1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
  2. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Cannot boot Win7; missing BitDefender driver

Discussion in 'Malware and Virus Removal' started by supersix, 2018/05/13.

  1. 2018/05/13
    supersix

    supersix New Member Thread Starter

    Joined:
    2018/05/13
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    1
    Computer Experience:
    Experienced
    I have a Windows 7 PC that unexpectedly refused to boot, seemingly because the boot directory was removed and/or corrupted (potentially targeted by malware). After finally getting the boot directory rebuilt (at least I think it is...), I'm receiving the following error when I attempt to boot (both in Normal and Safe Mode):

    Windows failed to start. A recent hardware or software change might be the cause. To fix the problem:
    1. Insert your Windows installation disc and restart your computer.
    2. Choose your language settings, and then click "Next."
    3. Click "Repair your computer."

    If you do not have this disc, contact your system administrator or computer manufacturer for assistance.

    File: \Windows\system32\DRIVERS\trufos.sys
    Status: 0xc0000221
    Info: Windows failed to load because a critical system driver is missing, or corrupt.

    I believe "trufos" is a driver related to the BitDefender anti-virus client installed on the machine, and it sounds like the absence or corruption of this file is preventing Windows from booting. After some Googling, it sounds like this thread was related to a similar issue and was able to be resolved.

    Anyways, I ran Farbar Recovery Scan Tool (with the "List BCD" option selected) and got the following results:

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12.05.2018
    Ran by SYSTEM on MININT-HT3V8MF (13-05-2018 20:07:42)
    Running from F:\
    Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Recovery
    Default: ControlSet001
    ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

    Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [404376 2015-08-09] ()
    HKLM\...\Run: [HotKeysCmds] => "C:\Windows\system32\hkcmd.exe"
    HKLM\...\Run: [Persistence] => "C:\Windows\system32\igfxpers.exe"
    HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-07-30] (Intel Corporation)
    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7194840 2013-07-26] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-07-29] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-07-29] (Realtek Semiconductor)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
    HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (CANON INC.)
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4174464 2017-05-23] (Safer-Networking Ltd.)
    Winlogon\Notify\igfxcui: igfxdev.dll [X]
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [132736 2013-07-02] (Qualcomm®Atheros®)
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [312448 2013-07-02] (Windows (R) Win 7 DDK provider)
    S2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [97616 2017-01-11] (Dell)
    S2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [79552 2016-03-08] (Bitdefender)
    S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-07-30] (Intel Corporation)
    S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [355232 2015-08-09] (Intel Corporation)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
    S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-09] (Intel Corporation)
    S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
    S2 MSSQL$UPSWSDBSERVER; c:\PROGRAM FILES (X86)\UPS\WSTD\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
    S2 Printer DCA; C:\Program Files (x86)\Printer DCA\PrinterDCA.Service.exe [80416 2017-11-27] (PrintFleet Inc)
    S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor)
    S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1776864 2017-05-23] (Safer-Networking Ltd.)
    S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2131760 2017-05-23] (Safer-Networking Ltd.)
    S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233936 2017-05-23] (Safer-Networking Ltd.)
    S2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [2005392 2015-02-11] (SoftThinks SAS)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2015-01-06] (Microsoft Corporation)
    S2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [81536 2013-06-21] (Atheros)

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [718840 2013-04-17] (BitDefender)
    S5 avchv; C:\Windows\System32\Drivers\avchv.sys [261056 2012-11-02] (BitDefender)
    S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [593144 2013-04-17] (BitDefender)
    S1 bdfwfpf; C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [121928 2013-07-02] (Bitdefender SRL)
    S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-07-02] (Qualcomm Atheros)
    S1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [76192 2018-03-19] ()
    S3 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [148696 2013-04-22] (BitDefender LLC)
    S0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2013-07-24] (Intel Corporation)
    S2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193768 2018-04-15] (Malwarebytes)
    S3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [112864 2018-04-26] (Malwarebytes)
    S0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-04-15] (Malwarebytes)
    S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2013-12-09] (Intel Corporation)
    S0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [382536 2013-05-28] (BitDefender S.R.L.)
    S3 MFE_RR; \??\C:\Users\SUSAN~1.SEL\AppData\Local\Temp\mfe_rr.sys [X] <==== ATTENTION

