Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: 95p.com redirekt rootkid

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 31.12.2011, 15:24   #1
dieter1989
 
95p.com redirekt rootkid - Standard

95p.com redirekt rootkid



hey

habe seit gestern das problem das ich bei einer google suche immer auf die seite 95p.com komme.
habe bissel gelesen und habe dann erstmal TDSS einen scan gemacht und dann einen mit OTL

hier der TDSS scan

Zitat:
15:09:37.0399 3176 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
15:09:37.0992 3176 ============================================================
15:09:37.0992 3176 Current date / time: 2011/12/31 15:09:37.0992
15:09:37.0992 3176 SystemInfo:
15:09:37.0992 3176
15:09:37.0992 3176 OS Version: 6.1.7600 ServicePack: 0.0
15:09:37.0992 3176 Product type: Workstation
15:09:37.0992 3176 ComputerName: BENNI-PC
15:09:37.0992 3176 UserName: Benni
15:09:37.0992 3176 Windows directory: C:\windows
15:09:37.0992 3176 System windows directory: C:\windows
15:09:37.0992 3176 Processor architecture: Intel x86
15:09:37.0992 3176 Number of processors: 2
15:09:37.0992 3176 Page size: 0x1000
15:09:37.0992 3176 Boot type: Normal boot
15:09:37.0992 3176 ============================================================
15:09:42.0188 3176 Initialize success
15:09:43.0858 2948 ============================================================
15:09:43.0858 2948 Scan started
15:09:43.0858 2948 Mode: Manual;
15:09:43.0858 2948 ============================================================
15:09:49.0271 2948 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
15:09:49.0286 2948 1394ohci - ok
15:09:49.0474 2948 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
15:09:49.0474 2948 ACPI - ok
15:09:49.0661 2948 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
15:09:49.0661 2948 AcpiPmi - ok
15:09:49.0879 2948 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
15:09:49.0895 2948 adp94xx - ok
15:09:50.0113 2948 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
15:09:50.0113 2948 adpahci - ok
15:09:50.0300 2948 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
15:09:50.0300 2948 adpu320 - ok
15:09:50.0566 2948 AFD (810592182d0bfaed90ee088e7735ec7f) C:\windows\system32\drivers\afd.sys
15:09:50.0581 2948 AFD - ok
15:09:50.0768 2948 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
15:09:50.0768 2948 agp440 - ok
15:09:50.0987 2948 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
15:09:50.0987 2948 aic78xx - ok
15:09:51.0252 2948 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
15:09:51.0252 2948 aliide - ok
15:09:51.0470 2948 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
15:09:51.0470 2948 amdagp - ok
15:09:51.0814 2948 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
15:09:51.0814 2948 amdide - ok
15:09:52.0141 2948 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
15:09:52.0188 2948 AmdK8 - ok
15:09:52.0406 2948 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
15:09:52.0406 2948 AmdPPM - ok
15:09:52.0609 2948 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\windows\system32\drivers\amdsata.sys
15:09:52.0625 2948 amdsata - ok
15:09:52.0890 2948 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
15:09:52.0906 2948 amdsbs - ok
15:09:53.0108 2948 amdxata (869e67d66be326a5a9159fba8746fa70) C:\windows\system32\drivers\amdxata.sys
15:09:53.0108 2948 amdxata - ok
15:09:53.0296 2948 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
15:09:53.0296 2948 AppID - ok
15:09:53.0623 2948 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
15:09:53.0639 2948 arc - ok
15:09:53.0920 2948 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
15:09:53.0935 2948 arcsas - ok
15:09:54.0154 2948 AsUpIO (561d6b76c045311691b870f6b3f19eab) C:\windows\system32\drivers\AsUpIO.sys
15:09:54.0169 2948 AsUpIO - ok
15:09:54.0372 2948 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
15:09:54.0372 2948 AsyncMac - ok
15:09:54.0590 2948 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
15:09:54.0590 2948 atapi - ok
15:09:54.0793 2948 athr (b01751cc563aecac09bbe36aaa21fbef) C:\windows\system32\DRIVERS\athr.sys
15:09:54.0809 2948 athr - ok
15:09:55.0214 2948 avgntflt (7713e4eb0276702faa08e52a6e23f2a6) C:\windows\system32\DRIVERS\avgntflt.sys
15:09:55.0214 2948 avgntflt - ok
15:09:55.0433 2948 avipbb (475fbb85956534720858ae72010c0a43) C:\windows\system32\DRIVERS\avipbb.sys
15:09:55.0448 2948 avipbb - ok
15:09:55.0651 2948 avkmgr (271cfd1a989209b1964e24d969552bf7) C:\windows\system32\DRIVERS\avkmgr.sys
15:09:55.0651 2948 avkmgr - ok
15:09:56.0010 2948 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
15:09:56.0026 2948 b06bdrv - ok
15:09:56.0322 2948 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
15:09:56.0322 2948 b57nd60x - ok
15:09:56.0977 2948 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
15:09:56.0977 2948 Beep - ok
15:09:57.0383 2948 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
15:09:57.0398 2948 blbdrive - ok
15:09:57.0710 2948 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\windows\system32\DRIVERS\bowser.sys
15:09:57.0710 2948 bowser - ok
15:09:57.0944 2948 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
15:09:57.0944 2948 BrFiltLo - ok
15:09:58.0256 2948 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
15:09:58.0256 2948 BrFiltUp - ok
15:09:58.0709 2948 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
15:09:58.0709 2948 Brserid - ok
15:09:59.0005 2948 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
15:09:59.0021 2948 BrSerWdm - ok
15:09:59.0130 2948 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
15:09:59.0177 2948 BrUsbMdm - ok
15:09:59.0520 2948 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
15:09:59.0536 2948 BrUsbSer - ok
15:09:59.0926 2948 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\windows\system32\drivers\BthEnum.sys
15:09:59.0988 2948 BthEnum - ok
15:10:00.0175 2948 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
15:10:00.0191 2948 BTHMODEM - ok
15:10:00.0648 2948 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\windows\system32\DRIVERS\bthpan.sys
15:10:00.0689 2948 BthPan - ok
15:10:00.0853 2948 BTHPORT (88059ff1ded4472acd17eebabd393069) C:\windows\System32\Drivers\BTHport.sys
15:10:00.0897 2948 BTHPORT - ok
15:10:01.0113 2948 BTHUSB (80e6384beec03b8bd45edea29802d657) C:\windows\System32\Drivers\BTHUSB.sys
15:10:01.0136 2948 BTHUSB - ok
15:10:01.0326 2948 btusbflt (92c5b845803f3662637eb691ac0b250f) C:\windows\system32\drivers\btusbflt.sys
15:10:01.0361 2948 btusbflt - ok
15:10:01.0557 2948 btwaudio - ok
15:10:01.0666 2948 btwavdt - ok
15:10:01.0810 2948 btwl2cap - ok
15:10:01.0945 2948 btwrchid - ok
15:10:02.0139 2948 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
15:10:02.0164 2948 cdfs - ok
15:10:02.0322 2948 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
15:10:02.0343 2948 cdrom - ok
15:10:02.0541 2948 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
15:10:02.0545 2948 circlass - ok
15:10:02.0696 2948 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
15:10:02.0765 2948 CLFS - ok
15:10:03.0030 2948 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
15:10:03.0033 2948 CmBatt - ok
15:10:03.0266 2948 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
15:10:03.0271 2948 cmdide - ok
15:10:03.0433 2948 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
15:10:03.0440 2948 CNG - ok
15:10:03.0890 2948 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
15:10:03.0893 2948 Compbatt - ok
15:10:04.0119 2948 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
15:10:04.0125 2948 CompositeBus - ok
15:10:04.0332 2948 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
15:10:04.0336 2948 crcdisk - ok
15:10:04.0626 2948 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\windows\system32\Drivers\dfsc.sys
15:10:04.0629 2948 DfsC - ok
15:10:04.0776 2948 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
15:10:04.0779 2948 discache - ok
15:10:05.0013 2948 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
15:10:05.0022 2948 Disk - ok
