Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Firewall Vista funktioniert nicht, kein Internetzugang, Trojaner? (https://www.trojaner-board.de/106601-firewall-vista-funktioniert-kein-internetzugang-trojaner.html)

cosinus 22.12.2011 17:34

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:51919
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{4ecad743-72c5-11df-927e-0021707e92e8}\Shell - "" = AutoRun
O33 - MountPoints2\{4ecad743-72c5-11df-927e-0021707e92e8}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{50827675-3c8b-11df-98e2-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{50827675-3c8b-11df-98e2-00a0c6000000}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{76a96e77-746e-11df-9e7d-0021707e92e8}\Shell - "" = AutoRun
O33 - MountPoints2\{76a96e77-746e-11df-9e7d-0021707e92e8}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
:Files
C:\Program Files\LP
C:\Users\Mankel\AppData\Local\ElevatedDiagnostics
C:\Users\Mankel\AppData\Local\b966f25c
C:\Users\Mankel\AppData\Roaming\6E83C
C:\Users\Mankel\AppData\Roaming\26B6E
C:\Windows\Tasks\At1.job
C:\Windows\$NtUninstallKB46277$
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Michael_w 29.12.2011 14:02

Hallo,

sorry wegen der späten Rückmeldung, Weihnachten ist dazwischen gekommen. Vielen vielen Dank für die Hilfe! Ich habe jetzt den OTL-Fix durchgeführt, soll ich jetzt nochmal einen Scan machen bzw. wie kann ich sichergehen, dass mein Rechner "kuriert" ist?

100000000 Dank!

cosinus 29.12.2011 16:47

Du solltest doch das Fixlog posten...

Michael_w 29.12.2011 16:57

ups sorry, im eifer des gefechts die letzten beiden sätze überlesen.
kann ich irgendwie nochmal an das fixlog rankommen? ist es evtl. das hier?

Code:

All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4ecad743-72c5-11df-927e-0021707e92e8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4ecad743-72c5-11df-927e-0021707e92e8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4ecad743-72c5-11df-927e-0021707e92e8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4ecad743-72c5-11df-927e-0021707e92e8}\ not found.
File G:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50827675-3c8b-11df-98e2-00a0c6000000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50827675-3c8b-11df-98e2-00a0c6000000}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50827675-3c8b-11df-98e2-00a0c6000000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50827675-3c8b-11df-98e2-00a0c6000000}\ not found.
File G:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{76a96e77-746e-11df-9e7d-0021707e92e8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76a96e77-746e-11df-9e7d-0021707e92e8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{76a96e77-746e-11df-9e7d-0021707e92e8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76a96e77-746e-11df-9e7d-0021707e92e8}\ not found.
File G:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
File G:\setup_vmc_lite.exe /checkApplicationPresence not found.
========== FILES ==========
C:\Program Files\LP\2102 folder moved successfully.
C:\Program Files\LP folder moved successfully.
C:\Users\Mankel\AppData\Local\ElevatedDiagnostics\2035183873\2011121921.000\ElevatedDiagnostics\Images folder moved successfully.
C:\Users\Mankel\AppData\Local\ElevatedDiagnostics\2035183873\2011121921.000\ElevatedDiagnostics folder moved successfully.
C:\Users\Mankel\AppData\Local\ElevatedDiagnostics\2035183873\2011121921.000 folder moved successfully.
C:\Users\Mankel\AppData\Local\ElevatedDiagnostics\2035183873 folder moved successfully.
C:\Users\Mankel\AppData\Local\ElevatedDiagnostics folder moved successfully.
C:\Users\Mankel\AppData\Local\b966f25c\U folder moved successfully.
C:\Users\Mankel\AppData\Local\b966f25c folder moved successfully.
C:\Users\Mankel\AppData\Roaming\6E83C folder moved successfully.
C:\Users\Mankel\AppData\Roaming\26B6E folder moved successfully.
C:\Windows\Tasks\At1.job moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\TxR scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\Vorlagen folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Videos folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Startmenü folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\SendTo folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Searches folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Saved Games folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Recent folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Pictures\Slide Shows folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Pictures folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Netzwerkumgebung folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Music\Playlists folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Music folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Lokale Einstellungen folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Links folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Favorites folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Eigene Dateien folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Druckumgebung folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Downloads folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Documents\Eigene Videos folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Documents\Eigene Musik folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Documents\Eigene Bilder folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Documents folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Desktop folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Cookies folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\Contacts folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Vodafone\Vodafone Mobile Connect\UserData folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Vodafone\Vodafone Mobile Connect\Temp folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Vodafone\Vodafone Mobile Connect\Log folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Vodafone\Vodafone Mobile Connect folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Vodafone folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Templates folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programme folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Recent folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Speech\Files\UserLexicons folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Speech\Files folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Speech folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\TLGK0TQZ folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\O8NB2Y5F folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\JJK9P4ZE folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\G7P3KSE3 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Internet Explorer folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\S4Z2RN6U folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia\Flash Player folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Macromedia folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Apple Computer\Logs folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Apple Computer folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Adobe\Flash Player\AssetCache\52YCDETG folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Adobe\Flash Player\AssetCache folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Adobe\Flash Player folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Adobe folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\6baea4fe-13ab34eb-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\5b902232-543b1d27-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\4f710eed-6acf59fb-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\39ba6e6-26a4e90c-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\3976f065-3902acb9-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\2c4a0065-34e27063-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\258cea61-54f95908-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\4e09eacf-68765f58-n folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun\Java folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Sun folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Microsoft scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Apple Computer\QuickTime folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Apple Computer folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Verlauf folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Temporary Internet Files folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows Sidebar\Gadgets folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows Sidebar folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows Photo Gallery\Original Images folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows Photo Gallery folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows Media\11.0 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows Media folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\History scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\GameExplorer folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Burn\Burn folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Burn folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Portable Devices folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Internet Explorer scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Apps\2.0\66Z168BA.8HH\NCG4GV1B.OEE\manifests folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Apps\2.0\66Z168BA.8HH\NCG4GV1B.OEE folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Apps\2.0\66Z168BA.8HH folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Apps\2.0 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Apps folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Anwendungsdaten folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\Anwendungsdaten folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\RegBack scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\Journal folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$ scheduled to be moved on reboot.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Mankel
->Temp folder emptied: 4648754 bytes
->Temporary Internet Files folder emptied: 9837062 bytes
->Java cache emptied: 45822 bytes
->FireFox cache emptied: 43176022 bytes
->Flash cache emptied: 562 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 19980 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 55,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 12292011_135002

Files\Folders moved on Reboot...
Folder move failed. C:\Windows\$NtUninstallKB46277$\TxR scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\Windows folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow\Microsoft folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\LocalLow folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5 folder moved successfully.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\History folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows scheduled to be moved on reboot.
C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Internet Explorer folder moved successfully.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\RegBack scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\TxR scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Roaming scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4AT38DB scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSLNLVG2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYTT6XLA scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8G9DU84 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1J8JOVR2 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft\Windows scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local\Microsoft scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData\Local scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile\AppData scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\systemprofile scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$\RegBack scheduled to be moved on reboot.
Folder move failed. C:\Windows\$NtUninstallKB46277$ scheduled to be moved on reboot.
File move failed. C:\Windows\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 29.12.2011 17:17

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Michael_w 29.12.2011 17:52

hab ich gemacht, hier das log:

Code:

