tdsskiller.3.1.0.9_16.06.2016_15.22.20_log

Upload: ivan-cirkovic

Post on 28-Feb-2018

216 views

Category:

Documents


0 download

TRANSCRIPT

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    1/32

    15:22:21.0042 0x116c TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:1215:22:27.0127 0x116c ============================================================15:22:27.0127 0x116c Current date / time: 2016/06/16 15:22:27.012715:22:27.0127 0x116c SystemInfo:15:22:27.0127 0x116c15:22:27.0128 0x116c OS Version: 6.1.7600 ServicePack: 0.015:22:27.0128 0x116c Product type: Workstation15:22:27.0128 0x116c ComputerName: IVAN-PC15:22:27.0129 0x116c UserName: Ivan15:22:27.0129 0x116c Windows directory: C:\Windows15:22:27.0129 0x116c System windows directory: C:\Windows15:22:27.0129 0x116c Processor architecture: Intel x8615:22:27.0129 0x116c Number of processors: 215:22:27.0129 0x116c Page size: 0x100015:22:27.0129 0x116c Boot type: Normal boot15:22:27.0129 0x116c ============================================================15:22:38.0398 0x116c KLMD registered as C:\Windows\system32\drivers\84132866.sys15:22:43.0692 0x116c System UUID: {C041FD5D-044E-F171-C983-B7A293A58D5A}15:23:02.0327 0x116c Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050

    15:23:02.0573 0x116c ============================================================15:23:02.0573 0x116c \Device\Harddisk0\DR0:15:23:02.0573 0x116c MBR partitions:15:23:02.0573 0x116c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA0x3F, BlocksNum 0x14B9A54D15:23:02.0573 0x116c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA0x14B9A5CB, BlocksNum 0x1492E67615:23:02.0574 0x116c \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA0x294C9000, BlocksNum 0x10EBC80015:23:02.0575 0x116c ============================================================15:23:02.0606 0x116c C: \Device\Harddisk0\DR0\Partition3

    15:23:02.0667 0x116c D: \Device\Harddisk0\DR0\Partition215:23:02.0728 0x116c F: \Device\Harddisk0\DR0\Partition115:23:02.0729 0x116c ============================================================15:23:02.0729 0x116c Initialize success15:23:02.0730 0x116c ============================================================15:23:06.0219 0x0844 ============================================================15:23:06.0219 0x0844 Scan started15:23:06.0219 0x0844 Mode: Manual;15:23:06.0220 0x0844 ============================================================

    15:23:06.0220 0x0844 KSN ping started15:23:21.0398 0x0844 KSN ping finished: true15:23:26.0566 0x0844 ================ Scan system memory ========================15:23:26.0567 0x0844 System memory - ok15:23:26.0570 0x0844 ================ Scan services =============================15:23:26.0823 0x0844 [ 6D2ACA41739BFE8CB86EE8E85F29697D, 74A4F53C8309A8E5E94CDE4D440DD5308566185E6D8D98FD08E70A25BD728C91 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    2/32

    15:23:26.0867 0x0844 1394ohci - ok15:23:27.0113 0x0844 [ F0E07D144C8685B8774BC32FC8DA4DF0, 39816ED2623CA9ABE2B2EDCDB2F8481634742F00FEEF7E324F34D2BAAD668A67 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys15:23:27.0138 0x0844 ACPI - ok15:23:27.0170 0x0844 [ 98D81CA942D19F7D9153B095162AC013, ACE5C073323176621F3312AA9B1EE1A3382F8CDD590D90DC57B34035FD6BC281 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys15:23:27.0176 0x0844 AcpiPmi - ok15:23:27.0261 0x0844 [ C460349E4C6CD6C12E93476C3923A1B0, 7192F6D38EC83228CCB01B065625D895ACC2DE65DC34D1F13979F56A88AD8675 ] ACPIVPC C:\Windows\system32\DRIVERS\AcpiVpc.sys15:23:27.0266 0x0844 ACPIVPC - ok15:23:27.0429 0x0844 [ FC5B75CA6A1DA31EDD4F8D53F5540B98, CDC445F2790ADFC4C5568C40D4DA8BB95CD71991665B38AEC3D84571C99C3520 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe15:23:27.0454 0x0844 AdobeARMservice - ok15:23:27.0576 0x0844 [ 07883F80A1C815473E973B2801FA6FDB, E01095600DA35E0304B1CB7E141841071E438E3C3DF2CA610F3B3FF33609BC8F ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe15:23:27.0599 0x0844 AdobeFlashPlayerUpdateSvc - ok15:23:27.0667 0x0844 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys

    15:23:27.0858 0x0844 adp94xx - ok15:23:27.0932 0x0844 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys15:23:27.0959 0x0844 adpahci - ok15:23:28.0011 0x0844 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys15:23:28.0042 0x0844 adpu320 - ok15:23:28.0168 0x0844 [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\Windows\System32\aelupsvc.dll15:23:28.0182 0x0844 AeLookupSvc - ok

    15:23:28.0310 0x0844 [ 0DB7A48388D54D154EBEC120461A0FCD, 567B65F96ADE0E8252B7D8CE7F254CB8054C3AE4BC3577C394EFDEF8D8A61427 ] AFD C:\Windows\system32\drivers\afd.sys15:23:28.0389 0x0844 AFD - ok15:23:28.0460 0x0844 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys15:23:28.0481 0x0844 agp440 - ok15:23:28.0515 0x0844 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys15:23:28.0526 0x0844 aic78xx - ok15:23:28.0547 0x0844 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C

    4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe15:23:28.0555 0x0844 ALG - ok15:23:28.0577 0x0844 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\DRIVERS\aliide.sys15:23:28.0584 0x0844 aliide - ok15:23:28.0657 0x0844 [ D4A8B3FB5AB83A59785F31E8D581E418, 2E1DEC949C51C96363C85F27960BF8DDC4BC5DA29AB719B3193EF7692FFE5D61 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    3/32

    15:23:28.0674 0x0844 AMD External Events Utility - ok15:23:28.0704 0x0844 AMD FUEL Service - ok15:23:28.0736 0x0844 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys15:23:28.0746 0x0844 amdagp - ok15:23:28.0781 0x0844 [ 7933FB35658E0F666FD01FEEA2C74EBC, D075BAD9CD954AF909919B03C73EE0C40E74055B28F0E9E17AEC7AAD604BB1E7 ] amdhub30 C:\Windows\system32\DRIVERS\amdhub30.sys15:23:28.0806 0x0844 amdhub30 - ok15:23:28.0834 0x0844 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\DRIVERS\amdide.sys15:23:28.0841 0x0844 amdide - ok15:23:28.0869 0x0844 [ FF258424F0B2EF25EB98F04EE386E6E3, 09DC3854BF0D52FB80AB08DC4E0DD4A9E37ACAA500083A56F9836C837EBCFA82 ] amdiox86 C:\Windows\system32\DRIVERS\amdiox86.sys15:23:28.0876 0x0844 amdiox86 - ok15:23:28.0907 0x0844 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys15:23:28.0916 0x0844 AmdK8 - ok15:23:30.0143 0x0844 [ 8B99EDDFE33F360DF7283211BE7509C0, 5A51E9CF1FF168783386CE260BA09FF3FDCFF24FA2E9B41EF3893983F13F7CB7 ] amdkmdag C:\Windows\system32

    \DRIVERS\atikmdag.sys15:23:31.0560 0x0844 amdkmdag - ok15:23:31.0767 0x0844 [ 57BA15A00E45D32527DC35CC8FD249BA, B7F3F51DF050BA238D01663E6F9CD4896DBE4B4934C5AF9B9FE8CF4894DF77E8 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys15:23:31.0790 0x0844 amdkmdap - ok15:23:31.0832 0x0844 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys15:23:31.0840 0x0844 AmdPPM - ok15:23:31.0886 0x0844 [ 19CE906B4CDC11FC4FEF5745F33A63B6, 27BF91DB1FDC81CFCF0E0DCFD3C4AD51FCFB778D36F1E83105C2AFCF6851A4DF ] amdsata C:\Windows\system32\drivers\amdsata.sys

    15:23:31.0899 0x0844 amdsata - ok15:23:31.0951 0x0844 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys15:23:31.0974 0x0844 amdsbs - ok15:23:32.0023 0x0844 [ 869E67D66BE326A5A9159FBA8746FA70, 8F493A340F19FB39B5BD24EF8603812BECE7770544AB91817FF67236448569CB ] amdxata C:\Windows\system32\drivers\amdxata.sys15:23:32.0034 0x0844 amdxata - ok15:23:32.0082 0x0844 [ DE6F0911D3ACFA04678871DD2E9AD08D, 46214DF68BDFE6C3D436AB13C31724B937D80AED198C86CCD7D48826D5019188 ] amdxhc C:\Windows\system32\DRIVERS\amdxhc.sys15:23:32.0117 0x0844 amdxhc - ok

    15:23:32.0149 0x0844 [ FEB834C02CE1E84B6A38F953CA067706, E5A7F8B632ABFBD1283C3D44FB02449814EDB653B204E1720DAA780A6D64FD01 ] AppID C:\Windows\system32\drivers\appid.sys15:23:32.0158 0x0844 AppID - ok15:23:32.0214 0x0844 [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc C:\Windows\System32\appidsvc.dll15:23:32.0223 0x0844 AppIDSvc - ok15:23:32.0250 0x0844 [ 7DEAD9E3F65DCB2794F2711003BBF650, F541C30EEFD1BDB70F361B878B6E51DC728873695DD137148CE531FBACCDA21B ] Appinfo C:\Windows\System32

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    4/32

    \appinfo.dll15:23:32.0260 0x0844 Appinfo - ok15:23:32.0305 0x0844 [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt C:\Windows\System32\appmgmts.dll15:23:32.0325 0x0844 AppMgmt - ok15:23:32.0379 0x0844 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys15:23:32.0392 0x0844 arc - ok15:23:32.0416 0x0844 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys15:23:32.0427 0x0844 arcsas - ok15:23:32.0549 0x0844 [ 776ACEFA0CA9DF0FAA51A5FB2F435705, 72DF7ED6B085BC468994F5B3189506FD726A9A17A9C42ACA1E420D787691361D ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe15:23:32.0569 0x0844 aspnet_state - ok15:23:32.0634 0x0844 [ 7E31ED7D09D591DDD04B3C1BDE31A631, 49253C254F552BF390480705DFF607534C15793FE9747F008970321F4C3A290F ] aswHwid C:\Windows\system32\drivers\aswHwid.sys15:23:32.0640 0x0844 aswHwid - ok15:23:32.0688 0x0844 [ D522080F0AD8AEB0D51CEABE4AE71AFB, AA8D2BD9D34C933BDD3E18E3194BF36D49FD1E0EF6F246FBBD11767BC8B27056 ] aswMonFlt C:\Windows\system32

