14:56:21.0071 0x0a8c TDSS rootkit removing tool 3.0.0.25 Feb 27 2014 15:23:02 14:56:21.0492 0x0a8c ============================================================ 14:56:21.0492 0x0a8c Current date / time: 2014/03/17 14:56:21.0492 14:56:21.0492 0x0a8c SystemInfo: 14:56:21.0492 0x0a8c 14:56:21.0492 0x0a8c OS Version: 6.0.6002 ServicePack: 2.0 14:56:21.0492 0x0a8c Product type: Workstation 14:56:21.0492 0x0a8c ComputerName: HOMEPC 14:56:21.0492 0x0a8c UserName: Renia 14:56:21.0492 0x0a8c Windows directory: C:\Windows 14:56:21.0492 0x0a8c System windows directory: C:\Windows 14:56:21.0492 0x0a8c Processor architecture: Intel x86 14:56:21.0492 0x0a8c Number of processors: 2 14:56:21.0492 0x0a8c Page size: 0x1000 14:56:21.0492 0x0a8c Boot type: Normal boot 14:56:21.0492 0x0a8c ============================================================ 14:56:21.0492 0x0a8c BG loaded 14:56:21.0633 0x0a8c System UUID: {5979468E-55CB-96CB-B3F6-3A961B37795D} 14:56:23.0097 0x0a8c Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 14:56:23.0132 0x0a8c ============================================================ 14:56:23.0132 0x0a8c \Device\Harddisk0\DR0: 14:56:23.0171 0x0a8c MBR partitions: 14:56:23.0171 0x0a8c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x406093, BlocksNum 0x3C00800 14:56:23.0171 0x0a8c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x4007000, BlocksNum 0xEA12000 14:56:23.0171 0x0a8c ============================================================ 14:56:23.0249 0x0a8c C: <-> \Device\Harddisk0\DR0\Partition1 14:56:23.0436 0x0a8c D: <-> \Device\Harddisk0\DR0\Partition2 14:56:23.0436 0x0a8c ============================================================ 14:56:23.0436 0x0a8c Initialize success 14:56:23.0436 0x0a8c ============================================================ 14:56:31.0517 0x0dfc ============================================================ 14:56:31.0517 0x0dfc Scan started 14:56:31.0517 0x0dfc Mode: Manual; 14:56:31.0517 0x0dfc ============================================================ 14:56:31.0517 0x0dfc KSN ping started 14:56:34.0325 0x0dfc KSN ping finished: true 14:56:35.0807 0x0dfc ================ Scan system memory ======================== 14:56:35.0807 0x0dfc System memory - ok 14:56:35.0807 0x0dfc ================ Scan services ============================= 14:56:35.0869 0x0dfc Suspicious service (NoAccess): 2e7c80c788dd5602 14:56:36.0056 0x0dfc [ B87B4691217E8F84A5512630D28AA712, 95BAFAD7BBCF65342A5A70F1B7F7E263C8FD1227CB6D2C34363BC21E3B90AE13 ] 2e7c80c788dd5602 C:\Windows\System32\Drivers\2e7c80c788dd5602.sys 14:56:36.0056 0x0dfc Suspicious file ( NoAccess ): C:\Windows\System32\Drivers\2e7c80c788dd5602.sys. md5: B87B4691217E8F84A5512630D28AA712, sha256: 95BAFAD7BBCF65342A5A70F1B7F7E263C8FD1227CB6D2C34363BC21E3B90AE13 14:56:36.0212 0x0dfc 2e7c80c788dd5602 - detected Rootkit.Win32.Necurs.gen ( 0 ) 14:56:39.0660 0x0dfc 2e7c80c788dd5602 ( Rootkit.Win32.Necurs.gen ) - infected 14:56:39.0660 0x0dfc Force sending object to P2P due to detect: C:\Windows\System32\Drivers\2e7c80c788dd5602.sys 14:56:48.0646 0x0dfc Object send P2P result: true 14:56:51.0563 0x0dfc [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI C:\Windows\system32\drivers\acpi.sys 14:56:51.0594 0x0dfc ACPI - ok 14:56:51.0656 0x0dfc [ B944AD9F92D31285DBA3D190DEB43883, D2B32FFC345F093AC6CF6142B111C4C72484A4C5C93050730632011F116ACA35 ] adiusbaw C:\Windows\system32\DRIVERS\adiusbaw.sys 14:56:51.0672 0x0dfc adiusbaw - ok 14:56:51.0766 0x0dfc [ 9D96B0D5855FD1B98023B3EEC9F06786, E4C79233158BE8AA4E9C6DD71585E5D2703A5156531EB3D692D7D81BC443E844 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 14:56:51.0812 0x0dfc AdobeFlashPlayerUpdateSvc - ok 14:56:51.0922 0x0dfc [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 14:56:51.0984 0x0dfc adp94xx - ok 14:56:52.0046 0x0dfc [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci C:\Windows\system32\drivers\adpahci.sys 14:56:52.0062 0x0dfc adpahci - ok 14:56:52.0093 0x0dfc [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 14:56:52.0109 0x0dfc adpu160m - ok 14:56:52.0140 0x0dfc [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 14:56:52.0156 0x0dfc adpu320 - ok 14:56:52.0187 0x0dfc [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 14:56:52.0202 0x0dfc AeLookupSvc - ok 14:56:52.0265 0x0dfc [ 3911B972B55FEA0478476B2E777B29FA, 62545B90C7DD3F73777E62CD8264E611A4D71B6956CABFD2D820D25F41F471FD ] AFD C:\Windows\system32\drivers\afd.sys 14:56:52.0280 0x0dfc AFD - ok 14:56:52.0327 0x0dfc [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx C:\Windows\system32\drivers\djsvs.sys 14:56:52.0327 0x0dfc aic78xx - ok 14:56:52.0358 0x0dfc [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG C:\Windows\System32\alg.exe 14:56:52.0374 0x0dfc ALG - ok 14:56:52.0405 0x0dfc [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide C:\Windows\system32\drivers\aliide.sys 14:56:52.0405 0x0dfc aliide - ok 14:56:52.0436 0x0dfc [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp C:\Windows\system32\drivers\amdagp.sys 14:56:52.0436 0x0dfc amdagp - ok 14:56:52.0452 0x0dfc [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide C:\Windows\system32\drivers\amdide.sys 14:56:52.0468 0x0dfc amdide - ok 14:56:52.0499 0x0dfc [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7 C:\Windows\system32\drivers\amdk7.sys 14:56:52.0499 0x0dfc AmdK7 - ok 14:56:52.0514 0x0dfc [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 14:56:52.0530 0x0dfc AmdK8 - ok 14:56:52.0577 0x0dfc [ C6D704C7F0434DC791AAC37CAC4B6E14, 35CF7D1895F97637E0C678A39F3049B871BCA9526D379C7793ED33B87D2EAC4C ] Appinfo C:\Windows\System32\appinfo.dll 14:56:52.0577 0x0dfc Appinfo - ok 14:56:52.0592 0x0dfc [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc C:\Windows\system32\drivers\arc.sys 14:56:52.0592 0x0dfc arc - ok 14:56:52.0608 0x0dfc [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas C:\Windows\system32\drivers\arcsas.sys 14:56:52.0608 0x0dfc arcsas - ok 14:56:52.0670 0x0dfc [ 61953E5E1FFAEAF246A610BEE2554879, AF489668BC4DCA5CFC81BF056C6AFC7CE4E5B917413FE513B13830B210524785 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys 14:56:52.0670 0x0dfc aswMonFlt - ok 14:56:52.0702 0x0dfc [ 98C18C78B0C3E7EFBDDA7BD0C35F5903, 92128EA70472EBA8804C2972DAA8557F460C2E082084E29B40CE93A05447592F ] aswRdr C:\Windows\system32\drivers\aswRdr.sys 14:56:52.0702 0x0dfc aswRdr - ok 14:56:52.0748 0x0dfc [ F385467DF95D0A73775CB3B076B8B969, D427A5F4FB4D1DAB04AFC29E7EC510844F907ABBA053538995E65747BAD37422 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys 14:56:52.0764 0x0dfc aswRvrt - ok 14:56:52.0811 0x0dfc [ 8CD8710457FCC1CDE88CBFA3AA119B92, B750481B2D44E2D01DEF500276A7253731EDD2BCB117B083EE10FAA7A8FFF729 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys 14:56:52.0826 0x0dfc aswSnx - ok 14:56:52.0873 0x0dfc [ C1F95C9481F46B96E23A276639C55AC9, 75F7BCF74E46E3A8EC9AF0DB5D7FCA280DCAF97BD932767DCBDE66E26BF0E7CE ] aswSP C:\Windows\system32\drivers\aswSP.sys 14:56:52.0889 0x0dfc aswSP - ok 14:56:52.0920 0x0dfc [ E6390554DCB2A730702188547267093C, 1F97F23A2C1767ABD52041DFA0EF9065567CDB02B12F674CF4EE4E8FBA69773B ] aswTdi C:\Windows\system32\drivers\aswTdi.sys 14:56:52.0920 0x0dfc aswTdi - ok 14:56:52.0967 0x0dfc [ 1B0662514A68C3A42E60D240C5ABEF28, 71301759C135895C72CAED297A669BA58B3F73E0B7E46DB981F6559D5D5E2B89 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys 14:56:52.0982 0x0dfc aswVmm - ok 14:56:52.0998 0x0dfc [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 14:56:52.0998 0x0dfc AsyncMac - ok 14:56:53.0029 0x0dfc [ 1F05B78AB91C9075565A9D8A4B880BC4, 737BE9F9376DAB0CCDFED93EA6D67F0C432367EA63CD772A453485BE769AF3BD ] atapi C:\Windows\system32\drivers\atapi.sys 14:56:53.0029 0x0dfc atapi - ok 14:56:53.0123 0x0dfc [ 44362605F5FFF00C9B7696B47680A8C5, E972D0C046760B04CEDF2DBAC03128866691DC299FB96CA87A124278613EFBEA ] athr C:\Windows\system32\DRIVERS\athr.sys 14:56:53.0154 0x0dfc athr - ok 14:56:53.0201 0x0dfc [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 14:56:53.0216 0x0dfc AudioEndpointBuilder - ok 14:56:53.0248 0x0dfc [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] Audiosrv C:\Windows\System32\Audiosrv.dll 14:56:53.0263 0x0dfc Audiosrv - ok 14:56:53.0388 0x0dfc [ CC42F104172B4A62793083D380867317, 0B09823419B328E29EB9FFBD033B3295590E414F31E7B37F11F62BD4B7EBAF06 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 14:56:53.0404 0x0dfc avast! Antivirus - ok 14:56:53.0450 0x0dfc [ 502F1C30BD50B32D00CE4DCAECC3D3C7, F1F74D821C0D436C438313B522704F5DCA38A008725B74C2F6659ACAABDB210C ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 14:56:53.0466 0x0dfc b57nd60x - ok 14:56:53.0497 0x0dfc [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep C:\Windows\system32\drivers\Beep.sys 14:56:53.0513 0x0dfc Beep - ok 14:56:53.0575 0x0dfc [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE C:\Windows\System32\bfe.dll 14:56:53.0591 0x0dfc BFE - ok 14:56:53.0794 0x0dfc [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS C:\Windows\System32\qmgr.dll 14:56:53.0840 0x0dfc BITS - ok 14:56:53.0872 0x0dfc [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 14:56:53.0872 0x0dfc blbdrive - ok 14:56:53.0903 0x0dfc [ 35F376253F687BDE63976CCB3F2108CA, C5EF6301D7BC067050038DB75D961681D1CBE418285AD60167C1334B0B54DFE9 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 14:56:53.0903 0x0dfc bowser - ok 14:56:53.0965 0x0dfc [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 14:56:54.0028 0x0dfc BrFiltLo - ok 14:56:54.0043 0x0dfc [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 14:56:54.0043 0x0dfc BrFiltUp - ok 14:56:54.0074 0x0dfc [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser C:\Windows\System32\browser.dll 14:56:54.0074 0x0dfc Browser - ok 14:56:54.0106 0x0dfc [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid C:\Windows\system32\drivers\brserid.sys 14:56:54.0106 0x0dfc Brserid - ok 14:56:54.0137 0x0dfc [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 14:56:54.0137 0x0dfc BrSerWdm - ok 14:56:54.0152 0x0dfc [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 14:56:54.0152 0x0dfc BrUsbMdm - ok 14:56:54.0168 0x0dfc [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 14:56:54.0168 0x0dfc BrUsbSer - ok 14:56:54.0230 0x0dfc [ 6D39C954799B63BA866910234CF7D726, 1D807C3410C01C76E5810D626F23C1CCED3C9C5A65F39267B770C494C8D64114 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys 14:56:54.0230 0x0dfc BthEnum - ok 14:56:54.0262 0x0dfc [ 9A966A8E86D1771911AE34A20D11BFF3, FBD5F621A47A3530B325816E71F0C4BCE5CCE731C57DEBD42ACFC8BCAA258656 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 14:56:54.0262 0x0dfc BTHMODEM - ok 14:56:54.0277 0x0dfc [ 5904EFA25F829BF84EA6FB045134A1D8, 66E4160CC404744576BA6E9DD606B533F42B3D4A3E2FDD457DAA016CC72A81CC ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 14:56:54.0293 0x0dfc BthPan - ok 14:56:54.0355 0x0dfc [ 611FF3F2F095C8D4A6D4CFD9DCC09793, 2F27A1287ABCDB9C316EB720D1855100666240959CF969D5B2679C9ABCBD6050 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys 14:56:54.0386 0x0dfc BTHPORT - ok 14:56:54.0464 0x0dfc [ A4C8377FA4A994E07075107DBE2E3DCE, C3CDAA7B83D130100044341C23897CC6C257FA075A8D08B8551F4A28AE8CE6C4 ] BthServ C:\Windows\System32\bthserv.dll 14:56:54.0464 0x0dfc BthServ - ok 14:56:54.0527 0x0dfc [ D330803EAB2A15CAEC7F011F1D4CB30E, 240FFF317C90AD8966DA9666F2748F98CEC3CB99C486F399D1C68FE0E393EE68 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys 14:56:54.0527 0x0dfc BTHUSB - ok 14:56:54.0574 0x0dfc [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 14:56:54.0574 0x0dfc cdfs - ok 14:56:54.0620 0x0dfc [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 14:56:54.0636 0x0dfc cdrom - ok 14:56:54.0698 0x0dfc [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc C:\Windows\System32\certprop.dll 14:56:54.0698 0x0dfc CertPropSvc - ok 14:56:54.0745 0x0dfc [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass C:\Windows\system32\drivers\circlass.sys 14:56:54.0745 0x0dfc circlass - ok 14:56:54.0808 0x0dfc [ D7659D3B5B92C31E84E53C1431F35132, 6BFE644AD9890A8CEEDCC4B97ADD564AD57202FBC5D21599469E0C4B31BB27C6 ] CLFS C:\Windows\system32\CLFS.sys 14:56:54.0823 0x0dfc CLFS - ok 14:56:54.0886 0x0dfc [ 8EE772032E2FE80A924F3B8DD5082194, B743DF91563A22CC15D9B44105804B5866A29D3DFC156DBE88DFAFEF903B94C0 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 14:56:54.0901 0x0dfc clr_optimization_v2.0.50727_32 - ok 14:56:54.0932 0x0dfc [ 99AFC3795B58CC478FBBBCDC658FCB56, 0D1B27C42A058C5D56A0157B5ECA9A054254F6B9C8015D0321021A7EFCE10CE2 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 14:56:54.0948 0x0dfc CmBatt - ok 14:56:54.0964 0x0dfc [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide C:\Windows\system32\drivers\cmdide.sys 14:56:54.0964 0x0dfc cmdide - ok 14:56:55.0010 0x0dfc [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 14:56:55.0010 0x0dfc Compbatt - ok 14:56:55.0010 0x0dfc COMSysApp - ok 14:56:55.0042 0x0dfc [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 14:56:55.0042 0x0dfc crcdisk - ok 14:56:55.0057 0x0dfc [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe C:\Windows\system32\drivers\crusoe.sys 14:56:55.0057 0x0dfc Crusoe - ok 14:56:55.0120 0x0dfc [ FB27772BEAF8E1D28CCD825C09DA939B, D074A314FB3E6B2248F2DB0A734B98A110F618804449E055B4178BF414826982 ] CryptSvc C:\Windows\system32\cryptsvc.dll 14:56:55.0120 0x0dfc CryptSvc - ok 14:56:55.0198 0x0dfc [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch C:\Windows\system32\rpcss.dll 14:56:55.0229 0x0dfc DcomLaunch - ok 14:56:55.0260 0x0dfc [ 622C41A07CA7E6DD91770F50D532CB6C, 2A9040949CB45F9970FDE930278F30D2F08E957290CB3D4DC4F2CA94F3D444D2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 14:56:55.0260 0x0dfc DfsC - ok 14:56:55.0400 0x0dfc [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR C:\Windows\system32\DFSR.exe 14:56:55.0510 0x0dfc DFSR - ok 14:56:55.0650 0x0dfc [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp C:\Windows\System32\dhcpcsvc.dll 14:56:55.0650 0x0dfc Dhcp - ok 14:56:55.0697 0x0dfc [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk C:\Windows\system32\drivers\disk.sys 14:56:55.0697 0x0dfc disk - ok 14:56:55.0759 0x0dfc [ 57D762F6F5974AF0DA2BE88A3349BAAA, D9E7DC8F9FB7837F88BBB95B52147AA80E688FB9762EEA99B8046D9C6AD48F3C ] Dnscache C:\Windows\System32\dnsrslvr.dll 14:56:55.0775 0x0dfc Dnscache - ok 14:56:55.0837 0x0dfc [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc C:\Windows\System32\dot3svc.dll 14:56:55.0837 0x0dfc dot3svc - ok 14:56:55.0978 0x0dfc [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS C:\Windows\system32\dps.dll 14:56:55.0993 