Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with multiple random letter exe's


  • This topic is locked This topic is locked
16 replies to this topic

#1 Queschun

Queschun

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 12:37 AM

I have weird processes running in task manager, one looks like an Intel process called "igfxmtc.exe", the others look like they are randomly named with one having multiple .exe processes running. It disabled my windows defender and doesn't let you access the folders they are from "C:\Users\Nath\AppData\Local".

 

Tried running Malwarebytes in safe mode but they are still sticking so I'm unsure what to do. I did get ahead and try to run rograms from here like rkill and adwcleaner, Can't run Combofix though cause I'm windows 8.1. I'm really trying to avoid reformatting if possible.

 

Attached Files



BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:02:58 AM

Posted 09 December 2017 - 01:30 PM

Hi

Welcome :)

I'll be helping you with your computer.

Please read this post completely before beginning. If there's anything that you do not understand, please don't hesitate to ask before proceeding.

Please take note of the guidelines for this fix:

  • Please note that I am a volunteer. I do have a family, a career, and other endeavors that may prevent immediate responses that meet your schedule. Do note that the differences in time zones could present a problem as well. Your patience and understanding will be greatly appreciated.
  • First of all, the procedures we are about to perform are specific to your problem and should only be used on this specific computer.
  • Do not make any changes to your computer that include installing/uninstalling programs, deleting files, modifying the registry, nor running scanners or tools of any kind unless specifically requested by me.
  • Please read ALL instructions carefully and perform the steps fully and in the order they are written.
  • If things appear to be better, let me know. Just because the symptoms no longer exist as before, does not mean that you are clean.
  • Continue to read and follow my instructions until I tell you that your machine is clean.
  • If you have any questions at all, please do not hesitate to ask before performing the task that I ask of you, and please wait for my reply before you proceed.
  • Scanning with programs and reading the logs do take a fair amount of time. Again, your patience will be necessary. :)

Let's begin... :)

  • Highlight the entire content of the quote box below.

Start::
CMD: fltmc instances  
CMD: Dir C:\Windows\system32\drivers\nih*.sys
Folder: C:\Windows\System32\Drivers
Reg: Reg query "HKLM\SYSTEM\Select"
C:\Users\Narth\AppData\Local\tiedcwn
C:\Users\Narth\AppData\Local\radmhvs
C:\Users\Narth\AppData\Local\igfxmtc
C:\Windows\system32\nvbkriwsvc.exe
End::

  • Right click on the highlighted text and select Copy.
  • Start FRST (FRST64) with Administrator privileges
  • Press CTRL+Y while on FRST. A document will popup. Right click and select paste on this document to copy the lines above to it.
  • Save the document and Press the Fix button.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.


Edited by JSntgRvr, 09 December 2017 - 01:34 PM.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 Queschun

Queschun
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 02:11 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 09-12-2017
Ran by Narth (09-12-2017 14:05:08) Run:1
Running from C:\Pcstuff
Loaded Profiles: Narth (Available Profiles: Narth)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CMD: fltmc instances  
CMD: Dir C:\Windows\system32\drivers\nih*.sys
Folder: C:\Windows\System32\Drivers
Reg: Reg query "HKLM\SYSTEM\Select"
C:\Users\Narth\AppData\Local\tiedcwn
C:\Users\Narth\AppData\Local\radmhvs
C:\Users\Narth\AppData\Local\igfxmtc
C:\Windows\system32\nvbkriwsvc.exe

*****************


========= fltmc instances =========

Filter                Volume Name                              Altitude        Instance Name       Frame   SprtFtrs  VlStatus
--------------------  -------------------------------------  ------------  ----------------------  -----   --------  --------
FileInfo                                                         45000     FileInfo                  0     00000003  
FileInfo              C:                                         45000     FileInfo                  0     00000003  
FileInfo              D:                                         45000     FileInfo                  0     00000003  
FileInfo              \Device\Mup                                45000     FileInfo                  0     00000003  
MBAMChameleon                                                   400900     MBAMChameleon             0     00000000  
MBAMChameleon         C:                                        400900     MBAMChameleon             0     00000000  
MBAMChameleon         D:                                        400900     MBAMChameleon             0     00000000  
MBAMChameleon         \Device\Mup                               400900     MBAMChameleon             0     00000000  
MBAMFarflt                                                      268150     MBAMFarflt                0     00000000  
MBAMFarflt            C:                                        268150     MBAMFarflt                0     00000000  
MBAMFarflt            D:                                        268150     MBAMFarflt                0     00000000  
MBAMProtection                                                  328800     MBAMProtection            0     00000000  
MBAMProtection        C:                                        328800     MBAMProtection            0     00000000  
MBAMProtection        D:                                        328800     MBAMProtection            0     00000000  
MBAMProtection        \Device\Mup                               328800     MBAMProtection            0     00000000  
SbieDrv                                                          86900     SbieDrv Instance          0     00000000  
SbieDrv               C:                                         86900     SbieDrv Instance          0     00000000  
SbieDrv               D:                                         86900     SbieDrv Instance          0     00000000  
SbieDrv               \Device\Mup                                86900     SbieDrv Instance          0     00000000  
hotascx               C:                                         45666     hotascx Instance          0     00000000  
hotascx               \Device\Mup                                45666     hotascx Instance          0     00000000  
luafv                 C:                                        135000     luafv                     0     00000003  
npsvctrig             \Device\NamedPipe                          46000     npsvctrig                 0     00000000  
udiskMgr                                                         45888     udiskMgr Instance         0     00000000  
udiskMgr              C:                                         45888     udiskMgr Instance         0     00000000  
udiskMgr              D:                                         45888     udiskMgr Instance         0     00000000  

========= End of CMD: =========


========= Dir C:\Windows\system32\drivers\nih*.sys =========

 Volume in drive C has no label.
 Volume Serial Number is B8E4-F6AC

 Directory of C:\Windows\system32\drivers

12/08/2017  11:14 PM           142,136 nihycfil.sys
               1 File(s)        142,136 bytes
               0 Dir(s)  888,706,740,224 bytes free

========= End of CMD: =========


========================= Folder: C:\Windows\System32\Drivers ========================

