Liste der Anhänge anzeigen (Anzahl: 1) Hallo mort,
vielen Dank für die Lösung!!!
Einzig der empfohlene TDSSKiller war in der Lage, den Befall zu beheben (ADWCleaner z. B. nicht). Beim ersten Scandurchgang wurde ein Befall festgestellt (Log 1) nach dem Neustart habe ich den Scan nochmals gemacht (diesmal alles angehakt) und es wurde 2 mal "Rootkit.Win32.Necurs.gen" (Log2) gefunden und beseitigt. Seitdem funktioniert alles wieder bestens! Ich bin Dir sehr dankbar, weil ich viel Zeit für ein Neuaufsetzen des Systems gespart habe!
Schönes Wochenende
Samos Code:
15:26:44.0067 0x0b74 TDSS rootkit removing tool 3.0.0.33 Apr 24 2014 14:02:50
15:26:44.0379 0x0b74 ============================================================
15:26:44.0379 0x0b74 Current date / time: 2014/04/25 15:26:44.0379
15:26:44.0379 0x0b74 SystemInfo:
15:26:44.0379 0x0b74
15:26:44.0379 0x0b74 OS Version: 6.1.7601 ServicePack: 1.0
15:26:44.0379 0x0b74 Product type: Workstation
15:26:44.0379 0x0b74 ComputerName:
15:26:44.0379 0x0b74 UserName:
15:26:44.0379 0x0b74 Windows directory: C:\Windows
15:26:44.0379 0x0b74 System windows directory: C:\Windows
15:26:44.0379 0x0b74 Running under WOW64
15:26:44.0379 0x0b74 Processor architecture: Intel x64
15:26:44.0379 0x0b74 Number of processors: 8
15:26:44.0379 0x0b74 Page size: 0x1000
15:26:44.0379 0x0b74 Boot type: Normal boot
15:26:44.0379 0x0b74 ============================================================
15:26:44.0410 0x0b74 BG loaded
15:26:47.0514 0x0b74 System UUID: {47825797-1968-70A5-E70A-EB250F488D52}
15:26:48.0341 0x0b74 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:26:48.0357 0x0b74 ============================================================
15:26:48.0357 0x0b74 \Device\Harddisk0\DR0:
15:26:48.0372 0x0b74 MBR partitions:
15:26:48.0372 0x0b74 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1880000
15:26:48.0372 0x0b74 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1894000, BlocksNum 0x23B9A000
15:26:48.0372 0x0b74 ============================================================
15:26:48.0450 0x0b74 C: <-> \Device\Harddisk0\DR0\Partition2
15:26:48.0450 0x0b74 ============================================================
15:26:48.0450 0x0b74 Initialize success
15:26:48.0450 0x0b74 ============================================================
15:26:58.0080 0x0cc4 ============================================================
15:26:58.0080 0x0cc4 Scan started
15:26:58.0080 0x0cc4 Mode: Manual;
15:26:58.0080 0x0cc4 ============================================================
15:26:58.0080 0x0cc4 KSN ping started
15:27:01.0310 0x0cc4 KSN ping finished: true
15:27:03.0509 0x0cc4 ================ Scan system memory ========================
15:27:03.0509 0x0cc4 System memory - ok
15:27:03.0509 0x0cc4 ================ Scan services =============================
15:27:04.0991 0x0cc4 [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
15:27:04.0991 0x0cc4 1394ohci - ok
15:27:05.0007 0x0cc4 Suspicious service (NoAccess): 1cbccdb6771da47b
15:27:05.0116 0x0cc4 [ 039015F79A88101FB4D195583DDAA964, 5C885D57B0B8EC27C83650EE15703CDACEA9E25410679BF4BB3DC04A51BE5325 ] 1cbccdb6771da47b C:\Windows\System32\Drivers\1cbccdb6771da47b.sys
15:27:05.0116 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\System32\Drivers\1cbccdb6771da47b.sys. md5: 039015F79A88101FB4D195583DDAA964, sha256: 5C885D57B0B8EC27C83650EE15703CDACEA9E25410679BF4BB3DC04A51BE5325
15:27:05.0178 0x0cc4 1cbccdb6771da47b - detected Rootkit.Win32.Necurs.gen ( 0 )
15:27:07.0674 0x0cc4 1cbccdb6771da47b ( Rootkit.Win32.Necurs.gen ) - infected
15:27:07.0674 0x0cc4 Force sending object to P2P due to detect: C:\Windows\System32\Drivers\1cbccdb6771da47b.sys
15:27:10.0202 0x0cc4 Object send P2P result: true
15:27:13.0946 0x0cc4 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys
15:27:13.0961 0x0cc4 ACPI - ok
