Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Google leitet auf falsche Seiten weiter (https://www.trojaner-board.de/105077-google-leitet-falsche-seiten.html)

henniberlin 13.11.2011 20:08

Google leitet auf falsche Seiten weiter
 
Hallo :)

habe das wohl öfter vorkommende Problem, dass Google mich nicht auf die gewünschte sondern andere Seiten weiterleitet.

anbei die gewünschten dateien

vielen dank schon mal für die Hilfe

markusg 14.11.2011 11:58

hiho

achtung!
dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
F3:64bit: - HKCU WinNT: Load - (C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe) - C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe ()
F3 - HKCU WinNT: Load - (C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe) -C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe ()
F3:64bit: - HKCU WinNT: Load - (C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe) - C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe ()
O4 - HKCU..\Run: [F30.exe] C:\Users\Hendrik\AppData\Roaming\Microsoft\B113\F30.exe ()
O4 - HKCU..\Run: [06D.exe] C:\Users\Hendrik\AppData\Roaming\Microsoft\E963\06D.exe ()
O20 - HKCU Winlogon: Shell - (C:\Users\Hendrik\AppData\Roaming\340CE\08DB1.exe) -C:\Users\Hendrik\AppData\Roaming\340CE\08DB1.exe ()
:Files
C:\Users\Hendrik\AppData\Roaming\CE789
C:\Users\Hendrik\AppData\Roaming\Microsoft\B113
C:\Users\Hendrik\AppData\Roaming\Microsoft\E963
C:\Users\Hendrik\AppData\Roaming\340CE
C:\Program Files (x86)\LP
:Commands
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.


lade unhide:
http://filepony.de/download-unhide/
doppelklicken, dateien werden sichtbar

öffne computer, öffne C: dann _OTL
dort rechtsklick auf moved files
wähle zu moved files.rar oder zip hinzufügen.
folge dem link, und lade das archiv im upload channel hoch
http://www.trojaner-board.de/54791-a...ner-board.html

henniberlin 14.11.2011 16:50

Code:

========== OTL ==========
C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe moved successfully.
64bit-Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe deleted successfully.
File \Users\Hendrik\AppData\Roaming\CE789\lvvm.exe) -C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe deleted successfully.
File C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe not found.
64bit-Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Hendrik\AppData\Roaming\CE789\lvvm.exe deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\F30.exe deleted successfully.
C:\Users\Hendrik\AppData\Roaming\Microsoft\B113\F30.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\06D.exe deleted successfully.
C:\Users\Hendrik\AppData\Roaming\Microsoft\E963\06D.exe moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Users\Hendrik\AppData\Roaming\340CE\08DB1.exe deleted successfully.
File \Users\Hendrik\AppData\Roaming\340CE\08DB1.exe) -C:\Users\Hendrik\AppData\Roaming\340CE\08DB1.exe not found.
========== FILES ==========
C:\Users\Hendrik\AppData\Roaming\CE789 folder moved successfully.
C:\Users\Hendrik\AppData\Roaming\Microsoft\B113 folder moved successfully.
Folder move failed. C:\Users\Hendrik\AppData\Roaming\Microsoft\E963 scheduled to be moved on reboot.
C:\Users\Hendrik\AppData\Roaming\340CE folder moved successfully.
C:\Program Files (x86)\LP\E963 folder moved successfully.
C:\Program Files (x86)\LP folder moved successfully.
========== COMMANDS ==========
 
OTL by OldTimer - Version 3.2.31.0 log created on 11142011_164131

Files\Folders moved on Reboot...
C:\Users\Hendrik\AppData\Roaming\Microsoft\E963 folder moved successfully.

Registry entries deleted on Reboot...


markusg 14.11.2011 16:59

ok weiter mit unhide und upload des moved files ordner im upload channel

henniberlin 14.11.2011 17:21

jo, hab ich

markusg 14.11.2011 17:35

ok
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.

Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
  • Besuche folgende Seite für Downloadlinks und Anweisungen für dieses
    Tool

    Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Hinweis:
    Gehe sicher das all deine Anti Virus und Anti Malware Programme abgeschalten sind, damit diese Combofix nicht bei der Arbeit stören.
  • Poste bitte die C:\Combofix.txt in deiner nächsten Antwort.

henniberlin 14.11.2011 18:44

Code:

Combofix Logfile:

       
Code:

       
ComboFix 11-11-14.02 - Hendrik 14.11.2011  18:06:29.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.2989.1794 [GMT 1:00]
ausgeführt von:: c:\users\Hendrik\Documents\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: Trend Micro Internet Security *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\facemoods.com
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.crx
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.png
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe
c:\programdata\FullRemove.exe
c:\users\Hendrik\AppData\Roaming\202A.C8B
c:\users\Hendrik\AppData\Roaming\firefox.exe
c:\users\Hendrik\AppData\Roaming\java.exe
c:\users\Hendrik\AppData\Roaming\Microsoft\lvvm.exe
c:\windows\IsUn0407.exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At2.job
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-10-14 bis 2011-11-14  ))))))))))))))))))))))))))))))
.
.
2011-11-14 17:18 . 2011-11-14 17:18        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-11-14 16:59 . 2011-11-14 16:59        --------        d-----w-        c:\windows\de
2011-11-14 16:54 . 2011-05-13 14:37        48488        ----a-w-        c:\windows\system32\drivers\fssfltr.sys
2011-11-14 16:52 . 2009-09-04 16:44        69464        ----a-w-        c:\windows\SysWow64\XAPOFX1_3.dll
2011-11-14 16:52 . 2009-09-04 16:44        515416        ----a-w-        c:\windows\SysWow64\XAudio2_5.dll
2011-11-14 16:52 . 2009-09-04 16:29        453456        ----a-w-        c:\windows\SysWow64\d3dx10_42.dll
2011-11-14 16:52 . 2009-09-04 16:29        523088        ----a-w-        c:\windows\system32\d3dx10_42.dll
2011-11-14 16:51 . 2006-11-29 12:06        4398360        ----a-w-        c:\windows\system32\d3dx9_32.dll
2011-11-14 16:51 . 2006-11-29 12:06        3426072        ----a-w-        c:\windows\SysWow64\d3dx9_32.dll
2011-11-14 16:50 . 2011-11-14 16:50        15712        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\7d43616d1cca2ed06\MeshBetaRemover.exe
2011-11-14 16:50 . 2011-11-14 16:50        94040        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\79f1962b1cca2ed05\DSETUP.dll
2011-11-14 16:50 . 2011-11-14 16:50        525656        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\79f1962b1cca2ed05\DXSETUP.exe
2011-11-14 16:50 . 2011-11-14 16:50        1691480        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\79f1962b1cca2ed05\dsetup32.dll
2011-11-14 16:50 . 2011-11-14 16:50        94040        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\76833a661cca2ed04\DSETUP.dll
2011-11-14 16:50 . 2011-11-14 16:50        525656        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\76833a661cca2ed04\DXSETUP.exe
2011-11-14 16:50 . 2011-11-14 16:50        1691480        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\76833a661cca2ed04\dsetup32.dll
2011-11-14 16:06 . 2011-11-14 17:00        --------        d-----w-        c:\users\Hendrik\AppData\Local\Windows Live
2011-11-14 16:01 . 2011-11-14 16:48        --------        d-----w-        c:\users\Hendrik\AppData\Roaming\ICQ
2011-11-14 16:01 . 2011-11-14 16:02        --------        d-----w-        c:\program files (x86)\ICQ7.7
2011-11-14 15:41 . 2011-11-14 15:59        --------        d-----w-        C:\_OTL
2011-11-13 18:32 . 2011-11-13 18:32        --------        d-----w-        c:\program files (x86)\7-Zip
2011-11-13 17:59 . 2011-11-13 17:59        --------        d-----w-        c:\windows\system32\SPReview
2011-11-13 17:57 . 2011-11-13 17:57        --------        d-----w-        c:\windows\system32\EventProviders
2011-11-09 15:42 . 2011-10-01 05:45        886784        ----a-w-        c:\program files\Common Files\System\wab32.dll
2011-11-09 15:42 . 2011-10-01 04:37        708608        ----a-w-        c:\program files (x86)\Common Files\System\wab32.dll
2011-11-09 15:42 . 2011-09-29 16:29        1923952        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2011-11-09 15:42 . 2011-09-29 04:03        3144704        ----a-w-        c:\windows\system32\win32k.sys
2011-11-05 14:34 . 2011-11-05 14:34        --------        d-----w-        c:\program files (x86)\Java
2011-10-30 17:03 . 2011-11-01 08:07        283648        ----a-w-        c:\users\Hendrik\AppData\Roaming\Microsoft\3D7C\CE7.exe
2011-10-30 17:03 . 2011-10-30 17:03        283648        ----a-w-        c:\users\Hendrik\AppData\Roaming\Microsoft\E96C\CE7.exe
2011-10-26 12:37 . 2011-08-13 05:27        6144        ----a-w-        c:\program files\Internet Explorer\iecompat.dll
2011-10-26 12:37 . 2011-08-13 04:18        6144        ----a-w-        c:\program files (x86)\Internet Explorer\iecompat.dll
2011-10-22 13:57 . 2011-10-22 13:57        --------        d-----w-        c:\programdata\iMesh
2011-10-22 13:57 . 2011-10-22 13:57        --------        d-----w-        c:\program files (x86)\iMesh Applications
2011-10-22 13:57 . 2011-10-22 13:58        --------        dc----w-        c:\programdata\{D7941DA4-2EF5-4E70-8A3D-3CF7634A336B}
2011-10-22 13:57 . 2011-10-22 13:57        --------        d-----w-        c:\users\Hendrik\AppData\Local\PackageAware
2011-10-16 17:55 . 2011-10-16 17:55        18139008        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-14 17:00 . 2011-03-28 17:36        18328        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-11-13 18:10 . 2009-07-14 02:36        175616        ----a-w-        c:\windows\system32\msclmd.dll
2011-11-13 18:10 . 2009-07-14 02:36        152576        ----a-w-        c:\windows\SysWow64\msclmd.dll
2011-11-05 14:34 . 2010-10-23 14:54        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2011-10-07 14:24 . 2011-10-07 14:24        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-01 03:25 . 2011-10-12 23:33        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2011-10-01 02:42 . 2011-10-12 23:33        1638912        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2011-09-18 17:03 . 2011-09-18 17:03        21840        ----a-w-        c:\windows\SysWow64\SIntfNT.dll
2011-09-18 17:03 . 2011-09-18 17:03        17212        ----a-w-        c:\windows\SysWow64\SIntf32.dll
2011-09-18 17:03 . 2011-09-18 17:03        12067        ----a-w-        c:\windows\SysWow64\SIntf16.dll
2011-09-18 12:00 . 2011-09-18 11:55        1668        ----a-w-        c:\windows\system32\ASOROSet.bin
2011-08-29 08:00 . 2011-09-18 11:28        74752        ----a-w-        c:\windows\SysWow64\ff_vfw.dll
2011-08-27 05:37 . 2011-10-12 23:33        861696        ----a-w-        c:\windows\system32\oleaut32.dll
2011-08-27 05:37 . 2011-10-12 23:33        331776        ----a-w-        c:\windows\system32\oleacc.dll
2011-08-27 04:26 . 2011-10-12 23:33        571904        ----a-w-        c:\windows\SysWow64\oleaut32.dll
2011-08-27 04:26 . 2011-10-12 23:33        233472        ----a-w-        c:\windows\SysWow64\oleacc.dll
2011-08-20 05:37 . 2011-10-12 23:33        1188864        ----a-w-        c:\windows\system32\wininet.dll
2011-08-20 04:31 . 2011-10-12 23:33        981504        ----a-w-        c:\windows\SysWow64\wininet.dll
2011-08-17 05:26 . 2011-10-12 23:33        613888        ----a-w-        c:\windows\system32\psisdecd.dll
2011-08-17 05:25 . 2011-10-12 23:33        108032        ----a-w-        c:\windows\system32\psisrndr.ax
2011-08-17 04:24 . 2011-10-12 23:33        465408        ----a-w-        c:\windows\SysWow64\psisdecd.dll
2011-08-17 04:19 . 2011-10-12 23:33        75776        ----a-w-        c:\windows\SysWow64\psisrndr.ax
2009-04-08 17:31 . 2009-04-08 17:31        106496        ----a-w-        c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45        155648        ----a-w-        c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}"= "c:\program files (x86)\vShare.tv plugin\BarLcher.dll" [2011-06-01 177712]
.
[HKEY_CLASSES_ROOT\clsid\{7ac3e13b-3bca-4158-b330-f66dbb03c1b5}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1]
[HKEY_CLASSES_ROOT\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-07-20 2429]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ           kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 135664]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2010-02-23 917768]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 07:01]
.
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 07:01]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XeroxEndeavorBackgroundTask"="xrWCbgnd.dll" [2009-07-14 58368]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.facemoods.com/?a=ddrnw
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://startsear.ch/?aff=1
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=127.0.0.1:50182
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\ljmyjwac.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - kicker.de
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&clid=faf9aa620cfe4e4da105c849b2dede2a&subid=&Keywords=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50182
FF - prefs.js: network.proxy.type - 4
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe
Wow6432Node-HKLM-Run-06D.exe - c:\program files (x86)\LP\E963\06D.exe
Toolbar-Locked - (no file)
WebBrowser-{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - (no file)
AddRemove-CodInstl - c:\windows\system32\CDUninst.isu
AddRemove-DSF Fussball Manager 98 - c:\windows\IsUn0407.exe
AddRemove-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
AddRemove-{15CD0411-2BCA-4D1D-8E3B-611900ABB53F}_is1 - d:\spiele\Call of Duty Black Ops AT UNCUT\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1026848055-2084105530-1121592593-1001\Software\SecuROM\License information*]
"datasecu"=hex:30,9e,05,f3,db,7b,09,8e,bd,44,fd,0c,1e,96,6e,88,85,0d,7f,67,79,
   6b,54,1f,cb,c9,3e,41,af,39,5e,9e,a4,89,16,3b,96,30,16,71,95,9c,cb,cf,63,d9,\
"rkeysecu"=hex:b5,33,eb,9b,af,f4,d5,94,e1,51,2a,97,17,33,3c,7b
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-11-14  18:35:06 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-11-14 17:34
.
Vor Suchlauf: 15 Verzeichnis(se), 20.604.895.232 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 21.273.669.632 Bytes frei
.
- - End Of File - - 4DF02243ABC29F9678FCF3E5E873F588


--- --- ---


markusg 14.11.2011 19:00

start programme zubehör editor reinkopieren:

Killall::
Rootkit::
Folder::
c:\users\Hendrik\AppData\Roaming\Microsoft\3D7C
c:\users\Hendrik\AppData\Roaming\Microsoft\E96C

datei speichern unter, ort, dort wo sich combofix.exe befindet, typ, alle dateien.
name:
cfscript.txt

schalte jetzt alles an laufenden programmen aus, auch antivirus.
dann ziehe cfscript auf combofix, programm startet log posten

henniberlin 14.11.2011 19:57

Code:

Combofix Logfile:

       
Code:

       
ComboFix 11-11-14.02 - Hendrik 14.11.2011  19:23:16.2.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.2989.1741 [GMT 1:00]
ausgeführt von:: c:\users\Hendrik\Documents\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Hendrik\Documents\Desktop\cfscript.txt
AV: Trend Micro Internet Security *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: Trend Micro Internet Security *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Hendrik\AppData\Roaming\Microsoft\3D7C
c:\users\Hendrik\AppData\Roaming\Microsoft\3D7C\CE7.exe
c:\users\Hendrik\AppData\Roaming\Microsoft\E96C
c:\users\Hendrik\AppData\Roaming\Microsoft\E96C\CE7.exe
c:\users\Hendrik\AppData\Roaming\Microsoft\E96C\F519.tmp
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-10-14 bis 2011-11-14  ))))))))))))))))))))))))))))))
.
.
2011-11-14 18:28 . 2011-11-14 18:28        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-11-14 16:59 . 2011-11-14 16:59        --------        d-----w-        c:\windows\de
2011-11-14 16:54 . 2011-05-13 14:37        48488        ----a-w-        c:\windows\system32\drivers\fssfltr.sys
2011-11-14 16:52 . 2009-09-04 16:44        69464        ----a-w-        c:\windows\SysWow64\XAPOFX1_3.dll
2011-11-14 16:52 . 2009-09-04 16:44        515416        ----a-w-        c:\windows\SysWow64\XAudio2_5.dll
2011-11-14 16:52 . 2009-09-04 16:29        453456        ----a-w-        c:\windows\SysWow64\d3dx10_42.dll
2011-11-14 16:52 . 2009-09-04 16:29        523088        ----a-w-        c:\windows\system32\d3dx10_42.dll
2011-11-14 16:51 . 2006-11-29 12:06        4398360        ----a-w-        c:\windows\system32\d3dx9_32.dll
2011-11-14 16:51 . 2006-11-29 12:06        3426072        ----a-w-        c:\windows\SysWow64\d3dx9_32.dll
2011-11-14 16:50 . 2011-11-14 16:50        15712        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\7d43616d1cca2ed06\MeshBetaRemover.exe
2011-11-14 16:50 . 2011-11-14 16:50        94040        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\79f1962b1cca2ed05\DSETUP.dll
2011-11-14 16:50 . 2011-11-14 16:50        525656        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\79f1962b1cca2ed05\DXSETUP.exe
2011-11-14 16:50 . 2011-11-14 16:50        1691480        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\79f1962b1cca2ed05\dsetup32.dll
2011-11-14 16:50 . 2011-11-14 16:50        94040        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\76833a661cca2ed04\DSETUP.dll
2011-11-14 16:50 . 2011-11-14 16:50        525656        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\76833a661cca2ed04\DXSETUP.exe
2011-11-14 16:50 . 2011-11-14 16:50        1691480        ----a-w-        c:\program files (x86)\Common Files\Windows Live\.cache\76833a661cca2ed04\dsetup32.dll
2011-11-14 16:06 . 2011-11-14 18:20        --------        d-----w-        c:\users\Hendrik\AppData\Local\Windows Live
2011-11-14 16:01 . 2011-11-14 18:20        --------        d-----w-        c:\users\Hendrik\AppData\Roaming\ICQ
2011-11-14 16:01 . 2011-11-14 16:02        --------        d-----w-        c:\program files (x86)\ICQ7.7
2011-11-14 15:41 . 2011-11-14 15:59        --------        d-----w-        C:\_OTL
2011-11-13 18:32 . 2011-11-13 18:32        --------        d-----w-        c:\program files (x86)\7-Zip
2011-11-13 17:59 . 2011-11-13 17:59        --------        d-----w-        c:\windows\system32\SPReview
2011-11-13 17:57 . 2011-11-13 17:57        --------        d-----w-        c:\windows\system32\EventProviders
2011-11-09 15:42 . 2011-10-01 05:45        886784        ----a-w-        c:\program files\Common Files\System\wab32.dll
2011-11-09 15:42 . 2011-10-01 04:37        708608        ----a-w-        c:\program files (x86)\Common Files\System\wab32.dll
2011-11-09 15:42 . 2011-09-29 16:29        1923952        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2011-11-09 15:42 . 2011-09-29 04:03        3144704        ----a-w-        c:\windows\system32\win32k.sys
2011-11-05 14:34 . 2011-11-05 14:34        --------        d-----w-        c:\program files (x86)\Java
2011-10-26 12:37 . 2011-08-13 05:27        6144        ----a-w-        c:\program files\Internet Explorer\iecompat.dll
2011-10-26 12:37 . 2011-08-13 04:18        6144        ----a-w-        c:\program files (x86)\Internet Explorer\iecompat.dll
2011-10-22 13:57 . 2011-10-22 13:57        --------        d-----w-        c:\programdata\iMesh
2011-10-22 13:57 . 2011-10-22 13:57        --------        d-----w-        c:\program files (x86)\iMesh Applications
2011-10-22 13:57 . 2011-10-22 13:58        --------        dc----w-        c:\programdata\{D7941DA4-2EF5-4E70-8A3D-3CF7634A336B}
2011-10-22 13:57 . 2011-10-22 13:57        --------        d-----w-        c:\users\Hendrik\AppData\Local\PackageAware
2011-10-16 17:55 . 2011-10-16 17:55        18139008        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-14 17:00 . 2011-03-28 17:36        18328        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-11-13 18:10 . 2009-07-14 02:36        175616        ----a-w-        c:\windows\system32\msclmd.dll
2011-11-13 18:10 . 2009-07-14 02:36        152576        ----a-w-        c:\windows\SysWow64\msclmd.dll
2011-11-05 14:34 . 2010-10-23 14:54        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2011-10-07 14:24 . 2011-10-07 14:24        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-01 03:25 . 2011-10-12 23:33        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2011-10-01 02:42 . 2011-10-12 23:33        1638912        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2011-09-18 17:03 . 2011-09-18 17:03        21840        ----a-w-        c:\windows\SysWow64\SIntfNT.dll
2011-09-18 17:03 . 2011-09-18 17:03        17212        ----a-w-        c:\windows\SysWow64\SIntf32.dll
2011-09-18 17:03 . 2011-09-18 17:03        12067        ----a-w-        c:\windows\SysWow64\SIntf16.dll
2011-09-18 12:00 . 2011-09-18 11:55        1668        ----a-w-        c:\windows\system32\ASOROSet.bin
2011-08-29 08:00 . 2011-09-18 11:28        74752        ----a-w-        c:\windows\SysWow64\ff_vfw.dll
2011-08-27 05:37 . 2011-10-12 23:33        861696        ----a-w-        c:\windows\system32\oleaut32.dll
2011-08-27 05:37 . 2011-10-12 23:33        331776        ----a-w-        c:\windows\system32\oleacc.dll
2011-08-27 04:26 . 2011-10-12 23:33        571904        ----a-w-        c:\windows\SysWow64\oleaut32.dll
2011-08-27 04:26 . 2011-10-12 23:33        233472        ----a-w-        c:\windows\SysWow64\oleacc.dll
2011-08-20 05:37 . 2011-10-12 23:33        1188864        ----a-w-        c:\windows\system32\wininet.dll
2011-08-20 04:31 . 2011-10-12 23:33        981504        ----a-w-        c:\windows\SysWow64\wininet.dll
2011-08-17 05:26 . 2011-10-12 23:33        613888        ----a-w-        c:\windows\system32\psisdecd.dll
2011-08-17 05:25 . 2011-10-12 23:33        108032        ----a-w-        c:\windows\system32\psisrndr.ax
2011-08-17 04:24 . 2011-10-12 23:33        465408        ----a-w-        c:\windows\SysWow64\psisdecd.dll
2011-08-17 04:19 . 2011-10-12 23:33        75776        ----a-w-        c:\windows\SysWow64\psisrndr.ax
2009-04-08 17:31 . 2009-04-08 17:31        106496        ----a-w-        c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45        155648        ----a-w-        c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((   SnapShot@2011-11-14_17.21.26   )))))))))))))))))))))))))))))))))))))))))
.
- 2011-11-14 17:19 . 2011-11-14 17:19        13342              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2011-11-14 18:28 . 2011-11-14 18:28        13342              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2009-07-14 04:54 . 2011-11-14 17:20        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-11-14 18:30        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-11-14 17:20        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-11-14 18:30        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-14 17:20        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-11-14 18:30        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-07-20 07:17 . 2011-11-14 18:31        50004              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-11-14 16:48        32748              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-11-14 18:31        32748              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-10-23 11:35 . 2011-11-14 18:31        12600              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1026848055-2084105530-1121592593-1001_UserData.bin
- 2010-10-24 02:24 . 2011-11-14 17:20        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-10-24 02:24 . 2011-11-14 18:30        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-10-24 02:24 . 2011-11-14 17:20        32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-10-24 02:24 . 2011-11-14 18:30        32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-11-14 18:30        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-14 17:20        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-10-23 11:42 . 2011-11-14 17:41        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-10-23 11:42 . 2011-11-14 16:47        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:46 . 2011-11-14 17:48        91888              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2010-10-23 11:42 . 2011-11-14 17:41        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-10-23 11:42 . 2011-11-14 16:47        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-10-23 11:42 . 2011-11-14 17:41        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-10-23 11:42 . 2011-11-14 16:47        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-10-23 11:36 . 2011-11-14 17:00        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-10-23 11:36 . 2011-11-14 17:41        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-10-23 11:36 . 2011-11-14 17:41        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-10-23 11:36 . 2011-11-14 17:00        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-11-14 17:20 . 2011-11-14 17:20        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-14 18:29 . 2011-11-14 18:29        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-14 18:29 . 2011-11-14 18:29        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-11-14 17:20 . 2011-11-14 17:20        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2011-11-14 16:52        616452              c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-11-14 17:44        616452              c:\windows\system32\perfh009.dat
+ 2009-08-04 09:51 . 2011-11-14 17:44        654610              c:\windows\system32\perfh007.dat
- 2009-08-04 09:51 . 2011-11-14 16:52        654610              c:\windows\system32\perfh007.dat
+ 2009-07-14 02:36 . 2011-11-14 17:44        106574              c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-11-14 16:52        106574              c:\windows\system32\perfc009.dat
+ 2009-08-04 09:51 . 2011-11-14 17:44        130192              c:\windows\system32\perfc007.dat
- 2009-08-04 09:51 . 2011-11-14 16:52        130192              c:\windows\system32\perfc007.dat
+ 2009-07-14 05:12 . 2011-11-14 18:30        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:12 . 2011-11-14 17:20        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:01 . 2011-11-14 18:28        329944              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-11-14 17:19        329944              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:45 . 2011-11-14 16:50        7112398              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2011-11-14 17:22        7112398              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-07-19 16:35 . 2011-11-14 18:28        1843112              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2010-07-19 16:35 . 2011-11-14 17:19        1843112              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-05-09 08:09 . 2011-11-14 17:19        1398393              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1026848055-2084105530-1121592593-1001-8192.dat
+ 2011-05-09 08:09 . 2011-11-14 18:28        1398393              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1026848055-2084105530-1121592593-1001-8192.dat
.
-- Snapshot auf jetziges Datum zurückgesetzt --
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}"= "c:\program files (x86)\vShare.tv plugin\BarLcher.dll" [2011-06-01 177712]
.
[HKEY_CLASSES_ROOT\clsid\{7ac3e13b-3bca-4158-b330-f66dbb03c1b5}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1]
[HKEY_CLASSES_ROOT\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-07-20 2429]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ           kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 135664]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2010-02-23 917768]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 07:01]
.
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-20 07:01]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XeroxEndeavorBackgroundTask"="xrWCbgnd.dll" [2009-07-14 58368]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.facemoods.com/?a=ddrnw
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://startsear.ch/?aff=1
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=127.0.0.1:50182
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\ljmyjwac.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - kicker.de
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&clid=faf9aa620cfe4e4da105c849b2dede2a&subid=&Keywords=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50182
FF - prefs.js: network.proxy.type - 4
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1026848055-2084105530-1121592593-1001\Software\SecuROM\License information*]
"datasecu"=hex:30,9e,05,f3,db,7b,09,8e,bd,44,fd,0c,1e,96,6e,88,85,0d,7f,67,79,
   6b,54,1f,cb,c9,3e,41,af,39,5e,9e,a4,89,16,3b,96,30,16,71,95,9c,cb,cf,63,d9,\
"rkeysecu"=hex:b5,33,eb,9b,af,f4,d5,94,e1,51,2a,97,17,33,3c,7b
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-11-14  19:35:04 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-11-14 18:35
ComboFix2.txt  2011-11-14 17:35
.
Vor Suchlauf: 18 Verzeichnis(se), 21.402.353.664 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 21.329.977.344 Bytes frei
.
- - End Of File - - 18DF8850B5511390BE5C42ED54C8E53C