17:45:16.0734 2868        TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
17:45:16.0906 2868        ============================================================
17:45:16.0906 2868        Current date / time: 2011/12/29 17:45:16.0906
17:45:16.0906 2868        SystemInfo:
17:45:16.0906 2868       
17:45:16.0906 2868        OS Version: 6.0.6002 ServicePack: 2.0
17:45:16.0906 2868        Product type: Workstation
17:45:16.0906 2868        ComputerName: MANKEL-PC
17:45:16.0906 2868        UserName: Mankel
17:45:16.0906 2868        Windows directory: C:\Windows
17:45:16.0906 2868        System windows directory: C:\Windows
17:45:16.0906 2868        Processor architecture: Intel x86
17:45:16.0906 2868        Number of processors: 2
17:45:16.0906 2868        Page size: 0x1000
17:45:16.0906 2868        Boot type: Normal boot
17:45:16.0906 2868        ============================================================
17:45:17.0702 2868        Initialize success
17:46:04.0934 3316        ============================================================
17:46:04.0934 3316        Scan started
17:46:04.0934 3316        Mode: Manual; SigCheck; TDLFS;
17:46:04.0934 3316        ============================================================
17:46:09.0443 3316        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
17:46:09.0646 3316        ACPI - ok
17:46:09.0739 3316        adp94xx        (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
17:46:09.0786 3316        adp94xx - ok
17:46:10.0020 3316        adpahci        (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
17:46:10.0051 3316        adpahci - ok
17:46:10.0192 3316        adpu160m        (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
17:46:10.0207 3316        adpu160m - ok
17:46:10.0348 3316        adpu320        (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
17:46:10.0363 3316        adpu320 - ok
17:46:10.0519 3316        Afc            (a7b8a3a79d35215d798a300df49ed23f) C:\Windows\system32\drivers\Afc.sys
17:46:10.0582 3316        Afc ( UnsignedFile.Multi.Generic ) - warning
17:46:10.0582 3316        Afc - detected UnsignedFile.Multi.Generic (1)
17:46:10.0738 3316        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
17:46:10.0831 3316        AFD - ok
17:46:11.0003 3316        agp440          (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
17:46:11.0050 3316        agp440 - ok
17:46:11.0174 3316        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
17:46:11.0206 3316        aic78xx - ok
17:46:11.0486 3316        aliide          (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
17:46:11.0502 3316        aliide - ok
17:46:12.0064 3316        amdagp          (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
17:46:12.0079 3316        amdagp - ok
17:46:12.0188 3316        amdide          (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
17:46:12.0204 3316        amdide - ok
17:46:12.0329 3316        AmdK7          (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
17:46:12.0532 3316        AmdK7 - ok
17:46:12.0672 3316        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
17:46:12.0750 3316        AmdK8 - ok
17:46:13.0093 3316        ApfiltrService  (1de27858a431a5749e0f3df54ba935b9) C:\Windows\system32\DRIVERS\Apfiltr.sys
17:46:13.0140 3316        ApfiltrService - ok
17:46:13.0249 3316        arc            (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
17:46:13.0265 3316        arc - ok
17:46:13.0452 3316        arcsas          (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
17:46:13.0468 3316        arcsas - ok
17:46:13.0639 3316        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
17:46:13.0717 3316        AsyncMac - ok
17:46:13.0889 3316        atapi          (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
17:46:13.0904 3316        atapi - ok
17:46:14.0201 3316        atikmdag        (ac9e487e3513561e4f7953c438727ff7) C:\Windows\system32\DRIVERS\atikmdag.sys
17:46:14.0560 3316        atikmdag - ok
17:46:14.0716 3316        bcbus - ok
17:46:14.0872 3316        BCM42RLY        (bcb27987aaf7962c72b0f337a201cc28) C:\Windows\system32\drivers\BCM42RLY.sys
17:46:14.0950 3316        BCM42RLY - ok
17:46:15.0184 3316        BCM43XX        (b2134f695efd5eb392e906ac2413452e) C:\Windows\system32\DRIVERS\bcmwl6.sys
17:46:15.0262 3316        BCM43XX - ok
17:46:15.0511 3316        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
17:46:15.0589 3316        Beep - ok
17:46:15.0839 3316        blbdrive        (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
17:46:15.0964 3316        blbdrive - ok
17:46:16.0182 3316        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
17:46:16.0307 3316        bowser - ok
17:46:16.0494 3316        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
17:46:16.0759 3316        BrFiltLo - ok
17:46:17.0118 3316        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
17:46:17.0165 3316        BrFiltUp - ok
17:46:17.0383 3316        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
17:46:17.0648 3316        Brserid - ok
17:46:17.0929 3316        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
17:46:18.0054 3316        BrSerWdm - ok
17:46:18.0226 3316        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
17:46:18.0382 3316        BrUsbMdm - ok
17:46:18.0506 3316        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
17:46:18.0616 3316        BrUsbSer - ok
17:46:18.0678 3316        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
17:46:18.0787 3316        BTHMODEM - ok
17:46:18.0865 3316        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
17:46:18.0943 3316        cdfs - ok
17:46:19.0037 3316        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
17:46:19.0099 3316        cdrom - ok
17:46:19.0146 3316        circlass        (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
17:46:19.0208 3316        circlass - ok
17:46:19.0286 3316        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
17:46:19.0318 3316        CLFS - ok
17:46:19.0396 3316        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
17:46:19.0505 3316        CmBatt - ok
17:46:19.0583 3316        cmdide          (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
17:46:19.0598 3316        cmdide - ok
17:46:19.0676 3316        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
17:46:19.0692 3316        Compbatt - ok
17:46:20.0144 3316        crcdisk        (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
17:46:20.0160 3316        crcdisk - ok
17:46:20.0300 3316        Crusoe          (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
17:46:20.0378 3316        Crusoe - ok
17:46:20.0628 3316        CVirtA          (b5ecadf7708960f1818c7fa015f4c239) C:\Windows\system32\DRIVERS\CVirtA.sys
17:46:20.0706 3316        CVirtA - ok
17:46:21.0002 3316        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
17:46:21.0096 3316        DfsC - ok
17:46:21.0252 3316        DgiVecp        (770471de2550820feeb7e5d24bf2e273) C:\Windows\system32\Drivers\DgiVecp.sys
17:46:21.0283 3316        DgiVecp ( UnsignedFile.Multi.Generic ) - warning
17:46:21.0283 3316        DgiVecp - detected UnsignedFile.Multi.Generic (1)
17:46:21.0486 3316        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
17:46:21.0502 3316        disk - ok
17:46:21.0720 3316        Dot4            (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
17:46:21.0798 3316        Dot4 - ok
17:46:21.0938 3316        Dot4Print      (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
17:46:22.0079 3316        Dot4Print - ok
17:46:22.0219 3316        dot4usb        (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
17:46:22.0297 3316        dot4usb - ok
17:46:22.0422 3316        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
17:46:22.0469 3316        drmkaud - ok
17:46:22.0718 3316        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
17:46:22.0765 3316        DXGKrnl - ok
17:46:23.0218 3316        e1express      (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
17:46:23.0280 3316        e1express - ok
17:46:23.0452 3316        E1G60          (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
17:46:23.0545 3316        E1G60 - ok
17:46:23.0670 3316        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
17:46:23.0701 3316        Ecache - ok
17:46:23.0888 3316        elxstor        (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
17:46:23.0920 3316        elxstor - ok
17:46:24.0169 3316        ErrDev          (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
17:46:24.0232 3316        ErrDev - ok
17:46:24.0575 3316        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
17:46:24.0715 3316        exfat - ok
17:46:24.0887 3316        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
17:46:24.0934 3316        fastfat - ok
17:46:26.0104 3316        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
17:46:26.0166 3316        fdc - ok
17:46:26.0400 3316        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
17:46:26.0447 3316        FileInfo - ok
17:46:26.0494 3316        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
17:46:26.0572 3316        Filetrace - ok
17:46:26.0634 3316        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
17:46:26.0728 3316        flpydisk - ok
17:46:26.0774 3316        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
17:46:26.0852 3316        FltMgr - ok
17:46:26.0977 3316        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
17:46:27.0024 3316        Fs_Rec - ok
17:46:27.0086 3316        gagp30kx        (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
17:46:27.0102 3316        gagp30kx - ok
17:46:27.0289 3316        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17:46:27.0289 3316        GEARAspiWDM - ok
17:46:27.0352 3316        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
17:46:27.0398 3316        HdAudAddService - ok
17:46:27.0461 3316        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
17:46:27.0570 3316        HDAudBus - ok
17:46:27.0601 3316        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
17:46:27.0710 3316        HidBth - ok
17:46:27.0757 3316        HidIr          (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
17:46:27.0820 3316        HidIr - ok
17:46:27.0913 3316        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
17:46:28.0038 3316        HidUsb - ok
17:46:28.0085 3316        HpCISSs        (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
17:46:28.0100 3316        HpCISSs - ok
17:46:28.0147 3316        HTCAND32        (cbd09ed9cf6822177ee85aea4d8816a2) C:\Windows\system32\Drivers\ANDROIDUSB.sys
17:46:28.0256 3316        HTCAND32 - ok
17:46:28.0319 3316        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
17:46:28.0444 3316        HTTP - ok
17:46:28.0475 3316        i2omp          (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
17:46:28.0506 3316        i2omp - ok
17:46:28.0537 3316        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
17:46:28.0600 3316        i8042prt - ok
17:46:28.0662 3316        iaStor          (2358c53f30cb9dcd1d3843c4e2f299b2) C:\Windows\system32\drivers\iastor.sys
17:46:28.0693 3316        iaStor - ok
17:46:28.0724 3316        iaStorV        (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
17:46:28.0756 3316        iaStorV - ok
17:46:28.0802 3316        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
17:46:28.0834 3316        iirsp - ok
17:46:28.0880 3316        intelide        (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
17:46:28.0896 3316        intelide - ok
17:46:28.0927 3316        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
17:46:28.0990 3316        intelppm - ok
17:46:29.0021 3316        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:46:29.0099 3316        IpFilterDriver - ok
17:46:29.0114 3316        IpInIp - ok
17:46:29.0146 3316        IPMIDRV        (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
17:46:29.0224 3316        IPMIDRV - ok
17:46:29.0270 3316        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
17:46:29.0333 3316        IPNAT - ok