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-05-13 20:05 - 2018-05-13 20:07 - 000000000 ____D C:\FRST
    2018-05-13 15:57 - 2010-11-20 19:23 - 000383786 __RSH C:\bootmgr
    2018-05-13 15:20 - 2018-05-13 15:51 - 000024576 _____ C:\bcdbackup
    2018-05-08 23:28 - 2018-05-08 23:28 - 000382536 _____ (BitDefender S.R.L.) C:\Windows\System32\Drivers\trufos.sys.upd
    2018-05-08 22:54 - 2018-04-21 23:27 - 000615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2018-05-08 22:54 - 2018-04-21 23:00 - 000152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
    2018-05-08 22:54 - 2018-04-21 22:55 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2018-05-08 22:54 - 2018-04-21 22:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2018-05-08 22:53 - 2018-04-21 23:38 - 000417280 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
    2018-05-08 22:53 - 2018-04-21 23:37 - 000088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
    2018-05-08 22:53 - 2018-04-21 23:31 - 000054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2018-05-08 22:53 - 2018-04-21 23:15 - 000489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
    2018-05-08 22:53 - 2018-04-21 23:08 - 000087552 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx
    2018-05-08 22:53 - 2018-04-21 23:08 - 000077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
    2018-05-08 22:53 - 2018-04-21 23:03 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2018-05-08 22:53 - 2018-04-21 23:02 - 000315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
    2018-05-08 22:53 - 2018-04-21 23:02 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2018-05-08 22:53 - 2018-04-21 22:45 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2018-05-08 22:53 - 2018-04-21 22:40 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
    2018-05-08 22:53 - 2018-04-21 22:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2018-05-08 22:53 - 2018-03-14 09:07 - 000091136 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll
    2018-05-08 22:52 - 2018-04-23 10:57 - 000396960 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2018-05-08 22:52 - 2018-04-23 10:02 - 000348832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2018-05-08 22:52 - 2018-04-21 23:53 - 002724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2018-05-08 22:52 - 2018-04-21 23:53 - 000004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
    2018-05-08 22:52 - 2018-04-21 23:39 - 000066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2018-05-08 22:52 - 2018-04-21 23:38 - 000578048 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2018-05-08 22:52 - 2018-04-21 23:30 - 000034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2018-05-08 22:52 - 2018-04-21 23:26 - 000814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
    2018-05-08 22:52 - 2018-04-21 23:26 - 000794624 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2018-05-08 22:52 - 2018-04-21 23:26 - 000144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2018-05-08 22:52 - 2018-04-21 23:16 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2018-05-08 22:52 - 2018-04-21 23:07 - 000107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
    2018-05-08 22:52 - 2018-04-21 23:04 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2018-05-08 22:52 - 2018-04-21 23:04 - 000199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
    2018-05-08 22:52 - 2018-04-21 23:04 - 000092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2018-05-08 22:52 - 2018-04-21 23:04 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2018-05-08 22:52 - 2018-04-21 22:57 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2018-05-08 22:52 - 2018-04-21 22:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2018-05-08 22:52 - 2018-04-21 22:54 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2018-05-08 22:52 - 2018-04-21 22:53 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2018-05-08 22:52 - 2018-04-21 22:51 - 000262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
    2018-05-08 22:52 - 2018-04-21 22:49 - 000809472 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2018-05-08 22:52 - 2018-04-21 22:49 - 000728064 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2018-05-08 22:52 - 2018-04-21 22:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2018-05-08 22:52 - 2018-04-21 22:39 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2018-05-08 22:52 - 2018-04-21 22:37 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2018-05-08 22:52 - 2018-04-21 22:37 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2018-05-08 22:52 - 2018-04-21 22:33 - 003241472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2018-05-08 22:52 - 2018-04-21 22:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2018-05-08 22:52 - 2018-04-21 22:27 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2018-05-08 22:52 - 2018-04-21 22:22 - 001546240 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2018-05-08 22:52 - 2018-04-21 22:11 - 000800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
    2018-05-08 22:52 - 2018-04-21 22:08 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2018-05-08 22:52 - 2018-04-21 22:04 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2018-05-08 22:52 - 2018-04-21 22:03 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2018-05-08 22:52 - 2018-03-14 08:57 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2018-05-08 22:52 - 2018-03-14 08:52 - 000012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll
    2018-05-08 22:51 - 2018-04-22 00:04 - 025744896 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2018-05-08 22:51 - 2018-04-21 23:40 - 002902016 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2018-05-08 22:51 - 2018-04-21 23:38 - 000048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
    2018-05-08 22:51 - 2018-04-21 23:32 - 005779456 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2018-05-08 22:51 - 2018-04-21 23:26 - 000116224 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
