Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 05.11.2012, 22:20   #16
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



soll ich die firewall während dessen auch deaktivieren?

Alt 05.11.2012, 22:26   #17
markusg
/// Malware-holic
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



jepp, wenn möglich alle programme, die im hintergrund aktiev sind.
sollte combofix dann trotzdem anzeigen, dass antimalware software aktiv is, einfach weiter mit ok
__________________

__________________

Alt 05.11.2012, 22:36   #18
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



Bin mal gespannt. Kann ich das Programm eigentlich immer wieder verwenden? Combofix?
__________________

Alt 05.11.2012, 22:44   #19
markusg
/// Malware-holic
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



nein. steht ja auch in der anleitung
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 05.11.2012, 22:50   #20
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



Wer lesen kann, ist klar im Vorteil. ..lach. Stufe 32. Wie viele stufen sind es? Eine Frage noch, meinst du eset ist eine gute software? Wieso konnte eset nicht das problem lösen?


Alt 05.11.2012, 22:53   #21
markusg
/// Malware-holic
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



weil du zb eset 4 nutzt aktuell aber eset 5 ist.
malware software sollte sowieso immer die letzte möglichkeit sein, das dazugehörige system muss schon von sich aus gut konfiguriert sein, dazu später
__________________
--> Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme

Alt 05.11.2012, 22:57   #22
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



Combofix Logfile:
Code:
ATTFilter
ComboFix 12-11-05.03 - Krause 05.11.2012  22:24:14.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3956.2087 [GMT 1:00]
ausgeführt von:: c:\users\Krause\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal Firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\10.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\11.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\2.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\3.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\4.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\5.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\596e0bd6255c81826771d599c49a9aeb.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\6.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\7.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\8.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\aoe-narnia_intro.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e07.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e08.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e10.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e11.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\FILE4CD3AF47E2FC5.plong.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\FILE8842594C04C27.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\kinowelt-sexcity2-xvid700.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Post_Install_RB_HiQ_de.divx.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\596e0bd6255c81826771d599c49a9aeb.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\aoe-narnia_intro.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e07.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e08.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e10.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e11.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\FILE4CD3AF47E2FC5.plong.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\FILE8842594C04C27.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\kinowelt-sexcity2-xvid.avi(2).ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\kinowelt-sexcity2-xvid.avi.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\kinowelt-sexcity2-xvid700.avi.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Post_Install_RB_HiQ_de.divx
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\muzapp.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-10-05 bis 2012-11-05  ))))))))))))))))))))))))))))))
.
.
2012-11-05 21:52 . 2012-11-05 21:52	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-11-04 13:45 . 2012-11-05 19:38	69000	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{8F63BD03-D84B-4381-ACDA-EC883BB2EDE1}\offreg.dll
2012-11-03 17:24 . 2012-10-12 07:19	9291768	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{8F63BD03-D84B-4381-ACDA-EC883BB2EDE1}\mpengine.dll
2012-10-30 20:44 . 2012-10-30 20:44	--------	d-----w-	C:\Temp
2012-10-30 20:41 . 2012-09-20 04:35	203104	----a-w-	c:\windows\system32\drivers\ssudmdm.sys
2012-10-30 20:39 . 2012-09-20 04:35	102368	----a-w-	c:\windows\system32\drivers\ssudbus.sys
2012-10-30 20:26 . 2012-10-30 20:26	--------	d-----w-	c:\users\Krause\AppData\Local\Samsung
2012-10-30 20:26 . 2012-10-30 20:26	--------	d-----w-	c:\users\Krause\AppData\Roaming\Samsung
2012-10-30 20:20 . 2012-09-26 19:57	4659712	----a-w-	c:\windows\SysWow64\Redemption.dll
2012-10-30 20:20 . 2012-10-30 20:20	--------	d-----w-	c:\program files (x86)\MarkAny
2012-10-30 20:20 . 2012-09-26 19:57	821824	----a-w-	c:\windows\SysWow64\dgderapi.dll
2012-10-30 20:18 . 2012-10-30 20:21	--------	d-----w-	c:\program files (x86)\Samsung
2012-10-30 20:18 . 2012-10-30 20:20	--------	d-----w-	c:\programdata\Samsung
2012-10-30 20:03 . 2012-10-30 20:03	--------	d-----w-	c:\users\Krause\AppData\Local\InstallShare
2012-10-30 20:00 . 2012-10-30 20:00	--------	d-----w-	c:\programdata\Browser Manager
2012-10-30 20:00 . 2012-10-30 20:00	--------	d-----w-	c:\program files (x86)\BabylonToolbar
2012-10-30 19:59 . 2012-10-30 19:59	119808	----a-w-	c:\windows\system32\GFilterSvc.exe
2012-10-30 19:59 . 2012-10-30 19:59	111616	----a-w-	c:\windows\system32\actjveds.exe
2012-10-30 19:59 . 2012-10-30 19:59	--------	d-----w-	c:\users\Krause\AppData\Roaming\Babylon
2012-10-30 19:59 . 2012-10-30 19:59	--------	d-----w-	c:\programdata\Babylon
2012-10-22 17:34 . 2012-10-22 17:34	--------	d-----w-	c:\program files (x86)\Werksfeuerwehr-Simulator
2012-10-14 15:25 . 2012-10-14 15:27	696760	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-11 19:01 . 2012-08-31 18:19	1659760	----a-w-	c:\windows\system32\drivers\ntfs.sys
2012-10-11 19:01 . 2012-08-30 18:03	5559664	----a-w-	c:\windows\system32\ntoskrnl.exe
2012-10-11 19:01 . 2012-08-30 17:12	3914096	----a-w-	c:\windows\SysWow64\ntoskrnl.exe
2012-10-11 19:01 . 2012-08-30 17:12	3968880	----a-w-	c:\windows\SysWow64\ntkrnlpa.exe
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-14 15:27 . 2012-09-16 17:19	73656	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-12 09:32 . 2010-11-26 20:24	65309168	----a-w-	c:\windows\system32\MRT.exe
2012-09-26 19:57 . 2012-09-26 19:57	90112	----a-w-	c:\windows\MAMCityDownload.ocx
2012-09-26 19:57 . 2012-09-26 19:57	330240	----a-w-	c:\windows\MASetupCaller.dll
2012-09-26 19:57 . 2012-09-26 19:57	30568	----a-w-	c:\windows\MusiccityDownload.exe
2012-09-26 19:57 . 2012-09-26 19:57	974848	----a-w-	c:\windows\SysWow64\cis-2.4.dll
2012-09-26 19:57 . 2012-09-26 19:57	81920	----a-w-	c:\windows\SysWow64\issacapi_bs-2.3.dll
2012-09-26 19:57 . 2012-09-26 19:57	65536	----a-w-	c:\windows\SysWow64\issacapi_pe-2.3.dll
2012-09-26 19:57 . 2012-09-26 19:57	57344	----a-w-	c:\windows\SysWow64\MTXSYNCICON.dll
2012-09-26 19:57 . 2012-09-26 19:57	57344	----a-w-	c:\windows\SysWow64\MK_Lyric.dll
2012-09-26 19:57 . 2012-09-26 19:57	57344	----a-w-	c:\windows\SysWow64\issacapi_se-2.3.dll
2012-09-26 19:57 . 2012-09-26 19:57	569344	----a-w-	c:\windows\SysWow64\muzdecode.ax
2012-09-26 19:57 . 2012-09-26 19:57	491520	----a-w-	c:\windows\SysWow64\muzapp.dll
2012-09-26 19:57 . 2012-09-26 19:57	49152	----a-w-	c:\windows\SysWow64\MaJGUILib.dll
2012-09-26 19:57 . 2012-09-26 19:57	45320	----a-w-	c:\windows\SysWow64\MAMACExtract.dll
2012-09-26 19:57 . 2012-09-26 19:57	45056	----a-w-	c:\windows\SysWow64\MaXMLProto.dll
2012-09-26 19:57 . 2012-09-26 19:57	45056	----a-w-	c:\windows\SysWow64\MACXMLProto.dll
2012-09-26 19:57 . 2012-09-26 19:57	40960	----a-w-	c:\windows\SysWow64\MTTELECHIP.dll
2012-09-26 19:57 . 2012-09-26 19:57	352256	----a-w-	c:\windows\SysWow64\MSLUR71.dll
2012-09-26 19:57 . 2012-09-26 19:57	258048	----a-w-	c:\windows\SysWow64\muzoggsp.ax
2012-09-26 19:57 . 2012-09-26 19:57	245760	----a-w-	c:\windows\SysWow64\MSCLib.dll
2012-09-26 19:57 . 2012-09-26 19:57	24576	----a-w-	c:\windows\SysWow64\MASetupCleaner.exe
2012-09-26 19:57 . 2012-09-26 19:57	200704	----a-w-	c:\windows\SysWow64\muzwmts.dll
2012-09-26 19:57 . 2012-09-26 19:57	155648	----a-w-	c:\windows\SysWow64\MSFLib.dll
2012-09-26 19:57 . 2012-09-26 19:57	143360	----a-w-	c:\windows\SysWow64\3DAudio.ax
2012-09-26 19:57 . 2012-09-26 19:57	135168	----a-w-	c:\windows\SysWow64\muzaf1.dll
2012-09-26 19:57 . 2012-09-26 19:57	131072	----a-w-	c:\windows\SysWow64\muzmpgsp.ax
2012-09-26 19:57 . 2012-09-26 19:57	122880	----a-w-	c:\windows\SysWow64\muzeffect.ax
2012-09-26 19:57 . 2012-09-26 19:57	118784	----a-w-	c:\windows\SysWow64\MaDRM.dll
2012-09-26 19:57 . 2012-09-26 19:57	110592	----a-w-	c:\windows\SysWow64\muzmp4sp.ax
2012-09-16 15:40 . 2012-09-16 15:40	9232584	----a-w-	c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-08-24 11:15 . 2012-09-25 15:01	17810944	----a-w-	c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-25 15:01	10925568	----a-w-	c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-25 15:01	2312704	----a-w-	c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-25 15:01	1346048	----a-w-	c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-25 15:01	1392128	----a-w-	c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-25 15:01	1494528	----a-w-	c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-25 15:01	237056	----a-w-	c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-25 15:01	85504	----a-w-	c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-25 15:01	173056	----a-w-	c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-25 15:01	816640	----a-w-	c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-25 15:01	599040	----a-w-	c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-25 15:01	2144768	----a-w-	c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-25 15:01	729088	----a-w-	c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-25 15:01	96768	----a-w-	c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-25 15:01	2382848	----a-w-	c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-25 15:01	248320	----a-w-	c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-25 15:01	1800704	----a-w-	c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-25 15:01	1129472	----a-w-	c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-25 15:01	1427968	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-25 15:01	142848	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-25 15:01	420864	----a-w-	c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-25 15:01	2382848	----a-w-	c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 13:57	1913200	----a-w-	c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 13:57	950128	----a-w-	c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 13:57	376688	----a-w-	c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 13:57	288624	----a-w-	c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-27 19:49	245760	----a-w-	c:\windows\system32\OxpsConverter.exe
2012-08-20 17:38 . 2012-10-11 19:00	44032	----a-w-	c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 02:40	120176	----a-w-	c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Spotify Web Helper"="c:\users\Krause\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-26 932528]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-10-11 966072]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-10-09 580096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-06-28 265984]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-25 98304]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-11 975952]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"DivX Download Manager"="c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-12-09 74752]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-07 585728]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-10-11 309688]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~3\BROWSE~1\23796~1.11\{16CDF~1\browsemngr.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"LexwareInfoService"=c:\program files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R2 SndVol64;Application Microsoft-Tunnelminiport-Adaptertreiber Shellhardwareerkennung;c:\windows\system32\actjveds.exe [2012-10-30 111616]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2010-06-10 40448]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-20 102368]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2011-02-22 13352]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-01 33736]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2010-04-17 50432]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-20 203104]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-02-18 51712]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-17 1255736]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-26 203264]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-11 321104]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-09-03 170104]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2010-11-04 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 50624]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 868896]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 GFilterSvc;G-Filter Service;c:\windows\System32\GFilterSvc.exe [2012-10-30 119808]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-03-25 204304]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-06-28 255744]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2010-04-17 144640]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-03-23 87040]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-08-16 116240]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2010-06-08 406056]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2011-02-22 34032]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-11-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2012-09-10 19:59]
.
2012-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-06 17:49]
.
2012-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-06 17:49]
.
2012-09-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1227247490-993995614-759896167-1000.job
- c:\program files (x86)\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 02:42	137584	----a-w-	c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-06-10 324608]
"mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-29 11101800]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-10-10 206208]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-10-22 325120]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 861216]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-11-04 2919168]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.babylon.com/?affID=109958&tt=4412_5&babsrc=HP_ss&mntrId=c6d7688e0000000000002a7c8f270689
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://acer.msn.com
mStart Page = hxxp://acer.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{398E2C31-F499-437E-B290-953A2DB48003}: NameServer = 62.109.123.7 213.191.92.86
FF - ProfilePath - c:\users\Krause\AppData\Roaming\Mozilla\Firefox\Profiles\dj5w8jkh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2903600&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Productivity 2.1 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=c6d7688e0000000000002a7c8f270689&q=
FF - user.js: extensions.BabylonToolbar.id - c6d7688e0000000000002a7c8f270689
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15643
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.3.8
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.3.8
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.3.821:00
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109958&tt=4412_5
FF - user.js: extensions.BabylonToolbar_i.babExt - 
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-11-05  22:54:50
ComboFix-quarantined-files.txt  2012-11-05 21:54
.
Vor Suchlauf: 10 Verzeichnis(se), 16.234.598.400 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 15.779.516.416 Bytes frei
.
- - End Of File - - 1F79326DDCE577603F2D03F62B22EA29
         
