![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab!Code:
ATTFilter All processes killed
========== OTL ==========
Service EagleNT stopped successfully!
Service EagleNT deleted successfully!
File C:\Users\...~1\AppData\Local\Temp\EagleNT.sys File not found not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\Users\...~1\AppData\Local\Temp\catchme.sys File not found not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: ...
->Temp folder emptied: 1881344 bytes
->Temporary Internet Files folder emptied: 34047041 bytes
->Java cache emptied: 8010071 bytes
->FireFox cache emptied: 82974388 bytes
->Apple Safari cache emptied: 13346816 bytes
->Flash cache emptied: 5870 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 200704 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 14913 bytes
Total Files Cleaned = 134,00 mb
OTL by OldTimer - Version 3.2.17.3 log created on 12032010_111334
Files\Folders moved on Reboot...
File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
jetzt funktioniert aber die scroll-funktion meines touchpads nicht mehr... wie kann das denn jetzt sein? |
| | #2 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! ich habe grade den neuesten treiber von HP für mein touchpad installiert, aber meine scroll-funktion funktioniert nicht mehr...hilfe
__________________ |
| | #3 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! Probier CF nochmal, aber strikt nach dieser Anleitung!
__________________ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ |
| | #4 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab!Code:
ATTFilter ComboFix 10-12-02.06 - ... 03.12.2010 21:38:31.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.3069.2166 [GMT 1:00]
ausgeführt von:: c:\users\...\Desktop\confi.exe
.
((((((((((((((((((((((( Dateien erstellt von 2010-11-03 bis 2010-12-03 ))))))))))))))))))))))))))))))
.
2010-12-03 20:43 . 2010-12-03 20:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-03 20:10 . 2010-12-03 20:10 -------- d-----w- c:\program files\Synaptics
2010-12-03 10:27 . 2010-12-03 10:27 -------- d-----w- c:\program files\HP
2010-12-03 10:13 . 2010-12-03 10:13 -------- d-----w- C:\_OTL
2010-12-03 10:03 . 2010-12-03 20:43 -------- d-----w- c:\users\...\AppData\Local\temp
2010-12-03 09:55 . 2010-12-03 20:37 -------- d-----w- C:\ComboFix
2010-12-03 09:52 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F401FEA7-D244-4947-A548-4BA2BC6C01D7}\mpengine.dll
2010-12-02 11:44 . 2010-12-02 11:45 -------- d-----w- c:\program files\DivX
2010-12-02 10:52 . 2009-07-19 15:03 497664 ----a-w- c:\windows\system32\ac3filter.acm
2010-12-02 10:52 . 2010-12-02 10:52 -------- d-----w- c:\program files\AC3Filter
2010-11-30 18:45 . 2010-12-03 19:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-11-30 18:45 . 2010-11-30 18:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-11-30 18:41 . 2010-11-30 18:41 -------- d-----w- c:\users\...\AppData\Roaming\Malwarebytes
2010-11-30 18:41 . 2010-11-30 18:41 -------- d-----w- c:\programdata\Malwarebytes
2010-11-30 18:41 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-30 18:41 . 2010-11-30 18:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-30 18:41 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-30 12:18 . 2010-11-30 12:18 -------- d-----w- c:\users\...\AppData\Roaming\Intel
2010-11-30 12:16 . 2010-11-30 12:16 -------- d-----w- c:\program files\Cisco
2010-11-30 12:16 . 2010-11-30 12:16 -------- d-----w- c:\program files\Common Files\Intel
2010-11-30 12:16 . 2010-11-30 12:16 -------- d-----w- c:\programdata\Intel
2010-11-30 10:58 . 2010-10-16 18:55 888424 ----a-w- c:\windows\system32\nvdispco322050.dll
2010-11-30 10:58 . 2010-10-16 18:55 813672 ----a-w- c:\windows\system32\nvgenco322030.dll
2010-11-30 10:58 . 2010-09-07 20:09 26216 ----a-w- c:\windows\system32\nvhdap32.dll
2010-11-30 10:58 . 2010-09-07 20:09 65640 ----a-w- c:\windows\system32\nvapo32v.dll
2010-11-30 10:58 . 2010-09-07 20:08 123496 ----a-w- c:\windows\system32\drivers\nvhda32v.sys
2010-11-30 10:58 . 2010-09-07 20:08 813672 ----a-w- c:\windows\system32\nvgenco32.dll
2010-11-20 18:22 . 2010-11-20 18:22 -------- d-----w- c:\program files\Veetle
2010-11-06 20:46 . 2010-11-06 20:46 -------- d-----w- c:\program files\Common Files\Java
2010-11-06 20:46 . 2010-09-15 03:50 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-11-06 10:37 . 2010-11-06 10:37 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-11-06 10:37 . 2010-11-06 10:37 103864 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2010-11-05 20:29 . 2010-11-05 20:29 -------- d-----w- c:\program files\ICQ Update Patch
