![]() |
25 verschiedene Trojaner bzw. Malware,Exploit und backdoor server! Ich habe gestern AntiVirus laufen lassen und am Ende war ich geschockt :eek: ich habe 25 Viren auf meinem PC!!!! Ich schreibe mal die einzelnen Details zu den Viren. Ich danke euch schonmal :zunge: EXP/JS.Expack.AT Exploit Level 2 11.11.2012 Mehr Infos 2 EXP/Pidief.dlm Exploit Level 2 10.11.2012 08.11.2012 3 BDS/Rabasheeta.A Backdoor Server Level 3 09.11.2012 13.10.2012 4 TR/ZAccess.AA Trojan Level 1 09.11.2012 23.10.2011 5 Adware/InstallBai.A Malware Level 1 08.11.2012 06.11.2012 6 ADWARE/Eorezo.AJ Malware Level 1 07.11.2012 05.11.2012 7 JAVA/Jogek.GN Malware Level 1 04.11.2012 02.11.2012 8 TR/Graftor.Elzob.16889.1 Trojan Level 1 04.11.2012 03.11.2012 9 EXP/2012-1723.FP Exploit Level 1 03.11.2012 16.10.2012 10 EXP/Pidief.dla Exploit Level 1 01.11.2012 30.10.2012 11 EXP/Pidief.dld Exploit Level 1 01.11.2012 30.10.2012 12 BOO/Vrabber.A Malware Level 1 31.10.2012 30.05.2012 13 HTML/IFrame.ame Malware Level 1 29.10.2012 Mehr Infos 14 Adware/InstallM.C.3 Malware Level 1 27.10.2012 24.10.2012 15 TR/Spy.Agent.153 Trojan Level 3 26.10.2012 23.10.2012 16 EXP/Pidief.dkm Exploit Level 2 26.10.2012 23.10.2012 17 Adware/PcMega.E.2 Malware Level 1 25.10.2012 23.10.2012 18 TR/Kazy.100152.7 Trojan Level 1 21.10.2012 17.10.2012 19 TR/Kazy.100147.3 Trojan Level 1 21.10.2012 16.10.2012 20 EXP/CVE-2010-0188.B Exploit Level 1 19.10.2012 08.10.2010 21 TR/Spy.Esdino.A Trojan Level 1 18.10.2012 17.10.2012 22 EXP/Pidief.dis Exploit Level 2 17.10.2012 16.10.2012 23 TR/Buzus.HL.2619 Trojan Level 2 17.10.2012 16.10.2012 24 TR/PSW.Tepfer.bhrm.1 Trojan Level 2 17.10.2012 16.10.2012 25 Java/Dldr.Kara.AN.1 Malware Level 1 17.10.2012 20.09.2012 |
:hallo: Eine Bereinigung ist mitunter mit viel Arbeit für Dich verbunden.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der Schnellere und immer der sicherste Weg. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis dir jemand vom Team sagt, dass Du clean bist. Vista und Win7 User Alle Tools mit Rechtsklick "als Administrator ausführen" starten. 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten. 2. Schritt Systemscan mit OTL (bebilderte Anleitung) |
Hey t'john,ich danke dir schonmal im voraus :) Komisch,Malwarebytes Anti-Malware sagt mir das ich null Viren auf meinem PC habe... Hier einmal der Text von Malwarebytes Anti-Malware: Malwarebytes Anti-Malware 1.65.1.1000 Malwarebytes : Free anti-malware download Datenbank Version: v2012.11.16.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Denny :: DENNY-PC [Administrator] 16.11.2012 19:41:38 mbam-log-2012-11-16 (19-41-38).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 371161 Laufzeit: 1 Stunde(n), 33 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
Poste die Logfiles nochmal! |
OTL Logfile: Code: OTL logfile created on: 16.11.2012 20:46:19 - Run 1 OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 16.11.2012 20:46:19 - Run 1 OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 16.11.2012 20:46:19 - Run 1 |
Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 4 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern mede dies bitte. 1. Schritt Scan mit Malwarebytes' Anti-Rootkit Download: Download - Malwarebytes Anti-Rootkit BETA Anleitung: Anleitung: Malwarebytes Anti-Rootkit 2. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 3. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 4. Schritt Downloade Dir bitte ![]()
|
Malwarebytes Anti-Rootkit 1.1.0.1009 Malwarebytes : Free anti-malware download Database version: v2012.11.18.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Denny :: DENNY-PC [administrator] 18.11.2012 10:58:20 mbar-log-2012-11-18 (10-58-20).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: PUP | PUM | P2P Objects scanned: 27401 Time elapsed: 7 minute(s), 11 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 2 C:\Windows\Installer\{93832d05-75e6-fdfc-982d-8cf84e7110f2}\L (Backdoor.0Access) -> Delete on reboot. [925f11a6a7b61422522f8878699738c8] C:\Windows\Installer\{93832d05-75e6-fdfc-982d-8cf84e7110f2}\U (Backdoor.0Access) -> Delete on reboot. [a849e2d5f06da78f80021ce4d9270af6] Files Detected: 0 (No malicious items detected) (end) All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. C:\Windows\SysWOW64\pbsvc (1).exe moved successfully. C:\ProgramData\ism_0_llatsni.pad moved successfully. C:\Users\Denny\AppData\Local\{93832d05-75e6-fdfc-982d-8cf84e7110f2}\@ moved successfully. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\*.dll not found. File\Folder C:\ProgramData\*.tmp not found. C:\ProgramData\Temp\{E3D04529-6EDB-11D8-A372-0050BAE317E1} folder moved successfully. C:\ProgramData\Temp\{E3739848-5329-48E3-8D28-5BBD6E8BE384} folder moved successfully. C:\ProgramData\Temp\{C59C179C-668D-49A9-B6EA-0121CCFC1243} folder moved successfully. C:\ProgramData\Temp\{72BF1DA0-2B00-4794-9173-159722019B74} folder moved successfully. C:\ProgramData\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41} folder moved successfully. C:\ProgramData\Temp\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5} folder moved successfully. C:\ProgramData\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658} folder moved successfully. C:\ProgramData\Temp\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3} folder moved successfully. C:\ProgramData\Temp\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} folder moved successfully. C:\ProgramData\Temp folder moved successfully. File\Folder C:\Users\Denny\*.tmp not found. C:\Users\Denny\AppData\Local\{62DCA54F-0812-4F5C-8755-42A146EAD7A8} folder moved successfully. C:\Users\Denny\AppData\Local\{6453C01D-FBF4-474E-8C48-29227CE1495F} folder moved successfully. C:\Users\Denny\AppData\Local\{93832d05-75e6-fdfc-982d-8cf84e7110f2}\U folder moved successfully. C:\Users\Denny\AppData\Local\{93832d05-75e6-fdfc-982d-8cf84e7110f2}\L folder moved successfully. C:\Users\Denny\AppData\Local\{93832d05-75e6-fdfc-982d-8cf84e7110f2} folder moved successfully. C:\Users\Denny\AppData\Local\{FC11A7EE-18E6-4668-913F-E2F1EE2A01FC} folder moved successfully. C:\Users\Denny\AppData\Local\Temp\sonarinst.exe moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Denny\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. File/Folder C:\Users\Denny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Denny\Desktop\cmd.bat deleted successfully. C:\Users\Denny\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56468 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Denny ->Temp folder emptied: 23086553 bytes ->Temporary Internet Files folder emptied: 23648536 bytes ->FireFox cache emptied: 332207568 bytes ->Google Chrome cache emptied: 208099916 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 79703 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56468 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 61325053 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 619,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 11182012_113223 Files\Folders moved on Reboot... C:\Users\Denny\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Denny\AppData\Local\Mozilla\Firefox\Profiles\d7r95x4y.default\Cache\_CACHE_001_ moved successfully. C:\Users\Denny\AppData\Local\Mozilla\Firefox\Profiles\d7r95x4y.default\Cache\_CACHE_002_ moved successfully. C:\Users\Denny\AppData\Local\Mozilla\Firefox\Profiles\d7r95x4y.default\Cache\_CACHE_003_ moved successfully. C:\Users\Denny\AppData\Local\Mozilla\Firefox\Profiles\d7r95x4y.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\Denny\AppData\Local\Mozilla\Firefox\Profiles\d7r95x4y.default\urlclassifier3.sqlite moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Schritt 3 und 4 ? |
kommen gleich,bin gerade dabei ^^ Malwarebytes Anti-Malware 1.65.1.1000 Malwarebytes : Free anti-malware download Datenbank Version: v2012.11.18.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Denny :: DENNY-PC [Administrator] 18.11.2012 11:56:23 mbam-log-2012-11-18 (11-56-23).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 359762 Laufzeit: 56 Minute(n), 10 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) # AdwCleaner v2.008 - Datei am 18/11/2012 um 12:54:44 erstellt # Aktualisiert am 17/11/2012 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : Denny - DENNY-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Denny\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\Users\Denny\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel Ordner Gelöscht : C:\Users\Denny\AppData\Roaming\Media Finder Ordner Gelöscht : C:\Users\Denny\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\MediaFinder Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Download with &Media Finder Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MF Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v16.0.2 (de) Profilname : default Datei : C:\Users\Denny\AppData\Roaming\Mozilla\Firefox\Profiles\d7r95x4y.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v [Version kann nicht ermittelt werden] Datei : C:\Users\Denny\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. -\\ Opera v [Version kann nicht ermittelt werden] Datei : C:\Users\Denny\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [2089 octets] - [18/11/2012 12:54:44] ########## EOF - C:\AdwCleaner[S1].txt - [2149 octets] ########## |
