:18.0433 2564 HidServ - ok
13:09:18.0503 2564 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
13:09:18.0733 2564 HidUsb - ok
13:09:18.0813 2564 hpn - ok
13:09:18.0883 2564 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
13:09:18.0913 2564 HTTP - ok
13:09:18.0994 2564 HTTPFilter (064d8581adf77c25133e7d751d917d83) C:\WINDOWS\System32\w3ssl.dll
13:09:19.0254 2564 HTTPFilter - ok
13:09:19.0314 2564 i2omgmt - ok
13:09:19.0374 2564 i2omp - ok
13:09:19.0424 2564 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
13:09:19.0624 2564 i8042prt - ok
13:09:19.0765 2564 idsvc (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:09:19.0815 2564 idsvc - ok
13:09:19.0925 2564 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
13:09:20.0165 2564 Imapi - ok
13:09:20.0245 2564 ImapiService (fa788520bcac0f5d9d5cde5615c0d931) C:\WINDOWS\system32\imapi.exe
13:09:20.0516 2564 ImapiService - ok
13:09:20.0596 2564 ini910u - ok
13:09:20.0676 2564 IntelIde - ok
13:09:20.0736 2564 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
13:09:20.0956 2564 Ip6Fw - ok
13:09:21.0037 2564 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
13:09:21.0247 2564 IpFilterDriver - ok
13:09:21.0337 2564 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
13:09:21.0567 2564 IpInIp - ok
13:09:21.0637 2564 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys
13:09:21.0878 2564 IpNat - ok
13:09:21.0958 2564 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
13:09:22.0178 2564 IPSec - ok
13:09:22.0268 2564 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
13:09:22.0378 2564 IRENUM - ok
13:09:22.0459 2564 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
13:09:22.0699 2564 isapnp - ok
13:09:22.0789 2564 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
13:09:23.0069 2564 Kbdclass - ok
13:09:23.0150 2564 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys
13:09:23.0360 2564 kmixer - ok
13:09:23.0430 2564 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
13:09:23.0460 2564 KSecDD - ok
13:09:23.0530 2564 lanmanserver (93d32468d34e000cb3407947d1d6e22a) C:\WINDOWS\System32\srvsvc.dll
13:09:23.0750 2564 lanmanserver - ok
13:09:23.0861 2564 lanmanworkstation (e1f27cfcd114ec9f1e1f44674b2ff9f0) C:\WINDOWS\System32\wkssvc.dll
13:09:23.0881 2564 lanmanworkstation - ok
13:09:23.0951 2564 lbrtfdc - ok
13:09:24.0001 2564 lcs - ok
13:09:24.0081 2564 LmHosts (b3eff6d938c572e90a07b3d87a3c7657) C:\WINDOWS\System32\lmhsvc.dll
13:09:24.0301 2564 LmHosts - ok
13:09:24.0401 2564 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
13:09:24.0451 2564 McComponentHostService - ok
13:09:24.0532 2564 Messenger (95fd808e4ac22aba025a7b3eac0375d2) C:\WINDOWS\System32\msgsvc.dll
13:09:24.0762 2564 Messenger - ok
13:09:24.0852 2564 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
13:09:25.0102 2564 mnmdd - ok
13:09:25.0182 2564 mnmsrvc (f6415361201915b9fe3896b0e4e724ff) C:\WINDOWS\system32\mnmsrvc.exe
13:09:25.0383 2564 mnmsrvc - ok
13:09:25.0453 2564 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
13:09:25.0693 2564 Modem - ok
13:09:25.0763 2564 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
13:09:26.0024 2564 Mouclass - ok
13:09:26.0104 2564 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
13:09:26.0314 2564 mouhid - ok
13:09:26.0394 2564 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
13:09:26.0645 2564 MountMgr - ok
13:09:26.0715 2564 mraid35x - ok
