Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Windows XP Repair Malware

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 06.07.2011, 07:33   #1
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Hallo liebe Community,
ich wurde vor einigen Tagen von Windows Xp Repair befallen. Fake Security Center, unsichtbare Dateien, extrem langsam, ungefragte Reboots, etc.
Ich habe mich einer Empfehlung dieser Seite folgend zunächst an rkill, malwarebytes und TDSSKiller gehalten.
Ich habe diese Programme zuerst im abgesicherten Modus ausgeführt, aber nach einem Reboot war Windows XP Repair wieder aktiv wie zuvor.

Also habe ich jetzt nochmal im normalen Modus alle Programme geupdated und drüber laufen lassen. Ich habe den Pc aber noch nicht neu gestartet, ich wollte euch erstmal die Ergebnisse posten und um Rat fragen, damit ich das Problem wirklich los werde.

rkill.log
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 05.07.2011 at 22:35:22.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:

C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\cRdQIGspBdjhpow.exe
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\19390244.exe
C:\Dokumente und Einstellungen\Marian Kasprowski\Eigene Dateien\eXplorer.exe


Rkill completed on 05.07.2011 at 22:35:53.

malwarebytes log:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 7029

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

06.07.2011 08:06:22
mbam-log-2011-07-06 (08-06-22).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Objects scanned: 332946
Time elapsed: 2 hour(s), 7 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cRdQIGspBdjhpow (Trojan.FakeAlert) -> Value: cRdQIGspBdjhpow -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\dokumente und einstellungen\all users\anwendungsdaten\crdqigspbdjhpow.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\dokumente und einstellungen\all users\anwendungsdaten\19390244.exe (Trojan.Agent) -> Quarantined and deleted successfully.





Hoffe ihr könnt mir weitere Handlungsanweisungen geben.

Danke.

Alt 06.07.2011, 13:23   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den Inhalt in die Textbox.
Code:
ATTFilter
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
__________________

__________________

Alt 06.07.2011, 16:04   #3
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Gesagt, getan, nun hat sich allerdings OTL aufgehangen (keine Rückmeldung) an der Stelle, wo es unten in der Statusanzeige heißt: "Scanning firefox settings...", dazu fällt mir noch ein, dass ich jetzt auch grade Iexplorer benutze, denn seit dem Virusbefall kriege ich beim Versuch firefox u starten die Fehlermeldung: "Couldn't read application.ini".

Soll ich einfach OTL mit dem gleichen Skript noch mal neu starten oder vorher irgendeine andere Aktion durchführen?

Vielen Dank für die Hilfe übrigens, ich weiss das sehr zu schätzen.
__________________

Alt 06.07.2011, 20:23   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Probier es bitte nochmal. Wenn das nicht klappt probier es so:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 06.07.2011, 23:10   #5
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Auch wenn ich OTL mit Minimal Output laufen lasse, das gleiche Ergebnis, irgendwann bleibt er bei "Scanning firefox settings..." hängen und egal wie lange ich warte, es tut sich nichts, der Mauszeiger verwandelt sich eine Stopuhr, klickt man auf die OTL Arbeitsoberfläche: Reagiert nicht.

Muss ich Firefox deinstallieren? Gibt es eine andere Möglichkeit?


Alt 07.07.2011, 08:45   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Dann überspringen wir OTL erstmal.
Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.




Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen!
__________________
--> Windows XP Repair Malware

Alt 07.07.2011, 19:24   #7
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Hi, also, ich habe TDSSKiller schon diverse Male im abgesicherten Modus laufen lassen, bevor ich mich an dieses Forum gewendet habe, da ich nach jedem Neustart komischerweise wieder von Windows XP Repair geplagt wurde, obwohl mir vor dem Reboot ein Malware/Rootkit freier Pc angezeigt wurde.

Ich habe aber alle in den letzten Tagen ausgeführten TDSSKiller Skripte gespeichert und führe diese nun in chronologischer Reihenfolge auf (momentan wird mir (im nicht abgesicherten Modus) kein Befund angezeigt):