Sehr gut! :daumenhoc Wie laeuft der Rechner? TDSSKiller von Kaspersky - Lade den TDSSKiller und entpacke das Archiv auf Deinen Desktop.Hier findest Du eine ausführlichere TDSSKiller Anleitung. danach Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
18:28:26.0483 5288 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 18:28:26.0813 5288 ============================================================ 18:28:26.0813 5288 Current date / time: 2012/11/19 18:28:26.0813 18:28:26.0813 5288 SystemInfo: 18:28:26.0813 5288 18:28:26.0813 5288 OS Version: 6.1.7601 ServicePack: 1.0 18:28:26.0813 5288 Product type: Workstation 18:28:26.0813 5288 ComputerName: DENNY-PC 18:28:26.0823 5288 UserName: Denny 18:28:26.0823 5288 Windows directory: C:\Windows 18:28:26.0823 5288 System windows directory: C:\Windows 18:28:26.0823 5288 Running under WOW64 18:28:26.0823 5288 Processor architecture: Intel x64 18:28:26.0823 5288 Number of processors: 4 18:28:26.0823 5288 Page size: 0x1000 18:28:26.0823 5288 Boot type: Normal boot 18:28:26.0823 5288 ============================================================ 18:28:27.0193 5288 Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 18:28:27.0223 5288 ============================================================ 18:28:27.0223 5288 \Device\Harddisk0\DR0: 18:28:27.0223 5288 MBR partitions: 18:28:27.0223 5288 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 18:28:27.0223 5288 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xE27D5800 18:28:27.0223 5288 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xE2808000, BlocksNum 0x6400000 18:28:27.0223 5288 ============================================================ 18:28:27.0253 5288 C: <-> \Device\Harddisk0\DR0\Partition2 18:28:27.0343 5288 D: <-> \Device\Harddisk0\DR0\Partition3 18:28:27.0343 5288 ============================================================ 18:28:27.0343 5288 Initialize success 18:28:27.0343 5288 ============================================================ 18:28:32.0241 3392 ============================================================ 18:28:32.0241 3392 Scan started 18:28:32.0241 3392 Mode: Manual; SigCheck; TDLFS; 18:28:32.0241 3392 ============================================================ 18:28:32.0351 3392 ================ Scan system memory ======================== 18:28:32.0351 3392 System memory - ok 18:28:32.0351 3392 ================ Scan services ============================= 18:28:32.0460 3392 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 18:28:32.0522 3392 1394ohci - ok 18:28:32.0663 3392 [ B33CF4DE909A5B30F526D82053A63C8E ] ABBYY.Licensing.FineReader.Sprint.9.0 C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe 18:28:32.0694 3392 ABBYY.Licensing.FineReader.Sprint.9.0 - ok 18:28:32.0725 3392 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 18:28:32.0741 3392 ACPI - ok 18:28:32.0772 3392 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 18:28:32.0788 3392 AcpiPmi - ok 18:28:32.0850 3392 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 18:28:32.0866 3392 AdobeARMservice - ok 18:28:32.0944 3392 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 18:28:32.0959 3392 AdobeFlashPlayerUpdateSvc - ok 18:28:33.0006 3392 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 18:28:33.0022 3392 adp94xx - ok 18:28:33.0053 3392 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 18:28:33.0068 3392 adpahci - ok 18:28:33.0100 3392 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 18:28:33.0100 3392 adpu320 - ok 18:28:33.0131 3392 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 18:28:33.0178 3392 AeLookupSvc - ok 18:28:33.0209 3392 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 18:28:33.0224 3392 AFD - ok 18:28:33.0240 3392 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 18:28:33.0256 3392 agp440 - ok 18:28:33.0271 3392 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 18:28:33.0287 3392 ALG - ok 18:28:33.0302 3392 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 18:28:33.0318 3392 aliide - ok 18:28:33.0334 3392 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 18:28:33.0334 3392 amdide - ok 18:28:33.0349 3392 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 18:28:33.0365 3392 AmdK8 - ok 18:28:33.0365 3392 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 18:28:33.0365 3392 AmdPPM - ok 18:28:33.0396 3392 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 18:28:33.0396 3392 amdsata - ok 18:28:33.0412 3392 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 18:28:33.0427 3392 amdsbs - ok 18:28:33.0443 3392 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 18:28:33.0458 3392 amdxata - ok 18:28:33.0536 3392 [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 18:28:33.0552 3392 AntiVirSchedulerService - ok 18:28:33.0552 3392 [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 18:28:33.0568 3392 AntiVirService - ok 18:28:33.0583 3392 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 18:28:33.0614 3392 AppID - ok 18:28:33.0630 3392 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 18:28:33.0661 3392 AppIDSvc - ok 18:28:33.0677 3392 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 18:28:33.0692 3392 Appinfo - ok 18:28:33.0724 3392 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 18:28:33.0739 3392 arc - ok 18:28:33.0739 3392 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 18:28:33.0755 3392 arcsas - ok 18:28:33.0786 3392 [ 0AA7A996792FB0287B33A57A8093AE44 ] asmthub3 C:\Windows\system32\drivers\asmthub3.sys 18:28:33.0817 3392 asmthub3 - ok 18:28:33.0833 3392 [ 125DC3ABF5BFCCFE82AD17D078E0B9EC ] asmtxhci C:\Windows\system32\drivers\asmtxhci.sys 18:28:33.0848 3392 asmtxhci - ok 18:28:33.0864 3392 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 18:28:33.0895 3392 AsyncMac - ok 18:28:33.0926 3392 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 18:28:33.0926 3392 atapi - ok 18:28:33.0958 3392 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 18:28:33.0989 3392 AudioEndpointBuilder - ok 18:28:33.0989 3392 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 18:28:34.0020 3392 AudioSrv - ok 18:28:34.0067 3392 [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 18:28:34.0067 3392 avgntflt - ok 18:28:34.0098 3392 [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 18:28:34.0098 3392 avipbb - ok 18:28:34.0114 3392 [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 18:28:34.0114 3392 avkmgr - ok 18:28:34.0145 3392 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 18:28:34.0160 3392 AxInstSV - ok 18:28:34.0238 3392 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 18:28:34.0254 3392 b06bdrv - ok 18:28:34.0285 3392 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 18:28:34.0301 3392 b57nd60a - ok 18:28:34.0316 3392 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 18:28:34.0332 3392 BDESVC - ok 18:28:34.0348 3392 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 18:28:34.0394 3392 Beep - ok 18:28:34.0410 3392 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 18:28:34.0441 3392 BFE - ok 18:28:34.0472 3392 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 18:28:34.0504 3392 BITS - ok 18:28:34.0535 3392 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 18:28:34.0535 3392 blbdrive - ok 18:28:34.0550 3392 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 18:28:34.0566 3392 bowser - ok 18:28:34.0597 3392 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 18:28:34.0597 3392 BrFiltLo - ok 18:28:34.0613 3392 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 18:28:34.0628 3392 BrFiltUp - ok 18:28:34.0675 3392 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 18:28:34.0706 3392 BridgeMP - ok 18:28:34.0738 3392 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 18:28:34.0753 3392 Browser - ok 18:28:34.0769 3392 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 18:28:34.0784 3392 Brserid - ok 18:28:34.0800 3392 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 18:28:34.0800 3392 BrSerWdm - ok 18:28:34.0831 3392 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 18:28:34.0847 3392 BrUsbMdm - ok 18:28:34.0847 3392 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 18:28:34.0862 3392 BrUsbSer - ok 18:28:34.0894 3392 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 18:28:34.0894 