15:10:05.0210 2948 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
15:10:05.0215 2948 drmkaud - ok
15:10:05.0390 2948 dtsoftbus01 (c0c7ceccb6c85994c2bc92d58e52d3f2) C:\windows\system32\DRIVERS\dtsoftbus01.sys
15:10:05.0405 2948 dtsoftbus01 - ok
15:10:05.0561 2948 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\windows\System32\drivers\dxgkrnl.sys
15:10:05.0577 2948 DXGKrnl - ok
15:10:05.0904 2948 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
15:10:06.0029 2948 ebdrv - ok
15:10:06.0248 2948 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
15:10:06.0263 2948 elxstor - ok
15:10:06.0404 2948 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
15:10:06.0404 2948 ErrDev - ok
15:10:06.0622 2948 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
15:10:06.0622 2948 exfat - ok
15:10:06.0778 2948 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
15:10:06.0778 2948 fastfat - ok
15:10:06.0950 2948 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
15:10:06.0965 2948 fdc - ok
15:10:07.0121 2948 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
15:10:07.0121 2948 FileInfo - ok
15:10:07.0215 2948 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
15:10:07.0215 2948 Filetrace - ok
15:10:07.0340 2948 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
15:10:07.0355 2948 flpydisk - ok
15:10:07.0527 2948 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
15:10:07.0527 2948 FltMgr - ok
15:10:07.0761 2948 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
15:10:07.0761 2948 FsDepends - ok
15:10:07.0917 2948 fssfltr (b74b0578fd1d3f897e95f2a2b69ea051) C:\windows\system32\DRIVERS\fssfltr.sys
15:10:07.0917 2948 fssfltr - ok
15:10:08.0010 2948 FsUsbExDisk (10398b515653442a5b89fdf6a1d06180) C:\windows\system32\FsUsbExDisk.SYS
15:10:08.0010 2948 FsUsbExDisk - ok
15:10:08.0135 2948 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
15:10:08.0135 2948 Fs_Rec - ok
15:10:08.0338 2948 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\windows\system32\DRIVERS\fvevol.sys
15:10:08.0338 2948 fvevol - ok
15:10:08.0541 2948 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
15:10:08.0541 2948 gagp30kx - ok
15:10:08.0666 2948 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
15:10:08.0666 2948 hcw85cir - ok
15:10:08.0759 2948 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
15:10:08.0759 2948 HdAudAddService - ok
15:10:08.0915 2948 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
15:10:08.0931 2948 HDAudBus - ok
15:10:09.0071 2948 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
15:10:09.0071 2948 HidBatt - ok
15:10:09.0212 2948 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
15:10:09.0227 2948 HidBth - ok
15:10:09.0368 2948 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
15:10:09.0368 2948 HidIr - ok
15:10:09.0508 2948 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
15:10:09.0524 2948 HidUsb - ok
15:10:09.0726 2948 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
15:10:09.0726 2948 HpSAMD - ok
15:10:09.0898 2948 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
15:10:09.0914 2948 HTTP - ok
15:10:10.0023 2948 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
15:10:10.0038 2948 hwpolicy - ok
15:10:10.0226 2948 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
15:10:10.0241 2948 i8042prt - ok
15:10:10.0397 2948 iaStor (d483687eace0c065ee772481a96e05f5) C:\windows\system32\DRIVERS\iaStor.sys
15:10:10.0413 2948 iaStor - ok
15:10:10.0584 2948 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\windows\system32\drivers\iaStorV.sys
15:10:10.0584 2948 iaStorV - ok
15:10:10.0912 2948 igfx (d0074897c6bc132f3980ea4654bf7fb9) C:\windows\system32\DRIVERS\igdkmd32.sys
15:10:11.0052 2948 igfx - ok
15:10:11.0271 2948 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
15:10:11.0271 2948 iirsp - ok
15:10:11.0614 2948 IntcAzAudAddService (bf9866875edf86aae24dd8bd9418deff) C:\windows\system32\drivers\RTKVHDA.sys
15:10:11.0708 2948 IntcAzAudAddService - ok
15:10:11.0879 2948 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
15:10:11.0879 2948 intelide - ok
15:10:12.0066 2948 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
15:10:12.0066 2948 intelppm - ok
15:10:12.0129 2948 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
15:10:12.0144 2948 IpFilterDriver - ok
15:10:12.0176 2948 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
15:10:12.0176 2948 IPMIDRV - ok
15:10:12.0207 2948 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
15:10:12.0207 2948 IPNAT - ok
15:10:12.0269 2948 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
15:10:12.0285 2948 IRENUM - ok
15:10:12.0332 2948 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
15:10:12.0332 2948 isapnp - ok
15:10:12.0410 2948 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
15:10:12.0425 2948 iScsiPrt - ok
15:10:12.0488 2948 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
15:10:12.0503 2948 kbdclass - ok
15:10:12.0550 2948 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
15:10:12.0550 2948 kbdhid - ok
15:10:12.0628 2948 kbfiltr (3eb803312987ff44265c87cb960df6ab) C:\windows\system32\DRIVERS\kbfiltr.sys
15:10:12.0628 2948 kbfiltr - ok
15:10:12.0690 2948 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
15:10:12.0690 2948 KSecDD - ok
15:10:12.0737 2948 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys
15:10:12.0737 2948 KSecPkg - ok
15:10:12.0862 2948 L1C (a158cea8644b8a5c1ec0e9a81b70f65a) C:\windows\system32\DRIVERS\L1C62x86.sys
15:10:12.0878 2948 L1C - ok
15:10:13.0096 2948 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
15:10:13.0112 2948 lltdio - ok
15:10:13.0205 2948 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
15:10:13.0221 2948 LSI_FC - ok
15:10:13.0268 2948 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
15:10:13.0268 2948 LSI_SAS - ok
15:10:13.0314 2948 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
15:10:13.0314 2948 LSI_SAS2 - ok
15:10:13.0346 2948 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
15:10:13.0346 2948 LSI_SCSI - ok
15:10:13.0408 2948 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
15:10:13.0408 2948 luafv - ok
15:10:13.0455 2948 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
15:10:13.0455 2948 megasas - ok
15:10:13.0517 2948 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
15:10:13.0517 2948 MegaSR - ok
15:10:13.0595 2948 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
15:10:13.0611 2948 Modem - ok
15:10:13.0767 2948 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
15:10:13.0767 2948 monitor - ok
15:10:13.0907 2948 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
15:10:13.0907 2948 mouclass - ok
15:10:14.0048 2948 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
15:10:14.0048 2948 mouhid - ok
15:10:14.0126 2948 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
15:10:14.0141 2948 mountmgr - ok
15:10:14.0235 2948 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
15:10:14.0235 2948 mpio - ok
15:10:14.0328 2948 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
15:10:14.0328 2948 mpsdrv - ok
15:10:14.0469 2948 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
15:10:14.0484 2948 MRxDAV - ok
15:10:14.0703 2948 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\windows\system32\DRIVERS\mrxsmb.sys
15:10:14.0703 2948 mrxsmb - ok
15:10:14.0874 2948 mrxsmb10 (f965c3ab2b2ae5c378f4562486e35051) C:\windows\system32\DRIVERS\mrxsmb10.sys
15:10:14.0874 2948 mrxsmb10 - ok
15:10:15.0062 2948 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\windows\system32\DRIVERS\mrxsmb20.sys
15:10:15.0062 2948 mrxsmb20 - ok
15:10:15.0264 2948 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
15:10:15.0264 2948 msahci - ok
15:10:15.0452 2948 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
15:10:15.0452 2948 msdsm - ok
15:10:16.0310 2948 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
15:10:16.0310 2948 Msfs - ok
15:10:16.0497 2948 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
15:10:16.0497 2948 mshidkmdf - ok
15:10:16.0856 2948 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