Zitat:
2011/07/04 21:59:42.0906 1360 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
2011/07/04 21:59:42.0953 1360 ================================================================================
2011/07/04 21:59:42.0953 1360 SystemInfo:
2011/07/04 21:59:42.0953 1360
2011/07/04 21:59:42.0953 1360 OS Version: 5.1.2600 ServicePack: 3.0
2011/07/04 21:59:42.0953 1360 Product type: Workstation
2011/07/04 21:59:42.0953 1360 ComputerName: MAID
2011/07/04 21:59:42.0953 1360 UserName: Administrator
2011/07/04 21:59:42.0953 1360 Windows directory: C:\WINDOWS
2011/07/04 21:59:42.0953 1360 System windows directory: C:\WINDOWS
2011/07/04 21:59:42.0953 1360 Processor architecture: Intel x86
2011/07/04 21:59:42.0953 1360 Number of processors: 2
2011/07/04 21:59:42.0953 1360 Page size: 0x1000
2011/07/04 21:59:42.0953 1360 Boot type: Safe boot
2011/07/04 21:59:42.0953 1360 ================================================================================
2011/07/04 21:59:45.0781 1360 Initialize success
2011/07/04 21:59:52.0453 1444 ================================================================================
2011/07/04 21:59:52.0453 1444 Scan started
2011/07/04 21:59:52.0453 1444 Mode: Manual;
2011/07/04 21:59:52.0453 1444 ================================================================================
2011/07/04 21:59:58.0250 1444 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/07/04 21:59:58.0875 1444 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/07/04 22:00:00.0062 1444 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/07/04 22:00:00.0703 1444 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/07/04 22:00:01.0375 1444 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/07/04 22:00:04.0796 1444 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2011/07/04 22:00:05.0468 1444 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/07/04 22:00:06.0265 1444 arusb(TP-LINK) (d8aa72b3760402b4a30925d9778e4688) C:\WINDOWS\system32\DRIVERS\arusb.sys
2011/07/04 22:00:08.0765 1444 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/07/04 22:00:09.0406 1444 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/07/04 22:00:10.0484 1444 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/07/04 22:00:11.0140 1444 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/07/04 22:00:11.0343 1444 avgio (87828ecd657f81503465ac705e845076) C:\Programme\AntiVir PersonalEdition Classic\avgio.sys
2011/07/04 22:00:11.0500 1444 avgntflt (fcb30820bed1d3feb55e3dd55a3f947f) C:\Programme\AntiVir PersonalEdition Classic\avgntflt.sys
2011/07/04 22:00:12.0140 1444 avipbb (0b09df022250fb7ba91fb932eac6ea9b) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/07/04 22:00:12.0796 1444 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/07/04 22:00:13.0421 1444 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/07/04 22:00:14.0031 1444 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/07/04 22:00:15.0125 1444 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/07/04 22:00:15.0703 1444 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/07/04 22:00:16.0328 1444 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/07/04 22:00:17.0500 1444 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/07/04 22:00:18.0578 1444 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/07/04 22:00:19.0828 1444 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
2011/07/04 22:00:20.0562 1444 CVPNDRVA (18994842386fd3039279d7865740abbd) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
2011/07/04 22:00:22.0390 1444 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/07/04 22:00:23.0328 1444 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2011/07/04 22:00:24.0312 1444 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys
2011/07/04 22:00:24.0984 1444 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2011/07/04 22:00:25.0609 1444 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/07/04 22:00:26.0203 1444 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/07/04 22:00:26.0875 1444 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/07/04 22:00:28.0125 1444 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/07/04 22:00:28.0750 1444 E100B (5c940a174dfb2c42b9f6ba6edc2baa0b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/07/04 22:00:29.0468 1444 e1express (389cf2cded384be477c3b3f15747d495) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
2011/07/04 22:00:30.0250 1444 erwi (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\gftemjy.sys
2011/07/04 22:00:30.0984 1444 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/07/04 22:00:31.0593 1444 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/07/04 22:00:32.0140 1444 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2011/07/04 22:00:32.0718 1444 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/07/04 22:00:33.0328 1444 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/07/04 22:00:34.0000 1444 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2011/07/04 22:00:34.0640 1444 FsVga (1f943241f4963cd51e5f61c93d3f45c7) C:\WINDOWS\system32\DRIVERS\fsvga.sys
2011/07/04 22:00:35.0156 1444 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/07/04 22:00:35.0765 1444 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/07/04 22:00:36.0359 1444 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2011/07/04 22:00:37.0046 1444 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/07/04 22:00:37.0703 1444 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/07/04 22:00:38.0343 1444 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/07/04 22:00:39.0031 1444 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/07/04 22:00:40.0218 1444 HSFHWAZL (acc46dda7fece95a253ae88cea172e12) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/07/04 22:00:41.0375 1444 HSF_DPV (c9f4e7da78a02623abf78a4a34ce79b1) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/07/04 22:00:42.0515 1444 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/07/04 22:00:44.0500 1444 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/07/04 22:00:45.0187 1444 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/07/04 22:00:46.0953 1444 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/07/04 22:00:47.0515 1444 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/07/04 22:00:48.0140 1444 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/07/04 22:00:48.0781 1444 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/07/04 22:00:49.0375 1444 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/07/04 22:00:50.0109 1444 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/07/04 22:00:50.0734 1444 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/07/04 22:00:51.0343 1444 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/07/04 22:00:51.0968 1444 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/07/04 22:00:52.0578 1444 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/07/04 22:00:53.0250 1444 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/07/04 22:00:54.0562 1444 MBAMSwissArmy (b309912717c29fc67e1ba4730a82b6dd) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011/07/04 22:00:55.0218 1444 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/07/04 22:00:55.0843 1444 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2011/07/04 22:00:56.0421 1444 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/07/04 22:00:57.0000 1444 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2011/07/04 22:00:57.0546 1444 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/07/04 22:00:58.0125 1444 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/07/04 22:00:58.0671 1444 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/07/04 22:00:59.0843 1444 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/07/04 22:01:00.0734 1444 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/07/04 22:01:01.0593 1444 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/07/04 22:01:02.0187 1444 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/07/04 22:01:02.0703 1444 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/07/04 22:01:03.0218 1444 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/07/04 22:01:03.0796 1444 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/07/04 22:01:04.0390 1444 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/07/04 22:01:05.0000 1444 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/07/04 22:01:05.0640 1444 MXOPSWD (c29f284ff7ab4ed38ce419a9424e52a2) C:\WINDOWS\system32\DRIVERS\mxopswd.sys
