![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: files indexation process failedWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #1 |
![]() | files indexation process failed Hallo, ich habe mir einenn Virus eingefangen. Es blinkten eine Menge von Meldungen auf die besagten: Hard drive clusters are partly damaged Windows - Delayed Write Failed Critical Error Außerdem ist mein kompletter Desktop leer und das Startmenü ist nicht mehr zu sehen. Habe das Problem gegoogelt und auf der Seite mcafee.com. folgende Anweisungen befolgt: 1) Habe Rootkit TDSSKiller laufen lassen. 2)Habe Malwarebytes laufen lassen, danach waren die Fehlermeldungen weg, der Desktop ist immer noch schwarz, das Startmenü ist nicht wieder da. 3) Habe mit der Systemwiederherstellung einen Herstellungspunkt vom 18.02.2012 gewählt. Es ist noch keine Besserung eingetreten. logfile tdsskiller 21.03.2012 00.23 Code:
ATTFilter 00:22:20.0309 1712 TDSS rootkit removing tool 2.7.20.0 Mar 9 2012 17:10:43
00:22:20.0449 1712 ============================================================
00:22:20.0449 1712 Current date / time: 2012/03/21 00:22:20.0449
00:22:20.0449 1712 SystemInfo:
00:22:20.0449 1712
00:22:20.0449 1712 OS Version: 6.0.6002 ServicePack: 2.0
00:22:20.0449 1712 Product type: Workstation
00:22:20.0449 1712 ComputerName: YVONNE-PC
00:22:20.0451 1712 UserName: Yvonne
00:22:20.0451 1712 Windows directory: C:\Windows
00:22:20.0451 1712 System windows directory: C:\Windows
00:22:20.0451 1712 Processor architecture: Intel x86
00:22:20.0451 1712 Number of processors: 2
00:22:20.0451 1712 Page size: 0x1000
00:22:20.0451 1712 Boot type: Normal boot
00:22:20.0451 1712 ============================================================
00:22:21.0764 1712 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
00:22:21.0768 1712 \Device\Harddisk0\DR0:
00:22:21.0769 1712 MBR used
00:22:21.0769 1712 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x12D50800
00:22:21.0769 1712 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1303F000, BlocksNum 0x123EF800
00:22:21.0887 1712 Initialize success
00:22:21.0887 1712 ============================================================
00:22:33.0130 4268 ============================================================
00:22:33.0130 4268 Scan started
00:22:33.0131 4268 Mode: Manual;
00:22:33.0131 4268 ============================================================
00:22:34.0353 4268 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
00:22:34.0362 4268 ACPI - ok
00:22:34.0437 4268 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
00:22:34.0450 4268 adp94xx - ok
00:22:34.0580 4268 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
00:22:34.0586 4268 adpahci - ok
00:22:34.0630 4268 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
00:22:34.0633 4268 adpu160m - ok
00:22:34.0760 4268 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
00:22:34.0763 4268 adpu320 - ok
00:22:34.0843 4268 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
00:22:34.0853 4268 AFD - ok
00:22:34.0960 4268 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
00:22:34.0962 4268 agp440 - ok
00:22:34.0995 4268 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
00:22:34.0997 4268 aic78xx - ok
00:22:35.0098 4268 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
00:22:35.0099 4268 aliide - ok
00:22:35.0134 4268 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
00:22:35.0136 4268 amdagp - ok
00:22:35.0162 4268 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
00:22:35.0163 4268 amdide - ok
00:22:35.0302 4268 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
00:22:35.0303 4268 AmdK7 - ok
00:22:35.0340 4268 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
00:22:35.0341 4268 AmdK8 - ok
00:22:35.0444 4268 ApfiltrService (45f47f79ad3f587a334345fd2969354b) C:\Windows\system32\DRIVERS\Apfiltr.sys
00:22:35.0453 4268 ApfiltrService - ok
00:22:35.0517 4268 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
00:22:35.0521 4268 arc - ok
00:22:35.0609 4268 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
00:22:35.0610 4268 arcsas - ok
00:22:35.0674 4268 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
00:22:35.0675 4268 AsyncMac - ok
00:22:35.0777 4268 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
00:22:35.0779 4268 atapi - ok
00:22:35.0952 4268 atikmdag (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
00:22:36.0070 4268 atikmdag - ok
00:22:36.0186 4268 AtiPcie (4aa1eb65481c392955939e735d27118b) C:\Windows\system32\DRIVERS\AtiPcie.sys
00:22:36.0189 4268 AtiPcie - ok
00:22:36.0245 4268 avgntflt (7713e4eb0276702faa08e52a6e23f2a6) C:\Windows\system32\DRIVERS\avgntflt.sys
00:22:36.0248 4268 avgntflt - ok
00:22:36.0457 4268 avipbb (13b02b9b969dde270cd7c351203dad3c) C:\Windows\system32\DRIVERS\avipbb.sys
00:22:36.0461 4268 avipbb - ok
00:22:36.0550 4268 avkmgr (271cfd1a989209b1964e24d969552bf7) C:\Windows\system32\DRIVERS\avkmgr.sys
00:22:36.0553 4268 avkmgr - ok
00:22:36.0599 4268 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
00:22:36.0602 4268 Beep - ok
00:22:36.0721 4268 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
00:22:36.0723 4268 blbdrive - ok
00:22:36.0833 4268 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
00:22:36.0837 4268 bowser - ok
00:22:36.0938 4268 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
00:22:36.0940 4268 BrFiltLo - ok