3392 BTHMODEM - ok 18:28:34.0925 3392 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 18:28:34.0956 3392 bthserv - ok 18:28:34.0987 3392 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 18:28:35.0034 3392 cdfs - ok 18:28:35.0081 3392 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 18:28:35.0081 3392 cdrom - ok 18:28:35.0096 3392 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 18:28:35.0128 3392 CertPropSvc - ok 18:28:35.0143 3392 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 18:28:35.0159 3392 circlass - ok 18:28:35.0174 3392 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 18:28:35.0190 3392 CLFS - ok 18:28:35.0268 3392 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:28:35.0268 3392 clr_optimization_v2.0.50727_32 - ok 18:28:35.0315 3392 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 18:28:35.0315 3392 clr_optimization_v2.0.50727_64 - ok 18:28:35.0393 3392 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 18:28:35.0408 3392 clr_optimization_v4.0.30319_32 - ok 18:28:35.0424 3392 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 18:28:35.0440 3392 clr_optimization_v4.0.30319_64 - ok 18:28:35.0455 3392 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 18:28:35.0471 3392 CmBatt - ok 18:28:35.0502 3392 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 18:28:35.0518 3392 cmdide - ok 18:28:35.0549 3392 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 18:28:35.0580 3392 CNG - ok 18:28:35.0596 3392 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 18:28:35.0611 3392 Compbatt - ok 18:28:35.0627 3392 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 18:28:35.0642 3392 CompositeBus - ok 18:28:35.0642 3392 COMSysApp - ok 18:28:35.0674 3392 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 18:28:35.0674 3392 crcdisk - ok 18:28:35.0736 3392 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 18:28:35.0752 3392 CryptSvc - ok 18:28:35.0814 3392 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 18:28:35.0830 3392 cvhsvc - ok 18:28:35.0861 3392 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 18:28:35.0892 3392 DcomLaunch - ok 18:28:35.0908 3392 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 18:28:35.0939 3392 defragsvc - ok 18:28:35.0954 3392 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 18:28:35.0970 3392 DfsC - ok 18:28:36.0001 3392 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 18:28:36.0001 3392 Dhcp - ok 18:28:36.0017 3392 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 18:28:36.0048 3392 discache - ok 18:28:36.0079 3392 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 18:28:36.0079 3392 Disk - ok 18:28:36.0110 3392 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 18:28:36.0126 3392 Dnscache - ok 18:28:36.0142 3392 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 18:28:36.0173 3392 dot3svc - ok 18:28:36.0188 3392 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 18:28:36.0220 3392 DPS - ok 18:28:36.0235 3392 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 18:28:36.0251 3392 drmkaud - ok 18:28:36.0266 3392 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 18:28:36.0282 3392 DXGKrnl - ok 18:28:36.0298 3392 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 18:28:36.0329 3392 EapHost - ok 18:28:36.0376 3392 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 18:28:36.0407 3392 ebdrv - ok 18:28:36.0438 3392 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 18:28:36.0438 3392 EFS - ok 18:28:36.0500 3392 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 18:28:36.0516 3392 ehRecvr - ok 18:28:36.0532 3392 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 18:28:36.0547 3392 ehSched - ok 18:28:36.0578 3392 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 18:28:36.0594 3392 elxstor - ok 18:28:36.0656 3392 [ 7C5BFAAC8DCE7292B0C04EBF892E71F9 ] EPSON_EB_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE 18:28:36.0672 3392 EPSON_EB_RPCV4_04 - ok 18:28:36.0672 3392 [ D4615670CD49A1679E6067F155C47C68 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE 18:28:36.0688 3392 EPSON_PM_RPCV4_04 - ok 18:28:36.0719 3392 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 18:28:36.0734 3392 ErrDev - ok 18:28:36.0750 3392 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 18:28:36.0797 3392 EventSystem - ok 18:28:36.0828 3392 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 18:28:36.0859 3392 exfat - ok 18:28:36.0890 3392 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 18:28:36.0922 3392 fastfat - ok 18:28:36.0953 3392 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 18:28:36.0968 3392 Fax - ok 18:28:37.0015 3392 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 18:28:37.0031 3392 fdc - ok 18:28:37.0031 3392 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 18:28:37.0078 3392 fdPHost - ok 18:28:37.0093 3392 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 18:28:37.0124 3392 FDResPub - ok 18:28:37.0171 3392 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 18:28:37.0187 3392 FileInfo - ok 18:28:37.0202 3392 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 18:28:37.0234 3392 Filetrace - ok 18:28:37.0265 3392 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 18:28:37.0265 3392 flpydisk - ok 18:28:37.0280 3392 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 18:28:37.0296 3392 FltMgr - ok 18:28:37.0327 3392 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 18:28:37.0343 3392 FontCache - ok 18:28:37.0374 3392 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 18:28:37.0390 3392 FontCache3.0.0.0 - ok 18:28:37.0405 3392 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 18:28:37.0421 3392 FsDepends - ok 18:28:37.0436 3392 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 18:28:37.0436 3392 Fs_Rec - ok 18:28:37.0468 3392 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 18:28:37.0483 3392 fvevol - ok 18:28:37.0499 3392 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 18:28:37.0514 3392 gagp30kx - ok 18:28:37.0530 3392 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 18:28:37.0561 3392 gpsvc - ok 18:28:37.0608 3392 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:28:37.0608 3392 gupdate - ok 18:28:37.0624 3392 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:28:37.0639 3392 gupdatem - ok 18:28:37.0686 3392 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 18:28:37.0686 3392 gusvc - ok 18:28:37.0717 3392 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 18:28:37.0733 3392 hcw85cir - ok 18:28:37.0764 3392 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 18:28:37.0795 3392 HdAudAddService - ok 18:28:37.0811 3392 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 18:28:37.0826 3392 HDAudBus - ok 18:28:37.0842 3392 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 18:28:37.0858 3392 HidBatt - ok 18:28:37.0873 3392 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 18:28:37.0889 3392 HidBth - ok 18:28:37.0920 3392 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 18:28:37.0936 3392 HidIr - ok 18:28:37.0936 3392 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 18:28:37.0982 3392 hidserv - ok 18:28:38.0014 3392 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 18:28:38.0014 3392 HidUsb - ok 18:28:38.0045 3392 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 18:28:38.0076 3392 hkmsvc - ok 18:28:38.0092 3392 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 18:28:38.0107 3392 HomeGroupListener - ok 18:28:38.0123 3392 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 18:28:38.0138 3392 HomeGroupProvider - ok 18:28:38.0154 3392 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 18:28:38.0154 3392 HpSAMD - ok 18:28:38.0185 3392 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 18:28:38.0216 3392 HTTP - ok 18:28:38.0248 3392 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 18:28:38.0248 3392 hwpolicy - ok 18:28:38.0294 3392 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 18:28:38.0294 3392 i8042prt - ok 18:28:38.0326 3392 [ 26CF4275034214ECEDD8EC17B0A18A99 ] iaStor C:\Windows\system32\drivers\iaStor.sys 18:28:38.0341 3392 iaStor - ok 18:28:38.0388 3392 [ E79A8E33BD136D14BAE1FA20EB2EF124 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 18:28:38.0388 3392 IAStorDataMgrSvc - ok 18:28:38.0419 3392 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 18:28:38.0450 3392 iaStorV - ok 18:28:38.0497 3392 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 18:28:38.0513 3392 idsvc - ok 18:28:38.0638 3392 [ A87261EF1546325B559374F5689CF5BC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 18:28:38.0684 3392 igfx - ok 18:28:38.0700 3392 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 18:28:38.0700 3392 iirsp - ok 18:28:38.0747 3392 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 