--- --- ---


fertig...nun herunter fahren?

Keine Fehlermeldung erhalten. Und wie gehts weiter? Man, Respekt, ihr habt echt was drauf.

So, muss mich für heute verabschieden. Werde morgen wieder hier rein schauen um zu sehen wie wir weiter machen. Bis hierher schon mal schönen Dank.

Moin moin. Wo waren wir gestern stehen geblieben??

Alt 07.11.2012, 00:32   #23
markusg
/// Malware-holic
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



download tdss killer:
http://www.trojaner-board.de/82358-t...entfernen.html
Klicke auf Change parameters
• Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system
• Klick auf OK und anschließend auf Start scan
- bei funden erst mal immer skip wählen, log posten
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.11.2012, 17:58   #24
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



da sind einige Funde, aber ich bekomme die logs nicht kopiert um sie weiterzuleiten oder so.

Alt 07.11.2012, 19:12   #25
markusg
/// Malware-holic
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



computer öffnen, c:
tdss-killer-datum-version.txt öffnen, log kopieren und posten
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.11.2012, 23:44   #26
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



18:08:35.0863 3788 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
18:08:36.0129 3788 ============================================================
18:08:36.0129 3788 Current date / time: 2012/11/07 18:08:36.0129
18:08:36.0129 3788 SystemInfo:
18:08:36.0129 3788
18:08:36.0129 3788 OS Version: 6.1.7601 ServicePack: 1.0
18:08:36.0129 3788 Product type: Workstation
18:08:36.0129 3788 ComputerName: KRAUSE-PC
18:08:36.0129 3788 UserName: Krause
18:08:36.0129 3788 Windows directory: C:\Windows
18:08:36.0129 3788 System windows directory: C:\Windows
18:08:36.0129 3788 Running under WOW64
18:08:36.0129 3788 Processor architecture: Intel x64
18:08:36.0129 3788 Number of processors: 4
18:08:36.0129 3788 Page size: 0x1000
18:08:36.0129 3788 Boot type: Normal boot
18:08:36.0129 3788 ============================================================
18:08:36.0487 3788 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:08:36.0487 3788 ============================================================
18:08:36.0487 3788 \Device\Harddisk0\DR0:
18:08:36.0487 3788 MBR partitions:
18:08:36.0487 3788 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1A5E800, BlocksNum 0x32000
18:08:36.0487 3788 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1A90800, BlocksNum 0xC350030
18:08:36.0503 3788 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xDDE1800, BlocksNum 0x2C5A4000
18:08:36.0503 3788 ============================================================
18:08:36.0550 3788 C: <-> \Device\Harddisk0\DR0\Partition2
18:08:36.0581 3788 E: <-> \Device\Harddisk0\DR0\Partition3
18:08:36.0581 3788 ============================================================
18:08:36.0581 3788 Initialize success
18:08:36.0581 3788 ============================================================
18:09:03.0226 4732 ============================================================
18:09:03.0226 4732 Scan started
18:09:03.0226 4732 Mode: Manual; SigCheck; TDLFS;
18:09:03.0226 4732 ============================================================
18:09:03.0460 4732 ================ Scan system memory ========================
18:09:03.0460 4732 System memory - ok
18:09:03.0460 4732 ================ Scan services =============================
18:09:03.0616 4732 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:09:03.0709 4732 1394ohci - ok
18:09:03.0756 4732 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:09:03.0787 4732 ACPI - ok
18:09:03.0834 4732 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:09:03.0850 4732 AcpiPmi - ok
18:09:03.0912 4732 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:09:03.0959 4732 adp94xx - ok
18:09:03.0975 4732 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:09:04.0006 4732 adpahci - ok
18:09:04.0037 4732 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:09:04.0068 4732 adpu320 - ok
18:09:04.0115 4732 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:09:04.0193 4732 AeLookupSvc - ok
18:09:04.0255 4732 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
18:09:04.0287 4732 AFD - ok
18:09:04.0318 4732 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
18:09:04.0333 4732 agp440 - ok
18:09:04.0396 4732 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
18:09:04.0411 4732 ALG - ok
18:09:04.0458 4732 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
18:09:04.0474 4732 aliide - ok
18:09:04.0521 4732 [ FF779F9DE1CDF477033858B7681CEDA8 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
18:09:04.0536 4732 AMD External Events Utility - ok
18:09:04.0567 4732 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
18:09:04.0583 4732 amdide - ok
18:09:04.0614 4732 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
18:09:04.0630 4732 AmdK8 - ok
18:09:04.0817 4732 [ EF2B99DCEE397B45F50594696D7B5339 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:09:04.0911 4732 amdkmdag - ok
18:09:04.0926 4732 [ 239DCE60BEE6E1576C803948AB4D54C5 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
18:09:04.0942 4732 amdkmdap - ok
18:09:04.0973 4732 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
18:09:04.0989 4732 AmdPPM - ok
18:09:05.0020 4732 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
18:09:05.0035 4732 amdsata - ok
18:09:05.0067 4732 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
18:09:05.0129 4732 amdsbs - ok
18:09:05.0145 4732 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
18:09:05.0176 4732 amdxata - ok
18:09:05.0238 4732 [ 391887990CDAA83DE5C56C3FDE966DA1 ] AmUStor C:\Windows\system32\drivers\AmUStor.SYS
18:09:05.0254 4732 AmUStor - ok
18:09:05.0285 4732 [ FAB590E0FC28CB474B965F8267458E14 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
18:09:05.0363 4732 ApfiltrService - ok
18:09:05.0394 4732 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
18:09:05.0457 4732 AppID - ok
18:09:05.0488 4732 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
18:09:05.0581 4732 AppIDSvc - ok
18:09:05.0613 4732 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
18:09:05.0691 4732 Appinfo - ok
18:09:05.0784 4732 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:09:05.0800 4732 Apple Mobile Device - ok
18:09:05.0862 4732 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
18:09:05.0893 4732 arc - ok
18:09:05.0909 4732 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
18:09:05.0925 4732 arcsas - ok
18:09:05.0971 4732 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:09:06.0018 4732 AsyncMac - ok
18:09:06.0049 4732 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
18:09:06.0065 4732 atapi - ok
18:09:06.0159 4732 [ E642491F64E58CD5BC8FB8B347DCF65F ] athr C:\Windows\system32\DRIVERS\athrx.sys
18:09:06.0252 4732 athr - ok
18:09:06.0315 4732 [ FDA1E117A7E880BFF5540D180C06EA87 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
18:09:06.0330 4732 AtiHDAudioService - ok
18:09:06.0393 4732 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:09:06.0502 4732 AudioEndpointBuilder - ok
18:09:06.0517 4732 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
18:09:06.0595 4732 AudioSrv - ok
18:09:06.0642 4732 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
18:09:06.0673 4732 AxInstSV - ok
18:09:06.0736 4732 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
18:09:06.0767 4732 b06bdrv - ok
18:09:06.0814 4732 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
18:09:06.0845 4732 b57nd60a - ok
18:09:06.0970 4732 [ A2494901E7226B356B8C1005C45F1C5F ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe
18:09:06.0985 4732 BBSvc - ok
18:09:07.0048 4732 [ 63B1CBBAE4790B5BAC98F01BF9449722 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe
18:09:07.0079 4732 BBUpdate - ok
18:09:07.0141 4732 [ 9E84A931DBEE0292E38ED672F6293A99 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
18:09:07.0188 4732 BCM43XX - ok
18:09:07.0219 4732 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
18:09:07.0235 4732 BDESVC - ok
18:09:07.0282 4732 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
18:09:07.0329 4732 Beep - ok
18:09:07.0375 4732 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
18:09:07.0453 4732 BFE - ok
18:09:07.0485 4732 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
18:09:07.0531 4732 BITS - ok
18:09:07.0547 4732 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
18:09:07.0609 4732 blbdrive - ok
18:09:07.0656 4732 [ F2060A34C8A75BC24A9222EB4F8C07BD ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
18:09:07.0687 4732 Bonjour Service - ok
18:09:07.0719 4732 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:09:07.0734 4732 bowser - ok
18:09:07.0765 4732 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:09:07.0797 4732 BrFiltLo - ok
18:09:07.0828 4732 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:09:07.0843 4732 BrFiltUp - ok
18:09:07.0875 4732 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
18:09:07.0953 4732 BridgeMP - ok
18:09:07.0984 4732 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
18:09:08.0015 4732 Browser - ok
18:09:08.0046 4732 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
18:09:08.0077 4732 Brserid - ok
18:09:08.0093 4732 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
18:09:08.0140 4732 BrSerWdm - ok