    \drivers\aswMonFlt.sys15:23:32.0698 0x0844 aswMonFlt - ok15:23:32.0731 0x0844 [ 1E481F7BDA311259C180EA99B5BD8585, 663733A454E8AD782EDF768C50B0C07BF31E93919FC6E145D320E2CB136C33DA ] aswRdr C:\Windows\system32\drivers\aswRdr2.sys15:23:32.0750 0x0844 aswRdr - ok15:23:32.0776 0x0844 [ F47C251FAFCB1785849A3C54A8EDA56B, 6A8577244C5D134154120A6EE4B313301A384B578EE7FE11713CF29003A3669B ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys15:23:32.0803 0x0844 aswRvrt - ok15:23:32.0948 0x0844 [ B9A9BE793A4BFA49120C321A6B0045D9, 4CBB768FE2F604C1ADD4883B299ECB6ECCCD5980C4116554316D389C0261D20E ] aswSnx C:\Windows\system32\drivers\aswSnx.sys

    15:23:33.0106 0x0844 aswSnx - ok15:23:33.0257 0x0844 [ 67527C8C4041FAFBF4DC51A6DD88B479, BEAB64D76E136EB722F8CA4673E446BAE499D7B9EA24393E9672CFEBD956789A ] aswSP C:\Windows\system32\drivers\aswSP.sys15:23:33.0304 0x0844 aswSP - ok15:23:33.0449 0x0844 [ B9A86D39229010342E434FFAF836AC6C, FAB505E50F744294A40A1F11FCCEAF96299D3858E4E2FA68A03277C6246EC4A9 ] aswStm C:\Windows\system32\drivers\aswStm.sys15:23:33.0481 0x0844 aswStm - ok15:23:33.0523 0x0844 [ 7358232E267C175061775FF258558D67, 65E1DBC05643B4298A6F45F5F0C58EE65303BF61B8A84E85E4F69EA2C1744D4C ] aswVmm C:\Windows\system32\drivers\aswVmm.sys15:23:33.0547 0x0844 aswVmm - ok

    15:23:33.0567 0x0844 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys15:23:33.0573 0x0844 AsyncMac - ok15:23:33.0624 0x0844 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\DRIVERS\atapi.sys15:23:33.0632 0x0844 atapi - ok15:23:33.0767 0x0844 [ 4D201D8B576BE4473405B2A86A2D28B3, 97D14459C5ED6EA67220485CC8828C07E9C39C4D04A371AB86AB6379E664DC7D ] AtiHDAudioService C:\Windows\system

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    5/32

    32\drivers\AtihdW73.sys15:23:33.0780 0x0844 AtiHDAudioService - ok15:23:33.0864 0x0844 [ 510C873BFA135AA829F4180352772734, BC528D840EB338B0C5D11801C63D8EADD40AF8043DC77ACB4B42E8D20767538F ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll15:23:33.0950 0x0844 AudioEndpointBuilder - ok15:23:34.0012 0x0844 [ 510C873BFA135AA829F4180352772734, BC528D840EB338B0C5D11801C63D8EADD40AF8043DC77ACB4B42E8D20767538F ] Audiosrv C:\Windows\System32\Audiosrv.dll15:23:34.0060 0x0844 Audiosrv - ok15:23:34.0176 0x0844 [ 11120878E5276B367E1A10FF8C9B595B, 7C02EEF3733307C31BAC4DA9975EC017AC40D0893D88228C30FFAA536DAA73FB ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe15:23:34.0230 0x0844 avast! Antivirus - ok15:23:34.0785 0x0844 [ 5240A6EF7387964F2DA24A60FAAA5FB0, D4FF51880A46EE3034A2C5519A9A504694480503A35491B7CF4227FD9D5575B6 ] AvastVBoxSvc C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe15:23:35.0138 0x0844 AvastVBoxSvc - ok15:23:35.0208 0x0844 [ DD6A431B43E34B91A767D1CE33728175, 8BFF6474C9DFBEC96FA7B2789EF9B17C7910B52DBCF70CDA1F0C698CFA5EFB6E ] AxInstSV C:\Windows\System32\AxInstSV.dll15:23:35.0220 0x0844 AxInstSV - ok15:23:35.0287 0x0844 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32

    \DRIVERS\bxvbdx.sys15:23:35.0336 0x0844 b06bdrv - ok15:23:35.0384 0x0844 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys15:23:35.0407 0x0844 b57nd60x - ok15:23:35.0522 0x0844 [ A2ECECE11639FEA1CCB66D853451F7E2, 1DEE5A7C710FEDB725610D17B71AA9D6FAD8039DE4EE1165854399A5D8193AD7 ] BazisVirtualCDBus C:\Windows\system32\DRIVERS\BazisVirtualCDBus.sys15:23:35.0552 0x0844 BazisVirtualCDBus - ok15:23:36.0018 0x0844 [ 978480C2F811041D59AEBC91930BABC9, F5ECF9C95B72FB656D4C52478ECAD534219895743C4C57C4E307DEF8BCA54762 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys

    15:23:36.0535 0x0844 BCM43XX - ok15:23:36.0637 0x0844 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll15:23:36.0675 0x0844 BDESVC - ok15:23:36.0701 0x0844 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys15:23:36.0706 0x0844 Beep - ok15:23:36.0766 0x0844 [ 85AC71C045CEB054ED48A7841AAE0C11, BA0C0CC50E5C49838116AC9A12A7CF1A683601FD08D3CF6EC06620C51C0806FF ] BFE C:\Windows\System32\bfe.dll15:23:36.0899 0x0844 BFE - ok

    15:23:37.0065 0x0844 [ 53F476476F55A27F580661BDE09C4EC4, 90DFBF97F011CFF41D2CFA2E33978BC746A7E693AC75EED1436130C4F10B4E67 ] BITS C:\Windows\System32\qmgr.dll15:23:37.0137 0x0844 BITS - ok15:23:37.0222 0x0844 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys15:23:37.0233 0x0844 blbdrive - ok15:23:37.0271 0x0844 [ 9A5C671B7FBAE4865149BB11F59B91B2, BE1D5901CB8EF20E34F711D6451BDFBCA4BD65AFAD6028964C5CE1673D94FBAD ] bowser C:\Windows\system32

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    6/32

    \DRIVERS\bowser.sys15:23:37.0293 0x0844 bowser - ok15:23:37.0318 0x0844 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys15:23:37.0323 0x0844 BrFiltLo - ok15:23:37.0348 0x0844 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys15:23:37.0353 0x0844 BrFiltUp - ok15:23:37.0406 0x0844 [ A0E691DC6589D4D2CBE373171D1A49E5, 66BAED3EF7AFE0FB4304FC97ABE2BB106ADE1A956F89DCB52E70F30239461D05 ] Browser C:\Windows\System32\browser.dll15:23:37.0422 0x0844 Browser - ok15:23:37.0499 0x0844 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys15:23:37.0557 0x0844 Brserid - ok15:23:37.0608 0x0844 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys15:23:37.0620 0x0844 BrSerWdm - ok15:23:37.0639 0x0844 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32

    \Drivers\BrUsbMdm.sys15:23:37.0648 0x0844 BrUsbMdm - ok15:23:37.0683 0x0844 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys15:23:37.0689 0x0844 BrUsbSer - ok15:23:37.0717 0x0844 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys15:23:37.0730 0x0844 BTHMODEM - ok15:23:37.0819 0x0844 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll

    15:23:37.0833 0x0844 bthserv - ok15:23:37.0913 0x0844 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys15:23:37.0934 0x0844 cdfs - ok15:23:37.0999 0x0844 [ BA6E70AA0E6091BC39DE29477D866A77, A17A68BDA46995F75FB1C2C593A81CD3B2BFE290CEAA45FA2380DDF5537A23C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys15:23:38.0027 0x0844 cdrom - ok15:23:38.0051 0x0844 [ 628A9E30EC5E18DD5DE6BE4DBDC12198, DDA43DCCB195440D6BD5752BD00D984F45BD6D23DBE2A656C33E3CD1E5D17AD7 ] CertPropSvc C:\Windows\System32\certprop.dll15:23:38.0075 0x0844 CertPropSvc - ok

    15:23:38.0094 0x0844 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys15:23:38.0101 0x0844 circlass - ok15:23:38.0155 0x0844 [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS C:\Windows\system32\CLFS.sys15:23:38.0201 0x0844 CLFS - ok15:23:38.0296 0x0844 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\W

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    7/32

    indows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe15:23:38.0309 0x0844 clr_optimization_v2.0.50727_32 - ok15:23:38.0381 0x0844 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe15:23:38.0415 0x0844 clr_optimization_v4.0.30319_32 - ok15:23:38.0568 0x0844 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys15:23:38.0594 0x0844 CmBatt - ok15:23:38.0629 0x0844 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys15:23:38.0635 0x0844 cmdide - ok15:23:38.0727 0x0844 [ DB5E008B3744DD60C8498CBBF2A1CFA6, 1D851BF2433A953B32438A911D194C9DB42A52CD6E8DA296CA3C8DD2CCA83381 ] CNG C:\Windows\system32\Drivers\cng.sys15:23:38.0756 0x0844 CNG - ok15:23:38.0785 0x0844 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys15:23:38.0796 0x0844 Compbatt - ok15:23:38.0836 0x0844 [ F1724BA27E97D627F808FB0BA77A28A6, F7D69082EEFEC0FB8B309F6AEE282D4A5DFC1A40851ED65904AA9582C5DEA5AB ] CompositeBus C:\Windows\system32

    \DRIVERS\CompositeBus.sys15:23:38.0843 0x0844 CompositeBus - ok15:23:38.0878 0x0844 COMSysApp - ok15:23:38.0920 0x0844 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys15:23:38.0928 0x0844 crcdisk - ok15:23:39.0045 0x0844 [ F2FDE6C8DBAAD44CC58D1E07E4AF4EED, 579D206CF49FB78C2D9BA29A9C57489B7875242EB618019CB7B8D336C70A09E6 ] CryptSvc C:\Windows\system32\cryptsvc.dll15:23:39.0074 0x0844 CryptSvc - ok15:23:39.0139 0x0844 [ 27C9490BDD0AE48911AB8CF1932591ED, 751F576F797F8A7BA576C32598BD6FD2E60D4FACC7836CC5BA3F68C38D27CCCA ] CSC C:\Windows\system32