0x0dfc DPS - ok 14:56:56.0134 0x0dfc [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 14:56:56.0134 0x0dfc drmkaud - ok 14:56:56.0258 0x0dfc [ FB85F7F69E9B109820409243F578CC4D, FBE0426E51B83DD973EC08ABA4E69E99F54B1C44995E0FD42B68A07549D52D7F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 14:56:56.0290 0x0dfc DXGKrnl - ok 14:56:56.0446 0x0dfc [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys 14:56:56.0446 0x0dfc E1G60 - ok 14:56:56.0680 0x0dfc [ A777D095402B31B0AAFE7F19C89FB3A1, 624EF08DA5FDD50CB62A1C601CFAA7C149B8CC7D64A1C333F134C9DF7A54D08E ] eamon C:\Windows\system32\DRIVERS\eamon.sys 14:56:56.0742 0x0dfc eamon - ok 14:56:56.0789 0x0dfc [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost C:\Windows\System32\eapsvc.dll 14:56:56.0804 0x0dfc EapHost - ok 14:56:56.0836 0x0dfc [ E6DFFB60BDBD91749EAB4D45BC8926A9, 4FDB453F6EC614606785AEBC46CA647D1AF112CF26EDBCFBCA99273F692D6BAA ] easdrv C:\Windows\system32\DRIVERS\easdrv.sys 14:56:56.0836 0x0dfc easdrv - ok 14:56:56.0882 0x0dfc [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371, F3E9CF5D8E9124CB06F08454C5F0E510DE19A92780151FB2F8A58A0905D59B8F ] Ecache C:\Windows\system32\drivers\ecache.sys 14:56:56.0898 0x0dfc Ecache - ok 14:56:56.0992 0x0dfc [ 08EE8892FD19A6A951F40254E97F6EF3, 76F19B49DDC7B1CD7839BF0DF6A417F2DD756C924931F39291BC1D25A3C6077D ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 14:56:56.0992 0x0dfc eeCtrl - ok 14:56:57.0070 0x0dfc [ 44E5CFB428C55BDE550F0648B426FBC0, BB063D7A5FC7D1AC05E00E3570FE81F54D069A8DE4B17EC8F83ECF93ADECF4B9 ] EhttpSrv C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe 14:56:57.0070 0x0dfc EhttpSrv - ok 14:56:57.0132 0x0dfc [ 49485FA5C3A8A5CE866B281E75E99F24, 41A03E1BD1012AB6DFE175B5F3421D798921C9B730BA39EE003C639B6BFA8B04 ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe 14:56:57.0163 0x0dfc ekrn - ok 14:56:57.0226 0x0dfc [ 9A3A8614859FB77767B63A82A017CCC6, 729E89BC6938A621802676C2CD3D5762796C5F3CB59207DBCF1171ACAE33358C ] ELOADER C:\Windows\system32\Drivers\adildr.sys 14:56:57.0226 0x0dfc ELOADER - ok 14:56:57.0288 0x0dfc [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor C:\Windows\system32\drivers\elxstor.sys 14:56:57.0319 0x0dfc elxstor - ok 14:56:57.0397 0x0dfc [ 4E6B23DFC917EA39306B529B773950F4, C4BA77632B4BD46C4C1797F7F57399DB506D3EB6E5A0A36C269A793DAA3445C2 ] EMDMgmt C:\Windows\system32\emdmgmt.dll 14:56:57.0428 0x0dfc EMDMgmt - ok 14:56:57.0460 0x0dfc [ BB2E195088AF3F6091EF9F8E42F0581F, C1EA5BC19886A09AE8DF53A19D6FB49E2A55AAD38CCA55683AA4CC1FFA69DA9F ] epfwtdir C:\Windows\system32\DRIVERS\epfwtdir.sys 14:56:57.0460 0x0dfc epfwtdir - ok 14:56:57.0491 0x0dfc [ 3DB974F3935483555D7148663F726C61, C288CFC04213B0340ABEC752C0A7B308B29122B5F51E68387BA1D9E9D7166FDD ] ErrDev C:\Windows\system32\drivers\errdev.sys 14:56:57.0491 0x0dfc ErrDev - ok 14:56:57.0569 0x0dfc [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem C:\Windows\system32\es.dll 14:56:57.0584 0x0dfc EventSystem - ok 14:56:57.0647 0x0dfc [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat C:\Windows\system32\drivers\exfat.sys 14:56:57.0662 0x0dfc exfat - ok 14:56:57.0725 0x0dfc [ 1E9B9A70D332103C52995E957DC09EF8, 7E709D545D4025A2E9F3489CF2A231040904CB53E3E4EEAC15A22468FAB2A5B3 ] fastfat C:\Windows\system32\drivers\fastfat.sys 14:56:57.0725 0x0dfc fastfat - ok 14:56:57.0772 0x0dfc [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc C:\Windows\system32\DRIVERS\fdc.sys 14:56:57.0772 0x0dfc fdc - ok 14:56:57.0803 0x0dfc [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost C:\Windows\system32\fdPHost.dll 14:56:57.0803 0x0dfc fdPHost - ok 14:56:57.0850 0x0dfc [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub C:\Windows\system32\fdrespub.dll 14:56:57.0865 0x0dfc FDResPub - ok 14:56:57.0896 0x0dfc [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 14:56:57.0912 0x0dfc FileInfo - ok 14:56:57.0943 0x0dfc [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 14:56:57.0959 0x0dfc Filetrace - ok 14:56:57.0990 0x0dfc [ 85B7CF99D532820495D68D747FDA9EBD, 682D35D219D1AFBE51CF0AB03F2D3E15C940F5AF291C1A611A19F4D279143F3C ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 14:56:58.0006 0x0dfc flpydisk - ok 14:56:58.0037 0x0dfc [ 01334F9EA68E6877C4EF05D3EA8ABB05, 82F8AA6AD2B5077898773D4A5814819EAF0E872FFD95894E06FEDAB6EE92CF99 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 14:56:58.0052 0x0dfc FltMgr - ok 14:56:58.0099 0x0dfc [ C7FBDD1ED42F82BFA35167A5C9803EA3, 372FF71070D5ECE17342466A690737A0622E93C98DBED8172C49B0854F0012B7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 14:56:58.0115 0x0dfc FontCache3.0.0.0 - ok 14:56:58.0162 0x0dfc [ B972A66758577E0BFD1DE0F91AAA27B5, E934034F3F740A83D4E7ABCD2C581845AC2945B0BCCAACF65CC3F99A1DBDE455 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 14:56:58.0177 0x0dfc Fs_Rec - ok 14:56:58.0224 0x0dfc [ 34582A6E6573D54A07ECE5FE24A126B5, 5F45DC38F8015AD90616EAD3B57820CCD284938A96B2C4E1FF5FC7BDEE8A848D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 14:56:58.0224 0x0dfc gagp30kx - ok 14:56:58.0318 0x0dfc [ CD5D0AEEE35DFD4E986A5AA1500A6E66, DCED5126837292593F1C1B35DF18E3B631D6C0C6D0742B77C7B7742C55A7825F ] gpsvc C:\Windows\System32\gpsvc.dll 14:56:58.0349 0x0dfc gpsvc - ok 14:56:58.0411 0x0dfc [ 3F90E001369A07243763BD5A523D8722, 25907F85787D879E75C3FE74C93567382AFB2D528BEEC61D71E3A6BE2D71DFBE ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 14:56:58.0411 0x0dfc HdAudAddService - ok 14:56:58.0489 0x0dfc [ 062452B7FFD68C8C042A6261FE8DFF4A, DD9873502456D3C058C6177AC223B28C71370E624FA0814C17EA3D93201F2B56 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 14:56:58.0552 0x0dfc HDAudBus - ok 14:56:58.0614 0x0dfc [ FCB3F4BE408F72C1BD81BCABA87FC22F, F63D75904888E40889A600EF32AA77130C088014949F5A574B49F547E9F9D4AD ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 14:56:58.0614 0x0dfc HidBth - ok 14:56:58.0676 0x0dfc [ FF3160C3A2445128C5A6D9B076DA519E, DC1A70C80CD55F33B3AD5A21E86AF7C3086D8CC2DC6148C058E74A871E0BAD4A ] HidIr C:\Windows\system32\drivers\hidir.sys 14:56:58.0676 0x0dfc HidIr - ok 14:56:58.0754 0x0dfc [ 84067081F3318162797385E11A8F0582, 11E32E3800CFCA37354388243F88D0239D622891BAC5483518A2BE5D1CA19015 ] hidserv C:\Windows\system32\hidserv.dll 14:56:58.0754 0x0dfc hidserv - ok 14:56:58.0786 0x0dfc [ CCA4B519B17E23A00B826C55716809CC, 91AD0758A6185B0FBBE383BDB1B457FFB850477AFF8DE040DE9527A97D28EF62 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 14:56:58.0786 0x0dfc HidUsb - ok 14:56:58.0848 0x0dfc [ D8AD255B37DA92434C26E4876DB7D418, C901EADDD93FC90C8F29F4B6DE808F8E4F486C877FC0AA27DA4ACDE17E28899D ] hkmsvc C:\Windows\system32\kmsvc.dll 14:56:58.0848 0x0dfc hkmsvc - ok 14:56:58.0864 0x0dfc [ 16EE7B23A009E00D835CDB79574A91A6, 964AFE7D2F7E48C7DE7FDAB48F57ADC4AD44A0B2A9A03071E0E8D334007E5572 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 14:56:58.0879 0x0dfc HpCISSs - ok 14:56:58.0988 0x0dfc [ 0EEECA26C8D4BDE2A4664DB058A81937, 6F88567A116B1420BE1C9C8888F34D05F51378092C805EF4E489635CF92D416B ] HTTP C:\Windows\system32\drivers\HTTP.sys 14:56:59.0004 0x0dfc HTTP - ok 14:56:59.0051 0x0dfc [ C6B032D69650985468160FC9937CF5B4, 4D5A944C70037F35A9DBA4F49F174455FA80ED7EAEDAA143F0A2C0E05AE585D8 ] i2omp C:\Windows\system32\drivers\i2omp.sys 14:56:59.0051 0x0dfc i2omp - ok 14:56:59.0098 0x0dfc [ 22D56C8184586B7A1F6FA60BE5F5A2BD, D96A2962848C1F59B143BFEC22EC48BD1C5A75D0EBCFD7FB965E66B85FF7D8CA ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 14:56:59.0098 0x0dfc i8042prt - ok 14:56:59.0285 0x0dfc [ 496DB78E6A0C4C44023D9A92B4A7AC31, 2B44213C39F05090D2057E3A21C1718DFC4478E976D44255B6FA5C3B8CF20FFF ] ialm C:\Windows\system32\DRIVERS\igdkmd32.sys 14:56:59.0285 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\igdkmd32.sys. md5: 496DB78E6A0C4C44023D9A92B4A7AC31, sha256: 2B44213C39F05090D2057E3A21C1718DFC4478E976D44255B6FA5C3B8CF20FFF 14:56:59.0285 0x0dfc ialm - detected LockedFile.Multi.Generic ( 1 ) 14:57:01.0796 0x0dfc Detect skipped due to KSN trusted 14:57:01.0796 0x0dfc ialm - ok 14:57:01.0859 0x0dfc [ 54155EA1B0DF185878E0FC9EC3AC3A14, 344A0793499261D2E4FF2FCCC70501329485F8E299EBC68953D07BA86F0D4729 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 14:57:01.0906 0x0dfc iaStorV - ok 14:57:02.0062 0x0dfc [ 98477B08E61945F974ED9FDC4CB6BDAB, C7E8F661F6FBF6AB493E950D2E70363496E155B1838CE7B490B981BD840B04FC ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 14:57:02.0155 0x0dfc idsvc - ok 14:57:02.0186 0x0dfc [ 2D077BF86E843F901D8DB709C95B49A5, 78FF558A881F307858F5C7C74A748B8B2562AF3CAC7EA8639945609001D790CE ] iirsp C:\Windows\system32\drivers\iirsp.sys 14:57:02.0202 0x0dfc iirsp - ok 14:57:02.0296 0x0dfc [ 9908D8A397B76CD8D31D0D383C5773C9, FFA6996BE9F11A81CB63C849C2400EB44A07706D1EEB7A3502D4110DAC3684A2 ] IKEEXT C:\Windows\System32\ikeext.dll 14:57:02.0311 0x0dfc IKEEXT - ok 14:57:02.0342 0x0dfc IntcAzAudAddService - ok 14:57:02.0374 0x0dfc [ 83AA759F3189E6370C30DE5DC5590718, 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A ] intelide C:\Windows\system32\drivers\intelide.sys 14:57:02.0374 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\intelide.sys. md5: 83AA759F3189E6370C30DE5DC5590718, sha256: 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A 14:57:02.0374 0x0dfc intelide - detected LockedFile.Multi.Generic ( 1 ) 14:57:04.0979 0x0dfc Detect skipped due to KSN trusted 14:57:04.0979 0x0dfc intelide - ok 14:57:05.0026 0x0dfc [ 224191001E78C89DFA78924C3EA595FF, E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 14:57:05.0026 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\intelppm.sys. md5: 224191001E78C89DFA78924C3EA595FF, sha256: E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 14:57:05.0026 0x0dfc intelppm - detected LockedFile.Multi.Generic ( 1 ) 14:57:07.0537 0x0dfc Detect skipped due to KSN trusted 14:57:07.0537 0x0dfc intelppm - ok 14:57:07.0584 0x0dfc [ 9AC218C6E6105477484C6FDBE7D409A4, FF30D09CD2A0F5BBEC309E953370F194B6F26BF4227E627B594AAA48B0F5D3C2 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 14:57:07.0600 0x0dfc IPBusEnum - ok 14:57:07.0646 0x0dfc [ 62C265C38769B864CB25B4BCF62DF6C3, CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 14:57:07.0646 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ipfltdrv.sys. md5: 62C265C38769B864CB25B4BCF62DF6C3, sha256: CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 14:57:07.0646 0x0dfc IpFilterDriver - detected LockedFile.Multi.Generic ( 1 ) 14:57:10.0236 0x0dfc Detect skipped due to KSN trusted 14:57:10.0236 0x0dfc IpFilterDriver - ok 14:57:10.0330 0x0dfc [ 1998BD97F950680BB55F55A7244679C2, A4E8BB4C6B2AF4800BD5E0BA8725FD0927F8FB6751AEBF6DD16B59C414CCB9D8 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 14:57:10.0345 0x0dfc iphlpsvc - ok 14:57:10.0361 0x0dfc IpInIp - ok 14:57:10.0408 0x0dfc [ B25AAF203552B7B3491139D582B39AD1, EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 14:57:10.0408 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ipmidrv.sys. md5: B25AAF203552B7B3491139D582B39AD1, sha256: EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 14:57:10.0408 0x0dfc IPMIDRV - detected LockedFile.Multi.Generic ( 1 ) 14:57:12.0919 0x0dfc Detect skipped due to KSN trusted 14:57:12.0919 0x0dfc IPMIDRV - ok 14:57:12.0966 0x0dfc [ 8793643A67B42CEC66490B2A0CF92D68, 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 14:57:12.0966 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ipnat.sys. md5: 8793643A67B42CEC66490B2A0CF92D68, sha256: 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 14:57:12.0966 0x0dfc IPNAT - detected LockedFile.Multi.Generic ( 1 ) 14:57:15.0478 0x0dfc Detect skipped due to KSN trusted 14:57:15.0478 0x0dfc IPNAT - ok 14:57:15.0509 0x0dfc [ 109C0DFB82C3632FBD11949B73AEEAC9, 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 ] IRENUM C:\Windows\system32\drivers\irenum.sys 14:57:15.0509 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\irenum.sys. md5: 109C0DFB82C3632FBD11949B73AEEAC9, sha256: 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 14:57:15.0509 0x0dfc IRENUM - detected LockedFile.Multi.Generic ( 1 ) 14:57:18.0192 0x0dfc Detect skipped due to KSN trusted 14:57:18.0192 0x0dfc IRENUM - ok 14:57:18.0254 0x0dfc [ 6C70698A3E5C4376C6AB5C7C17FB0614, 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 ] isapnp C:\Windows\system32\drivers\isapnp.sys 14:57:18.0254 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\isapnp.sys. md5: 6C70698A3E5C4376C6AB5C7C17FB0614, sha256: 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 14:57:18.0254 0x0dfc isapnp - detected LockedFile.Multi.Generic ( 1 ) 14:57:20.0791 0x0dfc Detect skipped due to KSN trusted 14:57:20.0791 0x0dfc isapnp - ok 14:57:20.0843 0x0dfc [ 232FA340531D940AAC623B121A595034, 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 14:57:20.0844 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\msiscsi.sys. md5: 232FA340531D940AAC623B121A595034, sha256: 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 14:57:20.0845 0x0dfc iScsiPrt - detected LockedFile.Multi.Generic ( 1 ) 14:57:23.0320 0x0dfc Detect skipped due to KSN trusted 14:57:23.0320 0x0dfc iScsiPrt - ok 14:57:23.0364 0x0dfc [ BCED60D16156E428F8DF8CF27B0DF150, 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 14:57:23.0365 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\iteatapi.sys. md5: BCED60D16156E428F8DF8CF27B0DF150, sha256: 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 14:57:23.0366 0x0dfc iteatapi - detected LockedFile.Multi.Generic ( 1 ) 14:57:25.0844 0x0dfc Detect skipped due to KSN trusted 14:57:25.0844 0x0dfc iteatapi - ok 14:57:25.0893 0x0dfc [ 06FA654504A498C30ADCA8BEC4E87E7E, 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 ] iteraid C:\Windows\system32\drivers\iteraid.sys 14:57:25.0894 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\iteraid.sys. md5: 06FA654504A498C30ADCA8BEC4E87E7E, sha256: 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 14:57:25.0895 0x0dfc iteraid - detected LockedFile.Multi.Generic ( 1 ) 14:57:28.0371 0x0dfc Detect skipped due to KSN trusted 14:57:28.0372 0x0dfc iteraid - ok 14:57:28.0408 0x0dfc [ 37605E0A8CF00CBBA538E753E4344C6E, B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 14:57:28.0409 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\kbdclass.sys. md5: 37605E0A8CF00CBBA538E753E4344C6E, sha256: B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 14:57:28.0409 0x0dfc kbdclass - detected LockedFile.Multi.Generic ( 1 ) 14:57:30.0963 0x0dfc Detect skipped due to KSN trusted 14:57:30.0963 0x0dfc kbdclass - ok 14:57:31.0045 0x0dfc [ EDE59EC70E25C24581ADD1FBEC7325F7, 41B37778E9A12675FC0DF74606AAF18C652EB88513B3C4889C5C512E14587CEE ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 14:57:31.0046 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\kbdhid.sys. md5: EDE59EC70E25C24581ADD1FBEC7325F7, sha256: 41B37778E9A12675FC0DF74606AAF18C652EB88513B3C4889C5C512E14587CEE 14:57:31.0047 0x0dfc kbdhid - detected LockedFile.Multi.Generic ( 1 ) 14:57:33.0506 0x0dfc Detect skipped due to KSN trusted 14:57:33.0506 0x0dfc kbdhid - ok 14:57:34.0760 0x0dfc [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] KeyIso C:\Windows\system32\lsass.exe 14:57:34.0786 0x0dfc KeyIso - ok 14:57:34.0842 0x0dfc [ 566C5FD480FDBCE3BA5CF9FBCFFAEA9A, 573681387B27FB2C8DC6612474B9BB8631F6CD3CED29AEBF91992606875724D2 ] KMWDFILTER C:\Windows\system32\DRIVERS\KMWDFILTER.sys 14:57:34.0843 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\KMWDFILTER.sys. md5: 566C5FD480FDBCE3BA5CF9FBCFFAEA9A, sha256: 573681387B27FB2C8DC6612474B9BB8631F6CD3CED29AEBF91992606875724D2 14:57:34.0844 0x0dfc KMWDFILTER - detected LockedFile.Multi.Generic ( 1 ) 14:57:37.0414 0x0dfc Detect skipped due to KSN trusted 14:57:37.0414 0x0dfc KMWDFILTER - ok 14:57:37.0482 0x0dfc [ 2B2F1638466E8CB091400C9019CC730E, 7E0861EBA191779743F930D63C8F4FA1ABC56C04BBCBD76B6B8A5A8E9EB310A7 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 14:57:37.0483 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\ksecdd.sys. md5: 2B2F1638466E8CB091400C9019CC730E, sha256: 7E0861EBA191779743F930D63C8F4FA1ABC56C04BBCBD76B6B8A5A8E9EB310A7 14:57:37.0485 0x0dfc KSecDD - detected LockedFile.Multi.Generic ( 1 ) 14:57:39.0962 0x0dfc Detect skipped due to KSN trusted 14:57:39.0962 0x0dfc KSecDD - ok 14:57:40.0033 0x0dfc [ 8078F8F8F7A79E2E6B494523A828C585, BB399993166853F0C01B7508649ECD7E7473238267BA8333D0441128FE656347 ] KtmRm C:\Windows\system32\msdtckrm.dll 14:57:40.0066 0x0dfc KtmRm - ok 14:57:40.0111 0x0dfc [ 1BF5EEBFD518DD7298434D8C862F825D, F41C79410345C40B346EB5EDEA397ECD29ECB9B921AC3E19F9453E52A7B9288A ] LanmanServer C:\Windows\system32\srvsvc.dll 14:57:40.0123 0x0dfc LanmanServer - ok 14:57:40.0167 0x0dfc [ 1DB69705B695B987082C8BAEC0C6B34F, D395B272F6B69D4A9FC3CDEFD812EF0DBFECF3C1B1C787C7CC1E1A1B091B8DB3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 14:57:40.0181 0x0dfc LanmanWorkstation - ok 14:57:40.0246 0x0dfc [ D1C5883087A0C3F1344D9D55A44901F6, 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 14:57:40.0247 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\lltdio.sys. md5: D1C5883087A0C3F1344D9D55A44901F6, sha256: 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 14:57:40.0248 0x0dfc lltdio - detected LockedFile.Multi.Generic ( 1 ) 14:57:42.0862 0x0dfc Detect skipped due to KSN trusted 14:57:42.0862 0x0dfc lltdio - ok 14:57:42.0940 0x0dfc [ 2D5A428872F1442631D0959A34ABFF63, E532C6ECFFB936EFF744CA57BDC6394C89E797B6B0822D04F1F3F35D9BDDD4F0 ] lltdsvc C:\Windows\System32\lltdsvc.dll 14:57:42.0956 0x0dfc lltdsvc - ok 14:57:43.0003 0x0dfc [ 35D40113E4A5B961B6CE5C5857702518, 453097AEF46ED48107395D9A1696AAC259FD6CEA8A655D38C5E246FDDAB81664 ] lmhosts C:\Windows\System32\lmhsvc.dll 14:57:43.0018 0x0dfc lmhosts - ok 14:57:43.0065 0x0dfc [ C7E15E82879BF3235B559563D4185365, 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 14:57:43.0065 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_fc.sys. md5: C7E15E82879BF3235B559563D4185365, sha256: 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 14:57:43.0065 0x0dfc LSI_FC - detected LockedFile.Multi.Generic ( 1 ) 14:57:45.0577 0x0dfc Detect skipped due to KSN trusted 14:57:45.0577 0x0dfc LSI_FC - ok 14:57:45.0623 0x0dfc [ EE01EBAE8C9BF0FA072E0FF68718920A, 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 14:57:45.0623 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_sas.sys. md5: EE01EBAE8C9BF0FA072E0FF68718920A, sha256: 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 14:57:45.0623 0x0dfc LSI_SAS - detected LockedFile.Multi.Generic ( 1 ) 14:57:48.0650 0x0dfc Detect skipped due to KSN trusted 14:57:48.0650 0x0dfc LSI_SAS - ok 14:57:48.0697 0x0dfc [ 912A04696E9CA30146A62AFA1463DD5C, 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 14:57:48.0697 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_scsi.sys. md5: 912A04696E9CA30146A62AFA1463DD5C, sha256: 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 14:57:48.0697 0x0dfc LSI_SCSI - detected LockedFile.Multi.Generic ( 1 ) 14:57:51.0286 0x0dfc Detect skipped due to KSN trusted 14:57:51.0286 0x0dfc LSI_SCSI - ok 14:57:51.0317 0x0dfc [ 8F5C7426567798E62A3B3614965D62CC, 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E ] luafv C:\Windows\system32\drivers\luafv.sys 14:57:51.0317 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\luafv.sys. md5: 8F5C7426567798E62A3B3614965D62CC, sha256: 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E 14:57:51.0317 0x0dfc luafv - detected LockedFile.Multi.Generic ( 1 ) 14:57:53.0845 0x0dfc Detect skipped due to KSN trusted 14:57:53.0845 0x0dfc luafv - ok 14:57:53.0891 0x0dfc [ 4470E3C1E0C3378E4CAB137893C12C3A, CA8E66356F0E671D5454E561E7EAD74DE25DCF53BE452369F96ECACFA8709489 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 14:57:53.0891 0x0dfc MBAMProtector - ok 14:57:53.0969 0x0dfc [ 65085456FD9A74D7F1A999520C299ECB, EA564BC913EF1B8A4CAA9242FC70F525B68CF1F3CA462F63B0B7215B93FE8530 ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 14:57:53.0985 0x0dfc MBAMScheduler - ok 14:57:54.0063 0x0dfc [ E0D7732F2D2E24B2DB3F67B6750295B8, AA5CA86AF1ACEC900F60339016B3DC55472DB40ADB99186005A7ABE67B7D66FC ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 14:57:54.0079 0x0dfc MBAMService - ok 14:57:54.0141 0x0dfc [ 0001CE609D66632FA17B84705F658879, D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD ] megasas C:\Windows\system32\drivers\megasas.sys 14:57:54.0141 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\megasas.sys. md5: 0001CE609D66632FA17B84705F658879, sha256: D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD 14:57:54.0141 0x0dfc megasas - detected LockedFile.Multi.Generic ( 1 ) 14:57:56.0824 0x0dfc Detect skipped due to KSN trusted 14:57:56.0824 0x0dfc megasas - ok 14:57:56.0902 0x0dfc [ C252F32CD9A49DBFC25ECF26EBD51A99, 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 ] MegaSR C:\Windows\system32\drivers\megasr.sys 14:57:56.0902 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\megasr.sys. md5: C252F32CD9A49DBFC25ECF26EBD51A99, sha256: 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 14:57:56.0902 0x0dfc MegaSR - detected LockedFile.Multi.Generic ( 1 ) 14:57:59.0429 0x0dfc Detect skipped due to KSN trusted 14:57:59.0429 0x0dfc MegaSR - ok 14:57:59.0476 0x0dfc [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] MMCSS C:\Windows\system32\mmcss.dll 14:57:59.0476 0x0dfc MMCSS - ok 14:57:59.0507 0x0dfc [ E13B5EA0F51BA5B1512EC671393D09BA, 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A ] Modem C:\Windows\system32\drivers\modem.sys 14:57:59.0507 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\modem.sys. md5: E13B5EA0F51BA5B1512EC671393D09BA, sha256: 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A 14:57:59.0507 0x0dfc Modem - detected LockedFile.Multi.Generic ( 1 ) 14:58:02.0035 0x0dfc Detect skipped due to KSN trusted 14:58:02.0035 0x0dfc Modem - ok 14:58:02.0097 0x0dfc [ 0A9BB33B56E294F686ABB7C1E4E2D8A8, 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 14:58:02.0097 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\monitor.sys. md5: 0A9BB33B56E294F686ABB7C1E4E2D8A8, sha256: 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 14:58:02.0097 0x0dfc monitor - detected LockedFile.Multi.Generic ( 1 ) 14:58:04.0687 0x0dfc Detect skipped due to KSN trusted 14:58:04.0687 0x0dfc monitor - ok 14:58:04.0749 0x0dfc [ 37E5A8C7F9A3B38F113B71EC7CE34F92, 71FF57CCBD345F63CCBBABB2D89B506AF4EE096D9B7B865EDAB148CE408DECB6 ] motmodem C:\Windows\system32\DRIVERS\motmodem.sys 14:58:04.0749 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\motmodem.sys. md5: 37E5A8C7F9A3B38F113B71EC7CE34F92, sha256: 71FF57CCBD345F63CCBBABB2D89B506AF4EE096D9B7B865EDAB148CE408DECB6 14:58:04.0749 0x0dfc motmodem - detected LockedFile.Multi.Generic ( 1 ) 14:58:07.0354 0x0dfc Detect skipped due to KSN trusted 14:58:07.0354 0x0dfc motmodem - ok 14:58:07.0401 0x0dfc [ 5BF6A1326A335C5298477754A506D263, CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 14:58:07.0401 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mouclass.sys. md5: 5BF6A1326A335C5298477754A506D263, sha256: CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D 14:58:07.0401 0x0dfc mouclass - detected LockedFile.Multi.Generic ( 1 ) 14:58:09.0913 0x0dfc Detect skipped due to KSN trusted 14:58:09.0913 0x0dfc mouclass - ok 14:58:09.0944 0x0dfc [ 93B8D4869E12CFBE663915502900876F, 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 14:58:09.0944 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mouhid.sys. md5: 93B8D4869E12CFBE663915502900876F, sha256: 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 14:58:09.0944 0x0dfc mouhid - detected LockedFile.Multi.Generic ( 1 ) 14:58:12.0736 0x0dfc Detect skipped due to KSN trusted 14:58:12.0736 0x0dfc mouhid - ok 14:58:12.0767 0x0dfc [ BDAFC88AA6B92F7842416EA6A48E1600, 2CA8A7BB260016D6B7953980A94C45A3C5D41F7DC7E73EEFB1C18EA144749503 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 14:58:12.0767 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mountmgr.sys. md5: BDAFC88AA6B92F7842416EA6A48E1600, sha256: 2CA8A7BB260016D6B7953980A94C45A3C5D41F7DC7E73EEFB1C18EA144749503 14:58:12.0767 0x0dfc MountMgr - detected LockedFile.Multi.Generic ( 1 ) 14:58:15.0279 0x0dfc Detect skipped due to KSN trusted 14:58:15.0279 0x0dfc MountMgr - ok 14:58:15.0373 0x0dfc [ 338037EFA0E8E8699B2667D57B751574, 59E0D39806D0C4EB57913AA013242837FD39AD378726AEE42D250CBA87C1C3BF ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 14:58:15.0388 0x0dfc MozillaMaintenance - ok 14:58:15.0451 0x0dfc [ 511D011289755DD9F9A7579FB0B064E6, 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 ] mpio C:\Windows\system32\drivers\mpio.sys 14:58:15.0451 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mpio.sys. md5: 511D011289755DD9F9A7579FB0B064E6, sha256: 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 14:58:15.0451 0x0dfc mpio - detected LockedFile.Multi.Generic ( 1 ) 14:58:18.0040 0x0dfc Detect skipped due to KSN trusted 14:58:18.0040 0x0dfc mpio - ok 14:58:18.0071 0x0dfc [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E, 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 14:58:18.0071 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mpsdrv.sys. md5: 22241FEBA9B2DEFA669C8CB0A8DD7D2E, sha256: 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD 14:58:18.0071 0x0dfc mpsdrv - detected LockedFile.Multi.Generic ( 1 ) 14:58:20.0645 0x0dfc Detect skipped due to KSN trusted 14:58:20.0645 0x0dfc mpsdrv - ok 14:58:20.0801 0x0dfc [ 5DE62C6E9108F14F6794060A9BDECAEC, 655E6645CC4A1EDBE5F51F5F80C7B504DD956851E788A6E4E4E08CDCDCE160D9 ] MpsSvc C:\Windows\system32\mpssvc.dll 14:58:20.0817 0x0dfc MpsSvc - ok 14:58:20.0864 0x0dfc [ 4FBBB70D30FD20EC51F80061703B001E, 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 14:58:20.0864 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mraid35x.sys. md5: 4FBBB70D30FD20EC51F80061703B001E, sha256: 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A 14:58:20.0864 0x0dfc Mraid35x - detected LockedFile.Multi.Generic ( 1 ) 14:58:23.0438 0x0dfc Detect skipped due to KSN trusted 14:58:23.0438 0x0dfc Mraid35x - ok 14:58:23.0500 0x0dfc [ 82CEA0395524AACFEB58BA1448E8325C, 16E37990A291C848DE35F48EA7E09AE5B258AE589EB08A3FA2C60DC1278DE182 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 14:58:23.0500 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mrxdav.sys. md5: 82CEA0395524AACFEB58BA1448E8325C, sha256: 16E37990A291C848DE35F48EA7E09AE5B258AE589EB08A3FA2C60DC1278DE182 14:58:23.0500 0x0dfc MRxDAV - detected LockedFile.Multi.Generic ( 1 ) 14:58:26.0027 0x0dfc Detect skipped due to KSN trusted 14:58:26.0027 0x0dfc MRxDAV - ok 14:58:26.0090 0x0dfc [ 1E94971C4B446AB2290DEB71D01CF0C2, 4701AA1B419AEF735CB2DA34532B0F1844433272C36D79F4EB55807E39B923D1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 14:58:26.0090 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mrxsmb.sys. md5: 1E94971C4B446AB2290DEB71D01CF0C2, sha256: 4701AA1B419AEF735CB2DA34532B0F1844433272C36D79F4EB55807E39B923D1 14:58:26.0090 0x0dfc mrxsmb - detected LockedFile.Multi.Generic ( 1 ) 14:58:28.0898 0x0dfc Detect skipped due to KSN trusted 14:58:28.0898 0x0dfc mrxsmb - ok 14:58:28.0960 0x0dfc [ 4FCCB34D793B116423209C0F8B7A3B03, 7A483AEB691ADBE82779F12F0BB1CCCBFFD7E92902EC1ADC99AB7D129F887143 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 14:58:28.0960 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mrxsmb10.sys. md5: 4FCCB34D793B116423209C0F8B7A3B03, sha256: 7A483AEB691ADBE82779F12F0BB1CCCBFFD7E92902EC1ADC99AB7D129F887143 14:58:28.0960 0x0dfc mrxsmb10 - detected LockedFile.Multi.Generic ( 1 ) 14:58:31.0472 0x0dfc Detect skipped due to KSN trusted 14:58:31.0472 0x0dfc mrxsmb10 - ok 14:58:31.0519 0x0dfc [ C3CB1B40AD4A0124D617A1199B0B9D7C, B975A39DE6D324C6274B6E3B883F36082A958F028335CEB3A37F44481EB284B3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 14:58:31.0519 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mrxsmb20.sys. md5: C3CB1B40AD4A0124D617A1199B0B9D7C, sha256: B975A39DE6D324C6274B6E3B883F36082A958F028335CEB3A37F44481EB284B3 14:58:31.0519 0x0dfc mrxsmb20 - detected LockedFile.Multi.Generic ( 1 ) 14:58:34.0108 0x0dfc Detect skipped due to KSN trusted 14:58:34.0108 0x0dfc mrxsmb20 - ok 14:58:34.0139 0x0dfc [ F70590424EEFBF5C27A40C67AFDB8383, 1F2AC1DA12F7E6F09D8F6622EF1366ABD4B86EBE51DD1915E803D56A568A3412 ] msahci C:\Windows\system32\drivers\msahci.sys 14:58:34.0139 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msahci.sys. md5: F70590424EEFBF5C27A40C67AFDB8383, sha256: 1F2AC1DA12F7E6F09D8F6622EF1366ABD4B86EBE51DD1915E803D56A568A3412 14:58:34.0139 0x0dfc msahci - detected LockedFile.Multi.Generic ( 1 ) 14:58:36.0651 0x0dfc Detect skipped due to KSN trusted 14:58:36.0651 0x0dfc msahci - ok 14:58:36.0682 0x0dfc [ 4468B0F385A86ECDDAF8D3CA662EC0E7, EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 ] msdsm C:\Windows\system32\drivers\msdsm.sys 14:58:36.0682 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msdsm.sys. md5: 4468B0F385A86ECDDAF8D3CA662EC0E7, sha256: EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 14:58:36.0682 0x0dfc msdsm - detected LockedFile.Multi.Generic ( 1 ) 14:58:39.0209 0x0dfc Detect skipped due to KSN trusted 14:58:39.0209 0x0dfc msdsm - ok 