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 09:41 . 2009-10-14 02:21 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-09-29 16:47 . 2010-10-18 12:51 4032992 ----a-w- c:\windows\system32\GameMon.des
2010-09-15 03:50 . 2010-04-16 18:08 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-08 04:30 . 2010-10-13 09:15 978432 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28 . 2010-10-13 09:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22 . 2010-10-13 09:15 386048 ----a-w- c:\windows\system32\html.iec
2010-09-08 02:48 . 2010-10-13 09:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 321080]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-04-14 2790472]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-03-23 495708]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-06-08 284696]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"QuickLaunchEnabled"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TMMonitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk
backup=c:\windows\pss\TMMonitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^...^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^klickTel OEM 2008 - Schnellstarter.lnk]
path=c:\users\...\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\klickTel OEM 2008 - Schnellstarter.lnk
backup=c:\windows\pss\klickTel OEM 2008 - Schnellstarter.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2008-07-04 13:00 109056 ----a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-03-25 23:10 142120 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2009-08-20 11:25 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-07-02 10:20 671608 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
2010-10-13 07:57 215944 ----a-w- c:\program files\pdf24\pdf24.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
2007-12-14 09:36 50472 ------w- c:\program files\CyberLink\PowerDVD8\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
2008-03-20 18:23 83240 ------w- c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung Common SM]
2005-07-03 07:20 372736 ------w- c:\windows\Samsung\ComSMMgr\SSMMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 10:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2010-07-06 14:01 2634048 ----a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2007-09-27 01:05 734264 ----a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 iscFlash;iscFlash;c:\swsetup\sp45138\iscflash.sys [2009-06-16 13312]
R3 NETw5s32;Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 32-Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2010-05-31 6766080]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-09-29 4032992]
R3 RTL2832U_IRHID;HID Infrared Remote Receiver;c:\windows\system32\DRIVERS\RTL2832U_IRHID.sys [2009-07-13 37280]
R3 RTL2832UBDA;REALTEK 2832U BDA Driver;c:\windows\system32\drivers\RTL2832UBDA.sys [2009-07-06 91168]
R3 RTL2832UUSB;REALTEK 2832U USB Driver;c:\windows\system32\Drivers\RTL2832UUSB.sys [2009-07-06 32800]
R3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\DRIVERS\SCR3XX2K.sys [2010-01-06 57856]
S0 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys [2009-11-10 17320]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe [2009-03-02 81920]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-04-14 51792]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2010-06-15 26168]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-06-08 13336]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-28 59904]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-12-17 129136]
S3 NETwNs32;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 32-Bit;c:\windows\system32\DRIVERS\NETwNs32.sys [2010-07-14 6814720]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-09-07 123496]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
2010-11-30 c:\windows\Tasks\DriverEasy Scheduled Scan.job
- c:\program files\Easeware\DriverEasy\DriverEasy.exe [2010-08-27 12:17]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uInternet Settings,ProxyOverride = local
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: kino.to
TCP: {7325BC76-0D62-4F0E-99B7-BE30FE7A5D0E} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\...\AppData\Roaming\Mozilla\Firefox\Profiles\yqsjzsks....\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-556683703-228710120-2652249240-1000\Software\SecuROM\License information*]
"datasecu"=hex:e9,78,54,bc,83,6d,e6,63,79,fe,31,2a,dc,9e,ac,91,41,7f,a2,59,4b,
32,c9,4d,8c,ec,64,29,0b,9b,97,68,a9,39,5b,0a,5f,5e,95,8c,bb,74,7a,49,91,d5,\
"rkeysecu"=hex:ac,b0,07,4d,48,dc,c3,98,2e,1d,6f,8c,ab,d6,ed,50
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'Explorer.exe'(2736)
c:\windows\system32\fxsst.dll
.
