Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 01.04.2011, 13:38   #16
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Danke, werd ich machen, nur gibt es Problemchen:

EDIT: (Problem mit Zugriff auf Virenscanner gelöst, ist nun inaktiv)

Combofix lädt sich runter, aber als Binary file, nicht als Ausführung exe - trotzdem ok?

Geändert von ronze44 (01.04.2011 um 13:46 Uhr)

Alt 01.04.2011, 14:08   #17
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Hallo Arne, hier der Log.

Hatte vergessen, als Admin zu starten, aber ich gehe davon aus, dass ich das ohnehin bin.
Das Combofix Fenster zeigte auch nach dem Neustart oben "Administrator" an.
Anfangs gabs noch Meckern wegen Skript konnte nicht ausgeführt werden, aber Combofix hat dann trotzdem weitergemacht. War wohl meine Firewall, die zunächst den Netz-Zugriff verweigerte. Der Log:

Combofix Logfile:
Code:
ATTFilter
ComboFix 11-03-31.04 - *** 01.04.2011  14:49:11.1.2 - x86
ausgeführt von:: c:\users\***\Desktop\Cofi.exe.exe
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\hpeB6C0.dll
c:\users\***\AppData\Roaming\Desktopicon
c:\users\***\AppData\Roaming\Desktopicon\config.ini
c:\users\***\AppData\Roaming\EurekaLog
c:\windows\Fonts\Guitar Amp.exe
c:\windows\system32\Inetde.dll
t:\temp\catchme.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-03-01 bis 2011-04-01  ))))))))))))))))))))))))))))))
.
.
2011-04-01 12:55 . 2011-04-01 12:55	--------	d-----w-	c:\users\***\AppData\Local\temp
2011-04-01 12:55 . 2011-04-01 12:55	--------	d-----w-	c:\users\Default\AppData\Local\temp
2011-03-31 21:57 . 2004-03-08 22:00	662288	----a-w-	c:\windows\system32\MSCOMCT2.OCX
2011-03-31 21:57 . 2001-10-28 14:42	116224	----a-w-	c:\windows\system32\pdfcmnnt.dll
2011-03-31 21:57 . 1998-06-23 22:00	137000	----a-w-	c:\windows\system32\MSMAPI32.OCX
2011-03-31 21:57 . 2011-03-31 21:57	--------	d-----w-	c:\program files\PDFCreator
2011-03-31 21:57 . 1998-07-06 15:55	64512	----a-w-	c:\windows\system32\MSCC2DE.DLL
2011-03-31 21:57 . 1998-07-05 22:00	23552	----a-w-	c:\windows\system32\MSMPIDE.DLL
2011-03-31 20:06 . 2011-03-31 20:06	28752	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys
2011-03-31 20:05 . 2011-03-31 20:05	--------	d-----w-	C:\_OTL
2011-03-31 18:41 . 2011-03-31 18:41	--------	d-----w-	c:\users\***\AppData\Roaming\www.shadowexplorer.com
2011-03-31 18:41 . 2011-03-31 18:41	--------	d-----w-	c:\program files\ShadowExplorer
2011-03-31 18:32 . 2011-03-14 19:05	6792528	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\mpengine.dll
2011-03-27 23:04 . 2011-03-27 23:04	--------	d-----w-	c:\users\***\AppData\Local\{3C914691-E3BD-430B-A3F4-1B460BCD316F}
2011-03-27 19:55 . 2011-03-27 19:55	--------	d-----w-	c:\users\***\AppData\Local\MAGIX
2011-03-27 19:52 . 2011-03-27 19:52	--------	d-----w-	c:\program files\Common Files\MAGIX Services
2011-03-27 18:28 . 2011-03-28 21:41	--------	d-----w-	c:\program files\Sonne Screen Video Capture
2011-03-27 12:13 . 2011-03-27 12:48	--------	d-----w-	c:\users\***\AppData\Roaming\Web Page Maker
2011-03-27 12:13 . 2011-03-27 12:13	--------	d-----w-	c:\programdata\Web Page Maker
2011-03-27 10:45 . 2011-03-27 19:52	--------	d-----w-	c:\program files\MAGIX
2011-03-26 15:04 . 2011-03-26 15:04	--------	d-----w-	c:\program files\NetObjects
2011-03-26 14:15 . 2011-03-27 19:58	--------	d-----w-	c:\programdata\MAGIX
2011-03-26 14:15 . 2011-03-27 19:55	--------	d-----w-	c:\users\***\AppData\Local\Xara
2011-03-26 14:14 . 2011-03-26 14:14	--------	d-----w-	c:\programdata\Xara
2011-03-26 14:14 . 2011-03-26 14:14	--------	d-----w-	c:\program files\Xara
2011-03-26 14:10 . 2011-03-27 19:58	--------	d-----w-	c:\users\***\AppData\Roaming\MAGIX
2011-03-26 13:52 . 2004-03-08 23:00	609824	----a-w-	c:\windows\system32\Comctl32.ocx
2011-03-26 13:52 . 2000-07-16 15:20	185856	----a-w-	c:\windows\system32\Bmp2Jpeg.dll
2011-03-26 00:45 . 2011-03-29 12:24	--------	d-----w-	c:\users\***\VirtualBox VMs
2011-03-26 00:37 . 2011-02-17 17:06	160560	----a-w-	c:\windows\system32\drivers\VBoxDrv.sys
2011-03-26 00:37 . 2011-02-17 17:06	44784	----a-w-	c:\windows\system32\drivers\VBoxUSBMon.sys
2011-03-26 00:37 . 2011-03-31 00:57	--------	dc----w-	c:\windows\system32\DRVSTORE
2011-03-25 23:45 . 2011-03-29 01:46	--------	d-----w-	c:\program files\Inkscape
2011-03-25 22:10 . 2011-01-30 13:29	439632	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-03-25 00:06 . 2011-03-29 01:45	--------	d-----w-	c:\program files\Oracle
2011-03-24 23:55 . 2011-03-25 23:51	--------	d-----w-	c:\users\***\AppData\Roaming\inkscape
2011-03-23 20:37 . 2011-03-23 20:37	--------	d-----w-	c:\program files\Macromedia
2011-03-23 19:23 . 2011-03-23 19:23	--------	d-----w-	c:\programdata\Nitro PDF
2011-03-23 19:23 . 2011-03-23 19:23	--------	d-----w-	c:\program files\Nitro PDF
2011-03-23 19:23 . 2011-03-23 19:23	--------	d-----w-	c:\program files\Common Files\Nitro PDF
2011-03-23 17:51 . 2011-03-23 17:51	--------	d-----w-	c:\users\***\AppData\Roaming\Nitro PDF
2011-03-23 17:36 . 2011-03-23 19:23	--------	d-----w-	c:\program files\Common Files\BCL Technologies
2011-03-23 17:35 . 2011-03-23 17:35	--------	d-----w-	c:\users\***\AppData\Local\Downloaded Installations
2011-03-23 00:16 . 2011-03-25 01:40	--------	d-----w-	c:\users\***\HH Seiten
2011-03-22 23:01 . 2011-03-22 23:01	--------	d-----w-	c:\users\***\AppData\Roaming\AdobeUM
2011-03-22 13:40 . 2011-03-22 13:40	--------	d-----w-	c:\program files\Windows7FirewallControl
2011-03-21 23:20 . 2000-04-03 18:05	118784	----a-w-	c:\windows\system32\msstdfmt.dll
2011-03-21 23:20 . 1999-07-14 12:07	6656	----a-w-	c:\windows\system32\stdftde.dll
2011-03-21 23:20 . 1998-07-05 22:00	22528	----a-w-	c:\windows\system32\Tabctde.dll
2011-03-21 23:20 . 2011-03-21 23:21	--------	d-----w-	c:\program files\Biet-O-Matic
2011-03-21 23:02 . 2006-05-31 14:35	190464	----a-w-	c:\windows\system32\sevImLib.dll
2011-03-21 23:02 . 2005-11-27 19:07	262144	----a-w-	c:\windows\system32\CoolXPFrame.ocx
2011-03-21 23:02 . 2005-11-27 19:06	360448	----a-w-	c:\windows\system32\CoolXPLabel.ocx
2011-03-21 23:02 . 2008-04-21 11:58	231424	----a-w-	c:\windows\system32\sevXPCtl.ocx
2011-03-21 23:02 . 2006-09-29 13:11	929792	----a-w-	c:\windows\system32\CoolXPTabStrip.ocx
2011-03-21 23:02 . 2004-03-17 08:19	86016	----a-w-	c:\windows\system32\sevGrip.ocx
2011-03-21 23:02 . 2008-04-24 07:02	361984	----a-w-	c:\windows\system32\sevDataGrid2.ocx
2011-03-21 23:02 . 2008-04-17 13:14	289280	----a-w-	c:\windows\system32\sevEin20.ocx
2011-03-21 23:02 . 2005-08-30 07:51	126976	----a-w-	c:\windows\system32\sevTrayIcon.ocx
2011-03-21 23:02 . 2008-04-17 11:00	139264	----a-w-	c:\windows\system32\sevCmd3.ocx
2011-03-21 23:02 . 2007-11-07 06:55	113664	----a-w-	c:\windows\system32\sevClb20.ocx
2011-03-21 23:00 . 2011-03-29 01:46	--------	d-----w-	c:\windows\uninstall
2011-03-21 22:42 . 2011-03-29 01:46	--------	d-----w-	c:\users\***\AppData\Roaming\BayHunter
2011-03-21 22:42 . 2011-03-29 01:46	--------	d-----w-	c:\program files\BayHunter
2011-03-21 22:41 . 2011-03-25 22:03	--------	d-----w-	c:\users\***\AppData\Roaming\GetRightToGo
2011-03-20 22:54 . 2011-03-20 22:54	--------	d-----w-	c:\program files\Toon Boom Animation
2011-03-20 21:13 . 2011-03-25 22:03	--------	d-----w-	c:\program files\Microangelo
2011-03-20 21:01 . 2011-03-30 21:21	--------	d-----w-	c:\users\***\Install
2011-03-19 03:14 . 2011-03-29 01:45	--------	d-----w-	C:\Plugins
2011-03-19 03:13 . 2011-03-19 03:13	--------	d-----w-	c:\program files\Jasc Software Inc
2011-03-19 02:53 . 2011-03-19 02:53	--------	d-----w-	c:\program files\PhotoBrush
2011-03-18 23:26 . 2008-06-06 06:59	4887336	----a-w-	c:\windows\system32\WacomTablet.cpl
2011-03-18 23:26 . 2007-02-15 15:11	11440	----a-w-	c:\windows\system32\drivers\WacomVKHid.sys
2011-03-18 23:25 . 2008-06-06 07:08	3406120	----a-w-	c:\windows\system32\Wacom_Tablet.exe
2011-03-18 23:25 . 2008-06-06 07:00	159528	----a-w-	c:\windows\system32\Wacom_Tablet.dll
2011-03-18 23:13 . 2011-03-31 21:02	--------	d-----w-	c:\users\***\pap_projects
2011-03-18 23:12 . 2011-03-25 22:03	--------	d-----w-	c:\program files\PAP40
2011-03-15 10:45 . 2011-03-15 10:45	--------	d-----w-	c:\users\***\AppData\Roaming\HighAndes
2011-03-15 10:45 . 2011-03-15 10:45	--------	d-----w-	c:\users\***\AppData\Local\HighAndes
2011-03-15 10:45 . 2011-03-15 10:45	--------	d-----w-	c:\programdata\HighAndes
2011-03-15 03:03 . 2009-06-07 12:20	61440	----a-w-	c:\windows\system32\NlsSrv32.exe
2011-03-15 03:02 . 2011-03-15 03:03	--------	d-----w-	c:\users\***\AppData\Roaming\Blue Cat Audio
2011-03-15 03:02 . 2011-03-15 03:02	--------	d-----w-	c:\program files\HighAndes
2011-03-13 18:43 . 2011-03-13 18:43	--------	d-----w-	c:\program files\Line6
2011-03-12 15:00 . 2011-03-12 15:00	--------	d-----w-	c:\windows\system32\SPReview
2011-03-12 15:00 . 2011-03-12 15:00	--------	d-----w-	c:\windows\system32\EventProviders
2011-03-12 14:56 . 2010-11-20 12:30	3966848	----a-w-	c:\windows\system32\ntkrnlpa.exe
2011-03-12 14:55 . 2010-11-20 12:21	1227776	----a-w-	c:\windows\system32\wdc.dll
2011-03-12 14:54 . 2010-11-20 12:20	68096	----a-w-	c:\windows\system32\napdsnap.dll
2011-03-12 14:53 . 2010-11-20 12:18	323072	----a-w-	c:\windows\system32\drvstore.dll
2011-03-12 14:53 . 2010-11-20 12:18	257024	----a-w-	c:\windows\system32\dpx.dll
2011-03-11 23:01 . 2011-03-11 23:02	--------	d-----w-	c:\program files\VirtualDub-1.9.11
2011-03-11 00:58 . 2011-03-31 20:09	--------	d-----r-	c:\users\***\Dropbox
2011-03-11 00:52 . 2011-03-31 20:09	--------	d-----w-	c:\users\***\AppData\Roaming\Dropbox
2011-03-09 11:44 . 2010-12-23 05:54	850944	----a-w-	c:\windows\system32\sbe.dll
2011-03-09 11:44 . 2010-12-23 05:54	642048	----a-w-	c:\windows\system32\CPFilters.dll
2011-03-09 11:44 . 2010-12-23 05:54	534528	----a-w-	c:\windows\system32\EncDec.dll
2011-03-09 11:44 . 2010-12-23 05:50	199680	----a-w-	c:\windows\system32\mpg2splt.ax
2011-03-08 14:04 . 2011-03-08 14:04	--------	d-----w-	c:\program files\Lame For Audacity
2011-03-06 23:17 . 2011-03-06 23:17	--------	d-----w-	c:\users\***\AppData\Roaming\DVDVideoSoft
2011-03-06 03:17 . 2011-03-06 03:17	--------	d-----w-	c:\programdata\NCH Swift Sound
2011-03-06 01:49 . 2011-03-06 01:49	--------	d-----w-	c:\users\***\AppData\Roaming\Thinstall
2011-03-06 01:49 . 2011-03-06 01:49	--------	d-----w-	c:\users\***\AppData\Local\Thinstall
2011-03-06 01:05 . 2011-03-26 12:07	--------	d-----w-	c:\users\***\AppData\Roaming\NCH Software