--- --- ---


markusg 14.11.2011 20:03

öffne mal internet explorer, extras internet optionen verbindung, lanverbindung.
nun gehe zu proxy server, lösche adresse + port
und nimm den haken bei proxy server verwenden raus.
übernehmen ok klicken.
öffne firefox, extras einstellungen erweitert netzwerk, keinen proxy verwenden auswählen, übernehmen ok.


malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

henniberlin 14.11.2011 21:34

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8162

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

14.11.2011 21:32:31
mbam-log-2011-11-14 (21-32-31).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|Q:\|)
Durchsuchte Objekte: 366986
Laufzeit: 35 Minute(n), 6 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 14

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.StartPage) -> Bad: (hxxp://startsear.ch/?aff=1) Good: (hxxp://www.google.com) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Qoobox\quarantine\C\Users\Hendrik\AppData\Roaming\firefox.exe.vir (Malware.Packer) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Users\Hendrik\AppData\Roaming\java.exe.vir (Malware.Packer) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Users\Hendrik\AppData\Roaming\microsoft\lvvm.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Users\Hendrik\AppData\Roaming\microsoft\3D7C\ce7.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Users\Hendrik\AppData\Roaming\microsoft\E96C\ce7.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Hendrik\AppData\Roaming\B202A\lvvm.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\Users\Hendrik\AppData\Roaming\CC8B2\89A11.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\11142011_164131\c_program files (x86)\LP\E963\06D.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\11142011_164131\C_Users\Hendrik\AppData\Roaming\340CE\08DB1.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\11142011_164131\C_Users\Hendrik\AppData\Roaming\340CE\75CE9.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\11142011_164131\C_Users\Hendrik\AppData\Roaming\CE789\lvvm.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\11142011_164131\C_Users\Hendrik\AppData\Roaming\microsoft\B113\F30.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\11142011_164131\C_Users\Hendrik\AppData\Roaming\microsoft\E963\06D.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\program files (x86)\mozilla firefox\searchplugins\Mp3Tube.xml (Adware.Mp3Tube) -> Quarantined and deleted successfully.


markusg 14.11.2011 21:41

hiho

achtung!
dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
:Files
c:\Users\Hendrik\AppData\Roaming\B202A
c:\Users\Hendrik\AppData\Roaming\CC8B2
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.

henniberlin 14.11.2011 21:57

Code:

All processes killed
========== OTL ==========
========== FILES ==========
c:\Users\Hendrik\AppData\Roaming\B202A folder moved successfully.
c:\Users\Hendrik\AppData\Roaming\CC8B2 folder moved successfully.
========== COMMANDS ==========
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Hendrik
->Flash cache emptied: 4218 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Hendrik
->Temp folder emptied: 443059 bytes
->Temporary Internet Files folder emptied: 48045574 bytes
->Java cache emptied: 15763061 bytes
->FireFox cache emptied: 191470122 bytes
->Google Chrome cache emptied: 25370779 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 72939 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50635 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 268,00 mb
 
 
OTL by OldTimer - Version 3.2.31.0 log created on 11142011_215242

Files\Folders moved on Reboot...
C:\Users\Hendrik\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...


markusg 15.11.2011 12:17

kurzer zwischenstand, wie läuft das system?

henniberlin 15.11.2011 16:45

bisher is das problem mit den falschen seiten nicht mehr aufgetreten :)

also alles gereinigt?

markusg 15.11.2011 17:05

noch nicht fertig.
lade den CCleaner standard:
CCleaner Download - CCleaner 3.12.1572
falls der CCleaner
bereits instaliert, überspringen.
instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

henniberlin 15.11.2011 17:46

habe jetz bei allen, wo mir die funktion nich genau bekannt is, unbekannt hingeschrieben


Code:

7-Zip 9.20                12.11.2011                unnötig
Acrobat.com        Adobe Systems Incorporated        19.07.2010        1,61MB        1.6.65    unbekannt
Adobe AIR        Adobe Systems Inc.        19.07.2010                1.5.0.7220          unbekannt
Adobe Flash Player 10 ActiveX        Adobe Systems Incorporated        19.07.2010                10.0.42.34    unbekannt
Adobe Flash Player 11 Plugin 64-bit        Adobe Systems Incorporated        06.10.2011        6,00MB        11.0.1.152 notwendig
Adobe Reader 9.1 MUI        Adobe Systems Incorporated        19.07.2010        650MB        9.1.0  notwendig
Alice Greenfingers        Oberon Media        19.07.2010                unbekannt
ASUS AI Recovery        ASUS        19.07.2010        2,76MB        1.0.9  unbekannt
ASUS AP Bank        ASUSTEK        19.07.2010                1.0.0.0        unbekannt
ASUS CopyProtect        ASUS        19.07.2010        3,62MB        1.0.0015        unbekannt
ASUS FancyStart        ASUSTeK Computer Inc.        19.07.2010        12,1MB        1.0.8        unbekannt
ASUS LifeFrame3        ASUS        19.07.2010        27,7MB        3.0.20        unbekannt
ASUS Live Update        ASUS        19.07.2010                2.5.9 unbekannt
ASUS MultiFrame        ASUS        19.07.2010                1.0.0021 unbekannt
ASUS Power4Gear Hybrid        ASUS        19.07.2010        12,2MB        1.1.35 unbekannt
ASUS SmartLogon        ASUS        19.07.2010        10,9MB        1.0.0008 unbekannt
ASUS Splendid Video Enhancement Technology        ASUS        19.07.2010        24,4MB        1.02.0028 unbekannt
ASUS Virtual Camera        asus        19.07.2010        3,12MB        1.0.19 unbekannt
ASUS WebStorage        eCareme Technologies, Inc.        19.07.2010                2.0.46.1429  unbekannt
ATI Catalyst Install Manager        ATI Technologies, Inc.        19.07.2010        22,1MB        3.0.758.0  unbekannt
ATK Package        ASUS        16.05.2011        12,3MB        1.0.0006 unbekannt
Bing Bar        Microsoft Corporation        22.08.2011        26,7MB        7.0.822.0 unbekannt
Boingo Wi-Fi        Boingo Wireless, Inc.        19.07.2010        25,4MB        1.7.0048  unbekannt
Call of Duty Black Ops AT UNCUT        pcblizzard        03.05.2011                v3.0  notwendig
CCleaner        Piriform        14.11.2011                3.12 notwendig
Chicken Invaders 2        Oberon Media        19.07.2010                unnötig
Conexant HD Audio        Conexant        19.07.2010                4.98.18.65 unbekannt
ControlDeck        ASUS        19.07.2010        1,80MB        1.0.6 unbekannt
Counter-Strike 1.6                12.04.2011                1.6 notwendig
CyberLink LabelPrint        CyberLink Corp.        18.07.2010        137,6MB        2.5.1908  unbekannt
CyberLink Power2Go        CyberLink Corp.        18.07.2010        110,4MB        6.1.3602c  unbekannt
DAEMON Tools Toolbar        DT Soft Ltd        05.12.2010                1.1.2.0185 unnötig
DivX-Setup        DivX, Inc.        17.11.2010                2.1.2.2 unbekannt
Dream Day Wedding Married in Manhattan        Oberon Media        19.07.2010        unbekannt       
DSF Fussball Manager 98                27.07.2011 unnötig               
Empire Earth                17.09.2011        unnötig       
ETDWare PS/2-x64 7.0.5.10_WHQL        ELAN Microelectronics Corp.        19.07.2010                7.0.5.10 unbekannt
Facemoods Toolbar                18.09.2011                unbekannt
Fast Boot        ASUS        19.07.2010        1,47MB        1.0.5 unbekannt
FIFA 09        Electronic Arts        23.10.2010        5.635MB        1.0.1.1 notwendig
Game Park Console        Oberon Media, Inc.        19.07.2010                6.2.0.2 unbekannt
Google Chrome        Google Inc.        19.07.2010                15.0.874.120 unnötig
Google Toolbar for Internet Explorer        Google Inc.        19.07.2010        unnötig       
Grand Theft Auto San Andreas        Rockstar Games        29.03.2011                1.00.00001 unnötig
ICQ7.7        ICQ        13.11.2011                7.7 notwendig
iMesh        iMesh Inc.        21.10.2011                11.0.0.116221 unbekannt
Indeo® Software                24.04.2011                unbekannt
Intel A/V Codecs V2.0                24.04.2011                unbekannt
Intel(R) Management Engine Components        Intel Corporation        20.07.2010                6.0.0.1179 unbekannt
Java(TM) 6 Update 29        Oracle        04.11.2011        97,1MB        6.0.290 notwendig
JDownloader 0.9        AppWork GmbH        18.09.2011                0.9 unbekannt
JMicron Ethernet Adapter NDIS Driver        JMicron Technology Corp.        19.07.2010                6.0.17.1 unbekannt
JMicron Flash Media Controller Driver        JMicron Technology Corp.        19.07.2010                1.0.33.2 unbekannt
K-Lite Mega Codec Pack 7.7.0                17.09.2011        48,3MB        7.7.0 notwendig
K_Series_ScreenSaver_EN                19.07.2010                unbekannt
LECTURNITY Player        imc AG        01.11.2010        83,8MB        4.0.0000 notwendig
Malwarebytes' Anti-Malware Version 1.51.2.1300        Malwarebytes Corporation        13.11.2011        13,8MB        1.51.2.1300 notwendig
Microsoft .NET Framework 4 Client Profile        Microsoft Corporation        15.11.2010        38,8MB        4.0.30319 unbekannt
Microsoft Age of Empires II                17.04.2011                unnötig
Microsoft Age of Empires II: The Conquerors Expansion                17.04.2011                unnötig
Microsoft Games for Windows - LIVE Redistributable        Microsoft Corporation        28.03.2011        32,5MB        2.0.672.0 unbekannt
Microsoft Office 2010        Microsoft Corporation        18.07.2010        6,31MB        14.0.4763.1000 notwendig
Microsoft Office Enterprise 2007        Microsoft Corporation        13.12.2010                12.0.6425.1000 notwendig
Microsoft Office File Validation Add-In        Microsoft Corporation        13.11.2011        7,95MB        14.0.5130.5003 notwendig
Microsoft Office Klick-und-Los 2010        Microsoft Corporation        26.10.2010                14.0.4763.1000 notwendig
Microsoft Office Outlook Connector        Microsoft Corporation        13.11.2011        3,36MB        14.0.5118.5000 notwendig
Microsoft Office Starter 2010 - Deutsch        Microsoft Corporation        26.10.2010                14.0.4763.1000 notwendig
Microsoft PowerPoint Viewer        Microsoft Corporation        09.11.2011        194,8MB        14.0.4763.1000 notwendig
Microsoft Rise Of Nations        Microsoft        17.09.2011                notwendig
Microsoft Silverlight        Microsoft Corporation        12.10.2011        160,3MB        4.0.60831.0 unbekannt
Microsoft SQL Server 2005 Compact Edition [ENU]        Microsoft Corporation        13.11.2011        1,70MB        3.1.0000 unbekannt
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053        Microsoft Corporation        26.10.2010        0,25MB        8.0.50727.4053 unbekannt
Microsoft Visual C++ 2005 Redistributable        Microsoft Corporation        15.06.2011        0,29MB        8.0.61001 unbekannt
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148        Microsoft Corporation        04.05.2011        0,19MB        9.0.30729.4148 unbekannt
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570        Microsoft Corporation        21.04.2011        0,77MB        9.0.30729.5570 unbekannt
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570        Microsoft Corporation        09.05.2011        0,58MB        9.0.30729.5570 unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148        Microsoft Corporation        19.07.2010        0,77MB        9.0.30729.4148 unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161        Microsoft Corporation        15.06.2011        0,77MB        9.0.30729.6161 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17        Microsoft Corporation        02.05.2011        0,58MB        9.0.30729 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161        Microsoft Corporation        15.06.2011        0,59MB        9.0.30729.6161 unbekannt
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319        Microsoft Corporation        06.05.2011        11,0MB        10.0.30319 unbekannt
Mozilla Firefox 8.0 (x86 de)        Mozilla        09.11.2011        35,5MB        8.0 notwendig
MSXML 4.0 SP3 Parser (KB973685)        Microsoft Corporation        19.07.2010        1,53MB        4.30.2107.0 unbekannt
MSXML4 Parser        Microsoft Game Studios        18.09.2011        1,28MB        1.0.0 unbekannt
NBA LIVE 06                25.02.2011                unnötig
Piggly FREE        Oberon Media        19.07.2010        unnötig       
PokerStars        PokerStars        16.07.2011        notwendig
R for Windows 2.13.0        R Development Core Team        09.05.2011        59,3MB        2.13.0 notwendig
Rise of Nations Thrones and Patriots                17.09.2011                notwendig
Sierra-Dienstprogramme                27.07.2011                notwendig
Smileyville FREE        Oberon Media        19.07.2010        unbekannt       
SopCast 3.4.0        www.sopcast.com        17.09.2011                3.4.0 notwendig
SRS Premium Sound Control Panel        SRS Labs, Inc.        19.07.2010        1,85MB        1.8.5100 unbekannt
syncables desktop SE        syncables        19.07.2010        163,5MB        5.5.615.9518 unbekannt
Trend Micro Internet Security        Trend Micro Inc.        19.07.2010        94,3MB        17.50 notwendig
USB2.0 UVC VGA WebCam        Sonix        19.07.2010                5.8.54000.205 notwendig
Veetle TV 0.9.18        Veetle, Inc        04.12.2010                0.9.18 notwendig
vShare.tv plugin 1.3        vShare.tv, Inc.        26.08.2011                1.3 notwendig
Windows 7 Upgrade Advisor        Microsoft Corporation        17.09.2011        9,53MB        2.0.5000.0 unbekannt
Windows Live Essentials        Microsoft Corporation        14.11.2011                15.4.3538.0513 unbekannt
Windows Live Mesh ActiveX control for remote connections        Microsoft Corporation        13.11.2011        5,58MB        15.4.5722.2 unbekannt
Windows Live Sync        Microsoft Corporation        22.10.2010        2,79MB        14.0.8117.416 unbekannt
WinFlash        ASUS        19.07.2010        0,82MB        2.30.1 unbekannt
WinRAR 4.00 (32-Bit)        win.rar GmbH        28.03.2011                4.00.0 notwendig
Wireless Console 3        ASUS        19.07.2010        2,43MB        3.0.15