    2018-05-08 22:51 - 2018-04-21 23:18 - 000969216 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
    2018-05-08 22:51 - 2018-04-21 23:03 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2018-05-08 22:51 - 2018-04-21 23:00 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2018-05-08 22:51 - 2018-04-21 22:53 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2018-05-08 22:51 - 2018-04-21 22:48 - 015283200 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2018-05-08 22:51 - 2018-04-21 22:46 - 002135552 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2018-05-08 22:51 - 2018-04-21 22:46 - 001359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
    2018-05-08 22:51 - 2018-04-21 22:31 - 004496896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2018-05-08 22:51 - 2018-04-21 22:26 - 002059776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2018-05-08 22:51 - 2018-04-21 22:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2018-05-08 22:51 - 2018-03-18 14:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2018-05-08 22:51 - 2018-03-18 14:11 - 000002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
    2018-05-08 22:51 - 2018-03-14 09:16 - 000174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2018-05-08 22:51 - 2018-03-14 09:12 - 003165184 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2018-05-08 22:51 - 2018-03-14 09:12 - 000192512 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2018-05-08 22:51 - 2018-03-14 09:12 - 000098816 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2018-05-08 22:51 - 2018-03-14 08:57 - 000573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2018-05-08 22:51 - 2018-03-14 08:57 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2018-05-08 22:51 - 2018-03-14 08:57 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2018-05-08 22:51 - 2018-03-14 08:53 - 002651648 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2018-05-08 22:51 - 2018-03-14 08:53 - 000709120 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2018-05-08 22:51 - 2018-03-14 08:52 - 000140288 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2018-05-08 22:51 - 2018-03-14 08:52 - 000037888 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2018-05-08 22:51 - 2018-03-14 08:52 - 000037888 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2018-05-08 22:51 - 2018-03-14 08:52 - 000036864 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
    2018-05-08 22:50 - 2018-04-21 23:24 - 020286464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2018-05-08 22:50 - 2018-04-21 22:26 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2018-05-08 22:48 - 2018-04-22 16:35 - 000708288 _____ (Microsoft Corporation) C:\Windows\System32\winload.efi
    2018-05-08 22:48 - 2018-04-22 16:35 - 000262336 _____ (Microsoft Corporation) C:\Windows\System32\hal.dll
    2018-05-08 22:48 - 2018-04-22 16:35 - 000154816 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2018-05-08 22:48 - 2018-04-22 16:35 - 000095424 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2018-05-08 22:48 - 2018-04-22 16:10 - 000631640 _____ (Microsoft Corporation) C:\Windows\System32\winresume.efi
    2018-05-08 22:48 - 2018-04-22 16:00 - 001163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000880640 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000731648 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000690688 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000512512 _____ (Microsoft Corporation) C:\Windows\System32\rpcss.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000463872 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000419840 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000361984 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000345600 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000316928 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000215552 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000190464 _____ (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000123904 _____ (Microsoft Corporation) C:\Windows\System32\bcrypt.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000094208 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000063488 _____ (Microsoft Corporation) C:\Windows\System32\setbcdlocale.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000059904 _____ (Microsoft Corporation) C:\Windows\System32\appidapi.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000044032 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000034816 _____ (Microsoft Corporation) C:\Windows\System32\appidsvc.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\System32\oleres.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000008704 _____ (Microsoft Corporation) C:\Windows\System32\comcat.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000007168 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 16:00 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2018-05-08 22:48 - 2018-04-22 15:41 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000582144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:32 - 000148480 _____ (Microsoft Corporation) C:\Windows\System32\appidpolicyconverter.exe
    2018-05-08 22:48 - 2018-04-22 15:32 - 000062464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\appid.sys
    2018-05-08 22:48 - 2018-04-22 15:32 - 000017920 _____ (Microsoft Corporation) C:\Windows\System32\appidcertstorecheck.exe
    2018-05-08 22:48 - 2018-04-22 15:31 - 000064512 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
    2018-05-08 22:48 - 2018-04-22 15:28 - 000338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
    2018-05-08 22:48 - 2018-04-22 15:28 - 000129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\videoprt.sys
    2018-05-08 22:48 - 2018-04-22 15:27 - 000296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
    2018-05-08 22:48 - 2018-04-22 15:25 - 000160256 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
    2018-05-08 22:48 - 2018-04-22 15:24 - 000291328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