14:58:39.0256 0x0dfc [ FD7520CC3A80C5FC8C48852BB24C6DED, C3F3D7A07FAB9AF38A2A00BF0DF6EEE18CA8FE26277BEC9D8ADB793F2CD5EC1F ] MSDTC C:\Windows\System32\msdtc.exe 14:58:39.0272 0x0dfc MSDTC - ok 14:58:39.0319 0x0dfc [ A9927F4A46B816C92F461ACB90CF8515, 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 ] Msfs C:\Windows\system32\drivers\Msfs.sys 14:58:39.0319 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Msfs.sys. md5: A9927F4A46B816C92F461ACB90CF8515, sha256: 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 14:58:39.0319 0x0dfc Msfs - detected LockedFile.Multi.Generic ( 1 ) 14:58:41.0939 0x0dfc Detect skipped due to KSN trusted 14:58:41.0939 0x0dfc Msfs - ok 14:58:42.0017 0x0dfc [ 0F400E306F385C56317357D6DEA56F62, C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 14:58:42.0017 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msisadrv.sys. md5: 0F400E306F385C56317357D6DEA56F62, sha256: C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC 14:58:42.0017 0x0dfc msisadrv - detected LockedFile.Multi.Generic ( 1 ) 14:58:44.0529 0x0dfc Detect skipped due to KSN trusted 14:58:44.0529 0x0dfc msisadrv - ok 14:58:44.0576 0x0dfc [ 85466C0757A23D9A9AECDC0755203CB2, 79141B8DF9D7470466872AF03A85C3D3976512BFDBDB8B92A22225DC8EFD70A6 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 14:58:44.0623 0x0dfc MSiSCSI - ok 14:58:44.0623 0x0dfc msiserver - ok 14:58:44.0716 0x0dfc [ D8C63D34D9C9E56C059E24EC7185CC07, D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 14:58:44.0716 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSKSSRV.sys. md5: D8C63D34D9C9E56C059E24EC7185CC07, sha256: D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE 14:58:44.0716 0x0dfc MSKSSRV - detected LockedFile.Multi.Generic ( 1 ) 14:58:47.0243 0x0dfc Detect skipped due to KSN trusted 14:58:47.0243 0x0dfc MSKSSRV - ok 14:58:47.0290 0x0dfc [ 1D373C90D62DDB641D50E55B9E78D65E, 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 14:58:47.0290 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSPCLOCK.sys. md5: 1D373C90D62DDB641D50E55B9E78D65E, sha256: 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B 14:58:47.0290 0x0dfc MSPCLOCK - detected LockedFile.Multi.Generic ( 1 ) 14:58:49.0895 0x0dfc Detect skipped due to KSN trusted 14:58:49.0895 0x0dfc MSPCLOCK - ok 14:58:49.0911 0x0dfc [ B572DA05BF4E098D4BBA3A4734FB505B, B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 14:58:49.0911 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSPQM.sys. md5: B572DA05BF4E098D4BBA3A4734FB505B, sha256: B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA 14:58:49.0927 0x0dfc MSPQM - detected LockedFile.Multi.Generic ( 1 ) 14:58:52.0438 0x0dfc Detect skipped due to KSN trusted 14:58:52.0438 0x0dfc MSPQM - ok 14:58:52.0501 0x0dfc [ B49456D70555DE905C311BCDA6EC6ADB, 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 14:58:52.0501 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MsRPC.sys. md5: B49456D70555DE905C311BCDA6EC6ADB, sha256: 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F 14:58:52.0501 0x0dfc MsRPC - detected LockedFile.Multi.Generic ( 1 ) 14:58:55.0028 0x0dfc Detect skipped due to KSN trusted 14:58:55.0028 0x0dfc MsRPC - ok 14:58:55.0090 0x0dfc [ E384487CB84BE41D09711C30CA79646C, 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 14:58:55.0090 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mssmbios.sys. md5: E384487CB84BE41D09711C30CA79646C, sha256: 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C 14:58:55.0090 0x0dfc mssmbios - detected LockedFile.Multi.Generic ( 1 ) 14:58:57.0680 0x0dfc Detect skipped due to KSN trusted 14:58:57.0680 0x0dfc mssmbios - ok 14:58:57.0695 0x0dfc [ 7199C1EEC1E4993CAF96B8C0A26BD58A, DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 14:58:57.0695 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSTEE.sys. md5: 7199C1EEC1E4993CAF96B8C0A26BD58A, sha256: DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B 14:58:57.0695 0x0dfc MSTEE - detected LockedFile.Multi.Generic ( 1 ) 14:59:00.0207 0x0dfc Detect skipped due to KSN trusted 14:59:00.0207 0x0dfc MSTEE - ok 14:59:00.0254 0x0dfc [ 6A57B5733D4CB702C8EA4542E836B96C, 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 ] Mup C:\Windows\system32\Drivers\mup.sys 14:59:00.0269 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\mup.sys. md5: 6A57B5733D4CB702C8EA4542E836B96C, sha256: 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 14:59:00.0269 0x0dfc Mup - detected LockedFile.Multi.Generic ( 1 ) 14:59:02.0781 0x0dfc Detect skipped due to KSN trusted 14:59:02.0781 0x0dfc Mup - ok 14:59:02.0875 0x0dfc [ E4EAF0C5C1B41B5C83386CF212CA9584, 5946C3DCE65A0DB164169A1775DFCA544AF4E1895ADF6916BB1653F373F8D9AF ] napagent C:\Windows\system32\qagentRT.dll 14:59:02.0890 0x0dfc napagent - ok 14:59:02.0984 0x0dfc [ 85C44FDFF9CF7E72A40DCB7EC06A4416, DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 14:59:02.0984 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\nwifi.sys. md5: 85C44FDFF9CF7E72A40DCB7EC06A4416, sha256: DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 14:59:02.0984 0x0dfc NativeWifiP - detected LockedFile.Multi.Generic ( 1 ) 14:59:05.0495 0x0dfc Detect skipped due to KSN trusted 14:59:05.0495 0x0dfc NativeWifiP - ok 14:59:05.0573 0x0dfc [ 1357274D1883F68300AEADD15D7BBB42, EE6352CBF0D9D633816F338159CDA27F1A805C3DDC3402D8605B50D8F3CD3300 ] NDIS C:\Windows\system32\drivers\ndis.sys 14:59:05.0620 0x0dfc NDIS - ok 14:59:05.0651 0x0dfc [ 0E186E90404980569FB449BA7519AE61, DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 14:59:05.0667 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ndistapi.sys. md5: 0E186E90404980569FB449BA7519AE61, sha256: DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B 14:59:05.0667 0x0dfc NdisTapi - detected LockedFile.Multi.Generic ( 1 ) 14:59:08.0459 0x0dfc Detect skipped due to KSN trusted 14:59:08.0459 0x0dfc NdisTapi - ok 14:59:08.0506 0x0dfc [ D6973AA34C4D5D76C0430B181C3CD389, 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 14:59:08.0506 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ndisuio.sys. md5: D6973AA34C4D5D76C0430B181C3CD389, sha256: 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC 14:59:08.0522 0x0dfc Ndisuio - detected LockedFile.Multi.Generic ( 1 ) 14:59:11.0111 0x0dfc Detect skipped due to KSN trusted 14:59:11.0111 0x0dfc Ndisuio - ok 14:59:11.0158 0x0dfc [ 818F648618AE34F729FDB47EC68345C3, 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 14:59:11.0158 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ndiswan.sys. md5: 818F648618AE34F729FDB47EC68345C3, sha256: 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 14:59:11.0158 0x0dfc NdisWan - detected LockedFile.Multi.Generic ( 1 ) 14:59:13.0685 0x0dfc Detect skipped due to KSN trusted 14:59:13.0685 0x0dfc NdisWan - ok 14:59:13.0763 0x0dfc [ 71DAB552B41936358F3B541AE5997FB3, 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 14:59:13.0763 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\NDProxy.sys. md5: 71DAB552B41936358F3B541AE5997FB3, sha256: 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 14:59:13.0763 0x0dfc NDProxy - detected LockedFile.Multi.Generic ( 1 ) 14:59:16.0337 0x0dfc Detect skipped due to KSN trusted 14:59:16.0337 0x0dfc NDProxy - ok 14:59:16.0384 0x0dfc [ BCD093A5A6777CF626434568DC7DBA78, 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 14:59:16.0384 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\netbios.sys. md5: BCD093A5A6777CF626434568DC7DBA78, sha256: 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD 14:59:16.0384 0x0dfc NetBIOS - detected LockedFile.Multi.Generic ( 1 ) 14:59:18.0974 0x0dfc Detect skipped due to KSN trusted 14:59:18.0974 0x0dfc NetBIOS - ok 14:59:19.0021 0x0dfc [ ECD64230A59CBD93C85F1CD1CAB9F3F6, 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F ] netbt C:\Windows\system32\DRIVERS\netbt.sys 14:59:19.0036 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\netbt.sys. md5: ECD64230A59CBD93C85F1CD1CAB9F3F6, sha256: 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F 14:59:19.0052 0x0dfc netbt - detected LockedFile.Multi.Generic ( 1 ) 14:59:21.0626 0x0dfc Detect skipped due to KSN trusted 14:59:21.0626 0x0dfc netbt - ok 14:59:21.0657 0x0dfc [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] Netlogon C:\Windows\system32\lsass.exe 14:59:21.0657 0x0dfc Netlogon - ok 14:59:21.0782 0x0dfc [ C8052711DAECC48B982434C5116CA401, 417DEB86D157DD3F0B4678410FE27FDD3E8FA04AB03AF398F6C02BF207070B35 ] Netman C:\Windows\System32\netman.dll 14:59:21.0813 0x0dfc Netman - ok 14:59:21.0860 0x0dfc [ 2EF3BBE22E5A5ACD1428EE387A0D0172, 55DB91EDD0339D2434C06445F8A716A48EA90925B0FF7EBF45BB79D4B54B80BF ] netprofm C:\Windows\System32\netprofm.dll 14:59:21.0875 0x0dfc netprofm - ok 14:59:21.0922 0x0dfc [ D6C4E4A39A36029AC0813D476FBD0248, A0907D98580D1CD3007365CBBB53E84BEF39001E05912776F68EB0564B54B6EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 14:59:21.0938 0x0dfc NetTcpPortSharing - ok 14:59:21.0969 0x0dfc [ 2E7FB731D4790A1BC6270ACCEFACB36E, EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 14:59:21.0985 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nfrd960.sys. md5: 2E7FB731D4790A1BC6270ACCEFACB36E, sha256: EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 14:59:21.0985 0x0dfc nfrd960 - detected LockedFile.Multi.Generic ( 1 ) 14:59:24.0496 0x0dfc Detect skipped due to KSN trusted 14:59:24.0496 0x0dfc nfrd960 - ok 14:59:24.0543 0x0dfc [ 2997B15415F9BBE05B5A4C1C85E0C6A2, 5455536515FE740E18E090329FDCC40288724372AD18ACDB2CB4BB9D85CF681E ] NlaSvc C:\Windows\System32\nlasvc.dll 14:59:24.0559 0x0dfc NlaSvc - ok 14:59:24.0668 0x0dfc [ CB992AE1506985D9167E85883B4C3240, 667592260A9D3828BDF8955AA6D2864C8977EEC385D7EC2EE3A6B601B8DB70AB ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 14:59:24.0683 0x0dfc NMIndexingService - ok 14:59:24.0761 0x0dfc [ D36F239D7CCE1931598E8FB90A0DBC26, DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 ] Npfs C:\Windows\system32\drivers\Npfs.sys 14:59:24.0761 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Npfs.sys. md5: D36F239D7CCE1931598E8FB90A0DBC26, sha256: DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 14:59:24.0761 0x0dfc Npfs - detected LockedFile.Multi.Generic ( 1 ) 14:59:27.0273 0x0dfc Detect skipped due to KSN trusted 14:59:27.0273 0x0dfc Npfs - ok 14:59:27.0320 0x0dfc [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD, 15CA178518EB3D457AA4C109D97A8490821590842AE4E9841703B5A55870C8F6 ] nsi C:\Windows\system32\nsisvc.dll 14:59:27.0320 0x0dfc nsi - ok 14:59:27.0367 0x0dfc [ 609773E344A97410CE4EBF74A8914FCF, 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 14:59:27.0367 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nsiproxy.sys. md5: 609773E344A97410CE4EBF74A8914FCF, sha256: 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD 14:59:27.0367 0x0dfc nsiproxy - detected LockedFile.Multi.Generic ( 1 ) 14:59:29.0894 0x0dfc Detect skipped due to KSN trusted 14:59:29.0894 0x0dfc nsiproxy - ok 14:59:30.0190 0x0dfc [ 6A4A98CEE84CF9E99564510DDA4BAA47, 18C3D8C0F12761D3B7FC43D9413CF4C4CEBF8CA9BEC521381F40D241B35EA779 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 14:59:30.0190 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Ntfs.sys. md5: 6A4A98CEE84CF9E99564510DDA4BAA47, sha256: 18C3D8C0F12761D3B7FC43D9413CF4C4CEBF8CA9BEC521381F40D241B35EA779 14:59:30.0190 0x0dfc Ntfs - detected LockedFile.Multi.Generic ( 1 ) 14:59:32.0983 0x0dfc Detect skipped due to KSN trusted 14:59:32.0983 0x0dfc Ntfs - ok 14:59:33.0029 0x0dfc [ E875C093AEC0C978A90F30C9E0DFBB72, D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys 14:59:33.0029 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ntrigdigi.sys. md5: E875C093AEC0C978A90F30C9E0DFBB72, sha256: D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 14:59:33.0029 0x0dfc ntrigdigi - detected LockedFile.Multi.Generic ( 1 ) 14:59:35.0619 0x0dfc Detect skipped due to KSN trusted 14:59:35.0619 0x0dfc ntrigdigi - ok 14:59:35.0666 0x0dfc [ C5DBBCDA07D780BDA9B685DF333BB41E, 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 ] Null C:\Windows\system32\drivers\Null.sys 14:59:35.0666 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Null.sys. md5: C5DBBCDA07D780BDA9B685DF333BB41E, sha256: 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 14:59:35.0666 0x0dfc Null - detected LockedFile.Multi.Generic ( 1 ) 14:59:40.0315 0x0dfc Detect skipped due to KSN trusted 14:59:40.0315 0x0dfc Null - ok 14:59:40.0361 0x0dfc [ 2EDF9E7751554B42CBB60116DE727101, 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B ] nvraid C:\Windows\system32\drivers\nvraid.sys 14:59:40.0361 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nvraid.sys. md5: 2EDF9E7751554B42CBB60116DE727101, sha256: 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B 14:59:40.0361 0x0dfc nvraid - detected LockedFile.Multi.Generic ( 1 ) 14:59:42.0982 0x0dfc Detect skipped due to KSN trusted 14:59:42.0982 0x0dfc nvraid - ok 14:59:43.0029 0x0dfc [ ABED0C09758D1D97DB0042DBB2688177, 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 ] nvstor C:\Windows\system32\drivers\nvstor.sys 14:59:43.0029 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nvstor.sys. md5: ABED0C09758D1D97DB0042DBB2688177, sha256: 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 14:59:43.0029 0x0dfc nvstor - detected LockedFile.Multi.Generic ( 1 ) 14:59:45.0541 0x0dfc Detect skipped due to KSN trusted 14:59:45.0541 0x0dfc nvstor - ok 14:59:45.0650 0x0dfc [ 18BBDF913916B71BD54575BDB6EEAC0B, 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 14:59:45.0650 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nv_agp.sys. md5: 18BBDF913916B71BD54575BDB6EEAC0B, sha256: 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 14:59:45.0728 0x0dfc nv_agp - detected LockedFile.Multi.Generic ( 1 ) 14:59:48.0317 0x0dfc Detect skipped due to KSN trusted 14:59:48.0333 0x0dfc nv_agp - ok 14:59:48.0333 0x0dfc NwlnkFlt - ok 14:59:48.0349 0x0dfc NwlnkFwd - ok 14:59:48.0395 0x0dfc [ BE32DA025A0BE1878F0EE8D6D9386CD5, B9D6CB4626FC67D108D713467C9ED8D0E2A071D98621B5531AD9D0C172FE7B89 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 14:59:48.0395 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ohci1394.sys. md5: BE32DA025A0BE1878F0EE8D6D9386CD5, sha256: B9D6CB4626FC67D108D713467C9ED8D0E2A071D98621B5531AD9D0C172FE7B89 14:59:48.0395 0x0dfc ohci1394 - detected LockedFile.Multi.Generic ( 1 ) 14:59:50.0923 0x0dfc Detect skipped due to KSN trusted 14:59:50.0923 0x0dfc ohci1394 - ok 14:59:51.0001 0x0dfc [ 7A56CF3E3F12E8AF599963B16F50FB6A, 882C82BAE96D263138D4C0D6C425458B770B7B9C8E9C1D28AC918BF6BE94A5C2 