markusg 15.11.2011 18:03

7-Zip würd ich behalten, vllt musst ja mal wieder n archiv erstellen.
deinstaliere
Acrobat.com
Adobe AIR



Adobe Reader 9
Adobe - Adobe Reader herunterladen - Alle Versionen
neueste version laden, ohne mcafee instalieren.
deinstaliere:
Alice Greenfingers
ASUS Virtual Camera
Bing Bar
Chicken Invaders
CyberLink beide
DAEMON Tools Toolbar
DivX-Setup
Dream Day
DSF Fussball
Empire Earth
Facemoods
Fast Boot
Google beide
Grand Theft
iMesh
Indeo®
JDownloader
NBA LIVE
Piggly
Smileyville
Trend Micro solltest du mal updaten.
Antiviren- und Content-Security-Software | Securing Your Web World - Trend Micro Deutschland
bei sicherheitssoftware immer das aktuellste nutzen


Windows Live falls du davon nichts nutzt, alles weg
bereinige mit dem ccleaner.

henniberlin 15.11.2011 18:32

ok und jetz ?

markusg 15.11.2011 18:41

http://www.trojaner-board.de/82358-t...entfernen.html
ausführen nichts löschen log posten

henniberlin 16.11.2011 10:42

Code:

10:38:32.0748 1284        TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
10:38:32.0966 1284        ============================================================
10:38:32.0966 1284        Current date / time: 2011/11/16 10:38:32.0966
10:38:32.0966 1284        SystemInfo:
10:38:32.0966 1284       
10:38:32.0966 1284        OS Version: 6.1.7601 ServicePack: 1.0
10:38:32.0966 1284        Product type: Workstation
10:38:32.0966 1284        ComputerName: HENNI
10:38:32.0966 1284        UserName: Hendrik
10:38:32.0966 1284        Windows directory: C:\Windows
10:38:32.0966 1284        System windows directory: C:\Windows
10:38:32.0966 1284        Running under WOW64
10:38:32.0966 1284        Processor architecture: Intel x64
10:38:32.0966 1284        Number of processors: 4
10:38:32.0966 1284        Page size: 0x1000
10:38:32.0966 1284        Boot type: Normal boot
10:38:32.0966 1284        ============================================================
10:38:33.0403 1284        Initialize success
10:40:02.0261 4168        ============================================================
10:40:02.0261 4168        Scan started
10:40:02.0261 4168        Mode: Manual;
10:40:02.0261 4168        ============================================================
10:40:03.0774 4168        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
10:40:03.0774 4168        1394ohci - ok
10:40:03.0914 4168        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
10:40:03.0930 4168        ACPI - ok
10:40:04.0023 4168        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
10:40:04.0023 4168        AcpiPmi - ok
10:40:04.0117 4168        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
10:40:04.0133 4168        adp94xx - ok
10:40:04.0164 4168        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
10:40:04.0164 4168        adpahci - ok
10:40:04.0335 4168        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
10:40:04.0335 4168        adpu320 - ok
10:40:04.0491 4168        AFD            (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
10:40:04.0491 4168        AFD - ok
10:40:04.0741 4168        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
10:40:04.0741 4168        agp440 - ok
10:40:04.0850 4168        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
10:40:04.0850 4168        aliide - ok
10:40:05.0022 4168        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
10:40:05.0022 4168        amdide - ok
10:40:05.0334 4168        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
10:40:05.0334 4168        AmdK8 - ok
10:40:05.0973 4168        amdkmdag        (52679612d742bf74ca1ba6ab86ddf431) C:\Windows\system32\DRIVERS\atipmdag.sys
10:40:06.0020 4168        amdkmdag - ok
10:40:06.0317 4168        amdkmdap        (414e0788920a8c856032be2cbf29f984) C:\Windows\system32\DRIVERS\atikmpag.sys
10:40:06.0317 4168        amdkmdap - ok
10:40:06.0473 4168        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
10:40:06.0473 4168        AmdPPM - ok
10:40:06.0535 4168        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
10:40:06.0535 4168        amdsata - ok
10:40:06.0753 4168        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
10:40:06.0753 4168        amdsbs - ok
10:40:06.0972 4168        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
10:40:06.0972 4168        amdxata - ok
10:40:07.0190 4168        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
10:40:07.0206 4168        AppID - ok
10:40:07.0331 4168        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
10:40:07.0331 4168        arc - ok
10:40:07.0565 4168        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
10:40:07.0565 4168        arcsas - ok
10:40:07.0830 4168        ASMMAP64        (4c016fd76ed5c05e84ca8cab77993961) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
10:40:07.0830 4168        ASMMAP64 - ok
10:40:08.0064 4168        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
10:40:08.0064 4168        AsyncMac - ok
10:40:08.0376 4168        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
10:40:08.0376 4168        atapi - ok
10:40:08.0657 4168        athr            (f8633cdd09647a64ee8db550630427ff) C:\Windows\system32\DRIVERS\athrx.sys
10:40:08.0672 4168        athr - ok
10:40:09.0062 4168        AtiHdmiService  (fb7602c5c508be281368aae0b61b51c6) C:\Windows\system32\drivers\AtiHdmi.sys
10:40:09.0062 4168        AtiHdmiService - ok
10:40:09.0920 4168        atikmdag        (52679612d742bf74ca1ba6ab86ddf431) C:\Windows\system32\DRIVERS\atikmdag.sys
10:40:09.0967 4168        atikmdag - ok
10:40:10.0263 4168        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
10:40:10.0263 4168        b06bdrv - ok
10:40:10.0482 4168        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
10:40:10.0482 4168        b57nd60a - ok
10:40:10.0685 4168        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
10:40:10.0685 4168        Beep - ok
10:40:10.0919 4168        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
10:40:10.0919 4168        blbdrive - ok
10:40:11.0090 4168        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
10:40:11.0090 4168        bowser - ok
10:40:11.0355 4168        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:40:11.0355 4168        BrFiltLo - ok
10:40:11.0574 4168        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:40:11.0574 4168        BrFiltUp - ok
10:40:11.0839 4168        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
10:40:11.0839 4168        Brserid - ok
10:40:11.0948 4168        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
10:40:11.0948 4168        BrSerWdm - ok
10:40:12.0122 4168        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
10:40:12.0122 4168        BrUsbMdm - ok
10:40:12.0262 4168        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
10:40:12.0262 4168        BrUsbSer - ok
10:40:12.0371 4168        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
10:40:12.0371 4168        BTHMODEM - ok
10:40:12.0403 4168        catchme - ok
10:40:12.0527 4168        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
10:40:12.0527 4168        cdfs - ok
10:40:12.0574 4168        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
10:40:12.0574 4168        cdrom - ok
10:40:12.0652 4168        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
10:40:12.0652 4168        circlass - ok
10:40:12.0715 4168        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
10:40:12.0715 4168        CLFS - ok
10:40:12.0808 4168        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
10:40:12.0808 4168        CmBatt - ok
10:40:12.0824 4168        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
10:40:12.0824 4168        cmdide - ok
10:40:12.0871 4168        CNG            (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
10:40:12.0871 4168        CNG - ok
10:40:12.0933 4168        CnxtHdAudService (f7ca3accf5aa0e2182546c5be42b2e96) C:\Windows\system32\drivers\CHDRT64.sys
10:40:12.0933 4168        CnxtHdAudService - ok
10:40:12.0980 4168        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
10:40:12.0980 4168        Compbatt - ok
10:40:13.0011 4168        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
10:40:13.0011 4168        CompositeBus - ok
10:40:13.0042 4168        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
10:40:13.0042 4168        crcdisk - ok
10:40:13.0151 4168        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
10:40:13.0167 4168        DfsC - ok
10:40:13.0229 4168        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
10:40:13.0229 4168        discache - ok
10:40:13.0385 4168        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
10:40:13.0385 4168        Disk - ok
10:40:13.0838 4168        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
10:40:13.0838 4168        drmkaud - ok
10:40:14.0312 4168        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
10:40:14.0328 4168        DXGKrnl - ok
10:40:15.0030 4168        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
10:40:15.0061 4168        ebdrv - ok
10:40:15.0451 4168        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
10:40:15.0451 4168        elxstor - ok
10:40:15.0732 4168        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
10:40:15.0732 4168        ErrDev - ok
10:40:15.0997 4168        ETD            (06c94be9d9e1e6411429433a64a76936) C:\Windows\system32\DRIVERS\ETD.sys
10:40:15.0997 4168        ETD - ok
10:40:16.0309 4168        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
10:40:16.0309 4168        exfat - ok
10:40:16.0403 4168        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
10:40:16.0403 4168        fastfat - ok
10:40:16.0449 4168        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
10:40:16.0449 4168        fdc - ok
10:40:16.0574 4168        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
10:40:16.0574 4168        FileInfo - ok
10:40:16.0621 4168        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
10:40:16.0621 4168        Filetrace - ok
10:40:16.0668 4168        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
10:40:16.0668 4168        flpydisk - ok
10:40:16.0730 4168        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
10:40:16.0730 4168        FltMgr - ok
10:40:16.0793 4168        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
10:40:16.0793 4168        FsDepends - ok
10:40:16.0917 4168        fssfltr        (dc0dce4ec2c5d2cf6472f9fd6aa9a7dc) C:\Windows\system32\DRIVERS\fssfltr.sys
10:40:16.0917 4168        fssfltr - ok
10:40:16.0980 4168        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
10:40:16.0980 4168        Fs_Rec - ok
10:40:17.0058 4168        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
10:40:17.0058 4168        fvevol - ok
10:40:17.0136 4168        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
10:40:17.0136 4168        gagp30kx - ok
10:40:17.0198 4168        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
10:40:17.0198 4168        hcw85cir - ok
10:40:17.0307 4168        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
10:40:17.0307 4168        HdAudAddService - ok
10:40:17.0370 4168        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
10:40:17.0370 4168        HDAudBus - ok
10:40:17.0417 4168        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
10:40:17.0417 4168        HECIx64 - ok
10:40:17.0448 4168        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
10:40:17.0448 4168        HidBatt - ok
10:40:17.0479 4168        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
10:40:17.0495 4168        HidBth - ok
10:40:17.0526 4168        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