    2018-05-08 22:48 - 2018-04-22 15:24 - 000129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
    2018-05-08 22:48 - 2018-04-22 15:24 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
    2018-05-08 22:48 - 2018-04-22 15:23 - 000112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
    2018-05-08 22:48 - 2018-04-22 15:23 - 000030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
    2018-05-08 22:48 - 2018-04-22 15:22 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2018-05-08 22:48 - 2018-04-22 15:19 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2018-05-08 22:48 - 2018-04-22 15:19 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2018-05-08 22:48 - 2018-04-22 15:19 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2018-05-08 22:48 - 2018-04-22 15:19 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2018-05-08 22:48 - 2018-04-22 15:18 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
    2018-05-08 22:48 - 2018-04-22 15:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-22 15:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2018-05-08 22:48 - 2018-04-18 08:03 - 000701952 _____ (Microsoft Corporation) C:\Windows\System32\hhctrl.ocx
    2018-05-08 22:48 - 2018-04-18 08:03 - 000053248 _____ (Microsoft Corporation) C:\Windows\System32\hhsetup.dll
    2018-05-08 22:48 - 2018-04-18 07:51 - 000523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hhctrl.ocx
    2018-05-08 22:48 - 2018-04-18 07:51 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hhsetup.dll
    2018-05-08 22:48 - 2018-04-18 07:41 - 000016896 _____ (Microsoft Corporation) C:\Windows\hh.exe
    2018-05-08 22:48 - 2018-04-18 07:35 - 000015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hh.exe
    2018-05-08 22:48 - 2018-04-11 08:38 - 000194048 _____ (Microsoft Corporation) C:\Windows\System32\itircl.dll
    2018-05-08 22:48 - 2018-04-11 08:38 - 000170496 _____ (Microsoft Corporation) C:\Windows\System32\itss.dll
    2018-05-08 22:48 - 2018-04-11 08:36 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
    2018-05-08 22:48 - 2018-04-11 08:36 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
    2018-05-08 22:48 - 2018-04-10 11:45 - 000634272 _____ (Microsoft Corporation) C:\Windows\System32\winload.exe
    2018-05-08 22:48 - 2018-04-10 08:36 - 000236032 _____ (Microsoft Corporation) C:\Windows\System32\srvsvc.dll
    2018-05-08 22:48 - 2018-04-10 08:36 - 000013312 _____ (Microsoft Corporation) C:\Windows\System32\sscore.dll
    2018-05-08 22:48 - 2018-04-10 08:34 - 000525824 _____ (Microsoft Corporation) C:\Windows\System32\catsrvut.dll
    2018-05-08 22:48 - 2018-04-10 08:32 - 000487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
    2018-05-08 22:48 - 2018-04-10 08:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
    2018-05-08 22:48 - 2018-04-10 07:48 - 000464384 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv.sys
    2018-05-08 22:48 - 2018-04-10 07:47 - 000406016 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
    2018-05-08 22:48 - 2018-04-10 07:47 - 000169984 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
    2018-05-08 22:48 - 2018-04-07 08:41 - 000371392 _____ (Microsoft Corporation) C:\Windows\System32\clfs.sys
    2018-05-08 22:47 - 2018-04-22 16:35 - 005583552 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2018-05-08 22:47 - 2018-04-22 16:12 - 004047040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2018-05-08 22:47 - 2018-04-22 16:12 - 003958464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2018-05-08 22:47 - 2018-04-22 16:07 - 001665336 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
    2018-05-08 22:47 - 2018-04-22 16:00 - 002066432 _____ (Microsoft Corporation) C:\Windows\System32\ole32.dll
    2018-05-08 22:47 - 2018-04-22 16:00 - 001461248 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
    2018-05-08 22:47 - 2018-04-22 16:00 - 001212928 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
    2018-05-08 22:47 - 2018-04-22 16:00 - 000876032 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
    2018-05-08 22:47 - 2018-04-22 15:44 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2018-05-08 22:47 - 2018-04-22 15:41 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2018-05-08 22:47 - 2018-04-10 08:35 - 001735168 _____ (Microsoft Corporation) C:\Windows\System32\comsvcs.dll
    2018-05-08 22:47 - 2018-04-10 08:33 - 001241600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
    2018-05-08 22:47 - 2018-04-10 07:54 - 003226112 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2018-04-30 07:21 - 2013-05-28 09:12 - 000382536 _____ (BitDefender S.R.L.) C:\Windows\System32\Drivers\trufos.sys
    2018-04-17 08:38 - 2018-04-17 08:38 - 000000118 _____ C:\Windows\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2018-04-15 15:25 - 2018-04-16 03:31 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2018-04-15 15:25 - 2018-04-15 15:25 - 000000000 ____D C:\Windows\System32\Tasks\Safer-Networking
    2018-04-15 15:25 - 2017-05-23 06:22 - 000032240 _____ (Safer-Networking Ltd.) C:\Windows\System32\sdnclean64.exe
    2018-04-15 15:24 - 2018-04-15 15:31 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2018-04-15 15:11 - 2018-04-26 06:06 - 000112864 _____ (Malwarebytes) C:\Windows\System32\Drivers\farflt.sys
    2018-04-15 15:11 - 2018-04-15 15:11 - 000253664 _____ (Malwarebytes) C:\Windows\System32\Drivers\mbamswissarmy.sys
    2018-04-15 15:11 - 2018-04-15 15:11 - 000193768 _____ (Malwarebytes) C:\Windows\System32\Drivers\MbamChameleon.sys
    2018-04-15 15:10 - 2018-04-15 15:10 - 000000000 ____D C:\Program Files\Malwarebytes
    2018-04-15 15:10 - 2018-03-19 09:57 - 000076192 _____ C:\Windows\System32\Drivers\mbae64.sys
    2018-04-15 15:09 - 2018-04-15 15:10 - 000000000 ____D C:\ProgramData\Norton
    2018-04-15 15:09 - 2018-04-15 15:09 - 000000000 ____D C:\ProgramData\MB2Migration
    2018-04-15 15:09 - 2018-04-15 15:09 - 000000000 ____D C:\Program Files\Spyware Cleanup Tools