15:10:16.0856 2948 msisadrv - ok
15:10:17.0370 2948 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
15:10:17.0370 2948 MSKSSRV - ok
15:10:17.0526 2948 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
15:10:17.0526 2948 MSPCLOCK - ok
15:10:17.0714 2948 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
15:10:17.0714 2948 MSPQM - ok
15:10:17.0901 2948 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
15:10:17.0901 2948 MsRPC - ok
15:10:18.0026 2948 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
15:10:18.0041 2948 mssmbios - ok
15:10:18.0166 2948 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
15:10:18.0166 2948 MSTEE - ok
15:10:18.0338 2948 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
15:10:18.0338 2948 MTConfig - ok
15:10:18.0509 2948 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
15:10:18.0509 2948 Mup - ok
15:10:18.0696 2948 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
15:10:18.0712 2948 NativeWifiP - ok
15:10:18.0915 2948 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
15:10:18.0930 2948 NDIS - ok
15:10:19.0102 2948 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
15:10:19.0102 2948 NdisCap - ok
15:10:19.0227 2948 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
15:10:19.0227 2948 NdisTapi - ok
15:10:19.0383 2948 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
15:10:19.0383 2948 Ndisuio - ok
15:10:19.0508 2948 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
15:10:19.0508 2948 NdisWan - ok
15:10:19.0648 2948 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
15:10:19.0664 2948 NDProxy - ok
15:10:19.0851 2948 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
15:10:19.0851 2948 NetBIOS - ok
15:10:20.0007 2948 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys
15:10:20.0022 2948 NetBT - ok
15:10:20.0256 2948 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
15:10:20.0256 2948 nfrd960 - ok
15:10:20.0412 2948 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
15:10:20.0412 2948 Npfs - ok
15:10:20.0522 2948 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
15:10:20.0537 2948 nsiproxy - ok
15:10:20.0802 2948 Ntfs (187002ce05693c306f43c873f821381f) C:\windows\system32\drivers\Ntfs.sys
15:10:20.0834 2948 Ntfs - ok
15:10:20.0990 2948 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
15:10:20.0990 2948 Null - ok
15:10:21.0146 2948 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\windows\system32\drivers\nvraid.sys
15:10:21.0161 2948 nvraid - ok
15:10:21.0270 2948 nvstor (4520b63899e867f354ee012d34e11536) C:\windows\system32\drivers\nvstor.sys
15:10:21.0270 2948 nvstor - ok
15:10:21.0380 2948 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
15:10:21.0380 2948 nv_agp - ok
15:10:21.0536 2948 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
15:10:21.0536 2948 ohci1394 - ok
15:10:21.0801 2948 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
15:10:21.0801 2948 Parport - ok
15:10:21.0879 2948 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
15:10:21.0879 2948 partmgr - ok
15:10:21.0926 2948 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
15:10:21.0941 2948 Parvdm - ok
15:10:21.0988 2948 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
15:10:21.0988 2948 pci - ok
15:10:22.0035 2948 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
15:10:22.0035 2948 pciide - ok
15:10:22.0082 2948 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
15:10:22.0082 2948 pcmcia - ok
15:10:22.0128 2948 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
15:10:22.0128 2948 pcw - ok
15:10:22.0238 2948 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
15:10:22.0253 2948 PEAUTH - ok
15:10:22.0550 2948 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
15:10:22.0550 2948 PptpMiniport - ok
15:10:22.0690 2948 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
15:10:22.0690 2948 Processor - ok
15:10:22.0877 2948 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
15:10:22.0877 2948 Psched - ok
15:10:23.0064 2948 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
15:10:23.0111 2948 ql2300 - ok
15:10:23.0517 2948 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
15:10:23.0517 2948 ql40xx - ok
15:10:23.0829 2948 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
15:10:23.0829 2948 QWAVEdrv - ok
15:10:24.0188 2948 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
15:10:24.0188 2948 RasAcd - ok
15:10:24.0468 2948 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
15:10:24.0468 2948 RasAgileVpn - ok
15:10:24.0624 2948 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
15:10:24.0640 2948 Rasl2tp - ok
15:10:24.0780 2948 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
15:10:24.0780 2948 RasPppoe - ok
15:10:24.0952 2948 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
15:10:24.0952 2948 RasSstp - ok
15:10:25.0108 2948 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
15:10:25.0108 2948 rdbss - ok
15:10:25.0280 2948 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
15:10:25.0280 2948 rdpbus - ok
15:10:25.0326 2948 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
15:10:25.0326 2948 RDPCDD - ok
15:10:25.0576 2948 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
15:10:25.0576 2948 RDPENCDD - ok
15:10:25.0732 2948 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
15:10:25.0732 2948 RDPREFMP - ok
15:10:25.0982 2948 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
15:10:25.0982 2948 RDPWD - ok
15:10:26.0465 2948 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys
15:10:26.0528 2948 rdyboost - ok
15:10:26.0949 2948 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\windows\system32\DRIVERS\rfcomm.sys
15:10:26.0949 2948 RFCOMM - ok
15:10:27.0167 2948 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
15:10:27.0183 2948 rspndr - ok
15:10:27.0339 2948 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
15:10:27.0339 2948 sbp2port - ok
15:10:27.0573 2948 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
15:10:27.0573 2948 scfilter - ok
15:10:27.0869 2948 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
15:10:27.0885 2948 secdrv - ok
15:10:28.0275 2948 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
15:10:28.0275 2948 Serenum - ok
15:10:28.0400 2948 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
15:10:28.0415 2948 Serial - ok
15:10:28.0634 2948 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
15:10:28.0649 2948 sermouse - ok
15:10:28.0930 2948 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
15:10:28.0930 2948 sffdisk - ok
15:10:29.0133 2948 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
15:10:29.0148 2948 sffp_mmc - ok
15:10:29.0320 2948 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\windows\system32\DRIVERS\sffp_sd.sys
15:10:29.0320 2948 sffp_sd - ok
15:10:29.0460 2948 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
15:10:29.0460 2948 sfloppy - ok
15:10:29.0679 2948 Sftfs (8f00cc8cacf83dce5b35079f615b0f12) C:\windows\system32\DRIVERS\Sftfslh.sys
15:10:29.0710 2948 Sftfs - ok
15:10:29.0866 2948 Sftplay (afdb934586c4c8b2be39ae7eea6f52be) C:\windows\system32\DRIVERS\Sftplaylh.sys
15:10:29.0866 2948 Sftplay - ok
15:10:30.0022 2948 Sftredir (6b1865d82e0290729ed7496c24275592) C:\windows\system32\DRIVERS\Sftredirlh.sys
15:10:30.0022 2948 Sftredir - ok
15:10:30.0162 2948 Sftvol (621eccb1265a01ce2bdf6f2c5e727e2b) C:\windows\system32\DRIVERS\Sftvollh.sys
15:10:30.0162 2948 Sftvol - ok
15:10:30.0537 2948 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
15:10:30.0537 2948 sisagp - ok
15:10:30.0584 2948 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
15:10:30.0599 2948 SiSRaid2 - ok
15:10:30.0630 2948 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
15:10:30.0630 2948 SiSRaid4 - ok
15:10:30.0693 2948 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
15:10:30.0693 2948 Smb - ok
15:10:30.0786 2948 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
15:10:30.0786 2948 spldr - ok
15:10:30.0942 2948 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\windows\system32\DRIVERS\srv.sys