10:40:17.0526 4168        HidIr - ok
10:40:17.0573 4168        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
10:40:17.0573 4168        HidUsb - ok
10:40:17.0635 4168        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
10:40:17.0635 4168        HpSAMD - ok
10:40:17.0697 4168        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
10:40:17.0713 4168        HTTP - ok
10:40:17.0775 4168        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
10:40:17.0775 4168        hwpolicy - ok
10:40:17.0838 4168        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
10:40:17.0838 4168        i8042prt - ok
10:40:17.0916 4168        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
10:40:17.0916 4168        iaStor - ok
10:40:17.0994 4168        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
10:40:17.0994 4168        iaStorV - ok
10:40:18.0056 4168        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
10:40:18.0056 4168        iirsp - ok
10:40:18.0103 4168        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
10:40:18.0103 4168        intelide - ok
10:40:18.0165 4168        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
10:40:18.0165 4168        intelppm - ok
10:40:18.0243 4168        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:40:18.0243 4168        IpFilterDriver - ok
10:40:18.0306 4168        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
10:40:18.0306 4168        IPMIDRV - ok
10:40:18.0368 4168        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
10:40:18.0368 4168        IPNAT - ok
10:40:18.0415 4168        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
10:40:18.0415 4168        IRENUM - ok
10:40:18.0477 4168        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
10:40:18.0477 4168        isapnp - ok
10:40:18.0540 4168        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
10:40:18.0540 4168        iScsiPrt - ok
10:40:18.0602 4168        JMCR            (db917b998cbc15a153c00dd6efc34c13) C:\Windows\system32\DRIVERS\jmcr.sys
10:40:18.0602 4168        JMCR - ok
10:40:18.0665 4168        JME            (de4b2249d95c7815d06a39ea5ff4ee53) C:\Windows\system32\DRIVERS\JME.sys
10:40:18.0665 4168        JME - ok
10:40:18.0743 4168        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
10:40:18.0743 4168        kbdclass - ok
10:40:18.0789 4168        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
10:40:18.0789 4168        kbdhid - ok
10:40:18.0852 4168        kbfiltr        (e63ef8c3271d014f14e2469ce75fecb4) C:\Windows\system32\DRIVERS\kbfiltr.sys
10:40:18.0852 4168        kbfiltr - ok
10:40:18.0899 4168        KMWDFILTER      (07071c1e3cd8f0f9114aac8b072ca1e5) C:\Windows\system32\DRIVERS\KMWDFILTER.sys
10:40:18.0899 4168        KMWDFILTER - ok
10:40:18.0961 4168        KSecDD          (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
10:40:18.0977 4168        KSecDD - ok
10:40:19.0023 4168        KSecPkg        (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
10:40:19.0023 4168        KSecPkg - ok
10:40:19.0086 4168        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
10:40:19.0086 4168        ksthunk - ok
10:40:19.0164 4168        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
10:40:19.0164 4168        lltdio - ok
10:40:19.0226 4168        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
10:40:19.0226 4168        LSI_FC - ok
10:40:19.0257 4168        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
10:40:19.0257 4168        LSI_SAS - ok
10:40:19.0289 4168        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
10:40:19.0289 4168        LSI_SAS2 - ok
10:40:19.0335 4168        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
10:40:19.0335 4168        LSI_SCSI - ok
10:40:19.0382 4168        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
10:40:19.0382 4168        luafv - ok
10:40:19.0445 4168        lullaby        (085435ae1a124361304044029b5cc644) C:\Windows\system32\DRIVERS\lullaby.sys
10:40:19.0445 4168        lullaby - ok
10:40:19.0507 4168        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
10:40:19.0507 4168        megasas - ok
10:40:19.0554 4168        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
10:40:19.0554 4168        MegaSR - ok
10:40:19.0585 4168        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
10:40:19.0585 4168        Modem - ok
10:40:19.0632 4168        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
10:40:19.0632 4168        monitor - ok
10:40:19.0694 4168        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
10:40:19.0694 4168        mouclass - ok
10:40:19.0757 4168        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
10:40:19.0757 4168        mouhid - ok
10:40:19.0835 4168        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
10:40:19.0835 4168        mountmgr - ok
10:40:19.0913 4168        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
10:40:19.0913 4168        mpio - ok
10:40:19.0975 4168        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
10:40:19.0975 4168        mpsdrv - ok
10:40:20.0037 4168        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
10:40:20.0037 4168        MRxDAV - ok
10:40:20.0084 4168        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:40:20.0084 4168        mrxsmb - ok
10:40:20.0162 4168        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:40:20.0162 4168        mrxsmb10 - ok
10:40:20.0225 4168        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:40:20.0225 4168        mrxsmb20 - ok
10:40:20.0287 4168        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
10:40:20.0287 4168        msahci - ok
10:40:20.0349 4168        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
10:40:20.0365 4168        msdsm - ok
10:40:20.0505 4168        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
10:40:20.0505 4168        Msfs - ok
10:40:20.0552 4168        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
10:40:20.0552 4168        mshidkmdf - ok
10:40:20.0615 4168        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
10:40:20.0615 4168        msisadrv - ok
10:40:20.0693 4168        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
10:40:20.0693 4168        MSKSSRV - ok
10:40:20.0739 4168        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
10:40:20.0739 4168        MSPCLOCK - ok
10:40:20.0802 4168        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
10:40:20.0802 4168        MSPQM - ok
10:40:20.0864 4168        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
10:40:20.0864 4168        MsRPC - ok
10:40:20.0942 4168        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
10:40:20.0942 4168        mssmbios - ok
10:40:21.0005 4168        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
10:40:21.0005 4168        MSTEE - ok
10:40:21.0036 4168        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
10:40:21.0036 4168        MTConfig - ok
10:40:21.0098 4168        MTsensor        (032d35c996f21d19a205a7c8f0b76f3c) C:\Windows\system32\DRIVERS\ATK64AMD.sys
10:40:21.0098 4168        MTsensor - ok
10:40:21.0161 4168        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
10:40:21.0161 4168        Mup - ok
10:40:21.0239 4168        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
10:40:21.0239 4168        NativeWifiP - ok
10:40:21.0332 4168        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
10:40:21.0332 4168        NDIS - ok
10:40:21.0426 4168        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
10:40:21.0426 4168        NdisCap - ok
10:40:21.0473 4168        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
10:40:21.0473 4168        NdisTapi - ok
10:40:21.0519 4168        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
10:40:21.0519 4168        Ndisuio - ok
10:40:21.0582 4168        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
10:40:21.0582 4168        NdisWan - ok
10:40:21.0644 4168        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
10:40:21.0644 4168        NDProxy - ok
10:40:21.0691 4168        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
10:40:21.0691 4168        NetBIOS - ok
10:40:21.0769 4168        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
10:40:21.0769 4168        NetBT - ok
10:40:21.0863 4168        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
10:40:21.0863 4168        nfrd960 - ok
10:40:22.0190 4168        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
10:40:22.0190 4168        Npfs - ok
10:40:22.0253 4168        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
10:40:22.0253 4168        nsiproxy - ok
10:40:22.0362 4168        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
10:40:22.0362 4168        Ntfs - ok
10:40:22.0455 4168        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
10:40:22.0455 4168        Null - ok
10:40:22.0502 4168        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
10:40:22.0502 4168        nvraid - ok
10:40:22.0549 4168        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
10:40:22.0549 4168        nvstor - ok
10:40:22.0627 4168        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
10:40:22.0627 4168        nv_agp - ok
10:40:22.0674 4168        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
10:40:22.0674 4168        ohci1394 - ok
10:40:22.0783 4168        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
10:40:22.0783 4168        Parport - ok
10:40:22.0845 4168        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
10:40:22.0861 4168        partmgr - ok
10:40:22.0908 4168        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
10:40:22.0908 4168        pci - ok
10:40:22.0955 4168        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
10:40:22.0955 4168        pciide - ok
10:40:23.0001 4168        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
10:40:23.0001 4168        pcmcia - ok
10:40:23.0064 4168        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
10:40:23.0064 4168        pcw - ok
10:40:23.0111 4168        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
10:40:23.0126 4168        PEAUTH - ok
10:40:23.0251 4168        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
10:40:23.0251 4168        PptpMiniport - ok
10:40:23.0313 4168        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
10:40:23.0313 4168        Processor - ok
10:40:23.0376 4168        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
10:40:23.0391 4168        Psched - ok
10:40:23.0485 4168        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
10:40:23.0485 4168        ql2300 - ok
10:40:23.0547 4168        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
10:40:23.0547 4168        ql40xx - ok
10:40:23.0594 4168        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
10:40:23.0594 4168        QWAVEdrv - ok
10:40:23.0625 4168        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
10:40:23.0625 4168        RasAcd - ok
10:40:23.0672 4168        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
10:40:23.0672 4168        RasAgileVpn - ok
10:40:23.0735 4168        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:40:23.0735 4168        Rasl2tp - ok
10:40:23.0797 4168        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
10:40:23.0797 4168        RasPppoe - ok
10:40:23.0828 4168        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
10:40:23.0844 4168        RasSstp - ok
10:40:23.0906 4168        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
10:40:23.0906 4168        rdbss - ok
10:40:23.0953 4168        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