00:22:37.0045 4268 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
00:22:37.0048 4268 BrFiltUp - ok
00:22:37.0143 4268 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
00:22:37.0144 4268 Brserid - ok
00:22:37.0220 4268 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
00:22:37.0222 4268 BrSerWdm - ok
00:22:37.0291 4268 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
00:22:37.0293 4268 BrUsbMdm - ok
00:22:37.0577 4268 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
00:22:37.0580 4268 BrUsbSer - ok
00:22:37.0675 4268 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
00:22:37.0677 4268 BTHMODEM - ok
00:22:37.0762 4268 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
00:22:37.0767 4268 cdfs - ok
00:22:37.0861 4268 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
00:22:37.0864 4268 cdrom - ok
00:22:37.0924 4268 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
00:22:37.0928 4268 circlass - ok
00:22:38.0058 4268 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
00:22:38.0066 4268 CLFS - ok
00:22:38.0150 4268 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
00:22:38.0153 4268 CmBatt - ok
00:22:38.0309 4268 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
00:22:38.0310 4268 cmdide - ok
00:22:38.0379 4268 CnxtHdAudService (b6e7991e3d6146c04c85cd31af22a381) C:\Windows\system32\drivers\CHDRT32.sys
00:22:38.0390 4268 CnxtHdAudService - ok
00:22:38.0466 4268 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
00:22:38.0469 4268 Compbatt - ok
00:22:38.0537 4268 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
00:22:38.0540 4268 crcdisk - ok
00:22:38.0579 4268 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
00:22:38.0581 4268 Crusoe - ok
00:22:38.0722 4268 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
00:22:38.0726 4268 DfsC - ok
00:22:38.0782 4268 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
00:22:38.0784 4268 disk - ok
00:22:38.0968 4268 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
00:22:38.0969 4268 drmkaud - ok
00:22:39.0126 4268 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
00:22:39.0146 4268 DXGKrnl - ok
00:22:39.0274 4268 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
00:22:39.0279 4268 E1G60 - ok
00:22:39.0370 4268 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
00:22:39.0379 4268 Ecache - ok
00:22:39.0548 4268 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
00:22:39.0555 4268 elxstor - ok
00:22:39.0689 4268 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
00:22:39.0694 4268 ErrDev - ok
00:22:39.0823 4268 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
00:22:39.0881 4268 exfat - ok
00:22:40.0010 4268 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
00:22:40.0047 4268 fastfat - ok
00:22:40.0253 4268 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
00:22:40.0254 4268 fdc - ok
00:22:40.0346 4268 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
00:22:40.0350 4268 FileInfo - ok
00:22:40.0411 4268 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
00:22:40.0413 4268 Filetrace - ok
00:22:40.0498 4268 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
00:22:40.0500 4268 flpydisk - ok
00:22:40.0585 4268 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
00:22:40.0596 4268 FltMgr - ok
00:22:40.0701 4268 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
00:22:40.0705 4268 Fs_Rec - ok
00:22:40.0759 4268 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
00:22:40.0763 4268 gagp30kx - ok
00:22:40.0812 4268 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
00:22:40.0817 4268 GEARAspiWDM - ok
00:22:40.0913 4268 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
00:22:40.0927 4268 HdAudAddService - ok
00:22:41.0005 4268 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
00:22:41.0021 4268 HDAudBus - ok
00:22:41.0087 4268 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
00:22:41.0088 4268 HidBth - ok
00:22:41.0225 4268 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
00:22:41.0226 4268 HidIr - ok
00:22:41.0308 4268 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
00:22:41.0310 4268 HidUsb - ok
00:22:41.0402 4268 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
00:22:41.0404 4268 HpCISSs - ok
00:22:41.0473 4268 HSF_DPV (fadd7095163cb3cb4073793ebb50fe75) C:\Windows\system32\DRIVERS\HSX_DPV.sys
00:22:41.0503 4268 HSF_DPV - ok
00:22:41.0605 4268 HSXHWAZL (058783bedd17615d1fece09f77960436) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
00:22:41.0611 4268 HSXHWAZL - ok
00:22:41.0664 4268 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
00:22:41.0676 4268 HTTP - ok
00:22:41.0794 4268 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
00:22:41.0796 4268 i2omp - ok
00:22:41.0841 4268 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
00:22:41.0845 4268 i8042prt - ok
00:22:41.0892 4268 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
00:22:41.0901 4268 iaStorV - ok
00:22:42.0133 4268 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
00:22:42.0135 4268 iirsp - ok
00:22:42.0257 4268 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
00:22:42.0258 4268 intelide - ok
00:22:42.0320 4268 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
00:22:42.0321 4268 intelppm - ok
00:22:42.0442 4268 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
00:22:42.0444 4268 IpFilterDriver - ok
00:22:42.0468 4268 IpInIp - ok