15:10:30.0958 2948 srv - ok
15:10:31.0005 2948 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\windows\system32\DRIVERS\srv2.sys
15:10:31.0005 2948 srv2 - ok
15:10:31.0052 2948 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\windows\system32\DRIVERS\srvnet.sys
15:10:31.0052 2948 srvnet - ok
15:10:31.0130 2948 ssadbus (6d83ff6722baf7e82a4521dbec363e5a) C:\windows\system32\DRIVERS\ssadbus.sys
15:10:31.0130 2948 ssadbus - ok
15:10:31.0161 2948 ssadmdfl (5ae42e90f99749e0e35b9989a2d0275c) C:\windows\system32\DRIVERS\ssadmdfl.sys
15:10:31.0176 2948 ssadmdfl - ok
15:10:31.0208 2948 ssadmdm (9285d8aba50a4d6482b1574448f9eb76) C:\windows\system32\DRIVERS\ssadmdm.sys
15:10:31.0223 2948 ssadmdm - ok
15:10:31.0301 2948 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\windows\system32\DRIVERS\ssmdrv.sys
15:10:31.0301 2948 ssmdrv - ok
15:10:31.0379 2948 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
15:10:31.0379 2948 stexstor - ok
15:10:31.0457 2948 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
15:10:31.0457 2948 swenum - ok
15:10:31.0535 2948 SynTP (bd8e7f87de409a745a132a8812de5a96) C:\windows\system32\DRIVERS\SynTP.sys
15:10:31.0551 2948 SynTP - ok
15:10:31.0800 2948 tap0901 (5c7c939bbd03784fe58c80578d065cc9) C:\windows\system32\DRIVERS\tap0901.sys
15:10:31.0816 2948 tap0901 - ok
15:10:32.0050 2948 Tcpip (56c198ac82efa622dd93e9e43575f79c) C:\windows\system32\drivers\tcpip.sys
15:10:32.0081 2948 Tcpip - ok
15:10:32.0300 2948 TCPIP6 (56c198ac82efa622dd93e9e43575f79c) C:\windows\system32\DRIVERS\tcpip.sys
15:10:32.0315 2948 TCPIP6 - ok
15:10:32.0502 2948 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
15:10:32.0502 2948 tcpipreg - ok
15:10:32.0674 2948 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
15:10:32.0674 2948 TDPIPE - ok
15:10:32.0814 2948 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
15:10:32.0814 2948 TDTCP - ok
15:10:33.0017 2948 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
15:10:33.0017 2948 tdx - ok
15:10:33.0173 2948 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
15:10:33.0189 2948 TermDD - ok
15:10:33.0392 2948 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
15:10:33.0392 2948 tssecsrv - ok
15:10:33.0548 2948 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
15:10:33.0548 2948 tunnel - ok
15:10:33.0626 2948 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
15:10:33.0641 2948 uagp35 - ok
15:10:33.0719 2948 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
15:10:33.0735 2948 udfs - ok
15:10:33.0813 2948 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
15:10:33.0813 2948 uliagpkx - ok
15:10:33.0891 2948 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
15:10:33.0891 2948 umbus - ok
15:10:33.0938 2948 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
15:10:33.0938 2948 UmPass - ok
15:10:34.0125 2948 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys
15:10:34.0125 2948 usbaudio - ok
15:10:34.0234 2948 usbccgp (5c233aefb566ee78c1efbc0493fb066a) C:\windows\system32\DRIVERS\usbccgp.sys
15:10:34.0250 2948 usbccgp - ok
15:10:34.0406 2948 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
15:10:34.0406 2948 usbcir - ok
15:10:34.0530 2948 usbehci (5b71019a6aca0116fd21b368f19c0b91) C:\windows\system32\drivers\usbehci.sys
15:10:34.0530 2948 usbehci - ok
15:10:34.0749 2948 usbhub (5823d3965c2a4f6f785ed1a3b403f3b8) C:\windows\system32\DRIVERS\usbhub.sys
15:10:34.0749 2948 usbhub - ok
15:10:34.0967 2948 usbohci (e753ed6c49da13967ebabf9ea616454a) C:\windows\system32\drivers\usbohci.sys
15:10:34.0967 2948 usbohci - ok
15:10:35.0170 2948 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
15:10:35.0170 2948 usbprint - ok
15:10:35.0373 2948 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\windows\system32\DRIVERS\usbscan.sys
15:10:35.0373 2948 usbscan - ok
15:10:35.0513 2948 USBSTOR (1c4287739a93594e57e2a9e6a3ed7353) C:\windows\system32\DRIVERS\USBSTOR.SYS
15:10:35.0513 2948 USBSTOR - ok
15:10:35.0669 2948 usbuhci (6a30928a469ce802600e1ea8c0f2f53f) C:\windows\system32\drivers\usbuhci.sys
15:10:35.0669 2948 usbuhci - ok
15:10:35.0825 2948 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\windows\System32\Drivers\usbvideo.sys
15:10:35.0825 2948 usbvideo - ok
15:10:36.0044 2948 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
15:10:36.0044 2948 vdrvroot - ok
15:10:36.0231 2948 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
15:10:36.0231 2948 vga - ok
15:10:36.0387 2948 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
15:10:36.0387 2948 VgaSave - ok
15:10:36.0527 2948 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
15:10:36.0527 2948 vhdmp - ok
15:10:36.0605 2948 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
15:10:36.0621 2948 viaagp - ok
15:10:36.0652 2948 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
15:10:36.0652 2948 ViaC7 - ok
15:10:36.0699 2948 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
15:10:36.0699 2948 viaide - ok
15:10:36.0746 2948 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
15:10:36.0746 2948 volmgr - ok
15:10:36.0808 2948 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
15:10:36.0824 2948 volmgrx - ok
15:10:36.0902 2948 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
15:10:36.0902 2948 volsnap - ok
15:10:36.0980 2948 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
15:10:36.0980 2948 vsmraid - ok
15:10:37.0058 2948 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
15:10:37.0058 2948 vwifibus - ok
15:10:37.0120 2948 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
15:10:37.0120 2948 vwififlt - ok
15:10:37.0167 2948 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\windows\system32\DRIVERS\vwifimp.sys
15:10:37.0167 2948 vwifimp - ok
15:10:37.0229 2948 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
15:10:37.0229 2948 WacomPen - ok
15:10:37.0276 2948 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
15:10:37.0276 2948 WANARP - ok
15:10:37.0292 2948 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
15:10:37.0292 2948 Wanarpv6 - ok
15:10:37.0370 2948 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
15:10:37.0385 2948 Wd - ok
15:10:37.0494 2948 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
15:10:37.0510 2948 Wdf01000 - ok
15:10:37.0760 2948 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
15:10:37.0775 2948 WfpLwf - ok
15:10:37.0838 2948 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
15:10:37.0853 2948 WIMMount - ok
15:10:38.0072 2948 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys
15:10:38.0072 2948 WinUsb - ok
15:10:38.0274 2948 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
15:10:38.0274 2948 WmiAcpi - ok
15:10:38.0524 2948 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
15:10:38.0524 2948 ws2ifsl - ok
15:10:38.0727 2948 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
15:10:38.0727 2948 WudfPf - ok
15:10:38.0867 2948 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
15:10:38.0867 2948 WUDFRd - ok
15:10:38.0976 2948 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
15:10:39.0164 2948 \Device\Harddisk0\DR0 - ok
15:10:39.0164 2948 MBR (0x1B8) (087f8a78397c4962a28d2db48cbd882b) \Device\Harddisk1\DR1
15:10:39.0195 2948 \Device\Harddisk1\DR1 - ok
15:10:39.0195 2948 Boot (0x1200) (15cf4f23e3f1e9f5000288992f0d61e5) \Device\Harddisk0\DR0\Partition0
15:10:39.0210 2948 \Device\Harddisk0\DR0\Partition0 - ok
15:10:39.0226 2948 Boot (0x1200) (e561d3855e7409f40c075f86402524ce) \Device\Harddisk0\DR0\Partition1
15:10:39.0226 2948 \Device\Harddisk0\DR0\Partition1 - ok
15:10:39.0242 2948 Boot (0x1200) (924d05c7b82ca8876a1af722fb35dfb7) \Device\Harddisk1\DR1\Partition0
15:10:39.0242 2948 \Device\Harddisk1\DR1\Partition0 - ok
15:10:39.0257 2948 ============================================================
15:10:39.0257 2948 Scan finished
15:10:39.0257 2948 ============================================================
15:10:39.0288 3676 Detected object count: 0
15:10:39.0288 3676 Actual detected object count: 0
der andere läuft noch füge ihn dann dazu. kann mir jmd helfen:-) wäre klasse