    \drivers\csc.sys15:23:39.0173 0x0844 CSC - ok15:23:39.0255 0x0844 [ 56FB5F222EA30D3D3FC459879772CB73, 2C4646774575858E26DBA9C73853E06D0BD18CC8A4C73C633071FF5FE04CA0F4 ] CscService C:\Windows\System32\cscsvc.dll15:23:39.0304 0x0844 CscService - ok15:23:39.0399 0x0844 [ B82CD39E336973359D7C9BF911E8E84F, 45DB8F1E88FC25A81D2F3C2F8A8CDB6B34C44950B038E24FB71DCDD9823DB22A ] DcomLaunch C:\Windows\system32\rpcss.dll15:23:39.0495 0x0844 DcomLaunch - ok15:23:39.0569 0x0844 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll

    15:23:39.0593 0x0844 defragsvc - ok15:23:39.0675 0x0844 [ 83D1ECEA8FAAE75604C0FA49AC7AD996, 0EB4F374CB91AFF12ABC7EFC7858BDB6E58B50FCE0ADA1711F90FF592059DA40 ] DfsC C:\Windows\system32\Drivers\dfsc.sys15:23:39.0687 0x0844 DfsC - ok15:23:39.0766 0x0844 [ 560B0DCE52DFED6623B27C9BAFA6F236, BB4156BB1CCA64CCDE065870DAE56CD58BF05CEBF7C3B17C7A821FDF02A8B157 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys15:23:39.0788 0x0844 dg_ssudbus - ok15:23:39.0857 0x0844 [ C56495FBD770712367CAD35E5DE72DA6, 9D5456A2E208F542F0B6C9

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    8/32

    51EFCABA2A10919777C4287D7298A28F543D5BAC32 ] Dhcp C:\Windows\system32\dhcpcore.dll15:23:39.0882 0x0844 Dhcp - ok15:23:39.0916 0x0844 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys15:23:39.0923 0x0844 discache - ok15:23:39.0968 0x0844 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys15:23:39.0975 0x0844 Disk - ok15:23:40.0057 0x0844 [ B15BE77A2BACF9C3177D27518AFE26A9, FBF02038C2EC0262B401FCBD348C48DF184AD76E95643E3D6ED32C02E90D8FC9 ] Dnscache C:\Windows\System32\dnsrslvr.dll15:23:40.0085 0x0844 Dnscache - ok15:23:40.0142 0x0844 [ 4408C85C21EEA48EB0CE486BAEEF0502, 67EA726F4053665D94D7790EC89616EA0698A7548073A9211E3F75937B4384BE ] dot3svc C:\Windows\System32\dot3svc.dll15:23:40.0208 0x0844 dot3svc - ok15:23:40.0275 0x0844 [ 7FA81C6E11CAA594ADB52084DA73A1E5, 9ED1C585D9CA091E75E4A2A1E5B923B104EBDC5FC9D12154DE909C583E4D0CAE ] DPS C:\Windows\system32\dps.dll15:23:40.0300 0x0844 DPS - ok15:23:40.0379 0x0844 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA

    9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys15:23:40.0384 0x0844 drmkaud - ok15:23:40.0536 0x0844 [ 1679A4669326CB1A67CC95658D273234, 57429EC10744956635CAE0742320D7C03B3EEA0CB1F5769AEF21C054C0B5E498 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys15:23:40.0597 0x0844 DXGKrnl - ok15:23:40.0643 0x0844 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll15:23:40.0660 0x0844 EapHost - ok15:23:41.0129 0x0844 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32

    \DRIVERS\evbdx.sys15:23:41.0486 0x0844 ebdrv - ok15:23:41.0581 0x0844 [ C2243FF9E9AAD0C30E8B1A0914DA15B6, CD01BD44659FDAA6FE8679D0F76748409680A4F4885905EA56F655C60DDEC01F ] EFS C:\Windows\System32\lsass.exe15:23:41.0594 0x0844 EFS - ok15:23:41.0723 0x0844 [ 1697C39978CD69F6FBC15302EDCECE1F, E496FAE102EE33EBD35AC745E8647976DB9F91EF78E54EB962FF2D04D45B561A ] ehRecvr C:\Windows\ehome\ehRecvr.exe15:23:41.0772 0x0844 ehRecvr - ok15:23:41.0818 0x0844 [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe

    15:23:41.0830 0x0844 ehSched - ok15:23:41.0893 0x0844 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys15:23:41.0928 0x0844 elxstor - ok15:23:41.0981 0x0844 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys15:23:41.0987 0x0844 ErrDev - ok15:23:42.0075 0x0844 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F782

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    9/32

    9B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll15:23:42.0107 0x0844 EventSystem - ok15:23:42.0167 0x0844 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys15:23:42.0184 0x0844 exfat - ok15:23:42.0225 0x0844 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys15:23:42.0242 0x0844 fastfat - ok15:23:42.0334 0x0844 [ F7EA23CC5E6BF2181F3F399D54F6EFC1, 4659A2EDC5D5171668FB20BED7B56466A674876888519D6F524F7456EBD11263 ] Fax C:\Windows\system32\fxssvc.exe15:23:42.0380 0x0844 Fax - ok15:23:42.0431 0x0844 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys15:23:42.0438 0x0844 fdc - ok15:23:42.0487 0x0844 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll15:23:42.0498 0x0844 fdPHost - ok15:23:42.0550 0x0844 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB

    63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll15:23:42.0564 0x0844 FDResPub - ok15:23:42.0620 0x0844 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys15:23:42.0633 0x0844 FileInfo - ok15:23:42.0663 0x0844 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys15:23:42.0670 0x0844 Filetrace - ok15:23:42.0706 0x0844 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32

    \DRIVERS\flpydisk.sys15:23:42.0713 0x0844 flpydisk - ok15:23:42.0769 0x0844 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys15:23:42.0790 0x0844 FltMgr - ok15:23:42.0929 0x0844 [ 7FE4995528A7529A761875151EE3D512, 63F062A8E6AA9AEF39A46E94ADD548C72B4E21C1090DE9CBDCFB3F4489637BAF ] FontCache C:\Windows\system32\FntCache.dll15:23:42.0992 0x0844 FontCache - ok15:23:43.0090 0x0844 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

    15:23:43.0098 0x0844 FontCache3.0.0.0 - ok15:23:43.0135 0x0844 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys15:23:43.0145 0x0844 FsDepends - ok15:23:43.0215 0x0844 [ 500A9814FD9446A8126858A5A7F7D273, FB9607A43B8DDA87A449A3BFEBDC035F00BA7B5D9CC56AD5F310732A38F56A46 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys15:23:43.0225 0x0844 Fs_Rec - ok15:23:43.0284 0x0844 [ 4732E596BB1C50D9F9188C5074EE7782, 465E47C6AFA53B7CAFED5C

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    10/32

    61A5D832E7B3A1A33F82E1F11A472B84CD24D2ED55 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys15:23:43.0303 0x0844 fvevol - ok15:23:43.0338 0x0844 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys15:23:43.0347 0x0844 gagp30kx - ok15:23:43.0484 0x0844 [ 8BA3C04702BF8F927AB36AE8313CA4EE, 3B6460C8134AA9D6E4FB978201B35FE9B67DD5BBB6C8D9625F3097DDA30C2893 ] gpsvc C:\Windows\System32\gpsvc.dll15:23:43.0541 0x0844 gpsvc - ok15:23:43.0999 0x0844 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe15:23:44.0010 0x0844 gupdate - ok15:23:44.0050 0x0844 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe15:23:44.0087 0x0844 gupdatem - ok15:23:44.0147 0x0844 [ C1B577B2169900F4CF7190C39F085794, 73E104B96A48F4C80D8C37254ECB0891D15C0D2F0C251B57C168F90D60316447 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe15:23:44.0161 0x0844 gusvc - ok15:23:44.0210 0x0844 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421

    B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys15:23:44.0218 0x0844 hcw85cir - ok15:23:44.0329 0x0844 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F, 6706B8AD211A4B89B6571ACD227412026EAD87D71456B3EC6E7DD8FA15B997BE ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys15:23:44.0357 0x0844 HdAudAddService - ok15:23:44.0403 0x0844 [ 717A2207FD6F13AD3E664C7D5A43C7BF, BF28A6F00B64FA0E801493E3289CFFD5E313E724DF7B5AB521C9E37A20890DCF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys15:23:44.0417 0x0844 HDAudBus - ok15:23:44.0475 0x0844 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32

    \DRIVERS\HidBatt.sys15:23:44.0482 0x0844 HidBatt - ok15:23:44.0519 0x0844 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys15:23:44.0532 0x0844 HidBth - ok15:23:44.0591 0x0844 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys15:23:44.0601 0x0844 HidIr - ok15:23:44.0654 0x0844 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\system32\hidserv.dll

    15:23:44.0683 0x0844 hidserv - ok15:23:44.0721 0x0844 [ 25072FB35AC90B25F9E4E3BACF774102, EBCE089947CC5A251A517CB91E81FCB948B18405FBACA04C874D4A48AF88676D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys15:23:44.0729 0x0844 HidUsb - ok15:23:44.0786 0x0844 [ 741C2A45CA8407E374AABA3E330B7872, FCF31C46297CFDF8240F0E783A61C8463FEDB1EF7A676AB89DFF0EAE9F3534B4 ] hkmsvc C:\Windows\system32\kmsvc.dll15:23:44.0802 0x0844 hkmsvc - ok15:23:44.0837 0x0844 [ A768CA158BB06782A2835B907F4873C3, EFF736C6BA38FB8FC88072

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    11/32

    86AB273E7274F505E8E59D952E8563DF77C412C5AE ] HomeGroupListener C:\Windows\system32\ListSvc.dll15:23:44.0858 0x0844 HomeGroupListener - ok15:23:44.0910 0x0844 [ FB08DEC5EF43D0C66D83B8E9694E7549, 9C9ECE9E90F524791FC5DCE797BAE39605F966592126FF058BA3FA0BEFD07BEB ] HomeGroupProvider C:\Windows\system32\provsvc.dll15:23:44.0949 0x0844 HomeGroupProvider - ok15:23:44.0983 0x0844 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys15:23:44.0995 0x0844 HpSAMD - ok15:23:45.0071 0x0844 [ C531C7FD9E8B62021112787C4E2C5A5A, 09205E2A5BFB6C623B312B8AC82F7F7CA8A922B1D9A0E3952BD3BA47BBE1F18C ] HTTP C:\Windows\system32\drivers\HTTP.sys15:23:45.0112 0x0844 HTTP - ok15:23:45.0183 0x0844 [ 8305F33CDE89AD6C7A0763ED0B5A8D42, A7CA4978DC1FF6105EA39124DF854F0B1FD478476B871ED0E018AF3AE2165282 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys15:23:45.0187 0x0844 hwpolicy - ok15:23:45.0240 0x0844 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys15:23:45.0252 0x0844 i8042prt - ok15:23:45.0333 0x0844 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9, 3AF6B8220E5081C7995197