00:22:42.0513 4268 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
00:22:42.0514 4268 IPMIDRV - ok
00:22:42.0818 4268 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
00:22:42.0821 4268 IPNAT - ok
00:22:42.0919 4268 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
00:22:42.0921 4268 IRENUM - ok
00:22:42.0986 4268 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
00:22:42.0988 4268 isapnp - ok
00:22:43.0058 4268 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
00:22:43.0067 4268 iScsiPrt - ok
00:22:43.0198 4268 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
00:22:43.0200 4268 iteatapi - ok
00:22:43.0252 4268 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
00:22:43.0255 4268 iteraid - ok
00:22:43.0384 4268 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
00:22:43.0390 4268 kbdclass - ok
00:22:43.0442 4268 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys
00:22:43.0444 4268 kbdhid - ok
00:22:43.0555 4268 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys
00:22:43.0567 4268 KSecDD - ok
00:22:43.0628 4268 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
00:22:43.0631 4268 lltdio - ok
00:22:43.0770 4268 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
00:22:43.0772 4268 LSI_FC - ok
00:22:43.0800 4268 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
00:22:43.0802 4268 LSI_SAS - ok
00:22:43.0945 4268 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
00:22:43.0946 4268 LSI_SCSI - ok
00:22:44.0005 4268 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
00:22:44.0010 4268 luafv - ok
00:22:44.0198 4268 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
00:22:44.0202 4268 mdmxsdk - ok
00:22:44.0241 4268 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
00:22:44.0243 4268 megasas - ok
00:22:44.0347 4268 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
00:22:44.0354 4268 MegaSR - ok
00:22:44.0474 4268 mfeavfk (bafdd5e28baea99d7f4772af2f5ec7ee) C:\Windows\system32\drivers\mfeavfk.sys
00:22:44.0482 4268 mfeavfk - ok
00:22:44.0524 4268 mfebopk (1d003e3056a43d881597d6763e83b943) C:\Windows\system32\drivers\mfebopk.sys
00:22:44.0526 4268 mfebopk - ok
00:22:44.0646 4268 mfehidk (3f138a1c8a0659f329f242d1e389b2cf) C:\Windows\system32\drivers\mfehidk.sys
00:22:44.0658 4268 mfehidk - ok
00:22:44.0737 4268 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\Windows\system32\drivers\mferkdk.sys
00:22:44.0741 4268 mferkdk - ok
00:22:44.0844 4268 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\Windows\system32\drivers\mfesmfk.sys
00:22:44.0847 4268 mfesmfk - ok
00:22:44.0913 4268 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
00:22:44.0916 4268 Modem - ok
00:22:45.0150 4268 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
00:22:45.0158 4268 monitor - ok
00:22:45.0268 4268 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
00:22:45.0272 4268 mouclass - ok
00:22:45.0329 4268 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
00:22:45.0332 4268 mouhid - ok
00:22:45.0414 4268 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
00:22:45.0417 4268 MountMgr - ok
00:22:45.0456 4268 MPFP (95675c3398dcc084c8d1dc35cc4e9e01) C:\Windows\system32\Drivers\Mpfp.sys
00:22:45.0460 4268 MPFP - ok
00:22:45.0668 4268 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
00:22:45.0671 4268 mpio - ok
00:22:45.0766 4268 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
00:22:45.0773 4268 mpsdrv - ok
00:22:45.0840 4268 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
00:22:45.0843 4268 Mraid35x - ok
00:22:45.0964 4268 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
00:22:45.0973 4268 MRxDAV - ok
00:22:46.0054 4268 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
00:22:46.0058 4268 mrxsmb - ok
00:22:46.0200 4268 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
00:22:46.0208 4268 mrxsmb10 - ok
00:22:46.0346 4268 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
00:22:46.0351 4268 mrxsmb20 - ok
00:22:46.0408 4268 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys
00:22:46.0409 4268 msahci - ok
00:22:46.0532 4268 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
00:22:46.0537 4268 msdsm - ok
00:22:46.0597 4268 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
00:22:46.0601 4268 Msfs - ok
00:22:46.0696 4268 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
00:22:46.0700 4268 msisadrv - ok
00:22:46.0782 4268 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
00:22:46.0784 4268 MSKSSRV - ok
00:22:46.0876 4268 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
00:22:46.0877 4268 MSPCLOCK - ok
00:22:46.0914 4268 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
00:22:46.0915 4268 MSPQM - ok
00:22:46.0969 4268 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
00:22:46.0974 4268 MsRPC - ok
00:22:47.0101 4268 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
00:22:47.0103 4268 mssmbios - ok
00:22:47.0177 4268 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
00:22:47.0179 4268 MSTEE - ok
00:22:47.0304 4268 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
00:22:47.0308 4268 Mup - ok
00:22:47.0396 4268 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
00:22:47.0401 4268 NativeWifiP - ok
00:22:47.0523 4268 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
00:22:47.0537 4268 NDIS - ok
00:22:47.0619 4268 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