2013-08-22 06:38 - 2013-08-22 06:38 - 000231424 ____A [E1832BD9FD7E0FC2DC9FA5935DE3E8C1] (Microsoft Corporation) C:\Windows\System32\Drivers\1394ohci.sys
2017-12-08 20:11 - 2017-12-08 20:11 - 000255928 ____A [BDFA7A13CC73B180BBDF1ABA280E1CF7] (Malwarebytes) C:\Windows\System32\Drivers\237372E8.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000108896 ____A [AD508A1A46EC21B740AB31C28EFDFDB1] (LSI) C:\Windows\System32\Drivers\3ware.sys
2017-12-08 21:35 - 2017-12-08 21:35 - 000255928 ____A [BDFA7A13CC73B180BBDF1ABA280E1CF7] (Malwarebytes) C:\Windows\System32\Drivers\511587E8.sys
2017-12-07 06:17 - 2014-10-07 01:44 - 000533824 ____A [E796AE43DDD1844281DB4D57294D17C0] (Microsoft Corporation) C:\Windows\System32\Drivers\acpi.sys
2013-08-22 06:37 - 2013-08-22 07:49 - 000079712 ____A [AC8279D229398BCF05C3154ADCA86813] (Microsoft Corporation) C:\Windows\System32\Drivers\acpiex.sys
2013-08-22 06:39 - 2013-08-22 06:38 - 000010240 ____A [A8970D9BF23CD309E0403978A1B58F3F] (Microsoft Corporation) C:\Windows\System32\Drivers\acpipagr.sys
2013-08-22 06:39 - 2013-08-22 06:38 - 000012288 ____A [111A89C99C5B4F1A7BCE5F643DD86F65] (Microsoft Corporation) C:\Windows\System32\Drivers\acpipmi.sys
2013-08-22 06:39 - 2013-08-22 06:38 - 000010752 ____A [5758387D68A20AE7D3245011B07E36E7] (Microsoft Corporation) C:\Windows\System32\Drivers\acpitime.sys
2017-12-07 17:00 - 2014-04-27 12:40 - 000035576 ____A [561E1023BEB555A77DBEAFB83E74BA14] (Lenovo Corporation) C:\Windows\System32\Drivers\AcpiVpc.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000782176 ____A [7C1FDF1B48298CBA7CE4BDD4978951AD] (PMC-Sierra) C:\Windows\System32\Drivers\adp80xx.sys
2017-12-07 06:19 - 2015-10-13 12:10 - 000559616 ____A [A460C3AF3755A2A79A3C8EFE72E147B5] (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys
2017-12-07 06:14 - 2016-07-07 17:32 - 000095744 ____A [D5ECE7E7F349EB3C4B152AFF3577280D] (Microsoft Corporation) C:\Windows\System32\Drivers\agilevpn.sys
2013-08-22 06:39 - 2013-08-22 07:43 - 000062304 ____A [7DFAEBA9AD62D20102B576D5CAC45EC8] (Microsoft Corporation) C:\Windows\System32\Drivers\AGP440.sys
2017-12-07 06:19 - 2015-03-19 20:56 - 000080384 ____A [FE14D249D39368CA62D8DA6BC94AC694] (Microsoft Corporation) C:\Windows\System32\Drivers\ahcache.sys
2013-08-22 03:46 - 2013-08-22 03:46 - 000095744 ____A [7589DE749DB6F71A68489DCE04158729] (Microsoft Corporation) C:\Windows\System32\Drivers\amdk8.sys
2013-08-22 03:46 - 2013-08-22 03:46 - 000098816 ____A [B46D2D89AFF8A9490FA8C98C7A5616E3] (Microsoft Corporation) C:\Windows\System32\Drivers\amdppm.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000079200 ____A [D2BF2F94A47D332814910FD47C6BBCD2] (Advanced Micro Devices) C:\Windows\System32\Drivers\amdsata.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000259424 ____A [A8E04943C7BBA7219AA50400272C3C6E] (AMD Technologies Inc.) C:\Windows\System32\Drivers\amdsbs.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000025952 ____A [CEA5F4F27CFC08E3A44D576811B35F50] (Advanced Micro Devices) C:\Windows\System32\Drivers\amdxata.sys
2017-12-07 17:05 - 2015-07-23 08:06 - 000031016 ____A [724064DF549D5AFCD3DB381EA2C0FE70] (Alps Electric Co., Ltd.) C:\Windows\System32\Drivers\Apkbfiltr.sys
2017-12-07 06:16 - 2014-10-28 21:46 - 000082944 ____A [415DD71628795197F7AFC176CBADC74E] (Microsoft Corporation) C:\Windows\System32\Drivers\appid.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000114016 ____A [65045784366F7EC5FB4E71BCF923187B] (PMC-Sierra, Inc.) C:\Windows\System32\Drivers\arcsas.sys
2013-08-22 06:39 - 2013-08-22 06:38 - 000026624 ____A [3DB7721F06BC2FEDB25029EA23AB27DA] (Microsoft Corporation) C:\Windows\System32\Drivers\asyncmac.sys
2013-08-22 07:22 - 2013-08-22 07:43 - 000026464 ____A [74B14192CF79A72F7536B27CB8814FBD] (Microsoft Corporation) C:\Windows\System32\Drivers\atapi.sys
2013-08-22 07:22 - 2013-08-22 07:43 - 000199520 ____A [38E1F4E0148A24C65D215F14D57B0711] (Microsoft Corporation) C:\Windows\System32\Drivers\ataport.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000050688 ____A [8CC7F7E4AFCBA605921B137ED7992C68] (Microsoft Corporation) C:\Windows\System32\Drivers\BasicDisplay.sys
2017-12-07 06:26 - 2017-11-08 10:55 - 000032256 ____A [BF002CF6CA41491665F7D3DCA51B7EFB] (Microsoft Corporation) C:\Windows\System32\Drivers\BasicRender.sys
2013-08-22 06:40 - 2013-08-22 07:49 - 000035168 ____A [99387C515F80270F097F6DD9B5315649] (Microsoft Corporation) C:\Windows\System32\Drivers\battc.sys
2015-06-03 00:09 - 2015-09-28 13:08 - 000172376 ____A [09391BA416AA29682298A612FDFDD7B8] (Sysprogs OU) C:\Windows\System32\Drivers\BazisVirtualCDBus.sys
2017-12-07 16:59 - 2017-03-30 15:42 - 000187680 ____A [2B5D8955C1BD113EECE603CE82DA6D0D] (Broadcom Corporation.) C:\Windows\System32\Drivers\bcbtums.sys
2017-12-07 16:59 - 2017-03-30 12:38 - 000070201 ____A [40265CC99398F11459F250D9156046FC] () C:\Windows\System32\Drivers\BCM20702A1_001.002.014.1483.1651.hex
2013-08-22 01:57 - 2013-08-12 18:25 - 000017624 ____A [C1ABB0F7E3BEA48A0417BDF6FF14AB21] (Windows ® Win 7 DDK provider) C:\Windows\System32\Drivers\bcmfn2.sys
2017-12-07 17:08 - 2015-06-03 15:18 - 010491152 ____A [FE7AA77D936351E119A51CCEDE316AB2] (Broadcom Corporation) C:\Windows\System32\Drivers\BCMWL63a.SYS
2013-08-22 06:40 - 2013-08-22 06:40 - 000007680 ____A [EC19013E4CF87609534165DF897274D6] (Microsoft Corporation) C:\Windows\System32\Drivers\beep.sys
2017-12-07 06:26 - 2016-10-04 15:39 - 000101376 ____A [4938A9236300A356F97E378491EE4844] (Microsoft Corporation) C:\Windows\System32\Drivers\bowser.sys
2017-12-07 06:16 - 2014-10-28 21:45 - 000115712 ____A [F3C060444777A59FC63D920719E43CCD] (Microsoft Corporation) C:\Windows\System32\Drivers\bridge.sys
2017-12-07 05:20 - 2013-11-23 02:13 - 000019456 ____A [1C89EF529DB7DCA98E801EFDCC8437DE] (Microsoft Corporation) C:\Windows\System32\Drivers\BtaMPM.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000036992 ____A [A8F23D453A424FF4DE04989C4727ECC7] (Microsoft Corporation) C:\Windows\System32\Drivers\BthAvrcpTg.sys
2017-12-07 06:23 - 2015-06-09 17:39 - 000053248 ____A [12418846B057E4F92FC621F5C6CF737D] (Microsoft Corporation) C:\Windows\System32\Drivers\bthenum.sys
2017-12-07 06:21 - 2015-03-08 21:02 - 000057856 ____A [272A62B660A48AEF366F8A1836CED19F] (Microsoft Corporation) C:\Windows\System32\Drivers\bthhfenum.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000030720 ____A [71FE2A48E4C93DDB9798C024880B6C07] (Microsoft Corporation) C:\Windows\System32\Drivers\BthhfHid.sys
2017-12-07 05:47 - 2013-12-04 13:41 - 000226304 ____A [D30C67473A2E229662D21F27EAA9AAA5] (Microsoft Corporation) C:\Windows\System32\Drivers\BthLEEnum.sys
2013-08-22 06:36 - 2013-08-22 06:36 - 000063488 ____A [07E33226AD218A2A162662A05CAFB52F] (Microsoft Corporation) C:\Windows\System32\Drivers\bthmodem.sys
2017-12-07 06:26 - 2017-07-06 03:52 - 000119296 ____A [D0AF91AF656E25AD8617EFA5B52EF457] (Microsoft Corporation) C:\Windows\System32\Drivers\bthpan.sys
2017-12-07 06:23 - 2015-06-09 17:38 - 001201664 ____A [B810B2B39CCA90DC6BF42AF1658AE0D1] (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2017-12-07 06:23 - 2015-06-09 17:39 - 000081920 ____A [52A1B7ECAB4C9EF70FD41241691E09D3] (Microsoft Corporation) C:\Windows\System32\Drivers\BTHUSB.SYS
2017-12-07 16:59 - 2017-03-30 15:42 - 000195872 ____A [D7D86DA792D9A39F1D84F191A88E6659] (Broadcom Corporation.) C:\Windows\System32\Drivers\btwampfl.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000531296 ____A [A4A73F631FE2AA2826FBE4A399B04DEF] (Broadcom Corporation) C:\Windows\System32\Drivers\bxvbda.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000088576 ____A [2FA6510E33F7DEFEC03658B74101A9B9] (Microsoft Corporation) C:\Windows\System32\Drivers\cdfs.sys
2013-08-22 03:46 - 2013-08-22 03:46 - 000164352 ____A [C6796EA22B513E3457514D92DCDB1A3D] (Microsoft Corporation) C:\Windows\System32\Drivers\cdrom.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000044032 ____A [BE9936EDD3267FAAFF94A7835867F00B] (Microsoft Corporation) C:\Windows\System32\Drivers\circlass.sys
2017-12-07 06:15 - 2016-05-06 16:59 - 000331608 ____A [F9ED4FFE6EBAC59F564323848974C3B4] (Microsoft Corporation) C:\Windows\System32\Drivers\Classpnp.sys
2017-12-07 06:27 - 2017-07-08 15:14 - 000376672 ____A [39D72BA91AFE3C81C1AB0DE41AA07EF3] (Microsoft Corporation) C:\Windows\System32\Drivers\clfs.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000025472 ____A [EF6EF85DADC3184A10D8F2F7159973CB] (Microsoft Corporation) C:\Windows\System32\Drivers\CmBatt.sys
2017-12-07 06:27 - 2016-10-10 13:18 - 000022360 ____A [53517BC5BC4DD8B1FC860300A193E992] (Microsoft Corporation) C:\Windows\System32\Drivers\cmimcext.sys
2017-12-07 06:27 - 2017-01-21 16:37 - 000567152 ____A [C8823A6ECE66B997C8E9F413D1D671E7] (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-08-22 06:39 - 2013-08-22 06:38 - 000036352 ____A [03AAED827C36F35D70900558B8274905] (Microsoft Corporation) C:\Windows\System32\Drivers\CompositeBus.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000043008 ____A [A1FF7DFBFBE164CF92603C651D304DD2] (Microsoft Corporation) C:\Windows\System32\Drivers\condrv.sys
2013-08-22 06:40 - 2013-08-22 07:43 - 000068960 ____A [FA47B0AA255B7CF4519E995C6404AE22] (Microsoft Corporation) C:\Windows\System32\Drivers\crashdmp.sys
2017-12-07 06:27 - 2017-01-21 14:22 - 000559104 ____A [4C23917A28A50F59588EEF109ECDCBA4] (Microsoft Corporation) C:\Windows\System32\Drivers\csc.sys
2017-12-07 06:27 - 2014-11-04 14:33 - 000058176 ____A [389C998C64319CD97625B0550E52ECFA] (Microsoft Corporation) C:\Windows\System32\Drivers\dam.sys
2017-12-04 20:06 - 2017-12-04 20:06 - 000045640 ____A [FCC89FED34A5FD03B27A2B577A40ACF8] (Dropbox, Inc.) C:\Windows\System32\Drivers\dbx-canary.sys
2017-12-04 20:06 - 2017-12-04 20:06 - 000045672 ____A [728BE4B36BA453779AEC6459DDDB320B] (Dropbox, Inc.) C:\Windows\System32\Drivers\dbx-dev.sys
2017-12-04 20:06 - 2017-12-04 20:06 - 000045640 ____A [FCC89FED34A5FD03B27A2B577A40ACF8] (Dropbox, Inc.) C:\Windows\System32\Drivers\dbx-stable.sys
2017-12-07 06:26 - 2017-01-10 17:37 - 000138752 ____A [4FED6AD69C9EE1EE7FD3C88437138855] (Microsoft Corporation) C:\Windows\System32\Drivers\dfsc.sys
2017-12-07 06:26 - 2017-07-07 22:14 - 000100184 ____A [BF6D8575DDF30384939B2D5251F27C1F] (Microsoft Corporation) C:\Windows\System32\Drivers\disk.sys
2013-08-22 06:40 - 2013-08-22 07:43 - 000036192 ____A [224C2CB37497472C345CB2A02DF11363] (Microsoft Corporation) C:\Windows\System32\Drivers\Diskdump.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000013312 ____A [407B4FC1AEE5C19AC2ED7118CBB271E9] (Microsoft Corporation) C:\Windows\System32\Drivers\Dmpusbstor.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000029696 ____A [EB70A894708D1BC176AFD690FF06085F] (Microsoft Corporation) C:\Windows\System32\Drivers\dmvsc.sys
2017-12-07 06:16 - 2014-10-28 21:47 - 000089088 ____A [F00B189ECA74DDF408AD934ADDC72477] (Microsoft Corporation) C:\Windows\System32\Drivers\drmk.sys
2017-12-07 06:18 - 2014-10-28 22:58 - 000014528 ____A [00C594D5A1DBD22AD8B2902B9F6EFF94] (Microsoft Corporation) C:\Windows\System32\Drivers\drmkaud.sys
2013-08-22 06:39 - 2013-08-22 07:39 - 000033632 ____A [05F5C162881BE293956C60456EDB0092] (Microsoft Corporation) C:\Windows\System32\Drivers\Dumpata.sys
2017-12-07 06:15 - 2016-06-18 15:06 - 000072408 ____A [C5196B53CA2F8FC637D20DEC386CFBE2] (Microsoft Corporation) C:\Windows\System32\Drivers\dumpfve.sys
2017-12-07 06:14 - 2015-03-12 23:03 - 000154432 ____A [95E295FD19F80B3AD33629B5AEFEC9C7] (Microsoft Corporation) C:\Windows\System32\Drivers\dumpsd.sys
2017-12-07 06:27 - 2017-10-14 08:04 - 001548624 ____A [670E7F15CEEA22C34CED8F4D0EC161BF] (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2017-12-07 06:27 - 2017-04-09 17:00 - 000388448 ____A [0711E11DF676BC41B641ED31F9772517] (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-08-22 06:38 - 2013-08-22 07:43 - 000082784 ____A [43531A5993380CC5113242C29D265FD9] (Microsoft Corporation) C:\Windows\System32\Drivers\EhStorClass.sys
2013-08-22 06:37 - 2013-08-22 07:43 - 000114016 ____A [6F8E738A9505A388B1157FDDE7B3101B] (Microsoft Corporation) C:\Windows\System32\Drivers\EhStorTcgDrv.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000010240 ____A [DFFFAE1442BA4076E18EED5E406FA0D3] (Microsoft Corporation) C:\Windows\System32\Drivers\errdev.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 003357024 ____A [114BCFDF367FF37C3F1B0A96AF542E4D] (Broadcom Corporation) C:\Windows\System32\Drivers\evbda.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000200704 ____A [7729D294A555C7AEB281ED8E4D0E01E4] (Microsoft Corporation) C:\Windows\System32\Drivers\exfat.sys
2017-12-08 19:52 - 2017-12-08 23:16 - 000110016 ____A [20046A5DB1466EBD0DCAEB84D00C5432] (Malwarebytes) C:\Windows\System32\Drivers\farflt.sys