17:46:29.0395 3316        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
17:46:29.0458 3316        IRENUM - ok
17:46:29.0489 3316        isapnp          (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
17:46:29.0504 3316        isapnp - ok
17:46:29.0567 3316        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
17:46:29.0598 3316        iScsiPrt - ok
17:46:29.0645 3316        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
17:46:29.0660 3316        iteatapi - ok
17:46:29.0707 3316        itecir          (8bcd857c7932ad005d5f9c89329da2e1) C:\Windows\system32\DRIVERS\itecir.sys
17:46:29.0754 3316        itecir - ok
17:46:29.0816 3316        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
17:46:29.0832 3316        iteraid - ok
17:46:29.0894 3316        k57nd60x        (a67e8cfcad7d4f8b35643d6c79ba64c3) C:\Windows\system32\DRIVERS\k57nd60x.sys
17:46:29.0957 3316        k57nd60x - ok
17:46:30.0019 3316        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
17:46:30.0035 3316        kbdclass - ok
17:46:30.0097 3316        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
17:46:30.0144 3316        kbdhid - ok
17:46:30.0284 3316        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
17:46:30.0331 3316        KSecDD - ok
17:46:30.0394 3316        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
17:46:30.0472 3316        lltdio - ok
17:46:30.0534 3316        LSI_FC          (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
17:46:30.0581 3316        LSI_FC - ok
17:46:30.0612 3316        LSI_SAS        (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
17:46:30.0628 3316        LSI_SAS - ok
17:46:30.0659 3316        LSI_SCSI        (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
17:46:30.0674 3316        LSI_SCSI - ok
17:46:30.0721 3316        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
17:46:30.0799 3316        luafv - ok
17:46:30.0877 3316        massfilter      (f0435fe3c1ec2659d2bbf073ca0752ee) C:\Windows\system32\DRIVERS\massfilter.sys
17:46:30.0924 3316        massfilter - ok
17:46:30.0971 3316        MBAMSwissArmy - ok
17:46:31.0018 3316        megasas        (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
17:46:31.0033 3316        megasas - ok
17:46:31.0080 3316        MegaSR          (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
17:46:31.0142 3316        MegaSR - ok
17:46:31.0174 3316        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
17:46:31.0252 3316        Modem - ok
17:46:31.0298 3316        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
17:46:31.0361 3316        monitor - ok
17:46:31.0392 3316        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
17:46:31.0408 3316        mouclass - ok
17:46:31.0454 3316        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
17:46:31.0532 3316        mouhid - ok
17:46:31.0626 3316        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
17:46:31.0642 3316        MountMgr - ok
17:46:31.0673 3316        mpio            (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
17:46:31.0688 3316        mpio - ok
17:46:31.0735 3316        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
17:46:31.0798 3316        mpsdrv - ok
17:46:31.0844 3316        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
17:46:31.0860 3316        Mraid35x - ok
17:46:31.0907 3316        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
17:46:31.0954 3316        MRxDAV - ok
17:46:32.0000 3316        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
17:46:32.0047 3316        mrxsmb - ok
17:46:32.0094 3316        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:46:32.0141 3316        mrxsmb10 - ok
17:46:32.0156 3316        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:46:32.0203 3316        mrxsmb20 - ok
17:46:32.0250 3316        msahci          (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
17:46:32.0297 3316        msahci - ok
17:46:32.0359 3316        msdsm          (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
17:46:32.0390 3316        msdsm - ok
17:46:32.0422 3316        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
17:46:32.0515 3316        Msfs - ok
17:46:32.0546 3316        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
17:46:32.0562 3316        msisadrv - ok
17:46:32.0609 3316        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
17:46:32.0671 3316        MSKSSRV - ok
17:46:32.0702 3316        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
17:46:32.0765 3316        MSPCLOCK - ok
17:46:32.0812 3316        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
17:46:32.0874 3316        MSPQM - ok
17:46:32.0921 3316        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
17:46:32.0936 3316        MsRPC - ok
17:46:32.0983 3316        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
17:46:32.0999 3316        mssmbios - ok
17:46:33.0030 3316        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
17:46:33.0108 3316        MSTEE - ok
17:46:33.0155 3316        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
17:46:33.0170 3316        Mup - ok
17:46:33.0217 3316        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
17:46:33.0264 3316        NativeWifiP - ok
17:46:33.0326 3316        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
17:46:33.0389 3316        NDIS - ok
17:46:33.0420 3316        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
17:46:33.0467 3316        NdisTapi - ok
17:46:33.0514 3316        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
17:46:33.0576 3316        Ndisuio - ok
17:46:33.0623 3316        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
17:46:33.0701 3316        NdisWan - ok
17:46:33.0732 3316        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
17:46:33.0779 3316        NDProxy - ok
17:46:33.0857 3316        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
17:46:33.0919 3316        NetBIOS - ok
17:46:33.0982 3316        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
17:46:34.0060 3316        netbt - ok
17:46:34.0153 3316        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
17:46:34.0169 3316        nfrd960 - ok
17:46:34.0231 3316        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
17:46:34.0294 3316        Npfs - ok
17:46:34.0325 3316        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
17:46:34.0403 3316        nsiproxy - ok
17:46:34.0481 3316        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
17:46:34.0668 3316        Ntfs - ok
17:46:34.0762 3316        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
17:46:34.0871 3316        ntrigdigi - ok
17:46:34.0933 3316        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
17:46:34.0980 3316        Null - ok
17:46:35.0042 3316        nvraid          (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
17:46:35.0058 3316        nvraid - ok
17:46:35.0105 3316        nvstor          (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
17:46:35.0136 3316        nvstor - ok
17:46:35.0167 3316        nv_agp          (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
17:46:35.0198 3316        nv_agp - ok
17:46:35.0214 3316        NwlnkFlt - ok
17:46:35.0230 3316        NwlnkFwd - ok
17:46:35.0339 3316        OA001Ufd        (9b7cd7151a7c4009c383396155f02b95) C:\Windows\system32\DRIVERS\OA001Ufd.sys
17:46:35.0370 3316        OA001Ufd - ok
17:46:35.0417 3316        OA001Vid        (cdcdad303a9208cf3513400ef2a05f80) C:\Windows\system32\DRIVERS\OA001Vid.sys
17:46:35.0432 3316        OA001Vid - ok
17:46:35.0526 3316        ohci1394        (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
17:46:35.0573 3316        ohci1394 - ok
17:46:35.0666 3316        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
17:46:35.0776 3316        Parport - ok
17:46:35.0807 3316        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
17:46:35.0838 3316        partmgr - ok
17:46:35.0869 3316        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
17:46:35.0978 3316        Parvdm - ok
17:46:36.0166 3316        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
17:46:36.0181 3316        pci - ok
17:46:36.0244 3316        pciide          (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
17:46:36.0259 3316        pciide - ok
17:46:36.0290 3316        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
17:46:36.0322 3316        pcmcia - ok
17:46:36.0384 3316        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
17:46:36.0540 3316        PEAUTH - ok
17:46:36.0649 3316        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
17:46:36.0727 3316        PptpMiniport - ok
17:46:36.0743 3316        Processor      (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
17:46:36.0790 3316        Processor - ok
17:46:36.0992 3316        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
17:46:37.0039 3316        PSched - ok
17:46:37.0195 3316        ql2300          (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
17:46:37.0336 3316        ql2300 - ok
17:46:37.0414 3316        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
17:46:37.0429 3316        ql40xx - ok
17:46:37.0460 3316        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
17:46:37.0507 3316        QWAVEdrv - ok
17:46:37.0679 3316        R300            (ac9e487e3513561e4f7953c438727ff7) C:\Windows\system32\DRIVERS\atikmdag.sys
17:46:37.0897 3316        R300 - ok
17:46:37.0975 3316        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
17:46:38.0038 3316        RasAcd - ok
17:46:38.0084 3316        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
17:46:38.0147 3316        Rasl2tp - ok
17:46:38.0194 3316        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
17:46:38.0240 3316        RasPppoe - ok
17:46:38.0272 3316        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
17:46:38.0303 3316        RasSstp - ok
17:46:38.0350 3316        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
17:46:38.0412 3316        rdbss - ok
17:46:38.0459 3316        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
17:46:38.0521 3316        RDPCDD - ok
17:46:38.0568 3316        rdpdr          (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
17:46:38.0615 3316        rdpdr - ok
17:46:38.0630 3316        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
17:46:38.0693 3316        RDPENCDD - ok
17:46:38.0755 3316        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
17:46:38.0802 3316        RDPWD - ok
17:46:38.0927 3316        rimmptsk        (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys
17:46:38.0989 3316        rimmptsk - ok
17:46:39.0020 3316        rimsptsk        (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
17:46:39.0083 3316        rimsptsk - ok
17:46:39.0114 3316        RimUsb - ok
17:46:39.0270 3316        RimVSerPort    (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys
17:46:39.0379 3316        RimVSerPort - ok
17:46:39.0426 3316        rismxdp        (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys
17:46:39.0504 3316        rismxdp - ok
17:46:39.0785 3316        ROOTMODEM      (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys
17:46:39.0832 3316        ROOTMODEM - ok
17:46:40.0019 3316        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
17:46:40.0066 3316        rspndr - ok
17:46:40.0300 3316        SASDIFSV        (39763504067962108505bff25f024345) F:\Program Files\SASDIFSV.SYS
17:46:40.0315 3316        SASDIFSV - ok
17:46:40.0393 3316        SASKUTIL        (77b9fc20084b48408ad3e87570eb4a85) F:\Program Files\SASKUTIL.SYS
17:46:40.0409 3316        SASKUTIL - ok
17:46:40.0549 3316        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
17:46:40.0580 3316        sbp2port - ok
17:46:40.0736 3316        sdbus          (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
17:46:40.0783 3316        sdbus - ok
17:46:40.0924 3316        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
17:46:41.0002 3316        secdrv - ok
17:46:41.0126 3316        SeratoUsb      (fb2d6ff234f5d8d6a1477fb4dc5daf82) C:\Windows\system32\Drivers\SeratoUsb.sys
17:46:41.0158 3316        SeratoUsb - ok