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-14 19:05 . 2010-10-15 00:57	6792528	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-12 15:07 . 2009-07-14 02:05	152576	----a-w-	c:\windows\system32\msclmd.dll
2011-01-30 00:52 . 2011-01-30 00:52	218688	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys
2011-01-13 09:41 . 2011-01-30 13:03	5890896	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-01-07 07:45 . 2011-02-09 10:18	34304	----a-w-	c:\windows\system32\atmlib.dll
2011-01-07 06:01 . 2011-02-09 11:03	1638912	----a-w-	c:\windows\system32\mshtml.tlb
2011-01-07 05:43 . 2011-02-09 10:18	294400	----a-w-	c:\windows\system32\atmfd.dll
2011-01-05 05:55 . 2011-02-09 10:22	428032	----a-w-	c:\windows\system32\vbscript.dll
2011-01-05 03:51 . 2011-02-09 10:22	2330624	----a-w-	c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
2010-03-17 14:45	2355224	----a-w-	c:\program files\Winload\tbWinl.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{40C3CC16-7269-4B32-9531-17F2950FB06F}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36	94208	----a-w-	c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36	94208	----a-w-	c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36	94208	----a-w-	c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\WebDavOverlayUpload]
@="{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}"
[HKEY_CLASSES_ROOT\CLSID\{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}]
2010-10-27 11:13	284304	----a-w-	c:\windows\System32\WebDAV.ShellExtension.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-03 15028104]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Buyertools Reminder"="c:\program files\Buyertools Reminder\Reminder.exe" [2008-12-22 6607872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504]
"ACFanControl"="c:\program files\ACFanControl\ACFanControl.exe" [2010-10-04 249856]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Windows7FirewallControl"="c:\program files\Windows7FirewallControl\Windows7FirewallControl.exe" [2010-11-01 802816]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-3-31 23360040]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [2010-10-12 4142448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll" [2010-03-24 511344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MIDI3"=timiditydrv.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages	REG_MULTI_SZ   	kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=c:\windows\pss\TabUserW.exe.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^***^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Impulse Now.lnk]
path=c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk
backup=c:\windows\pss\Impulse Now.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePower Management]
2009-08-19 14:15	487424	----a-w-	c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-12-03 10:06	140568	----a-w-	c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-12-03 10:09	911184	----a-w-	c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07	932288	----a-r-	c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47	35760	----a-w-	c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Check Mail]
2007-04-18 21:37	2158080	----a-w-	c:\program files\CheckMail V2\CK_Mail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Koma-Mail]
2010-03-12 14:14	2836992	----a-w-	c:\program files\KomaMail\Koma_Mail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2009-09-15 13:24	883208	----a-w-	c:\program files\Launch Manager\LManager.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseExtender]
2010-09-23 01:26	455168	----a-w-	c:\users\***\Desktop\MouseExtender.1.9.7.2\MouseExtender.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38	421888	----a-w-	c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
2010-07-11 09:42	2199040	----a-w-	c:\program files\Rainlendar2\Rainlendar2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr]
2009-10-10 06:51	614400	----a-w-	c:\windows\Samsung\PanelMgr\SSMMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2009-11-20 08:17	434176	----a-w-	c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 10:44	248552	----a-w-	c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher]
2007-10-28 10:35	425984	----a-w-	c:\program files\Switcher\Switcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-12-03 10:06	2622104	----a-w-	c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" -hide -runkey
.
R1 MpKslda63107b;MpKslda63107b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{66193AB5-5D42-498E-A3C9-EF5CAC0D8D2D}\MpKslda63107b.sys [x]
R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-20 73728]
R3 EchoIndigo;echondgo;c:\windows\system32\DRIVERS\echondgo.sys [2009-12-08 132544]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-05 13224]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [2008-10-21 86824]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 15016]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 114600]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 108328]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 26024]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [2008-10-21 104616]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [2008-10-21 109736]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2007-10-24 23288]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 UDST7000BDA;TerraTec H7 service;c:\windows\system32\DRIVERS\TerraTecUsbBda.sys [2010-08-17 782840]
R3 UDST7000HID;TerraTec H7/S7 HID service;c:\windows\system32\DRIVERS\TerraTecUsbHid.sys [2010-08-04 22136]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-09-15 16240]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-08 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 RRamdisk;Ramdisk Driver;c:\windows\system32\DRIVERS\rramdisk.sys [2009-04-30 12288]
S1 cbfs3;cbfs3;c:\windows\system32\drivers\cbfs3.sys [2010-05-15 265800]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-30 218688]
S1 MpKsl66cf2e2f;MpKsl66cf2e2f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys [2011-03-31 28752]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-03-19 2964312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 136176]
S2 MCSWASVR;Mediencenter Service;c:\program files\Telekom\Mediencenter\WebDAV.AdminService.exe [2010-07-09 16016]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [2009-06-07 61440]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
S2 sesvc;ShadowExplorer Service;c:\program files\ShadowExplorer\sesvc.exe [2011-01-02 9216]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-11-30 5120]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-09-21 4867952]
S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-06-06 3406120]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-09-21 414576]
S2 Windows7FirewallService;Windows7FirewallService;c:\program files\Windows7FirewallControl\Windows7FirewallService.exe [2010-11-01 401408]
S3 echondgo;Indigo Service;c:\windows\system32\drivers\echondgo.sys [2009-12-08 132544]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30]
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://google.de/
uInternet Settings,ProxyOverride = *.local
IE: add to &BOM - c:\\PROGRA~1\\BIET-O~1\\\\AddToBOM.hta
IE: Free YouTube Download - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: {{27914077-B4D6-4A0E-9763-76B6E9DD9A81} - c:\program files\Buyertools Reminder\ReminderIE.exe
Trusted Zone: ***-lieblein.de
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.de
FF - prefs.js: keyword.URL - hxxp://go.gmx.net/tb/mff_keyurl_search/?su=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - c:\program files\Mozilla Firefox\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Dictionary Switcher: dictionary-switcher@design-noir.de - %profile%\extensions\dictionary-switcher@design-noir.de
FF - Ext: Dictionary (EN/DE): dictlookup@arnhold.com - %profile%\extensions\dictlookup@arnhold.com
FF - Ext: BabelFish: {ca0849e8-2c76-42ae-9abe-34e14d337acf} - %profile%\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf}
FF - Ext: German Dictionary: de-DE@dictionaries.addons.mozilla.org - %profile%\extensions\de-DE@dictionaries.addons.mozilla.org
FF - Ext: United States English Spellchecker: en-US@dictionaries.addons.mozilla.org - %profile%\extensions\en-US@dictionaries.addons.mozilla.org
FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - %profile%\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}
FF - Ext: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - %profile%\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Vacuum Places Improved: VacuumPlacesImproved@lultimouomo-gmail.com - %profile%\extensions\VacuumPlacesImproved@lultimouomo-gmail.com
FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com
FF - Ext: Lazarus: Form Recovery: lazarus@interclue.com - %profile%\extensions\lazarus@interclue.com
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Fasterfox Lite: FasterFox_Lite@BigRedBrent - %profile%\extensions\FasterFox_Lite@BigRedBrent
FF - Ext: WebMail Notifier: {37fa1426-b82d-11db-8314-0800200c9a66} - %profile%\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
FF - Ext: Biet-O-Matic Firefox Erweiterung: {B0D70E72-2FC1-4b9f-A3D4-5921C854D906} - %profile%\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906}
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
MSConfigStartUp-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
MSConfigStartUp-vsc32cnf - c:\program files\Roland\VSC32\vsc32cnf.exe
MSConfigStartUp-vscvol - c:\program files\Roland\VSC32\vscvol.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3FDF5132-F69F-04D1-7D21-68F96726F127}*]
"maffhilkingdbkajjfklhanbdn"=hex:6b,61,6d,6c,67,67,6b,6d,61,6b,69,70,62,69,63,
   70,66,6d,64,63,61,6f,00,77
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2272)
c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\CbFsNetRdr3.dll
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\Tablet\Pen\Pen_TouchUser.exe
c:\windows\system32\taskhost.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program files\Tablet\Pen\Pen_TabletUser.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WTablet\Wacom_TabletUser.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-04-01  15:00:48 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-04-01 13:00
.
Vor Suchlauf: 17 Verzeichnis(se), 72.745.836.544 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 72.300.859.392 Bytes frei
.
- - End Of File - - FECC1F8B8D47BF958290E5CF6D7FB27A
         