Zeit der Fertigstellung: 2010-12-03 21:44:41
ComboFix-quarantined-files.txt 2010-12-03 20:44
ComboFix2.txt 2010-12-03 10:03
Vor Suchlauf: 18 Verzeichnis(se), 126.164.307.968 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 125.771.444.224 Bytes frei
- - End Of File - - E301B845490091523D4145C36DB4856B
|
| | #5 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #6 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! GMER: Code:
ATTFilter GMER 1.0.15.15530 - hxxp://www.gmer.net
Rootkit scan 2010-12-04 20:51:52
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 FUJITSU_ rev.8909
Running: feh8d6fq.exe; Driver: C:\Users\...~1\AppData\Local\Temp\pxldapow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0x8B01550A]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0x8B01532E]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0x8B015468]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E5A599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E7EF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE ntkrnlpa.exe!ZwLoadDriver 82FB8291 7 Bytes JMP 8B01546C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 8301FFBF 5 Bytes JMP 8B0114AA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 83039CF3 5 Bytes JMP 8B0129E4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 83047D63 7 Bytes JMP 8B015332 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 830F1EAC 7 Bytes JMP 8B01550E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\System32\rundll32.exe[3312] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [755C5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3312] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [755C5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3312] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [755C5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3312] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [755C5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004d halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
OSAM: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 21:05:57 on 04.12.2010 OS: Windows 7 Ultimate Edition (Build 7600), 32-bit Default Browser: Microsoft Corporation Internet Explorer 8.00.7600.16385 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "DriverEasy Scheduled Scan.job" - "Easeware" - C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [Control Panel Objects] -----( %SystemRoot%\system32 )----- "DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl "nvcpl.cpl" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.cpl -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "HP 3D DriveGuard" - "Hewlett-Packard" - C:\Program Files\Hewlett-Packard\HP 3D DriveGuard\hpaccelerometercp.CPL "mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL "Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero 9\Nero BurnRights\NeroBurnRights_cpl.cpl "Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl "PROSet Tools" - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\iproset.cpl "QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "aswFsBlk" (aswFsBlk) - "ALWIL Software" - C:\Windows\system32\drivers\aswFsBlk.sys "aswMonFlt" (aswMonFlt) - "ALWIL Software" - C:\Windows\system32\drivers\aswMonFlt.sys "aswRdr" (aswRdr) - "ALWIL Software" - C:\Windows\system32\drivers\aswRdr.sys "aswSP" (aswSP) - "ALWIL Software" - C:\Windows\system32\drivers\aswSP.sys "avast! Network Shield Support" (aswTdi) - "ALWIL Software" - C:\Windows\system32\drivers\aswTdi.sys "catchme" (catchme) - ? - C:\Users\...~1\AppData\Local\Temp\catchme.sys (File not found) "giveio" (giveio) - ? - C:\Windows\System32\giveio.sys (File found, but it contains no detailed information) "iscFlash" (iscFlash) - "Insyde Software" - C:\SwSetup\sp45138\iscflash.sys "PPdus ASPI Shell" (Afc) - "Arcsoft, Inc." - C:\Windows\System32\drivers\Afc.sys "pxldapow" (pxldapow) - ? - C:\Users\...~1\AppData\Local\Temp\pxldapow.sys (Hidden registry entry, rootkit activity | File not found) "speedfan" (speedfan) - "Windows (R) 2000 DDK provider" - C:\Windows\System32\speedfan.sys "Team MFP Comm Driver" (DgiVecp) - "DeviceGuys, Inc." - C:\Windows\System32\Drivers\DgiVecp.sys [Explorer] -----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )----- {10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll -----( HKLM\Software\Classes\Protocols\Filter )----- {807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL -----( HKLM\Software\Classes\Protocols\Handler )----- {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll {88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} "vsharechrome" - ? - (File not found | COM-object registry key not found) {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} "WOT Protocol" - "WOT Services Oy" - C:\Program Files\WOT\WOT.