10:40:23.0953 4168        rdpbus - ok
10:40:24.0000 4168        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:40:24.0000 4168        RDPCDD - ok
10:40:24.0047 4168        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
10:40:24.0047 4168        RDPENCDD - ok
10:40:24.0078 4168        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
10:40:24.0078 4168        RDPREFMP - ok
10:40:24.0140 4168        RDPWD          (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
10:40:24.0140 4168        RDPWD - ok
10:40:24.0218 4168        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
10:40:24.0218 4168        rdyboost - ok
10:40:24.0359 4168        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
10:40:24.0359 4168        rspndr - ok
10:40:24.0421 4168        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
10:40:24.0421 4168        sbp2port - ok
10:40:24.0499 4168        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
10:40:24.0499 4168        scfilter - ok
10:40:24.0608 4168        sdbus          (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
10:40:24.0608 4168        sdbus - ok
10:40:24.0655 4168        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
10:40:24.0655 4168        secdrv - ok
10:40:24.0717 4168        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
10:40:24.0717 4168        Serenum - ok
10:40:24.0764 4168        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
10:40:24.0764 4168        Serial - ok
10:40:24.0811 4168        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
10:40:24.0811 4168        sermouse - ok
10:40:24.0889 4168        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
10:40:24.0889 4168        sffdisk - ok
10:40:24.0967 4168        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
10:40:24.0967 4168        sffp_mmc - ok
10:40:25.0029 4168        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
10:40:25.0029 4168        sffp_sd - ok
10:40:25.0123 4168        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
10:40:25.0123 4168        sfloppy - ok
10:40:25.0185 4168        Sftfs          (a40abfdcb75f835fdf3ce0cc64e4250d) C:\Windows\system32\DRIVERS\Sftfslh.sys
10:40:25.0201 4168        Sftfs - ok
10:40:25.0263 4168        Sftplay        (411769ed1cb12d2b44217734347bdb7a) C:\Windows\system32\DRIVERS\Sftplaylh.sys
10:40:25.0263 4168        Sftplay - ok
10:40:25.0310 4168        Sftredir        (a14d0df34bbb00ea94da16193d0c7957) C:\Windows\system32\DRIVERS\Sftredirlh.sys
10:40:25.0326 4168        Sftredir - ok
10:40:25.0373 4168        Sftvol          (393b22addd89979eb1c60898f51c3648) C:\Windows\system32\DRIVERS\Sftvollh.sys
10:40:25.0373 4168        Sftvol - ok
10:40:25.0513 4168        SiSGbeLH        (1bc348cf6baa90ec8e533ef6e6a69933) C:\Windows\system32\DRIVERS\SiSG664.sys
10:40:25.0513 4168        SiSGbeLH - ok
10:40:25.0544 4168        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:40:25.0544 4168        SiSRaid2 - ok
10:40:25.0575 4168        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
10:40:25.0575 4168        SiSRaid4 - ok
10:40:25.0622 4168        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
10:40:25.0622 4168        Smb - ok
10:40:25.0716 4168        SNP2UVC        (2114518e55b380a3acc28b2c27fd499a) C:\Windows\system32\DRIVERS\snp2uvc.sys
10:40:25.0731 4168        SNP2UVC - ok
10:40:25.0794 4168        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
10:40:25.0794 4168        spldr - ok
10:40:25.0887 4168        sptd            (602884696850c86434530790b110e8eb) C:\Windows\System32\Drivers\sptd.sys
10:40:25.0887 4168        sptd - ok
10:40:25.0950 4168        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
10:40:25.0950 4168        srv - ok
10:40:26.0028 4168        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
10:40:26.0028 4168        srv2 - ok
10:40:26.0090 4168        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
10:40:26.0090 4168        srvnet - ok
10:40:26.0153 4168        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
10:40:26.0153 4168        stexstor - ok
10:40:26.0215 4168        StillCam        (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
10:40:26.0215 4168        StillCam - ok
10:40:26.0277 4168        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
10:40:26.0277 4168        swenum - ok
10:40:26.0418 4168        Tcpip          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
10:40:26.0433 4168        Tcpip - ok
10:40:26.0543 4168        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
10:40:26.0558 4168        TCPIP6 - ok
10:40:26.0652 4168        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
10:40:26.0652 4168        tcpipreg - ok
10:40:26.0714 4168        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
10:40:26.0714 4168        TDPIPE - ok
10:40:26.0745 4168        TDTCP          (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
10:40:26.0745 4168        TDTCP - ok
10:40:26.0823 4168        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
10:40:26.0823 4168        tdx - ok
10:40:26.0870 4168        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
10:40:26.0870 4168        TermDD - ok
10:40:26.0979 4168        tmpreflt        (803ee35df92815ea5d41cee7410c8cc1) C:\Windows\system32\DRIVERS\tmpreflt.sys
10:40:26.0979 4168        tmpreflt - ok
10:40:27.0042 4168        tmtdi          (21cc12b7f8b44e91d03ead5b17aaf0b2) C:\Windows\system32\DRIVERS\tmtdi.sys
10:40:27.0042 4168        tmtdi - ok
10:40:27.0104 4168        tmxpflt        (9bd32132a3470cefb3cbea5fa492bd6f) C:\Windows\system32\DRIVERS\tmxpflt.sys
10:40:27.0104 4168        tmxpflt - ok
10:40:27.0432 4168        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:40:27.0432 4168        tssecsrv - ok
10:40:27.0572 4168        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
10:40:27.0572 4168        TsUsbFlt - ok
10:40:27.0635 4168        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
10:40:27.0635 4168        tunnel - ok
10:40:27.0697 4168        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
10:40:27.0697 4168        uagp35 - ok
10:40:27.0962 4168        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
10:40:27.0978 4168        udfs - ok
10:40:28.0290 4168        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
10:40:28.0290 4168        uliagpkx - ok
10:40:28.0477 4168        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
10:40:28.0508 4168        umbus - ok
10:40:28.0758 4168        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
10:40:28.0758 4168        UmPass - ok
10:40:29.0023 4168        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
10:40:29.0023 4168        usbccgp - ok
10:40:29.0319 4168        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
10:40:29.0319 4168        usbcir - ok
10:40:29.0538 4168        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
10:40:29.0538 4168        usbehci - ok
10:40:29.0912 4168        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
10:40:29.0928 4168        usbhub - ok
10:40:30.0259 4168        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
10:40:30.0259 4168        usbohci - ok
10:40:30.0478 4168        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
10:40:30.0478 4168        usbprint - ok
10:40:30.0759 4168        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\drivers\USBSTOR.SYS
10:40:30.0759 4168        USBSTOR - ok
10:40:30.0930 4168        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
10:40:30.0930 4168        usbuhci - ok
10:40:30.0977 4168        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
10:40:30.0977 4168        usbvideo - ok
10:40:31.0039 4168        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
10:40:31.0039 4168        vdrvroot - ok
10:40:31.0164 4168        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
10:40:31.0164 4168        vga - ok
10:40:31.0211 4168        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
10:40:31.0211 4168        VgaSave - ok
10:40:31.0273 4168        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
10:40:31.0273 4168        vhdmp - ok
10:40:31.0320 4168        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
10:40:31.0320 4168        viaide - ok
10:40:31.0383 4168        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
10:40:31.0383 4168        volmgr - ok
10:40:31.0445 4168        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
10:40:31.0445 4168        volmgrx - ok
10:40:31.0507 4168        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
10:40:31.0507 4168        volsnap - ok
10:40:31.0601 4168        vsapint        (b01ce1f5a44126892240d179a6dbd43f) C:\Windows\system32\DRIVERS\vsapint.sys
10:40:31.0617 4168        vsapint - ok
10:40:31.0710 4168        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
10:40:31.0710 4168        vsmraid - ok
10:40:31.0773 4168        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
10:40:31.0788 4168        vwifibus - ok
10:40:31.0835 4168        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
10:40:31.0835 4168        vwififlt - ok
10:40:31.0929 4168        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
10:40:31.0929 4168        vwifimp - ok
10:40:32.0085 4168        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
10:40:32.0085 4168        WacomPen - ok
10:40:32.0147 4168        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
10:40:32.0147 4168        WANARP - ok
10:40:32.0163 4168        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
10:40:32.0163 4168        Wanarpv6 - ok
10:40:32.0272 4168        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
10:40:32.0272 4168        Wd - ok
10:40:32.0334 4168        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
10:40:32.0334 4168        Wdf01000 - ok
10:40:32.0475 4168        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
10:40:32.0475 4168        WfpLwf - ok
10:40:32.0537 4168        WimFltr        (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
10:40:32.0537 4168        WimFltr - ok
10:40:32.0599 4168        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
10:40:32.0599 4168        WIMMount - ok
10:40:32.0693 4168        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
10:40:32.0693 4168        WinUsb - ok
10:40:32.0771 4168        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
10:40:32.0771 4168        WmiAcpi - ok
10:40:32.0849 4168        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
10:40:32.0849 4168        ws2ifsl - ok
10:40:32.0958 4168        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
10:40:32.0958 4168        WudfPf - ok
10:40:33.0122 4168        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:40:33.0122 4168        WUDFRd - ok
10:40:33.0183 4168        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:40:33.0245 4168        \Device\Harddisk0\DR0 - ok
10:40:33.0245 4168        Boot (0x1200)  (51e433db73dafaaabd15429022218f7b) \Device\Harddisk0\DR0\Partition0
10:40:33.0245 4168        \Device\Harddisk0\DR0\Partition0 - ok
10:40:33.0261 4168        Boot (0x1200)  (ae1cda363254382a83dd60a6bfae5bee) \Device\Harddisk0\DR0\Partition1
10:40:33.0277 4168        \Device\Harddisk0\DR0\Partition1 - ok
10:40:33.0277 4168        ============================================================
10:40:33.0277 4168        Scan finished
10:40:33.0277 4168        ============================================================
10:40:33.0401 4580        Detected object count: 0
10:40:33.0401 4580        Actual detected object count: 0
10:40:54.0399 4648        Deinitialize success