18:28:38.0778 3392 IKEEXT - ok 18:28:38.0856 3392 [ 8F6ED52134EBB4CE2953EC37C9275497 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 18:28:38.0903 3392 IntcAzAudAddService - ok 18:28:38.0918 3392 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 18:28:38.0918 3392 intelide - ok 18:28:38.0950 3392 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 18:28:38.0950 3392 intelppm - ok 18:28:38.0965 3392 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 18:28:38.0981 3392 IPBusEnum - ok 18:28:38.0996 3392 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 18:28:39.0028 3392 IpFilterDriver - ok 18:28:39.0043 3392 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 18:28:39.0059 3392 IPMIDRV - ok 18:28:39.0074 3392 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 18:28:39.0106 3392 IPNAT - ok 18:28:39.0106 3392 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 18:28:39.0121 3392 IRENUM - ok 18:28:39.0137 3392 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 18:28:39.0137 3392 isapnp - ok 18:28:39.0168 3392 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 18:28:39.0168 3392 iScsiPrt - ok 18:28:39.0199 3392 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 18:28:39.0215 3392 kbdclass - ok 18:28:39.0230 3392 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 18:28:39.0246 3392 kbdhid - ok 18:28:39.0262 3392 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 18:28:39.0262 3392 KeyIso - ok 18:28:39.0277 3392 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 18:28:39.0293 3392 KSecDD - ok 18:28:39.0308 3392 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 18:28:39.0324 3392 KSecPkg - ok 18:28:39.0324 3392 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 18:28:39.0355 3392 ksthunk - ok 18:28:39.0402 3392 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 18:28:39.0433 3392 KtmRm - ok 18:28:39.0449 3392 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 18:28:39.0464 3392 LanmanServer - ok 18:28:39.0480 3392 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 18:28:39.0511 3392 LanmanWorkstation - ok 18:28:39.0511 3392 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 18:28:39.0542 3392 lltdio - ok 18:28:39.0558 3392 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 18:28:39.0574 3392 lltdsvc - ok 18:28:39.0589 3392 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 18:28:39.0620 3392 lmhosts - ok 18:28:39.0652 3392 [ 1584DEEAE5AA0E3FB045F3D0EAC585EA ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 18:28:39.0667 3392 LMS - ok 18:28:39.0683 3392 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 18:28:39.0698 3392 LSI_FC - ok 18:28:39.0714 3392 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 18:28:39.0730 3392 LSI_SAS - ok 18:28:39.0745 3392 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 18:28:39.0761 3392 LSI_SAS2 - ok 18:28:39.0792 3392 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 18:28:39.0792 3392 LSI_SCSI - ok 18:28:39.0808 3392 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 18:28:39.0839 3392 luafv - ok 18:28:39.0901 3392 [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 18:28:39.0917 3392 MBAMProtector - ok 18:28:39.0948 3392 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 18:28:39.0964 3392 MBAMScheduler - ok 18:28:39.0979 3392 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 18:28:39.0995 3392 MBAMService - ok 18:28:40.0042 3392 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 18:28:40.0057 3392 Mcx2Svc - ok 18:28:40.0073 3392 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 18:28:40.0073 3392 megasas - ok 18:28:40.0088 3392 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 18:28:40.0120 3392 MegaSR - ok 18:28:40.0135 3392 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\drivers\HECIx64.sys 18:28:40.0151 3392 MEIx64 - ok 18:28:40.0166 3392 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 18:28:40.0198 3392 MMCSS - ok 18:28:40.0213 3392 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 18:28:40.0229 3392 Modem - ok 18:28:40.0244 3392 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 18:28:40.0260 3392 monitor - ok 18:28:40.0307 3392 [ FC44AD48746FFA5FD640EF1260AB5EC2 ] MotioninJoyXFilter C:\Windows\system32\DRIVERS\MijXfilt.sys 18:28:40.0307 3392 MotioninJoyXFilter - ok 18:28:40.0338 3392 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 18:28:40.0338 3392 mouclass - ok 18:28:40.0354 3392 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 18:28:40.0369 3392 mouhid - ok 18:28:40.0385 3392 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 18:28:40.0400 3392 mountmgr - ok 18:28:40.0416 3392 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 18:28:40.0432 3392 MozillaMaintenance - ok 18:28:40.0447 3392 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 18:28:40.0463 3392 mpio - ok 18:28:40.0478 3392 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 18:28:40.0525 3392 mpsdrv - ok 18:28:40.0541 3392 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 18:28:40.0556 3392 MRxDAV - ok 18:28:40.0588 3392 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 18:28:40.0603 3392 mrxsmb - ok 18:28:40.0619 3392 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 18:28:40.0634 3392 mrxsmb10 - ok 18:28:40.0650 3392 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 18:28:40.0666 3392 mrxsmb20 - ok 18:28:40.0697 3392 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 18:28:40.0712 3392 msahci - ok 18:28:40.0728 3392 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 18:28:40.0744 3392 msdsm - ok 18:28:40.0775 3392 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 18:28:40.0775 3392 MSDTC - ok 18:28:40.0790 3392 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 18:28:40.0822 3392 Msfs - ok 18:28:40.0837 3392 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 18:28:40.0868 3392 mshidkmdf - ok 18:28:40.0900 3392 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 18:28:40.0900 3392 msisadrv - ok 18:28:40.0931 3392 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 18:28:40.0946 3392 MSiSCSI - ok 18:28:40.0946 3392 msiserver - ok 18:28:40.0978 3392 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 18:28:40.0993 3392 MSKSSRV - ok 18:28:41.0009 3392 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 18:28:41.0040 3392 MSPCLOCK - ok 18:28:41.0040 3392 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 18:28:41.0071 3392 MSPQM - ok 18:28:41.0087 3392 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 18:28:41.0102 3392 MsRPC - ok 18:28:41.0118 3392 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 18:28:41.0118 3392 mssmbios - ok 18:28:41.0134 3392 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 18:28:41.0165 3392 MSTEE - ok 18:28:41.0180 3392 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 18:28:41.0180 3392 MTConfig - ok 18:28:41.0243 3392 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 18:28:41.0243 3392 Mup - ok 18:28:41.0274 3392 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 18:28:41.0305 3392 napagent - ok 18:28:41.0336 3392 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 18:28:41.0352 3392 NativeWifiP - ok 18:28:41.0383 3392 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 18:28:41.0399 3392 NDIS - ok 18:28:41.0414 3392 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 18:28:41.0446 3392 NdisCap - ok 18:28:41.0446 3392 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 18:28:41.0477 3392 NdisTapi - ok 18:28:41.0477 3392 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 18:28:41.0492 3392 Ndisuio - ok 18:28:41.0508 3392 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 18:28:41.0539 3392 NdisWan - ok 18:28:41.0539 3392 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 18:28:41.0570 3392 NDProxy - ok 18:28:41.0570 3392 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 18:28:41.0602 3392 NetBIOS - ok 18:28:41.0617 3392 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 18:28:41.0633 3392 NetBT - ok 18:28:41.0633 3392 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 18:28:41.0648 3392 Netlogon - ok 18:28:41.0680 3392 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 18:28:41.0695 3392 Netman - ok 18:28:41.0711 3392 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 18:28:41.0742 3392 netprofm - ok 18:28:41.0742 3392 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 18:28:41.0758 3392 NetTcpPortSharing - ok 18:28:41.0773 3392 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 18:28:41.0789 3392 nfrd960 - ok 18:28:41.0820 3392 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 18:28:41.0836 3392 NlaSvc - ok 18:28:41.0851 3392 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 18:28:41.0882 3392 Npfs - ok 18:28:41.0898 3392 