18:09:08.0155 4732 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
18:09:08.0171 4732 BrUsbMdm - ok
18:09:08.0187 4732 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
18:09:08.0202 4732 BrUsbSer - ok
18:09:08.0218 4732 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
18:09:08.0265 4732 BTHMODEM - ok
18:09:08.0343 4732 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
18:09:08.0421 4732 bthserv - ok
18:09:08.0467 4732 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:09:08.0530 4732 cdfs - ok
18:09:08.0561 4732 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys
18:09:08.0592 4732 cdrom - ok
18:09:08.0623 4732 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
18:09:08.0701 4732 CertPropSvc - ok
18:09:08.0733 4732 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:09:08.0764 4732 circlass - ok
18:09:08.0811 4732 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
18:09:08.0842 4732 CLFS - ok
18:09:08.0904 4732 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:09:08.0920 4732 clr_optimization_v2.0.50727_32 - ok
18:09:08.0982 4732 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:09:09.0013 4732 clr_optimization_v2.0.50727_64 - ok
18:09:09.0123 4732 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:09:09.0154 4732 clr_optimization_v4.0.30319_32 - ok
18:09:09.0185 4732 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:09:09.0201 4732 clr_optimization_v4.0.30319_64 - ok
18:09:09.0232 4732 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:09:09.0247 4732 CmBatt - ok
18:09:09.0279 4732 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:09:09.0294 4732 cmdide - ok
18:09:09.0341 4732 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
18:09:09.0388 4732 CNG - ok
18:09:09.0419 4732 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:09:09.0450 4732 Compbatt - ok
18:09:09.0481 4732 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:09:09.0513 4732 CompositeBus - ok
18:09:09.0544 4732 COMSysApp - ok
18:09:09.0559 4732 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:09:09.0575 4732 crcdisk - ok
18:09:09.0622 4732 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:09:09.0653 4732 CryptSvc - ok
18:09:09.0762 4732 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
18:09:09.0793 4732 cvhsvc - ok
18:09:09.0856 4732 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
18:09:09.0934 4732 DcomLaunch - ok
18:09:09.0981 4732 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
18:09:10.0027 4732 defragsvc - ok
18:09:10.0059 4732 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:09:10.0090 4732 DfsC - ok
18:09:10.0121 4732 dgderdrv - ok
18:09:10.0168 4732 [ B9430166FEB246F6070A62B3554932C9 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
18:09:10.0183 4732 dg_ssudbus - ok
18:09:10.0230 4732 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
18:09:10.0308 4732 Dhcp - ok
18:09:10.0339 4732 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
18:09:10.0371 4732 discache - ok
18:09:10.0402 4732 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:09:10.0464 4732 Disk - ok
18:09:10.0480 4732 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:09:10.0495 4732 Dnscache - ok
18:09:10.0542 4732 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
18:09:10.0620 4732 dot3svc - ok
18:09:10.0667 4732 [ B42ED0320C6E41102FDE0005154849BB ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys
18:09:10.0698 4732 Dot4 - ok
18:09:10.0729 4732 [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print C:\Windows\system32\drivers\Dot4Prt.sys
18:09:10.0776 4732 Dot4Print - ok
18:09:10.0792 4732 [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
18:09:10.0823 4732 dot4usb - ok
18:09:10.0854 4732 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
18:09:10.0917 4732 DPS - ok
18:09:10.0948 4732 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:09:11.0010 4732 drmkaud - ok
18:09:11.0057 4732 [ 9CF46FDF163E06B83D03FF929EF2296C ] DsiWMIService C:\Program Files (x86)\Launch Manager\dsiwmis.exe
18:09:11.0088 4732 DsiWMIService - ok
18:09:11.0151 4732 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:09:11.0197 4732 DXGKrnl - ok
18:09:11.0260 4732 [ 72A1AA3C6C79B928D02A6FAD387B1349 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
18:09:11.0291 4732 eamonm - ok
18:09:11.0322 4732 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
18:09:11.0400 4732 EapHost - ok
18:09:11.0494 4732 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
18:09:11.0587 4732 ebdrv - ok
18:09:11.0603 4732 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
18:09:11.0634 4732 EFS - ok
18:09:11.0681 4732 [ E99457900012B53B2226F146ECAF9136 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
18:09:11.0697 4732 ehdrv - ok
18:09:11.0775 4732 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:09:11.0821 4732 ehRecvr - ok
18:09:11.0853 4732 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
18:09:11.0868 4732 ehSched - ok
18:09:11.0962 4732 [ 0A38BD2C9589910C634B10E644D5759C ] EhttpSrv C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
18:09:11.0993 4732 EhttpSrv - ok
18:09:12.0040 4732 [ E6A6E6D58A8DCB64A0FFBC43863D0A80 ] ekrn C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
18:09:12.0087 4732 ekrn - ok
18:09:12.0133 4732 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:09:12.0165 4732 elxstor - ok
18:09:12.0227 4732 [ F9D0D6A7A6D48391BE1F314EF7669CE2 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
18:09:12.0243 4732 epfw - ok
18:09:12.0258 4732 [ 96620AD728144D8E30A7BAEC9DDC811C ] Epfwndis C:\Windows\system32\DRIVERS\Epfwndis.sys
18:09:12.0274 4732 Epfwndis - ok
18:09:12.0321 4732 [ 16576F3A76F4D0DD83522D69B5EAFAA1 ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
18:09:12.0336 4732 epfwwfp - ok
18:09:12.0414 4732 [ 3EA2C4F68A782839D97B3C83595575B6 ] ePowerSvc C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
18:09:12.0461 4732 ePowerSvc - ok
18:09:12.0492 4732 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:09:12.0508 4732 ErrDev - ok
18:09:12.0555 4732 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
18:09:12.0617 4732 EventSystem - ok
18:09:12.0648 4732 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
18:09:12.0679 4732 exfat - ok
18:09:12.0757 4732 Fabs - ok
18:09:12.0773 4732 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:09:12.0882 4732 fastfat - ok
18:09:12.0945 4732 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
18:09:12.0976 4732 Fax - ok
18:09:13.0023 4732 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:09:13.0054 4732 fdc - ok
18:09:13.0085 4732 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
18:09:13.0147 4732 fdPHost - ok
18:09:13.0163 4732 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
18:09:13.0225 4732 FDResPub - ok
18:09:13.0257 4732 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:09:13.0288 4732 FileInfo - ok
18:09:13.0319 4732 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:09:13.0366 4732 Filetrace - ok
18:09:13.0475 4732 [ FFF1130F7C9FA01D093A1EDFC5CCE8FC ] FirebirdServerMAGIXInstance C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
18:09:13.0569 4732 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - warning
18:09:13.0569 4732 FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic (1)
18:09:13.0600 4732 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:09:13.0615 4732 flpydisk - ok
18:09:13.0647 4732 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:09:13.0678 4732 FltMgr - ok
18:09:13.0740 4732 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
18:09:13.0787 4732 FontCache - ok
18:09:13.0818 4732 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:09:13.0834 4732 FontCache3.0.0.0 - ok
18:09:13.0865 4732 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:09:13.0881 4732 FsDepends - ok
18:09:13.0927 4732 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:09:13.0943 4732 Fs_Rec - ok
18:09:14.0005 4732 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:09:14.0052 4732 fvevol - ok
18:09:14.0083 4732 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:09:14.0193 4732 gagp30kx - ok
18:09:14.0224 4732 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
18:09:14.0239 4732 GEARAspiWDM - ok
18:09:14.0286 4732 [ 1017F2D3A4B90258CA730877D28B9FB1 ] GFilterSvc C:\Windows\System32\GFilterSvc.exe
18:09:14.0302 4732 GFilterSvc ( UnsignedFile.Multi.Generic ) - warning
18:09:14.0302 4732 GFilterSvc - detected UnsignedFile.Multi.Generic (1)
18:09:14.0349 4732 [ A4198F2BD8AA592CB90476277A81B5E1 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys
18:09:14.0364 4732 ggflt - ok
18:09:14.0380 4732 [ D266350BDAAB9EB6C1AEC370EEAAFF3A ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys
18:09:14.0380 4732 ggsemc - ok
18:09:14.0458 4732 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
18:09:14.0505 4732 gpsvc - ok
18:09:14.0567 4732 [ 0191DEE9B9EB7902AF2CF4F67301095D ] GREGService C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
18:09:14.0567 4732 GREGService - ok
18:09:14.0676 4732 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:09:14.0692 4732 gupdate - ok
18:09:14.0707 4732 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:09:14.0723 4732 gupdatem - ok
18:09:14.0754 4732 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:09:14.0770 4732 hcw85cir - ok
18:09:14.0801 4732 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:09:14.0817 4732 HdAudAddService - ok