2011/07/04 22:01:06.0265 1444 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/07/04 22:01:06.0921 1444 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/07/04 22:01:07.0578 1444 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/07/04 22:01:08.0125 1444 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/07/04 22:01:08.0703 1444 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/07/04 22:01:09.0296 1444 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/07/04 22:01:09.0906 1444 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/07/04 22:01:10.0484 1444 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/07/04 22:01:11.0140 1444 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/07/04 22:01:11.0875 1444 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/07/04 22:01:12.0531 1444 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/07/04 22:01:13.0390 1444 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/07/04 22:01:14.0296 1444 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/07/04 22:01:16.0625 1444 nv (24f48f02fa8d9efda3425440f9814057) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/07/04 22:01:18.0984 1444 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/07/04 22:01:19.0546 1444 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/07/04 22:01:20.0203 1444 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
2011/07/04 22:01:20.0812 1444 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
2011/07/04 22:01:21.0406 1444 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
2011/07/04 22:01:22.0062 1444 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/07/04 22:01:22.0703 1444 PalmUSBD (240c0d4049a833b16b63b636acf01672) C:\WINDOWS\system32\drivers\PalmUSBD.sys
2011/07/04 22:01:23.0281 1444 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2011/07/04 22:01:23.0921 1444 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/07/04 22:01:24.0484 1444 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/07/04 22:01:25.0031 1444 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/07/04 22:01:26.0203 1444 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/07/04 22:01:26.0812 1444 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/07/04 22:01:30.0671 1444 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/07/04 22:01:31.0312 1444 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/07/04 22:01:31.0937 1444 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/07/04 22:01:32.0515 1444 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/07/04 22:01:35.0656 1444 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/07/04 22:01:36.0296 1444 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/07/04 22:01:36.0953 1444 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/07/04 22:01:37.0515 1444 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/07/04 22:01:38.0156 1444 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/07/04 22:01:38.0828 1444 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/07/04 22:01:39.0468 1444 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/07/04 22:01:40.0218 1444 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/07/04 22:01:40.0937 1444 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/07/04 22:01:41.0625 1444 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/07/04 22:01:42.0265 1444 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/07/04 22:01:42.0984 1444 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/07/04 22:01:43.0609 1444 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2011/07/04 22:01:44.0234 1444 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/07/04 22:01:44.0921 1444 SI3132 (716a724a447c559f122ea140d636fa48) C:\WINDOWS\system32\DRIVERS\SI3132.sys
2011/07/04 22:01:45.0468 1444 SiFilter (72cf151fb410e544904dbc7d7f29b796) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
2011/07/04 22:01:46.0531 1444 SiRemFil (62fd549acf2943f89612a8777295fa57) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys
2011/07/04 22:01:47.0125 1444 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/07/04 22:01:47.0734 1444 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\Drivers\SonyNC.sys
2011/07/04 22:01:48.0343 1444 SonyImgF (b98be9c307a7f6695203a294276f9cd8) C:\WINDOWS\system32\DRIVERS\SonyImgF.sys
2011/07/04 22:01:49.0437 1444 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/07/04 22:01:50.0296 1444 sptd (951ac13e32cf122d46d57eef4277257d) C:\WINDOWS\system32\Drivers\sptd.sys
2011/07/04 22:01:50.0296 1444 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 951ac13e32cf122d46d57eef4277257d
2011/07/04 22:01:50.0343 1444 sptd - detected LockedFile.Multi.Generic (1)
2011/07/04 22:01:51.0046 1444 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/07/04 22:01:51.0796 1444 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/07/04 22:01:52.0546 1444 sscdbus (2d4027c46b4c6e45875e3c4ba3f67492) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
2011/07/04 22:01:53.0125 1444 sscdmdfl (f548f1eba107bc19e91189e6a460bd0e) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
2011/07/04 22:01:53.0734 1444 sscdmdm (71d348d53597379dfe1de255d70af13c) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
2011/07/04 22:01:54.0359 1444 ssmdrv (71d609c5dff067906d930bde031c4cfe) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/07/04 22:01:54.0953 1444 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2011/07/04 22:01:56.0109 1444 STHDA (bbbc5bf9a5f1fb5d57e91b944d2e51a5) C:\WINDOWS\system32\drivers\sthda.sys
2011/07/04 22:01:57.0234 1444 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/07/04 22:01:57.0812 1444 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/07/04 22:01:58.0343 1444 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/07/04 22:02:01.0078 1444 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/07/04 22:02:01.0921 1444 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/07/04 22:02:02.0671 1444 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/07/04 22:02:03.0250 1444 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/07/04 22:02:03.0828 1444 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/07/04 22:02:04.0875 1444 ti21sony (3106074a87bd5a16e2a3af6902bb6d91) C:\WINDOWS\system32\drivers\ti21sony.sys
2011/07/04 22:02:05.0875 1444 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/07/04 22:02:07.0062 1444 tosporte (6a404454c6133e749be33892eb6ffa35) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/07/04 22:02:07.0656 1444 Tosrfbd (e4901804c4d8d613fa3560de2c2e0261) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/07/04 22:02:08.0281 1444 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/07/04 22:02:08.0875 1444 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/07/04 22:02:09.0453 1444 Tosrfhid (7726332391d8fca1a491a17f592fd6b3) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/07/04 22:02:10.0015 1444 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/07/04 22:02:10.0593 1444 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/07/04 22:02:11.0187 1444 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/07/04 22:02:11.0875 1444 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/07/04 22:02:13.0140 1444 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/07/04 22:02:13.0984 1444 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/07/04 22:02:14.0578 1444 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/07/04 22:02:15.0171 1444 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/07/04 22:02:15.0781 1444 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/07/04 22:02:16.0359 1444 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/07/04 22:02:16.0890 1444 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/07/04 22:02:17.0437 1444 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/07/04 22:02:18.0046 1444 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/07/04 22:02:18.0703 1444 usbvm321 (f9d550545afec1d581d2539f3488c4cd) C:\WINDOWS\system32\Drivers\usbvm321.sys
2011/07/04 22:02:19.0625 1444 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
2011/07/04 22:02:19.0625 1444 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\vaxscsi.sys. md5: 92cebc2bc7be2c8d49391b365569f306
2011/07/04 22:02:19.0656 1444 vaxscsi - detected LockedFile.Multi.Generic (1)