mfg

Alt 31.12.2011, 15:26   #2
dieter1989
 
95p.com redirekt rootkid - Standard

95p.com redirekt rootkid



OTL scan

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 12/31/2011 3:17:12 PM - Run 1
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Benni\Downloads
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014.18 Mb Total Physical Memory | 218.29 Mb Available Physical Memory | 21.52% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 68.04 Gb Free Space | 68.04% Space Free | Partition Type: NTFS
Drive D: | 117.87 Gb Total Space | 53.00 Gb Free Space | 44.97% Space Free | Partition Type: NTFS
Drive E: | 630.24 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 186.31 Gb Total Space | 98.96 Gb Free Space | 53.11% Space Free | Partition Type: NTFS
 
Computer Name: BENNI-PC | User Name: Benni | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Benni\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\TDSSkiller\TDSSKiller.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - D:\Programme\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - D:\Programme\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - D:\Programme\ICQ\ICQ7.2\ICQ.exe (ICQ, LLC.)
PRC - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
PRC - C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (Boingo Wireless, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\MSTMON_S.EXE (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
 
 
========== Modules (No Company Name) ==========
 
MOD - D:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - D:\Programme\ICQ\ICQ7.2\MDb.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.DLL ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (sftvsa) --  File not found
SRV - (MySQL55) --  File not found
SRV - (cvhsvc) --  File not found
SRV - (BBUpdate) --  File not found
SRV - (AsusService) --  File not found
SRV - (BBSvc) -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (sftlist) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (AFD) -- C:\windows\system32\drivers\afd.sys ()
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ssadmdm) -- C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) -- C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) -- C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (Sftvol) -- C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) -- C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) -- C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) -- C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (AsUpIO) -- C:\Windows\System32\drivers\AsUpIO.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20) -- C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
DRV - (btusbflt) -- C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (kbfiltr) -- C:\Windows\System32\drivers\kbfiltr.sys ( )
DRV - (tap0901) -- C:\Windows\System32\drivers\tap0901.sys (The OpenVPN Project)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://asus.msn.comhxxp://eeepc.asus.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://my.daemon-search.com/startpage|hxxp://www.google.de/firefox"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\PROGRA~2\Vision\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\PROGRA~2\Vision\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\telekom.com/PagePlaceStarter: D:\Programme\Reader\npPagePlaceStarter.dll (Deutsche Telekom AG)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: D:\Programme\Mozilla Firefox\components [2011/11/10 08:52:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: D:\Programme\Mozilla Firefox\plugins [2011/11/10 08:52:13 | 000,000,000 | ---D | M]
 
[2010/12/18 10:59:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benni\AppData\Roaming\mozilla\Extensions
[2011/12/27 23:31:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benni\AppData\Roaming\mozilla\Firefox\Profiles\s4ib0x5s.default\extensions
() (No name found) -- C:\USERS\BENNI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\S4IB0X5S.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
 