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 14:59:51.0001 0x0dfc ose - ok 14:59:51.0110 0x0dfc [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2pimsvc C:\Windows\system32\p2psvc.dll 14:59:51.0141 0x0dfc p2pimsvc - ok 14:59:51.0313 0x0dfc [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2psvc C:\Windows\system32\p2psvc.dll 14:59:51.0359 0x0dfc p2psvc - ok 14:59:51.0406 0x0dfc [ 8A79FDF04A73428597E2CAF9D0D67850, DB438FDE5510AB2F350ED1AC4CF0E99D3CC665FE46533A438A8FDA4DAF950F93 ] Parport C:\Windows\system32\DRIVERS\parport.sys 14:59:51.0406 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\parport.sys. md5: 8A79FDF04A73428597E2CAF9D0D67850, sha256: DB438FDE5510AB2F350ED1AC4CF0E99D3CC665FE46533A438A8FDA4DAF950F93 14:59:51.0406 0x0dfc Parport - detected LockedFile.Multi.Generic ( 1 ) 14:59:54.0011 0x0dfc Detect skipped due to KSN trusted 14:59:54.0011 0x0dfc Parport - ok 14:59:54.0074 0x0dfc [ B9C2B89F08670E159F7181891E449CD9, BD48CE95CF4B75D1FD5FD379B2A8727BC000F2B6748B77636C6BDB0B37B0344A ] partmgr C:\Windows\system32\drivers\partmgr.sys 14:59:54.0074 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\partmgr.sys. md5: B9C2B89F08670E159F7181891E449CD9, sha256: BD48CE95CF4B75D1FD5FD379B2A8727BC000F2B6748B77636C6BDB0B37B0344A 14:59:54.0074 0x0dfc partmgr - detected LockedFile.Multi.Generic ( 1 ) 14:59:56.0601 0x0dfc Detect skipped due to KSN trusted 14:59:56.0601 0x0dfc partmgr - ok 14:59:56.0695 0x0dfc [ 6C580025C81CAF3AE9E3617C22CAD00E, 64F9061196462085E5DCD3ACB97A0D8FC67CA9A96DDD6E2103AFFF1593AE236A ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys 14:59:56.0695 0x0dfc Parvdm - ok 14:59:56.0741 0x0dfc [ C6276AD11F4BB49B58AA1ED88537F14A, 409E956AF994640DF8D062E5E41F87A6EE7EEE0335C191B582722A49322357CE ] PcaSvc C:\Windows\System32\pcasvc.dll 14:59:56.0757 0x0dfc PcaSvc - ok 14:59:56.0804 0x0dfc [ 941DC1D19E7E8620F40BBC206981EFDB, 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 ] pci C:\Windows\system32\drivers\pci.sys 14:59:56.0804 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pci.sys. md5: 941DC1D19E7E8620F40BBC206981EFDB, sha256: 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 14:59:56.0804 0x0dfc pci - detected LockedFile.Multi.Generic ( 1 ) 14:59:59.0315 0x0dfc Detect skipped due to KSN trusted 14:59:59.0315 0x0dfc pci - ok 14:59:59.0378 0x0dfc [ 1636D43F10416AEB483BC6001097B26C, 36E61A993693A46538FE0F726D67BB28886F61D53384AD600D1282296A27662E ] pciide C:\Windows\system32\drivers\pciide.sys 14:59:59.0393 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pciide.sys. md5: 1636D43F10416AEB483BC6001097B26C, sha256: 36E61A993693A46538FE0F726D67BB28886F61D53384AD600D1282296A27662E 14:59:59.0393 0x0dfc pciide - detected LockedFile.Multi.Generic ( 1 ) 15:00:01.0905 0x0dfc Detect skipped due to KSN trusted 15:00:01.0905 0x0dfc pciide - ok 15:00:01.0952 0x0dfc [ E6F3FB1B86AA519E7698AD05E58B04E5, 2C4B45DDD3B980C9DAA6F039CAEFCD6E84A4D5BB43AFBA73C0C42B5556C1303C ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 15:00:01.0952 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pcmcia.sys. md5: E6F3FB1B86AA519E7698AD05E58B04E5, sha256: 2C4B45DDD3B980C9DAA6F039CAEFCD6E84A4D5BB43AFBA73C0C42B5556C1303C 15:00:01.0952 0x0dfc pcmcia - detected LockedFile.Multi.Generic ( 1 ) 15:00:04.0463 0x0dfc Detect skipped due to KSN trusted 15:00:04.0463 0x0dfc pcmcia - ok 15:00:04.0573 0x0dfc [ 6349F6ED9C623B44B52EA3C63C831A92, 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 15:00:04.0573 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\peauth.sys. md5: 6349F6ED9C623B44B52EA3C63C831A92, sha256: 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 15:00:04.0573 0x0dfc PEAUTH - detected LockedFile.Multi.Generic ( 1 ) 15:00:07.0178 0x0dfc Detect skipped due to KSN trusted 15:00:07.0178 0x0dfc PEAUTH - ok 15:00:07.0365 0x0dfc [ B1689DF169143F57053F795390C99DB3, 887B8C76B34CABC68067C0F27CC4EEF02457A53634C96FE5B0FE9B99453BDBEF ] pla C:\Windows\system32\pla.dll 15:00:07.0443 0x0dfc pla - ok 15:00:07.0490 0x0dfc [ C5E7F8A996EC0A82D508FD9064A5569E, 416A93816CDF12DD42DEA796D37E6E2000D3172AAAB20D3EAD3B715DACD4B61F ] PlugPlay C:\Windows\system32\umpnpmgr.dll 15:00:07.0505 0x0dfc PlugPlay - ok 15:00:07.0537 0x0dfc [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 15:00:07.0552 0x0dfc PNRPAutoReg - ok 15:00:07.0599 0x0dfc [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPsvc C:\Windows\system32\p2psvc.dll 15:00:07.0615 0x0dfc PNRPsvc - ok 15:00:07.0677 0x0dfc [ D0494460421A03CD5225CCA0059AA146, FC30E90522C63F2A66D89381705712D2CDF07B2E029DF40C2DEBB2353E763E90 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 15:00:07.0677 0x0dfc PolicyAgent - ok 15:00:07.0724 0x0dfc [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1, 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 15:00:07.0724 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\raspptp.sys. md5: ECFFFAEC0C1ECD8DBC77F39070EA1DB1, sha256: 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 15:00:07.0724 0x0dfc PptpMiniport - detected LockedFile.Multi.Generic ( 1 ) 15:00:10.0298 0x0dfc Detect skipped due to KSN trusted 15:00:10.0298 0x0dfc PptpMiniport - ok 15:00:10.0329 0x0dfc [ 2027293619DD0F047C584CF2E7DF4FFD, B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 ] Processor C:\Windows\system32\drivers\processr.sys 15:00:10.0329 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\processr.sys. md5: 2027293619DD0F047C584CF2E7DF4FFD, sha256: B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 15:00:10.0329 0x0dfc Processor - detected LockedFile.Multi.Generic ( 1 ) 15:00:12.0856 0x0dfc Detect skipped due to KSN trusted 15:00:12.0856 0x0dfc Processor - ok 15:00:12.0965 0x0dfc [ 0508FAA222D28835310B7BFCA7A77346, 3AE2340C6E365F137CC00D9560069501DD2724756EA9EBF7A6CDFFC91B43709C ] ProfSvc C:\Windows\system32\profsvc.dll 15:00:12.0981 0x0dfc ProfSvc - ok 15:00:12.0997 0x0dfc [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] ProtectedStorage C:\Windows\system32\lsass.exe 15:00:12.0997 0x0dfc ProtectedStorage - ok 15:00:13.0075 0x0dfc [ F2D954E138A752CC0C416512C0C380AC, 062E0C7DF06BFA876C302E408D22C610B09BA48CA16A4853FDD3C893BA41E6A9 ] PsBoot C:\Windows\system32\Drivers\PsBoot.sys 15:00:13.0075 0x0dfc PsBoot - ok 15:00:13.0121 0x0dfc [ 99514FAA8DF93D34B5589187DB3AA0BA, 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 ] PSched C:\Windows\system32\DRIVERS\pacer.sys 15:00:13.0121 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\pacer.sys. md5: 99514FAA8DF93D34B5589187DB3AA0BA, sha256: 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 15:00:13.0121 0x0dfc PSched - detected LockedFile.Multi.Generic ( 1 ) 15:00:15.0712 0x0dfc Detect skipped due to KSN trusted 15:00:15.0712 0x0dfc PSched - ok 15:00:15.0852 0x0dfc [ 0A6DB55AFB7820C99AA1F3A1D270F4F6, 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C ] ql2300 C:\Windows\system32\drivers\ql2300.sys 15:00:15.0852 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ql2300.sys. md5: 0A6DB55AFB7820C99AA1F3A1D270F4F6, sha256: 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C 15:00:15.0852 0x0dfc ql2300 - detected LockedFile.Multi.Generic ( 1 ) 15:00:18.0410 0x0dfc Detect skipped due to KSN trusted 15:00:18.0410 0x0dfc ql2300 - ok 15:00:18.0473 0x0dfc [ 81A7E5C076E59995D54BC1ED3A16E60B, A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 15:00:18.0473 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ql40xx.sys. md5: 81A7E5C076E59995D54BC1ED3A16E60B, sha256: A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 15:00:18.0473 0x0dfc ql40xx - detected LockedFile.Multi.Generic ( 1 ) 15:00:20.0984 0x0dfc Detect skipped due to KSN trusted 15:00:20.0984 0x0dfc ql40xx - ok 15:00:21.0062 0x0dfc [ E9ECAE663F47E6CB43962D18AB18890F, F1A05320CAED9E745AA36A6DA9B64C48AAEDE888B42B249840CEB31448F7F432 ] QWAVE C:\Windows\system32\qwave.dll 15:00:21.0078 0x0dfc QWAVE - ok 15:00:21.0094 0x0dfc [ 9F5E0E1926014D17486901C88ECA2DB7, 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 15:00:21.0094 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\qwavedrv.sys. md5: 9F5E0E1926014D17486901C88ECA2DB7, sha256: 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E 15:00:21.0094 0x0dfc QWAVEdrv - detected LockedFile.Multi.Generic ( 1 ) 15:00:23.0683 0x0dfc Detect skipped due to KSN trusted 15:00:23.0683 0x0dfc QWAVEdrv - ok 15:00:23.0730 0x0dfc [ 147D7F9C556D259924351FEB0DE606C3, E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 15:00:23.0730 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rasacd.sys. md5: 147D7F9C556D259924351FEB0DE606C3, sha256: E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 15:00:23.0730 0x0dfc RasAcd - detected LockedFile.Multi.Generic ( 1 ) 15:00:26.0242 0x0dfc Detect skipped due to KSN trusted 15:00:26.0242 0x0dfc RasAcd - ok 15:00:26.0320 0x0dfc [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F, 6A410ABCCD2211EFF511CDBF22E4152B57D2996336EBE711DFF71904AF232DB2 ] RasAuto C:\Windows\System32\rasauto.dll 15:00:26.0320 0x0dfc RasAuto - ok 15:00:26.0351 0x0dfc [ A214ADBAF4CB47DD2728859EF31F26B0, A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 15:00:26.0351 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rasl2tp.sys. md5: A214ADBAF4CB47DD2728859EF31F26B0, sha256: A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 15:00:26.0351 0x0dfc Rasl2tp - detected LockedFile.Multi.Generic ( 1 ) 15:00:28.0972 0x0dfc Detect skipped due to KSN trusted 15:00:28.0972 0x0dfc Rasl2tp - ok 15:00:29.0018 0x0dfc [ 75D47445D70CA6F9F894B032FBC64FCF, 9112EA5D25F867136858524C7965ACCEDC02675D1E2985B950598D89CCF25E14 ] RasMan C:\Windows\System32\rasmans.dll 15:00:29.0034 0x0dfc RasMan - ok 15:00:29.0065 0x0dfc [ 509A98DD18AF4375E1FC40BC175F1DEF, CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 15:00:29.0065 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\raspppoe.sys. md5: 509A98DD18AF4375E1FC40BC175F1DEF, sha256: CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 15:00:29.0081 0x0dfc RasPppoe - detected LockedFile.Multi.Generic ( 1 ) 15:00:31.0592 0x0dfc Detect skipped due to KSN trusted 15:00:31.0592 0x0dfc RasPppoe - ok 15:00:31.0608 0x0dfc [ 2005F4A1E05FA09389AC85840F0A9E4D, D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 15:00:31.0608 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rassstp.sys. md5: 2005F4A1E05FA09389AC85840F0A9E4D, sha256: D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 15:00:31.0608 0x0dfc RasSstp - detected LockedFile.Multi.Generic ( 1 ) 15:00:34.0120 0x0dfc Detect skipped due to KSN trusted 15:00:34.0120 0x0dfc RasSstp - ok 15:00:34.0244 0x0dfc [ B14C9D5B9ADD2F84F70570BBBFAA7935, 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 15:00:34.0244 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rdbss.sys. md5: B14C9D5B9ADD2F84F70570BBBFAA7935, sha256: 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 15:00:34.0244 0x0dfc rdbss - detected LockedFile.Multi.Generic ( 1 ) 15:00:36.0834 0x0dfc Detect skipped due to KSN trusted 15:00:36.0834 0x0dfc rdbss - ok 15:00:36.0850 0x0dfc [ 89E59BE9A564262A3FB6C4F4F1CD9899, 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 15:00:36.0850 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\RDPCDD.sys. md5: 89E59BE9A564262A3FB6C4F4F1CD9899, sha256: 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB 15:00:36.0850 0x0dfc RDPCDD - detected LockedFile.Multi.Generic ( 1 ) 15:00:39.0470 0x0dfc Detect skipped due to KSN trusted 15:00:39.0470 0x0dfc RDPCDD - ok 15:00:39.0502 0x0dfc [ FBC0BACD9C3D7F6956853F64A66E252D, 7672B10C7039295B152C02C96903E869FF2C0A88A2C3FA89BAE9F1D593B43569 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 15:00:39.0517 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdpdr.sys. md5: FBC0BACD9C3D7F6956853F64A66E252D, sha256: 7672B10C7039295B152C02C96903E869FF2C0A88A2C3FA89BAE9F1D593B43569 15:00:39.0517 0x0dfc rdpdr - detected LockedFile.Multi.Generic ( 1 ) 15:00:42.0029 0x0dfc Detect skipped due to KSN trusted 15:00:42.0029 0x0dfc rdpdr - ok 15:00:42.0044 0x0dfc [ 9D91FE5286F748862ECFFA05F8A0710C, 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 15:00:42.0044 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdpencdd.sys. md5: 9D91FE5286F748862ECFFA05F8A0710C, sha256: 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B 15:00:42.0044 0x0dfc RDPENCDD - detected LockedFile.Multi.Generic ( 1 ) 15:00:44.0572 0x0dfc Detect skipped due to KSN trusted 15:00:44.0572 0x0dfc RDPENCDD - ok 15:00:44.0634 0x0dfc [ C127EBD5AFAB31524662C48DFCEB773A, 40A6B88FEAFF02D1B5C0CA32F290CF3D9B48B85D248C7532F30CC5C09BAA4D89 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 15:00:44.0634 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\RDPWD.sys. md5: C127EBD5AFAB31524662C48DFCEB773A, sha256: 40A6B88FEAFF02D1B5C0CA32F290CF3D9B48B85D248C7532F30CC5C09BAA4D89 15:00:44.0634 0x0dfc RDPWD - detected LockedFile.Multi.Generic ( 1 ) 15:00:47.0146 0x0dfc Detect skipped due to KSN trusted 15:00:47.0146 0x0dfc RDPWD - ok 15:00:47.0208 0x0dfc [ BCDD6B4804D06B1F7EBF29E53A57ECE9, 8A961CCD0A0265E03D9952C733B593B02B5CF64E308D6B420276D2D6B20F86FC ] RemoteAccess C:\Windows\System32\mprdim.dll 15:00:47.0208 0x0dfc RemoteAccess - ok 15:00:47.0270 0x0dfc [ 9E6894EA18DAFF37B63E1005F83AE4AB, 5D6DF994D297C875D547C7B111A571AA90D582DAECADE18A53F65AD988819E67 ] RemoteRegistry C:\Windows\system32\regsvc.dll 15:00:47.0286 0x0dfc RemoteRegistry - ok 15:00:47.0442 0x0dfc [ 6482707F9F4DA0ECBAB43B2E0398A101, 7D57FC36577121D7E26A4F2D46DCA8725D55EC9F75B91DF994DB742BC4FB89C2 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 15:00:47.0442 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rfcomm.sys. md5: 6482707F9F4DA0ECBAB43B2E0398A101, sha256: 7D57FC36577121D7E26A4F2D46DCA8725D55EC9F75B91DF994DB742BC4FB89C2 15:00:47.0442 0x0dfc RFCOMM - detected LockedFile.Multi.Generic ( 1 ) 15:00:49.0954 0x0dfc Detect skipped due to KSN trusted 15:00:49.0954 0x0dfc RFCOMM - ok 15:00:50.0032 0x0dfc [ 5123F83CBC4349D065534EEB6BBDC42B, 92A3F38EA924D83D601BB93E3750F9DBC2DD963FB7ACF2A0E776297E21815225 ] RpcLocator C:\Windows\system32\locator.exe 15:00:50.0032 0x0dfc RpcLocator - ok 15:00:50.0094 0x0dfc [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] RpcSs C:\Windows\system32\rpcss.dll 15:00:50.0125 0x0dfc RpcSs - ok 15:00:50.0156 0x0dfc [ 9C508F4074A39E8B4B31D27198146FAD, 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 15:00:50.0156 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rspndr.sys. md5: 9C508F4074A39E8B4B31D27198146FAD, sha256: 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB 15:00:50.0156 0x0dfc rspndr - detected LockedFile.Multi.Generic ( 1 ) 