18:09:14.0848 4732 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:09:14.0863 4732 HDAudBus - ok
18:09:14.0895 4732 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
18:09:14.0895 4732 HECIx64 - ok
18:09:14.0926 4732 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:09:14.0941 4732 HidBatt - ok
18:09:14.0941 4732 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:09:14.0973 4732 HidBth - ok
18:09:14.0988 4732 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:09:15.0004 4732 HidIr - ok
18:09:15.0035 4732 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
18:09:15.0066 4732 hidserv - ok
18:09:15.0113 4732 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:09:15.0129 4732 HidUsb - ok
18:09:15.0160 4732 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:09:15.0222 4732 hkmsvc - ok
18:09:15.0285 4732 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:09:15.0300 4732 HomeGroupListener - ok
18:09:15.0331 4732 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:09:15.0347 4732 HomeGroupProvider - ok
18:09:15.0456 4732 [ 1DAE5C46D42B02A6D5862E1482EFB390 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
18:09:15.0472 4732 hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning
18:09:15.0472 4732 hpqcxs08 - detected UnsignedFile.Multi.Generic (1)
18:09:15.0487 4732 [ 99E8EEF42FE2F4AF29B08C3355DD7685 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
18:09:15.0487 4732 hpqddsvc ( UnsignedFile.Multi.Generic ) - warning
18:09:15.0487 4732 hpqddsvc - detected UnsignedFile.Multi.Generic (1)
18:09:15.0534 4732 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:09:15.0550 4732 HpSAMD - ok
18:09:15.0597 4732 [ 7F57926169C1B8ABA9274EA7D4B70F18 ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
18:09:15.0628 4732 HPSLPSVC ( UnsignedFile.Multi.Generic ) - warning
18:09:15.0628 4732 HPSLPSVC - detected UnsignedFile.Multi.Generic (1)
18:09:15.0659 4732 [ F47CEC45FB85791D4AB237563AD0FA8F ] HTCAND64 C:\Windows\system32\Drivers\ANDROIDUSB.sys
18:09:15.0690 4732 HTCAND64 - ok
18:09:15.0737 4732 [ B8B1B284362E1D8135112573395D5DA5 ] htcnprot C:\Windows\system32\DRIVERS\htcnprot.sys
18:09:15.0753 4732 htcnprot - ok
18:09:15.0831 4732 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:09:15.0909 4732 HTTP - ok
18:09:15.0940 4732 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:09:15.0955 4732 hwpolicy - ok
18:09:15.0987 4732 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:09:16.0002 4732 i8042prt - ok
18:09:16.0033 4732 [ ABBF174CB394F5C437410A788B7E404A ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
18:09:16.0065 4732 iaStor - ok
18:09:16.0143 4732 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:09:16.0174 4732 iaStorV - ok
18:09:16.0236 4732 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
18:09:16.0252 4732 IDriverT ( UnsignedFile.Multi.Generic ) - warning
18:09:16.0252 4732 IDriverT - detected UnsignedFile.Multi.Generic (1)
18:09:16.0299 4732 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:09:16.0345 4732 idsvc - ok
18:09:16.0517 4732 [ A87261EF1546325B559374F5689CF5BC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
18:09:16.0642 4732 igfx - ok
18:09:16.0673 4732 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:09:16.0673 4732 iirsp - ok
18:09:16.0720 4732 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
18:09:16.0798 4732 IKEEXT - ok
18:09:16.0891 4732 [ E8017F1662D9142F45CEAB694D013C00 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
18:09:16.0954 4732 IntcAzAudAddService - ok
18:09:16.0969 4732 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
18:09:16.0985 4732 intelide - ok
18:09:17.0016 4732 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:09:17.0016 4732 intelppm - ok
18:09:17.0063 4732 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:09:17.0110 4732 IPBusEnum - ok
18:09:17.0157 4732 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:09:17.0188 4732 IpFilterDriver - ok
18:09:17.0250 4732 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:09:17.0313 4732 iphlpsvc - ok
18:09:17.0344 4732 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:09:17.0359 4732 IPMIDRV - ok
18:09:17.0391 4732 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:09:17.0453 4732 IPNAT - ok
18:09:17.0531 4732 [ A9E53E1A9C4274EEBC00D36AE5ED40DE ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
18:09:17.0562 4732 iPod Service - ok
18:09:17.0593 4732 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:09:17.0625 4732 IRENUM - ok
18:09:17.0640 4732 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:09:17.0656 4732 isapnp - ok
18:09:17.0687 4732 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:09:17.0703 4732 iScsiPrt - ok
18:09:17.0749 4732 [ 12E27942DBB7C91880163634B0D8A776 ] k57nd60a C:\Windows\system32\DRIVERS\k57nd60a.sys
18:09:17.0765 4732 k57nd60a - ok
18:09:17.0781 4732 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
18:09:17.0796 4732 kbdclass - ok
18:09:17.0827 4732 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
18:09:17.0843 4732 kbdhid - ok
18:09:17.0859 4732 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
18:09:17.0859 4732 KeyIso - ok
18:09:17.0890 4732 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:09:17.0890 4732 KSecDD - ok
18:09:17.0921 4732 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:09:17.0937 4732 KSecPkg - ok
18:09:17.0952 4732 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
18:09:17.0999 4732 ksthunk - ok
18:09:18.0046 4732 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
18:09:18.0124 4732 KtmRm - ok
18:09:18.0171 4732 [ 2AC603C3188C704CFCE353659AA7AD71 ] L1E C:\Windows\system32\DRIVERS\L1E62x64.sys
18:09:18.0202 4732 L1E - ok
18:09:18.0249 4732 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
18:09:18.0311 4732 LanmanServer - ok
18:09:18.0342 4732 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:09:18.0389 4732 LanmanWorkstation - ok
18:09:18.0436 4732 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:09:18.0498 4732 lltdio - ok
18:09:18.0545 4732 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:09:18.0623 4732 lltdsvc - ok
18:09:18.0654 4732 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
18:09:18.0701 4732 lmhosts - ok
18:09:18.0748 4732 [ 23DE5B62B0445A6F874BE633C95B483E ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
18:09:18.0763 4732 LMS - ok
18:09:18.0810 4732 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:09:18.0826 4732 LSI_FC - ok
18:09:18.0857 4732 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:09:18.0873 4732 LSI_SAS - ok
18:09:18.0888 4732 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:09:18.0888 4732 LSI_SAS2 - ok
18:09:18.0904 4732 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:09:18.0919 4732 LSI_SCSI - ok
18:09:18.0935 4732 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
18:09:18.0982 4732 luafv - ok
18:09:19.0044 4732 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:09:19.0060 4732 Mcx2Svc - ok
18:09:19.0075 4732 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:09:19.0091 4732 megasas - ok
18:09:19.0107 4732 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:09:19.0138 4732 MegaSR - ok
18:09:19.0169 4732 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
18:09:19.0216 4732 MMCSS - ok
18:09:19.0231 4732 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
18:09:19.0263 4732 Modem - ok
18:09:19.0294 4732 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:09:19.0309 4732 monitor - ok
18:09:19.0341 4732 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:09:19.0341 4732 mouclass - ok
18:09:19.0387 4732 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:09:19.0419 4732 mouhid - ok
18:09:19.0465 4732 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:09:19.0481 4732 mountmgr - ok
18:09:19.0528 4732 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
18:09:19.0543 4732 mpio - ok
18:09:19.0590 4732 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:09:19.0668 4732 mpsdrv - ok
18:09:19.0715 4732 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:09:19.0809 4732 MpsSvc - ok
18:09:19.0840 4732 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:09:19.0871 4732 MRxDAV - ok
18:09:19.0902 4732 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:09:19.0918 4732 mrxsmb - ok
18:09:19.0949 4732 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:09:19.0980 4732 mrxsmb10 - ok
18:09:19.0996 4732 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:09:20.0027 4732 mrxsmb20 - ok
18:09:20.0058 4732 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
18:09:20.0089 4732 msahci - ok
18:09:20.0105 4732 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:09:20.0136 4732 msdsm - ok
18:09:20.0152 4732 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
18:09:20.0167 4732 MSDTC - ok
18:09:20.0214 4732 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:09:20.0292 4732 Msfs - ok
18:09:20.0308 4732 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:09:20.0339 4732 mshidkmdf - ok
18:09:20.0370 4732 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:09:20.0370 4732 msisadrv - ok
18:09:20.0417 4732 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:09:20.0479 4732 MSiSCSI - ok
18:09:20.0495 4732 msiserver - ok
18:09:20.0511 4732 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:09:20.0557 4732 MSKSSRV - ok
18:09:20.0573 4732 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:09:20.0620 4732 MSPCLOCK - ok