O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files\Vision\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Windows 7 Starter Helper) - {D381FF29-7CFB-4D4E-B92A-C4EDDC696614} - C:\Program Files\Oceanis\SystemSetting\StarterHelper.dll (Oceanis)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Boingo Wi-Fi] C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk ()
O4 - HKLM..\Run: [CapsHook] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [EeeSplendidAgent] C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe File not found
O4 - HKLM..\Run: [HotkeyMon] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [HotkeyService] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\windows\System32\MSTMON_S.EXE (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
O4 - HKLM..\Run: [LiveUpdate] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [SuperHybridEngine] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Programme\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [ICQ] D:\Programme\ICQ\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [KiesHelper] D:\Programme\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesTrayAgent] D:\Programme\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Users\Benni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenVPN GUI.lnk = C:\Windows\System32\schtasks.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Benni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ubisoft register.lnk = C:\Program Files\Ubi Soft\Register\schedule.exe (Ubi Soft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Programme\ICQ\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Programme\ICQ\ICQ7.2\ICQ.exe (ICQ, LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - %SystemRoot%\system32\wshbth.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 10.0.0)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{785E45B2-F95B-4CE9-AFA3-03CAA028D70C}: DhcpNameServer = 131.246.9.116 131.246.1.116
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9C4D4F6-8E2A-4AE8-96F9-752B373F0060}: NameServer = 192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E79AF3FB-DABC-4232-8FA7-61445012E2AB}: NameServer = 192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FF0CD257-4965-476C-8CAD-1FF2482C3132}: NameServer = 192.168.1.2
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (C:\Users\Benni\AppData\Local\0b12b8ea\X) -C:\Users\Benni\AppData\Local\0b12b8ea\X ()
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2003/10/21 12:05:21 | 000,000,000 | ---D | M] - E:\Autorun -- [ CDFS ]
O32 - AutoRun File - [2002/11/12 16:39:16 | 000,258,048 | R--- | M] (Blue Byte Software, Inc.) - E:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2002/01/29 10:43:23 | 000,000,096 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{081c8007-c910-11e0-957e-20cf3070d3d6}\Shell - "" = AutoRun
O33 - MountPoints2\{081c8007-c910-11e0-957e-20cf3070d3d6}\Shell\AutoRun\command - "" = E:\Autorun.exe -- [2002/11/12 16:39:16 | 000,258,048 | R--- | M] (Blue Byte Software, Inc.)
O33 - MountPoints2\{0aeb2181-c489-11e0-8e31-20cf3070d3d6}\Shell - "" = AutoRun
O33 - MountPoints2\{0aeb2181-c489-11e0-8e31-20cf3070d3d6}\Shell\AutoRun\command - "" = C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.hta
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
File not found -- C:\windows\System32\
[2030/01/01 22:45:41 | 000,000,000 | -HSD | C] -- C:\Boot
[2011/12/31 15:15:17 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011/12/31 14:58:43 | 000,000,000 | ---D | C] -- C:\TDSSkiller
[2011/12/31 14:24:07 | 000,222,568 | ---- | C] (Teruten) -- C:\windows\System32\FsUsbExService.Exe
[2011/12/31 00:39:01 | 000,000,000 | ---D | C] -- C:\Users\Benni\AppData\Roaming\Avira
[2011/12/31 00:33:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/12/31 00:32:47 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\ssmdrv.sys
[2011/12/31 00:32:45 | 000,134,856 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avipbb.sys
[2011/12/31 00:32:45 | 000,074,640 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avgntflt.sys
[2011/12/31 00:32:45 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avkmgr.sys
[2011/12/31 00:32:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/12/31 00:32:40 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/12/28 22:10:07 | 000,000,000 | -HSD | C] -- C:\windows\System32\%APPDATA%
[2011/12/28 22:05:46 | 000,000,000 | -HSD | C] -- C:\Users\Benni\AppData\Local\0b12b8ea
[2011/12/27 21:50:03 | 000,000,000 | ---D | C] -- C:\Users\Benni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blue Byte
[2011/12/27 21:48:43 | 000,000,000 | ---D | C] -- C:\BlueByte
[2011/12/14 19:00:54 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mstime.dll
[2011/12/14 19:00:54 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2011/12/14 19:00:54 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2011/12/14 19:00:54 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieui.dll
[2011/12/14 19:00:53 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll
[2011/12/14 19:00:53 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\url.dll
[2011/12/14 19:00:53 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2011/12/14 19:00:53 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2011/12/14 19:00:53 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll
[2011/12/14 19:00:52 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2011/12/14 19:00:52 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\html.iec
[2011/12/14 19:00:52 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe
[2011/12/14 18:52:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\tzres.dll
[2011/12/14 18:37:37 | 002,340,352 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys
[2011/12/14 18:36:13 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\EncDec.dll
[2011/12/14 18:36:11 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\csrsrv.dll
[2011/12/14 18:36:07 | 003,901,808 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntoskrnl.exe
[2011/12/14 18:36:06 | 003,957,104 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntkrnlpa.exe
[2011/12/12 12:30:23 | 000,000,000 | ---D | C] -- C:\Users\Benni\Desktop\Homepage Prof. Dr. Peter Liell-Dateien
[2010/04/13 03:36:12 | 000,013,880 | ---- | C] ( ) -- C:\windows\System32\drivers\kbfiltr.sys
[1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
File not found -- C:\windows\System32\
[2011/12/31 15:15:29 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/31 15:15:29 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/31 15:08:11 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011/12/31 15:07:28 | 797,581,312 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/31 14:25:54 | 000,655,072 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2011/12/31 14:25:54 | 000,616,914 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2011/12/31 14:25:54 | 000,130,364 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2011/12/31 14:25:54 | 000,106,746 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2011/12/31 00:41:05 | 000,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/12/31 00:33:11 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2011/12/30 19:16:09 | 000,001,440 | ---- | M] () -- C:\Users\Benni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ubisoft register.lnk
[2011/12/27 21:50:39 | 000,002,048 | ---- | M] () -- C:\Users\Benni\Desktop\Ubi Soft Product Registration.lnk
[2011/12/27 21:49:53 | 000,000,743 | ---- | M] () -- C:\Users\Public\Desktop\Die Siedler IV Gold+ Edition.lnk
[2011/12/25 19:44:27 | 000,015,485 | ---- | M] () -- C:\Users\Benni\Desktop\last-christmas-piano-tab.png
[2011/12/18 03:26:25 | 000,273,544 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2011/12/15 15:00:00 | 000,134,856 | ---- | M] (Avira GmbH) -- C:\windows\System32\drivers\avipbb.sys
[2011/12/15 15:00:00 | 000,074,640 | ---- | M] (Avira GmbH) -- C:\windows\System32\drivers\avgntflt.sys
[2011/12/15 15:00:00 | 000,036,000 | ---- | M] (Avira GmbH) -- C:\windows\System32\drivers\avkmgr.sys
[2011/12/12 12:30:26 | 000,000,418 | ---- | M] () -- C:\Users\Benni\Desktop\Homepage Prof. Dr. Peter Liell.htm
[2011/12/02 09:15:49 | 000,000,017 | ---- | M] () -- C:\windows\System32\shortcut_ex.dat
[1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2030/01/01 22:45:41 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2011/12/31 00:33:11 | 000,002,016 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2011/12/30 19:16:09 | 000,001,440 | ---- | C] () -- C:\Users\Benni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ubisoft register.lnk
[2011/12/27 21:50:39 | 000,002,048 | ---- | C] () -- C:\Users\Benni\Desktop\Ubi Soft Product Registration.lnk
[2011/12/25 19:44:25 | 000,015,485 | ---- | C] () -- C:\Users\Benni\Desktop\last-christmas-piano-tab.png
[2011/12/12 12:30:21 | 000,000,418 | ---- | C] () -- C:\Users\Benni\Desktop\Homepage Prof. Dr. Peter Liell.htm
[2011/12/02 09:15:48 | 000,000,017 | ---- | C] () -- C:\windows\System32\shortcut_ex.dat
[2011/10/09 23:54:43 | 000,000,232 | ---- | C] () -- C:\windows\ODBCINST.INI
[2011/08/17 21:38:56 | 000,069,632 | R--- | C] () -- C:\windows\System32\xmltok.dll
[2011/08/17 21:38:56 | 000,036,864 | R--- | C] () -- C:\windows\System32\xmlparse.dll
[2011/08/16 21:53:54 | 000,021,747 | ---- | C] () -- C:\windows\MSTMON_S.INI
[2011/08/16 21:53:54 | 000,019,253 | ---- | C] () -- C:\windows\MSUMLT_S.INI
[2011/06/17 07:06:17 | 000,338,944 | ---- | C] () -- C:\windows\System32\drivers\afd.sys
[2011/03/18 19:41:30 | 000,005,120 | ---- | C] () -- C:\Users\Benni\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/25 17:59:34 | 000,110,592 | ---- | C] () -- C:\windows\System32\FsUsbExDevice.Dll
[2011/01/25 17:59:34 | 000,042,112 | ---- | C] () -- C:\windows\System32\FsUsbExDisk.Sys
[2011/01/07 11:18:55 | 000,001,769 | ---- | C] () -- C:\windows\Language_trs.ini
[2011/01/04 16:10:58 | 000,030,568 | ---- | C] () -- C:\windows\MusiccityDownload.exe
[2011/01/04 16:10:56 | 000,974,848 | ---- | C] () -- C:\windows\System32\cis-2.4.dll
[2011/01/04 16:10:56 | 000,081,920 | ---- | C] () -- C:\windows\System32\issacapi_bs-2.3.dll
[2011/01/04 16:10:56 | 000,065,536 | ---- | C] () -- C:\windows\System32\issacapi_pe-2.3.dll
[2011/01/04 16:10:56 | 000,057,344 | ---- | C] () -- C:\windows\System32\issacapi_se-2.3.dll
[2010/12/18 11:21:13 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/18 10:32:10 | 000,000,117 | ---- | C] () -- C:\windows\TmPfw.ini
[2010/12/18 10:30:50 | 000,006,144 | ---- | C] () -- C:\windows\System32\drivers\ASUSHWIO.SYS
[2010/12/18 10:09:45 | 000,004,692 | ---- | C] () -- C:\windows\System32\drivers\SamSfPa.dat
[2010/12/18 10:09:45 | 000,000,008 | ---- | C] () -- C:\windows\System32\drivers\rtkhdaud.dat
[2010/06/24 17:31:21 | 000,129,472 | ---- | C] () -- C:\windows\TISReg.exe
[2010/06/24 17:12:19 | 000,025,616 | ---- | C] () -- C:\windows\AsAcpiSvrLang.ini
[2010/06/24 17:10:26 | 000,131,984 | ---- | C] () -- C:\ProgramData\FullRemove.exe
[2010/06/24 17:08:32 | 000,011,520 | ---- | C] () -- C:\windows\System32\drivers\AsUpIO.sys
[2010/06/24 17:02:59 | 000,013,931 | ---- | C] () -- C:\windows\System32\RaCoInst.dat
[2009/10/26 04:38:22 | 000,000,176 | ---- | C] () -- C:\windows\explorer.exe.config
[2009/07/26 02:28:45 | 000,655,072 | ---- | C] () -- C:\windows\System32\perfh007.dat
[2009/07/26 02:28:45 | 000,295,922 | ---- | C] () -- C:\windows\System32\perfi007.dat
[2009/07/26 02:28:45 | 000,130,364 | ---- | C] () -- C:\windows\System32\perfc007.dat
[2009/07/26 02:28:45 | 000,038,104 | ---- | C] () -- C:\windows\System32\perfd007.dat
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/14 05:33:53 | 000,273,544 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,616,914 | ---- | C] () -- C:\windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,106,746 | ---- | C] () -- C:\windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat

< End of report >
         
--- --- ---



und der extra

OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 12/31/2011 3:17:12 PM - Run 1
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Benni\Downloads
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014.18 Mb Total Physical Memory | 218.29 Mb Available Physical Memory | 21.52% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 68.04 Gb Free Space | 68.04% Space Free | Partition Type: NTFS
Drive D: | 117.87 Gb Total Space | 53.00 Gb Free Space | 44.97% Space Free | Partition Type: NTFS
Drive E: | 630.24 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 186.31 Gb Total Space | 98.96 Gb Free Space | 53.11% Space Free | Partition Type: NTFS
 
Computer Name: BENNI-PC | User Name: Benni | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "D:\Program Files\Vision\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Program Files\Vision\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\Programme\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\Programme\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AutoUpdateDisableNotify" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{090C73E1-BB48-403D-9DFF-A60FD71FF73A}" = MySQL Connector J
"{16D0F2D2-242C-4885-BEF1-4B1655C141AE}" = Bing Bar
"{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"{185AFA7A-F63E-450B-94AA-011CAC18090E}" = E-Cam
"{1E5F3CC6-D390-4393-A2AA-6CEC04F1705A}" = Image Resizer Powertoy Clone for Windows
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java(TM) 7
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java(TM) SE Development Kit 7
"{38E5A3B1-ADF1-47E0-8024-76310A30EB36}" = LiveUpdate
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{491ADA37-04EE-2ECE-9F86-DDC0106047AC}" = Times Reader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B5092B6-F231-4D18-83BC-2618B729CA45}" = CapsHook
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{5FD88490-011C-4DF1-B886-F298D955171B}" = MySQL Connector Net 6.3.7
"{6333FC29-BFE5-4024-AC78-958A1A7555D1}" = EeeSplendid
"{66F9302D-E145-4375-8C84-54DA2339C483}" = MySQL Connector C 6.0.2
"{6F206B58-E2F7-4A70-ACAC-8E0ABFBC62F6}" = MySQL Connector/ODBC 5.1
"{71C0E38E-09F2-4386-9977-404D4F6640CD}" = Hotkey Service
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2
"{84C2B80B-64A2-4B22-93EC-F30C3D6BF7D8}" = Boingo Wi-Fi
"{859D40CF-8491-44AD-8FA8-7389CB418C64}" = 32 Bit HP CIO Components Installer
"{88F08F98-12BC-4613-81A2-8F9B88CFC73E}" = Super Hybrid Engine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}" = Ralink RT2860 Wireless LAN Card
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.VISIOR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIOR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.VISIOR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.VISIOR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0054-0407-0000-0000000FF1CE}" = Microsoft Office Visio MUI (German) 2010
"{90140000-0054-0407-0000-0000000FF1CE}_Office14.VISIOR_{1FEAC070-BB09-4055-9BD0-48CF52023F92}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-006D-0407-0000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.VISIOR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0057-0000-0000-0000000FF1CE}" = Microsoft Office Visio 2010
"{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{01D8AE4B-A04D-47E5-81BF-E3F98B81B8C3}" = Microsoft Visio 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{994223F3-A99B-4DDD-9E1D-0190A17C6860}" = Windows Live Family Safety
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.4.7 MUI
"{B9A129AB-CA6B-4CD1-B55C-792722E2B947}" = MySQL Installer
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C59C4A56-8560-4E3B-AA5D-BDCED4F110E7}" = MySQL Documents
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C1}" = WinZip 15.0
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D44AA979-47C2-4BC0-A860-09A54224EA44}_is1" = Game Park Console
"{D802DD00-16A8-4A58-AFC9-020C2380ECDA}" = EeeSplendid
"{DDE2DD42-9ABA-4164-BAAF-A8624819FAE3}" = Multimedia-Führerschein & Verkehr 2010/11
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3ABB4CC-1DC5-4430-BC49-D86AB708A9B8}" = MySQL Workbench 5.2 CE
"{E929D860-AB8D-4AC0-8B7F-8DB5D65E46D0}" = MySQL Server 5.5
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3D2DEDC-4732-4188-8A3A-1A3FFBD4D6C8}" = ebi.BookReader3J
"{F53503A3-41B3-4327-A5C0-B058AB72B90D}" = MySQL Examples and Samples 5.5
"{F58C1D44-4AC9-48E8-9049-7A6CDFCB415C}" = LocaleMe
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FD753E57-1F44-41E6-B962-E01D76676206}" = MySQL Connector C++ 1.1.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"B41C7C96D83162A676DA7365ADEFD6C1AF62A4EE" = Windows Driver Package - Broadcom Bluetooth  (07/17/2009 6.2.0.9403)
"B5C82F3814F82FB37F1513B3185399BD88892B08" = Windows Driver Package - Broadcom Bluetooth  (07/29/2009 6.1.7100.0)
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800)
"Blue Byte Game Channel" = Blue Byte Game Channel
"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Diagram Designer" = Diagram Designer
"Edraw Flowchart_is1" = Edraw Flowchart 6.1
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"KiSS PC-Link" = KiSS PC-Link 3.0.5
"KONICA MINOLTA magicolor 2400W" = KONICA MINOLTA magicolor 2400W
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Oceanis Change Background Windows 7_is1" = Oceanis Change Background Windows 7
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"Office14.VISIOR" = Microsoft Visio Professional 2010
"OpenVPN" = OpenVPN 2.1.1-gui-1.0.3
"PagePlace" = PagePlace
"PokerStars" = PokerStars
"S4Uninst" = Die Siedler IV
"SecureW2 EAP Suite" = SecureW2 EAP Suite 1.1.2 for Windows
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.6
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 (32-Bit)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 12/10/2011 3:02:19 PM | Computer Name = Benni-PC | Source = CVHSVC | ID = 100
Description = Nur zur Information.  (Patch task for {90140011-0066-0407-0000-0000000FF1CE}):
 DownloadLatest Failed: 
 