2011/07/04 22:02:20.0296 1444 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/07/04 22:02:21.0406 1444 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/07/04 22:02:22.0796 1444 w39n51 (73395a19fc86461a151d3c330604e8b3) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/07/04 22:02:24.0109 1444 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/07/04 22:02:25.0765 1444 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/07/04 22:02:26.0765 1444 winachsf (c1d5cbd8aa0d674da1ba1bb189696396) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/07/04 22:02:28.0062 1444 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/07/04 22:02:28.0625 1444 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/07/04 22:02:29.0265 1444 WSIMD (43f767d59bfc25d8f4fc2eb42043ec1e) C:\WINDOWS\system32\DRIVERS\wsimd.sys
2011/07/04 22:02:29.0875 1444 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/07/04 22:02:30.0500 1444 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/07/04 22:02:31.0093 1444 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/07/04 22:02:31.0562 1444 MBR (0x1B8) (6f9a1d528242bc09104b85e0becf5554) \Device\Harddisk0\DR0
2011/07/04 22:02:31.0593 1444 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.a (0)
2011/07/04 22:02:31.0640 1444 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR6
2011/07/04 22:02:31.0687 1444 MBR (0x1B8) (ddae9d649db12f6aff24483f2c298989) \Device\Harddisk3\DR8
2011/07/04 22:02:31.0796 1444 Boot (0x1200) (12803ab533efbaa260f979d134669071) \Device\Harddisk0\DR0\Partition0
2011/07/04 22:02:31.0875 1444 Boot (0x1200) (eb142777c4f384232b133eee9aadf225) \Device\Harddisk0\DR0\Partition1
2011/07/04 22:02:31.0906 1444 Boot (0x1200) (9a35b70b786cb52b35b28a2f1e3923ac) \Device\Harddisk3\DR8\Partition0
2011/07/04 22:02:31.0953 1444 ================================================================================
2011/07/04 22:02:31.0953 1444 Scan finished
2011/07/04 22:02:31.0953 1444 ================================================================================
2011/07/04 22:02:32.0015 1580 Detected object count: 3
2011/07/04 22:02:32.0015 1580 Actual detected object count: 3
2011/07/04 22:03:37.0281 1580 sptd (951ac13e32cf122d46d57eef4277257d) C:\WINDOWS\system32\Drivers\sptd.sys
2011/07/04 22:03:37.0281 1580 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 951ac13e32cf122d46d57eef4277257d
2011/07/04 22:03:37.0578 1580 C:\WINDOWS\system32\Drivers\sptd.sys - copied to quarantine
2011/07/04 22:03:37.0578 1580 LockedFile.Multi.Generic(sptd) - User select action: Quarantine
2011/07/04 22:03:38.0234 1580 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
2011/07/04 22:03:38.0250 1580 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\vaxscsi.sys. md5: 92cebc2bc7be2c8d49391b365569f306
2011/07/04 22:03:38.0265 1580 C:\WINDOWS\System32\Drivers\vaxscsi.sys - copied to quarantine
2011/07/04 22:03:38.0265 1580 LockedFile.Multi.Generic(vaxscsi) - User select action: Quarantine
2011/07/04 22:03:38.0359 1580 \Device\Harddisk0\DR0 (Rootkit.Boot.SST.a) - will be cured after reboot
2011/07/04 22:03:38.0359 1580 \Device\Harddisk0\DR0 - ok
2011/07/04 22:03:38.0359 1580 Rootkit.Boot.SST.a(\Device\Harddisk0\DR0) - User select action: Cure
2011/07/04 22:04:05.0250 1152 Deinitialize success
Zitat:
2011/07/04 23:07:21.0875 1848 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
2011/07/04 23:07:22.0125 1848 ================================================================================
2011/07/04 23:07:22.0125 1848 SystemInfo:
2011/07/04 23:07:22.0125 1848
2011/07/04 23:07:22.0125 1848 OS Version: 5.1.2600 ServicePack: 3.0
2011/07/04 23:07:22.0125 1848 Product type: Workstation
2011/07/04 23:07:22.0125 1848 ComputerName: MAID
2011/07/04 23:07:22.0125 1848 UserName: Marian Kasprowski
2011/07/04 23:07:22.0125 1848 Windows directory: C:\WINDOWS
2011/07/04 23:07:22.0125 1848 System windows directory: C:\WINDOWS
2011/07/04 23:07:22.0125 1848 Processor architecture: Intel x86
2011/07/04 23:07:22.0125 1848 Number of processors: 2
2011/07/04 23:07:22.0125 1848 Page size: 0x1000
2011/07/04 23:07:22.0125 1848 Boot type: Safe boot
2011/07/04 23:07:22.0125 1848 ================================================================================
2011/07/04 23:07:24.0750 1848 Initialize success
2011/07/04 23:07:27.0109 1904 ================================================================================
2011/07/04 23:07:27.0109 1904 Scan started
2011/07/04 23:07:27.0109 1904 Mode: Manual;
2011/07/04 23:07:27.0109 1904 ================================================================================
2011/07/04 23:07:32.0656 1904 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/07/04 23:07:33.0203 1904 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/07/04 23:07:34.0437 1904 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/07/04 23:07:35.0000 1904 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/07/04 23:07:35.0718 1904 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/07/04 23:07:39.0984 1904 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2011/07/04 23:07:40.0890 1904 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/07/04 23:07:42.0265 1904 arusb(TP-LINK) (d8aa72b3760402b4a30925d9778e4688) C:\WINDOWS\system32\DRIVERS\arusb.sys
2011/07/04 23:07:45.0796 1904 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/07/04 23:07:46.0765 1904 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/07/04 23:07:48.0562 1904 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/07/04 23:07:49.0562 1904 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/07/04 23:07:49.0859 1904 avgio (87828ecd657f81503465ac705e845076) C:\Programme\AntiVir PersonalEdition Classic\avgio.sys
2011/07/04 23:07:50.0281 1904 avgntflt (fcb30820bed1d3feb55e3dd55a3f947f) C:\Programme\AntiVir PersonalEdition Classic\avgntflt.sys
2011/07/04 23:07:51.0281 1904 avipbb (0b09df022250fb7ba91fb932eac6ea9b) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/07/04 23:07:52.0359 1904 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/07/04 23:07:53.0500 1904 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/07/04 23:07:54.0343 1904 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/07/04 23:07:55.0765 1904 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/07/04 23:07:56.0687 1904 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/07/04 23:07:57.0484 1904 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/07/04 23:07:58.0875 1904 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/07/04 23:08:00.0375 1904 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/07/04 23:08:01.0875 1904 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
2011/07/04 23:08:02.0828 1904 CVPNDRVA (18994842386fd3039279d7865740abbd) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
2011/07/04 23:08:05.0437 1904 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/07/04 23:08:06.0703 1904 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2011/07/04 23:08:07.0453 1904 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys
2011/07/04 23:08:08.0312 1904 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2011/07/04 23:08:09.0218 1904 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/07/04 23:08:10.0031 1904 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/07/04 23:08:10.0796 1904 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/07/04 23:08:12.0359 1904 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/07/04 23:08:13.0234 1904 E100B (5c940a174dfb2c42b9f6ba6edc2baa0b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/07/04 23:08:14.0218 1904 e1express (389cf2cded384be477c3b3f15747d495) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
2011/07/04 23:08:15.0593 1904 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/07/04 23:08:16.0203 1904 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/07/04 23:08:17.0171 1904 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2011/07/04 23:08:18.0156 1904 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/07/04 23:08:19.0250 1904 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/07/04 23:08:20.0531 1904 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2011/07/04 23:08:21.0343 1904 FsVga (1f943241f4963cd51e5f61c93d3f45c7) C:\WINDOWS\system32\DRIVERS\fsvga.sys