18:09:20.0635 4732 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:09:20.0667 4732 MSPQM - ok
18:09:20.0698 4732 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:09:20.0713 4732 MsRPC - ok
18:09:20.0745 4732 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:09:20.0760 4732 mssmbios - ok
18:09:20.0791 4732 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:09:20.0854 4732 MSTEE - ok
18:09:20.0869 4732 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:09:20.0869 4732 MTConfig - ok
18:09:20.0885 4732 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
18:09:20.0901 4732 Mup - ok
18:09:20.0932 4732 [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
18:09:20.0963 4732 mwlPSDFilter - ok
18:09:20.0979 4732 [ 0BEFE32CA56D6EE89D58175725596A85 ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
18:09:20.0994 4732 mwlPSDNServ - ok
18:09:21.0010 4732 [ D43BC633B8660463E446E28E14A51262 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
18:09:21.0025 4732 mwlPSDVDisk - ok
18:09:21.0103 4732 [ 3E5E20817259F7328C8F3BE5421F35B9 ] MWLService C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
18:09:21.0119 4732 MWLService - ok
18:09:21.0166 4732 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
18:09:21.0244 4732 napagent - ok
18:09:21.0291 4732 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:09:21.0384 4732 NativeWifiP - ok
18:09:21.0431 4732 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:09:21.0493 4732 NDIS - ok
18:09:21.0509 4732 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:09:21.0571 4732 NdisCap - ok
18:09:21.0603 4732 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:09:21.0681 4732 NdisTapi - ok
18:09:21.0712 4732 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:09:21.0759 4732 Ndisuio - ok
18:09:21.0790 4732 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:09:21.0915 4732 NdisWan - ok
18:09:21.0946 4732 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:09:21.0993 4732 NDProxy - ok
18:09:22.0039 4732 [ D5AC41AE382738483FAFFBD7E373D49A ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
18:09:22.0039 4732 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
18:09:22.0039 4732 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
18:09:22.0086 4732 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:09:22.0117 4732 NetBIOS - ok
18:09:22.0149 4732 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:09:22.0180 4732 NetBT - ok
18:09:22.0227 4732 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
18:09:22.0258 4732 Netlogon - ok
18:09:22.0289 4732 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
18:09:22.0367 4732 Netman - ok
18:09:22.0383 4732 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
18:09:22.0429 4732 netprofm - ok
18:09:22.0445 4732 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:09:22.0461 4732 NetTcpPortSharing - ok
18:09:22.0492 4732 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:09:22.0507 4732 nfrd960 - ok
18:09:22.0617 4732 [ 1BF62D8130BEDBA41B18FC36C3E2B3B6 ] NitroReaderDriverReadSpool2 C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe
18:09:22.0632 4732 NitroReaderDriverReadSpool2 - ok
18:09:22.0679 4732 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:09:22.0757 4732 NlaSvc - ok
18:09:22.0897 4732 [ 5839A8027D6D324A7CD494051A96628C ] NOBU C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
18:09:23.0007 4732 NOBU - ok
18:09:23.0022 4732 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:09:23.0100 4732 Npfs - ok
18:09:23.0116 4732 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
18:09:23.0163 4732 nsi - ok
18:09:23.0178 4732 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:09:23.0225 4732 nsiproxy - ok
18:09:23.0287 4732 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:09:23.0334 4732 Ntfs - ok
18:09:23.0412 4732 [ 9A308FCDCCA98A15B6F62D36A272160E ] NTI IScheduleSvc C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
18:09:23.0428 4732 NTI IScheduleSvc - ok
18:09:23.0459 4732 [ 28C59F594044CBF8598B18C927097091 ] NTIBackupSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
18:09:23.0475 4732 NTIBackupSvc - ok
18:09:23.0506 4732 [ 710263B44C1D1AEE07525A53401FBE48 ] NTIDrvr C:\Windows\system32\drivers\NTIDrvr.sys
18:09:23.0537 4732 NTIDrvr - ok
18:09:23.0584 4732 [ B8D903B2894FF9AFBD99CA51C35590D7 ] NTISchedulerSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
18:09:23.0599 4732 NTISchedulerSvc - ok
18:09:23.0615 4732 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
18:09:23.0709 4732 Null - ok
18:09:23.0740 4732 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:09:23.0755 4732 nvraid - ok
18:09:23.0787 4732 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:09:23.0818 4732 nvstor - ok
18:09:23.0849 4732 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:09:23.0865 4732 nv_agp - ok
18:09:23.0896 4732 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:09:23.0927 4732 ohci1394 - ok
18:09:23.0989 4732 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:09:24.0021 4732 ose - ok
18:09:24.0177 4732 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:09:24.0286 4732 osppsvc - ok
18:09:24.0317 4732 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:09:24.0333 4732 p2pimsvc - ok
18:09:24.0364 4732 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
18:09:24.0379 4732 p2psvc - ok
18:09:24.0411 4732 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:09:24.0442 4732 Parport - ok
18:09:24.0504 4732 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:09:24.0520 4732 partmgr - ok
18:09:24.0582 4732 [ AFADA8B97BE3C9398DC6C770409C3544 ] PassThru Service C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
18:09:24.0598 4732 PassThru Service ( UnsignedFile.Multi.Generic ) - warning
18:09:24.0598 4732 PassThru Service - detected UnsignedFile.Multi.Generic (1)
18:09:24.0629 4732 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:09:24.0660 4732 PcaSvc - ok
18:09:24.0676 4732 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
18:09:24.0691 4732 pci - ok
18:09:24.0738 4732 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
18:09:24.0754 4732 pciide - ok
18:09:24.0769 4732 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:09:24.0816 4732 pcmcia - ok
18:09:24.0816 4732 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
18:09:24.0847 4732 pcw - ok
18:09:24.0863 4732 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:09:24.0910 4732 PEAUTH - ok
18:09:25.0003 4732 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
18:09:25.0019 4732 PerfHost - ok
18:09:25.0066 4732 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
18:09:25.0113 4732 pla - ok
18:09:25.0159 4732 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:09:25.0191 4732 PlugPlay - ok
18:09:25.0222 4732 [ 37F6046CDC630442D7DC087501FF6FC6 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
18:09:25.0237 4732 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
18:09:25.0237 4732 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
18:09:25.0253 4732 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:09:25.0269 4732 PNRPAutoReg - ok
18:09:25.0300 4732 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:09:25.0315 4732 PNRPsvc - ok
18:09:25.0347 4732 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:09:25.0456 4732 PolicyAgent - ok
18:09:25.0487 4732 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
18:09:25.0565 4732 Power - ok
18:09:25.0581 4732 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:09:25.0627 4732 PptpMiniport - ok
18:09:25.0659 4732 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:09:25.0674 4732 Processor - ok
18:09:25.0705 4732 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
18:09:25.0721 4732 ProfSvc - ok
18:09:25.0737 4732 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:09:25.0737 4732 ProtectedStorage - ok
18:09:25.0783 4732 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:09:25.0815 4732 Psched - ok
18:09:25.0861 4732 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:09:25.0893 4732 ql2300 - ok
18:09:25.0924 4732 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:09:25.0939 4732 ql40xx - ok
18:09:25.0971 4732 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
18:09:26.0002 4732 QWAVE - ok
18:09:26.0033 4732 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:09:26.0095 4732 QWAVEdrv - ok
18:09:26.0111 4732 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:09:26.0189 4732 RasAcd - ok
18:09:26.0251 4732 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:09:26.0283 4732 RasAgileVpn - ok
18:09:26.0314 4732 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
18:09:26.0345 4732 RasAuto - ok
18:09:26.0376 4732 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:09:26.0423 4732 Rasl2tp - ok
18:09:26.0470 4732 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
18:09:26.0548 4732 RasMan - ok
18:09:26.0579 4732 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:09:26.0610 4732 RasPppoe - ok
18:09:26.0610 4732 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:09:26.0673 4732 RasSstp - ok
18:09:26.0688 4732 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:09:26.0735 4732 rdbss - ok
18:09:26.0751 4732 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:09:26.0766 4732 rdpbus - ok
18:09:26.0782 4732 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:09:26.0829 4732 RDPCDD - ok
18:09:26.0829 4732 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:09:26.0875 4732 RDPENCDD - ok