15:00:52.0668 0x0dfc Detect skipped due to KSN trusted 15:00:52.0668 0x0dfc rspndr - ok 15:00:52.0699 0x0dfc [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] SamSs C:\Windows\system32\lsass.exe 15:00:52.0699 0x0dfc SamSs - ok 15:00:52.0730 0x0dfc [ 3CE8F073A557E172B330109436984E30, CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 15:00:52.0730 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sbp2port.sys. md5: 3CE8F073A557E172B330109436984E30, sha256: CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 15:00:52.0730 0x0dfc sbp2port - detected LockedFile.Multi.Generic ( 1 ) 15:00:55.0242 0x0dfc Detect skipped due to KSN trusted 15:00:55.0242 0x0dfc sbp2port - ok 15:00:55.0304 0x0dfc [ 77B7A11A0C3D78D3386398FBBEA1B632, A3D290AB793BDC2F84C7B963300DFCE81CFE082A0FFF7489E8E5B14714892C00 ] SCardSvr C:\Windows\System32\SCardSvr.dll 15:00:55.0320 0x0dfc SCardSvr - ok 15:00:55.0429 0x0dfc [ 1A58069DB21D05EB2AB58EE5753EBE8D, EED8111EB613F4C93D1638C74FDB0A6DC6694E1B108DCD0D794B5B5F9B8C6EE4 ] Schedule C:\Windows\system32\schedsvc.dll 15:00:55.0460 0x0dfc Schedule - ok 15:00:55.0492 0x0dfc [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] SCPolicySvc C:\Windows\System32\certprop.dll 15:00:55.0492 0x0dfc SCPolicySvc - ok 15:00:55.0538 0x0dfc [ 716313D9F6B0529D03F726D5AAF6F191, 44FE994A11631C1D99C73026340BACE39973C65A1281D87A61B481C9B5FAB251 ] SDRSVC C:\Windows\System32\SDRSVC.dll 15:00:55.0538 0x0dfc SDRSVC - ok 15:00:55.0570 0x0dfc [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys 15:00:55.0570 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\secdrv.sys. md5: 90A3935D05B494A5A39D37E71F09A677, sha256: F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 15:00:55.0570 0x0dfc secdrv - detected LockedFile.Multi.Generic ( 1 ) 15:00:58.0175 0x0dfc Detect skipped due to KSN trusted 15:00:58.0175 0x0dfc secdrv - ok 15:00:58.0190 0x0dfc [ FD5199D4D8A521005E4B5EE7FE00FA9B, 0FB7A1D300C72B1ADC423CC57343C17853E5F8ACFE3EA2C42FAC2FF72E502FBE ] seclogon C:\Windows\system32\seclogon.dll 15:00:58.0190 0x0dfc seclogon - ok 15:00:58.0237 0x0dfc [ A9BBAB5759771E523F55563D6CBE140F, 415BF6F6A1E4C5F98DABF9C2EEAF8CA49730693046E5F94C7655683717EDAD75 ] SENS C:\Windows\System32\sens.dll 15:00:58.0237 0x0dfc SENS - ok 15:00:58.0268 0x0dfc [ CE9EC966638EF0B10B864DDEDF62A099, 2DEC5A8C947D87C12B342F15B8A552A0D49B979A2AC32D2C97FC7A3A76C34524 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 15:00:58.0268 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\serenum.sys. md5: CE9EC966638EF0B10B864DDEDF62A099, sha256: 2DEC5A8C947D87C12B342F15B8A552A0D49B979A2AC32D2C97FC7A3A76C34524 15:00:58.0268 0x0dfc Serenum - detected LockedFile.Multi.Generic ( 1 ) 15:01:00.0889 0x0dfc Detect skipped due to KSN trusted 15:01:00.0889 0x0dfc Serenum - ok 15:01:00.0952 0x0dfc [ 6D663022DB3E7058907784AE14B69898, 54263888C64A7F010D3B5E399369B0F3FF3AF0A0DE8ADB502B98277533E4D45F ] Serial C:\Windows\system32\DRIVERS\serial.sys 15:01:00.0952 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\serial.sys. md5: 6D663022DB3E7058907784AE14B69898, sha256: 54263888C64A7F010D3B5E399369B0F3FF3AF0A0DE8ADB502B98277533E4D45F 15:01:00.0952 0x0dfc Serial - detected LockedFile.Multi.Generic ( 1 ) 15:01:03.0463 0x0dfc Detect skipped due to KSN trusted 15:01:03.0463 0x0dfc Serial - ok 15:01:03.0526 0x0dfc [ 8AF3D28A879BF75DB53A0EE7A4289624, C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 ] sermouse C:\Windows\system32\drivers\sermouse.sys 15:01:03.0526 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sermouse.sys. md5: 8AF3D28A879BF75DB53A0EE7A4289624, sha256: C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 15:01:03.0526 0x0dfc sermouse - detected LockedFile.Multi.Generic ( 1 ) 15:01:06.0037 0x0dfc Detect skipped due to KSN trusted 15:01:06.0037 0x0dfc sermouse - ok 15:01:06.0115 0x0dfc [ D2193326F729B163125610DBF3E17D57, 82C894E24E2C139C884246A693AD37BBF0A4E9375B7F7A288EF1DB22F89434B9 ] SessionEnv C:\Windows\system32\sessenv.dll 15:01:06.0131 0x0dfc SessionEnv - ok 15:01:06.0146 0x0dfc [ 3EFA810BDCA87F6ECC24F9832243FE86, E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 15:01:06.0146 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffdisk.sys. md5: 3EFA810BDCA87F6ECC24F9832243FE86, sha256: E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F 15:01:06.0146 0x0dfc sffdisk - detected LockedFile.Multi.Generic ( 1 ) 15:01:08.0674 0x0dfc Detect skipped due to KSN trusted 15:01:08.0674 0x0dfc sffdisk - ok 15:01:08.0720 0x0dfc [ E95D451F7EA3E583AEC75F3B3EE42DC5, B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 15:01:08.0720 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffp_mmc.sys. md5: E95D451F7EA3E583AEC75F3B3EE42DC5, sha256: B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 15:01:08.0720 0x0dfc sffp_mmc - detected LockedFile.Multi.Generic ( 1 ) 15:01:11.0248 0x0dfc Detect skipped due to KSN trusted 15:01:11.0248 0x0dfc sffp_mmc - ok 15:01:11.0263 0x0dfc [ 3D0EA348784B7AC9EA9BD9F317980979, 2500CE188C9B71C50E966FA575303AEFE50934E376C530AECEC7C7533C15EF08 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 15:01:11.0263 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffp_sd.sys. md5: 3D0EA348784B7AC9EA9BD9F317980979, sha256: 2500CE188C9B71C50E966FA575303AEFE50934E376C530AECEC7C7533C15EF08 15:01:11.0263 0x0dfc sffp_sd - detected LockedFile.Multi.Generic ( 1 ) 15:01:13.0868 0x0dfc Detect skipped due to KSN trusted 15:01:13.0868 0x0dfc sffp_sd - ok 15:01:13.0915 0x0dfc [ 46ED8E91793B2E6F848015445A0AC188, 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 15:01:13.0915 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sfloppy.sys. md5: 46ED8E91793B2E6F848015445A0AC188, sha256: 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D 15:01:13.0915 0x0dfc sfloppy - detected LockedFile.Multi.Generic ( 1 ) 15:01:16.0442 0x0dfc Detect skipped due to KSN trusted 15:01:16.0442 0x0dfc sfloppy - ok 15:01:16.0552 0x0dfc [ E1499BD0FF76B1B2FBBF1AF339D91165, 9A8F0403467E75880D3070C4D862489A75134383BAF8E7C45F8C5E7DFB0605A5 ] SharedAccess C:\Windows\System32\ipnathlp.dll 15:01:16.0567 0x0dfc SharedAccess - ok 15:01:16.0630 0x0dfc [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 15:01:16.0645 0x0dfc ShellHWDetection - ok 15:01:16.0708 0x0dfc [ D91FE032CEB881A2E8A0326C6D4D5FC1, 0C2BC68C3580351D189DD50985F3A7D961EC06D29546D8ADBA7C85CAB8636523 ] SiS6350 C:\Windows\system32\DRIVERS\SISGRKMD.sys 15:01:16.0708 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\SISGRKMD.sys. md5: D91FE032CEB881A2E8A0326C6D4D5FC1, sha256: 0C2BC68C3580351D189DD50985F3A7D961EC06D29546D8ADBA7C85CAB8636523 15:01:16.0708 0x0dfc SiS6350 - detected LockedFile.Multi.Generic ( 1 ) 15:01:19.0235 0x0dfc Detect skipped due to KSN trusted 15:01:19.0235 0x0dfc SiS6350 - ok 15:01:19.0328 0x0dfc [ DF1AF7F5F1EC7800B3AC398ACC06C754, 84D42DA6C27322DF15A2696AB9456FE962013776D73B98F6107C726BECFFC6B5 ] SISAGP C:\Windows\system32\DRIVERS\SISAGPX.sys 15:01:19.0328 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\SISAGPX.sys. md5: DF1AF7F5F1EC7800B3AC398ACC06C754, sha256: 84D42DA6C27322DF15A2696AB9456FE962013776D73B98F6107C726BECFFC6B5 15:01:19.0328 0x0dfc SISAGP - detected LockedFile.Multi.Generic ( 1 ) 15:01:21.0918 0x0dfc Detect skipped due to KSN trusted 15:01:21.0918 0x0dfc SISAGP - ok 15:01:21.0965 0x0dfc [ 7A83BA25421C3254B4A133F2EC7C46AD, 9C9ED6E87CF03AC5141E32A522AED487952EECD6811B87F67CA6126C4BAD3400 ] SiSGbeLH C:\Windows\system32\DRIVERS\SiSGB6.sys 15:01:21.0965 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\SiSGB6.sys. md5: 7A83BA25421C3254B4A133F2EC7C46AD, sha256: 9C9ED6E87CF03AC5141E32A522AED487952EECD6811B87F67CA6126C4BAD3400 15:01:21.0965 0x0dfc SiSGbeLH - detected LockedFile.Multi.Generic ( 1 ) 15:01:24.0586 0x0dfc SiSGbeLH ( LockedFile.Multi.Generic ) - warning 15:01:24.0586 0x0dfc Force sending object to P2P due to detect: C:\Windows\system32\DRIVERS\SiSGB6.sys 15:01:29.0858 0x0dfc Object send P2P result: true 15:01:32.0386 0x0dfc [ 43CB7AA756C7DB280D01DA9B676CFDE2, 08484CAEA0518C0A4CCCD292D8C803B27FEC453537EE1E4CEE74A7208356A474 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 15:01:32.0386 0x0dfc SiSRaid2 - ok 15:01:32.0417 0x0dfc [ A99C6C8B0BAA970D8AA59DDC50B57F94, 97AC9DD6DC4F58AC60E819B999BB157663EE7C1739521D16768AA9AC00DAD012 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 15:01:32.0417 0x0dfc SiSRaid4 - ok 15:01:32.0698 0x0dfc [ 862BB4CBC05D80C5B45BE430E5EF872F, F4961B22C93E472C8C862421AA231CDDA9E40D3958741A1D666357F22CC3143D ] slsvc C:\Windows\system32\SLsvc.exe 15:01:32.0776 0x0dfc slsvc - ok 15:01:32.0854 0x0dfc [ 6EDC422215CD78AA8A9CDE6B30ABBD35, D8342BC3152859F4F7512E85ABEC61147DBCAB515458644728874E42F639D6CA ] SLUINotify C:\Windows\system32\SLUINotify.dll 15:01:32.0854 0x0dfc SLUINotify - ok 15:01:32.0900 0x0dfc [ 7B75299A4D201D6A6533603D6914AB04, 172BE3951F06B1991EF70B71EB91786D1EFC4E381C22BCA3A5F622CD59F3227E ] Smb C:\Windows\system32\DRIVERS\smb.sys 15:01:32.0900 0x0dfc Smb - ok 15:01:32.0916 0x0dfc SMR410 - ok 15:01:32.0978 0x0dfc [ 2A146A055B4401C16EE62D18B8E2A032, D0930FFA53951C92F56E1ECB41374F4C0AA01ECBF99F474513A21EAD579CFE47 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 15:01:32.0978 0x0dfc SNMPTRAP - ok 15:01:33.0649 0x0dfc [ C397234C360D9C5E0396F0FAC69D1BAD, 4E15FAA4B570C9005C99B97F03A4F3CAA6BF4879F10015683C4C4C3FEE4466E8 ] SNP325 C:\Windows\system32\DRIVERS\snp325.sys 15:01:34.0102 0x0dfc SNP325 - ok 15:01:34.0211 0x0dfc [ 7AEBDEEF071FE28B0EEF2CDD69102BFF, E03BEE733F4C2A5F39946D4955679A290E22758DFCE4222EE69ABF64FC54EDF7 ] spldr C:\Windows\system32\drivers\spldr.sys 15:01:34.0211 0x0dfc spldr - ok 15:01:34.0273 0x0dfc [ 8554097E5136C3BF9F69FE578A1B35F4, 2578545CFD647FB18F217B33C8CB4F0184A35F548659494056E455020CC15FB0 ] Spooler C:\Windows\System32\spoolsv.exe 15:01:34.0273 0x0dfc Spooler - ok 15:01:34.0336 0x0dfc [ 41987F9FC0E61ADF54F581E15029AD91, A46E718648C2DD3B43FC3798932C966315893A59442A0686CE46C605B9E4641E ] srv C:\Windows\system32\DRIVERS\srv.sys 15:01:34.0336 0x0dfc srv - ok 15:01:34.0382 0x0dfc [ FF33AFF99564B1AA534F58868CBE41EF, EFBB005DA19E5B320009CBF93E686D8BFA6A50A23B5A5001C7C84C7D85EF7D49 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 15:01:34.0382 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\srv2.sys. md5: FF33AFF99564B1AA534F58868CBE41EF, sha256: EFBB005DA19E5B320009CBF93E686D8BFA6A50A23B5A5001C7C84C7D85EF7D49 15:01:34.0382 0x0dfc srv2 - detected LockedFile.Multi.Generic ( 1 ) 15:01:36.0894 0x0dfc Detect skipped due to KSN trusted 15:01:36.0894 0x0dfc srv2 - ok 15:01:36.0956 0x0dfc [ 7605C0E1D01A08F3ECD743F38B834A44, 83A77E31004BCF83443F30EFC290E04BB1A2F332E8DFD614AB6E25B527C92299 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 15:01:36.0972 0x0dfc srvnet - ok 15:01:37.0019 0x0dfc [ 03D50B37234967433A5EA5BA72BC0B62, 7B61D6A4BF5D446A9473D058BC207FB6DA7C2FEFB8083F3B66CAC8907DBD8327 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 15:01:37.0034 0x0dfc SSDPSRV - ok 15:01:37.0066 0x0dfc [ 6F1A32E7B7B30F004D9A20AFADB14944, AA9D874A14CA4779E76701D2B02F4CCA92CD5917435FB4CACA149FCB2D1D4C4C ] SstpSvc C:\Windows\system32\sstpsvc.dll 15:01:37.0081 0x0dfc SstpSvc - ok 15:01:37.0144 0x0dfc [ 5DE7D67E49B88F5F07F3E53C4B92A352, 6930A598C35646646ED0E91633797EFE139AE6CDD0012335BD1340754A22F997 ] stisvc C:\Windows\System32\wiaservc.dll 15:01:37.0175 0x0dfc stisvc - ok 15:01:37.0206 0x0dfc [ 7BA58ECF0C0A9A69D44B3DCA62BECF56, 23CC47FA2D6E183D69DB0D3D3F3081A830D94A58FBC0A9A295B3A56C51E9486A ] swenum C:\Windows\system32\DRIVERS\swenum.sys 15:01:37.0206 0x0dfc swenum - ok 15:01:37.0284 0x0dfc [ F21FD248040681CCA1FB6C9A03AAA93D, 32FE765841A183A1F2C1ACACBBF8CDB11E7D4D4396F9C9F6CFF1B51C9B620ED3 ] swprv C:\Windows\System32\swprv.dll 15:01:37.0300 0x0dfc swprv - ok 15:01:37.0346 0x0dfc [ 192AA3AC01DF071B541094F251DEED10, 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 15:01:37.0346 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\symc8xx.sys. md5: 192AA3AC01DF071B541094F251DEED10, sha256: 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 15:01:37.0346 0x0dfc Symc8xx - detected LockedFile.Multi.Generic ( 1 ) 15:01:39.0858 0x0dfc Detect skipped due to KSN trusted 15:01:39.0858 0x0dfc Symc8xx - ok 15:01:39.0889 0x0dfc [ 8C8EB8C76736EBAF3B13B633B2E64125, A6C4845DDED81CCF4947612A4D6E42035136025BCD80812D2FF396927CAADEC5 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 15:01:39.0905 0x0dfc Sym_hi - ok 15:01:39.0936 0x0dfc [ 8072AF52B5FD103BBBA387A1E49F62CB, D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 15:01:39.0936 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sym_u3.sys. md5: 8072AF52B5FD103BBBA387A1E49F62CB, sha256: D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 15:01:39.0952 0x0dfc Sym_u3 - detected LockedFile.Multi.Generic ( 1 ) 15:01:42.0463 0x0dfc Detect skipped due to KSN trusted 15:01:42.0463 0x0dfc Sym_u3 - ok 15:01:42.0557 0x0dfc [ 9131B8AB722629A33649D6DEEE4FBFBE, FD39984178FE34F94F5562D566A1240C43D06F432B63CF93767A34733CEA0AF6 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 15:01:42.0557 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\SynTP.sys. md5: 9131B8AB722629A33649D6DEEE4FBFBE, sha256: FD39984178FE34F94F5562D566A1240C43D06F432B63CF93767A34733CEA0AF6 15:01:42.0557 0x0dfc SynTP - detected LockedFile.Multi.Generic ( 1 ) 15:01:45.0349 0x0dfc Detect skipped due to KSN trusted 15:01:45.0349 0x0dfc SynTP - ok 15:01:45.0443 0x0dfc [ 9A51B04E9886AA4EE90093586B0BA88D, 1666C29FBFA34174B506678C920636519051D03456A6DDCCD6FF708CAE5D9962 ] SysMain C:\Windows\system32\sysmain.dll 15:01:45.0474 0x0dfc SysMain - ok 15:01:45.0521 0x0dfc [ 2DCA225EAE15F42C0933E998EE0231C3, 67C7913E41854DFA3043426B7D59AA1FBBB9DE01A6E6904E40A696A7C61A5F98 ] TabletInputService C:\Windows\System32\TabSvc.dll 15:01:45.0536 0x0dfc TabletInputService - ok 15:01:45.0599 0x0dfc [ D7673E4B38CE21EE54C59EEEB65E2483, 330D0AD13F5008D8569CE8E5EA0BBD69F54F59FEB54FD903FA18D2849CEC6AF0 ] TapiSrv C:\Windows\System32\tapisrv.dll 15:01:45.0599 0x0dfc TapiSrv - ok 15:01:45.0646 0x0dfc [ CB05822CD9CC6C688168E113C603DBE7, 9DB8945BDC702BB13E9DE477F2D3CCA4CE0E9E8CE9B54CE1A25375F2A2C93F0E ] TBS C:\Windows\System32\tbssvc.dll 15:01:45.0646 0x0dfc TBS - ok 15:01:45.0708 0x0dfc [ 27D470DABC77BC60D0A3B0E4DEB6CB91, BB505F418856D722CC883CB4EEB51A26E9C62EFDF6E4B5BFCCCDEAE43025130C ] Tcpip C:\Windows\system32\drivers\tcpip.sys 15:01:45.0708 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tcpip.sys. md5: 27D470DABC77BC60D0A3B0E4DEB6CB91, sha256: BB505F418856D722CC883CB4EEB51A26E9C62EFDF6E4B5BFCCCDEAE43025130C 15:01:45.0708 0x0dfc Tcpip - detected LockedFile.Multi.Generic ( 1 ) 15:01:48.0220 0x0dfc Detect