    9FE59E980C0309C826E201AE286D3B42CD2BA8145F ] iaStorV C:\Windows\system32\drivers\iaStorV.sys15:23:45.0367 0x0844 iaStorV - ok15:23:45.0495 0x0844 [ 5AF815EB5BC9802E5A064E2BA62BFC0C, DC8CED05F623D30C57E8A7A382A219B4266C9C766ABF8A8D71783EACB8607B82 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe15:23:45.0578 0x0844 idsvc - ok15:23:45.0618 0x0844 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys15:23:45.0631 0x0844 iirsp - ok15:23:45.0742 0x0844 [ FAC0EE6562B121B1399D6E855583F7A5, 034C9EE9232EB2CE64297EC4BCBEB5DA443ED9176C436CC754EF84FFB4AD4B08 ] IKEEXT C:\Windows\System32

    \ikeext.dll15:23:45.0806 0x0844 IKEEXT - ok15:23:45.0864 0x0844 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\DRIVERS\intelide.sys15:23:45.0871 0x0844 intelide - ok15:23:45.0922 0x0844 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys15:23:45.0934 0x0844 intelppm - ok15:23:45.0962 0x0844 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll

    15:23:45.0982 0x0844 IPBusEnum - ok15:23:46.0015 0x0844 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys15:23:46.0025 0x0844 IpFilterDriver - ok15:23:46.0138 0x0844 [ 477397B432A256A50EE7E4339EB9EA14, 3722938E69D16962F773F39669E9B90279DC9527BBC63564B33C89DAFD283497 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll15:23:46.0202 0x0844 iphlpsvc - ok15:23:46.0250 0x0844 [ E4454B6C37D7FFD5649611F6496308A7, 5B2AA8C06076C9A1FF944E

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    12/32

    5EA07C29BA7FABEBB38E6BFB388ED46933EAC465FB ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys15:23:46.0267 0x0844 IPMIDRV - ok15:23:46.0334 0x0844 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys15:23:46.0345 0x0844 IPNAT - ok15:23:46.0378 0x0844 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys15:23:46.0383 0x0844 IRENUM - ok15:23:46.0454 0x0844 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys15:23:46.0466 0x0844 isapnp - ok15:23:46.0521 0x0844 [ ED46C223AE46C6866AB77CDC41C404B7, 1B2A4A3FF0E5F8F02717F20983D57612D62DFF809064A7E524700E7254BB7DB3 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys15:23:46.0537 0x0844 iScsiPrt - ok15:23:46.0602 0x0844 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys15:23:46.0608 0x0844 kbdclass - ok15:23:46.0651 0x0844 [ 3D9F0EBF350EDCFD6498057301455964, B3CB5F0C045B06C86E683F

    3C67DC0D4E37AF16E20B189B05C926A5A7011438FB ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys15:23:46.0658 0x0844 kbdhid - ok15:23:46.0697 0x0844 [ C2243FF9E9AAD0C30E8B1A0914DA15B6, CD01BD44659FDAA6FE8679D0F76748409680A4F4885905EA56F655C60DDEC01F ] KeyIso C:\Windows\system32\lsass.exe15:23:46.0707 0x0844 KeyIso - ok15:23:46.0778 0x0844 [ 52FC17C8589F11747D01D3CF592673D0, 0D432F14DF6A0964947FADF4AFBCC195946A68230DC17FA610CC000BB0C921A7 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys15:23:46.0788 0x0844 KSecDD - ok15:23:46.0821 0x0844 [ 3E5474B03568CFAB834DA3C38E8C9EFA, 1223B99AD86905C34BC95C61DA894F36567F4A23EA7E32E955133C5B2FD558DB ] KSecPkg C:\Windows\system32

    \Drivers\ksecpkg.sys15:23:46.0841 0x0844 KSecPkg - ok15:23:46.0920 0x0844 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll15:23:46.0957 0x0844 KtmRm - ok15:23:47.0040 0x0844 [ 8F6BF790D3168224C16F2AF68A84438C, CEEA0E38B746163A4110E157DAB50CC35A689A5BBC9B3691F2B9D3AE49B0D95E ] LanmanServer C:\Windows\system32\srvsvc.dll15:23:47.0075 0x0844 LanmanServer - ok15:23:47.0154 0x0844 [ B9891F885DCF1F0513A51CB58493CB1F, C883D243E1E7B7AEA031FB90FE4FCEED631F835DC95F9D9D60BC554E6EC358C2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll

    15:23:47.0181 0x0844 LanmanWorkstation - ok15:23:47.0323 0x0844 [ 8FF8B5F04AC4D57F9A965BB4DF07813E, E39669D8F4354CDCB7EDFA8722916E2BF6C3778EDDD81D0F6AF6D129B0619BA7 ] LHDmgr C:\Windows\system32\DRIVERS\LhdX86.sys15:23:47.0328 0x0844 LHDmgr - ok15:23:47.0372 0x0844 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys15:23:47.0383 0x0844 lltdio - ok15:23:47.0631 0x0844 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64B

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    13/32

    E47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll15:23:47.0673 0x0844 lltdsvc - ok15:23:47.0715 0x0844 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll15:23:47.0731 0x0844 lmhosts - ok15:23:47.0773 0x0844 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys15:23:47.0786 0x0844 LSI_FC - ok15:23:47.0836 0x0844 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys15:23:47.0848 0x0844 LSI_SAS - ok15:23:47.0889 0x0844 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys15:23:47.0902 0x0844 LSI_SAS2 - ok15:23:47.0939 0x0844 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys15:23:47.0958 0x0844 LSI_SCSI - ok15:23:48.0008 0x0844 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC512

    06A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys15:23:48.0024 0x0844 luafv - ok15:23:48.0086 0x0844 [ E2B0887816ED336685954E3D8FDAA51D, 4DCB08ADC6A89DCA68D1285734B283B567888EF72249F6BBA73A63D1BD462466 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll15:23:48.0105 0x0844 Mcx2Svc - ok15:23:48.0151 0x0844 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys15:23:48.0159 0x0844 megasas - ok15:23:48.0235 0x0844 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32

    \DRIVERS\MegaSR.sys15:23:48.0257 0x0844 MegaSR - ok15:23:48.0318 0x0844 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll15:23:48.0334 0x0844 MMCSS - ok15:23:48.0380 0x0844 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys15:23:48.0387 0x0844 Modem - ok15:23:48.0454 0x0844 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys

    15:23:48.0458 0x0844 monitor - ok15:23:48.0522 0x0844 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys15:23:48.0533 0x0844 mouclass - ok15:23:48.0605 0x0844 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys15:23:48.0621 0x0844 mouhid - ok15:23:48.0719 0x0844 [ 921C18727C5920D6C0300736646931C2, 19ACE502982E9C5B013467

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    14/32

    6102EAEE96675C9CA237E410DB36C389D6B4078301 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys15:23:48.0735 0x0844 mountmgr - ok15:23:48.0830 0x0844 [ 5961C5D8EDD2E2A3B99F1782AE1AC21F, C383A4724A335737C4C7C3211AFCFB82D373267EC634BC47EE078A1C66E1F62A ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe15:23:48.0846 0x0844 MozillaMaintenance - ok15:23:48.0905 0x0844 [ 2AF5997438C55FB79D33D015C30E1974, E8F048A02FEB400C133D0BFC1659921E73B59549E3F7D2A13929901B87A1901F ] mpio C:\Windows\system32\DRIVERS\mpio.sys15:23:48.0924 0x0844 mpio - ok15:23:49.0004 0x0844 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys15:23:49.0019 0x0844 mpsdrv - ok15:23:49.0208 0x0844 [ 5CD996CECF45CBC3E8D109C86B82D69E, ABE40DA4DA555D3D5054BE28BF82E775D90DCB9E31409DC95FABF2F016B17700 ] MpsSvc C:\Windows\system32\mpssvc.dll15:23:49.0281 0x0844 MpsSvc - ok15:23:49.0356 0x0844 [ B1BE47008D20E43DA3ADC37C24CDB89D, 6E8555E84B42E5098227B35EA5ABADF2CD3AC247B37CB9E9304FF67064EBE59B ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys15:23:49.0372 0x0844 MRxDAV - ok15:23:49.0480 0x0844 [ CA7570E42522E24324A12161DB14EC02, E4DA5EDC7CBCC9E6015430

    71A49347A0AA3EB4EAC205E342A1F2768FD785D08F ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys15:23:49.0494 0x0844 mrxsmb - ok15:23:49.0571 0x0844 [ F965C3AB2B2AE5C378F4562486E35051, 5FFDD5531B98FF0EA19A901C4EE1CE6043C245A4BE5533A495E331B5834D696B ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys15:23:49.0599 0x0844 mrxsmb10 - ok15:23:49.0631 0x0844 [ 25C38264A3C72594DD21D355D70D7A5D, DCEF2DEBB1859FED6FC7A19D13A841B6B6CA10577E12F116D0EB2D2B8C72A4A1 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys15:23:49.0658 0x0844 mrxsmb20 - ok15:23:49.0702 0x0844 [ 4326D168944123F38DD3B2D9C37A0B12, 322AE93418BE3BA6B3E11C86431EC3F4B23CADC3B968B92978A08A7C0D0D8902 ] msahci C:\Windows\system32

    \DRIVERS\msahci.sys15:23:49.0708 0x0844 msahci - ok15:23:49.0772 0x0844 [ 455029C7174A2DBB03DBA8A0D8BDDD9A, 614D71978B024109ADD9A7A74F74ABD5FAA1C36A2E859AF288398EAE7CD76DF2 ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys15:23:49.0786 0x0844 msdsm - ok15:23:49.0825 0x0844 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe15:23:49.0854 0x0844 MSDTC - ok15:23:49.0950 0x0844 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys

    15:23:49.0956 0x0844 Msfs - ok15:23:49.0997 0x0844 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys15:23:50.0004 0x0844 mshidkmdf - ok15:23:50.0032 0x0844 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys15:23:50.0053 0x0844 msisadrv - ok15:23:50.0136 0x0844 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA730784960074

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    15/32

    8842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll15:23:50.0171 0x0844 MSiSCSI - ok15:23:50.0192 0x0844 msiserver - ok15:23:50.0259 0x0844 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys15:23:50.0266 0x0844 MSKSSRV - ok15:23:50.0340 0x0844 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys15:23:50.0356 0x0844 MSPCLOCK - ok15:23:50.0408 0x0844 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys15:23:50.0417 0x0844 MSPQM - ok15:23:50.0466 0x0844 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys15:23:50.0483 0x0844 MsRPC - ok15:23:50.0557 0x0844 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys15:23:50.0567 0x0844 mssmbios - ok