15:27:13.0992 0x0cc4 [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
15:27:14.0008 0x0cc4 AcpiPmi - ok
15:27:14.0304 0x0cc4 [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
15:27:14.0304 0x0cc4 AdobeARMservice - ok
15:27:14.0788 0x0cc4 [ 9D96B0D5855FD1B98023B3EEC9F06786, E4C79233158BE8AA4E9C6DD71585E5D2703A5156531EB3D692D7D81BC443E844 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
15:27:14.0819 0x0cc4 AdobeFlashPlayerUpdateSvc - ok
15:27:14.0866 0x0cc4 [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
15:27:14.0882 0x0cc4 adp94xx - ok
15:27:14.0928 0x0cc4 [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\drivers\adpahci.sys
15:27:14.0944 0x0cc4 adpahci - ok
15:27:15.0053 0x0cc4 [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
15:27:15.0053 0x0cc4 adpu320 - ok
15:27:15.0116 0x0cc4 [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
15:27:15.0116 0x0cc4 AeLookupSvc - ok
15:27:15.0240 0x0cc4 [ 79059559E89D06E8B80CE2944BE20228, 6E041D2FED2D0C3D8E16E56CB61D3245F9144EA92F5BDC9A4AA30598D1C8E6EE ] AFD C:\Windows\system32\drivers\afd.sys
15:27:15.0240 0x0cc4 AFD - ok
15:27:15.0272 0x0cc4 [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys
15:27:15.0272 0x0cc4 agp440 - ok
15:27:15.0287 0x0cc4 [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe
15:27:15.0287 0x0cc4 ALG - ok
15:27:15.0334 0x0cc4 [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys
15:27:15.0334 0x0cc4 aliide - ok
15:27:15.0412 0x0cc4 [ B9C8770F3061582DA3F9AB39071DEE37, 058C948F10B54EBDB95025A9EAC55F45CF3616BA834A1733B80A269E4ADF391B ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
15:27:15.0412 0x0cc4 AMD External Events Utility - ok
15:27:15.0584 0x0cc4 [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys
15:27:15.0584 0x0cc4 amdide - ok
15:27:15.0615 0x0cc4 [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
15:27:15.0615 0x0cc4 AmdK8 - ok
15:27:16.0083 0x0cc4 [ 31D7999C389C7F1EFFD4B861B64ECAA9, 50D9EE9F3D85D65ED50A87C70284FA130348464C314960EFED4232787016C7C8 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
15:27:16.0208 0x0cc4 amdkmdag - ok
15:27:16.0254 0x0cc4 [ 48E49CB63CB14E1A6EE80A14381213B0, 7A150F1D8B8C9FD5BFAB76C8999AD08F0771DE9D824D64F829B04E09CE29EB33 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
15:27:16.0270 0x0cc4 amdkmdap - ok
15:27:16.0286 0x0cc4 [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
15:27:16.0301 0x0cc4 AmdPPM - ok
15:27:16.0332 0x0cc4 [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys
15:27:16.0348 0x0cc4 amdsata - ok
15:27:16.0379 0x0cc4 [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
15:27:16.0395 0x0cc4 amdsbs - ok
15:27:16.0395 0x0cc4 [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys
15:27:16.0395 0x0cc4 amdxata - ok
15:27:16.0410 0x0cc4 [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID C:\Windows\system32\drivers\appid.sys
15:27:16.0426 0x0cc4 AppID - ok
15:27:16.0457 0x0cc4 [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc C:\Windows\System32\appidsvc.dll
15:27:16.0457 0x0cc4 AppIDSvc - ok
15:27:16.0488 0x0cc4 [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo C:\Windows\System32\appinfo.dll
15:27:16.0504 0x0cc4 Appinfo - ok
15:27:16.0535 0x0cc4 [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll
15:27:16.0535 0x0cc4 AppMgmt - ok
15:27:16.0535 0x0cc4 [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\drivers\arc.sys
15:27:16.0551 0x0cc4 arc - ok
15:27:16.0551 0x0cc4 [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\drivers\arcsas.sys
15:27:16.0551 0x0cc4 arcsas - ok
15:27:16.0676 0x0cc4 [ 9A262EDD17F8473B91B333D6B031A901, 05DFBD3A7D83FDE1D062EA719ACA9EC48CB7FD42D17DDD88B82E5D25469ADD23 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
15:27:16.0722 0x0cc4 aspnet_state - ok
15:27:16.0754 0x0cc4 [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