--- --- ---
__________________


Alt 01.04.2011, 14:44   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:
ATTFilter
Regnull::
[HKEY_USERS\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3FDF5132-F69F-04D1-7D21-68F96726F127}*]
         
3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.



6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________
__________________

Alt 01.04.2011, 20:37   #19
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



und wieder bin ich besorgt, alles richtig gemacht zu haben, hoffe man kann das erkenne, falls nicht.
Habe ja diese WIN Firewall Control, die hab ich nicht aus gekriegt.
Von daher hat diese sich wieder gemeldet, als nach dem Scan pev.cfxxe ins Netz wollte.
Denke aber dass das Combofix gewesen sein müsste und dieses hat ja nach meiner Erlaubnis ins Netz zu gehen auch weiter gearbeitet. Ergebnis:

Combofix Logfile:
Code:
ATTFilter
ComboFix 11-03-31.04 - *** 01.04.2011  21:20:58.2.2 - x86
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.2973.1992 [GMT 2:00]
ausgeführt von:: c:\users\***\Desktop\Cofi.exe.exe
Benutzte Befehlsschalter :: c:\users\***\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
t:\temp\catchme.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-03-01 bis 2011-04-01  ))))))))))))))))))))))))))))))
.
.
2011-04-01 19:26 . 2011-04-01 19:26	--------	d-----w-	c:\users\***\AppData\Local\temp
2011-04-01 19:26 . 2011-04-01 19:26	--------	d-----w-	c:\users\Default\AppData\Local\temp
2011-04-01 19:10 . 2011-04-01 19:10	28752	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5E64436B-C2AC-415B-A79B-85CA355D720B}\MpKslf60824b1.sys
2011-04-01 19:10 . 2011-03-14 19:05	6792528	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5E64436B-C2AC-415B-A79B-85CA355D720B}\mpengine.dll
2011-03-31 21:57 . 2004-03-08 22:00	662288	----a-w-	c:\windows\system32\MSCOMCT2.OCX
2011-03-31 21:57 . 2001-10-28 14:42	116224	----a-w-	c:\windows\system32\pdfcmnnt.dll
2011-03-31 21:57 . 1998-06-23 22:00	137000	----a-w-	c:\windows\system32\MSMAPI32.OCX
2011-03-31 21:57 . 2011-03-31 21:57	--------	d-----w-	c:\program files\PDFCreator
2011-03-31 21:57 . 1998-07-06 15:55	64512	----a-w-	c:\windows\system32\MSCC2DE.DLL
2011-03-31 21:57 . 1998-07-05 22:00	23552	----a-w-	c:\windows\system32\MSMPIDE.DLL
2011-03-31 20:05 . 2011-03-31 20:05	--------	d-----w-	C:\_OTL
2011-03-31 18:41 . 2011-03-31 18:41	--------	d-----w-	c:\users\***\AppData\Roaming\www.shadowexplorer.com
2011-03-31 18:41 . 2011-03-31 18:41	--------	d-----w-	c:\program files\ShadowExplorer
2011-03-27 23:04 . 2011-03-27 23:04	--------	d-----w-	c:\users\***\AppData\Local\{3C914691-E3BD-430B-A3F4-1B460BCD316F}
2011-03-27 19:55 . 2011-03-27 19:55	--------	d-----w-	c:\users\***\AppData\Local\MAGIX
2011-03-27 19:52 . 2011-03-27 19:52	--------	d-----w-	c:\program files\Common Files\MAGIX Services
2011-03-27 18:28 . 2011-03-28 21:41	--------	d-----w-	c:\program files\Sonne Screen Video Capture
2011-03-27 12:13 . 2011-03-27 12:48	--------	d-----w-	c:\users\***\AppData\Roaming\Web Page Maker
2011-03-27 12:13 . 2011-03-27 12:13	--------	d-----w-	c:\programdata\Web Page Maker
2011-03-27 10:45 . 2011-03-27 19:52	--------	d-----w-	c:\program files\MAGIX
2011-03-26 15:04 . 2011-03-26 15:04	--------	d-----w-	c:\program files\NetObjects
2011-03-26 14:15 . 2011-03-27 19:58	--------	d-----w-	c:\programdata\MAGIX
2011-03-26 14:15 . 2011-03-27 19:55	--------	d-----w-	c:\users\***\AppData\Local\Xara
2011-03-26 14:14 . 2011-03-26 14:14	--------	d-----w-	c:\programdata\Xara
2011-03-26 14:14 . 2011-03-26 14:14	--------	d-----w-	c:\program files\Xara
2011-03-26 14:10 . 2011-03-27 19:58	--------	d-----w-	c:\users\***\AppData\Roaming\MAGIX
2011-03-26 13:52 . 2004-03-08 23:00	609824	----a-w-	c:\windows\system32\Comctl32.ocx
2011-03-26 13:52 . 2000-07-16 15:20	185856	----a-w-	c:\windows\system32\Bmp2Jpeg.dll
2011-03-26 00:45 . 2011-03-29 12:24	--------	d-----w-	c:\users\***\VirtualBox VMs
2011-03-26 00:37 . 2011-02-17 17:06	160560	----a-w-	c:\windows\system32\drivers\VBoxDrv.sys
2011-03-26 00:37 . 2011-02-17 17:06	44784	----a-w-	c:\windows\system32\drivers\VBoxUSBMon.sys
2011-03-26 00:37 . 2011-03-31 00:57	--------	dc----w-	c:\windows\system32\DRVSTORE
2011-03-25 23:45 . 2011-03-29 01:46	--------	d-----w-	c:\program files\Inkscape
2011-03-25 22:10 . 2011-01-30 13:29	439632	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-03-25 00:06 . 2011-03-29 01:45	--------	d-----w-	c:\program files\Oracle
2011-03-24 23:55 . 2011-03-25 23:51	--------	d-----w-	c:\users\***\AppData\Roaming\inkscape
2011-03-23 20:37 . 2011-03-23 20:37	--------	d-----w-	c:\program files\Macromedia
2011-03-23 19:23 . 2011-03-23 19:23	--------	d-----w-	c:\programdata\Nitro PDF
2011-03-23 19:23 . 2011-03-23 19:23	--------	d-----w-	c:\program files\Nitro PDF
2011-03-23 19:23 . 2011-03-23 19:23	--------	d-----w-	c:\program files\Common Files\Nitro PDF
2011-03-23 17:51 . 2011-03-23 17:51	--------	d-----w-	c:\users\***\AppData\Roaming\Nitro PDF
2011-03-23 17:36 . 2011-03-23 19:23	--------	d-----w-	c:\program files\Common Files\BCL Technologies
2011-03-23 17:35 . 2011-03-23 17:35	--------	d-----w-	c:\users\***\AppData\Local\Downloaded Installations
2011-03-23 00:16 . 2011-03-25 01:40	--------	d-----w-	c:\users\***\HH Seiten
2011-03-22 23:01 . 2011-03-22 23:01	--------	d-----w-	c:\users\***\AppData\Roaming\AdobeUM
2011-03-22 13:40 . 2011-03-22 13:40	--------	d-----w-	c:\program files\Windows7FirewallControl
2011-03-21 23:20 . 2000-04-03 18:05	118784	----a-w-	c:\windows\system32\msstdfmt.dll
2011-03-21 23:20 . 1999-07-14 12:07	6656	----a-w-	c:\windows\system32\stdftde.dll
2011-03-21 23:20 . 1998-07-05 22:00	22528	----a-w-	c:\windows\system32\Tabctde.dll
2011-03-21 23:20 . 2011-03-21 23:21	--------	d-----w-	c:\program files\Biet-O-Matic
2011-03-21 23:02 . 2006-05-31 14:35	190464	----a-w-	c:\windows\system32\sevImLib.dll
2011-03-21 23:02 . 2005-11-27 19:07	262144	----a-w-	c:\windows\system32\CoolXPFrame.ocx
2011-03-21 23:02 . 2005-11-27 19:06	360448	----a-w-	c:\windows\system32\CoolXPLabel.ocx
2011-03-21 23:02 . 2008-04-21 11:58	231424	----a-w-	c:\windows\system32\sevXPCtl.ocx
2011-03-21 23:02 . 2006-09-29 13:11	929792	----a-w-	c:\windows\system32\CoolXPTabStrip.ocx
2011-03-21 23:02 . 2004-03-17 08:19	86016	----a-w-	c:\windows\system32\sevGrip.ocx
2011-03-21 23:02 . 2008-04-24 07:02	361984	----a-w-	c:\windows\system32\sevDataGrid2.ocx
2011-03-21 23:02 . 2008-04-17 13:14	289280	----a-w-	c:\windows\system32\sevEin20.ocx
2011-03-21 23:02 . 2005-08-30 07:51	126976	----a-w-	c:\windows\system32\sevTrayIcon.ocx
2011-03-21 23:02 . 2008-04-17 11:00	139264	----a-w-	c:\windows\system32\sevCmd3.ocx
2011-03-21 23:02 . 2007-11-07 06:55	113664	----a-w-	c:\windows\system32\sevClb20.ocx
2011-03-21 23:00 . 2011-03-29 01:46	--------	d-----w-	c:\windows\uninstall
2011-03-21 22:42 . 2011-03-29 01:46	--------	d-----w-	c:\users\***\AppData\Roaming\BayHunter
2011-03-21 22:42 . 2011-03-29 01:46	--------	d-----w-	c:\program files\BayHunter
2011-03-21 22:41 . 2011-03-25 22:03	--------	d-----w-	c:\users\***\AppData\Roaming\GetRightToGo
2011-03-20 22:54 . 2011-03-20 22:54	--------	d-----w-	c:\program files\Toon Boom Animation
2011-03-20 21:13 . 2011-03-25 22:03	--------	d-----w-	c:\program files\Microangelo
2011-03-20 21:01 . 2011-03-30 21:21	--------	d-----w-	c:\users\***\Install
2011-03-19 03:14 . 2011-03-29 01:45	--------	d-----w-	C:\Plugins
2011-03-19 03:13 . 2011-03-19 03:13	--------	d-----w-	c:\program files\Jasc Software Inc
2011-03-19 02:53 . 2011-03-19 02:53	--------	d-----w-	c:\program files\PhotoBrush
2011-03-18 23:26 . 2008-06-06 06:59	4887336	----a-w-	c:\windows\system32\WacomTablet.cpl
2011-03-18 23:26 . 2007-02-15 15:11	11440	----a-w-	c:\windows\system32\drivers\WacomVKHid.sys
2011-03-18 23:25 . 2008-06-06 07:08	3406120	----a-w-	c:\windows\system32\Wacom_Tablet.exe
2011-03-18 23:25 . 2008-06-06 07:00	159528	----a-w-	c:\windows\system32\Wacom_Tablet.dll
2011-03-18 23:13 . 2011-03-31 21:02	--------	d-----w-	c:\users\***\pap_projects
2011-03-18 23:12 . 2011-03-25 22:03	--------	d-----w-	c:\program files\PAP40
2011-03-15 10:45 . 2011-03-15 10:45	--------	d-----w-	c:\users\***\AppData\Roaming\HighAndes
2011-03-15 10:45 . 2011-03-15 10:45	--------	d-----w-	c:\users\***\AppData\Local\HighAndes
2011-03-15 10:45 . 2011-03-15 10:45	--------	d-----w-	c:\programdata\HighAndes
2011-03-15 03:03 . 2009-06-07 12:20	61440	----a-w-	c:\windows\system32\NlsSrv32.exe
2011-03-15 03:02 . 2011-03-15 03:03	--------	d-----w-	c:\users\***\AppData\Roaming\Blue Cat Audio
2011-03-15 03:02 . 2011-03-15 03:02	--------	d-----w-	c:\program files\HighAndes
2011-03-13 18:43 . 2011-03-13 18:43	--------	d-----w-	c:\program files\Line6
2011-03-12 15:00 . 2011-03-12 15:00	--------	d-----w-	c:\windows\system32\SPReview
2011-03-12 15:00 . 2011-03-12 15:00	--------	d-----w-	c:\windows\system32\EventProviders
2011-03-12 14:56 . 2010-11-20 12:30	3966848	----a-w-	c:\windows\system32\ntkrnlpa.exe
2011-03-12 14:55 . 2010-11-20 12:21	1227776	----a-w-	c:\windows\system32\wdc.dll
2011-03-12 14:54 . 2010-11-20 12:20	68096	----a-w-	c:\windows\system32\napdsnap.dll
2011-03-12 14:53 . 2010-11-20 12:18	323072	----a-w-	c:\windows\system32\drvstore.dll
2011-03-12 14:53 . 2010-11-20 12:18	257024	----a-w-	c:\windows\system32\dpx.dll
2011-03-11 23:01 . 2011-03-11 23:02	--------	d-----w-	c:\program files\VirtualDub-1.9.11
2011-03-11 00:58 . 2011-03-31 20:09	--------	d-----r-	c:\users\***\Dropbox
2011-03-11 00:52 . 2011-03-31 20:09	--------	d-----w-	c:\users\***\AppData\Roaming\Dropbox
2011-03-09 11:44 . 2010-12-23 05:54	850944	----a-w-	c:\windows\system32\sbe.dll
2011-03-09 11:44 . 2010-12-23 05:54	642048	----a-w-	c:\windows\system32\CPFilters.dll
2011-03-09 11:44 . 2010-12-23 05:54	534528	----a-w-	c:\windows\system32\EncDec.dll
2011-03-09 11:44 . 2010-12-23 05:50	199680	----a-w-	c:\windows\system32\mpg2splt.ax
2011-03-08 14:04 . 2011-03-08 14:04	--------	d-----w-	c:\program files\Lame For Audacity
2011-03-06 23:17 . 2011-03-06 23:17	--------	d-----w-	c:\users\***\AppData\Roaming\DVDVideoSoft
2011-03-06 03:17 . 2011-03-06 03:17	--------	d-----w-	c:\programdata\NCH Swift Sound