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {472083B0-C522-11CF-8763-00608CC02F24} "avast" - "ALWIL Software" - C:\Program Files\Alwil Software\Avast5\ashShell.dll {A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll {D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll {83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll {99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL {00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {A929C4CE-FD36-4270-B4F5-34ECAC5BD63C} "NvAppShExt Class" - "NVIDIA Corporation" - C:\Windows\system32\nv3dappshext.dll {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll {FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll {E97DEC16-A50D-49bb-AE24-CF682282E08D} "OpenGLShExt Class" - "NVIDIA Corporation" - C:\Windows\system32\nv3dappshext.dll {0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) <binary data> "WOT" - "WOT Services Oy" - C:\Program Files\WOT\WOT.dll -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} "GMNRev Class" - "Hewlett-Packard" - C:\Program Files\HP\Common\HPGMNRev.dll / hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab {1851174C-97BD-4217-A0CC-E908F60D5B7A} "Hewlett-Packard Online Support Services" - "Hewlett-Packard" - C:\Windows\DOWNLO~1\HPISDA~1.DLL / https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB {6F15128C-E66A-490C-B848-5000B5ABEEAC} "HP Download Manager" - "Hewlett-Packard Co." - C:\Windows\Downloaded Program Files\HPDEXAXO.dll / https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_22.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab {166B1BCA-3F9C-11CF-8075-444553540000} "Shockwave ActiveX Control" - "Adobe Systems, Inc." - C:\Windows\system32\Adobe\Director\SwDir.dll / hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab {233C1507-6A77-46A4-9443-F871F945D258} "Shockwave ActiveX Control" - "Adobe Systems, Inc." - C:\Windows\system32\Adobe\Director\SwDir.dll / hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} "SysInfo Class" - "Husdawg, LLC" - C:\Program Files\SystemRequirementsLab\srldetect_intel_4.1.66.0.dll / hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab {E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? - (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll "ICQ6" - "ICQ, LLC." - C:\Program Files\ICQ6.5\ICQ.exe {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- {71576546-354D-41c9-AAE8-31F2EC22BF0D} "WOT" - "WOT Services Oy" - C:\Program Files\WOT\WOT.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} "WOT Helper" - "WOT Services Oy" - C:\Program Files\WOT\WOT.dll [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\...\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "avast5" - "ALWIL Software" - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui "IAStorIcon" - "Intel Corporation" - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe "QlbCtrl.exe" - " Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe "ArcSoft Connect Daemon" (ACDaemon) - "ArcSoft Inc." - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe "avast! Antivirus" (avast! Antivirus) - "ALWIL Software" - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe "avast! Mail Scanner" (avast! Mail Scanner) - "ALWIL Software" - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe "avast! Web Scanner" (avast! Web Scanner) - "ALWIL Software" - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe "Com4QLBEx" (Com4QLBEx) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe "Google Update Service (gupdate)" (gupdate) - ? - "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (File not found) "hpqwmiex" (hpqwmiex) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe "Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe "Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe "Intel(R) Rapid Storage Technology" (IAStorDataMgrSvc) - "Intel Corporation" - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe "iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe "LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE "Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe "Nero BackItUp Scheduler 4.0" (Nero BackItUp Scheduler 4.0) - "Nero AG" - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe "nProtect GameGuard Service" (npggsvc) - "INCA Internet Co., Ltd." - C:\Windows\system32\GameMon.des "NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [Winlogon] -----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )----- "ScCertProp" - ? - wlnotify.dll (File not found) ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Code:
ATTFilter MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv5 Notebook PC
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 207):