13:09:26.0785 2564 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
13:09:26.0995 2564 MRxDAV - ok
13:09:27.0105 2564 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
13:09:27.0155 2564 MRxSmb - ok
13:09:27.0265 2564 MSDTC (c7c3d89eb0a6f3dba622ea737fa335b1) C:\WINDOWS\system32\msdtc.exe
13:09:27.0506 2564 MSDTC - ok
13:09:27.0606 2564 msdv (11028c6a84a967070cb1286550f2058f) C:\WINDOWS\system32\sglfb.dll
13:09:27.0606 2564 msdv ( Backdoor.Multi.ZAccess.gen ) - infected
13:09:27.0606 2564 msdv - detected Backdoor.Multi.ZAccess.gen (0)
13:09:27.0716 2564 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
13:09:27.0916 2564 Msfs - ok
13:09:27.0946 2564 MSIServer - ok
13:09:28.0037 2564 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
13:09:28.0247 2564 MSKSSRV - ok
13:09:28.0337 2564 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
13:09:28.0557 2564 MSPCLOCK - ok
13:09:28.0637 2564 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
13:09:28.0858 2564 MSPQM - ok
13:09:28.0938 2564 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
13:09:29.0148 2564 mssmbios - ok
13:09:29.0228 2564 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
13:09:29.0439 2564 MSTEE - ok
13:09:29.0519 2564 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
13:09:29.0729 2564 ms_mpu401 - ok
13:09:29.0789 2564 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
13:09:29.0999 2564 Mup - ok
13:09:30.0039 2564 mzdsxczv - ok
13:09:30.0130 2564 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
13:09:30.0350 2564 NABTSFEC - ok
13:09:30.0440 2564 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
13:09:30.0660 2564 NDIS - ok
13:09:30.0740 2564 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
13:09:30.0961 2564 NdisIP - ok
13:09:31.0031 2564 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
13:09:31.0231 2564 NdisTapi - ok
13:09:31.0301 2564 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
13:09:31.0522 2564 Ndisuio - ok
13:09:31.0602 2564 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
13:09:31.0812 2564 NdisWan - ok
13:09:31.0882 2564 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
13:09:32.0112 2564 NDProxy - ok
13:09:32.0193 2564 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
13:09:32.0383 2564 NetBIOS - ok
13:09:32.0483 2564 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\drivers\tsk1E4.tmp
13:09:32.0483 2564 Suspicious file (NoAccess): C:\WINDOWS\system32\drivers\tsk1E4.tmp. md5: 0c80e410cd2f47134407ee7dd19cc86b
13:09:32.0583 2564 NetDDE (05afb5ad06462257bea7495283c86d50) C:\WINDOWS\system32\netdde.exe
13:09:32.0833 2564 NetDDE - ok
13:09:32.0864 2564 NetDDEdsdm (05afb5ad06462257bea7495283c86d50) C:\WINDOWS\system32\netdde.exe
13:09:33.0064 2564 NetDDEdsdm - ok
13:09:33.0144 2564 Netlogon (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe
13:09:33.0364 2564 Netlogon - ok
13:09:33.0434 2564 Netman (dab9e6c7105d2ef49876fe92c524f565) C:\WINDOWS\System32\netman.dll
13:09:33.0655 2564 Netman - ok
13:09:33.0755 2564 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:09:33.0765 2564 NetTcpPortSharing - ok
13:09:33.0845 2564 Nla (097722f235a1fb698bf9234e01b52637) C:\WINDOWS\System32\mswsock.dll
13:09:33.0915 2564 Nla - ok
13:09:33.0985 2564 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
13:09:34.0195 2564 Npfs - ok
13:09:34.0286 2564 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys
13:09:34.0516 2564 Ntfs - ok
13:09:34.0576 2564 NtLmSsp (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe
13:09:34.0786 2564 NtLmSsp - ok
13:09:34.0866 2564 NtmsSvc (b62f29c00ac55a761b2e45877d85ea0f) C:\WINDOWS\system32\ntmssvc.dll
13:09:35.0137 2564 NtmsSvc - ok
13:09:35.0227 2564 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
13:09:35.0427 2564 Null - ok
13:09:35.0537 2564 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
13:09:35.0828 2564 nv - ok
13:09:35.0908 2564 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
13:09:36.0118 2564 NwlnkFlt - ok
13:09:36.0208 2564 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
13:09:36.0419 2564 NwlnkFwd - ok
13:09:36.0459 2564 ose (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:09:36.0479 2564 ose - ok
13:09:36.0579 2564 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
13:09:36.0819 2564 Parport - ok
13:09:36.0889 2564 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
13:09:37.0100 2564 PartMgr - ok
13:09:37.0170 2564 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
13:09:37.0400 2564 ParVdm - ok
13:09:37.0470 2564 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
13:09:37.0670 2564 PCI - ok
13:09:37.0721 2564 PCIDump - ok
13:09:37.0761 2564 PCIIde - ok
13:09:37.0821 2564 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
13:09:38.0071 2564 Pcmcia - ok
13:09:38.0141 2564 PDCOMP - ok
13:09:38.0181 2564 PDFRAME - ok
13:09:38.0221 2564 PDRELI - ok
13:09:38.0261 2564 PDRFRAME - ok
13:09:38.0301 2564 perc2 - ok
13:09:38.0341 2564 perc2hib - ok
13:09:38.0472 2564 PlugPlay (37561f8d4160d62da86d24ae41fae8de) C:\WINDOWS\system32\services.exe
13:09:38.0552 2564 PlugPlay - ok
13:09:38.0612 2564 PolicyAgent (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe
13:09:38.0802 2564 PolicyAgent - ok
13:09:38.0872 2564 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
13:09:39.0062 2564 PptpMiniport - ok
13:09:39.0102 2564 ProtectedStorage (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe
13:09:39.0303 2564 ProtectedStorage - ok
13:09:39.0373 2564 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
13:09:39.0573 2564 PSched - ok
13:09:39.0633 2564 PSI_SVC_2 (a6a7ad767bf5141665f5c675f671b3e1) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
13:09:39.0643 2564 PSI_SVC_2 - ok
13:09:39.0753 2564 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
13:09:39.0954 2564 Ptilink - ok
13:09:40.0004 2564 ql1080 - ok
13:09:40.0044 2564 Ql10wnt - ok
13:09:40.0084 2564 ql12160 - ok
13:09:40.0134 2564 ql1240 - ok
13:09:40.0184 2564 ql1280 - ok
13:09:40.0254 2564 rampartsvc (11028c6a84a967070cb1286550f2058f) C:\WINDOWS\system32\Appn.dll
13:09:40.0254 2564 rampartsvc ( Backdoor.Multi.ZAccess.gen ) - infected
13:09:40.0254 2564 rampartsvc - detected Backdoor.Multi.ZAccess.gen (0)
13:09:40.0344 2564 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
13:09:40.0555 2564 RasAcd - ok
13:09:40.0625 2564 RasAuto (44db7a9bdd2fb58747d123fbf1d35adb) C:\WINDOWS\System32\rasauto.dll
13:09:40.0845 2564 RasAuto - ok
13:09:40.0915 2564 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
13:09:41.0135 2564 Rasl2tp - ok
13:09:41.0206 2564 RasMan (41a3c11e3517c962c9b44893bcec3b34) C:\WINDOWS\System32\rasmans.dll
13:09:41.0416 2564 RasMan - ok
13:09:41.0496 2564 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
13:09:41.0726 2564 RasPppoe - ok