2011-03-06 01:49 . 2011-03-06 01:49	--------	d-----w-	c:\users\***\AppData\Roaming\Thinstall
2011-03-06 01:49 . 2011-03-06 01:49	--------	d-----w-	c:\users\***\AppData\Local\Thinstall
2011-03-06 01:05 . 2011-03-26 12:07	--------	d-----w-	c:\users\***\AppData\Roaming\NCH Software
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-14 19:05 . 2010-10-15 00:57	6792528	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-12 15:07 . 2009-07-14 02:05	152576	----a-w-	c:\windows\system32\msclmd.dll
2011-01-30 00:52 . 2011-01-30 00:52	218688	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys
2011-01-13 09:41 . 2011-01-30 13:03	5890896	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-01-07 07:45 . 2011-02-09 10:18	34304	----a-w-	c:\windows\system32\atmlib.dll
2011-01-07 06:01 . 2011-02-09 11:03	1638912	----a-w-	c:\windows\system32\mshtml.tlb
2011-01-07 05:43 . 2011-02-09 10:18	294400	----a-w-	c:\windows\system32\atmfd.dll
2011-01-05 05:55 . 2011-02-09 10:22	428032	----a-w-	c:\windows\system32\vbscript.dll
2011-01-05 03:51 . 2011-02-09 10:22	2330624	----a-w-	c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
2010-03-17 14:45	2355224	----a-w-	c:\program files\Winload\tbWinl.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{40C3CC16-7269-4B32-9531-17F2950FB06F}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36	94208	----a-w-	c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36	94208	----a-w-	c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36	94208	----a-w-	c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\WebDavOverlayUpload]
@="{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}"
[HKEY_CLASSES_ROOT\CLSID\{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}]
2010-10-27 11:13	284304	----a-w-	c:\windows\System32\WebDAV.ShellExtension.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-03 15028104]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Buyertools Reminder"="c:\program files\Buyertools Reminder\Reminder.exe" [2008-12-22 6607872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504]
"ACFanControl"="c:\program files\ACFanControl\ACFanControl.exe" [2010-10-04 249856]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Windows7FirewallControl"="c:\program files\Windows7FirewallControl\Windows7FirewallControl.exe" [2010-11-01 802816]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-3-31 23360040]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [2010-10-12 4142448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll" [2010-03-24 511344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MIDI3"=timiditydrv.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages	REG_MULTI_SZ   	kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=c:\windows\pss\TabUserW.exe.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^***^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Impulse Now.lnk]
path=c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk
backup=c:\windows\pss\Impulse Now.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePower Management]
2009-08-19 14:15	487424	----a-w-	c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-12-03 10:06	140568	----a-w-	c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-12-03 10:09	911184	----a-w-	c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07	932288	----a-r-	c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47	35760	----a-w-	c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Check Mail]
2007-04-18 21:37	2158080	----a-w-	c:\program files\CheckMail V2\CK_Mail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Koma-Mail]
2010-03-12 14:14	2836992	----a-w-	c:\program files\KomaMail\Koma_Mail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2009-09-15 13:24	883208	----a-w-	c:\program files\Launch Manager\LManager.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseExtender]
2010-09-23 01:26	455168	----a-w-	c:\users\***\Desktop\MouseExtender.1.9.7.2\MouseExtender.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38	421888	----a-w-	c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
2010-07-11 09:42	2199040	----a-w-	c:\program files\Rainlendar2\Rainlendar2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr]
2009-10-10 06:51	614400	----a-w-	c:\windows\Samsung\PanelMgr\SSMMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2009-11-20 08:17	434176	----a-w-	c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 10:44	248552	----a-w-	c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher]
2007-10-28 10:35	425984	----a-w-	c:\program files\Switcher\Switcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-12-03 10:06	2622104	----a-w-	c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" -hide -runkey
.
R1 MpKslda63107b;MpKslda63107b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{66193AB5-5D42-498E-A3C9-EF5CAC0D8D2D}\MpKslda63107b.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 136176]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-20 73728]
R3 EchoIndigo;echondgo;c:\windows\system32\DRIVERS\echondgo.sys [2009-12-08 132544]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-05 13224]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [2008-10-21 86824]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 15016]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 114600]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 108328]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 26024]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [2008-10-21 104616]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [2008-10-21 109736]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2007-10-24 23288]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 UDST7000BDA;TerraTec H7 service;c:\windows\system32\DRIVERS\TerraTecUsbBda.sys [2010-08-17 782840]
R3 UDST7000HID;TerraTec H7/S7 HID service;c:\windows\system32\DRIVERS\TerraTecUsbHid.sys [2010-08-04 22136]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-09-15 16240]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-08 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 RRamdisk;Ramdisk Driver;c:\windows\system32\DRIVERS\rramdisk.sys [2009-04-30 12288]
S1 cbfs3;cbfs3;c:\windows\system32\drivers\cbfs3.sys [2010-05-15 265800]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-30 218688]
S1 MpKsl66cf2e2f;MpKsl66cf2e2f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys [x]
S1 MpKslf60824b1;MpKslf60824b1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5E64436B-C2AC-415B-A79B-85CA355D720B}\MpKslf60824b1.sys [2011-04-01 28752]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-03-19 2964312]
S2 MCSWASVR;Mediencenter Service;c:\program files\Telekom\Mediencenter\WebDAV.AdminService.exe [2010-07-09 16016]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [2009-06-07 61440]
S2 sesvc;ShadowExplorer Service;c:\program files\ShadowExplorer\sesvc.exe [2011-01-02 9216]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-11-30 5120]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-09-21 4867952]
S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-06-06 3406120]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-09-21 414576]
S2 Windows7FirewallService;Windows7FirewallService;c:\program files\Windows7FirewallControl\Windows7FirewallService.exe [2010-11-01 401408]
S3 echondgo;Indigo Service;c:\windows\system32\drivers\echondgo.sys [2009-12-08 132544]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MPKSLF60824B1
.
Inhalt des "geplante Tasks" Ordners
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30]
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://google.de/
uInternet Settings,ProxyOverride = *.local
IE: add to &BOM - c:\\PROGRA~1\\BIET-O~1\\\\AddToBOM.hta
IE: Free YouTube Download - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: {{27914077-B4D6-4A0E-9763-76B6E9DD9A81} - c:\program files\Buyertools Reminder\ReminderIE.exe
Trusted Zone: ***-lieblein.de
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.de
FF - prefs.js: keyword.URL - hxxp://go.gmx.net/tb/mff_keyurl_search/?su=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - c:\program files\Mozilla Firefox\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Dictionary Switcher: dictionary-switcher@design-noir.de - %profile%\extensions\dictionary-switcher@design-noir.de
FF - Ext: Dictionary (EN/DE): dictlookup@arnhold.com - %profile%\extensions\dictlookup@arnhold.com
FF - Ext: BabelFish: {ca0849e8-2c76-42ae-9abe-34e14d337acf} - %profile%\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf}
FF - Ext: German Dictionary: de-DE@dictionaries.addons.mozilla.org - %profile%\extensions\de-DE@dictionaries.addons.mozilla.org
FF - Ext: United States English Spellchecker: en-US@dictionaries.addons.mozilla.org - %profile%\extensions\en-US@dictionaries.addons.mozilla.org
FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - %profile%\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}
FF - Ext: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - %profile%\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Vacuum Places Improved: VacuumPlacesImproved@lultimouomo-gmail.com - %profile%\extensions\VacuumPlacesImproved@lultimouomo-gmail.com
FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com
FF - Ext: Lazarus: Form Recovery: lazarus@interclue.com - %profile%\extensions\lazarus@interclue.com
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Fasterfox Lite: FasterFox_Lite@BigRedBrent - %profile%\extensions\FasterFox_Lite@BigRedBrent
FF - Ext: WebMail Notifier: {37fa1426-b82d-11db-8314-0800200c9a66} - %profile%\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
FF - Ext: Biet-O-Matic Firefox Erweiterung: {B0D70E72-2FC1-4b9f-A3D4-5921C854D906} - %profile%\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906}
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-04-01  21:27:41
ComboFix-quarantined-files.txt  2011-04-01 19:27
ComboFix2.txt  2011-04-01 13:00
.
Vor Suchlauf: 21 Verzeichnis(se), 72.211.468.288 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 72.157.392.896 Bytes frei
.
- - End Of File - - ADDCA751A69EA0B5BBFCC830681AD85C
         