00:22:47.0621 4268 NdisTapi - ok
00:22:47.0658 4268 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
00:22:47.0661 4268 Ndisuio - ok
00:22:47.0758 4268 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
00:22:47.0858 4268 NdisWan - ok
00:22:48.0137 4268 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
00:22:48.0141 4268 NDProxy - ok
00:22:48.0221 4268 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
00:22:48.0224 4268 NetBIOS - ok
00:22:48.0330 4268 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
00:22:48.0340 4268 netbt - ok
00:22:48.0494 4268 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
00:22:48.0497 4268 nfrd960 - ok
00:22:48.0570 4268 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
00:22:48.0573 4268 Npfs - ok
00:22:48.0669 4268 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
00:22:48.0673 4268 nsiproxy - ok
00:22:48.0782 4268 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
00:22:48.0816 4268 Ntfs - ok
00:22:48.0990 4268 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
00:22:48.0992 4268 ntrigdigi - ok
00:22:49.0178 4268 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
00:22:49.0182 4268 Null - ok
00:22:49.0385 4268 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
00:22:49.0387 4268 nvraid - ok
00:22:49.0488 4268 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
00:22:49.0492 4268 nvstor - ok
00:22:49.0559 4268 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
00:22:49.0571 4268 nv_agp - ok
00:22:49.0594 4268 NwlnkFlt - ok
00:22:49.0626 4268 NwlnkFwd - ok
00:22:49.0706 4268 O2MDRDR (78575368974962042472f18b24d3cf28) C:\Windows\system32\DRIVERS\o2media.sys
00:22:49.0709 4268 O2MDRDR - ok
00:22:49.0936 4268 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
00:22:49.0940 4268 ohci1394 - ok
00:22:50.0092 4268 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
00:22:50.0095 4268 Parport - ok
00:22:50.0179 4268 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
00:22:50.0184 4268 partmgr - ok
00:22:50.0299 4268 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
00:22:50.0301 4268 Parvdm - ok
00:22:50.0386 4268 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
00:22:50.0393 4268 pci - ok
00:22:50.0483 4268 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
00:22:50.0487 4268 pciide - ok
00:22:50.0542 4268 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
00:22:50.0547 4268 pcmcia - ok
00:22:50.0669 4268 PCTBD (3a0262b85b5bb4d4cfc096ea00ed610b) C:\Windows\system32\Drivers\PCTBD.sys
00:22:50.0672 4268 PCTBD - ok
00:22:50.0937 4268 PCTCore (0edb74bd0d52d6d94cf862322e48b94e) C:\Windows\system32\drivers\PCTCore.sys
00:22:50.0952 4268 PCTCore - ok
00:22:51.0021 4268 pctDS (8734f7346b39a710491e0ddb136da2a3) C:\Windows\system32\drivers\pctDS.sys
00:22:51.0036 4268 pctDS - ok
00:22:51.0184 4268 pctEFA (653d8079cc000ec454789740a07b84a8) C:\Windows\system32\drivers\pctEFA.sys
00:22:51.0211 4268 pctEFA - ok
00:22:51.0344 4268 PCTSD (eb98f7514dcf1b922b318e6182d836b1) C:\Windows\system32\Drivers\PCTSD.sys
00:22:51.0360 4268 PCTSD - ok
00:22:51.0635 4268 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
00:22:51.0664 4268 PEAUTH - ok
00:22:51.0895 4268 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
00:22:51.0898 4268 PptpMiniport - ok
00:22:51.0925 4268 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
00:22:51.0927 4268 Processor - ok
00:22:51.0992 4268 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
00:22:51.0995 4268 PSched - ok
00:22:52.0085 4268 PxHelp20 (f7bb4e7a7c02ab4a2672937e124e306e) C:\Windows\system32\Drivers\PxHelp20.sys
00:22:52.0088 4268 PxHelp20 - ok
00:22:52.0131 4268 QIOMem (674eba70a52c02696e503b0a57ae6372) C:\Windows\system32\DRIVERS\QIOMem.sys
00:22:52.0134 4268 QIOMem - ok
00:22:52.0268 4268 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
00:22:52.0286 4268 ql2300 - ok
00:22:52.0392 4268 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
00:22:52.0395 4268 ql40xx - ok
00:22:52.0436 4268 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
00:22:52.0438 4268 QWAVEdrv - ok
00:22:52.0554 4268 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
00:22:52.0557 4268 RasAcd - ok
00:22:52.0610 4268 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
00:22:52.0615 4268 Rasl2tp - ok
00:22:52.0688 4268 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
00:22:52.0691 4268 RasPppoe - ok
00:22:52.0834 4268 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
00:22:52.0836 4268 RasSstp - ok
00:22:52.0895 4268 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
00:22:52.0902 4268 rdbss - ok
00:22:52.0994 4268 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
00:22:52.0996 4268 RDPCDD - ok
00:22:53.0041 4268 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
00:22:53.0044 4268 rdpdr - ok
00:22:53.0329 4268 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
00:22:53.0332 4268 RDPENCDD - ok
00:22:53.0472 4268 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys
00:22:53.0516 4268 RDPWD - ok
00:22:53.0799 4268 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
00:22:53.0802 4268 rspndr - ok
00:22:53.0983 4268 RTL8187B (5139a6c37c2d854e7b0ee6fa1f93ccda) C:\Windows\system32\DRIVERS\RTL8187B.sys
00:22:53.0993 4268 RTL8187B - ok
00:22:54.0091 4268 RtlProt (0d60b8c10a2c5e8dd620b3fdeb1cda64) C:\Windows\system32\DRIVERS\rtlprot.sys
00:22:54.0095 4268 RtlProt - ok