17:46:41.0298 3316        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
17:46:41.0392 3316        Serenum - ok
17:46:41.0563 3316        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
17:46:41.0672 3316        Serial - ok
17:46:41.0906 3316        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
17:46:42.0000 3316        sermouse - ok
17:46:42.0062 3316        sffdisk        (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
17:46:42.0094 3316        sffdisk - ok
17:46:42.0156 3316        sffp_mmc        (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
17:46:42.0203 3316        sffp_mmc - ok
17:46:42.0250 3316        sffp_sd        (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\DRIVERS\sffp_sd.sys
17:46:42.0312 3316        sffp_sd - ok
17:46:42.0343 3316        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
17:46:42.0437 3316        sfloppy - ok
17:46:42.0530 3316        sisagp          (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
17:46:42.0546 3316        sisagp - ok
17:46:42.0624 3316        SiSRaid2        (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
17:46:42.0640 3316        SiSRaid2 - ok
17:46:42.0686 3316        SiSRaid4        (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
17:46:42.0702 3316        SiSRaid4 - ok
17:46:42.0764 3316        Smb            (029d3dd5c7e732b6cad75f2c8bc753b4) C:\Windows\system32\DRIVERS\smb.sys
17:46:42.0764 3316        Suspicious file (Forged): C:\Windows\system32\DRIVERS\smb.sys. Real md5: 029d3dd5c7e732b6cad75f2c8bc753b4, Fake md5: 7b75299a4d201d6a6533603d6914ab04
17:46:42.0764 3316        Smb ( Rootkit.Win32.ZAccess.aml ) - infected
17:46:42.0764 3316        Smb - detected Rootkit.Win32.ZAccess.aml (0)
17:46:42.0858 3316        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
17:46:42.0889 3316        spldr - ok
17:46:42.0952 3316        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
17:46:43.0014 3316        srv - ok
17:46:43.0139 3316        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
17:46:43.0186 3316        srv2 - ok
17:46:43.0357 3316        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
17:46:43.0388 3316        srvnet - ok
17:46:43.0529 3316        SSPORT          (ef3458337d7341a05169cefc73709264) C:\Windows\system32\Drivers\SSPORT.sys
17:46:43.0544 3316        SSPORT ( UnsignedFile.Multi.Generic ) - warning
17:46:43.0544 3316        SSPORT - detected UnsignedFile.Multi.Generic (1)
17:46:43.0763 3316        StarOpen - ok
17:46:44.0106 3316        STHDA          (c4be9c3af8af6f2e4cdd22fcabf77a1b) C:\Windows\system32\DRIVERS\stwrt.sys
17:46:44.0200 3316        STHDA - ok
17:46:44.0402 3316        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
17:46:44.0418 3316        swenum - ok
17:46:44.0590 3316        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
17:46:44.0605 3316        Symc8xx - ok
17:46:44.0730 3316        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
17:46:44.0746 3316        Sym_hi - ok
17:46:44.0917 3316        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
17:46:45.0120 3316        Sym_u3 - ok
17:46:45.0307 3316        Tcpip          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
17:46:45.0448 3316        Tcpip - ok
17:46:45.0791 3316        Tcpip6          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
17:46:45.0884 3316        Tcpip6 - ok
17:46:46.0087 3316        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
17:46:46.0150 3316        tcpipreg - ok
17:46:46.0306 3316        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
17:46:46.0368 3316        TDPIPE - ok
17:46:46.0633 3316        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
17:46:46.0696 3316        TDTCP - ok
17:46:46.0805 3316        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
17:46:46.0867 3316        tdx - ok
17:46:47.0086 3316        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
17:46:47.0117 3316        TermDD - ok
17:46:47.0335 3316        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
17:46:47.0398 3316        tssecsrv - ok
17:46:47.0554 3316        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
17:46:47.0663 3316        tunmp - ok
17:46:47.0803 3316        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
17:46:47.0819 3316        tunnel - ok
17:46:48.0131 3316        uagp35          (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
17:46:48.0146 3316        uagp35 - ok
17:46:48.0287 3316        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
17:46:48.0334 3316        udfs - ok
17:46:48.0521 3316        uliagpkx        (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
17:46:48.0552 3316        uliagpkx - ok
17:46:48.0724 3316        uliahci        (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
17:46:49.0129 3316        uliahci - ok
17:46:49.0301 3316        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
17:46:49.0332 3316        UlSata - ok
17:46:49.0441 3316        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
17:46:49.0472 3316        ulsata2 - ok
17:46:49.0628 3316        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
17:46:49.0675 3316        umbus - ok
17:46:49.0956 3316        USBAAPL        (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
17:46:50.0018 3316        USBAAPL - ok
17:46:50.0362 3316        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
17:46:50.0408 3316        usbaudio - ok
17:46:51.0173 3316        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
17:46:51.0220 3316        usbccgp - ok
17:46:51.0563 3316        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
17:46:51.0703 3316        usbcir - ok
17:46:51.0984 3316        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
17:46:52.0078 3316        usbehci - ok
17:46:52.0249 3316        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
17:46:52.0296 3316        usbhub - ok
17:46:52.0561 3316        usbohci        (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
17:46:52.0655 3316        usbohci - ok
17:46:52.0748 3316        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
17:46:52.0826 3316        usbprint - ok
17:46:52.0951 3316        usbscan        (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
17:46:53.0029 3316        usbscan - ok
17:46:53.0170 3316        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:46:53.0232 3316        USBSTOR - ok
17:46:53.0357 3316        usbuhci        (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
17:46:53.0404 3316        usbuhci - ok
17:46:53.0606 3316        usb_rndisx      (35c9095fa7076466afbfc5b9ec4b779e) C:\Windows\system32\DRIVERS\usb8023x.sys
17:46:53.0653 3316        usb_rndisx - ok
17:46:53.0794 3316        vga            (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
17:46:53.0903 3316        vga - ok
17:46:54.0355 3316        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
17:46:54.0402 3316        VgaSave - ok
17:46:54.0511 3316        viaagp          (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
17:46:54.0527 3316        viaagp - ok
17:46:54.0683 3316        ViaC7          (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
17:46:54.0745 3316        ViaC7 - ok
17:46:55.0026 3316        viaide          (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
17:46:55.0057 3316        viaide - ok
17:46:55.0260 3316        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
17:46:55.0276 3316        volmgr - ok
17:46:55.0385 3316        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
17:46:55.0432 3316        volmgrx - ok
17:46:55.0478 3316        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
17:46:55.0510 3316        volsnap - ok
17:46:55.0541 3316        vpnva          (fc94804932cfc35f01b3ae510e3b4d5c) C:\Windows\system32\DRIVERS\vpnva.sys
17:46:55.0556 3316        vpnva - ok
17:46:55.0603 3316        vsmraid        (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
17:46:55.0634 3316        vsmraid - ok
17:46:55.0681 3316        VSTHWBS2        (c466021d31ff6c0a6069d12299d80c0b) C:\Windows\system32\DRIVERS\VSTBS23.SYS
17:46:55.0744 3316        VSTHWBS2 - ok
17:46:55.0822 3316        VST_DPV        (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
17:46:55.0962 3316        VST_DPV - ok
17:46:56.0196 3316        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
17:46:56.0336 3316        WacomPen - ok
17:46:56.0555 3316        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
17:46:56.0617 3316        Wanarp - ok
17:46:56.0648 3316        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
17:46:56.0680 3316        Wanarpv6 - ok
17:46:56.0836 3316        Wd              (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
17:46:56.0851 3316        Wd - ok
17:46:57.0007 3316        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
17:46:57.0101 3316        Wdf01000 - ok
17:46:57.0491 3316        winachsf        (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
17:46:57.0584 3316        winachsf - ok
17:46:57.0740 3316        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
17:46:57.0787 3316        WmiAcpi - ok
17:46:57.0959 3316        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
17:46:58.0006 3316        WpdUsb - ok
17:46:58.0146 3316        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
17:46:58.0208 3316        ws2ifsl - ok
17:46:58.0380 3316        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
17:46:58.0427 3316        WUDFRd - ok
17:46:58.0598 3316        ZTEusbmdm6k    (c2215c6ada8b1e9feb507cee9b446661) C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
17:46:58.0645 3316        ZTEusbmdm6k - ok
17:46:58.0754 3316        ZTEusbnet      (9862f9d2ff50ae748ed42c022e6aac15) C:\Windows\system32\DRIVERS\ZTEusbnet.sys
17:46:58.0786 3316        ZTEusbnet - ok
17:46:58.0957 3316        ZTEusbnmea      (f16ce3c7690ab7426dc96520d54a737e) C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
17:46:59.0004 3316        ZTEusbnmea - ok
17:46:59.0144 3316        ZTEusbser6k    (c2215c6ada8b1e9feb507cee9b446661) C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
17:46:59.0160 3316        ZTEusbser6k - ok
17:46:59.0300 3316        ZTEusbvoice    (f16ce3c7690ab7426dc96520d54a737e) C:\Windows\system32\DRIVERS\ZTEusbvoice.sys
17:46:59.0363 3316        ZTEusbvoice - ok
17:46:59.0425 3316        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
17:46:59.0644 3316        \Device\Harddisk0\DR0 - ok
17:46:59.0675 3316        Boot (0x1200)  (abb7c4ad917b0efdd87fe3c3942de837) \Device\Harddisk0\DR0\Partition0
17:46:59.0675 3316        \Device\Harddisk0\DR0\Partition0 - ok
17:46:59.0690 3316        Boot (0x1200)  (c523417236dc6425c2e1e6476f9ea75b) \Device\Harddisk0\DR0\Partition1
17:46:59.0690 3316        \Device\Harddisk0\DR0\Partition1 - ok
17:46:59.0737 3316        Boot (0x1200)  (b3744a2a2f84488b8165bffd03425c7c) \Device\Harddisk0\DR0\Partition2
17:46:59.0737 3316        \Device\Harddisk0\DR0\Partition2 - ok
17:46:59.0737 3316        ============================================================
17:46:59.0737 3316        Scan finished
17:46:59.0737 3316        ============================================================
17:46:59.0768 2868        Detected object count: 4
17:46:59.0768 2868        Actual detected object count: 4
17:48:20.0717 2868        Afc ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:20.0717 2868        Afc ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:20.0717 2868        DgiVecp ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:20.0717 2868        DgiVecp ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:20.0904 2868        Backup copy found, using it..
17:48:20.0951 2868        C:\Windows\system32\DRIVERS\smb.sys - will be cured on reboot
17:48:23.0182 2868        C:\Windows\System32\c_76252.nls - will be deleted on reboot
17:48:23.0821 2868        Smb ( Rootkit.Win32.ZAccess.aml ) - User select action: Cure
17:48:23.0821 2868        SSPORT ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:23.0821 2868        SSPORT ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:47.0065 3620        Deinitialize success