18:09:26.0922 4732 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:09:27.0016 4732 RDPREFMP - ok
18:09:27.0063 4732 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:09:27.0078 4732 RDPWD - ok
18:09:27.0125 4732 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:09:27.0141 4732 rdyboost - ok
18:09:27.0172 4732 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
18:09:27.0203 4732 RemoteAccess - ok
18:09:27.0250 4732 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:09:27.0328 4732 RemoteRegistry - ok
18:09:27.0343 4732 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:09:27.0406 4732 RpcEptMapper - ok
18:09:27.0437 4732 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
18:09:27.0437 4732 RpcLocator - ok
18:09:27.0468 4732 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
18:09:27.0577 4732 RpcSs - ok
18:09:27.0609 4732 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:09:27.0671 4732 rspndr - ok
18:09:27.0687 4732 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
18:09:27.0702 4732 SamSs - ok
18:09:27.0733 4732 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:09:27.0765 4732 sbp2port - ok
18:09:27.0780 4732 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:09:27.0843 4732 SCardSvr - ok
18:09:27.0874 4732 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:09:27.0921 4732 scfilter - ok
18:09:27.0983 4732 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
18:09:28.0061 4732 Schedule - ok
18:09:28.0092 4732 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:09:28.0123 4732 SCPolicySvc - ok
18:09:28.0155 4732 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:09:28.0170 4732 SDRSVC - ok
18:09:28.0201 4732 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:09:28.0248 4732 secdrv - ok
18:09:28.0279 4732 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
18:09:28.0357 4732 seclogon - ok
18:09:28.0404 4732 [ EDE7A1D2715AAC2190D51DC07AFD44E3 ] seehcri C:\Windows\system32\DRIVERS\seehcri.sys
18:09:28.0420 4732 seehcri - ok
18:09:28.0451 4732 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
18:09:28.0498 4732 SENS - ok
18:09:28.0513 4732 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:09:28.0529 4732 SensrSvc - ok
18:09:28.0576 4732 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:09:28.0591 4732 Serenum - ok
18:09:28.0623 4732 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:09:28.0638 4732 Serial - ok
18:09:28.0669 4732 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:09:28.0701 4732 sermouse - ok
18:09:28.0732 4732 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
18:09:28.0794 4732 SessionEnv - ok
18:09:28.0825 4732 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:09:28.0841 4732 sffdisk - ok
18:09:28.0841 4732 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:09:28.0857 4732 sffp_mmc - ok
18:09:28.0872 4732 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:09:28.0888 4732 sffp_sd - ok
18:09:28.0919 4732 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:09:28.0935 4732 sfloppy - ok
18:09:28.0981 4732 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
18:09:29.0013 4732 Sftfs - ok
18:09:29.0075 4732 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
18:09:29.0106 4732 sftlist - ok
18:09:29.0122 4732 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
18:09:29.0137 4732 Sftplay - ok
18:09:29.0153 4732 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
18:09:29.0169 4732 Sftredir - ok
18:09:29.0200 4732 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
18:09:29.0215 4732 Sftvol - ok
18:09:29.0247 4732 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
18:09:29.0262 4732 sftvsa - ok
18:09:29.0325 4732 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:09:29.0403 4732 SharedAccess - ok
18:09:29.0434 4732 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:09:29.0512 4732 ShellHWDetection - ok
18:09:29.0543 4732 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:09:29.0559 4732 SiSRaid2 - ok
18:09:29.0574 4732 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:09:29.0590 4732 SiSRaid4 - ok
18:09:29.0761 4732 [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
18:09:29.0824 4732 Skype C2C Service - ok
18:09:29.0871 4732 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
18:09:29.0886 4732 SkypeUpdate - ok
18:09:29.0917 4732 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:09:29.0995 4732 Smb - ok
18:09:30.0089 4732 [ B24F7A40F2B4901DA7B76A88339553B8 ] SndVol64 C:\Windows\system32\actjveds.exe
18:09:30.0089 4732 SndVol64 ( UnsignedFile.Multi.Generic ) - warning
18:09:30.0089 4732 SndVol64 - detected UnsignedFile.Multi.Generic (1)
18:09:30.0136 4732 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:09:30.0167 4732 SNMPTRAP - ok
18:09:30.0198 4732 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
18:09:30.0245 4732 spldr - ok
18:09:30.0276 4732 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
18:09:30.0292 4732 Spooler - ok
18:09:30.0401 4732 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
18:09:30.0479 4732 sppsvc - ok
18:09:30.0510 4732 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:09:30.0541 4732 sppuinotify - ok
18:09:30.0588 4732 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
18:09:30.0666 4732 srv - ok
18:09:30.0682 4732 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:09:30.0697 4732 srv2 - ok
18:09:30.0697 4732 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:09:30.0713 4732 srvnet - ok
18:09:30.0744 4732 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:09:30.0791 4732 SSDPSRV - ok
18:09:30.0807 4732 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:09:30.0838 4732 SstpSvc - ok
18:09:30.0885 4732 [ C692C94FE55CAD0633440236022C27B3 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
18:09:30.0916 4732 ssudmdm - ok
18:09:30.0947 4732 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:09:30.0978 4732 stexstor - ok
18:09:31.0025 4732 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
18:09:31.0072 4732 stisvc - ok
18:09:31.0087 4732 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
18:09:31.0103 4732 swenum - ok
18:09:31.0150 4732 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
18:09:31.0243 4732 swprv - ok
18:09:31.0306 4732 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
18:09:31.0337 4732 SysMain - ok
18:09:31.0368 4732 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:09:31.0384 4732 TabletInputService - ok
18:09:31.0415 4732 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
18:09:31.0462 4732 TapiSrv - ok
18:09:31.0477 4732 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
18:09:31.0509 4732 TBS - ok
18:09:31.0587 4732 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:09:31.0649 4732 Tcpip - ok
18:09:31.0727 4732 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:09:31.0774 4732 TCPIP6 - ok
18:09:31.0805 4732 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:09:31.0836 4732 tcpipreg - ok
18:09:31.0867 4732 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:09:31.0883 4732 TDPIPE - ok
18:09:31.0930 4732 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:09:31.0945 4732 TDTCP - ok
18:09:31.0992 4732 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:09:32.0070 4732 tdx - ok
18:09:32.0101 4732 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:09:32.0117 4732 TermDD - ok
18:09:32.0164 4732 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
18:09:32.0257 4732 TermService - ok
18:09:32.0289 4732 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
18:09:32.0304 4732 Themes - ok
18:09:32.0335 4732 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
18:09:32.0413 4732 THREADORDER - ok
18:09:32.0429 4732 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
18:09:32.0491 4732 TrkWks - ok
18:09:32.0538 4732 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:09:32.0616 4732 TrustedInstaller - ok
18:09:32.0647 4732 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:09:32.0694 4732 tssecsrv - ok
18:09:32.0710 4732 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:09:32.0757 4732 TsUsbFlt - ok
18:09:32.0788 4732 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:09:32.0819 4732 tunnel - ok
18:09:32.0850 4732 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:09:32.0866 4732 uagp35 - ok
18:09:32.0897 4732 [ 40079B0B801C5432BA435B5AD61CE6E3 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys
18:09:32.0913 4732 UBHelper - ok
18:09:32.0944 4732 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:09:33.0006 4732 udfs - ok
18:09:33.0053 4732 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:09:33.0069 4732 UI0Detect - ok
18:09:33.0084 4732 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:09:33.0100 4732 uliagpkx - ok
18:09:33.0131 4732 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
18:09:33.0147 4732 umbus - ok
18:09:33.0178 4732 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:09:33.0209 4732 UmPass - ok
18:09:33.0349 4732 [ CC3775100ABA633984F73DFAE1F55CAE ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
18:09:33.0412 4732 UNS - ok
18:09:33.0490 4732 [ F9EC9ACD504D823D9B9CA98A4F8D3CA2 ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
18:09:33.0521 4732 Updater Service - ok
18:09:33.0552 4732 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
18:09:33.0630 4732 upnphost - ok
18:09:33.0661 4732 [ 54D4B48D443E7228BF64CF7CDC3118AC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