13:09:41.0786 2564 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
13:09:41.0977 2564 Raspti - ok
13:09:42.0027 2564 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys
13:09:42.0237 2564 Rdbss - ok
13:09:42.0277 2564 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
13:09:42.0467 2564 RDPCDD - ok
13:09:42.0537 2564 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
13:09:42.0738 2564 rdpdr - ok
13:09:42.0818 2564 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys
13:09:43.0028 2564 RDPWD - ok
13:09:43.0138 2564 RDSessMgr (729798e0933076b8fcfcd9934698f164) C:\WINDOWS\system32\sessmgr.exe
13:09:43.0329 2564 RDSessMgr - ok
13:09:43.0429 2564 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
13:09:43.0619 2564 redbook - ok
13:09:43.0689 2564 RemoteAccess (3046db917e3cfa040632799dd9b14865) C:\WINDOWS\System32\mprdim.dll
13:09:43.0889 2564 RemoteAccess - ok
13:09:43.0949 2564 RemoteRegistry (3151427db7d87107d1c5be58fac53960) C:\WINDOWS\system32\regsvc.dll
13:09:44.0150 2564 RemoteRegistry - ok
13:09:44.0220 2564 RFCOMM (99c4b74981a1413f142a3903130088cb) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
13:09:44.0410 2564 RFCOMM - ok
13:09:44.0470 2564 RpcLocator (793f04a09b15e7c6c11dbdffaf06c0ab) C:\WINDOWS\system32\locator.exe
13:09:44.0660 2564 RpcLocator - ok
13:09:44.0731 2564 RpcSs (01095febf33beea00c2a0730b9b3ec28) C:\WINDOWS\system32\rpcss.dll
13:09:44.0851 2564 RpcSs - ok
13:09:44.0941 2564 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
13:09:45.0131 2564 RSVP - ok
13:09:45.0211 2564 RT2500 (ae1e626f00180bfb3ca5a81fffc65332) C:\WINDOWS\system32\DRIVERS\RT2500.sys
13:09:45.0231 2564 RT2500 - ok
13:09:45.0311 2564 s125bus (06847aa6f3a9bf7c44134d00a2e578c0) C:\WINDOWS\system32\DRIVERS\s125bus.sys
13:09:45.0321 2564 s125bus - ok
13:09:45.0412 2564 s125mdfl (f83f88e1b125308fb5015ea0349502b0) C:\WINDOWS\system32\DRIVERS\s125mdfl.sys
13:09:45.0422 2564 s125mdfl - ok
13:09:45.0482 2564 s125mdm (402a97756c14940ad6ae5169c2fb105e) C:\WINDOWS\system32\DRIVERS\s125mdm.sys
13:09:45.0492 2564 s125mdm - ok
13:09:45.0562 2564 s125mgmt (82b14c51de76825ec769a6374e4c57d6) C:\WINDOWS\system32\DRIVERS\s125mgmt.sys
13:09:45.0582 2564 s125mgmt - ok
13:09:45.0652 2564 s125obex (bedfc5707c356fd073bf1a4afe442d91) C:\WINDOWS\system32\DRIVERS\s125obex.sys
13:09:45.0662 2564 s125obex - ok
13:09:45.0752 2564 SamSs (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe
13:09:45.0942 2564 SamSs - ok
13:09:46.0022 2564 SCardSvr (25d8de134df108e3dbc8d7d23b1aa58e) C:\WINDOWS\System32\SCardSvr.exe
13:09:46.0223 2564 SCardSvr - ok
13:09:46.0303 2564 Schedule (92360854316611f6cc471612213c3d92) C:\WINDOWS\system32\schedsvc.dll
13:09:46.0493 2564 Schedule - ok
13:09:46.0573 2564 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
13:09:46.0693 2564 Secdrv - ok
13:09:46.0753 2564 seclogon (b1e0ce09895376871746f36dc5773b4f) C:\WINDOWS\System32\seclogon.dll
13:09:46.0964 2564 seclogon - ok
13:09:47.0004 2564 SENS (dfd9870cf39c791d86c4c209da9fa919) C:\WINDOWS\system32\sens.dll
13:09:47.0204 2564 SENS - ok
13:09:47.0264 2564 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
13:09:47.0455 2564 serenum - ok
13:09:47.0525 2564 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
13:09:47.0725 2564 Serial - ok
13:09:47.0845 2564 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
13:09:48.0035 2564 Sfloppy - ok
13:09:48.0105 2564 SharedAccess (36cc8c01b5e50163037bef56cb96deff) C:\WINDOWS\System32\ipnathlp.dll