2011/07/04 23:08:22.0046 1904 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/07/04 23:08:22.0984 1904 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/07/04 23:08:23.0781 1904 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2011/07/04 23:08:24.0656 1904 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/07/04 23:08:25.0718 1904 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/07/04 23:08:26.0656 1904 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/07/04 23:08:27.0578 1904 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/07/04 23:08:29.0187 1904 HSFHWAZL (acc46dda7fece95a253ae88cea172e12) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/07/04 23:08:30.0765 1904 HSF_DPV (c9f4e7da78a02623abf78a4a34ce79b1) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/07/04 23:08:31.0812 1904 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/07/04 23:08:33.0921 1904 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/07/04 23:08:34.0906 1904 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/07/04 23:08:37.0078 1904 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/07/04 23:08:37.0843 1904 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/07/04 23:08:38.0687 1904 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/07/04 23:08:39.0546 1904 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/07/04 23:08:40.0359 1904 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/07/04 23:08:41.0156 1904 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/07/04 23:08:42.0265 1904 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/07/04 23:08:43.0187 1904 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/07/04 23:08:44.0140 1904 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/07/04 23:08:44.0968 1904 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/07/04 23:08:45.0718 1904 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/07/04 23:08:47.0343 1904 MBAMSwissArmy (b309912717c29fc67e1ba4730a82b6dd) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011/07/04 23:08:47.0937 1904 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/07/04 23:08:48.0703 1904 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2011/07/04 23:08:49.0500 1904 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/07/04 23:08:50.0250 1904 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2011/07/04 23:08:50.0968 1904 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/07/04 23:08:51.0703 1904 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/07/04 23:08:52.0500 1904 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/07/04 23:08:54.0031 1904 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/07/04 23:08:54.0890 1904 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/07/04 23:08:55.0812 1904 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/07/04 23:08:56.0671 1904 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/07/04 23:08:57.0312 1904 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/07/04 23:08:58.0078 1904 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/07/04 23:08:58.0828 1904 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/07/04 23:08:59.0828 1904 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/07/04 23:09:00.0515 1904 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/07/04 23:09:01.0203 1904 MXOPSWD (c29f284ff7ab4ed38ce419a9424e52a2) C:\WINDOWS\system32\DRIVERS\mxopswd.sys
2011/07/04 23:09:01.0968 1904 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/07/04 23:09:02.0656 1904 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/07/04 23:09:03.0343 1904 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/07/04 23:09:04.0031 1904 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/07/04 23:09:04.0531 1904 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/07/04 23:09:05.0156 1904 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/07/04 23:09:05.0671 1904 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/07/04 23:09:06.0281 1904 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/07/04 23:09:07.0140 1904 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/07/04 23:09:08.0250 1904 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/07/04 23:09:09.0062 1904 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/07/04 23:09:10.0156 1904 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/07/04 23:09:10.0687 1904 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/07/04 23:09:12.0953 1904 nv (24f48f02fa8d9efda3425440f9814057) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/07/04 23:09:13.0515 1904 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/07/04 23:09:14.0046 1904 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/07/04 23:09:14.0609 1904 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
2011/07/04 23:09:15.0109 1904 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
2011/07/04 23:09:15.0687 1904 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
2011/07/04 23:09:16.0250 1904 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/07/04 23:09:16.0812 1904 PalmUSBD (240c0d4049a833b16b63b636acf01672) C:\WINDOWS\system32\drivers\PalmUSBD.sys
2011/07/04 23:09:17.0375 1904 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2011/07/04 23:09:17.0906 1904 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/07/04 23:09:18.0437 1904 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/07/04 23:09:18.0968 1904 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/07/04 23:09:19.0984 1904 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/07/04 23:09:20.0562 1904 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/07/04 23:09:24.0046 1904 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/07/04 23:09:24.0609 1904 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/07/04 23:09:25.0109 1904 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/07/04 23:09:25.0640 1904 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/07/04 23:09:28.0546 1904 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/07/04 23:09:29.0093 1904 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/07/04 23:09:29.0593 1904 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/07/04 23:09:30.0125 1904 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/07/04 23:09:30.0671 1904 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/07/04 23:09:31.0203 1904 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/07/04 23:09:31.0828 1904 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/07/04 23:09:32.0406 1904 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/07/04 23:09:32.0937 1904 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/07/04 23:09:33.0468 1904 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/07/04 23:09:34.0046 1904 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/07/04 23:09:34.0625 1904 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/07/04 23:09:35.0203 1904 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2011/07/04 23:09:35.0765 1904 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/07/04 23:09:36.0312 1904 SI3132 (716a724a447c559f122ea140d636fa48) C:\WINDOWS\system32\DRIVERS\SI3132.sys
2011/07/04 23:09:36.0796 1904 SiFilter (72cf151fb410e544904dbc7d7f29b796) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
2011/07/04 23:09:37.0812 1904 SiRemFil (62fd549acf2943f89612a8777295fa57) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys
2011/07/04 23:09:38.0328 1904 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/07/04 23:09:38.0890 1904 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\Drivers\SonyNC.sys
2011/07/04 23:09:39.0468 1904 SonyImgF (b98be9c307a7f6695203a294276f9cd8) C:\WINDOWS\system32\DRIVERS\SonyImgF.sys
2011/07/04 23:09:40.0468 1904 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/07/04 23:09:41.0312 1904 sptd (951ac13e32cf122d46d57eef4277257d) C:\WINDOWS\system32\Drivers\sptd.sys
2011/07/04 23:09:41.0312 1904 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 951ac13e32cf122d46d57eef4277257d
2011/07/04 23:09:41.0328 1904 sptd - detected LockedFile.Multi.Generic (1)
2011/07/04 23:09:41.0875 1904 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/07/04 23:09:42.0656 1904 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/07/04 23:09:43.0203 1904 sscdbus (2d4027c46b4c6e45875e3c4ba3f67492) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
2011/07/04 23:09:43.0718 1904 sscdmdfl (f548f1eba107bc19e91189e6a460bd0e) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
2011/07/04 23:09:44.0343 1904 sscdmdm (71d348d53597379dfe1de255d70af13c) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