18:09:33.0677 4732 USBAAPL64 - ok
18:09:33.0708 4732 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:09:33.0724 4732 usbccgp - ok
18:09:33.0755 4732 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:09:33.0771 4732 usbcir - ok
18:09:33.0786 4732 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
18:09:33.0802 4732 usbehci - ok
18:09:33.0849 4732 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:09:33.0864 4732 usbhub - ok
18:09:33.0880 4732 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:09:33.0895 4732 usbohci - ok
18:09:33.0927 4732 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:09:33.0942 4732 usbprint - ok
18:09:33.0989 4732 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
18:09:34.0005 4732 usbscan - ok
18:09:34.0036 4732 [ 0F0C72A657C622286013788B886968AD ] usbser C:\Windows\system32\DRIVERS\usbser.sys
18:09:34.0051 4732 usbser - ok
18:09:34.0083 4732 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:09:34.0098 4732 USBSTOR - ok
18:09:34.0129 4732 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
18:09:34.0145 4732 usbuhci - ok
18:09:34.0176 4732 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
18:09:34.0192 4732 usbvideo - ok
18:09:34.0223 4732 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
18:09:34.0254 4732 UxSms - ok
18:09:34.0270 4732 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
18:09:34.0285 4732 VaultSvc - ok
18:09:34.0317 4732 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
18:09:34.0348 4732 vdrvroot - ok
18:09:34.0395 4732 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
18:09:34.0441 4732 vds - ok
18:09:34.0473 4732 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:09:34.0519 4732 vga - ok
18:09:34.0551 4732 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
18:09:34.0597 4732 VgaSave - ok
18:09:34.0629 4732 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
18:09:34.0644 4732 vhdmp - ok
18:09:34.0660 4732 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
18:09:34.0675 4732 viaide - ok
18:09:34.0691 4732 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:09:34.0738 4732 volmgr - ok
18:09:34.0753 4732 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:09:34.0769 4732 volmgrx - ok
18:09:34.0769 4732 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:09:34.0785 4732 volsnap - ok
18:09:34.0831 4732 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
18:09:34.0831 4732 vsmraid - ok
18:09:34.0894 4732 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
18:09:34.0941 4732 VSS - ok
18:09:34.0956 4732 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
18:09:34.0972 4732 vwifibus - ok
18:09:34.0987 4732 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
18:09:35.0003 4732 vwififlt - ok
18:09:35.0019 4732 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
18:09:35.0034 4732 vwifimp - ok
18:09:35.0081 4732 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
18:09:35.0128 4732 W32Time - ok
18:09:35.0159 4732 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
18:09:35.0159 4732 WacomPen - ok
18:09:35.0206 4732 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
18:09:35.0268 4732 WANARP - ok
18:09:35.0268 4732 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:09:35.0331 4732 Wanarpv6 - ok
18:09:35.0409 4732 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
18:09:35.0440 4732 WatAdminSvc - ok
18:09:35.0502 4732 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
18:09:35.0533 4732 wbengine - ok
18:09:35.0565 4732 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
18:09:35.0580 4732 WbioSrvc - ok
18:09:35.0627 4732 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:09:35.0643 4732 wcncsvc - ok
18:09:35.0658 4732 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:09:35.0674 4732 WcsPlugInService - ok
18:09:35.0705 4732 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
18:09:35.0705 4732 Wd - ok
18:09:35.0736 4732 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:09:35.0752 4732 Wdf01000 - ok
18:09:35.0783 4732 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:09:35.0799 4732 WdiServiceHost - ok
18:09:35.0799 4732 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:09:35.0814 4732 WdiSystemHost - ok
18:09:35.0845 4732 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
18:09:35.0861 4732 WebClient - ok
18:09:35.0892 4732 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:09:35.0939 4732 Wecsvc - ok
18:09:35.0970 4732 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:09:36.0001 4732 wercplsupport - ok
18:09:36.0033 4732 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
18:09:36.0095 4732 WerSvc - ok
18:09:36.0126 4732 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
18:09:36.0173 4732 WfpLwf - ok
18:09:36.0189 4732 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
18:09:36.0204 4732 WIMMount - ok
18:09:36.0220 4732 WinDefend - ok
18:09:36.0220 4732 WinHttpAutoProxySvc - ok
18:09:36.0282 4732 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:09:36.0313 4732 Winmgmt - ok
18:09:36.0376 4732 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
18:09:36.0438 4732 WinRM - ok
18:09:36.0485 4732 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
18:09:36.0501 4732 WinUsb - ok
18:09:36.0563 4732 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
18:09:36.0594 4732 Wlansvc - ok
18:09:36.0625 4732 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:09:36.0657 4732 WmiAcpi - ok
18:09:36.0672 4732 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:09:36.0703 4732 wmiApSrv - ok
18:09:36.0719 4732 WMPNetworkSvc - ok
18:09:36.0750 4732 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:09:36.0750 4732 WPCSvc - ok
18:09:36.0797 4732 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:09:36.0813 4732 WPDBusEnum - ok
18:09:36.0844 4732 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:09:36.0906 4732 ws2ifsl - ok
18:09:36.0937 4732 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
18:09:36.0953 4732 wscsvc - ok
18:09:36.0953 4732 WSearch - ok
18:09:37.0031 4732 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
18:09:37.0078 4732 wuauserv - ok
18:09:37.0093 4732 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:09:37.0140 4732 WudfPf - ok
18:09:37.0171 4732 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:09:37.0218 4732 WUDFRd - ok
18:09:37.0249 4732 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:09:37.0281 4732 wudfsvc - ok
18:09:37.0312 4732 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
18:09:37.0343 4732 WwanSvc - ok
18:09:37.0374 4732 ================ Scan global ===============================
18:09:37.0405 4732 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
18:09:37.0437 4732 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
18:09:37.0452 4732 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
18:09:37.0468 4732 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
18:09:37.0499 4732 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
18:09:37.0499 4732 [Global] - ok
18:09:37.0499 4732 ================ Scan MBR ==================================
18:09:37.0530 4732 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
18:09:37.0873 4732 \Device\Harddisk0\DR0 - ok
18:09:37.0873 4732 ================ Scan VBR ==================================
18:09:37.0889 4732 [ 95FBC11516C450CB1AABD87ACC9059F2 ] \Device\Harddisk0\DR0\Partition1
18:09:37.0889 4732 \Device\Harddisk0\DR0\Partition1 - ok
18:09:37.0905 4732 [ 46EA97EADE8EF6E83A3CABA9BB530D37 ] \Device\Harddisk0\DR0\Partition2
18:09:37.0905 4732 \Device\Harddisk0\DR0\Partition2 - ok
18:09:37.0920 4732 [ 69C4A2B68B1ED542E46588579E77DA99 ] \Device\Harddisk0\DR0\Partition3
18:09:37.0920 4732 \Device\Harddisk0\DR0\Partition3 - ok
18:09:37.0920 4732 ============================================================
18:09:37.0920 4732 Scan finished
18:09:37.0920 4732 ============================================================
18:09:37.0936 3752 Detected object count: 10
18:09:37.0936 3752 Actual detected object count: 10
18:15:53.0957 3752 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0957 3752 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0960 3752 GFilterSvc ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0960 3752 GFilterSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0963 3752 hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0963 3752 hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0966 3752 hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0966 3752 hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0969 3752 HPSLPSVC ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0969 3752 HPSLPSVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0972 3752 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0972 3752 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0974 3752 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0974 3752 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0976 3752 PassThru Service ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0976 3752 PassThru Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0978 3752 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0978 3752 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0980 3752 SndVol64 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0980 3752 SndVol64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:17:21.0603 4136 Deinitialize success