15:27:16.0754 0x0cc4 AsyncMac - ok
15:27:16.0800 0x0cc4 [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys
15:27:16.0800 0x0cc4 atapi - ok
15:27:16.0894 0x0cc4 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:27:16.0910 0x0cc4 AudioEndpointBuilder - ok
15:27:16.0956 0x0cc4 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv C:\Windows\System32\Audiosrv.dll
15:27:16.0972 0x0cc4 AudioSrv - ok
15:27:17.0034 0x0cc4 AVKWCtl - ok
15:27:17.0112 0x0cc4 [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll
15:27:17.0112 0x0cc4 AxInstSV - ok
15:27:17.0190 0x0cc4 [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
15:27:17.0222 0x0cc4 b06bdrv - ok
15:27:17.0300 0x0cc4 [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
15:27:17.0300 0x0cc4 b57nd60a - ok
15:27:17.0378 0x0cc4 [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll
15:27:17.0378 0x0cc4 BDESVC - ok
15:27:17.0409 0x0cc4 [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys
15:27:17.0409 0x0cc4 Beep - ok
15:27:17.0487 0x0cc4 [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll
15:27:17.0502 0x0cc4 BFE - ok
15:27:17.0580 0x0cc4 [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll
15:27:17.0612 0x0cc4 BITS - ok
15:27:17.0658 0x0cc4 [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
15:27:17.0658 0x0cc4 blbdrive - ok
15:27:17.0752 0x0cc4 [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
15:27:17.0752 0x0cc4 bowser - ok
15:27:17.0783 0x0cc4 [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
15:27:17.0783 0x0cc4 BrFiltLo - ok
15:27:17.0783 0x0cc4 [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
15:27:17.0799 0x0cc4 BrFiltUp - ok
15:27:18.0407 0x0cc4 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll
15:27:20.0420 0x0cc4 Browser - ok
15:27:20.0466 0x0cc4 [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys
15:27:20.0482 0x0cc4 Brserid - ok
15:27:20.0498 0x0cc4 [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
15:27:20.0498 0x0cc4 BrSerWdm - ok
15:27:20.0498 0x0cc4 [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
15:27:20.0513 0x0cc4 BrUsbMdm - ok
15:27:20.0513 0x0cc4 [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
15:27:20.0513 0x0cc4 BrUsbSer - ok
15:27:20.0529 0x0cc4 [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
15:27:20.0529 0x0cc4 BTHMODEM - ok
15:27:20.0576 0x0cc4 [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll
15:27:20.0576 0x0cc4 bthserv - ok
15:27:20.0607 0x0cc4 [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
15:27:20.0622 0x0cc4 cdfs - ok
15:27:20.0654 0x0cc4 [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
15:27:20.0654 0x0cc4 cdrom - ok
15:27:20.0685 0x0cc4 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll
15:27:20.0700 0x0cc4 CertPropSvc - ok
15:27:20.0732 0x0cc4 [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\drivers\circlass.sys
15:27:20.0732 0x0cc4 circlass - ok
15:27:20.0841 0x0cc4 [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS C:\Windows\system32\CLFS.sys
15:27:20.0872 0x0cc4 CLFS - ok
15:27:21.0106 0x0cc4 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:27:21.0106 0x0cc4 clr_optimization_v2.0.50727_32 - ok
15:27:21.0246 0x0cc4 [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
15:27:21.0246 0x0cc4 clr_optimization_v2.0.50727_64 - ok
15:27:21.0558 0x0cc4 [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:27:22.0385 0x0cc4 clr_optimization_v4.0.30319_32 - ok
15:27:22.0385 0x0cc4 [ 4AEDAB50F83580D0B4D6CF78191F92AA, D113C47013B018B45161911B96E93AF96A2F3B34FA47061BF6E7A71FBA03194A ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
15:27:22.0572 0x0cc4 clr_optimization_v4.0.30319_64 - ok
15:27:22.0604 0x0cc4 [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
15:27:22.0619 0x0cc4 CmBatt - ok
15:27:22.0650 0x0cc4 [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys
15:27:22.0650 0x0cc4 cmdide - ok
15:27:22.0728 0x0cc4 [ EBF28856F69CF094A902F884CF989706, AD6C9F0BC20AA49EEE5478DA0F856F0EA2B414B63208C5FFB03C9D7F5B59765F ] CNG C:\Windows\system32\Drivers\cng.sys
15:27:22.0728 0x0cc4 CNG - ok
15:27:22.0760 0x0cc4 [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
15:27:22.0775 0x0cc4 Compbatt - ok
15:27:22.0791 0x0cc4 [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
15:27:22.0791 0x0cc4 CompositeBus - ok
15:27:22.0806 0x0cc4 COMSysApp - ok
15:27:22.0838 0x0cc4 [ 3CA734CE373E5675FBC15CA2C45228E5, A6C6E9FABDE5EA18D266DB71C0CC6B51D682116D1898CCB4E9BA730F15C44B32 ] cpudrv64 C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys
15:27:22.0853 0x0cc4 cpudrv64 - ok
15:27:22.0853 0x0cc4 [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
15:27:22.0869 0x0cc4 crcdisk - ok
15:27:22.0916 0x0cc4 [ 6B400F211BEE880A37A1ED0368776BF4, 2F27C6FA96A1C8CBDA467846DA57E63949A7EA37DB094B13397DDD30114295BD ] CryptSvc C:\Windows\system32\cryptsvc.dll
15:27:22.0916 0x0cc4 CryptSvc - ok
15:27:22.0962 0x0cc4 [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys
15:27:22.0962 0x0cc4 CSC - ok
15:27:23.0134 0x0cc4 [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll
15:27:23.0150 0x0cc4 CscService - ok
15:27:23.0274 0x0cc4 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll
15:27:23.0274 0x0cc4 DcomLaunch - ok
15:27:23.0321 0x0cc4 [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll
15:27:23.0321 0x0cc4 defragsvc - ok
15:27:23.0337 0x0cc4 [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys
15:27:23.0337 0x0cc4 DfsC - ok
15:27:23.0415 0x0cc4 [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll
15:27:23.0415 0x0cc4 Dhcp - ok
15:27:23.0493 0x0cc4 [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys
15:27:23.0493 0x0cc4 discache - ok
15:27:23.0540 0x0cc4 [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\drivers\disk.sys
15:27:23.0540 0x0cc4 Disk - ok
15:27:23.0602 0x0cc4 [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys
15:27:23.0602 0x0cc4 dmvsc - ok
15:27:23.0664 0x0cc4 [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll
15:27:23.0664 0x0cc4 Dnscache - ok
15:27:23.0742 0x0cc4 [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll
15:27:23.0758 0x0cc4 dot3svc - ok
15:27:23.0805 0x0cc4 [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll
15:27:23.0820 0x0cc4 DPS - ok
15:27:23.0852 0x0cc4 [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
15:27:23.0867 0x0cc4 drmkaud - ok
15:27:23.0961 0x0cc4 [ 88612F1CE3BF42256913BF6E61C70D52, 7CF190F83FA8F15C33008EB381D3E345CEF37CBC046227DED26B36799EF4D9A7 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
15:27:23.0976 0x0cc4 DXGKrnl - ok
15:27:24.0054 0x0cc4 [ BA01A130D2B850CA87483CE6AC1A2BBA, DFF760DB1A6F60A856D64F01C67B8FC075ABED9DD80FFA50AA681296FF56FCE0 ] e1cexpress C:\Windows\system32\DRIVERS\e1c62x64.sys
15:27:24.0054 0x0cc4 e1cexpress - ok
15:27:24.0070 0x0cc4 [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll
15:27:24.0070 0x0cc4 EapHost - ok
15:27:24.0507 0x0cc4 [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\drivers\evbda.sys
15:27:24.0600 0x0cc4 ebdrv - ok
15:27:24.0663 0x0cc4 [ 4D71227301DD8D09097B9E4CC6527E5A, 193D47ADCB722B581CC0F29B794AB3E455B6E9BEA367CE9A5216A09E055B7F1E ] EFS C:\Windows\System32\lsass.exe
15:27:24.0663 0x0cc4 EFS - ok
15:27:24.0788 0x0cc4 [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
15:27:24.0819 0x0cc4 ehRecvr - ok
15:27:24.0834 0x0cc4 [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe
15:27:24.0834 0x0cc4 ehSched - ok
15:27:24.0897 0x0cc4 [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\drivers\elxstor.sys
15:27:24.0912 0x0cc4 elxstor - ok
15:27:24.0928 0x0cc4 [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys
15:27:24.0928 0x0cc4 ErrDev - ok