2011/07/04 23:09:44.0843 1904 ssmdrv (71d609c5dff067906d930bde031c4cfe) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/07/04 23:09:45.0359 1904 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2011/07/04 23:09:46.0468 1904 STHDA (bbbc5bf9a5f1fb5d57e91b944d2e51a5) C:\WINDOWS\system32\drivers\sthda.sys
2011/07/04 23:09:47.0000 1904 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/07/04 23:09:47.0562 1904 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/07/04 23:09:48.0125 1904 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/07/04 23:09:50.0718 1904 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/07/04 23:09:51.0578 1904 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/07/04 23:09:52.0343 1904 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/07/04 23:09:53.0078 1904 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/07/04 23:09:53.0875 1904 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/07/04 23:09:55.0015 1904 ti21sony (3106074a87bd5a16e2a3af6902bb6d91) C:\WINDOWS\system32\drivers\ti21sony.sys
2011/07/04 23:09:55.0578 1904 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/07/04 23:09:57.0078 1904 tosporte (6a404454c6133e749be33892eb6ffa35) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/07/04 23:09:57.0828 1904 Tosrfbd (e4901804c4d8d613fa3560de2c2e0261) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/07/04 23:09:58.0515 1904 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/07/04 23:09:59.0062 1904 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/07/04 23:09:59.0578 1904 Tosrfhid (7726332391d8fca1a491a17f592fd6b3) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/07/04 23:10:00.0093 1904 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/07/04 23:10:00.0656 1904 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/07/04 23:10:01.0156 1904 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/07/04 23:10:01.0734 1904 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/07/04 23:10:02.0937 1904 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/07/04 23:10:03.0484 1904 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/07/04 23:10:04.0046 1904 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/07/04 23:10:04.0640 1904 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/07/04 23:10:05.0203 1904 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/07/04 23:10:05.0718 1904 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/07/04 23:10:06.0203 1904 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/07/04 23:10:06.0718 1904 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/07/04 23:10:07.0265 1904 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/07/04 23:10:07.0953 1904 usbvm321 (f9d550545afec1d581d2539f3488c4cd) C:\WINDOWS\system32\Drivers\usbvm321.sys
2011/07/04 23:10:08.0640 1904 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
2011/07/04 23:10:08.0640 1904 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\vaxscsi.sys. md5: 92cebc2bc7be2c8d49391b365569f306
2011/07/04 23:10:08.0656 1904 vaxscsi - detected LockedFile.Multi.Generic (1)
2011/07/04 23:10:09.0218 1904 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/07/04 23:10:10.0265 1904 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/07/04 23:10:11.0500 1904 w39n51 (73395a19fc86461a151d3c330604e8b3) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/07/04 23:10:12.0062 1904 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/07/04 23:10:13.0625 1904 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/07/04 23:10:14.0765 1904 winachsf (c1d5cbd8aa0d674da1ba1bb189696396) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/07/04 23:10:15.0859 1904 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/07/04 23:10:16.0843 1904 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/07/04 23:10:17.0593 1904 WSIMD (43f767d59bfc25d8f4fc2eb42043ec1e) C:\WINDOWS\system32\DRIVERS\wsimd.sys
2011/07/04 23:10:18.0125 1904 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/07/04 23:10:18.0859 1904 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/07/04 23:10:19.0796 1904 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/07/04 23:10:20.0562 1904 xmwvq (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\yjhkwtq.sys
2011/07/04 23:10:20.0640 1904 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
2011/07/04 23:10:21.0031 1904 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR4
2011/07/04 23:10:21.0046 1904 MBR (0x1B8) (ddae9d649db12f6aff24483f2c298989) \Device\Harddisk2\DR5
2011/07/04 23:10:21.0062 1904 Boot (0x1200) (12803ab533efbaa260f979d134669071) \Device\Harddisk0\DR0\Partition0
2011/07/04 23:10:21.0093 1904 Boot (0x1200) (eb142777c4f384232b133eee9aadf225) \Device\Harddisk0\DR0\Partition1
2011/07/04 23:10:21.0109 1904 Boot (0x1200) (9a35b70b786cb52b35b28a2f1e3923ac) \Device\Harddisk2\DR5\Partition0
2011/07/04 23:10:21.0109 1904 ================================================================================
2011/07/04 23:10:21.0109 1904 Scan finished
2011/07/04 23:10:21.0109 1904 ================================================================================
2011/07/04 23:10:21.0109 1884 Detected object count: 2
2011/07/04 23:10:21.0109 1884 Actual detected object count: 2
2011/07/04 23:11:04.0656 1884 HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted after reboot
2011/07/04 23:11:04.0734 1884 HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted after reboot
2011/07/04 23:11:04.0734 1884 HKLM\SYSTEM\ControlSet003\services\sptd - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 HKLM\SYSTEM\ControlSet004\services\sptd - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 C:\WINDOWS\system32\Drivers\sptd.sys - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 LockedFile.Multi.Generic(sptd) - User select action: Delete
2011/07/04 23:11:04.0750 1884 HKLM\SYSTEM\ControlSet001\services\vaxscsi - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 HKLM\SYSTEM\ControlSet002\services\vaxscsi - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 HKLM\SYSTEM\ControlSet003\services\vaxscsi - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 HKLM\SYSTEM\ControlSet004\services\vaxscsi - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 C:\WINDOWS\System32\Drivers\vaxscsi.sys - will be deleted after reboot
2011/07/04 23:11:04.0750 1884 LockedFile.Multi.Generic(vaxscsi) - User select action: Delete
Zitat:
2011/07/04 23:30:04.0890 0788 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
2011/07/04 23:30:05.0140 0788 ================================================================================
2011/07/04 23:30:05.0140 0788 SystemInfo:
2011/07/04 23:30:05.0140 0788
2011/07/04 23:30:05.0140 0788 OS Version: 5.1.2600 ServicePack: 3.0
2011/07/04 23:30:05.0140 0788 Product type: Workstation
2011/07/04 23:30:05.0140 0788 ComputerName: MAID
2011/07/04 23:30:05.0140 0788 UserName: Marian Kasprowski
2011/07/04 23:30:05.0140 0788 Windows directory: C:\WINDOWS
2011/07/04 23:30:05.0140 0788 System windows directory: C:\WINDOWS
2011/07/04 23:30:05.0140 0788 Processor architecture: Intel x86
2011/07/04 23:30:05.0140 0788 Number of processors: 2
2011/07/04 23:30:05.0140 0788 Page size: 0x1000
2011/07/04 23:30:05.0140 0788 Boot type: Safe boot
2011/07/04 23:30:05.0140 0788 ================================================================================
2011/07/04 23:30:05.0515 0788 Initialize success
2011/07/04 23:30:06.0953 0856 ================================================================================
2011/07/04 23:30:06.0953 0856 Scan started
2011/07/04 23:30:06.0953 0856 Mode: Manual;
2011/07/04 23:30:06.0953 0856 ================================================================================
2011/07/04 23:30:09.0484 0856 98327771 (98ee366fde48d0bbed6c33ccc63ed2a8) C:\WINDOWS\system32\drivers\69924078.sys
2011/07/04 23:30:11.0171 0856 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/07/04 23:30:11.0750 0856 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/07/04 23:30:12.0890 0856 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/07/04 23:30:13.0437 0856 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/07/04 23:30:14.0062 0856 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/07/04 23:30:17.0312 0856 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2011/07/04 23:30:17.0953 0856 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/07/04 23:30:18.0671 0856 arusb(TP-LINK) (d8aa72b3760402b4a30925d9778e4688) C:\WINDOWS\system32\DRIVERS\arusb.sys