markusg 16.11.2011 13:23

sieht gut aus, öffne otl, klicke bereinigen,
die meisten von uns genutzten tools werden gelöscht.
wenn alles io ist, können wir den pc noch absichern falls du magst.

henniberlin 16.11.2011 18:04

super, können wa machen

und dann hab ich noch n kleines problem

beim start von windows öffnet sich immer das programm asus control deck und der bildschirm wird für einige sekunden schwarz...nervt halt auf lange sicht

markusg 16.11.2011 18:22

gehe mal auf start suchen tippe
msconfig
enter
systemstart
da kannst du überall den haken raus nehmen wies aussieht.
dann übernehmen ok.
neustarten und gucken ob das problem noch auftritt

henniberlin 16.11.2011 19:23

da hatte ich schon geguckt, control deck gibts da nicht

markusg 16.11.2011 19:38

trotzdem da mal bitte alles abschalten, ist unnütz was da startet. und dann neustarten.

henniberlin 16.11.2011 20:47

es kann so einfach sein :)
danke :D

und was war wegen absichern?

markusg 16.11.2011 21:04

hi, ja man muss ja nicht das ganze unnötige dedöns mit starten lassen, kostet ja alles nur leistung.
da ich dir nen anderes antimalware programm empfehle, deinstaliere deins.
da ich nen andern browser empfehle musst du mir sagen ob der dir zusagt, sonst muss ich die anleitung anpassen, der rest sollte bitte komplett umgesetzt werden!


http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
Als nächstes kommen wir zu dem Antimalware Programm.
Dieses ist ein wichtiger Bestandteil des Sicherheitskonzeptes, deswegen sollte man sich gut überlegen, welche Wahl man trifft.
Bei den kostenlosen Scannern halte ich Persönlich Avast! für die beste Wahl.
Als kostenpflichtiges würde ich Emsisoft empfehlen
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware
Weitere Vertreter .
kaspersky:
Kaspersky Lab: Antivirus software
Symantec (Norton)
Symantec - AntiVirus, Anti-Spyware, Endpoint Security, Backup, Storage Solutions

Browserwahl:
Da wir häufig mit dem Browser arbeiten, ist diese Wahl natürlich ebenfalls wichtig, die wichtigen Vertreter befinden sich in dem Verlinktem Thema.
ich persönlich rate dir zum opera
Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
http://filepony.de/download-sandboxie/
anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
http://filepony.de/download-sandboxie/

Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
Anleitung: Backup mit Windows 7-Bordmitteln - NETZWELT
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

henniberlin 16.11.2011 21:24

ok werd ich mir ma alles angucken

und danke nochma :D


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131