--- --- ---

Geändert von ronze44 (01.04.2011 um 20:52 Uhr)

Alt 02.04.2011, 13:26   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 02.04.2011, 21:34   #21
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Danke Arne,
no infections found -

LOG:

2011/04/02 22:29:33.0884 5520 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/04/02 22:29:34.0055 5520 ================================================================================
2011/04/02 22:29:34.0055 5520 SystemInfo:
2011/04/02 22:29:34.0055 5520
2011/04/02 22:29:34.0055 5520 OS Version: 6.1.7601 ServicePack: 1.0
2011/04/02 22:29:34.0055 5520 Product type: Workstation
2011/04/02 22:29:34.0055 5520 ComputerName: ***-PC
2011/04/02 22:29:34.0055 5520 UserName: ***
2011/04/02 22:29:34.0055 5520 Windows directory: C:\Windows
2011/04/02 22:29:34.0055 5520 System windows directory: C:\Windows
2011/04/02 22:29:34.0055 5520 Processor architecture: Intel x86
2011/04/02 22:29:34.0055 5520 Number of processors: 2
2011/04/02 22:29:34.0055 5520 Page size: 0x1000
2011/04/02 22:29:34.0055 5520 Boot type: Normal boot
2011/04/02 22:29:34.0055 5520 ================================================================================
2011/04/02 22:29:34.0773 5520 Initialize success
2011/04/02 22:29:49.0794 4844 ================================================================================
2011/04/02 22:29:49.0794 4844 Scan started
2011/04/02 22:29:49.0794 4844 Mode: Manual;
2011/04/02 22:29:49.0794 4844 ================================================================================
2011/04/02 22:29:50.0308 4844 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
2011/04/02 22:29:50.0433 4844 a2acc (71574a98093d94bdbb3cb74e272d29a5) C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys
2011/04/02 22:29:50.0574 4844 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
2011/04/02 22:29:50.0698 4844 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
2011/04/02 22:29:50.0839 4844 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/04/02 22:29:50.0886 4844 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/04/02 22:29:50.0995 4844 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/04/02 22:29:51.0073 4844 AFD (1151fd4fb0216cfed887bfde29ebd516) C:\Windows\system32\drivers\afd.sys
2011/04/02 22:29:51.0166 4844 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
2011/04/02 22:29:51.0229 4844 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/04/02 22:29:51.0385 4844 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
2011/04/02 22:29:51.0416 4844 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
2011/04/02 22:29:51.0447 4844 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
2011/04/02 22:29:51.0572 4844 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/04/02 22:29:51.0588 4844 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/04/02 22:29:51.0681 4844 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys
2011/04/02 22:29:51.0712 4844 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/04/02 22:29:51.0728 4844 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys
2011/04/02 22:29:51.0868 4844 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
2011/04/02 22:29:51.0962 4844 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/04/02 22:29:52.0040 4844 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/04/02 22:29:52.0118 4844 Aspi32 (5b01af89d16d562825c4db4530f20cbb) C:\Windows\system32\drivers\aspi32.sys
2011/04/02 22:29:52.0165 4844 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/04/02 22:29:52.0258 4844 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
2011/04/02 22:29:52.0336 4844 athr (76bab0c824e2d05b940c4dd40a9b08bf) C:\Windows\system32\DRIVERS\athr.sys
2011/04/02 22:29:52.0524 4844 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/04/02 22:29:52.0586 4844 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/04/02 22:29:52.0726 4844 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/04/02 22:29:52.0789 4844 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/04/02 22:29:52.0820 4844 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
2011/04/02 22:29:52.0851 4844 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/04/02 22:29:52.0945 4844 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/04/02 22:29:52.0992 4844 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/04/02 22:29:53.0023 4844 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/04/02 22:29:53.0054 4844 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/04/02 22:29:53.0163 4844 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/04/02 22:29:53.0179 4844 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/04/02 22:29:53.0335 4844 cbfs3 (afab1d4cab04218cbab0ae69625d0d65) C:\Windows\system32\drivers\cbfs3.sys
2011/04/02 22:29:53.0444 4844 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/04/02 22:29:53.0600 4844 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
2011/04/02 22:29:53.0678 4844 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/04/02 22:29:53.0772 4844 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/04/02 22:29:53.0881 4844 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/04/02 22:29:53.0928 4844 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
2011/04/02 22:29:54.0037 4844 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/04/02 22:29:54.0099 4844 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/04/02 22:29:54.0177 4844 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
2011/04/02 22:29:54.0286 4844 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/04/02 22:29:54.0411 4844 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
2011/04/02 22:29:54.0583 4844 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/04/02 22:29:54.0645 4844 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/04/02 22:29:54.0754 4844 DKbFltr (c701324c9e0c25dd9d60311bd87fbc84) C:\Windows\system32\DRIVERS\DKbFltr.sys
2011/04/02 22:29:54.0848 4844 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/04/02 22:29:54.0957 4844 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
2011/04/02 22:29:55.0035 4844 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
2011/04/02 22:29:55.0269 4844 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/04/02 22:29:55.0472 4844 EchoIndigo (aa9d3951465cff3137c6b531e19fb21b) C:\Windows\system32\DRIVERS\echondgo.sys
2011/04/02 22:29:55.0534 4844 echondgo (aa9d3951465cff3137c6b531e19fb21b) C:\Windows\system32\drivers\echondgo.sys
2011/04/02 22:29:55.0612 4844 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/04/02 22:29:55.0722 4844 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
2011/04/02 22:29:55.0831 4844 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/04/02 22:29:55.0878 4844 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/04/02 22:29:55.0924 4844 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/04/02 22:29:56.0034 4844 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/04/02 22:29:56.0080 4844 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/04/02 22:29:56.0112 4844 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/04/02 22:29:56.0236 4844 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/04/02 22:29:56.0299 4844 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/04/02 22:29:56.0346 4844 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/04/02 22:29:56.0455 4844 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
2011/04/02 22:29:56.0564 4844 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/04/02 22:29:56.0658 4844 ggflt (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys
2011/04/02 22:29:56.0720 4844 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys
2011/04/02 22:29:56.0860 4844 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/04/02 22:29:56.0938 4844 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
2011/04/02 22:29:57.0032 4844 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
2011/04/02 22:29:57.0126 4844 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/04/02 22:29:57.0141 4844 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/04/02 22:29:57.0219 4844 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/04/02 22:29:57.0344 4844 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
2011/04/02 22:29:57.0469 4844 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
2011/04/02 22:29:57.0594 4844 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
2011/04/02 22:29:57.0703 4844 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
2011/04/02 22:29:57.0765 4844 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
2011/04/02 22:29:57.0890 4844 iaStor (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\DRIVERS\iaStor.sys
2011/04/02 22:29:57.0968 4844 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys
2011/04/02 22:29:58.0327 4844 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/04/02 22:29:58.0686 4844 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/04/02 22:29:58.0842 4844 IntcAzAudAddService (f2baa4ff548f7f0317f7638951c1cd9c) C:\Windows\system32\drivers\RTKVHDA.sys
2011/04/02 22:29:59.0013 4844 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
2011/04/02 22:29:59.0091 4844 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/04/02 22:29:59.0200 4844 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/04/02 22:29:59.0263 4844 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
2011/04/02 22:29:59.0294 4844 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/04/02 22:29:59.0434 4844 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/04/02 22:29:59.0466 4844 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
2011/04/02 22:29:59.0497 4844 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
2011/04/02 22:29:59.0622 4844 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/04/02 22:29:59.0684 4844 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/04/02 22:29:59.0731 4844 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
2011/04/02 22:29:59.0840 4844 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
2011/04/02 22:29:59.0949 4844 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/04/02 22:30:00.0090 4844 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/04/02 22:30:00.0105 4844 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/04/02 22:30:00.0136 4844 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/04/02 22:30:00.0152 4844 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/04/02 22:30:00.0214 4844 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/04/02 22:30:00.0386 4844 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/04/02 22:30:00.0433 4844 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/04/02 22:30:00.0464 4844 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/04/02 22:30:00.0511 4844 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/04/02 22:30:00.0620 4844 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2011/04/02 22:30:00.0714 4844 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/04/02 22:30:00.0745 4844 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
2011/04/02 22:30:00.0901 4844 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\Windows\system32\DRIVERS\MpFilter.sys
2011/04/02 22:30:00.0932 4844 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
2011/04/02 22:30:01.0150 4844 MpKsl8deaba55 (5f53edfead46fa7adb78eee9ecce8fdf) C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{873FC184-6AD4-4794-8ECA-AE39170733D4}\MpKsl8deaba55.sys
2011/04/02 22:30:01.0306 4844 MpNWMon (f32e2d6a1640a469a9ed4f1929a4a861) C:\Windows\system32\DRIVERS\MpNWMon.sys
2011/04/02 22:30:01.0353 4844 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/04/02 22:30:01.0416 4844 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
2011/04/02 22:30:01.0540 4844 mrxsmb (b272b4c3e085ea860c12f2e4faf2ffa2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/04/02 22:30:01.0572 4844 mrxsmb10 (9ac33ef26c8a3ad0f117d00eb7301d03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/04/02 22:30:01.0603 4844 mrxsmb20 (e0abdb5ed7e199e242a7d028e76c1d3a) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/04/02 22:30:01.0634 4844 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
2011/04/02 22:30:01.0728 4844 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
2011/04/02 22:30:01.0790 4844 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/04/02 22:30:01.0821 4844 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/04/02 22:30:01.0837 4844 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
2011/04/02 22:30:01.0962 4844 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/04/02 22:30:02.0040 4844 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/04/02 22:30:02.0055 4844 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/04/02 22:30:02.0149 4844 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/04/02 22:30:02.0196 4844 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
2011/04/02 22:30:02.0242 4844 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/04/02 22:30:02.0289 4844 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/04/02 22:30:02.0367 4844 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/04/02 22:30:02.0445 4844 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/04/02 22:30:02.0601 4844 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
2011/04/02 22:30:02.0726 4844 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/04/02 22:30:02.0773 4844 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/04/02 22:30:02.0835 4844 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/04/02 22:30:02.0944 4844 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/04/02 22:30:03.0022 4844 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
2011/04/02 22:30:03.0132 4844 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/04/02 22:30:03.0178 4844 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
2011/04/02 22:30:03.0334 4844 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/04/02 22:30:03.0444 4844 NisDrv (17e2c08c5ecfbe94a7c67b1c275ee9d9) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
2011/04/02 22:30:03.0615 4844 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/04/02 22:30:03.0646 4844 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/04/02 22:30:03.0802 4844 Ntfs (33c3093d09017cfe2e219f2472bff6eb) C:\Windows\system32\drivers\Ntfs.sys
2011/04/02 22:30:03.0912 4844 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/04/02 22:30:03.0990 4844 nvraid (af2eec9580c1d32fb7eaf105d9784061) C:\Windows\system32\drivers\nvraid.sys
2011/04/02 22:30:04.0021 4844 nvstor (9283c58ebaa2618f93482eb5dabcec82) C:\Windows\system32\drivers\nvstor.sys
2011/04/02 22:30:04.0114 4844 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
2011/04/02 22:30:04.0161 4844 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
2011/04/02 22:30:04.0317 4844 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/04/02 22:30:04.0364 4844 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
2011/04/02 22:30:04.0395 4844 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/04/02 22:30:04.0426 4844 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
2011/04/02 22:30:04.0520 4844 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
2011/04/02 22:30:04.0582 4844 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/04/02 22:30:04.0614 4844 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/04/02 22:30:04.0660 4844 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/04/02 22:30:04.0785 4844 PenClass (4a108cc9cc0e0605e68cce7021479879) C:\Windows\system32\Drivers\PenClass.sys
2011/04/02 22:30:04.0926 4844 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/04/02 22:30:05.0035 4844 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/04/02 22:30:05.0113 4844 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/04/02 22:30:05.0238 4844 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/04/02 22:30:05.0347 4844 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/04/02 22:30:05.0394 4844 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/04/02 22:30:05.0409 4844 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/04/02 22:30:05.0487 4844 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/04/02 22:30:05.0565 4844 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/04/02 22:30:05.0628 4844 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/04/02 22:30:05.0674 4844 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/04/02 22:30:05.0784 4844 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
2011/04/02 22:30:05.0846 4844 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/04/02 22:30:05.0893 4844 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/04/02 22:30:06.0002 4844 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/04/02 22:30:06.0033 4844 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/04/02 22:30:06.0080 4844 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
2011/04/02 22:30:06.0142 4844 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
2011/04/02 22:30:06.0298 4844 RRamdisk (519d3c83d04bc3e0289e80f61d2febc0) C:\Windows\system32\DRIVERS\rramdisk.sys
2011/04/02 22:30:06.0376 4844 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/04/02 22:30:06.0501 4844 s0017bus (594ff5620661d1386475406e78cb6f2f) C:\Windows\system32\DRIVERS\s0017bus.sys
2011/04/02 22:30:06.0548 4844 s0017mdfl (7258f550419d543bc5c8e80c578a5d54) C:\Windows\system32\DRIVERS\s0017mdfl.sys
2011/04/02 22:30:06.0579 4844 s0017mdm (1de4f6607feb17a15dbd4f1b139e6d2f) C:\Windows\system32\DRIVERS\s0017mdm.sys
2011/04/02 22:30:06.0688 4844 s0017mgmt (9814e6bacc06d2526cd52981c7eeedf0) C:\Windows\system32\DRIVERS\s0017mgmt.sys
2011/04/02 22:30:06.0751 4844 s0017nd5 (2c62cd58225973f26682cd4f783ddede) C:\Windows\system32\DRIVERS\s0017nd5.sys
2011/04/02 22:30:06.0860 4844 s0017obex (f87c3422e84b2fb1b43e0a26247ad5a5) C:\Windows\system32\DRIVERS\s0017obex.sys
2011/04/02 22:30:06.0891 4844 s0017unic (df5e7360a0afa5956bf75da683d0679f) C:\Windows\system32\DRIVERS\s0017unic.sys
2011/04/02 22:30:06.0938 4844 s217bus (0266151de3f36429f6ac3c4b28085061) C:\Windows\system32\DRIVERS\s217bus.sys
2011/04/02 22:30:07.0063 4844 s217mdfl (a43c0af0e46be7ef0c7e8ccf0f058600) C:\Windows\system32\DRIVERS\s217mdfl.sys
2011/04/02 22:30:07.0094 4844 s217mdm (005f5ded1ed8f8a9d2399d765ead20f1) C:\Windows\system32\DRIVERS\s217mdm.sys
2011/04/02 22:30:07.0125 4844 s217mgmt (de9562ad0c91e1857d11f65a91ee1a47) C:\Windows\system32\DRIVERS\s217mgmt.sys
2011/04/02 22:30:07.0250 4844 s217nd5 (11cc5d7f992799e7e75d018e9c018563) C:\Windows\system32\DRIVERS\s217nd5.sys
2011/04/02 22:30:07.0297 4844 s217obex (0f9f4045799afb66b85eef999d0609ec) C:\Windows\system32\DRIVERS\s217obex.sys
2011/04/02 22:30:07.0328 4844 s217unic (1c91e1023f07b6407d84b5a43537d984) C:\Windows\system32\DRIVERS\s217unic.sys
2011/04/02 22:30:07.0453 4844 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
2011/04/02 22:30:07.0500 4844 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
2011/04/02 22:30:07.0578 4844 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/04/02 22:30:07.0687 4844 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
2011/04/02 22:30:07.0765 4844 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/04/02 22:30:07.0812 4844 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/04/02 22:30:07.0905 4844 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/04/02 22:30:08.0030 4844 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
2011/04/02 22:30:08.0108 4844 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
2011/04/02 22:30:08.0155 4844 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
2011/04/02 22:30:08.0202 4844 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/04/02 22:30:08.0233 4844 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
2011/04/02 22:30:08.0358 4844 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/04/02 22:30:08.0389 4844 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/04/02 22:30:08.0420 4844 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/04/02 22:30:08.0560 4844 snapman (bcc773872041aa59bc9a6cf770fb32e2) C:\Windows\system32\DRIVERS\snapman.sys
2011/04/02 22:30:08.0607 4844 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/04/02 22:30:08.0685 4844 srv (112127c3b2e64d7680cc39cd0a39dd7e) C:\Windows\system32\DRIVERS\srv.sys
2011/04/02 22:30:08.0794 4844 srv2 (e5dd784a4ee5ebc72a86c677c988fcdb) C:\Windows\system32\DRIVERS\srv2.sys
2011/04/02 22:30:08.0857 4844 srvnet (cdbe627e16cc9e98f343d73f8e81d258) C:\Windows\system32\DRIVERS\srvnet.sys
2011/04/02 22:30:08.0982 4844 SSPORT (ef3458337d7341a05169cefc73709264) C:\Windows\system32\Drivers\SSPORT.sys
2011/04/02 22:30:09.0060 4844 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\Windows\system32\drivers\StarOpen.sys
2011/04/02 22:30:09.0122 4844 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/04/02 22:30:09.0247 4844 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
2011/04/02 22:30:09.0340 4844 SynasUSB (e46088b882e6315518630e249ddf958c) C:\Windows\system32\drivers\SynasUSB.sys
2011/04/02 22:30:09.0590 4844 Tcpip (37e8fa3779668837ca9e2c36d2415949) C:\Windows\system32\drivers\tcpip.sys
2011/04/02 22:30:09.0777 4844 TCPIP6 (37e8fa3779668837ca9e2c36d2415949) C:\Windows\system32\DRIVERS\tcpip.sys
2011/04/02 22:30:09.0902 4844 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/04/02 22:30:09.0964 4844 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
2011/04/02 22:30:10.0042 4844 tdrpman (3b7b6779eb231f731bba8f9fe67aadfc) C:\Windows\system32\DRIVERS\tdrpman.sys
2011/04/02 22:30:10.0152 4844 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
2011/04/02 22:30:10.0198 4844 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
2011/04/02 22:30:10.0245 4844 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
2011/04/02 22:30:10.0370 4844 tifsfilter (b0b3122bff3910e0ba97014045467778) C:\Windows\system32\DRIVERS\tifsfilt.sys
2011/04/02 22:30:10.0417 4844 timounter (13bfe330880ac0ce8672d00aa5aff738) C:\Windows\system32\DRIVERS\timntr.sys
2011/04/02 22:30:10.0604 4844 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/04/02 22:30:10.0666 4844 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
2011/04/02 22:30:10.0807 4844 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
2011/04/02 22:30:10.0869 4844 TVicPort (3147063508eae931becc01573c204fac) C:\Windows\system32\DRIVERS\TVICPORT.SYS
2011/04/02 22:30:10.0994 4844 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/04/02 22:30:11.0056 4844 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
2011/04/02 22:30:11.0212 4844 UDST7000BDA (d785cdc0d6e27aa27dc30d3b3aad7819) C:\Windows\system32\DRIVERS\TerraTecUsbBda.sys
2011/04/02 22:30:11.0353 4844 UDST7000HID (527fea6f1669fca060c8fa17174db19b) C:\Windows\system32\DRIVERS\TerraTecUsbHid.sys
2011/04/02 22:30:11.0462 4844 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
2011/04/02 22:30:11.0587 4844 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
2011/04/02 22:30:11.0634 4844 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/04/02 22:30:11.0758 4844 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
2011/04/02 22:30:11.0790 4844 usbccgp (7e72e7d7e0757d59481d530fd2b0bfae) C:\Windows\system32\drivers\usbccgp.sys
2011/04/02 22:30:11.0821 4844 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
2011/04/02 22:30:11.0868 4844 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2011/04/02 22:30:11.0992 4844 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\drivers\usbhub.sys
2011/04/02 22:30:12.0039 4844 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2011/04/02 22:30:12.0102 4844 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/04/02 22:30:12.0195 4844 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/04/02 22:30:12.0258 4844 USBSTOR (bf63ebfc6979fefb2bc03df7989a0c1a) C:\Windows\system32\drivers\USBSTOR.SYS
2011/04/02 22:30:12.0304 4844 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/04/02 22:30:12.0429 4844 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
2011/04/02 22:30:12.0507 4844 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
2011/04/02 22:30:12.0570 4844 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/04/02 22:30:12.0648 4844 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/04/02 22:30:12.0710 4844 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
2011/04/02 22:30:12.0772 4844 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
2011/04/02 22:30:12.0866 4844 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/04/02 22:30:12.0928 4844 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
2011/04/02 22:30:12.0944 4844 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
2011/04/02 22:30:13.0038 4844 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/04/02 22:30:13.0116 4844 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
2011/04/02 22:30:13.0225 4844 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/04/02 22:30:13.0287 4844 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
2011/04/02 22:30:13.0396 4844 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
2011/04/02 22:30:13.0490 4844 wacmoumonitor (f24ee97511fb901189e11cbbd51605ba) C:\Windows\system32\DRIVERS\wacmoumonitor.sys
2011/04/02 22:30:13.0584 4844 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\Windows\system32\DRIVERS\wacommousefilter.sys
2011/04/02 22:30:13.0646 4844 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/04/02 22:30:13.0771 4844 wacomvhid (73e6f16a1f187d71fb26af308551e54a) C:\Windows\system32\DRIVERS\wacomvhid.sys
2011/04/02 22:30:13.0833 4844 WacomVKHid (889459833432b161cb99cfdf84a1a9bb) C:\Windows\system32\DRIVERS\WacomVKHid.sys
2011/04/02 22:30:13.0958 4844 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/02 22:30:13.0974 4844 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/02 22:30:14.0114 4844 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/04/02 22:30:14.0208 4844 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/04/02 22:30:14.0364 4844 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/04/02 22:30:14.0395 4844 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/04/02 22:30:14.0613 4844 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/04/02 22:30:14.0707 4844 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
2011/04/02 22:30:14.0847 4844 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/04/02 22:30:14.0925 4844 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
2011/04/02 22:30:15.0066 4844 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/04/02 22:30:15.0190 4844 ================================================================================
2011/04/02 22:30:15.0190 4844 Scan finished
2011/04/02 22:30:15.0190 4844 ================================================================================