Error - 12/10/2011 5:16:08 PM | Computer Name = Benni-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei
 "C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
Der
 Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 12/12/2011 9:56:50 AM | Computer Name = Benni-PC | Source = .NET Runtime | ID = 1026
Description = 
 
Error - 12/12/2011 9:56:53 AM | Computer Name = Benni-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: MySQLWorkbench.exe, Version: 5.2.34.7780,
 Zeitstempel: 0x4ddbbfe9  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00908ec4  ID des fehlerhaften
 Prozesses: 0xcedc  Startzeit der fehlerhaften Anwendung: 0x01ccb8d4da778eec  Pfad der
 fehlerhaften Anwendung: D:\Program Files\MySQL\MySQL Workbench CE 5.2.34.2\MySQLWorkbench.exe
Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 2508f454-24c9-11e1-9f3b-20cf3070d3d6
 
Error - 12/12/2011 11:23:53 AM | Computer Name = Benni-PC | Source = Application Hang | ID = 1002
Description = Programm MySQLWorkbench.exe, Version 5.2.34.7780 kann nicht mehr unter
 Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf 
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
 zu suchen.    Prozess-ID: caa0    Startzeit: 01ccb8d5efe5d6eb    Endzeit: 155    Anwendungspfad:
 D:\Program Files\MySQL\MySQL Workbench CE 5.2.34.2\MySQLWorkbench.exe    Berichts-ID:
 42ccef3e-24d5-11e1-9f3b-20cf3070d3d6  
 
Error - 12/12/2011 6:29:06 PM | Computer Name = Benni-PC | Source = .NET Runtime | ID = 1026
Description = 
 
Error - 12/12/2011 6:29:07 PM | Computer Name = Benni-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: MySQLWorkbench.exe, Version: 5.2.34.7780,
 Zeitstempel: 0x4ddbbfe9  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x055b6e50  ID des fehlerhaften
 Prozesses: 0x18d54  Startzeit der fehlerhaften Anwendung: 0x01ccb91b66bfc823  Pfad 
der fehlerhaften Anwendung: D:\Program Files\MySQL\MySQL Workbench CE 5.2.34.2\MySQLWorkbench.exe
Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: b3b4e9aa-2510-11e1-9f3b-20cf3070d3d6
 
Error - 12/14/2011 3:50:27 PM | Computer Name = Benni-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei
 "C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
Der
 Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 12/14/2011 4:12:23 PM | Computer Name = Benni-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei
 "C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
Der
 Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 12/17/2011 2:51:59 PM | Computer Name = Benni-PC | Source = CVHSVC | ID = 100
Description = Nur zur Information.  (Patch task for {90140011-0066-0407-0000-0000000FF1CE}):
 DownloadLatest Failed: 
 
[ System Events ]
Error - 12/8/2011 1:52:33 PM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst ShellHWDetection erreicht.
 
Error - 12/10/2011 3:01:34 PM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst ShellHWDetection erreicht.
 
Error - 12/11/2011 3:45:21 AM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst Wlansvc erreicht.
 
Error - 12/11/2011 7:03:30 AM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst Wlansvc erreicht.
 
Error - 12/12/2011 4:38:36 AM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst ShellHWDetection erreicht.
 
Error - 12/12/2011 10:46:14 AM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst ShellHWDetection erreicht.
 
Error - 12/13/2011 9:47:40 AM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst upnphost erreicht.
 
Error - 12/15/2011 3:39:38 PM | Computer Name = Benni-PC | Source = Tcpip | ID = 4199
Description = Das System hat einen Adressenkonflikt der IP-Adresse 192.168.1.2 mit
 dem Computer mit der  Netzwerkhardwareadresse 00-15-0C-B9-5E-34 ermittelt. Netzwerkvorgänge
 könnten daher auf diesem  System unterbrochen werden.
 
Error - 12/17/2011 2:51:18 PM | Computer Name = Benni-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst ShellHWDetection erreicht.
 
Error - 12/17/2011 2:52:38 PM | Computer Name = Benni-PC | Source = Server | ID = 2505
Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht
 \Device\NetBT_Tcpip_{E79AF3FB-DABC-4232-8FA7-61445012E2AB} vom Serverdienst nicht
 gebunden werden. Der Serverdienst konnte nicht gestartet werden.
 
 
< End of report >
         
--- --- ---
__________________


Alt 02.01.2012, 16:28   #3
markusg
/// Malware-holic
 
95p.com redirekt rootkid - Standard

95p.com redirekt rootkid



Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.

Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
  • Besuche folgende Seite für Downloadlinks und Anweisungen für dieses
    Tool

    Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Hinweis:
    Gehe sicher das all deine Anti Virus und Anti Malware Programme abgeschalten sind, damit diese Combofix nicht bei der Arbeit stören.
  • Poste bitte die C:\Combofix.txt in deiner nächsten Antwort.
__________________
__________________

Antwort

Themen zu 95p.com redirekt rootkid
95p.com, andere, ccc, config, device, drivers, gestern, google, harddisk, intel, manual, object, partition, problem, rootkit, scan, seite, servicepack, suche, system32, tdss, tool, version, windows\system32\drivers, works



Ähnliche Themen: 95p.com redirekt rootkid


  1. Werbetooltipps doppelt blau unterstrichen in Chrome und IE 11 (Win 8.1) + Redirekt
    Plagegeister aller Art und deren Bekämpfung - 13.04.2014 (7)
  2. Windows XP, Agent-ARRQ, Rootkid-Gen, Generic-IF
    Log-Analyse und Auswertung - 10.09.2013 (15)
  3. Redirekt Virus
    Plagegeister aller Art und deren Bekämpfung - 19.10.2012 (13)
  4. Probleme mit Trojan.Small, Trojan.Sirefef.AG.35, Rootkid.0Access,TR/ATRAPS.Gen2
    Log-Analyse und Auswertung - 28.06.2012 (23)
  5. Redirekt Virus Google und andere Bidvertiser ?!
    Plagegeister aller Art und deren Bekämpfung - 02.04.2012 (28)
  6. TR/rootkid.gen & TR/sirefef.BP.1 - Problem
    Plagegeister aller Art und deren Bekämpfung - 12.03.2012 (6)
  7. Alle Dateien versteckt - behoben, jetzt ständg redirekt zu gomeo
    Log-Analyse und Auswertung - 30.05.2011 (2)
  8. redirekt zu cpcadnet
    Plagegeister aller Art und deren Bekämpfung - 12.02.2011 (15)
  9. Rootkid.Agend gefunden - Internet stürzt beim Start eines PC ab
    Plagegeister aller Art und deren Bekämpfung - 30.08.2010 (3)
  10. Wie kann man TR/Spy.gen und TR/Rootkid.gen entfernen oder unschädlich machen.
    Log-Analyse und Auswertung - 14.02.2010 (6)
  11. Redirekt Browser / Eingeschränkte Netzverbindung / Antir und Malwareohne Wirkung
    Log-Analyse und Auswertung - 06.01.2010 (3)
  12. 3 Vieren/Trojaner und evt Rootkid
    Plagegeister aller Art und deren Bekämpfung - 03.10.2009 (9)
  13. TR/Rootkid.C und TR/Agent.143360 und 5 Würmer und langsames Internet
    Log-Analyse und Auswertung - 30.07.2007 (8)

Zum Thema 95p.com redirekt rootkid - hey habe seit gestern das problem das ich bei einer google suche immer auf die seite 95p.com komme. habe bissel gelesen und habe dann erstmal TDSS einen scan gemacht und - 95p.com redirekt rootkid...
Archiv
Du betrachtest: 95p.com redirekt rootkid auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.