0x82E17000 \SystemRoot\system32\ntkrnlpa.exe
0x83227000 \SystemRoot\system32\halmacpi.dll
0x80BA5000 \SystemRoot\system32\kdcom.dll
0x8B03F000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8B0B7000 \SystemRoot\system32\PSHED.dll
0x8B0C8000 \SystemRoot\system32\BOOTVID.dll
0x8B0D0000 \SystemRoot\system32\CLFS.SYS
0x8B112000 \SystemRoot\system32\CI.dll
0x8B214000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8B285000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8B293000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x8B2DB000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x8B2E4000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x8B2EC000 \SystemRoot\system32\DRIVERS\pci.sys
0x8B316000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x8B321000 \SystemRoot\System32\drivers\partmgr.sys
0x8B332000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8B33A000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8B345000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x8B355000 \SystemRoot\System32\drivers\volmgrx.sys
0x8B3A0000 \SystemRoot\System32\drivers\mountmgr.sys
0x8B421000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x8B5D6000 \SystemRoot\system32\DRIVERS\atapi.sys
0x8B3B6000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x8B5DF000 \SystemRoot\system32\DRIVERS\msahci.sys
0x8B5E9000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8B5F7000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8B1BD000 \SystemRoot\system32\drivers\fltmgr.sys
0x8B400000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B623000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B752000 \SystemRoot\System32\Drivers\msrpc.sys
0x8B77D000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B790000 \SystemRoot\System32\Drivers\cng.sys
0x8B7ED000 \SystemRoot\System32\drivers\pcw.sys
0x8B600000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8B805000 \SystemRoot\system32\drivers\ndis.sys
0x8B8BC000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B8FA000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8BA26000 \SystemRoot\System32\drivers\tcpip.sys
0x8BB6F000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8BBA0000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8BBA9000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8BBE8000 \SystemRoot\System32\Drivers\spldr.sys
0x8BBF0000 \SystemRoot\system32\speedfan.sys
0x8B91F000 \SystemRoot\System32\drivers\rdyboost.sys
0x8BA00000 \SystemRoot\System32\Drivers\mup.sys
0x8BA10000 \SystemRoot\system32\DRIVERS\johci.sys
0x8BA18000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8BBF2000 \SystemRoot\system32\DRIVERS\hpdskflt.sys
0x8BBFB000 \SystemRoot\system32\giveio.sys
0x8B94C000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8B97E000 \SystemRoot\system32\DRIVERS\disk.sys
0x8B98F000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x909C9000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x909E8000 \SystemRoot\System32\Drivers\Null.SYS
0x909EF000 \SystemRoot\System32\Drivers\Beep.SYS
0x8B9C1000 \SystemRoot\System32\drivers\vga.sys
0x8B9CD000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8B9EE000 \SystemRoot\System32\drivers\watchdog.sys
0x909F6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8B609000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8B611000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8B411000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8B3D9000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8B3E7000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8B200000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8B619000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x90E21000 \SystemRoot\system32\drivers\afd.sys
0x90E7B000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x90E80000 \SystemRoot\System32\DRIVERS\netbt.sys
0x90EB2000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x90EB9000 \SystemRoot\system32\DRIVERS\pacer.sys
0x90ED8000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x90EE9000 \SystemRoot\system32\DRIVERS\netbios.sys
0x90EF7000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x90F0A000 \SystemRoot\system32\DRIVERS\termdd.sys
0x90F1A000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90F5B000 \SystemRoot\system32\drivers\nsiproxy.sys
0x90F65000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x90F6F000 \SystemRoot\System32\drivers\discache.sys
0x90F7B000 \SystemRoot\system32\drivers\csc.sys
0x90FDF000 \SystemRoot\System32\Drivers\dfsc.sys
0x90E00000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x8B000000 \SystemRoot\System32\Drivers\aswSP.SYS