00:22:54.0157 4268 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
00:22:54.0159 4268 sbp2port - ok
00:22:54.0272 4268 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
00:22:54.0277 4268 sdbus - ok
00:22:54.0372 4268 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
00:22:54.0376 4268 secdrv - ok
00:22:54.0481 4268 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
00:22:54.0484 4268 seehcri - ok
00:22:54.0589 4268 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
00:22:54.0591 4268 Serenum - ok
00:22:54.0687 4268 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
00:22:54.0690 4268 Serial - ok
00:22:54.0776 4268 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
00:22:54.0778 4268 sermouse - ok
00:22:54.0928 4268 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
00:22:54.0929 4268 sffdisk - ok
00:22:55.0169 4268 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
00:22:55.0171 4268 sffp_mmc - ok
00:22:55.0345 4268 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
00:22:55.0349 4268 sffp_sd - ok
00:22:55.0442 4268 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
00:22:55.0446 4268 sfloppy - ok
00:22:55.0573 4268 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
00:22:55.0578 4268 sisagp - ok
00:22:55.0658 4268 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
00:22:55.0660 4268 SiSRaid2 - ok
00:22:55.0708 4268 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
00:22:55.0711 4268 SiSRaid4 - ok
00:22:55.0862 4268 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
00:22:55.0919 4268 Smb - ok
00:22:56.0155 4268 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
00:22:56.0158 4268 spldr - ok
00:22:56.0402 4268 sptd (71e276f6d189413266ea22171806597b) C:\Windows\system32\Drivers\sptd.sys
00:22:56.0403 4268 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
00:22:56.0418 4268 sptd ( LockedFile.Multi.Generic ) - warning
00:22:56.0418 4268 sptd - detected LockedFile.Multi.Generic (1)
00:22:56.0670 4268 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
00:22:56.0685 4268 srv - ok
00:22:56.0870 4268 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
00:22:56.0882 4268 srv2 - ok
00:22:57.0089 4268 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
00:22:57.0097 4268 srvnet - ok
00:22:57.0221 4268 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
00:22:57.0228 4268 ssmdrv - ok
00:22:57.0297 4268 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
00:22:57.0305 4268 swenum - ok
00:22:57.0441 4268 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
00:22:57.0442 4268 Symc8xx - ok
00:22:57.0470 4268 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
00:22:57.0471 4268 Sym_hi - ok
00:22:57.0500 4268 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
00:22:57.0502 4268 Sym_u3 - ok
00:22:57.0756 4268 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
00:22:57.0780 4268 Tcpip - ok
00:22:57.0949 4268 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
00:22:57.0964 4268 Tcpip6 - ok
00:22:58.0106 4268 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
00:22:58.0110 4268 tcpipreg - ok
00:22:58.0174 4268 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys
00:22:58.0178 4268 tdcmdpst - ok
00:22:58.0303 4268 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
00:22:58.0305 4268 TDPIPE - ok
00:22:58.0558 4268 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
00:22:58.0563 4268 TDTCP - ok
00:22:58.0694 4268 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
00:22:58.0702 4268 tdx - ok
00:22:58.0765 4268 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
00:22:58.0772 4268 TermDD - ok
00:22:58.0946 4268 Tosrfcom - ok
00:22:59.0006 4268 tosrfec (5c4103544612e5011ef46301b93d1aa6) C:\Windows\system32\DRIVERS\tosrfec.sys
00:22:59.0012 4268 tosrfec - ok
00:22:59.0069 4268 tos_sps32 (1ea5f27c29405bf49799feca77186da9) C:\Windows\system32\DRIVERS\tos_sps32.sys
00:22:59.0086 4268 tos_sps32 - ok
00:22:59.0231 4268 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
00:22:59.0234 4268 tssecsrv - ok
00:22:59.0276 4268 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
00:22:59.0282 4268 tunmp - ok
00:22:59.0354 4268 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
00:22:59.0358 4268 tunnel - ok
00:22:59.0478 4268 TVALZ (792a8b80f8188aba4b2be271583f3e46) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
00:22:59.0482 4268 TVALZ - ok
00:22:59.0540 4268 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
00:22:59.0543 4268 uagp35 - ok
00:22:59.0705 4268 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
00:22:59.0710 4268 udfs - ok
00:22:59.0844 4268 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
00:22:59.0845 4268 uliagpkx - ok
00:22:59.0897 4268 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
00:22:59.0902 4268 uliahci - ok
00:23:00.0004 4268 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
00:23:00.0006 4268 UlSata - ok
00:23:00.0057 4268 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
00:23:00.0059 4268 ulsata2 - ok
00:23:00.0102 4268 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
00:23:00.0106 4268 umbus - ok
00:23:00.0239 4268 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
00:23:00.0244 4268 usbccgp - ok
00:23:00.0289 4268 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
00:23:00.0294 4268 usbcir - ok
00:23:00.0354 4268 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
