[QUOTE]12:07:55.0296 0x11e8 Suspicious service (Hidden): Ms7DB53800App
12:07:55.0390 0x11e8 [ 21DE4ABBC865EE357D34FC2BD3237F4A, 52755A946430CA80189A63FA5C12AF6F631ADC5EA0ADE1DC6E7622E479ED7F2B ] Ms7DB53800App C:\Windows\System32\Ms7DB53800App.dll
12:07:55.0390 0x11e8 Suspicious file ( Hidden ): C:\Windows\System32\Ms7DB53800App.dll. md5: 21DE4ABBC865EE357D34FC2BD3237F4A, sha256: 52755A946430CA80189A63FA5C12AF6F631ADC5EA0ADE1DC6E7622E479ED
12:07:55.0405 0x11e8 Ms7DB53800App - detected HiddenService.Multi.Generic ( 1 )
12:08:02.0534 0x11e8 Detect turned to UDS exact due to KSN untrusted
12:08:02.0612 0x11e8 Ms7DB53800App ( UDS:DangerousObject.Multi.Generic ) - infected
12:08:02.0612 0x11e8 Force sending object to P2P due to detect: Ms7DB53800App
12:08:42.0331 0x11e8 ============================================================
12:08:42.0331 0x11e8 Scan finished
12:08:42.0331 0x11e8 ============================================================
12:08:42.0357 0x1798 Detected object count: 1
12:08:42.0358 0x1798 Actual detected object count: 1
12:10:25.0914 0x1798 Ms7DB53800App ( UDS:DangerousObject.Multi.Generic ) - skipped by user
12:10:25.0914 0x1798 Ms7DB53800App ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
12:10:30.0095 0x1578 Deinitialize success
[/QUOTE]
пробуйте сделать образ автозапуска из под Winpe&uVS,
https://forum.esetnod32.ru/forum27/topic2102/
должны быть видны скрытые сервисы, при создании образа автозапуска из под Winpe