0x90401000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x90422000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x90434000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x93634000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x94095000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x94097000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x9414E000 \SystemRoot\System32\drivers\dxgmms1.sys
0x94187000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x94192000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x941DD000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x93600000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x97032000 \SystemRoot\system32\DRIVERS\NETwNs32.sys
0x976BC000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x976C6000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x9770B000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x9771B000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x9772F000 \SystemRoot\system32\DRIVERS\jmcr.sys
0x97750000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0x97776000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x9778E000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x97797000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x977A4000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x977D4000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x977D6000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x977E3000 \SystemRoot\system32\DRIVERS\enecir.sys
0x97000000 \SystemRoot\system32\drivers\Afc.sys
0x97008000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x9700E000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x97017000 \SystemRoot\system32\DRIVERS\Accelerometer.sys
0x97022000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x9361F000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x90438000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x941EC000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x90450000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x90472000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x9048A000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x904A1000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x904B8000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x9702F000 \SystemRoot\system32\DRIVERS\swenum.sys
0x904C2000 \SystemRoot\system32\DRIVERS\ks.sys
0x904F6000 \SystemRoot\system32\DRIVERS\circlass.sys
0x90504000 \SystemRoot\system32\DRIVERS\umbus.sys
0x90512000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x90556000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x90567000 \SystemRoot\system32\DRIVERS\stwrt.sys
0x97E35000 \SystemRoot\system32\DRIVERS\portcls.sys
0x97E64000 \SystemRoot\system32\DRIVERS\drmk.sys
0x97E7D000 \SystemRoot\system32\drivers\nvhda32v.sys
0x97E9E000 \SystemRoot\system32\DRIVERS\hidir.sys
0x97EAD000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x97EC0000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x97EC7000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x97ED3000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x82820000 \SystemRoot\System32\win32k.sys
0x97EDE000 \SystemRoot\System32\drivers\Dxapi.sys
0x97EE8000 \SystemRoot\System32\Drivers\crashdmp.sys
0x90800000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x97EF5000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x97F06000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x97F1D000 \SystemRoot\System32\Drivers\usbvideo.sys
0x97F41000 \SystemRoot\system32\DRIVERS\monitor.sys
0x82A80000 \SystemRoot\System32\TSDDD.dll
0x82AB0000 \SystemRoot\System32\cdd.dll
0x97F4C000 \SystemRoot\system32\drivers\luafv.sys
0x97F67000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x97F7E000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x97F81000 \SystemRoot\system32\drivers\WudfPf.sys
0x97F9B000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x97FAB000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x97E00000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x97E10000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9DA36000 \SystemRoot\system32\drivers\HTTP.sys
0x9DABB000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9DAD4000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9DAE6000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9DB09000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9DB44000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9DB5F000 \SystemRoot\system32\drivers\peauth.sys
0x9DBF6000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9DA00000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9DA21000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9E826000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9E8DF000 \SystemRoot\System32\DRIVERS\srv.sys
0x9E936000 \??\C:\Users\...~1\AppData\Local\Temp\pxldapow.sys