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-05-13 15:57 - 2009-07-13 21:32 - 000032768 _____ C:\Windows\System32\config\BCD-Template
    2018-05-13 12:34 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf
    2018-05-13 12:33 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\registration
    2018-05-12 09:04 - 2017-01-11 09:15 - 000000606 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-2837550921-1350929915-3458270989-1000.job
    2018-05-12 08:23 - 2017-01-11 09:15 - 000000510 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-2837550921-1350929915-3458270989-1000.job
    2018-05-12 08:17 - 2017-01-08 14:31 - 000000144 _____ C:\Windows\System32\config\netlogon.ftl
    2018-05-12 00:48 - 2009-07-13 20:45 - 000021312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2018-05-12 00:48 - 2009-07-13 20:45 - 000021312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2018-05-10 04:31 - 2009-07-13 21:32 - 000000000 ____D C:\Windows\System32\FxsTmp
    2018-05-09 06:39 - 2015-01-06 21:21 - 000000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
    2018-05-08 23:55 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\rescache
    2018-05-08 23:27 - 2009-07-13 21:13 - 000855020 _____ C:\Windows\System32\PerfStringBackup.INI
    2018-05-08 23:18 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2018-05-08 23:18 - 2009-07-13 20:45 - 000428592 _____ C:\Windows\System32\FNTCACHE.DAT
    2018-05-08 18:06 - 2015-01-06 21:03 - 000804864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2018-05-08 18:06 - 2015-01-06 21:03 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2018-05-08 18:06 - 2015-01-06 21:03 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2018-05-08 18:06 - 2015-01-06 21:03 - 000000000 ____D C:\Windows\SysWOW64\Macromed
    2018-05-08 18:06 - 2015-01-06 21:03 - 000000000 ____D C:\Windows\System32\Macromed
    2018-04-16 03:08 - 2011-02-10 06:33 - 000847142 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
    2018-04-15 15:10 - 2015-10-24 20:33 - 000000000 ____D C:\ProgramData\Malwarebytes