2011/07/04 23:30:21.0015 0856 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/07/04 23:30:21.0640 0856 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/07/04 23:30:22.0750 0856 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/07/04 23:30:23.0281 0856 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/07/04 23:30:23.0468 0856 avgio (87828ecd657f81503465ac705e845076) C:\Programme\AntiVir PersonalEdition Classic\avgio.sys
2011/07/04 23:30:23.0671 0856 avgntflt (fcb30820bed1d3feb55e3dd55a3f947f) C:\Programme\AntiVir PersonalEdition Classic\avgntflt.sys
2011/07/04 23:30:24.0312 0856 avipbb (0b09df022250fb7ba91fb932eac6ea9b) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/07/04 23:30:24.0890 0856 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/07/04 23:30:25.0531 0856 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/07/04 23:30:26.0109 0856 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/07/04 23:30:27.0156 0856 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/07/04 23:30:27.0703 0856 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/07/04 23:30:28.0296 0856 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/07/04 23:30:29.0390 0856 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/07/04 23:30:30.0484 0856 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/07/04 23:30:31.0625 0856 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
2011/07/04 23:30:32.0359 0856 CVPNDRVA (18994842386fd3039279d7865740abbd) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
2011/07/04 23:30:34.0015 0856 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/07/04 23:30:34.0953 0856 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2011/07/04 23:30:35.0546 0856 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys
2011/07/04 23:30:36.0187 0856 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2011/07/04 23:30:36.0718 0856 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/07/04 23:30:37.0296 0856 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/07/04 23:30:37.0984 0856 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/07/04 23:30:39.0093 0856 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/07/04 23:30:39.0734 0856 E100B (5c940a174dfb2c42b9f6ba6edc2baa0b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/07/04 23:30:40.0390 0856 e1express (389cf2cded384be477c3b3f15747d495) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
2011/07/04 23:30:41.0171 0856 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/07/04 23:30:41.0765 0856 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/07/04 23:30:42.0296 0856 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2011/07/04 23:30:42.0828 0856 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/07/04 23:30:43.0437 0856 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/07/04 23:30:44.0031 0856 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2011/07/04 23:30:44.0578 0856 FsVga (1f943241f4963cd51e5f61c93d3f45c7) C:\WINDOWS\system32\DRIVERS\fsvga.sys
2011/07/04 23:30:45.0125 0856 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/07/04 23:30:45.0750 0856 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/07/04 23:30:46.0281 0856 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2011/07/04 23:30:46.0890 0856 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/07/04 23:30:47.0531 0856 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/07/04 23:30:48.0187 0856 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/07/04 23:30:48.0796 0856 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/07/04 23:30:50.0000 0856 HSFHWAZL (acc46dda7fece95a253ae88cea172e12) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/07/04 23:30:51.0031 0856 HSF_DPV (c9f4e7da78a02623abf78a4a34ce79b1) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/07/04 23:30:51.0734 0856 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/07/04 23:30:53.0437 0856 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/07/04 23:30:54.0031 0856 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/07/04 23:30:55.0765 0856 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/07/04 23:30:56.0296 0856 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/07/04 23:30:56.0859 0856 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/07/04 23:30:57.0453 0856 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/07/04 23:30:58.0031 0856 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/07/04 23:30:58.0656 0856 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/07/04 23:30:59.0234 0856 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/07/04 23:30:59.0812 0856 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/07/04 23:31:00.0375 0856 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/07/04 23:31:01.0031 0856 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/07/04 23:31:01.0593 0856 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/07/04 23:31:02.0859 0856 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/07/04 23:31:03.0500 0856 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2011/07/04 23:31:04.0046 0856 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/07/04 23:31:04.0593 0856 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2011/07/04 23:31:05.0156 0856 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/07/04 23:31:05.0718 0856 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/07/04 23:31:06.0250 0856 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/07/04 23:31:07.0421 0856 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/07/04 23:31:08.0203 0856 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/07/04 23:31:08.0796 0856 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/07/04 23:31:09.0359 0856 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/07/04 23:31:09.0937 0856 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/07/04 23:31:10.0468 0856 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/07/04 23:31:11.0031 0856 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/07/04 23:31:11.0640 0856 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/07/04 23:31:12.0250 0856 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/07/04 23:31:12.0796 0856 MXOPSWD (c29f284ff7ab4ed38ce419a9424e52a2) C:\WINDOWS\system32\DRIVERS\mxopswd.sys
2011/07/04 23:31:13.0390 0856 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/07/04 23:31:14.0062 0856 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/07/04 23:31:14.0609 0856 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/07/04 23:31:15.0187 0856 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/07/04 23:31:15.0718 0856 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/07/04 23:31:16.0281 0856 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/07/04 23:31:16.0859 0856 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/07/04 23:31:17.0453 0856 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/07/04 23:31:18.0062 0856 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/07/04 23:31:18.0765 0856 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/07/04 23:31:19.0343 0856 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/07/04 23:31:20.0171 0856 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/07/04 23:31:20.0843 0856 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/07/04 23:31:23.0125 0856 nv (24f48f02fa8d9efda3425440f9814057) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/07/04 23:31:23.0734 0856 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/07/04 23:31:24.0296 0856 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/07/04 23:31:24.0921 0856 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
2011/07/04 23:31:25.0453 0856 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
2011/07/04 23:31:26.0031 0856 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
2011/07/04 23:31:26.0640 0856 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/07/04 23:31:27.0250 0856 PalmUSBD (240c0d4049a833b16b63b636acf01672) C:\WINDOWS\system32\drivers\PalmUSBD.sys