2013-08-22 06:40 - 2013-08-22 07:49 - 000217952 ____A [7C4E0D5900B2A1D11EDD626D6DDB937B] (Microsoft Corporation) C:\Windows\System32\Drivers\fastfat.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000030720 ____A [5D8402613E778B3BD45E687A8372710B] (Microsoft Corporation) C:\Windows\System32\Drivers\fdc.sys
2017-12-07 05:47 - 2014-02-22 11:00 - 000079192 ____A [BCFD8B149B3ADF92D0DB1E909CAF0265] (Microsoft Corporation) C:\Windows\System32\Drivers\fileinfo.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000034816 ____A [A1A66C4FDAFD6B0289523232AFB7D8AF] (Microsoft Corporation) C:\Windows\System32\Drivers\filetrace.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000025088 ____A [BE743083CF7063C486A4398E3AEFE59A] (Microsoft Corporation) C:\Windows\System32\Drivers\flpydisk.sys
2017-12-07 06:16 - 2014-08-25 22:30 - 000354112 ____A [C1FB505A73FA2E9019D32444AB33B75A] (Microsoft Corporation) C:\Windows\System32\Drivers\fltMgr.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000030048 ____A [09F460AFEDCA03F3BF6E07D1CCC9AC42] (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys
2017-12-07 06:16 - 2014-10-15 03:32 - 000061248 ____A [A7C31B168F371E8E6796219F23E354DB] (Microsoft Corporation) C:\Windows\System32\Drivers\fsdepends.sys
2017-12-07 06:15 - 2016-06-18 15:06 - 000590688 ____A [D4AB6EE3D715BC44C00277FD934FAACF] (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys
2017-12-07 06:26 - 2017-06-06 23:25 - 000428888 ____A [2AA78D58E9EEA2D2F04CC3EB6817B0D4] (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2013-08-22 03:46 - 2013-08-22 03:46 - 000027136 ____A [9591D0B9351ED489EAFD9D1CE52A8015] (Microsoft Corporation) C:\Windows\System32\Drivers\fxppm.sys
2013-08-22 06:39 - 2013-08-22 07:43 - 000065888 ____A [FC3EF65EE20D39F8749C2218DBA681CA] (Microsoft Corporation) C:\Windows\System32\Drivers\GAGP30KX.SYS
2013-08-22 02:51 - 2013-06-18 09:41 - 003440660 ____A [7F29903CB8F5590D52DB0C9F97049A25] () C:\Windows\System32\Drivers\gm.dls
2013-08-22 02:51 - 2013-06-18 09:41 - 000000646 ____A [7111BFA692A22E4B3C07F1E6C6FF6F72] () C:\Windows\System32\Drivers\gmreadme.txt
2017-12-07 06:16 - 2014-07-24 06:45 - 000076800 ____A [D4B7ED39C7900384D9E5C1283F1E7926] (Microsoft Corporation) C:\Windows\System32\Drivers\hdaudbus.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000395776 ____A [56F69F7C25FB67C970997D7066DBC593] (Microsoft Corporation) C:\Windows\System32\Drivers\HdAudio.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000026624 ____A [10A70BC1871CD955D85CD88372724906] (Microsoft Corporation) C:\Windows\System32\Drivers\hidbatt.sys
2017-12-07 06:15 - 2015-01-29 22:01 - 000097792 ____A [42F88B57CAE42FC10059C887B3FCFCEA] (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2017-12-07 06:15 - 2016-05-13 18:08 - 000111616 ____A [177D76B32D417537FAADFF90237A508B] (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000041472 ____A [C241A8BAFBBFC90176EA0F5240EACC17] (Microsoft Corporation) C:\Windows\System32\Drivers\hidi2c.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000045568 ____A [9BDDEE26255421017E161CCB9D5EDA95] (Microsoft Corporation) C:\Windows\System32\Drivers\hidir.sys
2017-12-07 06:15 - 2016-05-13 18:08 - 000032512 ____A [24E6C1F418BACEE4E7D18266F48FF2EA] (Microsoft Corporation) C:\Windows\System32\Drivers\hidparse.sys
2017-12-07 06:15 - 2016-05-13 18:08 - 000032768 ____A [49676FEC898AB2A11B157F848269A56E] (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000064352 ____A [A6AACEA4C785789BDA5912AD1FEDA80D] (Hewlett-Packard Company) C:\Windows\System32\Drivers\HpSAMD.sys
2017-12-07 06:27 - 2017-09-14 18:52 - 000986968 ____A [0821D9404151398E43B794828DFBFB07] (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-08-22 06:40 - 2013-08-22 07:39 - 000024416 ____A [90656C0B3864804B090434EFC582404F] (Microsoft Corporation) C:\Windows\System32\Drivers\hwpolicy.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000013824 ____A [6D6F9E3BF0484967E52F7E846BFF1CA1] (Microsoft Corporation) C:\Windows\System32\Drivers\hyperkbd.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000022016 ____A [907C870F8C31F8DDD6F090857B46AB25] (Microsoft Corporation) C:\Windows\System32\Drivers\HyperVideo.sys
2017-12-07 06:27 - 2014-11-04 01:54 - 000108544 ____A [49EE0AE9E5B64FFBBD06D55C4984B598] (Microsoft Corporation) C:\Windows\System32\Drivers\i8042prt.sys
2013-08-22 01:57 - 2013-07-30 13:47 - 000024568 ____A [5D90E32E36CE5D4C535D17CE08AEAF05] (Intel Corporation) C:\Windows\System32\Drivers\iaLPSSi_GPIO.sys
2013-08-22 01:57 - 2013-07-25 14:05 - 000099320 ____A [DD05E7E80F52ADE9AEB292819920F32C] (Intel Corporation) C:\Windows\System32\Drivers\iaLPSSi_I2C.sys
2017-12-07 17:01 - 2017-04-19 11:59 - 001469952 ____A [350735A5E5B1EB6C733F8D3E01545E3D] (Intel Corporation) C:\Windows\System32\Drivers\iaStorA.sys
2013-08-22 02:01 - 2013-08-09 19:39 - 000651248 ____A [08BFE413B0B4AA8DFA4B5684CE06D3DC] (Intel Corporation) C:\Windows\System32\Drivers\iaStorAV.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000412000 ____A [A2200C3033FA4EF249FC096A7A7D02A2] (Intel Corporation) C:\Windows\System32\Drivers\iaStorV.sys
2017-12-07 17:00 - 2017-05-08 06:39 - 000038480 ____A [1C3C0E8045D1F5BE43B4B37DCEC230A6] (Intel Corporation) C:\Windows\System32\Drivers\ICCWDT.sys
2017-12-07 17:07 - 2017-01-13 05:26 - 004935152 ____A [DB612DDA2E9643F8C759E68DAE07F2D4] (Intel Corporation) C:\Windows\System32\Drivers\igdkmd64.sys
2017-12-07 17:01 - 2017-07-09 15:25 - 000480800 ____A [3B7A082F5D593663164F7540D42CCED3] (Intel® Corporation) C:\Windows\System32\Drivers\IntcDAud.sys
2015-05-26 11:28 - 2015-11-17 12:39 - 000051704 ____A [ED5DC915D50A0E9FCB620772EB37727A] (Intel Corporation) C:\Windows\System32\Drivers\intelaud.sys
2013-08-22 07:22 - 2013-08-22 07:43 - 000018272 ____A [4E448FCFFD00E8D657CD9E48D3E47157] (Microsoft Corporation) C:\Windows\System32\Drivers\intelide.sys
2017-12-07 06:27 - 2014-10-16 23:56 - 000039744 ____A [7AA01AB1C110916825E6E1389F1B9AF2] (Microsoft Corporation) C:\Windows\System32\Drivers\intelpep.sys
2013-08-22 03:46 - 2013-08-22 03:46 - 000098816 ____A [47E74A8E53C7C24DCE38311E1451C1D9] (Microsoft Corporation) C:\Windows\System32\Drivers\intelppm.sys
2013-08-22 06:35 - 2013-08-22 06:35 - 000084992 ____A [9DB76D7F9E4E53EFE5DD8C53DE837514] (Microsoft Corporation) C:\Windows\System32\Drivers\ipfltdrv.sys
2017-12-07 06:15 - 2016-02-03 10:14 - 000080896 ____A [C800DCD904016B2BF6AB541083770A3A] (Microsoft Corporation) C:\Windows\System32\Drivers\IPMIDrv.sys
2017-12-07 05:20 - 2013-11-27 07:02 - 000142848 ____A [B7342B3C58E91107F6E946A93D9D4EFD] (Microsoft Corporation) C:\Windows\System32\Drivers\ipnat.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000118784 ____A [D826F4874A372FAE2F42478E0975EA02] (Microsoft Corporation) C:\Windows\System32\Drivers\irda.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000017920 ____A [AE44C526AB5F8A487D941CEB57B10C97] (Microsoft Corporation) C:\Windows\System32\Drivers\irenum.sys
2013-08-22 06:40 - 2013-08-22 07:43 - 000021856 ____A [8AFEEA3955AA43616A60F133B1D25F21] (Microsoft Corporation) C:\Windows\System32\Drivers\isapnp.sys
2015-05-26 11:28 - 2015-11-17 12:39 - 000039920 ____A [D3C5C896816AB22C7D5EEB17F638AEAE] (Intel Corporation) C:\Windows\System32\Drivers\iwdbus.sys
2017-12-07 06:27 - 2014-11-04 14:25 - 000059712 ____A [5917AFE4A3F695A54B99C1849C8207FE] (Microsoft Corporation) C:\Windows\System32\Drivers\kbdclass.sys
2017-12-07 06:27 - 2014-11-04 01:54 - 000032256 ____A [8CD840A062F6BDF41DDE3ACB96164B72] (Microsoft Corporation) C:\Windows\System32\Drivers\kbdhid.sys
2013-09-29 22:54 - 2013-09-29 22:54 - 000022272 ____A [DB7A09BC90DF20F44F16F8B0F9ED3491] (Microsoft Corporation) C:\Windows\System32\Drivers\kbldfltr.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000019456 ____A [813871C7D402A05F2E3A7075F9584A05] (Microsoft Corporation) C:\Windows\System32\Drivers\kdnic.sys
2017-12-07 06:16 - 2014-07-04 07:59 - 000295424 ____A [1DD05F4857C2188744B9E864658949DD] (Microsoft Corporation) C:\Windows\System32\Drivers\ks.sys
2017-12-07 06:14 - 2016-08-22 11:06 - 000100184 ____A [304DA394D958BC3B62AF6DF514005B01] (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2017-12-07 06:14 - 2016-05-18 18:16 - 000178016 ____A [3D4AE520CD6F6FFE549DD195C1F515BE] (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000021248 ____A [11AFB527AA370B1DAFD5C36F35F6D45F] (Microsoft Corporation) C:\Windows\System32\Drivers\ksthunk.sys
2013-08-22 06:36 - 2013-08-22 06:36 - 000059392 ____A [C09010B3680860131631F53E8FE7BAD8] (Microsoft Corporation) C:\Windows\System32\Drivers\lltdio.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000109408 ____A [C755AE4635457AA2A11F79C0DF857ABC] (LSI Corporation) C:\Windows\System32\Drivers\lsi_sas.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000093536 ____A [ADAC09CBE7A2040B7F68B5E5C9A75141] (LSI Corporation) C:\Windows\System32\Drivers\lsi_sas2.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000081760 ____A [04D1274BB9BBCCF12BD12374002AA191] (LSI Corporation) C:\Windows\System32\Drivers\lsi_sas3.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000082784 ____A [327469EEF3833D0C584B7E88A76AEC0C] (LSI Corporation) C:\Windows\System32\Drivers\lsi_sss.sys
2017-12-07 06:26 - 2017-10-10 11:36 - 000124416 ____A [B0AF753AF28303BB69C67BD85F06FFC9] (Microsoft Corporation) C:\Windows\System32\Drivers\luafv.sys
2017-12-08 19:52 - 2017-11-29 09:11 - 000077432 ____A [680AF1647150CF9B061FF40E71C7396A] () C:\Windows\System32\Drivers\mbae64.sys
2017-12-08 19:52 - 2017-12-08 23:16 - 000046008 ____A [29BD0BB2CD7E37B8C248CFA933FBD1F4] (Malwarebytes) C:\Windows\System32\Drivers\mbam.sys
2017-12-08 21:33 - 2017-12-08 21:33 - 000193968 ____A [5C3083CDE45F25797F6B4310BF916394] (Malwarebytes) C:\Windows\System32\Drivers\MbamChameleon.sys
2017-12-08 21:33 - 2017-12-08 21:50 - 000253880 ____A [B047B9CE5A0D800E6D713B43D0405221] (Malwarebytes) C:\Windows\System32\Drivers\mbamswissarmy.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000022016 ____A [C895E3FAE8628EAA4ADE0F52862CA575] (Microsoft Corporation) C:\Windows\System32\Drivers\mcd.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000056672 ____A [EB5C03A070F30D64A6DF80E53B22F53F] (LSI Corporation) C:\Windows\System32\Drivers\megasas.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000575840 ____A [F6F13533196DE7A582D422B0241E4363] (LSI Corporation, Inc.) C:\Windows\System32\Drivers\megasr.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000040960 ____A [8B38C44F69259987C95135C9627E2378] (Microsoft Corporation) C:\Windows\System32\Drivers\modem.sys
2013-08-22 06:36 - 2013-08-22 06:36 - 000030208 ____A [601589000CC90F0DF8DA2CC254A3CCC9] (Microsoft Corporation) C:\Windows\System32\Drivers\monitor.sys
2017-12-07 06:27 - 2014-11-04 14:25 - 000051008 ____A [08374E4E5B8914DE6067CBA99F61E930] (Microsoft Corporation) C:\Windows\System32\Drivers\mouclass.sys
2017-12-07 06:27 - 2014-11-04 01:54 - 000030208 ____A [5FCBAB60598AE119E02B4C27DE6B99EA] (Microsoft Corporation) C:\Windows\System32\Drivers\mouhid.sys
2017-12-07 06:26 - 2017-05-10 13:19 - 000101720 ____A [E5E8665272EBCD87A0A632314F0D221D] (Microsoft Corporation) C:\Windows\System32\Drivers\mountmgr.sys
2017-12-07 06:16 - 2014-10-28 21:45 - 000074240 ____A [6FC047578785B0435F4E2660946D1ADC] (Microsoft Corporation) C:\Windows\System32\Drivers\mpsdrv.sys
2017-12-07 06:26 - 2016-09-08 09:00 - 000140800 ____A [3F818C1518DA702C8F10259095C9BDE0] (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2017-12-07 06:27 - 2017-02-01 14:42 - 000401408 ____A [E2FC654EC895E92A022794329BFC53EC] (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2017-12-07 06:26 - 2017-09-07 16:32 - 000285184 ____A [AFE6DC2E57E876175BA074AD2CB5594F] (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2017-12-07 06:27 - 2017-02-01 14:44 - 000201728 ____A [B37B58F9F80A51098C42663D5FA5F2BA] (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000030208 ____A [D13329FBF8345B28AB30F44CC247DC08] (Microsoft Corporation) C:\Windows\System32\Drivers\msfs.sys
2017-12-07 17:06 - 2017-12-07 17:06 - 000000000 ___AH [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2017-12-07 17:06 - 2017-12-07 17:06 - 000000000 ___AH [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2017-12-08 00:22 - 2017-12-08 00:22 - 000000000 ___AH [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-08-22 06:39 - 2013-06-18 09:52 - 000000003 ____A [933222B19FF3E7EA5F65517EA1F7D57E] () C:\Windows\System32\Drivers\MsftWdf_Kernel_01013_Inbox_Critical.Wdf
2013-08-22 06:49 - 2013-06-18 10:20 - 000000003 ____A [933222B19FF3E7EA5F65517EA1F7D57E] () C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2017-12-07 06:16 - 2014-08-14 19:36 - 000146752 ____A [8DF1254093B5C354CE725EB6B9B0DE19] (Microsoft Corporation) C:\Windows\System32\Drivers\msgpioclx.sys