cosinus 29.12.2011 22:53

Eigentlich solltest du NICHTS ohne Anweisung entfernen oder hat Kaspersky das selbstgemacht? :pfeiff:
Starte Windows neu und mach ein neues Log mit dem TDSS-Killer

Michael_w 29.12.2011 23:48

sorry... muss wohl irgendwie schief gelaufen sein. hier das neue log, hoffe ich hab diesmal nichts gelöscht.

Code:

23:45:36.0649 2964        TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
23:45:36.0664 2964        ============================================================
23:45:36.0664 2964        Current date / time: 2011/12/29 23:45:36.0664
23:45:36.0664 2964        SystemInfo:
23:45:36.0664 2964       
23:45:36.0664 2964        OS Version: 6.0.6002 ServicePack: 2.0
23:45:36.0664 2964        Product type: Workstation
23:45:36.0664 2964        ComputerName: MANKEL-PC
23:45:36.0664 2964        UserName: Mankel
23:45:36.0664 2964        Windows directory: C:\Windows
23:45:36.0664 2964        System windows directory: C:\Windows
23:45:36.0664 2964        Processor architecture: Intel x86
23:45:36.0664 2964        Number of processors: 2
23:45:36.0664 2964        Page size: 0x1000
23:45:36.0664 2964        Boot type: Normal boot
23:45:36.0664 2964        ============================================================
23:45:37.0429 2964        Initialize success
23:45:46.0742 2208        ============================================================
23:45:46.0742 2208        Scan started
23:45:46.0742 2208        Mode: Manual; SigCheck; TDLFS;
23:45:46.0742 2208        ============================================================
23:45:47.0382 2208        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
23:45:47.0584 2208        ACPI - ok
23:45:47.0725 2208        adp94xx        (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
23:45:47.0756 2208        adp94xx - ok
23:45:47.0803 2208        adpahci        (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
23:45:47.0834 2208        adpahci - ok
23:45:47.0865 2208        adpu160m        (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
23:45:47.0881 2208        adpu160m - ok
23:45:47.0912 2208        adpu320        (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
23:45:47.0928 2208        adpu320 - ok
23:45:48.0021 2208        Afc            (a7b8a3a79d35215d798a300df49ed23f) C:\Windows\system32\drivers\Afc.sys
23:45:48.0068 2208        Afc ( UnsignedFile.Multi.Generic ) - warning
23:45:48.0068 2208        Afc - detected UnsignedFile.Multi.Generic (1)
23:45:48.0130 2208        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
23:45:48.0193 2208        AFD - ok
23:45:48.0271 2208        agp440          (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
23:45:48.0286 2208        agp440 - ok
23:45:48.0318 2208        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
23:45:48.0349 2208        aic78xx - ok
23:45:48.0396 2208        aliide          (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
23:45:48.0411 2208        aliide - ok
23:45:48.0427 2208        amdagp          (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
23:45:48.0442 2208        amdagp - ok
23:45:48.0474 2208        amdide          (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
23:45:48.0489 2208        amdide - ok
23:45:48.0520 2208        AmdK7          (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
23:45:48.0676 2208        AmdK7 - ok
23:45:48.0692 2208        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
23:45:48.0770 2208        AmdK8 - ok
23:45:48.0832 2208        ApfiltrService  (1de27858a431a5749e0f3df54ba935b9) C:\Windows\system32\DRIVERS\Apfiltr.sys
23:45:48.0895 2208        ApfiltrService - ok
23:45:49.0051 2208        arc            (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
23:45:49.0066 2208        arc - ok
23:45:49.0082 2208        arcsas          (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
23:45:49.0098 2208        arcsas - ok
23:45:49.0160 2208        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
23:45:49.0222 2208        AsyncMac - ok
23:45:49.0254 2208        atapi          (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
23:45:49.0269 2208        atapi - ok
23:45:49.0441 2208        atikmdag        (ac9e487e3513561e4f7953c438727ff7) C:\Windows\system32\DRIVERS\atikmdag.sys
23:45:49.0722 2208        atikmdag - ok
23:45:49.0753 2208        bcbus - ok
23:45:49.0800 2208        BCM42RLY        (bcb27987aaf7962c72b0f337a201cc28) C:\Windows\system32\drivers\BCM42RLY.sys
23:45:49.0815 2208        BCM42RLY - ok
23:45:49.0893 2208        BCM43XX        (b2134f695efd5eb392e906ac2413452e) C:\Windows\system32\DRIVERS\bcmwl6.sys
23:45:49.0971 2208        BCM43XX - ok
23:45:50.0049 2208        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
23:45:50.0205 2208        Beep - ok
23:45:50.0236 2208        blbdrive        (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
23:45:50.0314 2208        blbdrive - ok
23:45:50.0377 2208        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
23:45:50.0455 2208        bowser - ok
23:45:50.0486 2208        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
23:45:50.0611 2208        BrFiltLo - ok
23:45:50.0642 2208        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
23:45:50.0689 2208        BrFiltUp - ok
23:45:50.0720 2208        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
23:45:51.0001 2208        Brserid - ok
23:45:51.0126 2208        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
23:45:51.0235 2208        BrSerWdm - ok
23:45:51.0313 2208        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
23:45:51.0438 2208        BrUsbMdm - ok
23:45:51.0516 2208        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
23:45:51.0640 2208        BrUsbSer - ok
23:45:51.0672 2208        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
23:45:51.0765 2208        BTHMODEM - ok
23:45:51.0812 2208        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
23:45:51.0890 2208        cdfs - ok
23:45:51.0937 2208        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
23:45:51.0984 2208        cdrom - ok
23:45:52.0062 2208        circlass        (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
23:45:52.0124 2208        circlass - ok
23:45:52.0155 2208        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
23:45:52.0186 2208        CLFS - ok
23:45:52.0233 2208        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
23:45:52.0296 2208        CmBatt - ok
23:45:52.0342 2208        cmdide          (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
23:45:52.0358 2208        cmdide - ok
23:45:52.0389 2208        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
23:45:52.0405 2208        Compbatt - ok
23:45:52.0420 2208        crcdisk        (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
23:45:52.0436 2208        crcdisk - ok
23:45:52.0467 2208        Crusoe          (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
23:45:52.0545 2208        Crusoe - ok
23:45:52.0654 2208        CVirtA          (b5ecadf7708960f1818c7fa015f4c239) C:\Windows\system32\DRIVERS\CVirtA.sys
23:45:52.0732 2208        CVirtA - ok
23:45:52.0920 2208        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
23:45:52.0982 2208        DfsC - ok
23:45:53.0076 2208        DgiVecp        (770471de2550820feeb7e5d24bf2e273) C:\Windows\system32\Drivers\DgiVecp.sys
23:45:53.0107 2208        DgiVecp ( UnsignedFile.Multi.Generic ) - warning
23:45:53.0107 2208        DgiVecp - detected UnsignedFile.Multi.Generic (1)
23:45:53.0154 2208        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
23:45:53.0185 2208        disk - ok
23:45:53.0232 2208        Dot4            (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
23:45:53.0325 2208        Dot4 - ok
23:45:53.0356 2208        Dot4Print      (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
23:45:53.0403 2208        Dot4Print - ok
23:45:53.0450 2208        dot4usb        (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
23:45:53.0512 2208        dot4usb - ok
23:45:53.0590 2208        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
23:45:53.0668 2208        drmkaud - ok
23:45:53.0746 2208        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
23:45:53.0793 2208        DXGKrnl - ok
23:45:53.0824 2208        e1express      (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
23:45:53.0887 2208        e1express - ok
23:45:53.0918 2208        E1G60          (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
23:45:53.0996 2208        E1G60 - ok
23:45:54.0090 2208        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
23:45:54.0121 2208        Ecache - ok
23:45:54.0183 2208        elxstor        (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
23:45:54.0214 2208        elxstor - ok
23:45:54.0246 2208        ErrDev          (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
23:45:54.0292 2208        ErrDev - ok
23:45:54.0355 2208        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
23:45:54.0433 2208        exfat - ok
23:45:54.0480 2208        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
23:45:54.0511 2208        fastfat - ok
23:45:54.0558 2208        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
23:45:54.0620 2208        fdc - ok
23:45:54.0651 2208        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
23:45:54.0667 2208        FileInfo - ok
23:45:54.0682 2208        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
23:45:54.0745 2208        Filetrace - ok
23:45:54.0776 2208        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
23:45:54.0854 2208        flpydisk - ok
23:45:54.0885 2208        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
23:45:54.0916 2208        FltMgr - ok
23:45:54.0994 2208        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
23:45:55.0041 2208        Fs_Rec - ok
23:45:55.0104 2208        gagp30kx        (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
23:45:55.0119 2208        gagp30kx - ok
23:45:55.0197 2208        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
23:45:55.0213 2208        GEARAspiWDM - ok
23:45:55.0275 2208        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
23:45:55.0338 2208        HdAudAddService - ok
23:45:55.0400 2208        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
23:45:55.0681 2208        HDAudBus - ok
23:45:55.0837 2208        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
23:45:55.0930 2208        HidBth - ok
23:45:55.0977 2208        HidIr          (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
23:45:56.0040 2208        HidIr - ok
23:45:56.0133 2208        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
23:45:56.0227 2208        HidUsb - ok
23:45:56.0258 2208        HpCISSs        (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
23:45:56.0274 2208        HpCISSs - ok
23:45:56.0320 2208        HTCAND32        (cbd09ed9cf6822177ee85aea4d8816a2) C:\Windows\system32\Drivers\ANDROIDUSB.sys
23:45:56.0367 2208        HTCAND32 - ok
23:45:56.0430 2208        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
23:45:56.0554 2208        HTTP - ok
23:45:56.0601 2208        i2omp          (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
23:45:56.0617 2208        i2omp - ok
23:45:56.0648 2208        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
23:45:56.0695 2208        i8042prt - ok
23:45:56.0757 2208        iaStor          (2358c53f30cb9dcd1d3843c4e2f299b2) C:\Windows\system32\drivers\iastor.sys
23:45:56.0773 2208        iaStor - ok
23:45:56.0913 2208        iaStorV        (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
23:45:56.0929 2208        iaStorV - ok
23:45:56.0976 2208        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
23:45:56.0991 2208        iirsp - ok
23:45:57.0038 2208        intelide        (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
23:45:57.0054 2208        intelide - ok
23:45:57.0085 2208        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
23:45:57.0178 2208        intelppm - ok