Geändert von ronze44 (02.04.2011 um 21:41 Uhr)

Alt 03.04.2011, 13:55   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 03.04.2011, 17:46   #23
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



danke Arne.

Der Gemer hat mich den ganzen Nachmittag umsonst gekostet.
Hat gescannt und nach drei Stunden ungefähr war er fertig, aber als ich drauf klickte ist er abgestürzt mit samt seiner 32 Milliarden Daten.
Er hat auf meiner Ramdisk, der ja der Temp Ordner namens T ist einen Windows Ordner mit tausenden Dateien gescannt, den ich gar nicht dort sehe. Na ja, muss ja nicht alles verstehen.

Hier der OSAM:

OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 18:37:17 on 03.04.2011

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.16

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl
"PLWMidiMap.cpl" - "Putzlowitsch" - C:\Windows\system32\PLWMidiMap.cpl
"WacomTablet.cpl" - "Wacom Technology, Corp." - C:\Windows\system32\WacomTablet.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Bamboo" - "Wacom Technology, Corp." - C:\Program Files\Tablet\Pen\Consumer_CPL.exe
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
"Wacom Tablett" - "Wacom Technology, Corp." - C:\Windows\system32\WacomTablet.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"a2acc" (a2acc) - "Emsi Software GmbH" - C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys
"Acronis Snapshots Manager" (snapman) - "Acronis" - C:\Windows\System32\DRIVERS\snapman.sys
"Acronis True Image Backup Archive Explorer" (timounter) - "Acronis" - C:\Windows\System32\DRIVERS\timntr.sys
"Acronis True Image FS Filter" (tifsfilter) - "Acronis" - C:\Windows\System32\DRIVERS\tifsfilt.sys
"Acronis Try&Decide and Restore Points filter" (tdrpman) - "Acronis" - C:\Windows\System32\DRIVERS\tdrpman.sys
"Aspi32" (Aspi32) - "Adaptec" - C:\Windows\System32\drivers\aspi32.sys
"catchme" (catchme) - ? - T:\TEMP\catchme.sys  (File not found)
"cbfs3" (cbfs3) - "EldoS Corporation" - C:\Windows\system32\drivers\cbfs3.sys
"DgiVecp" (DgiVecp) - ? - C:\Windows\system32\Drivers\DgiVecp.sys  (File not found)
"kgldipod" (kgldipod) - ? - T:\TEMP\kgldipod.sys  (Hidden registry entry, rootkit activity | File not found)
"mbr" (mbr) - ? - C:\Cofi.exe\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
"MpKsl66cf2e2f" (MpKsl66cf2e2f) - ? - C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys  (File not found)
"MpKsl892c9348" (MpKsl892c9348) - "Microsoft Corporation" - C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A5ADC00A-7806-463E-9C83-E5C9B3D122FF}\MpKsl892c9348.sys
"MpKslda63107b" (MpKslda63107b) - ? - C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{66193AB5-5D42-498E-A3C9-EF5CAC0D8D2D}\MpKslda63107b.sys  (File not found)
"Pen Class" (PenClass) - "Wacom Technology Corporation" - C:\Windows\System32\Drivers\PenClass.sys
"Ramdisk Driver" (RRamdisk) - "gavotte" - C:\Windows\System32\DRIVERS\rramdisk.sys
"SSPORT" (SSPORT) - "Samsung Electronics" - C:\Windows\system32\Drivers\SSPORT.sys
"StarOpen" (StarOpen) - ? - C:\Windows\system32\drivers\StarOpen.sys  (File found, but it contains no detailed information)
"SynasUSB" (SynasUSB) - "SIA Syncrosoft" - C:\Windows\System32\drivers\SynasUSB.sys
"TVICPORT" (TVicPort) - "EnTech Taiwan" - C:\Windows\system32\DRIVERS\TVICPORT.SYS