2013-08-22 06:38 - 2013-08-22 07:43 - 000041824 ____A [C6B474E46F9E543B875981ED3FFE6ADD] (Microsoft Corporation) C:\Windows\System32\Drivers\msgpiowin32.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000008192 ____A [65C92EB9D08DB5C69F28C7FFD4E84E31] (Microsoft Corporation) C:\Windows\System32\Drivers\mshidkmdf.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000009728 ____A [52299F086AC2DAFD100DD5DC4A8614BA] (Microsoft Corporation) C:\Windows\System32\Drivers\mshidumdf.sys
2013-08-22 06:39 - 2013-08-22 07:43 - 000017248 ____A [36D92AF3343C3A3E57FEF11C449AEA4C] (Microsoft Corporation) C:\Windows\System32\Drivers\msisadrv.sys
2017-12-07 06:26 - 2017-06-11 19:14 - 000276320 ____A [C378ED678D1316721A40E1F60FB76184] (Microsoft Corporation) C:\Windows\System32\Drivers\msiscsi.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000010624 ____A [A9BBBD2BAE6142253B9195E949AC2E8D] (Microsoft Corporation) C:\Windows\System32\Drivers\mskssrv.sys
2017-12-07 06:16 - 2014-10-28 21:45 - 000066560 ____A [51B3AC0560848CD6D65AC2033E293113] (Microsoft Corporation) C:\Windows\System32\Drivers\mslldp.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000007040 ____A [7B2128EB875DCBC006E6A913211006D6] (Microsoft Corporation) C:\Windows\System32\Drivers\mspclock.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000006784 ____A [1E88171579B218115C7A772F8DE04BD8] (Microsoft Corporation) C:\Windows\System32\Drivers\mspqm.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000366432 ____A [BBE2A455053E63BECBF42C2F9B21FAE0] (Microsoft Corporation) C:\Windows\System32\Drivers\msrpc.sys
2013-08-22 06:39 - 2013-08-22 07:49 - 000037728 ____A [8D6B7D515C5CBCDB75B928A0B73C3C5E] (Microsoft Corporation) C:\Windows\System32\Drivers\mssmbios.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000007936 ____A [115019AE01E0EB9C048530D2928AB4A2] (Microsoft Corporation) C:\Windows\System32\Drivers\mstee.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000013312 ____A [96D604A35070360F0DD4A7A8AF410B5E] (Microsoft Corporation) C:\Windows\System32\Drivers\MTConfig.sys
2017-12-07 06:15 - 2016-04-06 16:21 - 000114528 ____A [438EA7A2D8D4F9B8AFB64748ACA70BA8] (Microsoft Corporation) C:\Windows\System32\Drivers\mup.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000063840 ____A [B8C35C94DCB2DFEAF03BB42131F2F77F] (Marvell Semiconductor, Inc.) C:\Windows\System32\Drivers\mvumis.sys
2017-12-08 19:52 - 2017-12-08 20:44 - 000094144 ____A [482F6D603BDCC825768D86D8228BD65F] (Malwarebytes) C:\Windows\System32\Drivers\mwac.sys
2017-12-07 06:27 - 2017-01-18 21:18 - 001113944 ____A [FFAA6C6E798FBA448FA7628A1B277F5C] (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2017-12-07 06:16 - 2014-10-28 21:46 - 000043008 ____A [8CECC8DA55F3274181FD1EA28AD76664] (Microsoft Corporation) C:\Windows\System32\Drivers\ndiscap.sys
2017-12-07 06:16 - 2014-10-28 21:45 - 000126464 ____A [269882812E9A68FFF1AFE1283D428322] (Microsoft Corporation) C:\Windows\System32\Drivers\NdisImPlatform.sys
2017-12-07 06:27 - 2014-11-07 23:00 - 000024576 ____A [DC1D9F692C2AD84C214584C28501C1F7] (Microsoft Corporation) C:\Windows\System32\Drivers\ndistapi.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000060416 ____A [B832B35055BA2B7B4181861FF94D8E59] (Microsoft Corporation) C:\Windows\System32\Drivers\ndisuio.sys
2013-08-22 06:36 - 2013-08-22 06:36 - 000016384 ____A [1F58E48EF75F34C35D8E93A0DC535CFE] (Microsoft Corporation) C:\Windows\System32\Drivers\NdisVirtualBus.sys
2017-12-07 06:15 - 2016-04-05 17:37 - 000205824 ____A [C3755FCF9A0B5C6FE8ED9E873B85D3CE] (Microsoft Corporation) C:\Windows\System32\Drivers\ndiswan.sys
2017-12-07 06:27 - 2014-11-07 23:00 - 000072192 ____A [0BBE2FA30BAD58C9ADC01E4F84A3D2A1] (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2017-12-07 06:16 - 2014-10-28 21:45 - 000103424 ____A [3083926D1CC5B56EA0786527B557DD1B] (Microsoft Corporation) C:\Windows\System32\Drivers\Ndu.sys
2017-12-07 06:16 - 2014-10-28 21:47 - 000048128 ____A [42FF4975D032CAE558AE4BB8448F6E5A] (Microsoft Corporation) C:\Windows\System32\Drivers\netbios.sys
2017-12-07 06:26 - 2017-08-10 22:27 - 000281600 ____A [0FE750800DEEE91D22399D081371BA79] (Microsoft Corporation) C:\Windows\System32\Drivers\netbt.sys
2017-12-07 06:27 - 2017-05-31 16:20 - 000470360 ____A [D8BBF2E779040E5BCBA68E08A9F52734] (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2017-12-07 06:16 - 2014-10-28 21:46 - 000087040 ____A [D4DCE03870314D3354F3501F9DDD4123] (Microsoft Corporation) C:\Windows\System32\Drivers\netvsc63.sys
2017-12-08 23:14 - 2017-12-08 23:14 - 000142136 ____N [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\nihycfil.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000058880 ____A [8F44A2F57C9F1A19AC9C6288C10FB351] (Microsoft Corporation) C:\Windows\System32\Drivers\npfs.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000023040 ____A [CBDB4F0871C88DF930FC0E8588CA67FC] (Microsoft Corporation) C:\Windows\System32\Drivers\npsvctrig.sys
2017-12-07 06:26 - 2017-08-13 12:19 - 000040960 ____A [018510D88536798852DAE12F9BA6E138] (Microsoft Corporation) C:\Windows\System32\Drivers\nsiproxy.sys
2017-12-07 06:27 - 2017-10-16 13:38 - 002013016 ____A [9907FCC207E470F94B9DB6BD037E79C4] (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000005632 ____A [EF1B290FC9F0E47CC0B537292BEE5904] (Microsoft Corporation) C:\Windows\System32\Drivers\null.sys
2013-08-22 06:39 - 2013-08-22 07:43 - 000124768 ____A [6934A936A7369DFE37B7DBA93F5E5E49] (Microsoft Corporation) C:\Windows\System32\Drivers\NV_AGP.SYS
2017-01-25 19:39 - 2017-01-25 19:39 - 014073400 ____A [62D9FB323C93ADD0DAAD5EB4890B7CED] (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000150368 ____A [BC6B5942AFF25EBAF62DE43C3807EDF8] (NVIDIA Corporation) C:\Windows\System32\Drivers\nvraid.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000168288 ____A [1F43ABFFAC3D6CA356851D517392966E] (NVIDIA Corporation) C:\Windows\System32\Drivers\nvstor.sys
2017-12-07 06:27 - 2017-09-13 08:32 - 000445952 ____A [BB78990894F14D725EBD301E1945BF0F] (Microsoft Corporation) C:\Windows\System32\Drivers\nwifi.sys
2017-12-07 06:16 - 2014-10-28 21:45 - 000151040 ____A [FC0141B4A5AD6D637D883C1A89FC45C5] (Microsoft Corporation) C:\Windows\System32\Drivers\pacer.sys
2017-12-07 06:26 - 2016-08-11 13:33 - 000096256 ____A [57DCE4FB0467986AE78E1C6FC5240D32] (Microsoft Corporation) C:\Windows\System32\Drivers\parport.sys
2017-12-07 06:16 - 2014-10-15 03:32 - 000088896 ____A [BAFF6122CFC9F95CA175AD8C348179A4] (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2017-12-07 06:16 - 2014-07-24 10:28 - 000280384 ____A [91ED124E261EA8FAA1C0FFDF2A71B0C4] (Microsoft Corporation) C:\Windows\System32\Drivers\pci.sys
2013-08-22 07:22 - 2013-08-22 07:43 - 000014688 ____A [346E38FCC6859A727DD28AFAD1F0AFF4] (Microsoft Corporation) C:\Windows\System32\Drivers\pciide.sys
2013-08-22 07:22 - 2013-08-22 07:43 - 000048992 ____A [5D4D6146346B82EB3CA4EE0C5573193C] (Microsoft Corporation) C:\Windows\System32\Drivers\pciidex.sys
2013-08-22 06:40 - 2013-08-22 07:49 - 000114528 ____A [4D3BDCC1C7B40C9D7B6AD990E6DEC397] (Microsoft Corporation) C:\Windows\System32\Drivers\pcmcia.sys
2013-08-22 03:46 - 2013-08-22 07:39 - 000050016 ____A [BF28771D1436C88BE1D297D3098B0F7D] (Microsoft Corporation) C:\Windows\System32\Drivers\pcw.sys
2017-12-07 06:27 - 2017-07-07 22:16 - 000086360 ____A [E6B3ACBA06BAF48594557FCCBFA66FD2] (Microsoft Corporation) C:\Windows\System32\Drivers\pdc.sys
2017-12-07 05:47 - 2014-02-22 07:09 - 000663040 ____A [0ECEE590F2E2EF969FB74A6FC583A1E6] (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2017-12-07 06:19 - 2014-10-28 21:46 - 000272384 ____A [C76097CA941FA7CAFEDB1E557969025C] (Microsoft Corporation) C:\Windows\System32\Drivers\portcls.sys
2013-08-22 03:46 - 2013-08-22 03:46 - 000092160 ____A [ECD373F9571C745894367CC2635EA44F] (Microsoft Corporation) C:\Windows\System32\Drivers\processr.sys
2017-12-07 06:16 - 2014-10-28 21:47 - 000047104 ____A [83868EB2924E6BC21A54337C65D614D1] (Microsoft Corporation) C:\Windows\System32\Drivers\qwavedrv.sys
2017-12-07 06:16 - 2014-10-28 21:48 - 000017408 ____A [B337B1F1E82A83E20A1743E008E25C0F] (Microsoft Corporation) C:\Windows\System32\Drivers\rasacd.sys
2017-12-07 06:20 - 2016-02-02 13:16 - 000112640 ____A [235624C147E3CB4C288D5D3D8E8D64A2] (Microsoft Corporation) C:\Windows\System32\Drivers\rasl2tp.sys
2013-08-22 06:36 - 2013-08-22 06:36 - 000084992 ____A [5247F308C4103CDC4FE12AE1D235800A] (Microsoft Corporation) C:\Windows\System32\Drivers\raspppoe.sys
2013-08-22 06:35 - 2013-08-22 06:35 - 000107520 ____A [E075CC071022BD4E9BE7C024717C0E0A] (Microsoft Corporation) C:\Windows\System32\Drivers\raspptp.sys
2017-12-07 06:16 - 2014-10-28 21:45 - 000093696 ____A [41F631007A158FEBB67F0E2AD1601BBA] (Microsoft Corporation) C:\Windows\System32\Drivers\rassstp.sys
2017-12-07 06:15 - 2016-04-06 13:20 - 000402432 ____A [D67ED4AB59D1EF66B05AD1A81AC28B26] (Microsoft Corporation) C:\Windows\System32\Drivers\rdbss.sys
2013-08-22 06:39 - 2013-08-22 06:38 - 000022528 ____A [6B21EBF892CD8CACB71669B35AB5DE32] (Microsoft Corporation) C:\Windows\System32\Drivers\rdpbus.sys
2013-09-29 22:54 - 2013-09-29 22:54 - 000195584 ____A [680C1DAE268B6FB67FA21B389A8B79EF] (Microsoft Corporation) C:\Windows\System32\Drivers\rdpdr.sys
2017-12-07 06:14 - 2014-10-28 22:56 - 000027456 ____A [BC8A79C625568DDB7DCA49D0C2741A64] (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2017-12-07 05:47 - 2014-02-22 11:00 - 000249688 ____A [A26AEC49F318FEE141DDDB2C5F99B3E6] (Microsoft Corporation) C:\Windows\System32\Drivers\rdyboost.sys
2017-12-07 06:27 - 2016-10-12 16:11 - 000922968 ____A [2D39BCFA4DD1081B8F282B623456B858] (Microsoft Corporation) C:\Windows\System32\Drivers\refs.sys
2017-12-07 06:15 - 2015-01-29 22:00 - 000167424 ____A [DC66AE45816614D2999DCD3834DCCC4E] (Microsoft Corporation) C:\Windows\System32\Drivers\rfcomm.sys
2017-12-07 06:20 - 2015-11-05 03:59 - 000145408 ____A [A7D51169CA28B0AA9B5DE2B7EFB5C3C9] (Microsoft Corporation) C:\Windows\System32\Drivers\rmcast.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000032256 ____A [4A24C61ED665DB4D13B93FACA06350CA] (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2017-12-07 06:16 - 2014-10-28 21:48 - 000011776 ____A [9746BA79DE0CA5EB5104406A9ED62D01] (Microsoft Corporation) C:\Windows\System32\Drivers\rootmdm.sys
2013-08-22 06:36 - 2013-08-22 06:36 - 000080384 ____A [2D05A5508F4685412F2B89E8C2189ABC] (Microsoft Corporation) C:\Windows\System32\Drivers\rspndr.sys
2017-12-07 17:01 - 2017-11-20 13:42 - 000986080 ____A [37999EA6F1AD59F3D73B9EE366A9ED44] (Realtek ) C:\Windows\System32\Drivers\Rt630x64.sys
2017-12-07 17:02 - 2017-11-22 15:44 - 015089989 ____A [23887C6B3808236F84314BCC61A4E878] () C:\Windows\System32\Drivers\RTAIODAT.DAT
2017-12-07 17:02 - 2017-11-22 16:20 - 006044584 ____A [12134077F62EE2487FA27B2800DF60E0] (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\RTKVHD64.sys
2017-12-07 17:00 - 2017-11-16 15:55 - 000873440 ____A [36B7541AD6CEA96882A5C76ED94EEF35] (Realsil Semiconductor Corporation) C:\Windows\System32\Drivers\RtsPer.sys
2017-12-07 17:09 - 2017-11-26 12:53 - 003236320 ____A [8A0AFC5DF77DEFD277E60988B9606421] (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\rtsuvc.sys
2017-12-07 17:02 - 2017-11-22 15:44 - 005804772 ____A [7D7FBC9504575D97885A858EA93684F5] () C:\Windows\System32\Drivers\rtvienna.dat
2013-08-22 03:46 - 2013-08-22 07:39 - 000107872 ____A [C624A1B32211C3166EDB3F4AB02A30B7] (Microsoft Corporation) C:\Windows\System32\Drivers\sbp2port.sys
2017-12-07 06:26 - 2016-12-24 20:21 - 000040960 ____A [FA7ABD857DEB0FE3C94CC39A4C845E66] (Microsoft Corporation) C:\Windows\System32\Drivers\scfilter.sys
2013-08-22 06:39 - 2013-08-22 07:43 - 000170848 ____A [1C4EB3ACEA98CAD8FC7CF50F629FF0C6] (Microsoft Corporation) C:\Windows\System32\Drivers\scsiport.sys
2017-12-07 06:14 - 2015-03-12 23:03 - 000239424 ____A [C54B6B2170BF628FD42F799A66956D75] (Microsoft Corporation) C:\Windows\System32\Drivers\sdbus.sys
2017-12-07 05:47 - 2014-02-22 10:49 - 000079192 ____A [0B1E929D11A8E358106955603FAC65E8] (Microsoft Corporation) C:\Windows\System32\Drivers\sdstor.sys
2013-08-22 10:36 - 2013-08-22 10:35 - 000023040 ____A [3EA8A16169C26AFBEB544E0E48421186] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) C:\Windows\System32\Drivers\secdrv.sys
2013-08-22 06:38 - 2013-08-22 07:43 - 000069472 ____A [DB2FF24CE0BDD15FE75870AFE312BA89] (Microsoft Corporation) C:\Windows\System32\Drivers\SerCx.sys
2017-12-07 05:20 - 2013-10-25 20:54 - 000146776 ____A [0044B31F93946D5D41982314381FE431] (Microsoft Corporation) C:\Windows\System32\Drivers\SerCx2.sys
2017-12-07 06:26 - 2016-08-11 13:33 - 000023040 ____A [1F0135949A6AD6025F363F80FE268251] (Microsoft Corporation) C:\Windows\System32\Drivers\serenum.sys