00:23:00.0359 4268 usbehci - ok
00:23:00.0449 4268 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
00:23:00.0456 4268 usbhub - ok
00:23:00.0499 4268 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
00:23:00.0503 4268 usbohci - ok
00:23:00.0606 4268 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
00:23:00.0607 4268 usbprint - ok
00:23:00.0691 4268 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
00:23:00.0693 4268 USBSTOR - ok
00:23:00.0969 4268 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
00:23:00.0973 4268 usbuhci - ok
00:23:01.0125 4268 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
00:23:01.0132 4268 usbvideo - ok
00:23:01.0238 4268 UVCFTR (8c5094a8ab24de7496c7c19942f2df04) C:\Windows\system32\Drivers\UVCFTR_S.SYS
00:23:01.0243 4268 UVCFTR - ok
00:23:01.0371 4268 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
00:23:01.0377 4268 vga - ok
00:23:01.0439 4268 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
00:23:01.0444 4268 VgaSave - ok
00:23:01.0494 4268 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
00:23:01.0496 4268 viaagp - ok
00:23:01.0572 4268 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
00:23:01.0576 4268 ViaC7 - ok
00:23:01.0661 4268 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
00:23:01.0662 4268 viaide - ok
00:23:01.0699 4268 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
00:23:01.0700 4268 volmgr - ok
00:23:01.0843 4268 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
00:23:01.0846 4268 volmgrx - ok
00:23:01.0941 4268 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
00:23:01.0949 4268 volsnap - ok
00:23:02.0026 4268 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
00:23:02.0028 4268 vsmraid - ok
00:23:02.0119 4268 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
00:23:02.0121 4268 WacomPen - ok
00:23:02.0155 4268 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:23:02.0159 4268 Wanarp - ok
00:23:02.0167 4268 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:23:02.0169 4268 Wanarpv6 - ok
00:23:02.0265 4268 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
00:23:02.0266 4268 Wd - ok
00:23:02.0337 4268 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
00:23:02.0353 4268 Wdf01000 - ok
00:23:02.0483 4268 winachsf (bb9cbaf6ac20452b245c324f1f50ee81) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
00:23:02.0505 4268 winachsf - ok
00:23:02.0670 4268 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
00:23:02.0674 4268 WmiAcpi - ok
00:23:02.0881 4268 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
00:23:02.0883 4268 WpdUsb - ok
00:23:03.0004 4268 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
00:23:03.0006 4268 ws2ifsl - ok
00:23:03.0059 4268 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
00:23:03.0062 4268 WUDFRd - ok
00:23:03.0103 4268 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
00:23:03.0107 4268 XAudio - ok
00:23:03.0262 4268 yukonwlh (7d4cca3659fa0780603206e3d12a993f) C:\Windows\system32\DRIVERS\yk60x86.sys
00:23:03.0274 4268 yukonwlh - ok
00:23:03.0314 4268 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
00:23:03.0482 4268 \Device\Harddisk0\DR0 - ok
00:23:03.0525 4268 Boot (0x1200) (96e7f834872d2e0e3ae57f0f7bff19b5) \Device\Harddisk0\DR0\Partition0
00:23:03.0740 4268 \Device\Harddisk0\DR0\Partition0 - ok
00:23:03.0770 4268 Boot (0x1200) (f594c1360451c2337f5b316771e93898) \Device\Harddisk0\DR0\Partition1
00:23:03.0774 4268 \Device\Harddisk0\DR0\Partition1 - ok
00:23:03.0775 4268 ============================================================
00:23:03.0776 4268 Scan finished
00:23:03.0776 4268 ============================================================
00:23:03.0826 5608 Detected object count: 1
00:23:03.0826 5608 Actual detected object count: 1
00:23:20.0185 5608 C:\Windows\system32\Drivers\sptd.sys - copied to quarantine
00:23:20.0345 5608 HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted on reboot
00:23:20.0399 5608 HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted on reboot
00:23:20.0426 5608 HKLM\SYSTEM\ControlSet003\services\sptd - will be deleted on reboot
00:23:20.0457 5608 C:\Windows\system32\Drivers\sptd.sys - will be deleted on reboot
00:23:20.0457 5608 sptd ( LockedFile.Multi.Generic ) - User select action: Delete
00:23:24.0866 4500 Deinitialize success
Code:
ATTFilter 2012/03/21 18:13:05 +0100 YVONNE-PC Yvonne MESSAGE Starting protection
2012/03/21 18:13:09 +0100 YVONNE-PC Yvonne MESSAGE Protection started successfully
2012/03/21 18:13:12 +0100 YVONNE-PC Yvonne MESSAGE Starting IP protection
2012/03/21 18:13:17 +0100 YVONNE-PC Yvonne MESSAGE IP Protection started successfully
2012/03/21 18:21:19 +0100 YVONNE-PC Yvonne MESSAGE Executing scheduled update: Daily
2012/03/21 18:21:21 +0100 YVONNE-PC Yvonne MESSAGE Database already up-to-date
2012/03/21 19:18:28 +0100 YVONNE-PC Yvonne DETECTION C:\ProgramData\8HaWtjvalLWn8y.exe Trojan.FakeAlert QUARANTINE
2012/03/21 19:18:28 +0100 YVONNE-PC Yvonne ERROR Quarantine failed: DeleteFile failed with error code 5
2012/03/21 19:18:33 +0100 YVONNE-PC Yvonne DETECTION C:\ProgramData\8HaWtjvalLWn8y.exe Trojan.FakeAlert DENY
2012/03/21 22:01:53 +0100 YVONNE-PC Yvonne MESSAGE Starting protection
2012/03/21 22:02:08 +0100 YVONNE-PC Yvonne MESSAGE Protection started successfully
2012/03/21 22:02:11 +0100 YVONNE-PC Yvonne MESSAGE Starting IP protection