    15:23:50.0583 0x0844 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys15:23:50.0587 0x0844 MSTEE - ok15:23:50.0648 0x0844 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys15:23:50.0655 0x0844 MTConfig - ok15:23:50.0705 0x0844 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys15:23:50.0715 0x0844 Mup - ok15:23:50.0792 0x0844 [ 80284F1985C70C86F0B5F86DA2DFE1DF, 424A5BBC28C72DA0DBABEB

    9E423B8C409754CD1BA3DFC9E174BF22D8BCE1BE63 ] napagent C:\Windows\system32\qagentRT.dll15:23:50.0879 0x0844 napagent - ok15:23:50.0980 0x0844 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys15:23:51.0037 0x0844 NativeWifiP - ok15:23:51.0128 0x0844 [ 23759D175A0A9BAAF04D05047BC135A8, 2C8C553B4E1ED3A644F619F16BCEDD5A3C6D74A17E6E75A3E740E06B1D636348 ] NDIS C:\Windows\system32\drivers\ndis.sys15:23:51.0225 0x0844 NDIS - ok15:23:51.0266 0x0844 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32

    \DRIVERS\ndiscap.sys15:23:51.0272 0x0844 NdisCap - ok15:23:51.0319 0x0844 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys15:23:51.0326 0x0844 NdisTapi - ok15:23:51.0371 0x0844 [ B30AE7F2B6D7E343B0DF32E6C08FCE75, 39BBBF7AF886732CB9ED3E6C06DA4318554089F3BEA74C74328FE1C6EF68E70B ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys15:23:51.0380 0x0844 Ndisuio - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    16/32

    15:23:51.0438 0x0844 [ 267C415EADCBE53C9CA873DEE39CF3A4, BAA8626BDA7B68176B19A99FBBD40FB2A774C8F44B56F9FFB99A1F5C16A1C555 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys15:23:51.0452 0x0844 NdisWan - ok15:23:51.0489 0x0844 [ AF7E7C63DCEF3F8772726F86039D6EB4, 1CFDED48E8844138864786DBF9D5519162A6DB28F885A781934E8AFBD52EAC50 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys15:23:51.0500 0x0844 NDProxy - ok15:23:51.0536 0x0844 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys15:23:51.0543 0x0844 NetBIOS - ok15:23:51.0591 0x0844 [ DD52A733BF4CA5AF84562A5E2F963B91, 5CEB9664CED3D120F5408A12035748728710D41090A289CF66023CED4C838A1F ] NetBT C:\Windows\system32\DRIVERS\netbt.sys15:23:51.0611 0x0844 NetBT - ok15:23:51.0643 0x0844 [ C2243FF9E9AAD0C30E8B1A0914DA15B6, CD01BD44659FDAA6FE8679D0F76748409680A4F4885905EA56F655C60DDEC01F ] Netlogon C:\Windows\system32\lsass.exe15:23:51.0661 0x0844 Netlogon - ok15:23:51.0741 0x0844 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll15:23:51.0779 0x0844 Netman - ok

    15:23:51.0861 0x0844 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe15:23:51.0876 0x0844 NetMsmqActivator - ok15:23:51.0903 0x0844 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe15:23:51.0917 0x0844 NetPipeActivator - ok15:23:51.0996 0x0844 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll15:23:52.0071 0x0844 netprofm - ok15:23:52.0116 0x0844 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B

    7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe15:23:52.0127 0x0844 NetTcpActivator - ok15:23:52.0170 0x0844 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe15:23:52.0189 0x0844 NetTcpPortSharing - ok15:23:52.0260 0x0844 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys15:23:52.0271 0x0844 nfrd960 - ok15:23:52.0373 0x0844 [ B06110733A2CCD49A3A5AFB6624F299E, 264AE7743D80B337ABCA785A7A7C69ADC84F4D0D6A5F5441FBF79AC9687A01C1 ] ngvss C:\Windows\system32

    \drivers\ngvss.sys15:23:52.0390 0x0844 ngvss - ok15:23:52.0442 0x0844 [ 2226496E34BD40734946A054B1CD657F, 98392D98C9213822268971432BB55047ABD8B4EBD42483FA69BF50FB8FAD64A2 ] NlaSvc C:\Windows\System32\nlasvc.dll15:23:52.0492 0x0844 NlaSvc - ok15:23:52.0576 0x0844 [ F6C40E0A565EE3CE5AEEB325E10054F2, 30C8BA41B1C235ECB2C7F29CD76C8F41B8D705BE7DD44F66666C28275EA56BAC ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys15:23:52.0580 0x0844 nmwcd - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    17/32

    15:23:52.0621 0x0844 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B, 879BE61C4256C9B855AA269C241A0D24E9ECE3CA0F3AFFB2E11D9340C0428D31 ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys15:23:52.0626 0x0844 nmwcdc - ok15:23:52.0689 0x0844 [ 25401B0C9576C8456B3E0BBD74FF0771, BB569C99360A631850537DC2EDA0BF85D091CC30BD98B3FD2AC9DABDFB7741DA ] NPF C:\Windows\system32\drivers\npf.sys15:23:52.0695 0x0844 NPF - ok15:23:52.0736 0x0844 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys15:23:52.0744 0x0844 Npfs - ok15:23:52.0782 0x0844 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll15:23:52.0812 0x0844 nsi - ok15:23:52.0882 0x0844 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys15:23:52.0887 0x0844 nsiproxy - ok15:23:53.0157 0x0844 [ A8F59428E9F361C7AC42A94AC1560BC9, 5B056375C8D21E7AE9E2EAC2EF62F5A2D6D0DBB52DD2FC34F9CC35F55C6766A6 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys15:23:53.0306 0x0844 Ntfs - ok

    15:23:53.0386 0x0844 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys15:23:53.0391 0x0844 Null - ok15:23:53.0462 0x0844 [ F1B0BED906F97E16F6D0C3629D2F21C6, 563DE1AF0BE884264FD0D17AAA92EA32A2EACDF1E6C56D038773919D731E110C ] nvraid C:\Windows\system32\drivers\nvraid.sys15:23:53.0475 0x0844 nvraid - ok15:23:53.0536 0x0844 [ 4520B63899E867F354EE012D34E11536, BDFF1033609834F44B0EDBE8B360FD7977D027034C469862385736AEFE8832B7 ] nvstor C:\Windows\system32\drivers\nvstor.sys15:23:53.0550 0x0844 nvstor - ok15:23:53.0596 0x0844 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FE

    FCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys15:23:53.0609 0x0844 nv_agp - ok15:23:53.0772 0x0844 [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE15:23:53.0830 0x0844 odserv - ok15:23:53.0879 0x0844 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys15:23:53.0897 0x0844 ohci1394 - ok15:23:53.0977 0x0844 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Co

    mmon Files\Microsoft Shared\Source Engine\OSE.EXE15:23:53.0994 0x0844 ose - ok15:23:54.0112 0x0844 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll15:23:54.0249 0x0844 p2pimsvc - ok15:23:54.0549 0x0844 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll15:23:54.0629 0x0844 p2psvc - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    18/32

    15:23:54.0677 0x0844 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys15:23:54.0694 0x0844 Parport - ok15:23:54.0762 0x0844 [ 66D3415C159741ADE7038A277EFFF99F, D9853845FE495A546328986718074373EAB0F59538CFE7E604B1A94C8CBE7140 ] partmgr C:\Windows\system32\drivers\partmgr.sys15:23:54.0772 0x0844 partmgr - ok15:23:54.0826 0x0844 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys15:23:54.0835 0x0844 Parvdm - ok15:23:54.0890 0x0844 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll15:23:54.0920 0x0844 PcaSvc - ok15:23:55.0040 0x0844 [ F451DCACBAA67F3307305EBD4A39EA07, C4435BF4C2D16F3DC0B35732BE3602FFA28DB0A5BC5576F45E0D32E5F4CD2DEA ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys15:23:55.0053 0x0844 pccsmcfd - ok15:23:55.0106 0x0844 [ C858CB77C577780ECC456A892E7E7D0F, 21AE545B736739DE5A7B02CF227516BA6D02B1AAAECD8CC516CCF9F1FD710BCF ] pci C:\Windows\system32\DRIVERS\pci.sys15:23:55.0127 0x0844 pci - ok

    15:23:55.0162 0x0844 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\DRIVERS\pciide.sys15:23:55.0168 0x0844 pciide - ok15:23:55.0228 0x0844 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys15:23:55.0247 0x0844 pcmcia - ok15:23:55.0266 0x0844 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys15:23:55.0272 0x0844 pcw - ok15:23:55.0356 0x0844 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884

    DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys15:23:55.0427 0x0844 PEAUTH - ok15:23:55.0595 0x0844 [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll15:23:55.0760 0x0844 PeerDistSvc - ok15:23:56.0153 0x0844 [ 9C1BFF7910C89A1D12E57343475840CB, 62E00E1278BD263B2AC8CB803C31F2818C54DB143C49470FAD07731E04BD2DE3 ] pla C:\Windows\system32\pla.dll15:23:56.0346 0x0844 pla - ok15:23:56.0479 0x0844 [ 71DEF5EC79774C798342D0EA16E41780, 5B5A365E57A7ACE3C4EDA1D891BD613879B284831E8253FDE498E40B2091E3B6 ] PlugPlay C:\Windows\system32

    \umpnpmgr.dll15:23:56.0550 0x0844 PlugPlay - ok15:23:56.0606 0x0844 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll15:23:56.0631 0x0844 PNRPAutoReg - ok15:23:56.0696 0x0844 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll15:23:56.0751 0x0844 PNRPsvc - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    19/32

    15:23:56.0832 0x0844 [ 48E1B75C6DC0232FD92BAAE4BD344721, 5BA4EB5A60725836D8085EABF87F51160BA57E318A0C4378410217911A393CE7 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll15:23:56.0879 0x0844 PolicyAgent - ok15:23:56.0956 0x0844 [ DBFF83F709A91049621C1D35DD45C92C, 0A722A44F431CAB5EA77FF5F25EB6975C2111B605564FF9FB59751067E7CD3A7 ] Power C:\Windows\system32\umpo.dll15:23:57.0010 0x0844 Power - ok15:23:57.0064 0x0844 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys15:23:57.0074 0x0844 PptpMiniport - ok15:23:57.0118 0x0844 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys15:23:57.0126 0x0844 Processor - ok15:23:57.0216 0x0844 [ AEA3BDBDBA667AA6F678CB38907E4F5E, AB698DCA117F8D5F22F9CD8D7884147BAB4E0C055B8A487BC035C18ED1634752 ] ProfSvc C:\Windows\system32\profsvc.dll15:23:57.0257 0x0844 ProfSvc - ok15:23:57.0290 0x0844 [ C2243FF9E9AAD0C30E8B1A0914DA15B6, CD01BD44659FDAA6FE8679D0F76748409680A4F4885905EA56F655C60DDEC01F ] ProtectedStorage C:\Windows\system32\lsass.exe15:23:57.0304 0x0844 ProtectedStorage - ok