13:09:48.0306 2564 SharedAccess - ok
13:09:48.0376 2564 ShellHWDetection (e7518dc542d3ebdcb80edd98462c7821) C:\WINDOWS\System32\shsvcs.dll
13:09:48.0576 2564 ShellHWDetection - ok
13:09:48.0636 2564 Simbad - ok
13:09:48.0726 2564 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
13:09:48.0917 2564 SLIP - ok
13:09:48.0997 2564 Sparrow - ok
13:09:49.0067 2564 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys
13:09:49.0247 2564 splitter - ok
13:09:49.0317 2564 Spooler (7435b108b935e42ea92ca94f59c8e717) C:\WINDOWS\system32\spoolsv.exe
13:09:49.0487 2564 Spooler - ok
13:09:49.0558 2564 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
13:09:49.0668 2564 sr - ok
13:09:49.0758 2564 srservice (92bdf74f12d6cbec43c94d4b7f804838) C:\WINDOWS\system32\srsvc.dll
13:09:49.0878 2564 srservice - ok
13:09:49.0968 2564 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
13:09:49.0998 2564 Srv - ok
13:09:50.0078 2564 SSDPSRV (4b8d61792f7175bed48859cc18ce4e38) C:\WINDOWS\System32\ssdpsrv.dll
13:09:50.0188 2564 SSDPSRV - ok
13:09:50.0249 2564 stisvc (d9f6c4f6b1e188adafc42b561d9bc2e6) C:\WINDOWS\system32\wiaservc.dll
13:09:50.0449 2564 stisvc - ok
13:09:50.0519 2564 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
13:09:50.0719 2564 streamip - ok
13:09:50.0779 2564 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
13:09:50.0970 2564 swenum - ok
13:09:51.0020 2564 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
13:09:51.0210 2564 swmidi - ok
13:09:51.0260 2564 SwPrv - ok
13:09:51.0320 2564 symc810 - ok
13:09:51.0380 2564 symc8xx - ok
13:09:51.0420 2564 sym_hi - ok
13:09:51.0470 2564 sym_u3 - ok
13:09:51.0520 2564 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
13:09:51.0721 2564 sysaudio - ok
13:09:51.0791 2564 SysmonLog (8b54aa346d1b1b113ffaa75501b8b1b2) C:\WINDOWS\system32\smlogsvc.exe
13:09:51.0981 2564 SysmonLog - ok
13:09:52.0061 2564 tangoservice (11028c6a84a967070cb1286550f2058f) C:\WINDOWS\system32\sweepsrv.sys.dll
13:09:52.0061 2564 tangoservice ( Backdoor.Multi.ZAccess.gen ) - infected
13:09:52.0061 2564 tangoservice - detected Backdoor.Multi.ZAccess.gen (0)
13:09:52.0141 2564 TapiSrv (eb4a4187d74a8efdcbea3ea2cb1bdfbd) C:\WINDOWS\System32\tapisrv.dll
13:09:52.0332 2564 TapiSrv - ok
13:09:52.0412 2564 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
13:09:52.0502 2564 Tcpip - ok
13:09:52.0582 2564 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
13:09:52.0772 2564 TDPIPE - ok
13:09:52.0872 2564 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
13:09:53.0053 2564 TDTCP - ok
13:09:53.0143 2564 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
13:09:53.0333 2564 TermDD - ok
13:09:53.0393 2564 TermService (b60c877d16d9c880b952fda04adf16e6) C:\WINDOWS\System32\termsrv.dll
13:09:53.0593 2564 TermService - ok
13:09:53.0653 2564 Themes (e7518dc542d3ebdcb80edd98462c7821) C:\WINDOWS\System32\shsvcs.dll
13:09:53.0854 2564 Themes - ok
13:09:53.0924 2564 TlntSvr (37db0a7d097310e8b4de803fc3119c78) C:\WINDOWS\system32\tlntsvr.exe
13:09:54.0024 2564 TlntSvr - ok
13:09:54.0094 2564 TosIde - ok
13:09:54.0154 2564 TrkWks (6d9ac544b30f96c57f8206566c1fb6a1) C:\WINDOWS\system32\trkwks.dll
13:09:54.0354 2564 TrkWks - ok
13:09:54.0435 2564 uagp35 (49c805d42d75eddc9b6a7130999c9054) C:\WINDOWS\system32\DRIVERS\uagp35.sys
13:09:54.0635 2564 uagp35 - ok
13:09:54.0735 2564 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