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler )-----
{1984DD45-52CF-49cd-AB77-18F378FEA264} "FencesShlExt Class" - "Stardock" - C:\Program Files\Stardock\Fences\FencesMenu.dll
{1984D045-52CF-49cd-DB77-08F378FEA4DB} "ObjectDockShlExt Class" - "Stardock" - C:\Program Files\Stardock\ObjectDockPlus2\ODMenu.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{C539A15A-3AF9-4c92-B771-50CB78F5C751} "Acronis True Image Shell Context Menu Extension" - "Acronis" - C:\Program Files\Acronis\TrueImageHome\tishell.dll
{C539A15B-3AF9-4c92-B771-50CB78F5C751} "Acronis True Image Shell Extension" - "Acronis" - C:\Program Files\Acronis\TrueImageHome\tishell.dll
{09A47860-11B0-4DA5-AFA5-26D86198A780} "EPP" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~4\shellext.dll
{693BE9C0-BEC3-11D2-B4C1-C33BBD3AD64B} "Fast Explorer Shell Extension" - "Alex Yakovlev" - C:\ProgramData\AllDup\FEShlExt.dll
{1984DD45-52CF-49cd-AB77-18F378FEA264} "FencesShlExt Class" - "Stardock" - C:\Program Files\Stardock\Fences\FencesMenu.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
{1984D045-52CF-49cd-DB77-08F378FEA4DB} "ObjectDockShlExt Class" - "Stardock" - C:\Program Files\Stardock\ObjectDockPlus2\ODMenu.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{4CF20B46-D006-4B90-A64B-DBAA9470EFBE} "PhotoToysClone" - "Brice Lambson" - C:\Program Files\Brice Lambson\PhotoToysClone\PhotoToysClone.dll
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? -   (File not found | COM-object registry key not found)
{BD88A479-9623-4897-8546-BC62B9628F44} "SPTHandler" - ? -   (File not found | COM-object registry key not found)
{0420B051-ECD8-4B18-9037-8739B4B6469F} "WebDavContextMenu Class" - "Deutsche Telekom AG" - C:\Windows\system32\WebDAV.ShellExtension.dll
{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262} "WebDavOverlayUpload Class" - "Deutsche Telekom AG" - C:\Windows\system32\WebDAV.ShellExtension.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -   (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
{1984D045-52CF-49cd-DB77-08F378FEA4DB} {000214e8-0000-0000-c000-000000000046} 0x401 "{1984D045-52CF-49cd-DB77-08F378FEA4DB} {000214e8-0000-0000-c000-000000000046} 0x401" - ? -   (File not found | COM-object registry key not found)
{1984DD45-52CF-49cd-AB77-18F378FEA264} {000214e8-0000-0000-c000-000000000046} 0x401 "{1984DD45-52CF-49cd-AB77-18F378FEA264} {000214e8-0000-0000-c000-000000000046} 0x401" - ? -   (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
<binary data> "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_23.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
"Buyertools Reminder" - ? - C:\Program Files\Buyertools Reminder\ReminderIE.exe  (File found, but it contains no detailed information)
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{AD6E6555-FB2C-47D4-8339-3E2965509877} "TerraTec Home Cinema" - "TerraTec Electronic GmbH" - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL
{40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{7C7A8947-5935-4430-AC0E-E7D04697414E} "Buyertools" - ? - C:\PROGRA~1\BUYERT~1\IEBUTT~1.DLL  (File found, but it contains no detailed information)
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
"Stardock ObjectDock.lnk" - "Stardock" - C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"McAfee Security Scan Plus.lnk" - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Buyertools Reminder" - "Buyertools Ltd." - "C:\Program Files\Buyertools Reminder\Reminder.exe" /autorun
"DAEMON Tools Lite" - "DT Soft Ltd" - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
"ISUSPM" - "Macrovision Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"ACFanControl" - "troubadix" - C:\Program Files\ACFanControl\ACFanControl.exe
"Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"Windows7FirewallControl" - "Sphinx Software" - C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe

[Network Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order )-----
"Virtual Network Shares CallbackFS v3" - "EldoS Corporation" - C:\Windows\System32\CbFsNetRdr3.dll

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)
"SSA1M Langmon" - ? - C:\Windows\system32\ssa1ml3.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243" (NisSrv) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
"Acronis Scheduler2 Service" (AcrSch2Svc) - "Acronis" - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
"Acronis Try And Decide Service" (TryAndDecideService) - ? - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe  (File found, but it contains no detailed information)
"Emsisoft Anti-Malware 5.0 - Service" (a2AntiMalware) - "Emsi Software GmbH" - C:\Program Files\Emsisoft Anti-Malware\a2service.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
"McAfee Security Scan Component Host Service" (McComponentHostService) - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
"Mediencenter Service" (MCSWASVR) - "Deutsche Telekom AG" - C:\Program Files\Telekom\Mediencenter\WebDAV.AdminService.exe
"Microsoft Antimalware Service" (MsMpSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
"Nalpeiron Licensing Service" (nlsX86cc) - "Nalpeiron Ltd." - C:\Windows\system32\NlsSrv32.exe
"NMSAccessU" (NMSAccessU) - ? - C:\Program Files\CDBurnerXP\NMSAccessU.exe  (File found, but it contains no detailed information)
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"ShadowExplorer Service" (sesvc) - "www.shadowexplorer.com" - C:\Program Files\ShadowExplorer\sesvc.exe
"Sony Ericsson OMSI download service" (OMSI download service) - ? - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe  (File found, but it contains no detailed information)
"TabletServicePen" (TabletServicePen) - "Wacom Technology, Corp." - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
"TabletServiceWacom" (TabletServiceWacom) - "Wacom Technology, Corp." - C:\Windows\system32\Wacom_Tablet.exe
"Wacom Consumer Touch Service" (TouchServicePen) - "Wacom Technology, Corp." - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
"Windows7FirewallService" (Windows7FirewallService) - "Sphinx Software" - C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


Und Hier MBRCheck:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 32-bit
Base Board Manufacturer: Acer, Inc.
BIOS Manufacturer: Acer
System Manufacturer: Acer, inc.
System Product Name: Extensa 7630EZ
Logical Drives Mask: 0x0008003c

Kernel Drivers (total 208):
0x82E03000 \SystemRoot\system32\ntkrnlpa.exe
0x83215000 \SystemRoot\system32\halmacpi.dll
0x80BAD000 \SystemRoot\system32\kdcom.dll
0x83818000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8389D000 \SystemRoot\system32\PSHED.dll
0x838AE000 \SystemRoot\system32\BOOTVID.dll
0x838B6000 \SystemRoot\system32\CLFS.SYS
0x838F8000 \SystemRoot\system32\CI.dll
0x83A23000 \SystemRoot\system32\drivers\Wdf01000.sys
0x83A94000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x83AA2000 \SystemRoot\system32\drivers\ACPI.sys
0x83AEA000 \SystemRoot\system32\drivers\WMILIB.SYS
0x83AF3000 \SystemRoot\system32\drivers\msisadrv.sys
0x83AFB000 \SystemRoot\system32\drivers\pci.sys
0x83B25000 \SystemRoot\system32\drivers\vdrvroot.sys
0x83B30000 \SystemRoot\System32\drivers\partmgr.sys
0x83B41000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x83B49000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x83B54000 \SystemRoot\system32\drivers\volmgr.sys
0x83B64000 \SystemRoot\System32\drivers\volmgrx.sys
0x83BAF000 \SystemRoot\system32\drivers\pciide.sys
0x83BB6000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x83BC4000 \SystemRoot\system32\DRIVERS\pcmcia.sys
0x83BF2000 \SystemRoot\system32\DRIVERS\rramdisk.sys
0x83A00000 \SystemRoot\System32\drivers\mountmgr.sys
0x83A16000 \SystemRoot\system32\drivers\atapi.sys
0x839A3000 \SystemRoot\system32\drivers\ataport.SYS
0x839C6000 \SystemRoot\system32\drivers\amdxata.sys
0x8B238000 \SystemRoot\system32\drivers\fltmgr.sys
0x8B26C000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B27D000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B3AC000 \SystemRoot\System32\Drivers\msrpc.sys
0x8B3D7000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B41B000 \SystemRoot\System32\Drivers\cng.sys
0x8B478000 \SystemRoot\System32\drivers\pcw.sys
0x8B486000 \SystemRoot\system32\Drivers\PenClass.sys
0x8B488000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8B491000 \SystemRoot\system32\drivers\ndis.sys
0x8B548000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B586000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8B635000 \SystemRoot\System32\drivers\tcpip.sys
0x8B77F000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B803000 \SystemRoot\system32\DRIVERS\timntr.sys
0x8B86E000 \SystemRoot\system32\drivers\volsnap.sys
0x8B8AD000 \SystemRoot\system32\DRIVERS\tdrpman.sys
0x8B906000 \SystemRoot\System32\Drivers\spldr.sys
0x8B90E000 \SystemRoot\system32\DRIVERS\snapman.sys
0x8B92C000 \SystemRoot\System32\drivers\rdyboost.sys
0x8B959000 \SystemRoot\System32\Drivers\mup.sys
0x8B969000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8B971000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8B9A3000 \SystemRoot\system32\DRIVERS\disk.sys
0x8B9B4000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8B7C1000 \SystemRoot\system32\drivers\cdrom.sys
0x8B600000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0x8B627000 \SystemRoot\System32\Drivers\Null.SYS
0x8B62E000 \SystemRoot\System32\Drivers\Beep.SYS
0x8B7E0000 \SystemRoot\System32\drivers\vga.sys
0x8B5AB000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8B7EC000 \SystemRoot\System32\drivers\watchdog.sys
0x8B5CC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8B5D4000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8B5DC000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8B5E4000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8B5EF000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8B400000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8B3EA000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x90436000 \SystemRoot\system32\drivers\afd.sys
0x90490000 \SystemRoot\System32\DRIVERS\netbt.sys
0x904C2000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x904C9000 \SystemRoot\system32\DRIVERS\pacer.sys
0x904E8000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x904F9000 \SystemRoot\system32\DRIVERS\netbios.sys
0x90507000 \SystemRoot\system32\DRIVERS\dtsoftbus01.sys
0x90542000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x90555000 \SystemRoot\system32\drivers\termdd.sys
0x90566000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x905A7000 \SystemRoot\system32\drivers\nsiproxy.sys
0x905B1000 \SystemRoot\system32\drivers\mssmbios.sys
0x905BB000 \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys
0x905C1000 \SystemRoot\System32\drivers\discache.sys
0x905CD000 \SystemRoot\System32\Drivers\dfsc.sys
0x93E03000 \??\C:\Windows\system32\drivers\cbfs3.sys
0x93E42000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x93E50000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x93E71000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x93E75000 \SystemRoot\system32\drivers\wmiacpi.sys
0x95037000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x93E7E000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x95954000 \SystemRoot\System32\drivers\dxgmms1.sys
0x9598D000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x95998000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x959E3000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x95000000 \SystemRoot\system32\drivers\HDAudBus.sys
0x94217000 \SystemRoot\system32\DRIVERS\athr.sys
0x94327000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x94331000 \SystemRoot\system32\DRIVERS\b57nd60x.sys
0x9436D000 \SystemRoot\system32\drivers\echondgo.sys
0x94390000 \SystemRoot\system32\drivers\portcls.sys
0x943BF000 \SystemRoot\system32\drivers\drmk.sys
0x93F35000 \SystemRoot\system32\drivers\ks.sys
0x943D8000 \SystemRoot\system32\drivers\i8042prt.sys
0x943F0000 \SystemRoot\system32\DRIVERS\DKbFltr.sys
0x94200000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x9501F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x93F69000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x959F2000 \SystemRoot\system32\drivers\CompositeBus.sys
0x9420D000 \SystemRoot\system32\DRIVERS\WacomVKHid.sys
0x93F7B000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x9420F000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x943FA000 \SystemRoot\system32\DRIVERS\wacomvhid.sys
0x93F8E000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x93FA0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x9502C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x93FB8000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x93FDA000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x905E5000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x90400000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x93FF2000 \SystemRoot\system32\DRIVERS\seehcri.sys
0x943FC000 \SystemRoot\system32\drivers\swenum.sys
0x90417000 \SystemRoot\system32\drivers\umbus.sys
0x9AE15000 \SystemRoot\system32\drivers\usbhub.sys
0x9AE59000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x9AE65000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x9AE70000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys
0x9AE78000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x9BC04000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x9BE8C000 \SystemRoot\system32\drivers\usbccgp.sys
0x9BEA3000 \SystemRoot\system32\drivers\USBD.SYS
0x9BEA5000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x9BEB0000 \SystemRoot\System32\Drivers\usbvideo.sys
0x9C050000 \SystemRoot\System32\win32k.sys
0x9BED4000 \SystemRoot\System32\drivers\Dxapi.sys
0x9BEDE000 \SystemRoot\System32\Drivers\crashdmp.sys
0x9BEEB000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x9BEF6000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x9BEFF000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x9BF10000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9C2B0000 \SystemRoot\System32\TSDDD.dll
0x9C2E0000 \SystemRoot\System32\cdd.dll
0x9BF1B000 \SystemRoot\system32\drivers\luafv.sys
0x9BF36000 \SystemRoot\system32\DRIVERS\tifsfilt.sys
0x9BF40000 \SystemRoot\system32\drivers\WudfPf.sys
0x9BF5A000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9BF6A000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9BFB0000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9BFC0000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9AE89000 \SystemRoot\system32\drivers\HTTP.sys
0x9BFD3000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9BFEC000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9AF0E000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9AF31000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9AF6C000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9BC00000 \SystemRoot\System32\drivers\aspi32.sys
0xAF607000 \SystemRoot\system32\drivers\peauth.sys
0xAF69E000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAF6A8000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAF6C9000 \??\C:\Windows\system32\Drivers\SSPORT.sys
0xAF6D0000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAF6DD000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAF72C000 \SystemRoot\System32\DRIVERS\srv.sys
0xAF7E7000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xAF7F0000 \??\C:\Windows\system32\Drivers\PROCEXP113.SYS
0xAF7F2000 \SystemRoot\system32\DRIVERS\MpNWMon.sys
0xAF79B000 \??\T:\TEMP\catchme.sys
0xAF785000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xAF7A3000 \??\T:\TEMP\kgldipod.sys
0xAF7CA000 \SystemRoot\system32\DRIVERS\NisDrvWFP.sys
0xAF7D6000 \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A5ADC00A-7806-463E-9C83-E5C9B3D122FF}\MpKsl892c9348.sys
0x76E40000 \Windows\System32\ntdll.dll
0x475D0000 \Windows\System32\smss.exe
0x77080000 \Windows\System32\apisetschema.dll
0x00840000 \Windows\System32\autochk.exe
0x77020000 \Windows\System32\gdi32.dll
0x76FE0000 \Windows\System32\ws2_32.dll
0x76D60000 \Windows\System32\kernel32.dll
0x76CD0000 \Windows\System32\clbcatq.dll
0x76B30000 \Windows\System32\setupapi.dll
0x76A60000 \Windows\System32\msctf.dll
0x76FC0000 \Windows\System32\imm32.dll
0x76900000 \Windows\System32\ole32.dll
0x76850000 \Windows\System32\rpcrt4.dll
0x76FB0000 \Windows\System32\normaliz.dll
0x76F80000 \Windows\System32\imagehlp.dll
0x76840000 \Windows\System32\nsi.dll
0x767F0000 \Windows\System32\Wldap32.dll
0x75BA0000 \Windows\System32\shell32.dll
0x75B80000 \Windows\System32\sechost.dll
0x75AE0000 \Windows\System32\usp10.dll
0x75A80000 \Windows\System32\shlwapi.dll
0x759F0000 \Windows\System32\oleaut32.dll
0x758F0000 \Windows\System32\wininet.dll
0x758E0000 \Windows\System32\psapi.dll
0x75830000 \Windows\System32\msvcrt.dll
0x757B0000 \Windows\System32\comdlg32.dll
0x756E0000 \Windows\System32\user32.dll
0x754E0000 \Windows\System32\iertutil.dll
0x75440000 \Windows\System32\advapi32.dll
0x753E0000 \Windows\System32\difxapi.dll
0x753D0000 \Windows\System32\lpk.dll
0x75290000 \Windows\System32\urlmon.dll
0x75240000 \Windows\System32\KernelBase.dll
0x75120000 \Windows\System32\crypt32.dll
0x750F0000 \Windows\System32\wintrust.dll
0x750D0000 \Windows\System32\devobj.dll
0x750A0000 \Windows\System32\cfgmgr32.dll
0x75010000 \Windows\System32\comctl32.dll
0x75000000 \Windows\System32\msasn1.dll