    15:23:57.0352 0x0844 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys15:23:57.0367 0x0844 Psched - ok15:23:57.0588 0x0844 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys15:23:57.0783 0x0844 ql2300 - ok15:23:57.0858 0x0844 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys15:23:57.0878 0x0844 ql40xx - ok15:23:57.0955 0x0844 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7

    676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll15:23:58.0013 0x0844 QWAVE - ok15:23:58.0122 0x0844 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys15:23:58.0134 0x0844 QWAVEdrv - ok15:23:58.0182 0x0844 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys15:23:58.0188 0x0844 RasAcd - ok15:23:58.0236 0x0844 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32

    \DRIVERS\AgileVpn.sys15:23:58.0247 0x0844 RasAgileVpn - ok15:23:58.0278 0x0844 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll15:23:58.0302 0x0844 RasAuto - ok15:23:58.0338 0x0844 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys15:23:58.0348 0x0844 Rasl2tp - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    20/32

    15:23:58.0435 0x0844 [ 0CE66EC736B7FC526D78F7624C7D2A94, D70B45AA413691CF84B24E966EBA1689955E54BDDA206380CAB7CD50F56D5CEB ] RasMan C:\Windows\System32\rasmans.dll15:23:58.0475 0x0844 RasMan - ok15:23:58.0498 0x0844 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys15:23:58.0510 0x0844 RasPppoe - ok15:23:58.0546 0x0844 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys15:23:58.0558 0x0844 RasSstp - ok15:23:58.0616 0x0844 [ 835D7E81BF517A3B72384BDCC85E1CE6, DC855AF17150C1B27926293115C01B5E1FD00FABCE18AFAEAB3DC68BDE4C908B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys15:23:58.0643 0x0844 rdbss - ok15:23:58.0708 0x0844 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys15:23:58.0718 0x0844 rdpbus - ok15:23:58.0750 0x0844 [ 1E016846895B15A99F9A176A05029075, 78AE674B6E7D3A69099B24AC07E06563A4C867F9DCD8548E4DAAE6FC5ACA4E29 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys15:23:58.0755 0x0844 RDPCDD - ok

    15:23:58.0856 0x0844 [ C5FF95883FFEF704D50C40D21CFB3AB5, 26CC53DDE126A6BD99F606695F063BB7FDC4BBABB9F75F7AD7A84B58C837EEAA ] RDPDR C:\Windows\system32\drivers\rdpdr.sys15:23:58.0870 0x0844 RDPDR - ok15:23:58.0909 0x0844 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys15:23:58.0914 0x0844 RDPENCDD - ok15:23:59.0194 0x0844 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys15:23:59.0198 0x0844 RDPREFMP - ok15:23:59.0297 0x0844 [ C5B8D47A4688DE9D335204EA757C2240, 2F646466120911B0CA0E33

    1B4959A470E18DFD51C8FAAB69BE0461C31D52DBBE ] RDPWD C:\Windows\system32\drivers\RDPWD.sys15:23:59.0341 0x0844 RDPWD - ok15:23:59.0438 0x0844 [ 4EA225BF1CF05E158853F30A99CA29A7, F211480F13E2FE36C31110AE67ABE74E9D572D3A36BEEDE29E14ECBD8C246878 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys15:23:59.0461 0x0844 rdyboost - ok15:23:59.0611 0x0844 [ 96EFEC24346A8EB1157E80523079ADDC, 7F8FC284029856C754E400B6C954369FFE27763C81D8F4AF4E58BFDD44CBC24A ] RealNetworks Downloader Resolver Service C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe15:23:59.0645 0x0844 RealNetworks Downloader Resolver Service - ok15:23:59.0775 0x0844 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32

    \mprdim.dll15:23:59.0802 0x0844 RemoteAccess - ok15:23:59.0876 0x0844 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll15:23:59.0899 0x0844 RemoteRegistry - ok15:24:00.0077 0x0844 [ 83A6C2CAFE236652D1559640594A0EA8, 52360F17C9C70C9CEA3316560B40C4D89FD705ED7E6B6088C99FC54D4CC35EB5 ] rpcapd C:\Program Files\WinPcap\rpcapd.exe15:24:00.0088 0x0844 rpcapd - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    21/32

    15:24:00.0136 0x0844 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll15:24:00.0157 0x0844 RpcEptMapper - ok15:24:00.0275 0x0844 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe15:24:00.0288 0x0844 RpcLocator - ok15:24:00.0522 0x0844 [ B82CD39E336973359D7C9BF911E8E84F, 45DB8F1E88FC25A81D2F3C2F8A8CDB6B34C44950B038E24FB71DCDD9823DB22A ] RpcSs C:\Windows\system32\rpcss.dll15:24:00.0622 0x0844 RpcSs - ok15:24:00.0699 0x0844 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys15:24:00.0707 0x0844 rspndr - ok15:24:00.0804 0x0844 [ FD731DD23A6C846A848BEA67DAEB70CA, 74D0A6626C8CD50585B08AA62976C3D012B8F440A670C9AEEEF71B3D0D484954 ] RSUSBVSTOR C:\Windows\system32\Drivers\RtsUVStor.sys15:24:00.0824 0x0844 RSUSBVSTOR - ok15:24:00.0963 0x0844 [ 568C33723F09B341A11800D5EEA02038, F61CAAD43493EEC67ABFB31FED465BD0AE3935915751FC8D76955CD39B814AF6 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys15:24:01.0015 0x0844 RTL8167 - ok

    15:24:01.0145 0x0844 [ 5423D8437051E89DD34749F242C98648, 28FD190E13676B0FD452A73C3069B72206E2938DB2240BAA9BDB56687C748A2B ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys15:24:01.0155 0x0844 s3cap - ok15:24:01.0207 0x0844 [ C2243FF9E9AAD0C30E8B1A0914DA15B6, CD01BD44659FDAA6FE8679D0F76748409680A4F4885905EA56F655C60DDEC01F ] SamSs C:\Windows\system32\lsass.exe15:24:01.0226 0x0844 SamSs - ok15:24:01.0273 0x0844 [ 34EE0C44B724E3E4CE2EFF29126DE5B5, D27AAF77CB8830893558A600E19CDBF9A6AA7D69DE4B34F317ED4AFD38E8CAFB ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys15:24:01.0292 0x0844 sbp2port - ok15:24:01.0350 0x0844 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD197

    7F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll15:24:01.0405 0x0844 SCardSvr - ok15:24:01.0438 0x0844 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51, 8C0189A6AF9AEC46CBA4DA422C52B2D3E4858B2F2658DB6CA7996B5F368D2503 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys15:24:01.0446 0x0844 scfilter - ok15:24:01.0700 0x0844 [ DF1E5C82E4D09CF8105CC644980C4803, 36BB8402B29466CF1AE5BD56ED6CF6FE47DE162ADF04D44E2BCEA168CB0BD4D4 ] Schedule C:\Windows\system32\schedsvc.dll15:24:01.0900 0x0844 Schedule - ok15:24:02.0011 0x0844 [ 628A9E30EC5E18DD5DE6BE4DBDC12198, DDA43DCCB195440D6BD5752BD00D984F45BD6D23DBE2A656C33E3CD1E5D17AD7 ] SCPolicySvc C:\Windows\System32

    \certprop.dll15:24:02.0019 0x0844 SCPolicySvc - ok15:24:02.0114 0x0844 [ 5FD90ABDBFAEE85986802622CBB03446, 0A8D9DC09C2ACA9EAABED04737E9EBF6EFB92BB2B9E5F37F10BFDF47CBF7DEDB ] SDRSVC C:\Windows\System32\SDRSVC.dll15:24:02.0156 0x0844 SDRSVC - ok15:24:02.0253 0x0844 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys15:24:02.0266 0x0844 secdrv - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    22/32

    15:24:02.0317 0x0844 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll15:24:02.0354 0x0844 seclogon - ok15:24:02.0425 0x0844 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll15:24:02.0478 0x0844 SENS - ok15:24:02.0554 0x0844 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll15:24:02.0573 0x0844 SensrSvc - ok15:24:02.0616 0x0844 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys15:24:02.0623 0x0844 Serenum - ok15:24:02.0688 0x0844 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys15:24:02.0704 0x0844 Serial - ok15:24:02.0741 0x0844 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys15:24:02.0751 0x0844 sermouse - ok

    15:24:02.0973 0x0844 [ C3BB6CF8F9EE199005A2AAE2815AD756, 7A817599C2F3AD819D643223AA714CCCB790EE5983096D8D9CD2D626D6924837 ] ServiceLayer C:\Program Files\PCConnectivity Solution\ServiceLayer.exe15:24:03.0069 0x0844 ServiceLayer - ok15:24:03.0226 0x0844 [ 8F55CE568C543D5ADF45C409D16718FC, 64D45854A91B656C1AF36EB272FDC54E9B5FB0200CB93E20F7D997DDA109EF7F ] SessionEnv C:\Windows\system32\sessenv.dll15:24:03.0256 0x0844 SessionEnv - ok15:24:03.0307 0x0844 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys15:24:03.0316 0x0844 sffdisk - ok15:24:03.0343 0x0844 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF

    7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys15:24:03.0352 0x0844 sffp_mmc - ok15:24:03.0402 0x0844 [ 4F1E5B0FE7C8050668DBFADE8999AEFB, E36DAACC3D11F004808A3F44C471BBFDC2F33411D9F5C18B55B0DB2A6DA6E74C ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys15:24:03.0409 0x0844 sffp_sd - ok15:24:03.0444 0x0844 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys15:24:03.0451 0x0844 sfloppy - ok15:24:03.0527 0x0844 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32

    \ipnathlp.dll15:24:03.0567 0x0844 SharedAccess - ok15:24:03.0651 0x0844 [ CD2E48FA5B29EE2B3B5858056D246EF2, B743F92D0121CF3D827753C85F1F5A14C2DAA1CAFD42C7810C3BECB853DB6175 ] ShellHWDetection C:\Windows\System32\shsvcs.dll15:24:03.0710 0x0844 ShellHWDetection - ok15:24:03.0772 0x0844 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys15:24:03.0782 0x0844 sisagp - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    23/32