15:27:24.0959 0x0cc4 [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll
15:27:24.0975 0x0cc4 EventSystem - ok
15:27:25.0006 0x0cc4 [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys
15:27:25.0006 0x0cc4 exfat - ok
15:27:25.0022 0x0cc4 [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys
15:27:25.0037 0x0cc4 fastfat - ok
15:27:25.0084 0x0cc4 [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe
15:27:25.0100 0x0cc4 Fax - ok
15:27:25.0100 0x0cc4 [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\drivers\fdc.sys
15:27:25.0100 0x0cc4 fdc - ok
15:27:25.0115 0x0cc4 [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll
15:27:25.0115 0x0cc4 fdPHost - ok
15:27:25.0131 0x0cc4 [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll
15:27:25.0131 0x0cc4 FDResPub - ok
15:27:25.0162 0x0cc4 [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
15:27:25.0162 0x0cc4 FileInfo - ok
15:27:25.0178 0x0cc4 [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
15:27:25.0178 0x0cc4 Filetrace - ok
15:27:25.0178 0x0cc4 [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
15:27:25.0178 0x0cc4 flpydisk - ok
15:27:25.0193 0x0cc4 [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
15:27:25.0209 0x0cc4 FltMgr - ok
15:27:25.0334 0x0cc4 [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache C:\Windows\system32\FntCache.dll
15:27:25.0349 0x0cc4 FontCache - ok
15:27:25.0458 0x0cc4 [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
15:27:25.0458 0x0cc4 FontCache3.0.0.0 - ok
15:27:25.0490 0x0cc4 [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
15:27:25.0505 0x0cc4 FsDepends - ok
15:27:25.0536 0x0cc4 [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
15:27:25.0536 0x0cc4 Fs_Rec - ok
15:27:25.0583 0x0cc4 [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
15:27:25.0583 0x0cc4 fvevol - ok
15:27:25.0599 0x0cc4 [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
15:27:25.0599 0x0cc4 gagp30kx - ok
15:27:25.0599 0x0cc4 GDBehave - ok
15:27:25.0614 0x0cc4 GDMnIcpt - ok
15:27:25.0661 0x0cc4 [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll
15:27:25.0677 0x0cc4 gpsvc - ok
15:27:25.0692 0x0cc4 [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
15:27:25.0692 0x0cc4 hcw85cir - ok
15:27:25.0724 0x0cc4 [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
15:27:25.0724 0x0cc4 HDAudBus - ok
15:27:25.0724 0x0cc4 [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
15:27:25.0724 0x0cc4 HidBatt - ok
15:27:25.0739 0x0cc4 [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\drivers\hidbth.sys
15:27:25.0739 0x0cc4 HidBth - ok
15:27:25.0770 0x0cc4 [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\drivers\hidir.sys
15:27:25.0770 0x0cc4 HidIr - ok
15:27:25.0786 0x0cc4 [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll
15:27:25.0802 0x0cc4 hidserv - ok
15:27:25.0833 0x0cc4 [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\drivers\hidusb.sys
15:27:25.0833 0x0cc4 HidUsb - ok
15:27:25.0848 0x0cc4 [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll
15:27:25.0848 0x0cc4 hkmsvc - ok
15:27:25.0864 0x0cc4 [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
15:27:25.0880 0x0cc4 HomeGroupListener - ok
15:27:25.0895 0x0cc4 [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
15:27:25.0895 0x0cc4 HomeGroupProvider - ok
15:27:25.0926 0x0cc4 [ 4CA17EE22B340DE8B85F6CEB3445E6DB, EE9D30CCDC80C16DA25F8054CF152586A3CCBACF2EEBE279C3BF7175D15375BB ] HookCentre C:\Windows\system32\drivers\HookCentre.sys
15:27:25.0926 0x0cc4 HookCentre - ok
15:27:25.0958 0x0cc4 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
15:27:25.0958 0x0cc4 HpSAMD - ok
15:27:25.0989 0x0cc4 [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP C:\Windows\system32\drivers\HTTP.sys
15:27:26.0004 0x0cc4 HTTP - ok
15:27:26.0020 0x0cc4 [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