13:09:54.0915 2564 Udfs - ok
13:09:54.0975 2564 ultra - ok
13:09:55.0045 2564 UnlockerDriver5 (bb879dcfd22926efbeb3298129898cbb) C:\Program Files\Unlocker\UnlockerDriver5.sys
13:09:55.0045 2564 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - warning
13:09:55.0045 2564 UnlockerDriver5 - detected UnsignedFile.Multi.Generic (1)
13:09:55.0146 2564 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys
13:09:55.0326 2564 Update - ok
13:09:55.0406 2564 upnphost (0546477bde979e33294fe97f6b3de84a) C:\WINDOWS\System32\upnphost.dll
13:09:55.0516 2564 upnphost - ok
13:09:55.0576 2564 UPS (3f5df65b0758675f95a2d43918a740a3) C:\WINDOWS\System32\ups.exe
13:09:55.0776 2564 UPS - ok
13:09:55.0837 2564 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
13:09:56.0027 2564 usbccgp - ok
13:09:56.0097 2564 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
13:09:56.0287 2564 usbehci - ok
13:09:56.0347 2564 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
13:09:56.0548 2564 usbhub - ok
13:09:56.0608 2564 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
13:09:56.0798 2564 usbscan - ok
13:09:56.0878 2564 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
13:09:57.0068 2564 USBSTOR - ok
13:09:57.0128 2564 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
13:09:57.0319 2564 usbuhci - ok
13:09:57.0379 2564 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys
13:09:57.0569 2564 usbvideo - ok
13:09:57.0629 2564 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
13:09:57.0819 2564 VgaSave - ok
13:09:57.0910 2564 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
13:09:58.0090 2564 ViaIde - ok
13:09:58.0180 2564 VIAudio (5e02b47671ec147251ab5487d039474d) C:\WINDOWS\system32\drivers\vinyl97.sys
13:09:58.0200 2564 VIAudio - ok
13:09:58.0280 2564 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
13:09:58.0470 2564 VolSnap - ok
13:09:58.0550 2564 VSS (3ee00364ae0fd8d604f46cbaf512838a) C:\WINDOWS\System32\vssvc.exe
13:09:58.0651 2564 VSS - ok
13:09:58.0741 2564 W32Time (2b281958f5d0cf99ed626e3ef39d5c8d) C:\WINDOWS\system32\w32time.dll
13:09:58.0951 2564 W32Time - ok
13:09:59.0051 2564 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
13:09:59.0241 2564 Wanarp - ok
13:09:59.0312 2564 WDICA - ok
13:09:59.0372 2564 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys
13:09:59.0572 2564 wdmaud - ok
13:09:59.0612 2564 WDM_YAMAHAAC97 - ok
13:09:59.0682 2564 WebClient (5d0a442864bfbf3b19dcca4cd29f6e99) C:\WINDOWS\System32\webclnt.dll
13:09:59.0872 2564 WebClient - ok
13:09:59.0962 2564 winmgmt (f399242a80c4066fd155efa4cf96658e) C:\WINDOWS\system32\wbem\WMIsvc.dll
13:10:00.0153 2564 winmgmt - ok
13:10:00.0283 2564 WmdmPmSN (c086483e3dba8c1c0a687ec8d5b3d4c1) C:\WINDOWS\system32\mspmsnsv.dll
13:10:00.0483 2564 WmdmPmSN - ok
13:10:00.0633 2564 Wmi (1081c185aed0660b2b5f173c3e023b23) C:\WINDOWS\System32\advapi32.dll
13:10:00.0724 2564 Wmi - ok
13:10:00.0864 2564 WmiApSrv (ba8cecc3e813e1f7c441b20393d4f86c) C:\WINDOWS\system32\wbem\wmiapsrv.exe
13:10:01.0054 2564 WmiApSrv - ok
13:10:01.0144 2564 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
13:10:01.0334 2564 WSTCODEC - ok
13:10:01.0395 2564 wuauserv (13d72740963cba12d9ff76a7f218bcd8) C:\WINDOWS\system32\wuauserv.dll
13:10:01.0595 2564 wuauserv - ok
13:10:01.0665 2564 WZCSVC (5a91e6feab9f901302fa7ff768c0120f) C:\WINDOWS\System32\wzcsvc.dll
13:10:01.0875 2564 WZCSVC - ok