0x77520000 \Windows\System32\ntdll.dll
0x477B0000 \Windows\System32\smss.exe
0x77760000 \Windows\System32\apisetschema.dll
0x009E0000 \Windows\System32\autochk.exe
0x776F0000 \Windows\System32\shlwapi.dll
0x77480000 \Windows\System32\usp10.dll
0x76830000 \Windows\System32\shell32.dll
0x766D0000 \Windows\System32\ole32.dll
0x76530000 \Windows\System32\setupapi.dll
0x776D0000 \Windows\System32\sechost.dll
0x76460000 \Windows\System32\msctf.dll
0x763D0000 \Windows\System32\clbcatq.dll
0x77680000 \Windows\System32\gdi32.dll
0x77670000 \Windows\System32\lpk.dll
0x76320000 \Windows\System32\msvcrt.dll
0x762C0000 \Windows\System32\difxapi.dll
0x76220000 \Windows\System32\advapi32.dll
0x76190000 \Windows\System32\oleaut32.dll
0x76150000 \Windows\System32\ws2_32.dll
0x760D0000 \Windows\System32\comdlg32.dll
0x76080000 \Windows\System32\Wldap32.dll
0x75F80000 \Windows\System32\wininet.dll
0x75EB0000 \Windows\System32\user32.dll
0x75E90000 \Windows\System32\imm32.dll
0x75E60000 \Windows\System32\imagehlp.dll
0x75DB0000 \Windows\System32\rpcrt4.dll
0x77660000 \Windows\System32\psapi.dll
0x75DA0000 \Windows\System32\normaliz.dll
0x75D90000 \Windows\System32\nsi.dll
0x75C50000 \Windows\System32\urlmon.dll
0x75B70000 \Windows\System32\kernel32.dll
0x75970000 \Windows\System32\iertutil.dll
0x758E0000 \Windows\System32\comctl32.dll
0x758C0000 \Windows\System32\devobj.dll
0x75870000 \Windows\System32\KernelBase.dll
0x75840000 \Windows\System32\wintrust.dll
0x75720000 \Windows\System32\crypt32.dll
0x756F0000 \Windows\System32\cfgmgr32.dll
0x756E0000 \Windows\System32\msasn1.dll
Processes (total 68):
0 System Idle Process
4 System
304 C:\Windows\System32\smss.exe
428 csrss.exe
492 C:\Windows\System32\wininit.exe
500 csrss.exe
540 C:\Windows\System32\services.exe
556 C:\Windows\System32\lsass.exe
564 C:\Windows\System32\lsm.exe
676 C:\Windows\System32\svchost.exe
748 C:\Windows\System32\nvvsvc.exe
788 C:\Windows\System32\svchost.exe
848 C:\Windows\System32\svchost.exe
884 C:\Windows\System32\svchost.exe
928 C:\Windows\System32\svchost.exe
960 C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe
1132 C:\Windows\System32\svchost.exe
1200 C:\Windows\System32\hpservice.exe
1256 C:\Windows\System32\svchost.exe
1352 C:\Windows\System32\winlogon.exe
1392 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
1400 C:\Windows\System32\wlanext.exe
1408 C:\Windows\System32\conhost.exe
1708 C:\Windows\System32\spoolsv.exe
1736 C:\Windows\System32\svchost.exe
1776 C:\Windows\System32\svchost.exe
1860 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
1880 C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\AEstSrv.exe
1908 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1976 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2000 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
108 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
432 C:\Windows\System32\svchost.exe
1048 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
2228 C:\Windows\System32\nvvsvc.exe
2360 unsecapp.exe
2508 WmiPrvSE.exe
2684 C:\Windows\System32\taskhost.exe
2832 C:\Windows\System32\dwm.exe
2952 C:\Windows\explorer.exe
3208 C:\Windows\System32\svchost.exe
3312 C:\Windows\System32\rundll32.exe
3476 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
3488 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
3500 C:\Program Files\IDT\WDM\sttray.exe
3508 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
3516 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3640 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3652 C:\Program Files\Windows Sidebar\sidebar.exe
3876 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
3916 C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
3984 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
2140 C:\Windows\System32\SearchIndexer.exe
2708 C:\Program Files\Windows Media Player\wmpnetwk.exe
236 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
4040 C:\Windows\System32\svchost.exe
4120 C:\Windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe
3816 C:\Program Files\Internet Explorer\iexplore.exe
5008 C:\Program Files\Internet Explorer\iexplore.exe
4460 C:\Windows\System32\SearchProtocolHost.exe
3376 C:\Program Files\Internet Explorer\iexplore.exe
4436 C:\Windows\System32\SearchProtocolHost.exe
2852 C:\Windows\System32\audiodg.exe
4496 C:\Windows\System32\SearchFilterHost.exe
2296 dllhost.exe
1228 dllhost.exe
4092 C:\Users\...\Desktop\MBRCheck.exe
4620 C:\Windows\System32\conhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000037`fac00000 (NTFS)
PhysicalDrive0 Model Number: FUJITSUMHZ2250BHG2, Rev: 8909
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
|
| | #7 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!!