2017-12-07 06:26 - 2016-08-11 13:33 - 000083456 ____A [81633C87B42B63BA484A6177179AC750] (Microsoft Corporation) C:\Windows\System32\Drivers\serial.sys
2017-12-07 06:27 - 2014-11-04 01:55 - 000026112 ____A [148195AE95D9BC7375A08846439FDAC1] (Microsoft Corporation) C:\Windows\System32\Drivers\sermouse.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000017408 ____A [472B7A5AC181C050888DB454663DD764] (Microsoft Corporation) C:\Windows\System32\Drivers\sfloppy.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000044896 ____A [2F518D13DD6F3053837FE606F1A2EA1F] (Silicon Integrated Systems Corp.) C:\Windows\System32\Drivers\sisraid2.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000081760 ____A [1AC9A200A9C49C4508F04AAFFCA34A3F] (Silicon Integrated Systems) C:\Windows\System32\Drivers\sisraid4.sys
2017-12-07 17:06 - 2016-07-17 19:37 - 000050808 ____A [C35A5F8D315C185BD2F19B277722275F] (Synaptics Incorporated) C:\Windows\System32\Drivers\Smb_driver_AMDASF_Aux.sys
2017-12-07 17:06 - 2016-07-17 19:37 - 000051320 ____A [3D9E6FF864F5D29666F0EEAAEAF1E823] (Synaptics Incorporated) C:\Windows\System32\Drivers\Smb_driver_Intel.sys
2017-12-07 17:06 - 2016-07-17 19:37 - 000051320 ____A [3D9E6FF864F5D29666F0EEAAEAF1E823] (Synaptics Incorporated) C:\Windows\System32\Drivers\Smb_driver_Intel_Aux.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000019968 ____A [8C0773703184485D57975B6C1ED48730] (Microsoft Corporation) C:\Windows\System32\Drivers\smclib.sys
2017-12-07 06:27 - 2017-01-11 12:28 - 000422744 ____A [F6AF6499C3788105EA7AF1DA27769A77] (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-08-22 06:38 - 2013-08-22 07:43 - 000072032 ____A [F337BE11071818FC3F5DC2940B6BDE34] (Microsoft Corporation) C:\Windows\System32\Drivers\SpbCx.sys
2017-12-07 06:27 - 2017-09-07 16:33 - 000415744 ____A [3D0CA97EA01210E0BC032EB6FDCCF03D] (Microsoft Corporation) C:\Windows\System32\Drivers\srv.sys
2017-12-07 06:27 - 2017-09-07 16:33 - 000686592 ____A [FD4A645C5BA587257A97D7AC46212F4A] (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2017-12-07 06:27 - 2017-09-07 16:32 - 000243200 ____A [D3EAE998706531157CBEA3F5218435BC] (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-08-22 01:57 - 2013-08-22 07:43 - 000031072 ____A [366DEA74BBA65B362BCCFC6FC2ADFD8B] (Promise Technology, Inc.) C:\Windows\System32\Drivers\stexstor.sys
2013-08-22 06:40 - 2013-08-22 07:43 - 000107872 ____A [0ED2E318ABB68C1A35A8B8038BDB4C90] (Microsoft Corporation) C:\Windows\System32\Drivers\storahci.sys
2017-12-07 06:26 - 2017-05-15 17:09 - 000057688 ____A [1D5A045F59D216448FCDE3A8D69970E2] (Microsoft Corporation) C:\Windows\System32\Drivers\stornvme.sys
2017-12-07 06:26 - 2017-10-05 02:17 - 000380248 ____A [485C591A57553EA3AC7C742E1010DAFC] (Microsoft Corporation) C:\Windows\System32\Drivers\storport.sys
2013-08-22 06:37 - 2013-08-22 07:36 - 000045888 ____A [548759755BC73DAD663250239D7E0B9F] (Microsoft Corporation) C:\Windows\System32\Drivers\storvsc.sys
2017-12-07 06:26 - 2017-01-12 10:03 - 000066560 ____A [B3A905F6E860F1C58264592F8393E322] (Microsoft Corporation) C:\Windows\System32\Drivers\storvsp.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000067584 ____A [FF184501F8F556147BBBDE571315C137] (Microsoft Corporation) C:\Windows\System32\Drivers\stream.sys
2017-12-07 06:18 - 2014-10-28 22:59 - 000014144 ____A [65454187E0F8B6C0DCECB0287D06EC43] (Microsoft Corporation) C:\Windows\System32\Drivers\swenum.sys
2017-12-07 17:06 - 2016-07-17 19:37 - 000098424 ____A [E81EC07BD12C89B3507BBC03BFB39920] (Synaptics Incorporated) C:\Windows\System32\Drivers\SynHidI2C_Aux.sys
2017-12-07 17:06 - 2016-07-17 19:37 - 000641656 ____A [AEAEF337D7958F13394B75C42F25F209] (Synaptics Incorporated) C:\Windows\System32\Drivers\SynTP.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000029696 ____A [B13A57CE2F17B8C789E895E15F115DB0] (Microsoft Corporation) C:\Windows\System32\Drivers\tape.sys
2017-12-07 06:16 - 2014-10-28 23:13 - 000021824 ____A [A57A897E3F87B8E9F30A627C42779A76] (Microsoft Corporation) C:\Windows\System32\Drivers\tbs.sys
2017-12-07 06:27 - 2017-06-07 20:48 - 002457936 ____A [4C58B60C1E6A2946D6E3D67A36E5E03E] (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2017-12-07 05:48 - 2014-03-06 04:19 - 000049152 ____A [41CF802064F72E55F50CA0A221FD36D4] (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000030208 ____A [3C7361E0A5A6966DB957B94ECF924A9E] (Microsoft Corporation) C:\Windows\System32\Drivers\tdi.sys
2017-12-07 06:26 - 2017-08-01 22:17 - 000107520 ____A [576FA545FAB846B06E79B324160DE25C] (Microsoft Corporation) C:\Windows\System32\Drivers\tdx.sys
2013-09-29 22:54 - 2013-09-29 22:54 - 000037216 ____A [232D185D2337F141311D0CF1983E1431] (Microsoft Corporation) C:\Windows\System32\Drivers\terminpt.sys
2017-12-07 06:26 - 2017-05-15 14:58 - 000121184 ____A [2B45645D0F1E950674CECE5606CF5E4E] (Microsoft Corporation) C:\Windows\System32\Drivers\tm.sys
2017-12-07 06:20 - 2015-09-29 07:24 - 000155480 ____A [80A2FC1A089A71F2DBE5D8394FFB009F] (Microsoft Corporation) C:\Windows\System32\Drivers\tpm.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000056320 ____A [BF8F54CA37E9C9D6582C31C5761F8C93] (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2017-12-07 06:16 - 2014-10-28 21:46 - 000029696 ____A [20185BEB7512EDE4EFECDFA148AC9F99] (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbGD.sys
2017-12-07 06:19 - 2015-09-04 14:24 - 000154112 ____A [E85916632CD3B9E9B546968DB950BF42] (Microsoft Corporation) C:\Windows\System32\Drivers\tunnel.sys
2013-08-22 06:39 - 2013-08-22 07:43 - 000064864 ____A [F6EEAD052943B5A3104C1405BB856C54] (Microsoft Corporation) C:\Windows\System32\Drivers\UAGP35.SYS
2013-08-22 06:37 - 2013-08-22 07:43 - 000074080 ____A [FE6067B1FD4E63650C667B33D080565B] (Microsoft Corporation) C:\Windows\System32\Drivers\uaspstor.sys
2017-12-07 06:14 - 2014-10-07 01:54 - 000189248 ____A [807F8CF3E973305FC435C61CBBEE2A49] (Microsoft Corporation) C:\Windows\System32\Drivers\UCX01000.SYS
2017-12-07 06:13 - 2015-03-12 21:02 - 000316416 ____A [C61EAF8E1E4B2F62BA4FDF457440B2C6] (Microsoft Corporation) C:\Windows\System32\Drivers\udfs.sys
2013-08-22 06:40 - 2013-08-22 07:39 - 000026976 ____A [9578691F297E1B1F519970FE6D47CB21] (Microsoft Corporation) C:\Windows\System32\Drivers\uefi.sys
2013-08-22 06:39 - 2013-08-22 07:43 - 000065888 ____A [5EAB5117DDB24FC4D39E6FFFCF1837B9] (Microsoft Corporation) C:\Windows\System32\Drivers\ULIAGPKX.SYS
2013-08-22 06:39 - 2013-08-22 06:38 - 000046080 ____A [DA34C39A18E60E7C3FA0630566408034] (Microsoft Corporation) C:\Windows\System32\Drivers\umbus.sys
2013-08-22 06:39 - 2013-08-22 06:38 - 000011776 ____A [AE8294875E5446E359B1E8035D40C05E] (Microsoft Corporation) C:\Windows\System32\Drivers\umpass.sys
2017-12-07 06:14 - 2015-04-24 21:25 - 000020992 ____A [312BB35275EB15145F4B6D1FFCE56C50] (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000032512 ____A [5D45329A96B1A417DC7F59FDEABC0DDE] (Microsoft Corporation) C:\Windows\System32\Drivers\USBCAMD2.sys
2017-12-07 06:26 - 2017-09-06 18:07 - 000158552 ____A [621317D14B93CBFBD5694767EFB6B40A] (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys
2017-12-07 06:16 - 2014-10-28 21:47 - 000098304 ____A [0139248F6B95CF0D837B5B46A2722D40] (Microsoft Corporation) C:\Windows\System32\Drivers\usbcir.sys
2017-12-07 06:14 - 2015-10-11 01:34 - 000027992 ____A [9A2B3A98D7982372CA36A823F673EFB8] (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys
2017-12-07 06:26 - 2016-01-08 20:38 - 000091992 ____A [C996CBEF922B5653A01E3F50DDCE2F86] (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys
2017-12-07 06:27 - 2017-09-06 16:17 - 000461144 ____A [E30B159760053C5A1297D2CD08046CD7] (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys
2017-12-07 06:14 - 2015-10-11 01:34 - 000468824 ____A [5C90D5379B53590FBB24BBAD4FA682EE] (Microsoft Corporation) C:\Windows\System32\Drivers\USBHUB3.SYS
2017-12-07 06:14 - 2015-10-10 13:41 - 000030208 ____A [A0F0484C97D6441ED6A75D7426ECCC9E] (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys
2017-12-07 06:26 - 2017-09-06 16:17 - 000443224 ____A [735623CABA16621A6892B70A38CB1E5A] (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys
2013-08-22 06:36 - 2013-08-22 06:36 - 000026112 ____A [4D655E3B684BE9B0F7FFD8A2935C348C] (Microsoft Corporation) C:\Windows\System32\Drivers\usbprint.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000030720 ____A [3431FBFAC156EB7FEF9B936EC2A77AF6] (Microsoft Corporation) C:\Windows\System32\Drivers\usbrpm.sys
2017-12-07 06:13 - 2016-01-31 14:16 - 000148832 ____A [9D168BFA334D47BE404367EB58D4E130] (Microsoft Corporation) C:\Windows\System32\Drivers\USBSTOR.SYS
2017-12-07 06:14 - 2015-10-10 13:41 - 000037376 ____A [FC974B03C8B87455F44F734C8F31A3C8] (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys
2017-12-07 06:16 - 2014-06-21 02:33 - 000212736 ____A [5C8F604F6DC74177CDD8372D7B1ADFF0] (Microsoft Corporation) C:\Windows\System32\Drivers\usbvideo.sys
2017-12-07 06:14 - 2015-04-16 01:17 - 000325464 ____A [44603DA5A87FB491EF59C889EBBB4DDB] (Microsoft Corporation) C:\Windows\System32\Drivers\USBXHCI.SYS
2013-08-22 06:38 - 2013-08-22 07:37 - 000037728 ____A [FEB26E3B8345A7E8D62F945C4AE86562] (Microsoft Corporation) C:\Windows\System32\Drivers\vdrvroot.sys
2013-09-29 23:14 - 2013-09-29 23:14 - 000175960 ____A [A026EDEAA5EECAE0B08E2748B616D4BD] (Microsoft Corporation) C:\Windows\System32\Drivers\VerifierExt.sys
2017-12-07 06:26 - 2016-10-09 17:59 - 000551256 ____A [8ABB4BABF59F092DF0B43778D8FD1884] (Microsoft Corporation) C:\Windows\System32\Drivers\vhdmp.sys
2013-08-22 07:22 - 2013-08-22 07:43 - 000019808 ____A [06D38968028E9AB19DE9B618C7B6D199] (VIA Technologies, Inc.) C:\Windows\System32\Drivers\viaide.sys
2017-12-07 06:26 - 2017-07-08 14:10 - 000220160 ____A [A8562942553B5C433CF4C2AACDA6D952] (Microsoft Corporation) C:\Windows\System32\Drivers\Vid.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000049152 ____A [608BD5400EFD2307A5F8DDDC87775734] (Microsoft Corporation) C:\Windows\System32\Drivers\videoprt.sys
2017-12-07 06:16 - 2014-10-28 22:56 - 000089368 ____A [A53E798C06D729CCF8459968B4372F6E] (Microsoft Corporation) C:\Windows\System32\Drivers\vmbkmcl.sys
2017-12-07 06:26 - 2017-04-09 15:39 - 000077312 ____A [C905B04C500FE822082B9FC4407B5DF9] (Microsoft Corporation) C:\Windows\System32\Drivers\vmbkmclr.sys
2017-12-07 06:16 - 2014-10-28 22:56 - 000097048 ____A [511AD3FF957A0127E6BD336FF6F89C38] (Microsoft Corporation) C:\Windows\System32\Drivers\vmbus.sys
2013-08-22 06:37 - 2013-08-22 06:37 - 000021760 ____A [DA40BEA0A863CE768C940CA9723BF81F] (Microsoft Corporation) C:\Windows\System32\Drivers\VMBusHID.sys
2017-12-07 06:26 - 2017-04-09 15:37 - 000129536 ____A [F5681EE04B0B0634665B4478E08A8527] (Microsoft Corporation) C:\Windows\System32\Drivers\vmbusr.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000011264 ____A [0BF5CAD281E25F1418E5B8875DC5ADD1] (Microsoft Corporation) C:\Windows\System32\Drivers\vmgencounter.sys
2013-08-22 06:38 - 2013-08-22 06:38 - 000007168 ____A [1A063730F221B2746FF00457AE17E4F0] (Microsoft Corporation) C:\Windows\System32\Drivers\vms3cap.sys
2017-12-07 06:16 - 2014-10-28 22:56 - 000049944 ____A [8B9486B64E5FC17FB9CC04CA10B77A34] (Microsoft Corporation) C:\Windows\System32\Drivers\vmstorfl.sys
2017-12-07 06:14 - 2016-04-11 01:21 - 000074584 ____A [436E1A724E7E683F6B612D3D58F04241] (Microsoft Corporation) C:\Windows\System32\Drivers\volmgr.sys
2017-12-07 06:26 - 2017-07-07 22:46 - 000377688 ____A [7DD4EAE2E680948D9AFF3E1B5234C1D3] (Microsoft Corporation) C:\Windows\System32\Drivers\volmgrx.sys
2017-12-07 06:13 - 2016-03-14 11:50 - 000316760 ____A [17F7B0F2298D97F4B6C7A69511033D3D] (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys
2017-12-07 06:14 - 2016-01-26 14:15 - 000072024 ____A [DAC438FB5FF85A9E72806E2341D5D732] (Microsoft Corporation) C:\Windows\System32\Drivers\vpci.sys
2017-12-07 06:26 - 2017-08-10 22:27 - 000065536 ____A [25A6BA75D7A1F63399F318213DC85EAC] (Microsoft Corporation) C:\Windows\System32\Drivers\vpcivsp.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000168800 ____A [4539F45F9F4C9757A86A56C949421E07] (VIA Technologies Inc.,Ltd) C:\Windows\System32\Drivers\vsmraid.sys
2013-08-22 02:01 - 2013-08-22 07:43 - 000305504 ____A [0849B7260F26FE05EA56DED0672E2F4B] (VIA Corporation) C:\Windows\System32\Drivers\VSTXRAID.SYS
2017-12-07 06:26 - 2016-08-12 19:03 - 000024576 ____A [71066FF95C487327E44C8AF1B72EBE8B] (Microsoft Corporation) C:\Windows\System32\Drivers\vwifibus.sys
2017-12-07 06:26 - 2016-08-12 19:02 - 000071680 ____A [29AB43937FFDA0B0FB56984226E698C6] (Microsoft Corporation) C:\Windows\System32\Drivers\vwififlt.sys
2017-12-07 06:26 - 2016-08-12 19:01 - 000038912 ____A [8B8624A93E3F88CB923AEB05B6313227] (Microsoft Corporation) C:\Windows\System32\Drivers\vwifimp.sys