23:45:57.0241 2208        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
23:45:57.0412 2208        IpFilterDriver - ok
23:45:57.0428 2208        IpInIp - ok
23:45:57.0475 2208        IPMIDRV        (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
23:45:57.0537 2208        IPMIDRV - ok
23:45:57.0568 2208        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
23:45:57.0631 2208        IPNAT - ok
23:45:57.0662 2208        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
23:45:57.0724 2208        IRENUM - ok
23:45:57.0787 2208        isapnp          (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
23:45:57.0802 2208        isapnp - ok
23:45:57.0849 2208        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
23:45:57.0865 2208        iScsiPrt - ok
23:45:57.0912 2208        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
23:45:57.0927 2208        iteatapi - ok
23:45:57.0958 2208        itecir          (8bcd857c7932ad005d5f9c89329da2e1) C:\Windows\system32\DRIVERS\itecir.sys
23:45:58.0005 2208        itecir - ok
23:45:58.0021 2208        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
23:45:58.0036 2208        iteraid - ok
23:45:58.0099 2208        k57nd60x        (a67e8cfcad7d4f8b35643d6c79ba64c3) C:\Windows\system32\DRIVERS\k57nd60x.sys
23:45:58.0192 2208        k57nd60x - ok
23:45:58.0224 2208        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
23:45:58.0239 2208        kbdclass - ok
23:45:58.0270 2208        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
23:45:58.0317 2208        kbdhid - ok
23:45:58.0380 2208        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
23:45:58.0411 2208        KSecDD - ok
23:45:58.0473 2208        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
23:45:58.0551 2208        lltdio - ok
23:45:58.0645 2208        LSI_FC          (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
23:45:58.0660 2208        LSI_FC - ok
23:45:58.0692 2208        LSI_SAS        (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
23:45:58.0707 2208        LSI_SAS - ok
23:45:58.0738 2208        LSI_SCSI        (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
23:45:58.0754 2208        LSI_SCSI - ok
23:45:58.0785 2208        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
23:45:58.0848 2208        luafv - ok
23:45:58.0926 2208        massfilter      (f0435fe3c1ec2659d2bbf073ca0752ee) C:\Windows\system32\DRIVERS\massfilter.sys
23:45:58.0957 2208        massfilter - ok
23:45:59.0004 2208        MBAMSwissArmy - ok
23:45:59.0097 2208        megasas        (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
23:45:59.0113 2208        megasas - ok
23:45:59.0175 2208        MegaSR          (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
23:45:59.0206 2208        MegaSR - ok
23:45:59.0253 2208        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
23:45:59.0331 2208        Modem - ok
23:45:59.0378 2208        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
23:45:59.0425 2208        monitor - ok
23:45:59.0472 2208        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
23:45:59.0487 2208        mouclass - ok
23:45:59.0534 2208        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
23:45:59.0612 2208        mouhid - ok
23:45:59.0659 2208        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
23:45:59.0674 2208        MountMgr - ok
23:45:59.0706 2208        mpio            (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
23:45:59.0721 2208        mpio - ok
23:45:59.0768 2208        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
23:45:59.0846 2208        mpsdrv - ok
23:45:59.0893 2208        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
23:45:59.0908 2208        Mraid35x - ok
23:45:59.0955 2208        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
23:46:00.0002 2208        MRxDAV - ok
23:46:00.0064 2208        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
23:46:00.0111 2208        mrxsmb - ok
23:46:00.0189 2208        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
23:46:00.0236 2208        mrxsmb10 - ok
23:46:00.0252 2208        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
23:46:00.0298 2208        mrxsmb20 - ok
23:46:00.0330 2208        msahci          (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
23:46:00.0345 2208        msahci - ok
23:46:00.0408 2208        msdsm          (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
23:46:00.0439 2208        msdsm - ok
23:46:00.0470 2208        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
23:46:00.0532 2208        Msfs - ok
23:46:00.0626 2208        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
23:46:00.0642 2208        msisadrv - ok
23:46:00.0673 2208        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
23:46:00.0735 2208        MSKSSRV - ok
23:46:00.0751 2208        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
23:46:00.0813 2208        MSPCLOCK - ok
23:46:00.0969 2208        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
23:46:01.0032 2208        MSPQM - ok
23:46:01.0188 2208        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
23:46:01.0219 2208        MsRPC - ok
23:46:01.0266 2208        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
23:46:01.0281 2208        mssmbios - ok
23:46:01.0297 2208        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
23:46:01.0375 2208        MSTEE - ok
23:46:01.0515 2208        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
23:46:01.0546 2208        Mup - ok
23:46:01.0734 2208        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
23:46:01.0765 2208        NativeWifiP - ok
23:46:01.0905 2208        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
23:46:01.0983 2208        NDIS - ok
23:46:02.0108 2208        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
23:46:02.0139 2208        NdisTapi - ok
23:46:02.0202 2208        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
23:46:02.0264 2208        Ndisuio - ok
23:46:02.0311 2208        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
23:46:02.0373 2208        NdisWan - ok
23:46:02.0420 2208        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
23:46:02.0467 2208        NDProxy - ok
23:46:02.0514 2208        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
23:46:02.0576 2208        NetBIOS - ok
23:46:02.0638 2208        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
23:46:02.0716 2208        netbt - ok
23:46:02.0794 2208        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
23:46:02.0826 2208        nfrd960 - ok
23:46:02.0872 2208        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
23:46:02.0919 2208        Npfs - ok
23:46:02.0950 2208        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
23:46:03.0028 2208        nsiproxy - ok
23:46:03.0091 2208        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
23:46:03.0200 2208        Ntfs - ok
23:46:03.0216 2208        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
23:46:03.0340 2208        ntrigdigi - ok
23:46:03.0356 2208        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
23:46:03.0418 2208        Null - ok
23:46:03.0450 2208        nvraid          (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
23:46:03.0465 2208        nvraid - ok
23:46:03.0496 2208        nvstor          (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
23:46:03.0512 2208        nvstor - ok
23:46:03.0543 2208        nv_agp          (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
23:46:03.0559 2208        nv_agp - ok
23:46:03.0574 2208        NwlnkFlt - ok
23:46:03.0606 2208        NwlnkFwd - ok
23:46:03.0652 2208        OA001Ufd        (9b7cd7151a7c4009c383396155f02b95) C:\Windows\system32\DRIVERS\OA001Ufd.sys
23:46:03.0668 2208        OA001Ufd - ok
23:46:03.0746 2208        OA001Vid        (cdcdad303a9208cf3513400ef2a05f80) C:\Windows\system32\DRIVERS\OA001Vid.sys
23:46:03.0762 2208        OA001Vid - ok
23:46:03.0840 2208        ohci1394        (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
23:46:03.0886 2208        ohci1394 - ok
23:46:03.0949 2208        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
23:46:04.0058 2208        Parport - ok
23:46:04.0105 2208        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
23:46:04.0120 2208        partmgr - ok
23:46:04.0152 2208        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
23:46:04.0245 2208        Parvdm - ok
23:46:04.0573 2208        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
23:46:04.0604 2208        pci - ok
23:46:04.0760 2208        pciide          (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
23:46:04.0791 2208        pciide - ok
23:46:04.0822 2208        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
23:46:04.0838 2208        pcmcia - ok
23:46:04.0900 2208        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
23:46:05.0088 2208        PEAUTH - ok
23:46:05.0181 2208        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
23:46:05.0275 2208        PptpMiniport - ok
23:46:05.0306 2208        Processor      (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
23:46:05.0353 2208        Processor - ok
23:46:05.0415 2208        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
23:46:05.0462 2208        PSched - ok
23:46:05.0587 2208        ql2300          (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
23:46:05.0712 2208        ql2300 - ok
23:46:05.0836 2208        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
23:46:05.0852 2208        ql40xx - ok
23:46:05.0930 2208        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
23:46:05.0977 2208        QWAVEdrv - ok
23:46:06.0164 2208        R300            (ac9e487e3513561e4f7953c438727ff7) C:\Windows\system32\DRIVERS\atikmdag.sys
23:46:06.0382 2208        R300 - ok
23:46:06.0460 2208        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
23:46:06.0507 2208        RasAcd - ok
23:46:06.0554 2208        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
23:46:06.0616 2208        Rasl2tp - ok
23:46:06.0679 2208        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
23:46:06.0710 2208        RasPppoe - ok
23:46:06.0757 2208        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
23:46:06.0788 2208        RasSstp - ok
23:46:06.0850 2208        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
23:46:06.0913 2208        rdbss - ok
23:46:06.0944 2208        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
23:46:07.0022 2208        RDPCDD - ok
23:46:07.0069 2208        rdpdr          (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
23:46:07.0116 2208        rdpdr - ok
23:46:07.0131 2208        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
23:46:07.0194 2208        RDPENCDD - ok
23:46:07.0272 2208        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
23:46:07.0334 2208        RDPWD - ok
23:46:07.0412 2208        rimmptsk        (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys
23:46:07.0443 2208        rimmptsk - ok
23:46:07.0474 2208        rimsptsk        (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
23:46:07.0506 2208        rimsptsk - ok
23:46:07.0552 2208        RimUsb - ok
23:46:07.0599 2208        RimVSerPort    (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys
23:46:07.0646 2208        RimVSerPort - ok
23:46:07.0677 2208        rismxdp        (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys
23:46:07.0724 2208        rismxdp - ok
23:46:07.0786 2208        ROOTMODEM      (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys
23:46:07.0849 2208        ROOTMODEM - ok
23:46:07.0880 2208        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
23:46:07.0927 2208        rspndr - ok
23:46:08.0052 2208        SASDIFSV        (39763504067962108505bff25f024345) F:\Program Files\SASDIFSV.SYS
23:46:08.0067 2208        SASDIFSV - ok
23:46:08.0145 2208        SASKUTIL        (77b9fc20084b48408ad3e87570eb4a85) F:\Program Files\SASKUTIL.SYS