skipped due to KSN trusted 15:01:48.0220 0x0dfc Tcpip - ok 15:01:48.0376 0x0dfc [ 27D470DABC77BC60D0A3B0E4DEB6CB91, BB505F418856D722CC883CB4EEB51A26E9C62EFDF6E4B5BFCCCDEAE43025130C ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 15:01:48.0376 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tcpip.sys. md5: 27D470DABC77BC60D0A3B0E4DEB6CB91, sha256: BB505F418856D722CC883CB4EEB51A26E9C62EFDF6E4B5BFCCCDEAE43025130C 15:01:48.0376 0x0dfc Tcpip6 - detected LockedFile.Multi.Generic ( 1 ) 15:01:48.0376 0x0dfc Detect skipped due to KSN trusted 15:01:48.0376 0x0dfc Tcpip6 - ok 15:01:48.0422 0x0dfc [ 608C345A255D82A6289C2D468EB41FD7, 74ECFDD45DC3EB3AFAEF9C42B546241AA1D6ACB2F6591A76DDB8BB1768545889 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 15:01:48.0422 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tcpipreg.sys. md5: 608C345A255D82A6289C2D468EB41FD7, sha256: 74ECFDD45DC3EB3AFAEF9C42B546241AA1D6ACB2F6591A76DDB8BB1768545889 15:01:48.0422 0x0dfc tcpipreg - detected LockedFile.Multi.Generic ( 1 ) 15:01:51.0028 0x0dfc Detect skipped due to KSN trusted 15:01:51.0028 0x0dfc tcpipreg - ok 15:01:51.0074 0x0dfc [ 5DCF5E267BE67A1AE926F2DF77FBCC56, E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 15:01:51.0074 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tdpipe.sys. md5: 5DCF5E267BE67A1AE926F2DF77FBCC56, sha256: E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B 15:01:51.0074 0x0dfc TDPIPE - detected LockedFile.Multi.Generic ( 1 ) 15:01:53.0570 0x0dfc Detect skipped due to KSN trusted 15:01:53.0570 0x0dfc TDPIPE - ok 15:01:53.0617 0x0dfc [ 389C63E32B3CEFED425B61ED92D3F021, E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 15:01:53.0617 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tdtcp.sys. md5: 389C63E32B3CEFED425B61ED92D3F021, sha256: E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 15:01:53.0617 0x0dfc TDTCP - detected LockedFile.Multi.Generic ( 1 ) 15:01:56.0129 0x0dfc Detect skipped due to KSN trusted 15:01:56.0129 0x0dfc TDTCP - ok 15:01:56.0207 0x0dfc [ 76B06EB8A01FC8624D699E7045303E54, EC30F244B48A35622ED3EE91792F6A1517C5A50770FAB3945E7A945EB7AF28A8 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 15:01:56.0207 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tdx.sys. md5: 76B06EB8A01FC8624D699E7045303E54, sha256: EC30F244B48A35622ED3EE91792F6A1517C5A50770FAB3945E7A945EB7AF28A8 15:01:56.0207 0x0dfc tdx - detected LockedFile.Multi.Generic ( 1 ) 15:01:58.0718 0x0dfc Detect skipped due to KSN trusted 15:01:58.0718 0x0dfc tdx - ok 15:01:58.0750 0x0dfc [ 3CAD38910468EAB9A6479E2F01DB43C7, 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 15:01:58.0750 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\termdd.sys. md5: 3CAD38910468EAB9A6479E2F01DB43C7, sha256: 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C 15:01:58.0750 0x0dfc TermDD - detected LockedFile.Multi.Generic ( 1 ) 15:02:01.0355 0x0dfc Detect skipped due to KSN trusted 15:02:01.0355 0x0dfc TermDD - ok 15:02:01.0558 0x0dfc [ BB95DA09BEF6E7A131BFF3BA5032090D, BAF6997F8D944F85F0553957677866C7F22E72AA434BA45FFFB6CC41041070DC ] TermService C:\Windows\System32\termsrv.dll 15:02:01.0589 0x0dfc TermService - ok 15:02:01.0714 0x0dfc [ 0309C520AB9F1DBB4BF0F0A4D4DF01BD, 46FAAE85E027D5BCC854B366C5571C17AA74F07BFF2A87B4AA99EC59108DB709 ] TestHandler C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe 15:02:01.0729 0x0dfc TestHandler - ok 15:02:01.0776 0x0dfc [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] Themes C:\Windows\system32\shsvcs.dll 15:02:01.0792 0x0dfc Themes - ok 15:02:01.0823 0x0dfc [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] THREADORDER C:\Windows\system32\mmcss.dll 15:02:01.0838 0x0dfc THREADORDER - ok 15:02:01.0870 0x0dfc [ EC74E77D0EB004BD3A809B5F8FB8C2CE, 1E4BBC58D0E35D79C764CF1BA73602C5E29A5A2393D40332801D533E445C6667 ] TrkWks C:\Windows\System32\trkwks.dll 15:02:01.0870 0x0dfc TrkWks - ok 15:02:01.0963 0x0dfc [ 97D9D6A04E3AD9B6C626B9931DB78DBA, 8E42133ED5EE5EEC414A8B11C1035385C6141E445EA9677F947D20768F25A877 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 15:02:01.0963 0x0dfc TrustedInstaller - ok 15:02:02.0010 0x0dfc [ DCF0F056A2E4F52287264F5AB29CF206, D9F770BD65AE4320A8C130DEA1D093AA4E37FCA573BBE6A59D6D045452EA711D ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 15:02:02.0010 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tssecsrv.sys. md5: DCF0F056A2E4F52287264F5AB29CF206, sha256: D9F770BD65AE4320A8C130DEA1D093AA4E37FCA573BBE6A59D6D045452EA711D 15:02:02.0010 0x0dfc tssecsrv - detected LockedFile.Multi.Generic ( 1 ) 15:02:04.0522 0x0dfc Detect skipped due to KSN trusted 15:02:04.0522 0x0dfc tssecsrv - ok 15:02:04.0584 0x0dfc [ CAECC0120AC49E3D2F758B9169872D38, 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 15:02:04.0584 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tunmp.sys. md5: CAECC0120AC49E3D2F758B9169872D38, sha256: 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 15:02:04.0584 0x0dfc tunmp - detected LockedFile.Multi.Generic ( 1 ) 15:02:07.0205 0x0dfc Detect skipped due to KSN trusted 15:02:07.0205 0x0dfc tunmp - ok 15:02:07.0283 0x0dfc [ 300DB877AC094FEAB0BE7688C3454A9C, 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 15:02:07.0283 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tunnel.sys. md5: 300DB877AC094FEAB0BE7688C3454A9C, sha256: 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C 15:02:07.0283 0x0dfc tunnel - detected LockedFile.Multi.Generic ( 1 ) 15:02:09.0888 0x0dfc Detect skipped due to KSN trusted 15:02:09.0888 0x0dfc tunnel - ok 15:02:09.0919 0x0dfc [ 7D33C4DB2CE363C8518D2DFCF533941F, C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 15:02:09.0919 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\uagp35.sys. md5: 7D33C4DB2CE363C8518D2DFCF533941F, sha256: C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 15:02:09.0919 0x0dfc uagp35 - detected LockedFile.Multi.Generic ( 1 ) 15:02:12.0446 0x0dfc Detect skipped due to KSN trusted 15:02:12.0446 0x0dfc uagp35 - ok 15:02:12.0540 0x0dfc [ D9728AF68C4C7693CB100B8441CBDEC6, A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE ] udfs C:\Windows\system32\DRIVERS\udfs.sys 15:02:12.0540 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\udfs.sys. md5: D9728AF68C4C7693CB100B8441CBDEC6, sha256: A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE 15:02:12.0540 0x0dfc udfs - detected LockedFile.Multi.Generic ( 1 ) 15:02:15.0052 0x0dfc Detect skipped due to KSN trusted 15:02:15.0052 0x0dfc udfs - ok 15:02:15.0130 0x0dfc [ ECEF404F62863755951E09C802C94AD5, 5D92062B3E371F196774EBFE840C78501E55A244DB2A49703C7AC0141C7DABF1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 15:02:15.0145 0x0dfc UI0Detect - ok 15:02:15.0161 0x0dfc [ B0ACFDC9E4AF279E9116C03E014B2B27, 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 15:02:15.0161 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\uliagpkx.sys. md5: B0ACFDC9E4AF279E9116C03E014B2B27, sha256: 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF 15:02:15.0161 0x0dfc uliagpkx - detected LockedFile.Multi.Generic ( 1 ) 15:02:17.0750 0x0dfc Detect skipped due to KSN trusted 15:02:17.0750 0x0dfc uliagpkx - ok 15:02:17.0828 0x0dfc [ 9224BB254F591DE4CA8D572A5F0D635C, C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 ] uliahci C:\Windows\system32\drivers\uliahci.sys 15:02:17.0828 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\uliahci.sys. md5: 9224BB254F591DE4CA8D572A5F0D635C, sha256: C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 15:02:17.0828 0x0dfc uliahci - detected LockedFile.Multi.Generic ( 1 ) 15:02:20.0340 0x0dfc Detect skipped due to KSN trusted 15:02:20.0340 0x0dfc uliahci - ok 15:02:20.0371 0x0dfc [ 8514D0E5CD0534467C5FC61BE94A569F, A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 ] UlSata C:\Windows\system32\drivers\ulsata.sys 15:02:20.0371 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ulsata.sys. md5: 8514D0E5CD0534467C5FC61BE94A569F, sha256: A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 15:02:20.0371 0x0dfc UlSata - detected LockedFile.Multi.Generic ( 1 ) 15:02:22.0976 0x0dfc Detect skipped due to KSN trusted 15:02:22.0976 0x0dfc UlSata - ok 15:02:23.0023 0x0dfc [ 38C3C6E62B157A6BC46594FADA45C62B, 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 15:02:23.0023 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ulsata2.sys. md5: 38C3C6E62B157A6BC46594FADA45C62B, sha256: 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA 15:02:23.0023 0x0dfc ulsata2 - detected LockedFile.Multi.Generic ( 1 ) 15:02:25.0628 0x0dfc Detect skipped due to KSN trusted 15:02:25.0628 0x0dfc ulsata2 - ok 15:02:25.0675 0x0dfc [ 32CFF9F809AE9AED85464492BF3E32D2, 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC ] umbus C:\Windows\system32\DRIVERS\umbus.sys 15:02:25.0675 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\umbus.sys. md5: 32CFF9F809AE9AED85464492BF3E32D2, sha256: 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC 15:02:25.0675 0x0dfc umbus - detected LockedFile.Multi.Generic ( 1 ) 15:02:28.0249 0x0dfc Detect skipped due to KSN trusted 15:02:28.0249 0x0dfc umbus - ok 15:02:28.0327 0x0dfc [ 68308183F4AE0BE7BF8ECD07CB297999, 4444233CA3C42BEE50ED47553D4AE5A7C12D8F288D2FA4B2DAE1D9B9FEC1A72D ] upnphost C:\Windows\System32\upnphost.dll 15:02:28.0343 0x0dfc upnphost - ok 15:02:28.0405 0x0dfc [ CAF811AE4C147FFCD5B51750C7F09142, BD670CF88D8F932AD1C6BA91FB68A7204BC473657C6A057C92AFB84D164D393C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 15:02:28.0405 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbccgp.sys. md5: CAF811AE4C147FFCD5B51750C7F09142, sha256: BD670CF88D8F932AD1C6BA91FB68A7204BC473657C6A057C92AFB84D164D393C 15:02:28.0405 0x0dfc usbccgp - detected LockedFile.Multi.Generic ( 1 ) 15:02:30.0917 0x0dfc Detect skipped due to KSN trusted 15:02:30.0917 0x0dfc usbccgp - ok 15:02:30.0979 0x0dfc [ E9476E6C486E76BC4898074768FB7131, D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 ] usbcir C:\Windows\system32\drivers\usbcir.sys 15:02:30.0979 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\usbcir.sys. md5: E9476E6C486E76BC4898074768FB7131, sha256: D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 15:02:30.0979 0x0dfc usbcir - detected LockedFile.Multi.Generic ( 1 ) 15:02:33.0491 0x0dfc Detect skipped due to KSN trusted 15:02:33.0491 0x0dfc usbcir - ok 15:02:33.0569 0x0dfc [ 79E96C23A97CE7B8F14D310DA2DB0C9B, EB441D3B93965CD927E0C181031AD1082F59F9885BF35CABFDCA08C6C76B0DAF ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 15:02:33.0569 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbehci.sys. md5: 79E96C23A97CE7B8F14D310DA2DB0C9B, sha256: EB441D3B93965CD927E0C181031AD1082F59F9885BF35CABFDCA08C6C76B0DAF 15:02:33.0569 0x0dfc usbehci - detected LockedFile.Multi.Generic ( 1 ) 15:02:36.0080 0x0dfc Detect skipped due to KSN trusted 15:02:36.0080 0x0dfc usbehci - ok 15:02:36.0158 0x0dfc [ 4673BBCB006AF60E7ABDDBE7A130BA42, 0B7DED0D887A3530AA5497FDBCB69389486FB9E2B6FAE3163E33713256D575BA ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 15:02:36.0158 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbhub.sys. md5: 4673BBCB006AF60E7ABDDBE7A130BA42, sha256: 0B7DED0D887A3530AA5497FDBCB69389486FB9E2B6FAE3163E33713256D575BA 15:02:36.0158 0x0dfc usbhub - detected LockedFile.Multi.Generic ( 1 ) 15:02:38.0748 0x0dfc Detect skipped due to KSN trusted 15:02:38.0748 0x0dfc usbhub - ok 15:02:38.0810 0x0dfc [ CE697FEE0D479290D89BEC80DFE793B7, D10F6BAD0467672CCE4F97C7F2E13437CE89AC754C895EAE05F0726B6DC617B1 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 15:02:38.0810 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbohci.sys. md5: CE697FEE0D479290D89BEC80DFE793B7, sha256: D10F6BAD0467672CCE4F97C7F2E13437CE89AC754C895EAE05F0726B6DC617B1 15:02:38.0810 0x0dfc usbohci - detected LockedFile.Multi.Generic ( 1 ) 15:02:41.0431 0x0dfc Detect skipped due to KSN trusted 15:02:41.0431 0x0dfc usbohci - ok 15:02:41.0478 0x0dfc [ B51E52ACF758BE00EF3A58EA452FE360, 79E629EC5DE8AB7F31B0EE9AE94C71E8F703FED5C09A816228726974F7790C85 ] usbprint C:\Windows\system32\drivers\usbprint.sys 15:02:41.0478 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\usbprint.sys. md5: B51E52ACF758BE00EF3A58EA452FE360, sha256: 79E629EC5DE8AB7F31B0EE9AE94C71E8F703FED5C09A816228726974F7790C85 15:02:41.0478 0x0dfc usbprint - detected LockedFile.Multi.Generic ( 1 ) 15:02:44.0083 0x0dfc Detect skipped due to KSN trusted 15:02:44.0083 0x0dfc usbprint - ok 15:02:44.0130 0x0dfc [ BE3DA31C191BC222D9AD503C5224F2AD, 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 15:02:44.0146 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\USBSTOR.SYS. md5: BE3DA31C191BC222D9AD503C5224F2AD, sha256: 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 15:02:44.0146 0x0dfc USBSTOR - detected LockedFile.Multi.Generic ( 1 ) 15:02:46.0657 0x0dfc Detect skipped due to KSN trusted 15:02:46.0657 0x0dfc USBSTOR - ok 15:02:46.0720 0x0dfc [ 814D653EFC4D48BE3B04A307ECEFF56F, D73D62F51AEFE2F8F2B938B20107C246F2AC2F62ED49112DBD092A5D2E4024B3 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 15:02:46.0720 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbuhci.sys. md5: 814D653EFC4D48BE3B04A307ECEFF56F, sha256: D73D62F51AEFE2F8F2B938B20107C246F2AC2F62ED49112DBD092A5D2E4024B3 15:02:46.0720 0x0dfc usbuhci - detected LockedFile.Multi.Generic ( 1 ) 15:02:49.0247 0x0dfc Detect skipped due to KSN trusted 15:02:49.0247 0x0dfc usbuhci - ok 15:02:49.0309 0x0dfc [ 1509E705F3AC1D474C92454A5C2DD81F, 7F525921A3513224F8B093A16E19B4235B300349A14B0B86EE11B7473BA53337 ] UxSms C:\Windows\System32\uxsms.dll 15:02:49.0325 0x0dfc UxSms - ok 15:02:49.0403 0x0dfc [ CD88D1B7776DC17A119049742EC07EB4, 6B68B9EDB8C6BCB2644F1F004D5743E928509D12107D996F390A24A72E0AA528 ] vds C:\Windows\System32\vds.exe 15:02:49.0418 0x0dfc vds - ok 15:02:49.0450 0x0dfc [ 87B06E1F30B749A114F74622D013F8D4, 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 15:02:49.0450 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\vgapnp.sys. md5: 87B06E1F30B749A114F74622D013F8D4, sha256: 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 15:02:49.0450 0x0dfc vga - detected LockedFile.Multi.Generic ( 1 ) 15:02:51.0961 0x0dfc Detect skipped due to KSN trusted 15:02:51.0961 0x0dfc vga - ok 15:02:52.0024 0x0dfc [ 2E93AC0A1D8C79D019DB6C51F036636C, 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 ] VgaSave C:\Windows\System32\drivers\vga.sys 15:02:52.0024 0x0dfc Suspicious file ( NoAccess ): C:\Windows\System32\drivers\vga.sys. md5: 2E93AC0A1D8C79D019DB6C51F036636C, sha256: 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 15:02:52.0024 