2012/03/21 22:02:18 +0100 YVONNE-PC Yvonne MESSAGE IP Protection started successfully
2012/03/21 23:15:49 +0100 YVONNE-PC Yvonne MESSAGE Starting protection
2012/03/21 23:15:56 +0100 YVONNE-PC Yvonne MESSAGE Protection started successfully
2012/03/21 23:15:59 +0100 YVONNE-PC Yvonne MESSAGE Starting IP protection
2012/03/21 23:16:05 +0100 YVONNE-PC Yvonne MESSAGE IP Protection started successfully
Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1)
Log created at 07:39 on 22/03/2012 (Yvonne)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU:DAEMON Tools Lite -> Removed
Checking for services/drivers...
-=E.O.F=-
.DDS Logfile: Code:
ATTFilter DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by Yvonne at 7:50:23 on 2012-03-22
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3293.1847 [GMT 1:00]
.
AV: McAfee VirusScan *Disabled/Outdated* {86355677-4064-3EA7-ABB3-1B136EB04637}
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan *Disabled/Outdated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Personal Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Windows\system32\taskeng.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Windows Sidebar\sidebar.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.de/
uDefault_Page_URL = hxxp://www.google.de
mDefault_Page_URL = hxxp://www.google.de
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: PC Tools Browser Defender: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools\pc tools security\bdt\PCTBrowserDefender.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: PC Tools Browser Defender BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\pc tools\pc tools security\bdt\PCTBrowserDefender.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: Windows Live Anmelde-Hilfsprogramm: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: PC Tools Browser Defender: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools\pc tools security\bdt\PCTBrowserDefender.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\TOSCDSPD.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Facebook Update] "c:\users\yvonne\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [Google Update] "c:\users\yvonne\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [ICQ] "c:\program files\icq7.5\ICQ.exe" silent loginmode=4
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [NDSTray.exe] NDSTray.exe
mRun: [cfFncEnabler.exe] cfFncEnabler.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Toshiba TEMPO] c:\program files\toshiba tempro\Toshiba.Tempo.UI.TrayApplication.exe
mRun: [topi] c:\program files\toshiba\toshiba online product information\topi.exe -startup
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [Camera Assistant Software] "c:\program files\camera assistant software for toshiba\traybar.exe" /start
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [HDMICtrlMan] c:\program files\toshiba\hdmictrlman\HDMICtrlMan.exe
mRun: [Toshiba Registration] c:\program files\toshiba\registration\ToshibaRegistration.exe
mRun: [Toshiba TEMPRO] c:\program files\toshiba tempro\TemproTray.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\users\yvonne\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\yvonne\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\yvonne\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\yvonne\appdata\roaming\micros~1\windows\startm~1\programs\startup\trdcre~1.lnk - c:\program files\toshiba\trdcreminder\TRDCReminder.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Free YouTube to MP3 Converter - c:\users\yvonne\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\icq7.5\ICQ.exe
IE: {76577871-04EC-495E-A12B-91F7C3600AFA} - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4
IE: {8A918C1D-E123-4E36-B562-5C1519E434CE} - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: c:\program files\avira\antivir desktop\avsda.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{06C5BC81-E8B8-4B0A-82B9-A0ABC0B6C63B} : DhcpNameServer = 192.168.2.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\yvonne\appdata\roaming\mozilla\firefox\profiles\7jrxiww7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.71\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\users\yvonne\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\users\yvonne\appdata\local\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\users\yvonne\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\yvonne\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2012-3-20 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2012-3-20 342168]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2012-3-20 909728]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-11-15 36000]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-6-3 214664]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2012-3-20 185560]
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\drivers\RtlProt.sys [2008-9-7 25896]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 AntiVirSchedulerService;Avira Planer;c:\program files\avira\antivir desktop\sched.exe [2011-11-15 86224]
R2 AntiVirService;Avira Echtzeit Scanner;c:\program files\avira\antivir desktop\avguard.exe [2011-11-15 110032]