    Some files in TEMP:
    ====================


    ==================== Known DLLs (Whitelisted) =========================


    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe
    [2018-04-11 05:48] - [2017-12-31 17:50] - 000455680 _____ (Microsoft Corporation) 11D6A262B617130F7C16E308C12E0D41

    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll
    [2018-05-08 22:48] - [2018-04-22 16:00] - 000512512 _____ (Microsoft Corporation) 4CE2D42E24914EE91BFFCD8D8485A1BB

    C:\Windows\System32\dnsapi.dll => MD5 is legit
    C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== Association (Whitelisted) =============


    ==================== Restore Points =========================

    Restore point date: 2018-05-08 21:00
    Restore point date: 2018-05-08 22:47
    Restore point date: 2018-05-08 22:50
    Restore point date: 2018-05-09 02:03
    Restore point date: 2018-05-12 09:13
    Restore point date: 2018-05-12 09:18

    ==================== BCD ================================

    Windows Boot Manager
    --------------------
    identifier {bootmgr}
    device partition=C:
    path \bootmgr
    description Windows Boot Manager
    locale en-us
    inherit {globalsettings}
    default {default}
    resumeobject {6e6373c2-5709-11e8-8062-f2504e64934d}
    displayorder {default}
    toolsdisplayorder {memdiag}
    timeout 30

    Windows Boot Loader
    -------------------
    identifier {default}
    device partition=C:
    path \Windows\system32\winload.exe
    description Windows 7
    locale en-us
    inherit {bootloadersettings}
    osdevice partition=C:
    systemroot \Windows
    resumeobject {6e6373c2-5709-11e8-8062-f2504e64934d}
    nx OptIn
    detecthal Yes

    Windows Boot Loader
    -------------------
    identifier {6e6373c4-5709-11e8-8062-f2504e64934d}
    device ramdisk=[D:]\Recovery\windowsre\Winre.wim,{6e6373c5-5709-11e8-8062-f2504e64934d}
    path \windows\system32\winload.exe
    description Windows Recovery Environment (recovered)
    locale
    osdevice ramdisk=[D:]\Recovery\windowsre\Winre.wim,{6e6373c5-5709-11e8-8062-f2504e64934d}
    systemroot \windows
    winpe Yes

    Resume from Hibernate
    ---------------------
    identifier {6e6373c2-5709-11e8-8062-f2504e64934d}
    device partition=C:
    path \Windows\system32\winresume.exe
    description Windows Resume Application
    locale en-us
    inherit {resumeloadersettings}
    filepath \hiberfil.sys

    Windows Memory Tester
    ---------------------
    identifier {memdiag}
    device partition=C:
    path \boot\memtest.exe
    description Windows Memory Diagnostic
    locale en-us
    inherit {globalsettings}
    badmemoryaccess Yes