15:27:26.0020 0x0cc4 hwpolicy - ok
15:27:26.0051 0x0cc4 [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
15:27:26.0051 0x0cc4 i8042prt - ok
15:27:26.0082 0x0cc4 [ D7921D5A870B11CC1ADAB198A519D50A, 5DF99EB5D5504E9D9EB21658E8B4A58DEE2AD143A1875DB7F9B7BF4877FCB57F ] iaStor C:\Windows\system32\drivers\iaStor.sys
15:27:26.0098 0x0cc4 iaStor - ok
15:27:26.0160 0x0cc4 [ 8FFF9083252C16FE3960173722605E9E, 6546FDA34B9AF94C5E86E5269BBC2F02F1E78D6D4BE5B5EC01F4B284CC934994 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
15:27:26.0160 0x0cc4 IAStorDataMgrSvc - ok
15:27:26.0176 0x0cc4 [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
15:27:26.0192 0x0cc4 iaStorV - ok
15:27:26.0363 0x0cc4 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
15:27:26.0410 0x0cc4 idsvc - ok
15:27:26.0426 0x0cc4 IEEtwCollectorService - ok
15:27:26.0441 0x0cc4 [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\drivers\iirsp.sys
15:27:26.0457 0x0cc4 iirsp - ok
15:27:26.0504 0x0cc4 [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll
15:27:26.0519 0x0cc4 IKEEXT - ok
15:27:26.0597 0x0cc4 [ 19F9D8F7C996D5AE22E913491C912009, 1E733E34F2D39203216F3542F1A5818F3EA21CE51F434FE3B255CB6BF0B048FC ] IntcAzAudAddService C:\Windows\system32\drivers\RTDVHD64.sys
15:27:26.0597 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\RTDVHD64.sys. md5: 19F9D8F7C996D5AE22E913491C912009, sha256: 1E733E34F2D39203216F3542F1A5818F3EA21CE51F434FE3B255CB6BF0B048FC
15:27:26.0597 0x0cc4 IntcAzAudAddService - detected LockedFile.Multi.Generic ( 1 )
15:27:29.0000 0x0cc4 Detect skipped due to KSN trusted
15:27:29.0000 0x0cc4 IntcAzAudAddService - ok
15:27:29.0031 0x0cc4 [ D7B978F4504D3DA95A21002863D0E7EE, 17B4B4F9334EF874FF7DF30C63D4541142DD0324F842050AC755B170F46C3159 ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
15:27:29.0031 0x0cc4 Intel(R) PROSet Monitoring Service - ok
15:27:29.0062 0x0cc4 [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys
15:27:29.0062 0x0cc4 intelide - ok
15:27:29.0109 0x0cc4 [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
15:27:29.0109 0x0cc4 intelppm - ok
15:27:29.0156 0x0cc4 [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll
15:27:29.0171 0x0cc4 IPBusEnum - ok
15:27:29.0187 0x0cc4 [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:27:29.0187 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ipfltdrv.sys. md5: C9F0E1BD74365A8771590E9008D22AB6, sha256: 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51
15:27:29.0187 0x0cc4 IpFilterDriver - detected LockedFile.Multi.Generic ( 1 )
15:27:31.0589 0x0cc4 Detect skipped due to KSN trusted
15:27:31.0589 0x0cc4 IpFilterDriver - ok
15:27:32.0057 0x0cc4 [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
15:27:32.0073 0x0cc4 iphlpsvc - ok
15:27:32.0120 0x0cc4 [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
15:27:32.0120 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\IPMIDrv.sys. md5: 0FC1AEA580957AA8817B8F305D18CA3A, sha256: 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9
15:27:32.0120 0x0cc4 IPMIDRV - detected LockedFile.Multi.Generic ( 1 )
15:27:34.0584 0x0cc4 Detect skipped due to KSN trusted
15:27:34.0584 0x0cc4 IPMIDRV - ok
15:27:34.0694 0x0cc4 [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys
15:27:34.0694 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ipnat.sys. md5: AF9B39A7E7B6CAA203B3862582E9F2D0, sha256: 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E
15:27:34.0694 0x0cc4 IPNAT - detected LockedFile.Multi.Generic ( 1 )
15:27:37.0096 0x0cc4 Detect skipped due to KSN trusted
15:27:37.0096 0x0cc4 IPNAT - ok
15:27:37.0704 0x0cc4 [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys
15:27:37.0704 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\irenum.sys. md5: 3ABF5E7213EB28966D55D58B515D5CE9, sha256: A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE
15:27:37.0704 0x0cc4 IRENUM - detected LockedFile.Multi.Generic ( 1 )
15:27:40.0169 0x0cc4 Detect skipped due to KSN trusted
15:27:40.0169 0x0cc4 IRENUM - ok
15:27:40.0278 0x0cc4 [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys
15:27:40.0278 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\isapnp.sys. md5: 2F7B28DC3E1183E5EB418DF55C204F38, sha256: D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548
15:27:40.0278 0x0cc4 isapnp - detected LockedFile.Multi.Generic ( 1 )
15:27:42.0743 0x0cc4 Detect skipped due to KSN trusted
15:27:42.0743 0x0cc4 isapnp - ok
15:27:42.0837 0x0cc4 [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3 ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
15:27:42.0837 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msiscsi.sys. md5: D931D7309DEB2317035B07C9F9E6B0BD, sha256: 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3
15:27:42.0837 0x0cc4 iScsiPrt - detected LockedFile.Multi.Generic ( 1 )
15:27:45.0317 0x0cc4 Detect skipped due to KSN trusted
15:27:45.0317 0x0cc4 iScsiPrt - ok
15:27:45.0411 0x0cc4 [ 6C85719A21B3F62C2C76280F4BD36C7B, 471E333467937720EF9369419EEDE5C2246C976123B437E0AC66F394CF1C056A ] jhi_service C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
15:27:45.0426 0x0cc4 jhi_service - ok
15:27:45.0473 0x0cc4 [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
15:27:45.0473 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\kbdclass.sys. md5: BC02336F1CBA7DCC7D1213BB588A68A5, sha256: 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93
15:27:45.0473 0x0cc4 kbdclass - detected LockedFile.Multi.Generic ( 1 )
15:27:47.0875 0x0cc4 Detect skipped due to KSN trusted
15:27:47.0875 0x0cc4 kbdclass - ok
15:27:47.0875 0x0cc4 [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
15:27:47.0875 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\kbdhid.sys. md5: 0705EFF5B42A9DB58548EEC3B26BB484, sha256: 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99
15:27:47.0875 0x0cc4 kbdhid - detected LockedFile.Multi.Generic ( 1 )
15:27:50.0979 0x0cc4 Detect skipped due to KSN trusted
15:27:50.0979 0x0cc4 kbdhid - ok
15:27:51.0010 0x0cc4 [ 4D71227301DD8D09097B9E4CC6527E5A, 193D47ADCB722B581CC0F29B794AB3E455B6E9BEA367CE9A5216A09E055B7F1E ] KeyIso C:\Windows\system32\lsass.exe
15:27:51.0010 0x0cc4 KeyIso - ok
15:27:51.0072 0x0cc4 [ 8F489706472F7E9A06BAAA198703FA64, F020406690FB38EABD82D63B91D33039CC93ED52A5497AE12BAF475F22D0B08A ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
15:27:51.0072 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\ksecdd.sys. md5: 8F489706472F7E9A06BAAA198703FA64, sha256: F020406690FB38EABD82D63B91D33039CC93ED52A5497AE12BAF475F22D0B08A
15:27:51.0072 0x0cc4 KSecDD - detected LockedFile.Multi.Generic ( 1 )
15:27:53.0535 0x0cc4 Detect skipped due to KSN trusted
15:27:53.0535 0x0cc4 KSecDD - ok
15:27:53.0551 0x0cc4 [ 868A2CAAB12EFC7A021682BCA0EEC54C, 12C4925B5B3D6EA7B6410C01F33158C6EAB50CBD6AF445F8B04ED9899720C2DD ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
15:27:53.0551 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\ksecpkg.sys. md5: 868A2CAAB12EFC7A021682BCA0EEC54C, sha256: 12C4925B5B3D6EA7B6410C01F33158C6EAB50CBD6AF445F8B04ED9899720C2DD
15:27:53.0551 0x0cc4 KSecPkg - detected LockedFile.Multi.Generic ( 1 )
15:27:55.0952 0x0cc4 Detect skipped due to KSN trusted
15:27:55.0952 0x0cc4 KSecPkg - ok
15:27:55.0983 0x0cc4 [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
15:27:55.0983 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ksthunk.sys. md5: 6869281E78CB31A43E969F06B57347C4, sha256: 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B
15:27:55.0983 0x0cc4 ksthunk - detected LockedFile.Multi.Generic ( 1 )
15:27:58.0446 0x0cc4 Detect skipped due to KSN trusted
15:27:58.0446 0x0cc4 ksthunk - ok
15:27:58.0680 0x0cc4 [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll
15:27:58.0696 0x0cc4 KtmRm - ok
15:27:58.0742 0x0cc4 [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll
15:27:58.0742 0x0cc4 LanmanServer - ok
15:27:58.0758 0x0cc4 [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:27:58.0758 0x0cc4 LanmanWorkstation - ok
15:27:58.0789 0x0cc4 [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
15:27:58.0789 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\lltdio.sys. md5: 1538831CF8AD2979A04C423779465827, sha256: E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C
15:27:58.0789 0x0cc4 lltdio - detected LockedFile.Multi.Generic ( 1 )
15:28:01.0268 0x0cc4 Detect skipped due to KSN trusted
15:28:01.0268 0x0cc4 lltdio - ok
15:28:01.0299 0x0cc4 [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll
15:28:01.0315 0x0cc4 lltdsvc - ok
15:28:01.0346 0x0cc4 [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll
15:28:01.0346 0x0cc4 lmhosts - ok
15:28:01.0408 0x0cc4 [ 713B289020B0C72DBAE93EB1EC79B28B, D15713E72D22D183C4AF7B75E74AF3F82F946C7B2AA841DB2B49D88FEF7C5853 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
15:28:01.0424 0x0cc4 LMS - ok
15:28:01.0455 0x0cc4 [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
15:28:01.0455 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_fc.sys. md5: 1A93E54EB0ECE102495A51266DCDB6A6, sha256: DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B
15:28:01.0455 0x0cc4 LSI_FC - detected LockedFile.Multi.Generic ( 1 )
15:28:03.0918 0x0cc4 Detect skipped due to KSN trusted
15:28:03.0918 0x0cc4 LSI_FC - ok
15:28:03.0934 0x0cc4 [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
15:28:03.0934 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_sas.sys. md5: 1047184A9FDC8BDBFF857175875EE810, sha256: F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B
15:28:03.0934 0x0cc4 LSI_SAS - detected LockedFile.Multi.Generic ( 1 )
15:28:06.0276 0x0cc4 Detect skipped due to KSN trusted
15:28:06.0276 0x0cc4 LSI_SAS - ok
15:28:06.0303 0x0cc4 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
15:28:06.0303 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_sas2.sys. md5: 30F5C0DE1EE8B5BC9306C1F0E4A75F93, sha256: 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06
15:28:06.0303 0x0cc4 LSI_SAS2 - detected LockedFile.Multi.Generic ( 1 )
15:28:08.0726 0x0cc4 Detect skipped due to KSN trusted
15:28:08.0726 0x0cc4 LSI_SAS2 - ok
15:28:08.0752 0x0cc4 [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
15:28:08.0753 0x0cc4 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_scsi.sys. md5: 0504EACAFF0D3C8AED161C4B0D369D4A, sha256: 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D
15:28:08.0753 0x0cc4 LSI_SCSI - detected LockedFile.Multi.Generic ( 1 )
15:28:11.0180 0x0cc4 Detect skipped due to KSN trusted
15:28:11.0180 0x0cc4 LSI_SCSI - ok
15:28:11.0191 0x0cc4 Scan was interrupted by user!
15:28:11.0227 0x0cc4 Win FW state via NFP2: enabled
15:28:13.0574 0x0cc4 ============================================================
15:28:13.0574 0x0cc4 Scan finished
15:28:13.0574 0x0cc4 ============================================================
15:28:13.0581 0x0c9c Detected object count: 1
15:28:13.0581 0x0c9c Actual detected object count: 1
15:28:18.0597 0x0c9c C:\Windows\System32\Drivers\1cbccdb6771da47b.sys - copied to quarantine
15:28:18.0597 0x0c9c HKLM\SYSTEM\ControlSet001\services\1cbccdb6771da47b - will be deleted on reboot
15:28:18.0610 0x0c9c HKLM\SYSTEM\ControlSet002\services\1cbccdb6771da47b - will be deleted on reboot
15:28:18.0769 0x0c9c C:\Windows\System32\Drivers\1cbccdb6771da47b.sys - will be deleted on reboot
15:28:18.0770 0x0c9c 1cbccdb6771da47b ( Rootkit.Win32.Necurs.gen ) - User select action: Delete
15:28:19.0639 0x0c9c KLMD registered as C:\Windows\system32\drivers\72731850.sys
15:28:27.0604 0x0b40 Deinitialize success |