R2 AntiVirWebService;Avira Browser Schutz;c:\program files\avira\antivir desktop\avwebgrd.exe [2011-11-15 463824]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-12-12 74640]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\pc tools\pc tools security\bdt\BDTUpdateService.exe [2012-3-20 550864]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2008-4-16 40960]
R2 FontCache;Windows-Dienst für Schriftartencache;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-3-21 652360]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-6-3 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-6-3 144704]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-3-21 20464]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-6-3 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-6-3 35272]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2008-4-15 51160]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [2012-3-20 56840]
R3 QIOMem;Generic IO & Memory Access;c:\windows\system32\drivers\QIOMem.sys [2007-4-9 8192]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54 MBit/s USB 2.0 Netzwerkadapter;c:\windows\system32\drivers\rtl8187B.sys [2008-9-7 292864]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-2-2 27632]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\toshiba\smartfacev\SmartFaceVWatchSrv.exe [2008-4-24 73728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-13 136176]
S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\toshiba tempro\TemproSvc.exe [2010-10-26 124368]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\magix\common\database\bin\fbserver.exe [2008-6-3 1527900]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-6-3 30192]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-5-13 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-6-3 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-6-3 40552]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools\pc tools security\pctsAuxs.exe [2012-3-21 402336]
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools\pc tools security\pctsSvc.exe [2012-3-21 1117624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-6-3 606736]
.
=============== Created Last 30 ================
.
2012-03-21 17:12:02 -------- d-----w- c:\users\yvonne\appdata\roaming\Malwarebytes
2012-03-21 17:11:50 -------- d-----w- c:\programdata\Malwarebytes
2012-03-21 17:11:48 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-21 17:11:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-20 23:23:19 -------- d--h--w- C:\TDSSKiller_Quarantine
2012-03-20 22:42:12 56840 ----a-w- c:\windows\system32\drivers\PCTBD.sys
2012-03-20 22:42:10 767952 ----a-w- c:\windows\BDTSupport.dll0309.old
2012-03-20 22:42:10 767952 ----a-w- c:\windows\BDTSupport.dll
2012-03-20 22:42:06 149456 ----a-w- c:\windows\SGDetectionTool.dll0309.old
2012-03-20 22:42:06 149456 ----a-w- c:\windows\SGDetectionTool.dll
2012-03-20 22:42:05 2250704 ----a-w- c:\windows\PCTBDCore.dll0309.old
2012-03-20 22:42:05 2250704 ----a-w- c:\windows\PCTBDCore.dll
2012-03-20 22:42:04 1681360 ----a-w- c:\windows\PCTBDRes.dll
2012-03-20 22:39:19 253352 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2012-03-20 22:39:19 107864 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2012-03-20 22:38:56 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys
2012-03-20 22:38:25 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2012-03-20 22:37:27 -------- d-----w- c:\program files\PC Tools
2012-03-20 22:34:18 909728 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2012-03-20 22:34:17 342168 ----a-w- c:\windows\system32\drivers\pctDS.sys
2012-03-20 22:34:02 331880 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2012-03-20 22:34:01 162584 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2012-03-20 22:33:54 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2012-03-20 22:33:51 -------- d-----w- c:\program files\common files\PC Tools
2012-03-20 22:32:31 -------- d--h--w- c:\programdata\PC Tools
2012-03-20 22:32:23 -------- d--h--w- c:\users\yvonne\appdata\roaming\TestApp
2012-03-18 03:39:19 592824 ----a-w- c:\program files\mozilla firefox\gkmedias.dll
2012-03-18 03:39:19 44472 ----a-w- c:\program files\mozilla firefox\mozglue.dll
2012-03-14 10:43:05 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 10:43:04 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-14 10:43:04 1068544 ----a-w- c:\windows\system32\DWrite.dll
2012-03-14 10:43:03 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-03-14 10:43:03 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-14 10:43:03 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-14 10:42:58 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2012-03-14 10:42:26 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-03-14 10:42:25 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-08 16:04:40 -------- d--h--w- c:\users\yvonne\appdata\local\AskToolbar
.
==================== Find3M ====================
.
2012-03-14 13:04:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 7:51:44,73 ===============
Geändert von Yvonette (22.03.2012 um 00:18 Uhr) |
| Themen zu files indexation process failed |
| acrobat update, avira searchfree toolbar, befolgt, besserung, bli, blink, desktop, desktop leer, device driver, drive, failed, fehlermeldungen, files, folge, folgende, google earth, laufen, leer, lockedfile.multi.generic, malwarebytes, meldungen, menge, nicht mehr, picasa, plug-in, problem, process, rootkit, schwarz, security scan, seite, startmenü, systemwiederherstellung, usb 2.0, virus |