2013-08-22 06:39 - 2013-08-22 06:39 - 000026752 ____A [0910AB9ED404C1434E2D0376C2AD5D8B] (Microsoft Corporation) C:\Windows\System32\Drivers\wacompen.sys
2017-12-07 06:27 - 2014-11-07 22:58 - 000080896 ____A [B41F3E5780D97CFD44A717153AD9CF2C] (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2017-12-07 05:47 - 2014-02-22 07:14 - 000054272 ____A [9CC0003FB8ED3763B977B43F1012FF63] (Microsoft Corporation) C:\Windows\System32\Drivers\watchdog.sys
2017-12-07 06:26 - 2017-02-10 09:37 - 000046600 ____A [F2E08D1C067FEFC3A42D21FD4810F1D3] (Microsoft Corporation) C:\Windows\System32\Drivers\WdBoot.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000839488 ____A [CB6C63FF8342B467E2EF76E98D5B934D] (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2017-12-07 06:27 - 2017-01-12 11:51 - 000274776 ____A [E234820E6B84ABA5E84E00227F505AE8] (Microsoft Corporation) C:\Windows\System32\Drivers\WdFilter.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000060224 ____A [42C23552FC0BF2BAB9053BE6E4DC3D13] (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys
2017-12-07 06:26 - 2017-01-12 11:51 - 000117592 ____A [A74AD6D80AC26E1B5DD276FC927F2BAC] (Microsoft Corporation) C:\Windows\System32\Drivers\WdNisDrv.sys
2013-08-22 06:40 - 2013-08-22 07:39 - 000038240 ____A [2E0AF5B354ED1BB10314353B6A625B68] (Microsoft Corporation) C:\Windows\System32\Drivers\werkernel.sys
2017-12-07 06:27 - 2014-11-10 13:06 - 000136512 ____A [715ABA3DD164D06457A2A3C92F6EA9D5] (Microsoft Corporation) C:\Windows\System32\Drivers\wfplwfs.sys
2017-12-07 06:16 - 2014-10-28 23:09 - 000033600 ____A [5F66B7BB330AA80067FC66149A692620] (Microsoft Corporation) C:\Windows\System32\Drivers\wimmount.sys
2017-12-07 06:16 - 2014-10-28 22:56 - 000061208 ____A [10A78656BF6126245631705E45F9B9CF] (Microsoft Corporation) C:\Windows\System32\Drivers\winhv.sys
2017-12-07 06:26 - 2017-04-09 15:40 - 000048128 ____A [6AEA666B3EDCBA26C1016370302333FF] (Microsoft Corporation) C:\Windows\System32\Drivers\winhvr.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000016384 ____A [2834D9D3B4F554A39C72F00EA3F0E128] (Microsoft Corporation) C:\Windows\System32\Drivers\wmiacpi.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000018272 ____A [1FE5DDC32243469E6FA4440C02775A34] (Microsoft Corporation) C:\Windows\System32\Drivers\wmilib.sys
2017-12-07 05:48 - 2014-03-13 07:35 - 000157016 ____A [7FC5667DF73D4B04AA457CC3A4180E09] (Microsoft Corporation) C:\Windows\System32\Drivers\wof.sys
2017-12-07 06:16 - 2014-10-28 22:57 - 000054784 ____A [A2468CC3509394A33C4C32F99563D845] (Microsoft Corporation) C:\Windows\System32\Drivers\wpcfltr.sys
2013-08-22 06:38 - 2013-08-22 07:36 - 000026976 ____A [9F2904B55F6CECCD1A8D986B5CE2609A] (Microsoft Corporation) C:\Windows\System32\Drivers\WpdUpFltr.sys
2013-08-22 08:25 - 2013-08-22 08:25 - 000023392 ____A [38CAE0D33091C6F3B542F230E70ED44B] (Microsoft Corporation) C:\Windows\System32\Drivers\WppRecorder.sys
2013-08-22 06:40 - 2013-08-22 06:40 - 000021504 ____A [AE072B0339D0A18E455DC21666CAD572] (Microsoft Corporation) C:\Windows\System32\Drivers\ws2ifsl.sys
2017-12-07 06:16 - 2014-10-28 21:46 - 000113664 ____A [481286719402E4BAEFEA0604AB1B5113] (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFPf.sys
2017-12-07 06:16 - 2014-10-28 21:46 - 000226304 ____A [D7B4859227B02BCC1055B279A63C937F] (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFRd.sys
2013-09-29 22:50 - 2017-12-07 13:33 - 000000000 ____D [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\en-US
2013-09-29 22:49 - 2013-09-29 22:49 - 000011776 ____A [CCA2D0FF42F019AA8D85BF2FB6E15F41] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\1394ohci.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000010240 ____A [B5DA56EFD818F1C893E2107EC968CE05] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\acpi.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000021504 ____A [3606D04BC7E6E305737BEC91CC8A6D0D] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\afd.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [A6B3942C1A97C929F4670B7B63370FF8] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\AGP440.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000014336 ____A [3B950A7C26EC075CC10D42826A2A4DF8] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\amdk8.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000014336 ____A [BBF7FD5AB839E2AA43D3B0ED9E39A0D0] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\amdppm.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000007168 ____A [CD43E5E2C950394ECD31F48E679FD97B] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ataport.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000007680 ____A [5FEAB7F5FF9E12200DA263C7C868FDFC] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\battc.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003584 ____A [2EA0F0337ABE762EB176210C5A0E683C] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\BthA2DP.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [40FE2A1CCF317A94B5FD56D497E79A13] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\BthAvrcpTg.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002048 ____A [9E9A08BA6542B63C0231DD321F0030C1] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\bthenum.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [4B3767CBC898F2B2888AB20C3235D106] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\bthhfenum.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002048 ____A [0C6D47DDFA425E40ADC00DD502195310] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\BthhfHid.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000012800 ____A [5DC5D6A51716CA7F90CFB74E7C599C8B] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\BthLEEnum.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [02F4FEF291855F17E1B1E659D8BC221B] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\BthMini.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000004608 ____A [5433113535C5AAE479DA3A154D9A861C] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\bthpan.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000032768 ____A [5FB5B412D00636CC62BC3066AF8B1229] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\bthport.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [D755E6687A0EE30DE68DB7A3318C7534] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\BTHUSB.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [DB12C55AE25DEA570948972948084FD0] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\cdrom.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000005632 ____A [1F619FB6D31D68F205AE220C3BF206E2] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\disk.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000005632 ____A [D783AC74060F59166C0637C0DB2DCEA0] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\dumpsd.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000008192 ____A [51DF0DF6DB0D673B9C02D54FCAC2CC50] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\EhStorTcgDrv.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000005120 ____A [102577751A4F9B0A571B17404447A38B] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\fltmgr.sys.mui
2017-12-07 05:46 - 2014-02-22 09:56 - 000021504 ____A [926EEDC62C2FCD647BC0D04675EE853E] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\fvevol.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000007680 ____A [71E571A0593B9904BBC95A09C7E5B7A1] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\fwpkclnt.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [FAC96A2530D79BBE22C2905A6FEDCF46] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\GAGP30KX.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000004096 ____A [99CD0F950160DEC012C3E557392DD925] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\hdaudbus.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [747F9203A6DF183606D1CBA3924012FD] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\HdAudio.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [14AE860A5AEAFC68EB6CF3B16DF98376] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\hidbth.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000006144 ____A [6BDAE5E18E43D55D879A38C17246B11B] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\hidclass.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003584 ____A [ED627E47A085C7D7046904681C5EDC64] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\hidi2c.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000038400 ____A [2AE5E1E320C912D7ADA1141A791E6B0E] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\http.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000010240 ____A [E4ABFFE744B447B16D7E404DD370EDEF] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\i8042prt.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000014336 ____A [92471F1B99E986EAED0A5A1E39B707A5] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\intelppm.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000006144 ____A [CE20CC9255F7A42651AA98EFB37017DB] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\IPMIDrv.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000004096 ____A [B535EE71D2A9E7F372C6EDA3CC08E5D9] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ipnat.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003584 ____A [89F45D27D843BB126CE75506EECAB27E] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\isapnp.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000004608 ____A [A13626BF0E5BE4EC425110ED6398289D] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\kbdclass.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [70F8E3861137B366290C76CC87DCC7A6] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\kbdhid.sys.mui
2017-12-07 05:46 - 2014-02-22 09:49 - 000002048 ____A [89044CB6A2E99FCD6892CC6F95FA052E] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ks.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000006656 ____A [589F4B32669697DCC86C87796AB9002A] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\luafv.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000003584 ____A [14C735491D0B03CD54D429DD35BED47A] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\modem.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000004096 ____A [2BDE3CAEF7E91D3EDE75004A70015488] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mouclass.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [A375D5A8086D30B50CDBED853D2DDA33] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mouhid.sys.mui
2017-12-07 06:15 - 2015-07-15 12:15 - 000002560 ____A [4AF392CEEDBEBEB4276A4B846690EDA7] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mountmgr.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000055296 ____A [D0CE1060C18401B68D3B83C68FB5A4B5] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mrxsmb.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [867F15AFDDF027A72DACF055AFA74BB5] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mshidkmdf.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [CAE33B50C378B0E89A2F0FA1501B20CC] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mshidumdf.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000008704 ____A [A1F415FFCBC26FA88C3644AC094F5DB7] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mslldp.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [2CFB49C6E6E1EB57545A83D4655C6056] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mssmbios.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [C4634B62A436D99F46284D14188D7AB1] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\MTConfig.sys.mui
2017-12-07 06:15 - 2015-01-10 04:07 - 000012800 ____A [78BAA3F54ED5AC8082D1AA985E0109EF] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\mup.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000057856 ____A [F450E013F78D0A5F1F17A96CB1233A27] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ndis.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000005632 ____A [35B1981AFD2DAC97DBE60ED3060CA3B0] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ndiscap.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000011264 ____A [8C4A2BA8EB99FD7CDF936EB9E696EAE0] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\NdisImPlatform.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000003072 ____A [8105B2BCB7472FE152999DBC1BBC1293] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ndisuio.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [9CDF5709BBAAB7058D7E25116962B91E] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\NdisVirtualBus.sys.mui