23:46:08.0176 2208        SASKUTIL - ok
23:46:08.0223 2208        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
23:46:08.0239 2208        sbp2port - ok
23:46:08.0332 2208        sdbus          (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
23:46:08.0379 2208        sdbus - ok
23:46:08.0457 2208        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
23:46:08.0535 2208        secdrv - ok
23:46:08.0598 2208        SeratoUsb      (fb2d6ff234f5d8d6a1477fb4dc5daf82) C:\Windows\system32\Drivers\SeratoUsb.sys
23:46:08.0660 2208        SeratoUsb - ok
23:46:08.0691 2208        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
23:46:08.0785 2208        Serenum - ok
23:46:08.0832 2208        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
23:46:08.0941 2208        Serial - ok
23:46:08.0956 2208        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
23:46:09.0019 2208        sermouse - ok
23:46:09.0112 2208        sffdisk        (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
23:46:09.0144 2208        sffdisk - ok
23:46:09.0175 2208        sffp_mmc        (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
23:46:09.0222 2208        sffp_mmc - ok
23:46:09.0284 2208        sffp_sd        (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\DRIVERS\sffp_sd.sys
23:46:09.0346 2208        sffp_sd - ok
23:46:09.0378 2208        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
23:46:09.0471 2208        sfloppy - ok
23:46:09.0549 2208        sisagp          (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
23:46:09.0565 2208        sisagp - ok
23:46:09.0612 2208        SiSRaid2        (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
23:46:09.0627 2208        SiSRaid2 - ok
23:46:09.0658 2208        SiSRaid4        (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
23:46:09.0674 2208        SiSRaid4 - ok
23:46:09.0736 2208        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
23:46:09.0783 2208        Smb - ok
23:46:09.0830 2208        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
23:46:09.0846 2208        spldr - ok
23:46:09.0908 2208        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
23:46:09.0955 2208        srv - ok
23:46:10.0002 2208        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
23:46:10.0048 2208        srv2 - ok
23:46:10.0080 2208        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
23:46:10.0111 2208        srvnet - ok
23:46:10.0173 2208        SSPORT          (ef3458337d7341a05169cefc73709264) C:\Windows\system32\Drivers\SSPORT.sys
23:46:10.0173 2208        SSPORT ( UnsignedFile.Multi.Generic ) - warning
23:46:10.0173 2208        SSPORT - detected UnsignedFile.Multi.Generic (1)
23:46:10.0204 2208        StarOpen - ok
23:46:10.0251 2208        STHDA          (c4be9c3af8af6f2e4cdd22fcabf77a1b) C:\Windows\system32\DRIVERS\stwrt.sys
23:46:10.0376 2208        STHDA - ok
23:46:10.0423 2208        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
23:46:10.0438 2208        swenum - ok
23:46:10.0485 2208        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
23:46:10.0501 2208        Symc8xx - ok
23:46:10.0532 2208        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
23:46:10.0548 2208        Sym_hi - ok
23:46:10.0563 2208        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
23:46:10.0594 2208        Sym_u3 - ok
23:46:10.0688 2208        Tcpip          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
23:46:10.0797 2208        Tcpip - ok
23:46:10.0844 2208        Tcpip6          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
23:46:10.0906 2208        Tcpip6 - ok
23:46:11.0156 2208        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
23:46:11.0203 2208        tcpipreg - ok
23:46:11.0390 2208        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
23:46:11.0468 2208        TDPIPE - ok
23:46:11.0499 2208        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
23:46:11.0562 2208        TDTCP - ok
23:46:11.0671 2208        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
23:46:11.0733 2208        tdx - ok
23:46:11.0780 2208        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
23:46:11.0811 2208        TermDD - ok
23:46:11.0889 2208        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
23:46:11.0952 2208        tssecsrv - ok
23:46:11.0967 2208        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
23:46:12.0030 2208        tunmp - ok
23:46:12.0061 2208        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
23:46:12.0076 2208        tunnel - ok
23:46:12.0108 2208        uagp35          (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
23:46:12.0123 2208        uagp35 - ok
23:46:12.0170 2208        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
23:46:12.0217 2208        udfs - ok
23:46:12.0279 2208        uliagpkx        (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
23:46:12.0295 2208        uliagpkx - ok
23:46:12.0357 2208        uliahci        (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
23:46:12.0373 2208        uliahci - ok
23:46:12.0404 2208        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
23:46:12.0420 2208        UlSata - ok
23:46:12.0451 2208        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
23:46:12.0482 2208        ulsata2 - ok
23:46:12.0513 2208        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
23:46:12.0560 2208        umbus - ok
23:46:12.0622 2208        USBAAPL        (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
23:46:12.0669 2208        USBAAPL - ok
23:46:12.0716 2208        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
23:46:12.0778 2208        usbaudio - ok
23:46:12.0825 2208        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
23:46:12.0872 2208        usbccgp - ok
23:46:12.0903 2208        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
23:46:13.0012 2208        usbcir - ok
23:46:13.0059 2208        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
23:46:13.0106 2208        usbehci - ok
23:46:13.0137 2208        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
23:46:13.0184 2208        usbhub - ok
23:46:13.0215 2208        usbohci        (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
23:46:13.0340 2208        usbohci - ok
23:46:13.0371 2208        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
23:46:13.0449 2208        usbprint - ok
23:46:13.0558 2208        usbscan        (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
23:46:13.0668 2208        usbscan - ok
23:46:13.0730 2208        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
23:46:13.0792 2208        USBSTOR - ok
23:46:13.0824 2208        usbuhci        (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
23:46:13.0855 2208        usbuhci - ok
23:46:13.0933 2208        usb_rndisx      (35c9095fa7076466afbfc5b9ec4b779e) C:\Windows\system32\DRIVERS\usb8023x.sys
23:46:13.0980 2208        usb_rndisx - ok
23:46:14.0058 2208        vga            (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
23:46:14.0120 2208        vga - ok
23:46:14.0167 2208        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
23:46:14.0214 2208        VgaSave - ok
23:46:14.0245 2208        viaagp          (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
23:46:14.0260 2208        viaagp - ok
23:46:14.0276 2208        ViaC7          (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
23:46:14.0338 2208        ViaC7 - ok
23:46:14.0401 2208        viaide          (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
23:46:14.0416 2208        viaide - ok
23:46:14.0432 2208        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
23:46:14.0463 2208        volmgr - ok
23:46:14.0526 2208        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
23:46:14.0557 2208        volmgrx - ok
23:46:14.0604 2208        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
23:46:14.0635 2208        volsnap - ok
23:46:14.0666 2208        vpnva          (fc94804932cfc35f01b3ae510e3b4d5c) C:\Windows\system32\DRIVERS\vpnva.sys
23:46:14.0682 2208        vpnva - ok
23:46:14.0760 2208        vsmraid        (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
23:46:14.0775 2208        vsmraid - ok
23:46:14.0822 2208        VSTHWBS2        (c466021d31ff6c0a6069d12299d80c0b) C:\Windows\system32\DRIVERS\VSTBS23.SYS
23:46:14.0900 2208        VSTHWBS2 - ok
23:46:14.0962 2208        VST_DPV        (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
23:46:15.0087 2208        VST_DPV - ok
23:46:15.0118 2208        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
23:46:15.0228 2208        WacomPen - ok
23:46:15.0259 2208        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
23:46:15.0321 2208        Wanarp - ok
23:46:15.0321 2208        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
23:46:15.0368 2208        Wanarpv6 - ok
23:46:15.0415 2208        Wd              (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
23:46:15.0446 2208        Wd - ok
23:46:15.0493 2208        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
23:46:15.0540 2208        Wdf01000 - ok
23:46:15.0633 2208        winachsf        (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
23:46:15.0742 2208        winachsf - ok
23:46:15.0805 2208        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
23:46:15.0867 2208        WmiAcpi - ok
23:46:15.0976 2208        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
23:46:16.0008 2208        WpdUsb - ok
23:46:16.0054 2208        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
23:46:16.0117 2208        ws2ifsl - ok
23:46:16.0164 2208        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
23:46:16.0226 2208        WUDFRd - ok
23:46:16.0288 2208        ZTEusbmdm6k    (c2215c6ada8b1e9feb507cee9b446661) C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
23:46:16.0335 2208        ZTEusbmdm6k - ok
23:46:16.0413 2208        ZTEusbnet      (9862f9d2ff50ae748ed42c022e6aac15) C:\Windows\system32\DRIVERS\ZTEusbnet.sys
23:46:16.0444 2208        ZTEusbnet - ok
23:46:16.0491 2208        ZTEusbnmea      (f16ce3c7690ab7426dc96520d54a737e) C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
23:46:16.0538 2208        ZTEusbnmea - ok
23:46:16.0569 2208        ZTEusbser6k    (c2215c6ada8b1e9feb507cee9b446661) C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
23:46:16.0585 2208        ZTEusbser6k - ok
23:46:16.0616 2208        ZTEusbvoice    (f16ce3c7690ab7426dc96520d54a737e) C:\Windows\system32\DRIVERS\ZTEusbvoice.sys
23:46:16.0632 2208        ZTEusbvoice - ok
23:46:16.0678 2208        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
23:46:16.0897 2208        \Device\Harddisk0\DR0 - ok
23:46:16.0928 2208        Boot (0x1200)  (abb7c4ad917b0efdd87fe3c3942de837) \Device\Harddisk0\DR0\Partition0
23:46:16.0928 2208        \Device\Harddisk0\DR0\Partition0 - ok
23:46:16.0944 2208        Boot (0x1200)  (c523417236dc6425c2e1e6476f9ea75b) \Device\Harddisk0\DR0\Partition1
23:46:16.0944 2208        \Device\Harddisk0\DR0\Partition1 - ok
23:46:16.0975 2208        Boot (0x1200)  (b3744a2a2f84488b8165bffd03425c7c) \Device\Harddisk0\DR0\Partition2
23:46:16.0975 2208        \Device\Harddisk0\DR0\Partition2 - ok
23:46:16.0975 2208        ============================================================
23:46:16.0975 2208        Scan finished
23:46:16.0975 2208        ============================================================
23:46:16.0990 2220        Detected object count: 3
23:46:16.0990 2220        Actual detected object count: 3
23:46:28.0878 2220        Afc ( UnsignedFile.Multi.Generic ) - skipped by user
23:46:28.0878 2220        Afc ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:46:28.0893 2220        DgiVecp ( UnsignedFile.Multi.Generic ) - skipped by user
23:46:28.0893 2220        DgiVecp ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:46:28.0893 2220        SSPORT ( UnsignedFile.Multi.Generic ) - skipped by user
23:46:28.0893 2220        SSPORT ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 30.12.2011 00:46