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 18:28:41.0914 3392 nsi - ok 18:28:41.0914 3392 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 18:28:41.0945 3392 nsiproxy - ok 18:28:41.0976 3392 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 18:28:41.0992 3392 Ntfs - ok 18:28:42.0007 3392 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 18:28:42.0023 3392 Null - ok 18:28:42.0070 3392 [ 10204955027011E08A9DC27737A48A54 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 18:28:42.0070 3392 NVHDA - ok 18:28:42.0304 3392 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 18:28:42.0460 3392 nvlddmkm - ok 18:28:42.0491 3392 nvpciflt - ok 18:28:42.0522 3392 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 18:28:42.0538 3392 nvraid - ok 18:28:42.0538 3392 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 18:28:42.0553 3392 nvstor - ok 18:28:42.0584 3392 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe 18:28:42.0600 3392 nvsvc - ok 18:28:42.0678 3392 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 18:28:42.0709 3392 nvUpdatusService - ok 18:28:42.0740 3392 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 18:28:42.0756 3392 nv_agp - ok 18:28:42.0772 3392 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 18:28:42.0787 3392 ohci1394 - ok 18:28:42.0850 3392 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 18:28:42.0850 3392 ose - ok 18:28:42.0959 3392 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 18:28:43.0021 3392 osppsvc - ok 18:28:43.0037 3392 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 18:28:43.0052 3392 p2pimsvc - ok 18:28:43.0068 3392 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 18:28:43.0084 3392 p2psvc - ok 18:28:43.0115 3392 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 18:28:43.0115 3392 Parport - ok 18:28:43.0146 3392 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 18:28:43.0146 3392 partmgr - ok 18:28:43.0162 3392 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 18:28:43.0177 3392 PcaSvc - ok 18:28:43.0193 3392 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 18:28:43.0193 3392 pci - ok 18:28:43.0208 3392 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 18:28:43.0208 3392 pciide - ok 18:28:43.0240 3392 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 18:28:43.0240 3392 pcmcia - ok 18:28:43.0271 3392 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 18:28:43.0286 3392 pcw - ok 18:28:43.0302 3392 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 18:28:43.0318 3392 PEAUTH - ok 18:28:43.0364 3392 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 18:28:43.0364 3392 PerfHost - ok 18:28:43.0411 3392 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 18:28:43.0458 3392 pla - ok 18:28:43.0474 3392 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 18:28:43.0489 3392 PlugPlay - ok 18:28:43.0505 3392 PnkBstrA - ok 18:28:43.0520 3392 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 18:28:43.0536 3392 PNRPAutoReg - ok 18:28:43.0552 3392 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 18:28:43.0567 3392 PNRPsvc - ok 18:28:43.0598 3392 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 18:28:43.0630 3392 PolicyAgent - ok 18:28:43.0645 3392 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 18:28:43.0676 3392 Power - ok 18:28:43.0708 3392 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 18:28:43.0723 3392 PptpMiniport - ok 18:28:43.0739 3392 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 18:28:43.0739 3392 Processor - ok 18:28:43.0754 3392 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 18:28:43.0770 3392 ProfSvc - ok 18:28:43.0786 3392 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 18:28:43.0786 3392 ProtectedStorage - ok 18:28:43.0817 3392 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 18:28:43.0832 3392 Psched - ok 18:28:43.0864 3392 [ 543A4EF0923BF70D126625B034EF25AF ] PSI_SVC_2 c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe 18:28:43.0879 3392 PSI_SVC_2 - ok 18:28:43.0926 3392 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 18:28:43.0973 3392 ql2300 - ok 18:28:44.0020 3392 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 18:28:44.0020 3392 ql40xx - ok 18:28:44.0051 3392 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 18:28:44.0066 3392 QWAVE - ok 18:28:44.0082 3392 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 18:28:44.0098 3392 QWAVEdrv - ok 18:28:44.0113 3392 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 18:28:44.0144 3392 RasAcd - ok 18:28:44.0160 3392 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 18:28:44.0176 3392 RasAgileVpn - ok 18:28:44.0191 3392 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 18:28:44.0222 3392 RasAuto - ok 18:28:44.0222 3392 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 18:28:44.0254 3392 Rasl2tp - ok 18:28:44.0285 3392 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 18:28:44.0300 3392 RasMan - ok 18:28:44.0316 3392 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 18:28:44.0347 3392 RasPppoe - ok 18:28:44.0363 3392 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 18:28:44.0394 3392 RasSstp - ok 18:28:44.0410 3392 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 18:28:44.0425 3392 rdbss - ok 18:28:44.0456 3392 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys 18:28:44.0456 3392 rdpbus - ok 18:28:44.0488 3392 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 18:28:44.0503 3392 RDPCDD - ok 18:28:44.0519 3392 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 18:28:44.0534 3392 RDPENCDD - ok 18:28:44.0550 3392 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 18:28:44.0566 3392 RDPREFMP - ok 18:28:44.0597 3392 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 18:28:44.0597 3392 RDPWD - ok 18:28:44.0612 3392 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 18:28:44.0628 3392 rdyboost - ok 18:28:44.0644 3392 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 18:28:44.0659 3392 RemoteAccess - ok 18:28:44.0675 3392 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 18:28:44.0690 3392 RemoteRegistry - ok 18:28:44.0722 3392 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 18:28:44.0737 3392 RpcEptMapper - ok 18:28:44.0753 3392 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 18:28:44.0753 3392 RpcLocator - ok 18:28:44.0784 3392 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 18:28:44.0831 3392 RpcSs - ok 18:28:44.0831 3392 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 18:28:44.0862 3392 rspndr - ok 18:28:44.0893 3392 [ E50CFB92986DCAB49DE93788FD695813 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 18:28:44.0893 3392 RTL8167 - ok 18:28:44.0940 3392 [ B3F36B4B3F192EA87DDC119F3A0B3E45 ] RTL8192su C:\Windows\system32\DRIVERS\RTL8192su.sys 18:28:44.0956 3392 RTL8192su - ok 18:28:44.0971 3392 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 18:28:44.0971 3392 SamSs - ok 18:28:45.0002 3392 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 18:28:45.0002 3392 sbp2port - ok 18:28:45.0018 3392 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 18:28:45.0034 3392 SCardSvr - ok 18:28:45.0049 3392 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 18:28:45.0080 3392 scfilter - ok 18:28:45.0096 3392 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 18:28:45.0127 3392 Schedule - ok 18:28:45.0143 3392 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 18:28:45.0158 3392 SCPolicySvc - ok 18:28:45.0174 3392 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 18:28:45.0174 3392 SDRSVC - ok 18:28:45.0205 3392 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 18:28:45.0221 3392 secdrv - ok 18:28:45.0236 3392 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 18:28:45.0268 3392 seclogon - ok 18:28:45.0283 3392 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 18:28:45.0299 3392 SENS - ok 18:28:45.0314 3392 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 18:28:45.0330 3392 SensrSvc - ok 18:28:45.0361 3392 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys 18:28:45.0361 3392 Serenum - ok 18:28:45.0392 3392 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys 18:28:45.0408 3392 Serial - ok 18:28:45.0439 3392 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 18:28:45.0455 3392 sermouse - ok 18:28:45.0470 3392 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 18:28:45.0502 3392 SessionEnv - ok 18:28:45.0517 3392 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 18:28:45.0533 3392 sffdisk - ok 18:28:45.0548 3392 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 18:28:45.0564 3392 sffp_mmc - ok 18:28:45.0595 3392 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 18:28:45.0611 3392 sffp_sd - ok 18:28:45.0642 3392 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 18:28:45.0658 3392 sfloppy - ok 18:28:45.0689 3392 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 18:28:45.0704 3392 Sftfs - ok 18:28:45.0767 3392 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 18:28:45.0782 3392 sftlist - ok 18:28:45.0798 3392 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 18:28:45.0814 3392 Sftplay - ok 18:28:45.0829 3392 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 18:28:45.0829 3392 Sftredir - ok 18:28:45.0845 3392 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 18:28:45.0860 3392 Sftvol - ok 18:28:45.0876 3392 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 18:28:45.0892 3392 sftvsa - ok 18:28:45.0907 3392 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 18:28:45.0954 3392 ShellHWDetection - ok 18:28:45.0985 3392 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 18:28:46.0001 3392 SiSRaid2 - ok 18:28:46.0032 3392 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 18:28:46.0048 3392 SiSRaid4 - ok 18:28:46.0079 3392 [ 01ACB9228C303DE1FFF82B807D28B2B0 ] skfiltv C:\Windows\system32\drivers\skfiltv.sys 18:28:46.0094 3392 skfiltv - ok 18:28:46.0141 3392 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 18:28:46.0172 3392 Smb - ok 18:28:46.0188 3392 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 18:28:46.0204 3392 SNMPTRAP - ok 18:28:46.0219 3392 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 18:28:46.0219 3392 spldr - ok 18:28:46.0250 3392 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 18:28:46.0266 3392 Spooler - ok 18:28:46.0313 3392 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 18:28:46.0360 3392 sppsvc - ok 18:28:46.0375 3392 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 18:28:46.0391 3392 sppuinotify - ok 18:28:46.0406 3392 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 18:28:46.0422 3392 srv - ok 18:28:46.0453 3392 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 18:28:46.0453 3392 srv2 - ok 18:28:46.0469 3392 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 18:28:46.0484 3392 srvnet - ok 18:28:46.0500 3392 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 18:28:46.0547 3392 SSDPSRV - ok 18:28:46.0562 3392 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 18:28:46.0578 3392 SstpSvc - ok 18:28:46.0672 3392 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 18:28:46.0703 3392 Stereo Service - ok 18:28:46.0718 3392 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 18:28:46.0734 3392 stexstor - ok 18:28:46.0765 3392 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 18:28:46.0796 3392 stisvc - ok 18:28:46.0812 3392 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 18:28:46.0828 3392 swenum - ok 18:28:46.0859 3392 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 18:28:46.0906 3392 swprv - ok 18:28:46.0937 3392 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 18:28:46.0984 3392 SysMain - ok 18:28:46.0999 3392 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 18:28:47.0015 3392 TabletInputService - ok 18:28:47.0030 3392 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 18:28:47.0046 3392 TapiSrv - ok 18:28:47.0062 3392 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 18:28:47.0093 3392 TBS - ok 18:28:47.0124 3392 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 18:28:47.0155 3392 Tcpip - ok 18:28:47.0171 3392 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 18:28:47.0202 3392 TCPIP6 - ok 18:28:47.0202 3392 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 18:28:47.0218 3392 tcpipreg - ok 18:28:47.0233 3392 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 18:28:47.0233 3392 TDPIPE - ok 18:28:47.0249 3392 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 18:28:47.0264 3392 TDTCP - ok 18:28:47.0296 3392 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 18:28:47.0342 3392 tdx - ok 18:28:47.0358 3392 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 18:28:47.0374 3392 TermDD - ok 18:28:47.0405 3392 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 18:28:47.0420 3392 TermService - ok 18:28:47.0452 3392 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 18:28:47.0467 3392 Themes - ok 18:28:47.0467 3392 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 18:28:47.0498 3392 THREADORDER - ok 18:28:47.0498 3392 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 18:28:47.0530 3392 TrkWks - ok 18:28:47.0561 3392 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 18:28:47.0608 3392 TrustedInstaller - ok 18:28:47.0623 3392 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 18:28:47.0654 3392 tssecsrv - ok 18:28:47.0670 3392 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 18:28:47.0686 3392 TsUsbFlt - ok 18:28:47.0717 3392 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 18:28:47.0717 3392 TsUsbGD - ok 18:28:47.0732 3392 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 18:28:47.0764 3392 tunnel - ok 18:28:47.0764 3392 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 18:28:47.0779 3392 uagp35 - ok 18:28:47.0795 3392 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 18:28:47.0810 3392 udfs - ok 18:28:47.0826 3392 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 18:28:47.0842 3392 UI0Detect - ok 18:28:47.0873 3392 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 18:28:47.0888 3392 uliagpkx - ok 18:28:47.0888 3392 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 18:28:47.0904 3392 umbus - ok 18:28:47.0935 3392 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 18:28:47.0951 3392 UmPass - ok 18:28:48.0029 3392 [ FC43877B4625F6EB773C98233EB625C5 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 18:28:48.0076 3392 UNS - ok 18:28:48.0091 3392 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 18:28:48.0107 3392 upnphost - ok 18:28:48.0122 3392 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 18:28:48.0138 3392 usbaudio - ok 18:28:48.0169 3392 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 18:28:48.0185 3392 usbccgp - ok 18:28:48.0200 3392 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 18:28:48.0216 3392 usbcir - ok 18:28:48.0247 3392 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 18:28:48.0263 3392 usbehci - ok 18:28:48.0310 3392 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\drivers\usbhub.sys 18:28:48.0325 3392 usbhub - ok 18:28:48.0325 3392 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 18:28:48.0341 3392 usbohci - ok 18:28:48.0356 3392 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 18:28:48.0372 3392 usbprint - ok 18:28:48.0388 3392 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 18:28:48.0403 3392 usbscan - ok 18:28:48.0419 3392 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 18:28:48.0419 3392 USBSTOR - ok 18:28:48.0450 3392 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 18:28:48.0450 3392 usbuhci - ok 18:28:48.0497 3392 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 18:28:48.0512 3392 usbvideo - ok 18:28:48.0528 3392 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 18:28:48.0559 3392 UxSms - ok 18:28:48.0559 3392 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 18:28:48.0575 3392 VaultSvc - ok 18:28:48.0622 3392 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 18:28:48.0622 3392 vdrvroot - ok 18:28:48.0653 3392 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 18:28:48.0684 3392 vds - ok 18:28:48.0700 3392 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 18:28:48.0715 3392 vga - ok 18:28:48.0731 3392 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 18:28:48.0762 3392 VgaSave - ok 18:28:48.0793 3392 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 18:28:48.0793 3392 vhdmp - ok 18:28:48.0809 3392 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 18:28:48.0824 3392 viaide - ok 18:28:48.0840 3392 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 18:28:48.0856 3392 volmgr - ok 18:28:48.0871 3392 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 18:28:48.0871 3392 volmgrx - ok 18:28:48.0902 3392 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 18:28:48.0902 3392 volsnap - ok 18:28:48.0934 3392 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 18:28:48.0949 3392 vsmraid - ok 18:28:48.0980 3392 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 18:28:49.0012 3392 VSS - ok 18:28:49.0027 3392 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 18:28:49.0043 3392 vwifibus - ok 18:28:49.0074 3392 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 18:28:49.0090 3392 vwififlt - ok 18:28:49.0105 3392 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 18:28:49.0121 3392 W32Time - ok 18:28:49.0152 3392 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 18:28:49.0168 3392 WacomPen - ok 18:28:49.0199 3392 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 18:28:49.0230 3392 WANARP - ok 18:28:49.0246 