    15:24:03.0866 0x0844 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys15:24:03.0873 0x0844 SiSRaid2 - ok15:24:03.0943 0x0844 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys15:24:03.0954 0x0844 SiSRaid4 - ok15:24:04.0079 0x0844 [ 50D9949020E02B847CD48F1243FCB895, 5BDAD5E44DE5B412645142810C5FCE4B2D9685F928FF4A6B836A9DCE7725BD78 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe15:24:04.0097 0x0844 SkypeUpdate - ok15:24:04.0179 0x0844 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys15:24:04.0190 0x0844 Smb - ok15:24:04.0321 0x0844 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe15:24:04.0338 0x0844 SNMPTRAP - ok15:24:04.0505 0x0844 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys15:24:04.0512 0x0844 spldr - ok

    15:24:04.0648 0x0844 [ E17323B0AA9FB3FF9945731D736EDA2F, 65837FC6329A4B2B042B0CDB04F139CA14C2BD1EE0CDB2C7705431E9D97D0597 ] Spooler C:\Windows\System32\spoolsv.exe15:24:04.0702 0x0844 Spooler - ok15:24:05.0577 0x0844 [ 4C287F9069FEDBD791178876EE9DE536, 6099E76FF6FBA002EBA2BA7BE4E3238D91332E077524D1DD402E0C9ADA22E852 ] sppsvc C:\Windows\system32\sppsvc.exe15:24:06.0144 0x0844 sppsvc - ok15:24:06.0241 0x0844 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7, E7A8A5774C62DC12B56DC3E0A385ACA9069F3A5E6AC664AD0C383EF44DCF81B3 ] sppuinotify C:\Windows\system32\sppuinotify.dll15:24:06.0268 0x0844 sppuinotify - ok15:24:06.0367 0x0844 [ C4A027B8C0BD3FC0699F41FA5E9E0C87, A709BD7DDF0ACA5CF65B5A

    541FC6013FF86181138B86D1BF631E4BF5F4F2E266 ] srv C:\Windows\system32\DRIVERS\srv.sys15:24:06.0417 0x0844 srv - ok15:24:06.0566 0x0844 [ 414BB592CAD8A79649D01F9D94318FB3, 093F52568B48E94B6C53F2E7F229416B8643DD9CEBB3E41601C64E932E3098F3 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys15:24:06.0592 0x0844 srv2 - ok15:24:06.0622 0x0844 [ FF207D67700AA18242AAF985D3E7D8F4, CFB36B6AA3D6915D23654FB11E848EC47DA8346F47151BE66967E51101FD4222 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys15:24:06.0641 0x0844 srvnet - ok15:24:06.0698 0x0844 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32

    \ssdpsrv.dll15:24:06.0734 0x0844 SSDPSRV - ok15:24:06.0760 0x0844 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll15:24:06.0792 0x0844 SstpSvc - ok15:24:06.0968 0x0844 [ 585FDB94DB04AC1C56298D1FD1F1389E, 5CEBAAF3B649E580B3EF2B9B38426D6EE13B244BE1274BA0C0A468EC4CFB680C ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys15:24:07.0026 0x0844 ssudmdm - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    24/32

    15:24:07.0125 0x0844 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys15:24:07.0133 0x0844 stexstor - ok15:24:07.0290 0x0844 [ A22825E7BB7018E8AF3E229A5AF17221, 5C97557F8BC6ABBB5BE624AE41AAC22C3D845F76C3E930337A4C07B2381086D7 ] StiSvc C:\Windows\System32\wiaservc.dll15:24:07.0373 0x0844 StiSvc - ok15:24:07.0470 0x0844 [ 957E346CA948668F2496A6CCF6FF82CC, 5C0E0F0E0F2D36E3213885C60BC3B075AFD2257FEB4B8186FC1FE253E0C218AF ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys15:24:07.0485 0x0844 storflt - ok15:24:07.0533 0x0844 [ D5751969DC3E4B88BF482AC8EC9FE019, DAEB50C0045364C75965B0E94744C6E2E1E85C8D00F1E8A5593F3EC780BDD7D9 ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys15:24:07.0541 0x0844 storvsc - ok15:24:07.0589 0x0844 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\DRIVERS\swenum.sys15:24:07.0598 0x0844 swenum - ok15:24:07.0812 0x0844 [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe15:24:07.0882 0x0844 SwitchBoard - ok

    15:24:07.0968 0x0844 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll15:24:08.0022 0x0844 swprv - ok15:24:08.0197 0x0844 [ 04105C8DA62353589C29BDAEB8D88BD8, CC7A3A779A143E09FE5C0AA6795A7B13496C4E121347949CB23F7946EE5E2DED ] SysMain C:\Windows\system32\sysmain.dll15:24:08.0380 0x0844 SysMain - ok15:24:08.0459 0x0844 [ FCFB6C552FBC0DA299799CBD50AD9FD4, A2A90829087B1A7F9B57D6F184EB4AE38D10B2986B0DC8D2ACA5EE9412CA3976 ] TabletInputService C:\Windows\System32\TabSvc.dll15:24:08.0484 0x0844 TabletInputService - ok15:24:08.0539 0x0844 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF, FF66CBA014F3F8B721088F

    5AB3D004C1711E7F587CC8D4AC3DCFB45CDB746800 ] TapiSrv C:\Windows\System32\tapisrv.dll15:24:08.0593 0x0844 TapiSrv - ok15:24:08.0639 0x0844 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll15:24:08.0671 0x0844 TBS - ok15:24:09.0201 0x0844 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD, D06B2B340BFF9AB71E2EC1B808079A43A09358495CB583840D79454D4BB1654E ] Tcpip C:\Windows\system32\drivers\tcpip.sys15:24:09.0440 0x0844 Tcpip - ok15:24:09.0832 0x0844 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD, D06B2B340BFF9AB71E2EC1B808079A43A09358495CB583840D79454D4BB1654E ] TCPIP6 C:\Windows\system32

    \DRIVERS\tcpip.sys15:24:10.0135 0x0844 TCPIP6 - ok15:24:10.0508 0x0844 [ E64444523ADD154F86567C469BC0B17F, FBE8A1DC28C102068183754F6BF0D03F5D18FD24BEB7E4B57D1CFCEBB13B381F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys15:24:10.0559 0x0844 tcpipreg - ok15:24:10.0792 0x0844 [ 1875C1490D99E70E449E3AFAE9FCBADF, FFDF03826DAB748D51B53B648B632E79B3CD6238F684FDEA749B4D0F93BE5A77 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys15:24:10.0859 0x0844 TDPIPE - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    25/32

    15:24:11.0044 0x0844 [ 7156308896D34EA75A582F9A09E50C17, B5663B4035EE4D7957D2EDB4F9D3342806CB0E094D9661C6BD6AFC031160F176 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys15:24:11.0050 0x0844 TDTCP - ok15:24:11.0109 0x0844 [ CB39E896A2A83702D1737BFD402B3542, FA77D98EA3606CA2FCEF0E0949FDE2C32A080B47CAFDE46CE903CA3CBFC5DF35 ] tdx C:\Windows\system32\DRIVERS\tdx.sys15:24:11.0125 0x0844 tdx - ok15:24:11.0151 0x0844 [ C36F41EE20E6999DBF4B0425963268A5, 9DB789A17DF2C283D6E803EEA15F2BDFC56EE3BE342A5606DD5C179C3550ECA6 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys15:24:11.0159 0x0844 TermDD - ok15:24:11.0432 0x0844 [ A01E50A04D7B1960B33E92B9080E6A94, 0512BF11F2FD62BDBD2B1AA34D509BE82AC374C37B925C8C0ED119C6331930FD ] TermService C:\Windows\System32\termsrv.dll15:24:11.0616 0x0844 TermService - ok15:24:11.0683 0x0844 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll15:24:11.0707 0x0844 Themes - ok15:24:11.0836 0x0844 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll15:24:11.0863 0x0844 THREADORDER - ok

    15:24:11.0967 0x0844 [ 2BFE28BBF9B5D7E68BF6E0ABE9B44248, E917684730A1381CFB84E2DF2F3306CD7AEF3D4B3964947ECD95973321F76588 ] TotRec7 C:\Windows\system32\drivers\TotRec7.sys15:24:12.0025 0x0844 TotRec7 - ok15:24:12.0166 0x0844 [ 6D7EB4AAB1A31AD47957E97ABD849DC8, FA5A275AFBFEAA826C4506053EE347F74D42F6999B1B6BCC5A098EFB9D1CF84C ] TotRec8 C:\Windows\system32\drivers\TotRec8.sys15:24:12.0177 0x0844 TotRec8 - ok15:24:12.0289 0x0844 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll15:24:12.0370 0x0844 TrkWks - ok15:24:12.0509 0x0844 [ 41A4C781D2286208D397D72099304133, 447CAAD5589AA499EEE49F

    BA2CB53210359DB76AFF1DF2F0BD4D92A397037C1D ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe15:24:12.0533 0x0844 TrustedInstaller - ok15:24:12.0613 0x0844 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242, 9606DACB8CBDAF520282BE8C8F064535767405F138D9E9A215D2C59183E93CC1 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys15:24:12.0630 0x0844 tssecsrv - ok15:24:12.0720 0x0844 [ 3E461D890A97F9D4C168F5FDA36E1D00, 82A8778F404F7AC5102802CF46F279F1E58AC74244665D06FD0C68A8BD887536 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys15:24:12.0748 0x0844 tunnel - ok15:24:12.0859 0x0844 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32

    \DRIVERS\uagp35.sys15:24:12.0888 0x0844 uagp35 - ok15:24:12.0984 0x0844 [ 09CC3E16F8E5EE7168E01CF8FCBE061A, 81EEAC72A7C4D72666C743DEFF8096FDB465AA1FA8076C60D19CC192846F01CA ] udfs C:\Windows\system32\DRIVERS\udfs.sys15:24:13.0092 0x0844 udfs - ok15:24:13.0325 0x0844 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe15:24:13.0441 0x0844 UI0Detect - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    26/32

    15:24:13.0485 0x0844 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys15:24:13.0493 0x0844 uliagpkx - ok15:24:13.0589 0x0844 [ 049B3A50B3D646BAEEEE9EEC9B0668DC, 5774438BBD0976424C20559E14BA2AC158D9FF5D4E1FDC1C9C9F4D7A5CE8C377 ] umbus C:\Windows\system32\DRIVERS\umbus.sys15:24:13.0597 0x0844 umbus - ok15:24:13.0667 0x0844 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys15:24:13.0674 0x0844 UmPass - ok15:24:13.0790 0x0844 [ 8ECACA5454844F66386F7BE4AE0D7CD1, F3B02A9F598C6A9EFA019F5833959DD1A86FDFDB9FDDF99A8687BBB6211AAD00 ] UmRdpService C:\Windows\System32\umrdp.dll15:24:13.0847 0x0844 UmRdpService - ok15:24:13.0940 0x0844 [ BB879DCFD22926EFBEB3298129898CBB, 2A24E6CD5D6E0CEA3082C0699A2371084CC1268B31BC714098EA0D0C11B3AFAC ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys15:24:13.0954 0x0844 UnlockerDriver5 - ok15:24:14.0088 0x0844 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll15:24:14.0156 0x0844 upnphost - ok