Alt 07.11.2012, 23:45   #27
markusg
/// Malware-holic
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



gibts momentan noch probleme?
wenn ja, welche
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 08.11.2012, 09:33   #28
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



Moin. Ja und zwar Mozilla stürzt immer nach ein paar Minuten ab. Beim Start des rechners keine Internet verbindung möglich.eset führt keine Überprüfung mehr durch und bricht immer bei der selben Datei ab. Internet sehr langsam.

Alt 08.11.2012, 12:56   #29
markusg
/// Malware-holic
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



hi
gibt es noch weitere eset funde? dann poste diese mal bitte
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 08.11.2012, 17:12   #30
pkhoschi
 
Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - Standard

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme



Nein denn eset Prüfung bleibt ja immer bei der selben Datei hängen, wenn ich Prüfung gestartet hab

Antwort

Themen zu Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme
browser, eset, eset smart security, gefunde, gemerkt, inter, interne, internet, internet browser, programm, security, smart, smart security, total, verlangsamt, viren, virus




Ähnliche Themen: Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme


  1. Habe ich einen Trojaner - und bekomme ich ihn weg
    Log-Analyse und Auswertung - 05.04.2014 (14)
  2. Habe ich einen Trojaner? Wie bekomme ich das raus?
    Plagegeister aller Art und deren Bekämpfung - 11.05.2013 (16)
  3. Ich habe einen TR/ATRAPS.Gen Trojaner und würde gerne wissen wie ich den weg bekomme.
    Log-Analyse und Auswertung - 30.08.2012 (28)
  4. Ich habe ein Virus und weiss nicht was ich machen soll =(
    Plagegeister aller Art und deren Bekämpfung - 21.12.2011 (13)
  5. Benötige einen Check meiner Dienste, evtl. habe ich einen Virus, der meinen PC überwacht!
    Log-Analyse und Auswertung - 19.12.2011 (10)
  6. Ich weiß nicht ob ich einen Virus habe oder nicht.
    Plagegeister aller Art und deren Bekämpfung - 22.08.2011 (1)
  7. habe ein virus und weiss nicht wie er heißt das einzige was ich dazu sagen kann ist das http://www1.
    Log-Analyse und Auswertung - 13.06.2011 (14)
  8. Ich habe Virus nur weiß nicht was für einen?
    Plagegeister aller Art und deren Bekämpfung - 22.08.2010 (3)
  9. Habe ich einen Virus? Avira funktioniert nicht und es taucht ein komischer prozess au
    Plagegeister aller Art und deren Bekämpfung - 29.12.2009 (1)
  10. - habe einen virus oder trojaner den ich nicht identifizieren kann -
    Mülltonne - 05.01.2009 (0)
  11. Bekomme immer eine Meldung,dass ich einen Virus auf meinem Rechner habe
    Plagegeister aller Art und deren Bekämpfung - 16.01.2007 (12)
  12. Ich habe wahrscheinlich einen Trojaner und weiss nicht weiter.
    Log-Analyse und Auswertung - 13.01.2007 (2)
  13. habe einen Trojaner auf meinem rechner und weiss nicht wie ich ihn lösche
    Log-Analyse und Auswertung - 22.02.2006 (3)
  14. Habe TROJANER oder VIRUS nd bekomme ihn nicht weg
    Plagegeister aller Art und deren Bekämpfung - 08.08.2005 (7)
  15. Hilfe ich habe einen Trojaner den ich nicht weg bekomme
    Plagegeister aller Art und deren Bekämpfung - 11.01.2005 (4)
  16. Hilfe ich habe einen Trojaner den ich nicht weg bekomme
    Antiviren-, Firewall- und andere Schutzprogramme - 11.01.2005 (1)
  17. Ich weiss nicht ob ich einen Virus auf meinem PC habe
    Plagegeister aller Art und deren Bekämpfung - 02.03.2003 (15)

Zum Thema Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme - soll ich die firewall während dessen auch deaktivieren? - Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme...
Archiv
Du betrachtest: Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.