2017-12-07 05:48 - 2014-02-22 09:42 - 000084992 ____A [0A132F1DD6167033D8942BDE1A9CA978] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ntfs.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [9A288DB3E2E4DFF9D50848F918A0D205] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\NV_AGP.SYS.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000014336 ____A [8408E3E07817356E554343A1858C046C] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\nwifi.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000017408 ____A [AAE0D51E60BA789F37E6F10CCDDA3B98] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\pacer.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003584 ____A [46E64135EC40C997D0A1505F5D25F617] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\parport.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [5F4FDF4706FB6E2A59DA1FD2273F01F2] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\partmgr.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000008192 ____A [6CDB4C7AE4EA0337A3072F14817C67F4] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\pci.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000004096 ____A [78E7F147FA21050EE167BF2F6F402250] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\pcmcia.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002048 ____A [A7AC203417A1933936DC1CF897FCEBBB] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\pdc.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [EAD2F339CE0D4167A7A6310364FCBD39] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\pnpmem.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000004096 ____A [7C2DB6B9CD440A339FE0702F35B377C1] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\portcls.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000014336 ____A [2E16897A12A9CB0B49CA832C290F11A4] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\processr.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [F3B786F1518B985EB2DF6154D460D6F3] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\qwavedrv.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000005632 ____A [555F9097CDC4EBFAB371523CC6569A5A] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\rdbss.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [51D107C9434AAB4C7FF006881AA3D684] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\rdpdr.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000008192 ____A [CD7D055498F2CBA489DE234AF2859994] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\refs.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000003072 ____A [CE456D3022A8963259DC2E247DAB4C1F] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\RNDISMP.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [D05D2E5DAC0E94A098F7C83CA9F0D9FF] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\rndismp6.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [CE456D3022A8963259DC2E247DAB4C1F] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\rndismpx.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [E740847276E386D2DB79F83EABFBAB2E] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\scfilter.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000003072 ____A [4B5307E8DF2F798C72E80FD1F77CCCCD] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\scsiport.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000005632 ____A [8BFA30900E037CBE612A30824304AED4] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\sdbus.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [ABF5E3081386BB6328A0A2609EB05842] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\sdstor.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000003584 ____A [6646B085AFD4E8A457D8D1BA27167C48] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\sercx.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000008704 ____A [9F79EA2950BCF1BFD87EFFB333DDD928] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\sercx2.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000010240 ____A [F5BEC30FE6093C89C0380B617F1D9D7E] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\serial.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000005120 ____A [6E7CBABB993BC0E1ACBEDD2769F133FF] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\sermouse.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [8FC0CC5F7BF27FB1A293D7EE66FC3C2F] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\serscan.sys.mui
2017-12-07 06:19 - 2016-01-24 09:35 - 000040960 ____A [9144FCF3AD8DAB06127F7AF7D2969AFD] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\spaceport.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000004096 ____A [55DD1A8228C09A259606001D1C60C009] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\spbcx.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [B19FFEAD517844AAC7DCFF652D900469] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\srv.sys.mui
2017-12-07 06:27 - 2017-05-03 11:04 - 000068096 ____A [EA180252C871E1A4566B2F362A9E7800] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\srv2.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000008192 ____A [7DA60A617A1F2AD846F239F48E894818] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\storvsp.sys.mui
2017-12-07 06:14 - 2016-03-11 10:12 - 000086528 ____A [6FD95912A5A219D79F376A2839567EBC] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\tcpip.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000008192 ____A [38FD7DF71EF1938646FE6BE00A5C51B7] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\tpm.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [5A9FA86928CC75DD03C0923AD2C39BAF] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\tsusbflt.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000007680 ____A [7A444882987D5D96C18BB5CFBCD2B386] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\tunnel.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [F038F9F62D356510CEB7EC7453643599] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\UAGP35.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000012288 ____A [5504447B7B5F3ADD660F51C7CAD2C195] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\UCX01000.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [667AF0980B238CE5BE2E8552C7DBCCF4] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ULIAGPKX.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [21B25F46EC3B0D49BB2041333C5B39B0] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\umbus.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [F1298FD692F5E9C9EAFBE917E0DC500B] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\USBAUDIO.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000003072 ____A [17FA2B0B3DDF42A80EBAB4F44C07D26F] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\usbehci.sys.mui
2017-12-07 06:16 - 2014-07-24 08:41 - 000014336 ____A [1F85505E3AD14BBF433FFF8A1514757D] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\usbhub.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000020480 ____A [F911CF1E512B09123ED2D8634A4E66FA] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\USBHUB3.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000026112 ____A [D23E6B1CAD00F60CCA8F12E49D3E91C0] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\usbport.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002048 ____A [B2A62B9ACA3A68AB872EB5638D7E8FCA] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\usbrpm.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [8532FAE8E484F5B08318013F1532738D] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\USBSTOR.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [9925DB33B91939166DAEE12CA7C412A4] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\usbvideo.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000014848 ____A [09A5B9D1965B98C60E01DAF6FED40BFA] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\USBXHCI.SYS.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000005120 ____A [02BD6A9AD41077AA823B399A304EEE44] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\vdrvroot.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000013312 ____A [2028053C56B3A17EEBF75BB96834DAA7] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\vhdmp.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000012288 ____A [0C3B799952EDF13A5E7980B077D831ED] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\Vid.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000060928 ____A [D447181BBE61E6E56801749A30A50D6F] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\vmswitch.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [427A9E28038A6C0E80646621C6D02BA2] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\volmgrx.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000023552 ____A [7F4A513CB90D51EB39CA955CF0FE23DB] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\volsnap.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002048 ____A [26E9F6CFBF2DC479ADBC7319D7369296] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\vwifibus.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000004096 ____A [79BFC84AEDA75F27E398394B398EB477] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\wacompen.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [CA1844B4098F1D6C2520699A7242C5C4] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\wdf01000.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [BFEE4840A672728A70ABDC452654B37C] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\wfplwfs.sys.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000013824 ____A [096724B4585F818F3E879F579C8AA13C] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\wmbclass.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002048 ____A [2B0B166692208DDA856662C490ABF0B3] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\WpdUpFltr.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002048 ____A [7C0AE658C7BE463B68BEC51E9AEFE203] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\ws2ifsl.sys.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [61F2D3C5CAB218B914825B23B3E68AAF] (Microsoft Corporation) C:\Windows\System32\Drivers\en-US\wudfpf.sys.mui
2013-08-22 08:36 - 2017-12-07 15:36 - 000000000 ____D [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\etc
2013-08-22 08:25 - 2013-08-22 08:25 - 000000824 ____A [3688374325B992DEF12793500307566D] () C:\Windows\System32\Drivers\etc\hosts
2013-08-22 10:36 - 2013-08-22 10:35 - 000003683 ____A [18413B90E1B291EC3E777A845C37CFEE] () C:\Windows\System32\Drivers\etc\lmhosts.sam
2013-08-22 08:25 - 2013-08-22 08:25 - 000000407 ____A [B65A1232FB4B35827CE7C5E2F8EC8947] () C:\Windows\System32\Drivers\etc\networks
2013-08-22 08:25 - 2013-08-22 08:25 - 000001358 ____A [7700D22FA108234E623D65FA72D9E29C] () C:\Windows\System32\Drivers\etc\protocol
2013-08-22 08:25 - 2013-08-22 08:25 - 000017463 ____A [D9E1A01B480D961B7CF0509D597A92D6] () C:\Windows\System32\Drivers\etc\services
2013-08-22 10:33 - 2017-12-08 00:21 - 000000000 ____D [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\UMDF
2017-12-07 06:16 - 2014-10-28 21:29 - 000088576 ____A [6C2117ABA0F9C6B9238DA92A4179EF1F] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\EhStorPwdDrv.dll
2017-12-07 06:16 - 2014-10-28 21:29 - 000054272 ____A [9E5A866A051CA31C84156A6803606E51] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\HidBthLE.dll
2017-12-07 06:16 - 2014-10-28 19:56 - 000297984 ____A [B751B25DD96BEDEEF32A075544A10803] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\WpdFs.dll
2013-09-29 22:50 - 2013-09-29 22:54 - 000000000 ____D [D41D8CD98F00B204E9800998ECF8427E] () C:\Windows\System32\Drivers\UMDF\en-US
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [BE37860FC26885A492DE883F3938F639] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\HidBthLE.dll.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002048 ____A [E5A318E3FAD0729EB0934117322E5594] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\hidscanner.dll.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [EF3547EAF8B3AC95BCF36CB84B3C32DC] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\idtsec.dll.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000005632 ____A [7FFEA04D96C5961BBAC8253890661D4D] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\LocationProvider.dll.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000002560 ____A [AD4D7D1BF668CC7BACE7CAABF4344D4B] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\mgtdyn.dll.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000009728 ____A [EE3C4AFD2A446B676A9A3FFA92294F04] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\SensorsHIDClassDriver.dll.mui
2013-09-29 22:50 - 2013-09-29 22:50 - 000002560 ____A [7B6E6AE3E171D15C17B16A63810AEDEC] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\WpdMtpDr.dll.mui
2013-09-29 22:49 - 2013-09-29 22:49 - 000006144 ____A [4D56FE5E7334CD9C1D956F207D18E4EE] (Microsoft Corporation) C:\Windows\System32\Drivers\UMDF\en-US\WUDFUsbccidDriver.dll.mui