3392 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 18:28:49.0261 3392 Wanarpv6 - ok 18:28:49.0308 3392 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 18:28:49.0324 3392 WatAdminSvc - ok 18:28:49.0386 3392 [ 878C947C69EE89E4DBFF9DBD6155C15D ] watchmi C:\Program Files (x86)\watchmi\TvdService.exe 18:28:49.0386 3392 watchmi ( UnsignedFile.Multi.Generic ) - warning 18:28:49.0386 3392 watchmi - detected UnsignedFile.Multi.Generic (1) 18:28:49.0417 3392 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 18:28:49.0448 3392 wbengine - ok 18:28:49.0464 3392 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 18:28:49.0480 3392 WbioSrvc - ok 18:28:49.0495 3392 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 18:28:49.0511 3392 wcncsvc - ok 18:28:49.0526 3392 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 18:28:49.0526 3392 WcsPlugInService - ok 18:28:49.0542 3392 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 18:28:49.0558 3392 Wd - ok 18:28:49.0573 3392 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 18:28:49.0589 3392 Wdf01000 - ok 18:28:49.0604 3392 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 18:28:49.0620 3392 WdiServiceHost - ok 18:28:49.0620 3392 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 18:28:49.0636 3392 WdiSystemHost - ok 18:28:49.0651 3392 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 18:28:49.0667 3392 WebClient - ok 18:28:49.0682 3392 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 18:28:49.0698 3392 Wecsvc - ok 18:28:49.0714 3392 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 18:28:49.0745 3392 wercplsupport - ok 18:28:49.0776 3392 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 18:28:49.0792 3392 WerSvc - ok 18:28:49.0823 3392 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 18:28:49.0838 3392 WfpLwf - ok 18:28:49.0854 3392 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 18:28:49.0854 3392 WIMMount - ok 18:28:49.0885 3392 WinDefend - ok 18:28:49.0901 3392 WinHttpAutoProxySvc - ok 18:28:49.0948 3392 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 18:28:49.0979 3392 Winmgmt - ok 18:28:50.0010 3392 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 18:28:50.0041 3392 WinRM - ok 18:28:50.0088 3392 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 18:28:50.0104 3392 WinUsb - ok 18:28:50.0119 3392 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 18:28:50.0135 3392 Wlansvc - ok 18:28:50.0197 3392 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 18:28:50.0213 3392 wlcrasvc - ok 18:28:50.0291 3392 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 18:28:50.0338 3392 wlidsvc - ok 18:28:50.0353 3392 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 18:28:50.0353 3392 WmiAcpi - ok 18:28:50.0369 3392 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 18:28:50.0384 3392 wmiApSrv - ok 18:28:50.0416 3392 WMPNetworkSvc - ok 18:28:50.0431 3392 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 18:28:50.0447 3392 WPCSvc - ok 18:28:50.0462 3392 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 18:28:50.0478 3392 WPDBusEnum - ok 18:28:50.0494 3392 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 18:28:50.0540 3392 ws2ifsl - ok 18:28:50.0540 3392 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 18:28:50.0556 3392 wscsvc - ok 18:28:50.0556 3392 WSearch - ok 18:28:50.0572 3392 [ 82E8F5AA03DF7DBDB8A33F700D5D8CDA ] wsvd C:\Windows\system32\DRIVERS\wsvd.sys 18:28:50.0587 3392 wsvd - ok 18:28:50.0634 3392 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 18:28:50.0665 3392 wuauserv - ok 18:28:50.0665 3392 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 18:28:50.0665 3392 WudfPf - ok 18:28:50.0696 3392 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 18:28:50.0696 3392 WUDFRd - ok 18:28:50.0712 3392 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 18:28:50.0728 3392 wudfsvc - ok 18:28:50.0743 3392 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 18:28:50.0759 3392 WwanSvc - ok 18:28:50.0774 3392 [ 9176C0822FAA649E45121875BE32F5D2 ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys 18:28:50.0790 3392 xusb21 - ok 18:28:50.0790 3392 ================ Scan global =============================== 18:28:50.0821 3392 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 18:28:50.0837 3392 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll 18:28:50.0852 3392 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll 18:28:50.0868 3392 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 18:28:50.0899 3392 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 18:28:50.0899 3392 [Global] - ok 18:28:50.0899 3392 ================ Scan MBR ================================== 18:28:50.0899 3392 [ 753CA1D394F3C0855134963D7361060F ] \Device\Harddisk0\DR0 18:28:52.0646 3392 \Device\Harddisk0\DR0 - ok 18:28:52.0646 3392 ================ Scan VBR ================================== 18:28:52.0646 3392 [ B5967DEE3556AB5547CE4A01720D3A87 ] \Device\Harddisk0\DR0\Partition1 18:28:52.0646 3392 \Device\Harddisk0\DR0\Partition1 - ok 18:28:52.0693 3392 [ 723B1384481DF8BCF39370C73915C3B3 ] \Device\Harddisk0\DR0\Partition2 18:28:52.0693 3392 \Device\Harddisk0\DR0\Partition2 - ok 18:28:52.0724 3392 [ 321024554349D673DA11DF6C854568BF ] \Device\Harddisk0\DR0\Partition3 18:28:52.0724 3392 \Device\Harddisk0\DR0\Partition3 - ok 18:28:52.0724 3392 ============================================================ 18:28:52.0724 3392 Scan finished 18:28:52.0724 3392 ============================================================ 18:28:52.0740 4916 Detected object count: 1 18:28:52.0740 4916 Actual detected object count: 1 18:28:56.0702 4916 C:\Program Files (x86)\watchmi\TvdService.exe - copied to quarantine 18:28:56.0702 4916 HKLM\SYSTEM\ControlSet001\services\watchmi - will be deleted on reboot 18:28:56.0734 4916 HKLM\SYSTEM\ControlSet002\services\watchmi - will be deleted on reboot 18:28:56.0858 4916 C:\Program Files (x86)\watchmi\TvdService.exe - will be deleted on reboot 18:28:56.0858 4916 watchmi ( UnsignedFile.Multi.Generic ) - User select action: Delete 18:29:00.0384 2828 Deinitialize success Emsisoft Anti-Malware - Version 7.0 Letztes Update: 19.11.2012 18:48:29 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\, Q:\ Riskware-Erkennung: Aus Archiv Scan: An ADS Scan: An Dateitypen-Filter: Aus Erweitertes Caching: An Direkter Festplattenzugriff: Aus Scan Beginn: 19.11.2012 18:50:18 C:\Users\Denny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uninstall Security Shield.lnk gefunden: Trace.File.SecurityShield (A) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1ceaf66e.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1fe005b2.qua -> (Quarantine-8) -> ta/a2.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1fe005b2.qua -> (Quarantine-8) -> ta/C.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1fe005b2.qua -> (Quarantine-8) -> ta/ta.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1fe005b2.qua -> (Quarantine-8) -> ta/tc.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1fe005b2.qua -> (Quarantine-8) -> ta/tb.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1fe005b2.qua -> (Quarantine-8) -> ta/er.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1ff243a8.qua -> (Quarantine-8) gefunden: Trojan.Generic.7616670 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3c5c673f.qua -> (Quarantine-8) -> ta/a2.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3c5c673f.qua -> (Quarantine-8) -> ta/C.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3c5c673f.qua -> (Quarantine-8) -> ta/ta.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3c5c673f.qua -> (Quarantine-8) -> ta/tc.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3c5c673f.qua -> (Quarantine-8) -> ta/tb.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3c5c673f.qua -> (Quarantine-8) -> ta/er.class gefunden: Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42905555.qua -> (Quarantine-8) -> NkeGa/NkeGd.class gefunden: Trojan.Java.Agent.C (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42905555.qua -> (Quarantine-8) -> NkeGa/NkeGe.class gefunden: Trojan.Java.Agent.C (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42905555.qua -> (Quarantine-8) -> NkeGa/NkeGb.class gefunden: Trojan.Java.Agent.C (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42905555.qua -> (Quarantine-8) -> NkeGa/NkeGc.class gefunden: Trojan.Java.Agent.C (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42905555.qua -> (Quarantine-8) -> NkeGa/NkeGa.class gefunden: Trojan.Java.Agent.C (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4849f9ed.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4954f375.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\495a9621.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\495afeaa.