Processes (total 70):
0 System Idle Process
4 System
392 C:\Windows\System32\smss.exe
536 csrss.exe
580 C:\Windows\System32\wininit.exe
596 csrss.exe
636 C:\Windows\System32\services.exe
660 C:\Windows\System32\lsass.exe
668 C:\Windows\System32\lsm.exe
724 C:\Windows\System32\winlogon.exe
812 C:\Windows\System32\svchost.exe
876 C:\Program Files\Emsisoft Anti-Malware\a2service.exe
960 C:\Windows\System32\svchost.exe
1008 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
1120 C:\Windows\System32\svchost.exe
1176 C:\Windows\System32\svchost.exe
1208 C:\Windows\System32\svchost.exe
1348 C:\Windows\System32\svchost.exe
1408 C:\Program Files\Tablet\Pen\Pen_TouchService.exe
1500 C:\Windows\System32\wisptis.exe
1536 C:\Windows\System32\svchost.exe
1708 C:\Windows\System32\spoolsv.exe
1736 C:\Windows\System32\svchost.exe
1820 C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
1864 C:\Program Files\Telekom\Mediencenter\WebDAV.AdminService.exe
112 C:\Windows\System32\wisptis.exe
420 C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
548 C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
664 C:\Windows\System32\taskhost.exe
936 C:\Windows\System32\dwm.exe
2400 C:\Windows\System32\NlsSrv32.exe
2432 C:\Program Files\CDBurnerXP\NMSAccessU.exe
2496 C:\Program Files\ShadowExplorer\sesvc.exe
2544 C:\Windows\System32\svchost.exe
2568 C:\Program Files\Tablet\Pen\Pen_Tablet.exe
2604 C:\Windows\System32\Wacom_Tablet.exe
2656 C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
2720 C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
2744 C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe
2772 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2896 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
3024 C:\Windows\System32\WTablet\Wacom_TabletUser.exe
3080 C:\Windows\System32\Wacom_Tablet.exe
3120 C:\Program Files\Tablet\Pen\Pen_Tablet.exe
3368 C:\Windows\System32\svchost.exe
3736 C:\Windows\System32\svchost.exe
2348 C:\Windows\System32\SearchIndexer.exe
2372 C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
3632 C:\Program Files\Windows Media Player\wmpnetwk.exe
2756 C:\Program Files\Microsoft Security Client\msseces.exe
4448 C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe
4616 C:\Windows\explorer.exe
5164 C:\Windows\explorer.exe
2600 C:\Windows\explorer.exe
5332 C:\Windows\System32\svchost.exe
4184 C:\Windows\System32\taskhost.exe
4120 C:\Windows\explorer.exe
6016 C:\Windows\explorer.exe
5608 C:\Windows\explorer.exe
5988 C:\Windows\explorer.exe
4700 C:\Windows\explorer.exe
2292 C:\Windows\explorer.exe
2408 C:\Windows\explorer.exe
2208 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
1248 C:\Program Files\Mozilla Firefox\firefox.exe
4760 C:\Windows\System32\audiodg.exe
3232 C:\Windows\System32\notepad.exe
1844 C:\Users\***\Desktop\MBRCheck.exe
5396 C:\Windows\System32\conhost.exe
3488 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`c0100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000001e`7c500000 (NTFS)
\\.\T: --> error 1

PhysicalDrive0 Model Number: HitachiHTS543225L9A300, Rev: FBEOC40C

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!

Alt 03.04.2011, 17:55   #24
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 03.04.2011, 20:45   #25
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



MalWBites:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6256

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

03.04.2011 20:56:37
mbam-log-2011-04-03 (20-56-37).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|T:\|)
Durchsuchte Objekte: 289107
Laufzeit: 1 Stunde(n), 57 Minute(n), 8 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 04/03/2011 at 09:23 PM

Application Version : 4.50.1002

Core Rules Database Version : 6743
Trace Rules Database Version: 4555

Scan type : Complete Scan
Total Scan Time : 01:56:00

Memory items scanned : 758
Memory threats detected : 0
Registry items scanned : 9286
Registry threats detected : 0
File items scanned : 139290
File threats detected : 4

Trojan.Agent/Gen-Cryptor[Egun]
C:\JWPACK\JWOSETUP.EXE
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\JUSTWRITE OFFICE\WERKZEUGLEISTE KONFIGURIEREN.LNK

Trojan.Agent/Gen-Bancos
C:\PROGRAM FILES\BUYERTOOLS REMINDER\IEBUTTONEBAYINTERFACE.DLL

Adware.Tracking Cookie
www.mjmedia.de [ C:\Users\***\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LTK5LV7K ]

Alt 04.04.2011, 09:10   #26
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Nur Fehlalarme und ein Cookie. Harmlos.
Rechner wieder ok oder noch Probleme?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 04.04.2011, 11:09   #27
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Rechner geht. Der komische RtkBtMnt.exe war ja schon länger verschwunden gewesen, nach Neustart ist er nun wieder da... muss wohl ein Falschalarm sein, den ich da bei Google fand.
Die Soundkarte funktioniert allerdings auch ohne das Ding.
...werde es einfach ignorieren

Jedenfalls bin ich erleichtert - Neuaufsetzen verhindert TOLL

Zudem hast du einen Wochenend-Bonus verdient, danke nochmal für alles :

Alt 04.04.2011, 11:47   #28
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



Dann wären wir durch!

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.04.2011, 11:40   #29
ronze44
 
RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Standard

RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL



-


nochmal tausend Milliarden Dank Arne für die Unterstützung!


-

Antwort

Themen zu RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL
administrator, anfang, anfänger, befall, datei, dateien, fix, gelöscht, löschen, malwarebytes, microsoft, microsoft security, microsoft security essentials, neustart, nicht mehr, ordner, prozess, rar datei, rechner, registry, scan, security, sophos, sophos anti-rootkit, system, system32, tablet, temp, voll, windows, write




Ähnliche Themen: RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL


  1. Bedrohungen in Local\Temp Ordner gefunden - Windows Befehlsprozessor erfragt Erlaubnis
    Plagegeister aller Art und deren Bekämpfung - 10.03.2015 (12)
  2. Windows 7: Viren im Temp-Ordner
    Log-Analyse und Auswertung - 19.11.2014 (13)
  3. Windows 7: Unbekannte .exe Datei in Temp Ordner
    Plagegeister aller Art und deren Bekämpfung - 05.03.2014 (9)
  4. Sonderbarer Ordner im Win Temp Ordner
    Alles rund um Windows - 14.02.2014 (1)
  5. Windows 7 - Temp-Ordner verdächtiges Verhalten
    Log-Analyse und Auswertung - 11.01.2014 (18)
  6. TrojWare.Win32.Buzus.carj in C:\Windows\Temp\HInfo.exe bzw. C:\Windows\Temp\restart.exe
    Plagegeister aller Art und deren Bekämpfung - 27.09.2012 (2)
  7. Windows Live Trojaner und SVchost.exe im Temp-ordner
    Plagegeister aller Art und deren Bekämpfung - 26.12.2011 (1)
  8. TR/crypt.xpack.gen3 in Vista im Ordner c:\windows\temp\TMP....
    Plagegeister aller Art und deren Bekämpfung - 17.10.2010 (8)
  9. TR/Dropper.Gen im Windows\Temp Ordner
    Plagegeister aller Art und deren Bekämpfung - 01.07.2010 (1)
  10. Automatisch neue Ordner in Windows/Temp nach Trojan/Virusbefall
    Plagegeister aller Art und deren Bekämpfung - 27.05.2010 (2)
  11. SCREENSHOTS im Temp-Ordner
    Log-Analyse und Auswertung - 20.04.2010 (1)
  12. Windows Temp Ordner wächst und wächst...
    Mülltonne - 16.11.2008 (0)
  13. Trojaner generiert sich immer wieder neu im windows/temp ordner
    Log-Analyse und Auswertung - 21.07.2007 (8)
  14. mx_**.temp dateien in windows/temp ordner?
    Plagegeister aller Art und deren Bekämpfung - 27.06.2007 (1)
  15. Trojaner agent.age in Windows Temp Ordner
    Plagegeister aller Art und deren Bekämpfung - 16.02.2007 (7)
  16. Temp und Cache Ordner
    Alles rund um Windows - 10.03.2005 (7)
  17. mehrere GB grosser avast ordner unter windows/temp/_AVAST4_ normal ?
    Antiviren-, Firewall- und andere Schutzprogramme - 19.01.2005 (10)

Zum Thema RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - Danke, werd ich machen, nur gibt es Problemchen: EDIT: (Problem mit Zugriff auf Virenscanner gelöst, ist nun inaktiv) Combofix lädt sich runter, aber als Binary file, nicht als Ausführung exe - RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL...
Archiv
Du betrachtest: RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.