====== End of Folder: ======


========= Reg query "HKLM\SYSTEM\Select" =========


HKEY_LOCAL_MACHINE\SYSTEM\Select
    Current    REG_DWORD    0x1
    Default    REG_DWORD    0x1
    Failed    REG_DWORD    0x0
    LastKnownGood    REG_DWORD    0x1



========= End of Reg: =========


"C:\Users\Narth\AppData\Local\tiedcwn" folder move:

Could not move "C:\Users\Narth\AppData\Local\tiedcwn" => Scheduled to move on reboot.


"C:\Users\Narth\AppData\Local\radmhvs" folder move:

Could not move "C:\Users\Narth\AppData\Local\radmhvs" => Scheduled to move on reboot.


"C:\Users\Narth\AppData\Local\igfxmtc" folder move:

Could not move "C:\Users\Narth\AppData\Local\igfxmtc" => Scheduled to move on reboot.

C:\Windows\system32\nvbkriwsvc.exe => moved successfully

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 09-12-2017 14:07:42)

"C:\Users\Narth\AppData\Local\tiedcwn" => Could not move
"C:\Users\Narth\AppData\Local\radmhvs" => Could not move
"C:\Users\Narth\AppData\Local\igfxmtc" => Could not move

==== End of Fixlog 14:07:42 ====



#4 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:02:58 AM

Posted 09 December 2017 - 02:56 PM

We will need to run the fix in the Recovery Environment.

Please download Farbar Recovery Scan Tool and save it to a flash drive.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

Please also download the attached file and save it in the same location the FRST64 is saved in the flash drive.

Insert the USB drive in the infected computer.

Boot to the Recovery Console's Command prompt.

Entry points into the Windows Recovery Environment (WinRE).

You can access WinRE features through the Boot Options menu, which can be launched from Windows in a few different ways:
  • Option 1: From the login screen, click Shutdown, then hold down the Shift key while selecting Restart.
  • Option 2: In Windows 10, select Start > Settings > Update & security > Recovery > under Advanced Startup, click Restart now.
  • Option 3: Boot to recovery media.
  • Option 4: Use a hardware recovery button (or button combination) configured by the OEM (Computer Manufacturer).
After any of these actions is performed, all user sessions are signed off and the Boot Options menu is displayed. The PC will restart into the WinRE and the selected feature is launched.

On the boot options, select Troubleshooting > Advanced Options > Command prompt.

Once in the Command Prompt:
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press the Fix button.
  • It will make a log (Fixlog.txt) in the flash drive. Please copy and paste it to your reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#5 Queschun

Queschun
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 03:44 PM

Sorry, was a little hassle trying to get into recovery mode, had to find windows disc.

 

I put the files on my flash drive and when at the command prompt in recovery mode, it says "The subsystem needed to support the image type is not present."



#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:02:58 AM

Posted 09 December 2017 - 05:30 PM

Try to use other computer to download FRST into the flash drive. The rootkit in the computer is resisting FRST. If unable to run FRST like this, then boot to WinRE command prompt and type the following and press Enter.

 

BCDEDIT | Find "osdevice"

 

Let me know the results.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#7 Queschun

Queschun
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 05:53 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 09-12-2017
Ran by SYSTEM (09-12-2017 17:49:02) Run:2
Running from d:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
Reg: Reg delete HKLM\SYSTEM\ControlSet001\hotascx /f
Reg: Reg delete HKLM\SYSTEM\ControlSet001\luafv /f
Reg: Reg delete HKLM\SYSTEM\ControlSet001\udiskMgr /f
C:\Windows\system32\drivers\nih*.sys
C:\Users\Narth\AppData\Local\tiedcwn
C:\Users\Narth\AppData\Local\radmhvs
C:\Users\Narth\AppData\Local\igfxmtc
*****************


========= Reg delete HKLM\SYSTEM\ControlSet001\hotascx /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


========= Reg delete HKLM\SYSTEM\ControlSet001\luafv /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


========= Reg delete HKLM\SYSTEM\ControlSet001\udiskMgr /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


=========== "C:\Windows\system32\drivers\nih*.sys" ==========

C:\Windows\system32\drivers\nihfilps.sys => moved successfully

========= End -> "C:\Windows\system32\drivers\nih*.sys" ========

C:\Users\Narth\AppData\Local\tiedcwn => moved successfully
C:\Users\Narth\AppData\Local\radmhvs => moved successfully
C:\Users\Narth\AppData\Local\igfxmtc => moved successfully

==== End of Fixlog 17:49:07 ====

 

I think it worked!



#8 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:02:58 AM

Posted 09 December 2017 - 06:20 PM

Lets re-check.

 

  • Highlight the entire content of the quote box below.

Start::
CMD: fltmc instances  
CMD: Dir C:\Windows\system32\drivers\nih*.sys
End::

  • Right click on the highlighted text and select Copy.
  • Start FRST (FRST64) with Administrator privileges
  • Press CTRL+Y while on FRST. A document will popup. Right click and select paste on this document to copy the lines above to it.
  • Save the document and Press the Fix button.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

 

Download AdwCleaner from here. Save the file to the desktop.

NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • XP users: Double click the AdwCleaner icon to start the program.
  • Vista/7/8/10 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:

65MBhLLb.png


  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be moved to Quarantine.
  • When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this

adwcleaner_delete_restart.jpg


  • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt

 


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#9 Queschun

Queschun
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 06:24 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 09-12-2017
Ran by Narth (09-12-2017 18:23:54) Run:3
Running from D:\
Loaded Profiles: Narth (Available Profiles: Narth)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CMD: fltmc instances  
CMD: Dir C:\Windows\system32\drivers\nih*.sys

*****************


========= fltmc instances =========

Filter                Volume Name                              Altitude        Instance Name       Frame   SprtFtrs  VlStatus
--------------------  -------------------------------------  ------------  ----------------------  -----   --------  --------
FileInfo              E:                                         45000     FileInfo                  0     00000003  
FileInfo                                                         45000     FileInfo                  0     00000003  
FileInfo              C:                                         45000     FileInfo                  0     00000003  
FileInfo              D:                                         45000     FileInfo                  0     00000003  
FileInfo              \Device\Mup                                45000     FileInfo                  0     00000003  
MBAMChameleon         E:                                        400900     MBAMChameleon             0     00000000  
MBAMChameleon                                                   400900     MBAMChameleon             0     00000000  
MBAMChameleon         C:                                        400900     MBAMChameleon             0     00000000  
MBAMChameleon         D:                                        400900     MBAMChameleon             0     00000000  
MBAMChameleon         \Device\Mup                               400900     MBAMChameleon             0     00000000  
MBAMFarflt                                                      268150     MBAMFarflt                0     00000000  
MBAMFarflt            C:                                        268150     MBAMFarflt                0     00000000  
MBAMFarflt            D:                                        268150     MBAMFarflt                0     00000000  
MBAMProtection        E:                                        328800     MBAMProtection            0     00000000  
MBAMProtection                                                  328800     MBAMProtection            0     00000000  
MBAMProtection        C:                                        328800     MBAMProtection            0     00000000  
MBAMProtection        D:                                        328800     MBAMProtection            0     00000000  
MBAMProtection        \Device\Mup                               328800     MBAMProtection            0     00000000  
SbieDrv               E:                                         86900     SbieDrv Instance          0     00000000  
SbieDrv                                                          86900     SbieDrv Instance          0     00000000  
SbieDrv               C:                                         86900     SbieDrv Instance          0     00000000  
SbieDrv               D:                                         86900     SbieDrv Instance          0     00000000  
SbieDrv               \Device\Mup                                86900     SbieDrv Instance          0     00000000  
luafv                 C:                                        135000     luafv                     0     00000003  
npsvctrig             \Device\NamedPipe                          46000     npsvctrig                 0     00000000  

========= End of CMD: =========


========= Dir C:\Windows\system32\drivers\nih*.sys =========

 Volume in drive C has no label.
 Volume Serial Number is B8E4-F6AC

 Directory of C:\Windows\system32\drivers

File Not Found

========= End of CMD: =========


==== End of Fixlog 18:23:55 ====



#10 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:02:58 AM

Posted 09 December 2017 - 06:27 PM

Sorry. I realize something in that fix.

 

Please download this fixlist    to the flash drive, and run it in WinRE as you did before.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#11 Queschun

Queschun
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 06:27 PM

# AdwCleaner 7.0.5.0 - Logfile created on Sat Dec 09 02:32:47 2017
# Updated on 2017/29/11 by Malwarebytes
# Running on Windows 8.1 Pro (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [945 B] - [2017/12/9 2:32:34]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########



#12 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:02:58 AM

Posted 09 December 2017 - 06:33 PM

Check Post #10.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#13 Queschun

Queschun
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 06:35 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 09-12-2017
Ran by SYSTEM (09-12-2017 18:32:47) Run:4
Running from d:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
Reg: Reg delete HKLM\SYSTEM\ControlSet001\Services\hotascx /f
Reg: Reg delete HKLM\SYSTEM\ControlSet001\Services\luafv /f
Reg: Reg delete HKLM\SYSTEM\ControlSet001\Services\udiskMgr /f
C:\Windows\system32\drivers\nih*.sys
C:\Users\Narth\AppData\Local\tiedcwn
C:\Users\Narth\AppData\Local\radmhvs
C:\Users\Narth\AppData\Local\igfxmtc
*****************


========= Reg delete HKLM\SYSTEM\ControlSet001\Services\hotascx /f =========

The operation completed successfully.



========= End of Reg: =========


========= Reg delete HKLM\SYSTEM\ControlSet001\Services\luafv /f =========

The operation completed successfully.



========= End of Reg: =========


========= Reg delete HKLM\SYSTEM\ControlSet001\Services\udiskMgr /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


=========== "C:\Windows\system32\drivers\nih*.sys" ==========

not found

========= End -> "C:\Windows\system32\drivers\nih*.sys" ========

"C:\Users\Narth\AppData\Local\tiedcwn" => not found.
"C:\Users\Narth\AppData\Local\radmhvs" => not found.
"C:\Users\Narth\AppData\Local\igfxmtc" => not found.

==== End of Fixlog 18:32:47 ====



#14 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:02:58 AM

Posted 09 December 2017 - 06:58 PM

Now I am convinced, How is the computer doing?


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#15 Queschun

Queschun
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 09 December 2017 - 07:05 PM

My pc is back in working order, thank you so much for your excellent work JSntgRvr!






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users