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #8 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! Malwarebytes Code:
ATTFilter Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Datenbank Version: 5247
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
05.12.2010 13:25:16
mbam-log-2010-12-05 (13-25-16).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 252921
Laufzeit: 37 Minute(n), 45 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
|
| | #9 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab!Code:
ATTFilter SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com
Generated 12/05/2010 at 02:49 PM
Application Version : 4.46.1000
Core Rules Database Version : 5954
Trace Rules Database Version: 3766
Scan type : Complete Scan
Total Scan Time : 01:14:44
Memory items scanned : 815
Memory threats detected : 0
Registry items scanned : 10295
Registry threats detected : 0
File items scanned : 117847
File threats detected : 7
Adware.Tracking Cookie
C:\Users\...\AppData\Roaming\Microsoft\Windows\Cookies\...@atwola[1].txt
C:\Users\...\AppData\Roaming\Microsoft\Windows\Cookies\...@doubleclick[1].txt
C:\Users\...\AppData\Roaming\Microsoft\Windows\Cookies\...@content.yieldmanager[1].txt
C:\Users\...\AppData\Roaming\Microsoft\Windows\Cookies\...@ad.yieldmanager[2].txt
C:\Users\...\AppData\Roaming\Microsoft\Windows\Cookies\...@adbrite[2].txt
vidii.hardsextube.com [ C:\Users\...\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\9WHG3GMG ]
www.naiadsystems.com [ C:\Users\...\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\9WHG3GMG ]
|
| | #10 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! Sieht ok aus, da wurden nur Cookies gefunden. Noch Probleme oder weitere Funde in der Zwischenzeit?
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #11 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! nope...soweit nicht. 1) weiß du was über das vshare-plugin für FF oder IE? pc will, dass ich das installiere um fußball zu gucken. gibts da besondere infos zu dem plugin? 2) ich hab avast als antiviren programm... is das in ordnung? oder würdes du ein anderes empfehlen? Geändert von marble (05.12.2010 um 16:37 Uhr) |
| | #12 | ||
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab!Zitat:
Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #13 |
![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! gucken auf www.atdhe.net installieren würd ichs über chip.de |
| | #14 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! Und was für ein Plugin ist das? atdhe kenn ich, war für mich aber unbrauchbar langsam damals. Seitdem (ist schon 2 jahre her oder so) meide ich diese Seite. man ärgert sich nur.
__________________ Logfiles bitte immer in CODE-Tags posten |
![]() |
| Themen zu PC stürzt bei Combofix nach der Hälfte mit Bluescreen ab! |
| antivirenprogramm, bluescreen, combofix, dns, eingestellt, erhalte, firefox, firefox neu, firewalls, formatieren, funktioniert, hoffe, installieren, kino.to, laufen, malwarebytes, min, neu, neuem, programm, seite, starte, stürzt, windows, wirklich, woche |