    EMS Settings
    ------------
    identifier {emssettings}
    bootems Yes

    Debugger Settings
    -----------------
    identifier {dbgsettings}
    debugtype Serial
    debugport 1
    baudrate 115200

    RAM Defects
    -----------
    identifier {badmemory}

    Global Settings
    ---------------
    identifier {globalsettings}
    inherit {dbgsettings}
    {emssettings}
    {badmemory}

    Boot Loader Settings
    --------------------
    identifier {bootloadersettings}
    inherit {globalsettings}
    {hypervisorsettings}

    Hypervisor Settings
    -------------------
    identifier {hypervisorsettings}
    hypervisordebugtype Serial
    hypervisordebugport 1
    hypervisorbaudrate 115200

    Resume Loader Settings
    ----------------------
    identifier {resumeloadersettings}
    inherit {globalsettings}

    Device options
    --------------
    identifier {6e6373c5-5709-11e8-8062-f2504e64934d}
    ramdisksdidevice partition=D:
    ramdisksdipath \Recovery\windowsre\boot.sdi


    ==================== Memory info ===========================

    Percentage of memory in use: 15%
    Total physical RAM: 8108.95 MB
    Available physical RAM: 6815.31 MB
    Total Virtual: 8107.14 MB
    Available Virtual: 6886.73 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:907.25 GB) (Free:453.41 GB) NTFS ==>[drive with boot components (obtained from BCD)]
    Drive d: (RECOVERY) (Fixed) (Total:24.22 GB) (Free:13.73 GB) NTFS ==>[system with boot components (obtained from drive)]
    Drive e: (W7SP1_PROFESSIONAL) (CDROM) (Total:5.23 GB) (Free:0 GB) UDF
    Drive f: (Samsung USB) (Removable) (Total:29.88 GB) (Free:29.81 GB) NTFS
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS


    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 54ACCE48)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Not Active) - (Size=24.2 GB) - (Type=27)
    Partition 3: (Active) - (Size=907.3 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 29.9 GB) (Disk ID: C3072E18)
    Partition 1: (Not Active) - (Size=29.9 GB) - (Type=07 NTFS)

    LastRegBack: 2018-05-07 21:11

    ==================== End of FRST.txt ============================

    Any help would by immensely appreciated as I've run out of ideas at this point. And please let me know if there's any additional information I could provide that would be useful. Thanks in advance!
     
  2. 2018/05/16
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    14,977
    Likes Received:
    403
    Trophy Points:
    1,093
    If the system won't boot in safe mode, I would suggest doing a System Restore.
    • Restart your computer.
    • Press F8 before the Windows 7 logo appears.
    • At the Advanced Boot Options menu, select the Repair your computer option.
    • Press Enter.
    • Select a keyboard layout, and then click Next
    • System Recovery Options should now be available.
    • Choose System Restore and follow the prompts
    Chose a restore point from when the system was still working.
     
    Arie,
    #2

  3. to hide this advert.

  4. 2018/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,576
    Likes Received:
    103
    Trophy Points:
    843
    Location:
    Daly City, CA
    Computer Experience:
    Experienced
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ======================================

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

    See if you can boot into any mode.
     

    Attached Files:

  5. 2018/05/16
    supersix

    supersix New Member Thread Starter

    Joined:
    2018/05/13
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    1
    Computer Experience:
    Experienced
    Arie and broni - after browsing the file system using the Windows installation disk, I noticed that the trufos file did in fact exist, along up a trufos.sys.upd file. My assumption is that the file was being updated when something went wrong, thereby corrupting the file. I' was actually able to remediate the boot issue by copying the trufos.sys from a similar Windows 7 installation, and using it to replace the corrupted file. The system is up and running now.

    Thanks again for the responses!
     
  6. 2018/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,576
    Likes Received:
    103
    Trophy Points:
    843
    Location:
    Daly City, CA
    Computer Experience:
    Experienced
    Good job :)
     

Share This Page