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\497a93f5.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\49d697d9.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4a0b6acd.qua -> (Quarantine-8) gefunden: Trojan.Generic.KDV.607651 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4a4990ac.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4a51fcdc.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4c675f61.qua -> (Quarantine-8) gefunden: Gen:Variant.Delf.56 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4d9d113b.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4dbc1940.qua -> (Quarantine-8) gefunden: Gen:Heur.FakeAV.2 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4deb64e2.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4e2c1e0a.qua -> (Quarantine-8) gefunden: Trojan.Generic.KDV.629940 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4e6a6e74.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4eb5ac86.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\50ded64a.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5141b87e.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\51cdd10d.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\52debf0b.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\54b894ca.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.FR (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\54e370c7.qua -> (Quarantine-8) gefunden: Gen:Variant.Barys.5309 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\550a3e9c.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\553a36e0.qua -> (Quarantine-8) gefunden: Trojan.Generic.7616670 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\553efa5f.qua -> (Quarantine-8) -> (JAVASCRIPT) gefunden: Exploit.PDF-JS.Gen (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\553efa5f.qua -> (Quarantine-8) -> (INFECTED_JS) gefunden: PDF:Exploit.PDF.AX (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\556992cb.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.FR (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\557c4b45.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\55a232a2.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\55bf32a1.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\56228321.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HC (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\564b8b91.qua -> (Quarantine-8) gefunden: Gen:Variant.Graftor.26540 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\568e8742.qua -> (Quarantine-8) gefunden: Trojan.Generic.KDV.651891 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\56b031b9.qua -> (Quarantine-8) gefunden: Gen:Variant.Barys.5309 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\56fd41d3.qua -> (Quarantine-8) gefunden: Trojan.Sirefef.HD (B) Gescannt 459475 Gefunden 55 Scan Ende: 19.11.2012 19:46:05 Scan Zeit: 0:55:47 C:\ProgramData\Avira\AntiVir Desktop\INFECTED\568e8742.qua -> (Quarantine-8) Quarantäne Trojan.Generic.KDV.651891 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\564b8b91.qua -> (Quarantine-8) Quarantäne Gen:Variant.Graftor.26540 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\56228321.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HC (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\553efa5f.qua -> (Quarantine-8) -> (INFECTED_JS) Quarantäne PDF:Exploit.PDF.AX (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\54e370c7.qua -> (Quarantine-8) Quarantäne Gen:Variant.Barys.5309 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\56b031b9.qua -> (Quarantine-8) Quarantäne Gen:Variant.Barys.5309 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\54b894ca.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.FR (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\556992cb.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.FR (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4e2c1e0a.qua -> (Quarantine-8) Quarantäne Trojan.Generic.KDV.629940 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4dbc1940.qua -> (Quarantine-8) Quarantäne Gen:Heur.FakeAV.2 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4c675f61.qua -> (Quarantine-8) Quarantäne Gen:Variant.Delf.56 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4a0b6acd.qua -> (Quarantine-8) Quarantäne Trojan.Generic.KDV.607651 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4849f9ed.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\495afeaa.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\497a93f5.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\49d697d9.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4a4990ac.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4a51fcdc.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4deb64e2.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4eb5ac86.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\550a3e9c.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\55a232a2.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\55bf32a1.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\56fd41d3.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.HD (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42905555.qua -> (Quarantine-8) -> NkeGa/NkeGd.class Quarantäne Trojan.Java.Agent.C (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1ff243a8.qua -> (Quarantine-8) Quarantäne Trojan.Generic.7616670 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\553a36e0.qua -> (Quarantine-8) Quarantäne Trojan.Generic.7616670 (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1fe005b2.qua -> (Quarantine-8) -> ta/a2.class Quarantäne Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3c5c673f.qua -> (Quarantine-8) -> ta/a2.class Quarantäne Exploit.Java.Blacole.K (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1ceaf66e.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4954f375.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\495a9621.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4d9d113b.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4e6a6e74.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\50ded64a.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5141b87e.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\51cdd10d.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\52debf0b.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\ProgramData\Avira\AntiVir Desktop\INFECTED\557c4b45.qua -> (Quarantine-8) Quarantäne Trojan.Sirefef.GW (B) C:\Users\Denny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uninstall Security Shield.lnk Quarantäne Trace.File.SecurityShield (A) Quarantäne 40 |
Malware mit Combofix beseitigen Lade Combofix von einem der folgenden Download-Spiegel herunter: BleepingComputer.com - ForoSpyware.com und speichere das Programm auf den Desktop, nicht woanders hin, das ist wichtig! Beachte die ausführliche Original-Anleitung. Zurzeit ist Combofix auf folgenden Windows-Versionen lauffähig:
Vorbereitung und wichtige Hinweise
Combofix nicht auf eigene Faust einsetzen. Wenn keine entsprechende Infektion vorliegt, kann das den Rechner lahmlegen und/oder nachhaltig schädigen! |
Ich habe ComboFix wie beschrieben ausgeführt. Aber als er fertig war hat er einen neustart gemacht.Ich dachte ok wird wohl so richtig sein. Ich musste wie gehabt mein passwort eingeben und landete auf meinem desktop. Dann kam diese Log-Datei von Combofix und ich habe alles markiert und WOLLTE den IE öffnen. Dort steht aber nur,auch bei jedem anderen Programm das ich öffnen will,"C:\Program Files (x86)\Mozilla Firefox\firefox.exe Es wurde versucht,einen Registrierungsschlüssel einem unzulässigen Vorgang zu unterziehen,der zum löschen markiert wurde. Dann kommt ein nächstes Fenster nachdem ich auf ok gedrückt habe mit folgendem Inhalt :"Dieses Element wurde gelöscht.Möglicherweise wurde es verschoben,umbennant oder gelöscht.Möchten sie dieses Elememt entfernen? Ich meine es funktioniert nichts,nada,niente. Ich wollte die Log-datei auf einen Stick rüber auf meinen Laptop,womit ich gerade schreibe,zeihen.Aber das geht,wie von mir vermutet,auch nicht. Habe ich einen Fehler gemacht???? Combofix Logfile: Code: ComboFix 12-11-25.01 - Denny 25.11.2012 17:25:47.1.4 - x64 |
Rechner neustarten sollte helfen. ESET Online Scanner
|
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=88397140a5cd3644bf4966c0a5a7340f # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-11-28 08:45:23 # local_time=2012-11-28 09:45:23 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 20682902 20682902 0 0 # compatibility_mode=5893 16776574 100 94 29737062 105761458 0 0 # compatibility_mode=8192 67108863 100 0 3766 3766 0 0 # scanned=152975 # found=0 # cleaned=0 # scan_time=3916 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 07:26 Uhr. |
Copyright ©2000-2025, Trojaner-Board