    15:24:14.0277 0x0844 [ 47F5F9D837D80FFD5882A14DB9DA0A67, 3B32E69B77E21CF98ED6E97B231B9633BE39D74328152EDFA7656FB16E3FF93A ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys15:24:14.0285 0x0844 upperdev - ok15:24:14.0469 0x0844 [ C31AE588E403042632DC796CF09E30B0, 3EA64F9637D6F0AFC9DA70775AC6598828CB289BC1F7B028B3CC22878A443F30 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys15:24:14.0512 0x0844 usbccgp - ok15:24:14.0614 0x0844 [ 04EC7CEC62EC3B6D9354EEE93327FC82, 6CB41D8644618A5F701F6CA91FB65BB94AA83EA48992133B5262DC539B334B2E ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys15:24:14.0624 0x0844 usbcir - ok15:24:14.0762 0x0844 [ E4C436D914768CE965D5E659BA7EEBD8, 4FE0B360D2FE4C8B1D3FA5

    BD9A0E24CA6C186CD99B72EA58F6B669FABB0B1269 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys15:24:14.0772 0x0844 usbehci - ok15:24:14.0858 0x0844 [ 04322AECFC8718883EE3A0FE21FB5B70, F2AEE1999E9ACA8D4D61B0FC165EB22827892BB1E6B93E3B86694101AD06DA9C ] usbfilter C:\Windows\system32\DRIVERS\usbfilter.sys15:24:14.0866 0x0844 usbfilter - ok15:24:15.0144 0x0844 [ BDCD7156EC37448F08633FD899823620, 557A6E8B1CD43213FCCB247DEC9EEBC12F263DA13CFF72DEE724E830F7F22C33 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys15:24:15.0293 0x0844 usbhub - ok15:24:15.0390 0x0844 [ EB2D819A639015253C871CDA09D91D58, E65757F3D162F26012BF9E16ECA0688BBCAE633AFFD1CE07083A3306376A4E82 ] usbohci C:\Windows\system32

    \DRIVERS\usbohci.sys15:24:15.0396 0x0844 usbohci - ok15:24:15.0482 0x0844 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys15:24:15.0490 0x0844 usbprint - ok15:24:15.0658 0x0844 [ 88701ECA76145E2C011C0EEFF0F7B70E, 1902E901E0E2548F100872F7E59C6A7FADA9E8A9F28810D7405B4F51B44FD4B4 ] usbser C:\Windows\system32\drivers\usbser.sys15:24:15.0671 0x0844 usbser - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    27/32

    15:24:15.0800 0x0844 [ E44F0D17BE0908B58DCC99CCB99C6C32, 6C5E62A688CD3A299FBE2C8CD87F2A860340CDE4616348D83C6FB3DDB561E6C9 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys15:24:15.0808 0x0844 UsbserFilt - ok15:24:15.0961 0x0844 [ 1C4287739A93594E57E2A9E6A3ED7353, FCA7D01D7A699B2C3514FD30D534C9ABA975D4AC2543546D94BEB224834BCA54 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS15:24:16.0134 0x0844 USBSTOR - ok15:24:16.0354 0x0844 [ 22480BF4E5A09192E5E30BA4DDE79FA4, E5CB29CD419009AC0F641E50E8B0E0B7FF6AD68ADB48A959FFD07A37FCF7B9BE ] usbuhci C:\Windows\system32\drivers\usbuhci.sys15:24:16.0436 0x0844 usbuhci - ok15:24:16.0775 0x0844 [ B5F6A992D996282B7FAE7048E50AF83A, CE8A3096DB78BD7E660A7B544AD3EE25AE747B3A63359D55B480B7FF1B6BEE8B ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys15:24:16.0801 0x0844 usbvideo - ok15:24:16.0893 0x0844 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll15:24:16.0918 0x0844 UxSms - ok15:24:16.0952 0x0844 [ C2243FF9E9AAD0C30E8B1A0914DA15B6, CD01BD44659FDAA6FE8679D0F76748409680A4F4885905EA56F655C60DDEC01F ] VaultSvc C:\Windows\system32\lsass.exe15:24:16.0969 0x0844 VaultSvc - ok

    15:24:17.0508 0x0844 [ FC27A8404D680F2E89F7E2EA68D097FB, 5D137C8BE0F45E7F23B2DD90AA95634CA351254AF9676D161E550656354194B4 ] VBoxAswDrv C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys15:24:17.0556 0x0844 VBoxAswDrv - ok15:24:17.0627 0x0844 [ CB8DDC06FE676D9C1A6447997DE72631, E0D9CFE8FF42CD9B8D027AF512AF5BBA02CAE8B35C4904052999E60F0A6C02DE ] VBoxNetAdp C:\Windows\system32\DRIVERS\VBoxNetAdp.sys15:24:17.0651 0x0844 VBoxNetAdp - ok15:24:17.0708 0x0844 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys15:24:17.0719 0x0844 vdrvroot - ok15:24:17.0822 0x0844 [ 8C4E7C49D3641BC9E299E466A7F8867D, 4F2E742EFE2DE47EE187B3

    BCDFDCB525FE484B74700A226D7894F9633F957AFA ] vds C:\Windows\System32\vds.exe15:24:17.0969 0x0844 vds - ok15:24:18.0038 0x0844 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys15:24:18.0045 0x0844 vga - ok15:24:18.0089 0x0844 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys15:24:18.0102 0x0844 VgaSave - ok15:24:18.0189 0x0844 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583, 33DF8F7C9A3176175113CA10D69FAF17A5412C055943F14DDC9923531FADB82D ] vhdmp C:\Windows\system32

    \DRIVERS\vhdmp.sys15:24:18.0210 0x0844 vhdmp - ok15:24:18.0314 0x0844 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys15:24:18.0334 0x0844 viaagp - ok15:24:18.0377 0x0844 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys15:24:18.0387 0x0844 ViaC7 - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    28/32

    15:24:18.0655 0x0844 [ FB711C2F013E20A348D76136647E0127, ECA3F3AC59220476A04002E66DEF495EFB4AF2716B65CC378C3EECDEB4D5546A ] vm331avs C:\Windows\system32\Drivers\vm331avs.sys15:24:19.0020 0x0844 vm331avs - ok15:24:19.0102 0x0844 [ 379B349F65F453D2A6E75EA6B7448E49, F52B1B3AE9F5D38B45C889A7B1EBE59533C17E73678D355D1466B5EF3338BF16 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys15:24:19.0141 0x0844 vmbus - ok15:24:19.0184 0x0844 [ EC2BBAB4B84D0738C6C83D2234DC36FE, 8BA2FA187DAC6994D5A29897AE5F46E6424FB53C827553E0BB148E31825D6676 ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys15:24:19.0191 0x0844 VMBusHID - ok15:24:19.0243 0x0844 [ 384E5A2AA49934295171E499F86BA6F3, C79271F98506392422325C075144F45436F9979FE1E002B57F9426F3DA96CEF0 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys15:24:19.0262 0x0844 volmgr - ok15:24:19.0308 0x0844 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys15:24:19.0340 0x0844 volmgrx - ok15:24:19.0386 0x0844 [ 59F06B4968E58BC83DFC56CA4517960E, F0ACE8D5F30B8C81E4FDE0CEBDBA71A212A3198ED09D92B2B40C48FBB243D3F5 ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys15:24:19.0415 0x0844 volsnap - ok

    15:24:19.0672 0x0844 [ 4A898D59BE5A015B4EE72FA13FD2A424, 80487CC53C8F408CA8F000670ADE7133E27B7BCEDD98330375258040E488BE19 ] VRSService C:\Program Files\NCH Software\VRS\vrs.exe15:24:19.0869 0x0844 VRSService - ok15:24:20.0055 0x0844 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C, 7CD6637BE0A08E3B0F9991D79751DCA8AEC9224B83301821DAA29C9F42B7A9E3 ] VSS C:\Windows\system32\vssvc.exe15:24:20.0369 0x0844 VSS - ok15:24:20.0410 0x0844 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys15:24:20.0420 0x0844 vwifibus - ok15:24:20.0460 0x0844 [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596

    C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys15:24:20.0473 0x0844 vwififlt - ok15:24:20.0522 0x0844 [ A3F04CBEA6C2A10E6CB01F8B47611882, 32AFE18B07FECA30BC95831A5DC94C784E543784DF16165334A777DC84E91EF3 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys15:24:20.0527 0x0844 vwifimp - ok15:24:20.0592 0x0844 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll15:24:20.0727 0x0844 W32Time - ok15:24:20.0825 0x0844 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32

    \DRIVERS\wacompen.sys15:24:20.0838 0x0844 WacomPen - ok15:24:20.0877 0x0844 [ 692A712062146E96D28BA0B7D75DE31B, B6D260272330E0C8EBFAD8F09212F48F1EFED42E6BD3F29A5780D0B691D55B34 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys15:24:20.0897 0x0844 WANARP - ok15:24:20.0915 0x0844 [ 692A712062146E96D28BA0B7D75DE31B, B6D260272330E0C8EBFAD8F09212F48F1EFED42E6BD3F29A5780D0B691D55B34 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys15:24:20.0922 0x0844 Wanarpv6 - ok

  • 7/25/2019 TDSSKiller.3.1.0.9_16.06.2016_15.22.20_log

    29/32

    15:24:21.0106 0x0844 [ 7790B77FE1E5EE47DCC66247095BB4C9, FFB541F83CDE32E65007D41217C2F46CDDF68121E2846B638EAB620ACA940B05 ] wbengine C:\Windows\system32\wbengine.exe15:24:21.0404 0x0844 wbengine - ok15:24:21.0460 0x0844 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll15:24:21.0509 0x0844 WbioSrvc - ok15:24:21.0603 0x0844 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6, 0805471A57DDF1974F3F7B36B0DD843731C608D10A1C00B01E6E9D0460098E1A ] wcncsvc C:\Windows\System32\wcncsvc.dll15:24:21.0665 0x0844 wcncsvc - ok15:24:21.0717 0x0844 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll15:24:21.0763 0x0844 WcsPlugInService - ok15:24:21.0820 0x0844 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys15:24:21.0827 0x0844 Wd - ok15:24:21.0943 0x0844 [ A840213F1ACDCC175B4D1D5AAEAC0D7A, B20F7CAEEA790290072BC170EBEEADB4C19E1C40DB0B3FE0D4A640D0D82300D6 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys15:24:21.0989 0x0844 Wdf01000 - ok

    15:24:22.0099 0x0844 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll15:24:22.0299 0x0844 WdiServiceHost - ok15:24:22.0355 0x0844 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\s