0x0dfc VgaSave - detected LockedFile.Multi.Generic ( 1 ) 15:02:54.0613 0x0dfc Detect skipped due to KSN trusted 15:02:54.0613 0x0dfc VgaSave - ok 15:02:54.0660 0x0dfc [ 5D7159DEF58A800D5781BA3A879627BC, 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 ] viaagp C:\Windows\system32\drivers\viaagp.sys 15:02:54.0660 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viaagp.sys. md5: 5D7159DEF58A800D5781BA3A879627BC, sha256: 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 15:02:54.0660 0x0dfc viaagp - detected LockedFile.Multi.Generic ( 1 ) 15:02:57.0187 0x0dfc Detect skipped due to KSN trusted 15:02:57.0187 0x0dfc viaagp - ok 15:02:57.0234 0x0dfc [ C4F3A691B5BAD343E6249BD8C2D45DEE, 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 ] ViaC7 C:\Windows\system32\drivers\viac7.sys 15:02:57.0234 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viac7.sys. md5: C4F3A691B5BAD343E6249BD8C2D45DEE, sha256: 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 15:02:57.0234 0x0dfc ViaC7 - detected LockedFile.Multi.Generic ( 1 ) 15:02:59.0746 0x0dfc Detect skipped due to KSN trusted 15:02:59.0746 0x0dfc ViaC7 - ok 15:02:59.0808 0x0dfc [ AADF5587A4063F52C2C3FED7887426FC, 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D ] viaide C:\Windows\system32\drivers\viaide.sys 15:02:59.0808 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viaide.sys. md5: AADF5587A4063F52C2C3FED7887426FC, sha256: 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D 15:02:59.0808 0x0dfc viaide - detected LockedFile.Multi.Generic ( 1 ) 15:03:02.0398 0x0dfc Detect skipped due to KSN trusted 15:03:02.0398 0x0dfc viaide - ok 15:03:02.0444 0x0dfc [ 69503668AC66C77C6CD7AF86FBDF8C43, 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 ] volmgr C:\Windows\system32\drivers\volmgr.sys 15:03:02.0444 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volmgr.sys. md5: 69503668AC66C77C6CD7AF86FBDF8C43, sha256: 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 15:03:02.0444 0x0dfc volmgr - detected LockedFile.Multi.Generic ( 1 ) 15:03:04.0972 0x0dfc Detect skipped due to KSN trusted 15:03:04.0972 0x0dfc volmgr - ok 15:03:05.0065 0x0dfc [ 23E41B834759917BFD6B9A0D625D0C28, 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 15:03:05.0065 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volmgrx.sys. md5: 23E41B834759917BFD6B9A0D625D0C28, sha256: 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 15:03:05.0065 0x0dfc volmgrx - detected LockedFile.Multi.Generic ( 1 ) 15:03:07.0670 0x0dfc Detect skipped due to KSN trusted 15:03:07.0670 0x0dfc volmgrx - ok 15:03:07.0717 0x0dfc [ 147281C01FCB1DF9252DE2A10D5E7093, DF5DCF6FD472F21863DC10B62F7647420B9686607857D08286B618D585E50219 ] volsnap C:\Windows\system32\drivers\volsnap.sys 15:03:07.0717 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volsnap.sys. md5: 147281C01FCB1DF9252DE2A10D5E7093, sha256: DF5DCF6FD472F21863DC10B62F7647420B9686607857D08286B618D585E50219 15:03:07.0733 0x0dfc volsnap - detected LockedFile.Multi.Generic ( 1 ) 15:03:10.0307 0x0dfc Detect skipped due to KSN trusted 15:03:10.0307 0x0dfc volsnap - ok 15:03:10.0385 0x0dfc [ 587253E09325E6BF226B299774B728A9, C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 15:03:10.0385 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vsmraid.sys. md5: 587253E09325E6BF226B299774B728A9, sha256: C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF 15:03:10.0385 0x0dfc vsmraid - detected LockedFile.Multi.Generic ( 1 ) 15:03:12.0896 0x0dfc Detect skipped due to KSN trusted 15:03:12.0896 0x0dfc vsmraid - ok 15:03:13.0037 0x0dfc [ DB3D19F850C6EB32BDCB9BC0836ACDDB, D81FF1CDA87A2FE83EFD5B3FE01EFF940952F8BAEE70BEA3B2F6EF30E2121704 ] VSS C:\Windows\system32\vssvc.exe 15:03:13.0099 0x0dfc VSS - ok 15:03:13.0162 0x0dfc [ 96EA68B9EB310A69C25EBB0282B2B9DE, C76D3427F8A2953CB4D96BBA1523679CBE1BBF7FA821A35D2FBEB3E67AC6A10B ] W32Time C:\Windows\system32\w32time.dll 15:03:13.0177 0x0dfc W32Time - ok 15:03:13.0208 0x0dfc [ 48DFEE8F1AF7C8235D4E626F0C4FE031, A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 15:03:13.0208 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wacompen.sys. md5: 48DFEE8F1AF7C8235D4E626F0C4FE031, sha256: A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 15:03:13.0208 0x0dfc WacomPen - detected LockedFile.Multi.Generic ( 1 ) 15:03:15.0720 0x0dfc Detect skipped due to KSN trusted 15:03:15.0720 0x0dfc WacomPen - ok 15:03:15.0782 0x0dfc [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 15:03:15.0782 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wanarp.sys. md5: 55201897378CCA7AF8B5EFD874374A26, sha256: 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC 15:03:15.0782 0x0dfc Wanarp - detected LockedFile.Multi.Generic ( 1 ) 15:03:18.0310 0x0dfc Detect skipped due to KSN trusted 15:03:18.0310 0x0dfc Wanarp - ok 15:03:18.0325 0x0dfc [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 15:03:18.0325 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wanarp.sys. md5: 55201897378CCA7AF8B5EFD874374A26, sha256: 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC 15:03:18.0372 0x0dfc Wanarpv6 - detected LockedFile.Multi.Generic ( 1 ) 15:03:18.0372 0x0dfc Detect skipped due to KSN trusted 15:03:18.0372 0x0dfc Wanarpv6 - ok 15:03:18.0450 0x0dfc [ A3CD60FD826381B49F03832590E069AF, 213C5DB5E5D828264286FD7548527566D6160CCA780BC6853B7B28CECF329674 ] wcncsvc C:\Windows\System32\wcncsvc.dll 15:03:18.0481 0x0dfc wcncsvc - ok 15:03:18.0512 0x0dfc [ 11BCB7AFCDD7AADACB5746F544D3A9C7, 0370E20FD12ED713F94E5CD76F068F7A7A5E7F42416DD2A8A41249020DA7DA31 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 15:03:18.0512 0x0dfc WcsPlugInService - ok 15:03:18.0544 0x0dfc [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd C:\Windows\system32\drivers\wd.sys 15:03:18.0544 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wd.sys. md5: 78FE9542363F297B18C027B2D7E7C07F, sha256: 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE 15:03:18.0544 0x0dfc Wd - detected LockedFile.Multi.Generic ( 1 ) 15:03:21.0055 0x0dfc Detect skipped due to KSN trusted 15:03:21.0055 0x0dfc Wd - ok 15:03:21.0149 0x0dfc [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96, 6A6EFFDB538DE1E201058A00F3E056F1256E92EED943FBFBCE28E54BE751E33D ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 15:03:21.0149 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Wdf01000.sys. md5: B6F0A7AD6D4BD325FBCD8BAC96CD8D96, sha256: 6A6EFFDB538DE1E201058A00F3E056F1256E92EED943FBFBCE28E54BE751E33D 15:03:21.0164 0x0dfc Wdf01000 - detected LockedFile.Multi.Generic ( 1 ) 15:03:23.0692 0x0dfc Detect skipped due to KSN trusted 15:03:23.0692 0x0dfc Wdf01000 - ok 15:03:23.0738 0x0dfc [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost C:\Windows\system32\wdi.dll 15:03:23.0754 0x0dfc WdiServiceHost - ok 15:03:23.0770 0x0dfc [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost C:\Windows\system32\wdi.dll 15:03:23.0770 0x0dfc WdiSystemHost - ok 15:03:23.0816 0x0dfc [ 04C37D8107320312FBAE09926103D5E2, 1C6726A9871CBACB240AFA93E57781515F01758D43693DDA395EA683D97234F0 ] WebClient C:\Windows\System32\webclnt.dll 15:03:23.0832 0x0dfc WebClient - ok 15:03:23.0863 0x0dfc [ 905214925A88311FCE52F66153DE7610, 5D18C6E835A2EA4108C93D9E6AA976142119860C8FC8ECB2DFA961A241B6E61C ] Wecsvc C:\Windows\system32\wecsvc.dll 15:03:23.0879 0x0dfc Wecsvc - ok 15:03:23.0894 0x0dfc [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport C:\Windows\System32\wercplsupport.dll 15:03:23.0910 0x0dfc wercplsupport - ok 15:03:23.0957 0x0dfc [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc C:\Windows\System32\WerSvc.dll 15:03:23.0972 0x0dfc WerSvc - ok 15:03:24.0050 0x0dfc [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 15:03:24.0082 0x0dfc WinDefend - ok 15:03:24.0097 0x0dfc WinHttpAutoProxySvc - ok 15:03:24.0160 0x0dfc [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 15:03:24.0160 0x0dfc Winmgmt - ok 15:03:24.0253 0x0dfc [ 01874D4689C212460FBABF0ECD7CB7F7, 8FC46BAD704A1E057DC4A8DC7374AAB93A96CC4A46E06FF9C2E06A6D62820469 ] WinRM C:\Windows\system32\WsmSvc.dll 15:03:24.0300 0x0dfc WinRM - ok 15:03:24.0394 0x0dfc [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc C:\Windows\System32\wlansvc.dll 15:03:24.0425 0x0dfc Wlansvc - ok 15:03:24.0456 0x0dfc [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 15:03:24.0456 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wmiacpi.sys. md5: 2E7255D172DF0B8283CDFB7B433B864E, sha256: 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 15:03:24.0456 0x0dfc WmiAcpi - detected LockedFile.Multi.Generic ( 1 ) 15:03:27.0046 0x0dfc Detect skipped due to KSN trusted 15:03:27.0046 0x0dfc WmiAcpi - ok 15:03:27.0108 0x0dfc [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 15:03:27.0124 0x0dfc wmiApSrv - ok 15:03:27.0233 0x0dfc [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 15:03:27.0295 0x0dfc WMPNetworkSvc - ok 15:03:27.0342 0x0dfc [ CFC5A04558F5070CEE3E3A7809F3FF52, 45899E04000E21C4E009BE8B6149F199A5B2E0512C657A525770BF9DBFED7D2B ] WPCSvc C:\Windows\System32\wpcsvc.dll 15:03:27.0358 0x0dfc WPCSvc - ok 15:03:27.0389 0x0dfc [ 396D406292B0CD26E3504FFE82784702, 5F9015BB515AC13D4DFE8F4B532352CF2C5B61DEFD3D0D61BCD82C781D36E7AF ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 15:03:27.0404 0x0dfc WPDBusEnum - ok 15:03:27.0436 0x0dfc [ 0CEC23084B51B8288099EB710224E955, E1AAB1E08E1745313D0A149A645AA878148D2DBE5CCC23C4ECCFC5003945C22B ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 15:03:27.0436 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wpdusb.sys. md5: 0CEC23084B51B8288099EB710224E955, sha256: E1AAB1E08E1745313D0A149A645AA878148D2DBE5CCC23C4ECCFC5003945C22B 15:03:27.0451 0x0dfc WpdUsb - detected LockedFile.Multi.Generic ( 1 ) 15:03:29.0963 0x0dfc Detect skipped due to KSN trusted 15:03:29.0963 0x0dfc WpdUsb - ok 15:03:30.0025 0x0dfc [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 15:03:30.0025 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ws2ifsl.sys. md5: E3A3CB253C0EC2494D4A61F5E43A389C, sha256: 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 15:03:30.0025 0x0dfc ws2ifsl - detected LockedFile.Multi.Generic ( 1 ) 15:03:32.0599 0x0dfc Detect skipped due to KSN trusted 15:03:32.0599 0x0dfc ws2ifsl - ok 15:03:32.0646 0x0dfc [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc C:\Windows\System32\wscsvc.dll 15:03:32.0662 0x0dfc wscsvc - ok 15:03:32.0662 0x0dfc WSearch - ok 15:03:32.0849 0x0dfc [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll 15:03:32.0989 0x0dfc wuauserv - ok 15:03:33.0052 0x0dfc [ AC13CB789D93412106B0FB6C7EB2BCB6, 8F5B0BD0CBBAB182A400F8994D4727BC0C978D749B6429A2D41B412AE97428B6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 15:03:33.0052 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\WUDFRd.sys. md5: AC13CB789D93412106B0FB6C7EB2BCB6, sha256: 8F5B0BD0CBBAB182A400F8994D4727BC0C978D749B6429A2D41B412AE97428B6 15:03:33.0052 0x0dfc WUDFRd - detected LockedFile.Multi.Generic ( 1 ) 15:03:35.0548 0x0dfc Detect skipped due to KSN trusted 15:03:35.0548 0x0dfc WUDFRd - ok 15:03:35.0610 0x0dfc [ 575A4190D989F64732119E4114045A4F, 373C344B106AFDB1E6125A21DFE28CA6CFC77FA87FE904656A4F209DB2ED69C7 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 15:03:35.0610 0x0dfc wudfsvc - ok 15:03:35.0672 0x0dfc [ BDFA6A3A7CE1D083889B316A484A356A, 9C8B33643439D7C28ACEA0873C47301B830167F2455B53822C84FF5910330023 ] zntport C:\Windows\system32\drivers\zntport.sys 15:03:35.0672 0x0dfc Suspicious file ( NoAccess ): C:\Windows\system32\drivers\zntport.sys. md5: BDFA6A3A7CE1D083889B316A484A356A, sha256: 9C8B33643439D7C28ACEA0873C47301B830167F2455B53822C84FF5910330023 15:03:35.0688 0x0dfc zntport - detected LockedFile.Multi.Generic ( 1 ) 15:03:38.0200 0x0dfc Detect skipped due to KSN trusted 15:03:38.0200 0x0dfc zntport - ok 15:03:38.0246 0x0dfc ================ Scan global =============================== 15:03:38.0278 0x0dfc [ F31EEBC1A1C81FD04005489CC3DCDFE7, 098C35ACFCCE1686C5A6DB6057001CBF8B06A863A0802CB2E9D793F4795F8CEE ] C:\Windows\system32\basesrv.dll 15:03:38.0356 0x0dfc [ D2293B069E4B63DC17B2F08D45E71124, 615305E8B854CFAAC70378B29014517FEBDA6BB90BDC2E455B5127CD7B0AEAB3 ] C:\Windows\system32\winsrv.dll 15:03:38.0418 0x0dfc [ D2293B069E4B63DC17B2F08D45E71124, 615305E8B854CFAAC70378B29014517FEBDA6BB90BDC2E455B5127CD7B0AEAB3 ] C:\Windows\system32\winsrv.dll 15:03:38.0496 0x0dfc [ D4E6D91C1349B7BFB3599A6ADA56851B, 8748091BF27F05D28D45688E04DD9229A4B2E159209A64F457703F66A8CECE4D ] C:\Windows\system32\services.exe 15:03:38.0512 0x0dfc [ Global ] - ok 15:03:38.0512 0x0dfc ================ Scan MBR ================================== 15:03:38.0527 0x0dfc [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 15:03:39.0276 0x0dfc \Device\Harddisk0\DR0 - ok 15:03:39.0276 0x0dfc ================ Scan VBR ================================== 15:03:39.0292 0x0dfc [ 71ED979A09CAD2E5079F84CB7855E6D2 ] \Device\Harddisk0\DR0\Partition1 15:03:39.0354 0x0dfc \Device\Harddisk0\DR0\Partition1 - ok 15:03:39.0354 0x0dfc [ 06D4605E0F93371856AEC09D8E84C6E1 ] \Device\Harddisk0\DR0\Partition2 15:03:39.0354 0x0dfc \Device\Harddisk0\DR0\Partition2 - ok 15:03:39.0354 0x0dfc Waiting for KSN requests completion. In queue: 1 15:03:40.0384 0x0dfc Waiting for KSN requests completion. In queue: 1 15:03:41.0398 0x0dfc Waiting for KSN requests completion. In queue: 1 15:03:42.0490 0x0dfc AV detected via SS2: ESET NOD32 Antivirus 3.0, C:\Program Files\ESET\ESET NOD32 Antivirus\ecmd.exe ( ), 0x40000 ( disabled : updated ) 15:03:42.0505 0x0dfc Win FW state via NFP2: enabled 15:03:45.0001 0x0dfc ============================================================ 15:03:45.0001 0x0dfc Scan finished 15:03:45.0001 0x0dfc ============================================================ 15:03:45.0017 0x0df4 Detected object count: 2 15:03:45.0017 0x0df4 Actual detected object count: 2 15:05:52.0391 0x0df4 C:\Windows\System32\Drivers\2e7c80c788dd5602.sys - copied to quarantine 15:05:52.0406 0x0df4 HKLM\SYSTEM\ControlSet001\services\2e7c80c788dd5602 - will be deleted on reboot 15:05:52.0422 0x0df4 HKLM\SYSTEM\ControlSet002\services\2e7c80c788dd5602 - will be deleted on reboot 15:05:52.0438 0x0df4 C:\Windows\System32\Drivers\2e7c80c788dd5602.sys - will be deleted on reboot 15:05:52.0438 0x0df4 2e7c80c788dd5602 ( Rootkit.Win32.Necurs.gen ) - User select action: Delete 15:05:52.0453 0x0df4 SiSGbeLH ( LockedFile.Multi.Generic ) - skipped by user 15:05:52.0453 0x0df4 SiSGbeLH ( LockedFile.Multi.Generic ) - User select action: Skip 15:05:53.0108 0x0df4 KLMD registered as C:\Windows\system32\drivers\23850881.sys 15:05:56.0072 0x0a08 Deinitialize success