13:10:01.0935 2564 xmlprov (eef46dab68229a14da3d8e73c99e2959) C:\WINDOWS\System32\xmlprov.dll
13:10:02.0136 2564 xmlprov - ok
13:10:02.0206 2564 zhynbowcjiqat3 (30bc6dd10c7c38a2425fb8e435a256ca) C:\WINDOWS\system32\drivers\zhynbowcjiqat3.sys
13:10:02.0206 2564 Suspicious file (Hidden): C:\WINDOWS\system32\drivers\zhynbowcjiqat3.sys. md5: 30bc6dd10c7c38a2425fb8e435a256ca
13:10:02.0206 2564 zhynbowcjiqat3 ( HiddenFile.Multi.Generic ) - warning
13:10:02.0206 2564 zhynbowcjiqat3 - detected HiddenFile.Multi.Generic (1)
13:10:02.0286 2564 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
13:10:02.0536 2564 \Device\Harddisk0\DR0 - ok
13:10:02.0566 2564 MBR (0x1B8) (e5fa06aca0d60ba9c870d0ef3d9898c9) \Device\Harddisk1\DR9
13:10:05.0050 2564 \Device\Harddisk1\DR9 - ok
13:10:05.0070 2564 Boot (0x1200) (4c217f2cd03213f8a2bc1e27f8bd979e) \Device\Harddisk0\DR0\Partition0
13:10:05.0070 2564 \Device\Harddisk0\DR0\Partition0 - ok
13:10:05.0100 2564 Boot (0x1200) (d94d46aa6f6f9f0320cb9e864465d6e8) \Device\Harddisk0\DR0\Partition1
13:10:05.0110 2564 \Device\Harddisk0\DR0\Partition1 - ok
13:10:05.0130 2564 Boot (0x1200) (e4e947332a924a4bfb88f4a9142ea65e) \Device\Harddisk1\DR9\Partition0
13:10:05.0130 2564 \Device\Harddisk1\DR9\Partition0 - ok
13:10:05.0140 2564 ============================================================
13:10:05.0140 2564 Scan finished
13:10:05.0140 2564 ============================================================
13:10:05.0280 2824 Detected object count: 6
13:10:05.0280 2824 Actual detected object count: 6
13:10:17.0698 2824 C:\WINDOWS\system32\starwindserviceae.dll - copied to quarantine
13:10:17.0698 2824 HKLM\SYSTEM\ControlSet001\services\ATIBTXBAR - will be deleted on reboot
13:10:17.0708 2824 C:\WINDOWS\system32\starwindserviceae.dll - will be deleted on reboot
13:10:17.0708 2824 ATIBTXBAR ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
13:10:17.0828 2824 C:\WINDOWS\system32\sglfb.dll - copied to quarantine
13:10:17.0838 2824 HKLM\SYSTEM\ControlSet001\services\msdv - will be deleted on reboot
13:10:17.0848 2824 C:\WINDOWS\system32\sglfb.dll - will be deleted on reboot
13:10:17.0848 2824 msdv ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
13:10:17.0908 2824 C:\WINDOWS\system32\Appn.dll - copied to quarantine
13:10:17.0908 2824 HKLM\SYSTEM\ControlSet001\services\rampartsvc - will be deleted on reboot
13:10:17.0908 2824 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - cured
13:10:17.0918 2824 C:\WINDOWS\system32\Appn.dll - will be deleted on reboot
13:10:17.0918 2824 rampartsvc ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
13:10:18.0018 2824 C:\WINDOWS\system32\sweepsrv.sys.dll - copied to quarantine
13:10:18.0018 2824 HKLM\SYSTEM\ControlSet001\services\tangoservice - will be deleted on reboot
13:10:18.0018 2824 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - cured
13:10:18.0028 2824 C:\WINDOWS\system32\sweepsrv.sys.dll - will be deleted on reboot
13:10:18.0028 2824 tangoservice ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
13:10:18.0048 2824 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - skipped by user
13:10:18.0048 2824 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:10:18.0059 2824 zhynbowcjiqat3 ( HiddenFile.Multi.Generic ) - skipped by user
13:10:18.0059 2824 zhynbowcjiqat3 ( HiddenFile.Multi.Generic ) - User select action: Skip
13:10:20.0232 2896 Deinitialize success