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Michael_w 30.12.2011 10:43

Guten Morgen,

habe gerade combofix ausgeführt. Leider hat sich am Ende keine combofix.txt geöffnet und ich kann die Datei auch nicht am angegebenen Ort finden...?
Was kann ich tun? Vielen Dank schon einmal...

Michael_w 30.12.2011 10:45

vielleicht noch als zusatzinfo wichtig: combofix hat einen rootkit entdeckt. die nächste meldung war, das versucht wird zu fixen und der computer neugestartet wird (so oder ähnlich?!?)
muss ich combofix jetzt nochmal starten?

cosinus 30.12.2011 18:38

Ich brauch den Quarantäneordner von Combofix. Bitte folgendes machen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinflussen!
2.) Ordner Quarantine in C:\Qoobox in eine Datei zippen
3.) die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten!

4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

Michael_w 31.12.2011 18:28

Lieber Arne,

vielen Dank für Deine Hilfe nochmal. Ich habe gerade die zip-Datei erstellt, allerdings gab es eine Fehlermeldung, in etwa: "Fehler beim Erstellen der Zieldatei… Prüfen Sie ob diese Datei verwendet wird."
Die Datei wurde aber trotzdem erstellt und ich habe sie hochgeladen. Der Virenscanner war nach meinem Ermessen aus... Ich bin mir aber nicht sicher, wo und wie ich das überprüfen kann.

Außerdem habe ich gerade noch ein WEITERES RIESIGES Problem bemerkt: Mein anderer Rechner ist auch infiziert... Soll ich dazu nochmal einen neuen Thread aufmachen...?
Oh mann oh mann...

Einen Guten Rutsch wünsche ich schonmal...

cosinus 02.01.2012 11:10

Du musst auch den Ordner C:\Qoobox betreten (öffnen) und von dort aus den Ordner Quarantine in eine ZIP packen. Ggf. das Ziel der ZIP ändern (auf dem Desktop als Beispiel)

Und ja zum anderen Rechner machst du einen neuen Strang auf bevor hier in diesem das Chaos ausbricht

Michael_w 02.01.2012 17:14

Hallo Arne,
habe das gerade versucht. Es gab wieder die gleiche Fehlermeldung. Auch mit WinZip gab es keinen Zugriff auf die Datei... Was kann ich machen?
Kommt das auch von dem Trojaner oder bin ich einfach nur zu blöd?

Beste Grüße

P.S.: Mache jetzt für den anderen Rechner einen neuen Thread auf:(


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:24 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131