2011/07/04 23:31:27.0828 0856 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2011/07/04 23:31:28.0375 0856 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/07/04 23:31:28.0984 0856 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/07/04 23:31:29.0578 0856 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/07/04 23:31:30.0671 0856 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/07/04 23:31:31.0281 0856 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/07/04 23:31:35.0109 0856 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/07/04 23:31:35.0671 0856 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/07/04 23:31:36.0250 0856 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/07/04 23:31:36.0812 0856 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/07/04 23:31:39.0984 0856 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/07/04 23:31:40.0578 0856 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/07/04 23:31:41.0156 0856 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/07/04 23:31:41.0750 0856 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/07/04 23:31:42.0359 0856 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/07/04 23:31:42.0906 0856 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/07/04 23:31:43.0593 0856 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/07/04 23:31:44.0218 0856 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/07/04 23:31:44.0781 0856 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/07/04 23:31:45.0437 0856 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/07/04 23:31:46.0093 0856 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/07/04 23:31:46.0781 0856 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/07/04 23:31:47.0453 0856 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2011/07/04 23:31:48.0046 0856 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/07/04 23:31:48.0671 0856 SI3132 (716a724a447c559f122ea140d636fa48) C:\WINDOWS\system32\DRIVERS\SI3132.sys
2011/07/04 23:31:49.0218 0856 SiFilter (72cf151fb410e544904dbc7d7f29b796) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
2011/07/04 23:31:50.0265 0856 SiRemFil (62fd549acf2943f89612a8777295fa57) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys
2011/07/04 23:31:50.0828 0856 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/07/04 23:31:51.0453 0856 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\Drivers\SonyNC.sys
2011/07/04 23:31:52.0000 0856 SonyImgF (b98be9c307a7f6695203a294276f9cd8) C:\WINDOWS\system32\DRIVERS\SonyImgF.sys
2011/07/04 23:31:53.0078 0856 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/07/04 23:31:53.0953 0856 sptd (951ac13e32cf122d46d57eef4277257d) C:\WINDOWS\system32\Drivers\sptd.sys
2011/07/04 23:31:53.0953 0856 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 951ac13e32cf122d46d57eef4277257d
2011/07/04 23:31:54.0000 0856 sptd - detected LockedFile.Multi.Generic (1)
2011/07/04 23:31:54.0578 0856 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/07/04 23:31:55.0343 0856 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/07/04 23:31:55.0953 0856 sscdbus (2d4027c46b4c6e45875e3c4ba3f67492) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
2011/07/04 23:31:56.0500 0856 sscdmdfl (f548f1eba107bc19e91189e6a460bd0e) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
2011/07/04 23:31:57.0140 0856 sscdmdm (71d348d53597379dfe1de255d70af13c) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
2011/07/04 23:31:57.0687 0856 ssmdrv (71d609c5dff067906d930bde031c4cfe) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/07/04 23:31:58.0265 0856 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2011/07/04 23:31:59.0375 0856 STHDA (bbbc5bf9a5f1fb5d57e91b944d2e51a5) C:\WINDOWS\system32\drivers\sthda.sys
2011/07/04 23:32:00.0015 0856 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/07/04 23:32:00.0531 0856 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/07/04 23:32:01.0187 0856 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/07/04 23:32:03.0890 0856 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/07/04 23:32:04.0656 0856 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/07/04 23:32:05.0171 0856 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/07/04 23:32:05.0750 0856 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/07/04 23:32:06.0375 0856 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/07/04 23:32:07.0375 0856 ti21sony (3106074a87bd5a16e2a3af6902bb6d91) C:\WINDOWS\system32\drivers\ti21sony.sys
2011/07/04 23:32:07.0968 0856 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/07/04 23:32:09.0031 0856 tosporte (6a404454c6133e749be33892eb6ffa35) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/07/04 23:32:09.0609 0856 Tosrfbd (e4901804c4d8d613fa3560de2c2e0261) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/07/04 23:32:10.0218 0856 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/07/04 23:32:10.0765 0856 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/07/04 23:32:11.0343 0856 Tosrfhid (7726332391d8fca1a491a17f592fd6b3) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/07/04 23:32:11.0937 0856 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/07/04 23:32:12.0484 0856 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/07/04 23:32:13.0031 0856 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/07/04 23:32:13.0703 0856 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/07/04 23:32:14.0968 0856 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/07/04 23:32:15.0593 0856 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/07/04 23:32:16.0171 0856 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/07/04 23:32:16.0750 0856 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/07/04 23:32:17.0312 0856 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/07/04 23:32:17.0875 0856 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/07/04 23:32:18.0421 0856 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/07/04 23:32:18.0968 0856 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/07/04 23:32:19.0515 0856 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/07/04 23:32:20.0140 0856 usbvm321 (f9d550545afec1d581d2539f3488c4cd) C:\WINDOWS\system32\Drivers\usbvm321.sys
2011/07/04 23:32:20.0937 0856 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
2011/07/04 23:32:20.0937 0856 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\vaxscsi.sys. md5: 92cebc2bc7be2c8d49391b365569f306
2011/07/04 23:32:20.0968 0856 vaxscsi - detected LockedFile.Multi.Generic (1)
2011/07/04 23:32:21.0578 0856 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/07/04 23:32:22.0640 0856 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/07/04 23:32:23.0984 0856 w39n51 (73395a19fc86461a151d3c330604e8b3) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/07/04 23:32:24.0609 0856 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/07/04 23:32:26.0187 0856 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/07/04 23:32:27.0156 0856 winachsf (c1d5cbd8aa0d674da1ba1bb189696396) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/07/04 23:32:28.0031 0856 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/07/04 23:32:28.0578 0856 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/07/04 23:32:29.0187 0856 WSIMD (43f767d59bfc25d8f4fc2eb42043ec1e) C:\WINDOWS\system32\DRIVERS\wsimd.sys
2011/07/04 23:32:29.0750 0856 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/07/04 23:32:30.0359 0856 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/07/04 23:32:30.0953 0856 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/07/04 23:32:31.0593 0856 xmwvq (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\yjhkwtq.sys
2011/07/04 23:32:31.0890 0856 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
2011/07/04 23:32:32.0312 0856 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR4
2011/07/04 23:32:32.0390 0856 MBR (0x1B8) (ddae9d649db12f6aff24483f2c298989) \Device\Harddisk2\DR5
2011/07/04 23:32:32.0453 0856 Boot (0x1200) (12803ab533efbaa260f979d134669071) \Device\Harddisk0\DR0\Partition0
2011/07/04 23:32:32.0546 0856 Boot (0x1200) (eb142777c4f384232b133eee9aadf225) \Device\Harddisk0\DR0\Partition1
2011/07/04 23:32:32.0593 0856 Boot (0x1200) (9a35b70b786cb52b35b28a2f1e3923ac) \Device\Harddisk2\DR5\Partition0
2011/07/04 23:32:32.0640 0856 ================================================================================
2011/07/04 23:32:32.0640 0856 Scan finished
2011/07/04 23:32:32.0640 0856 ================================================================================
2011/07/04 23:32:32.0703 0976 Detected object count: 2
2011/07/04 23:32:32.0703 0976 Actual detected object count: 2
2011/07/04 23:32:43.0703 0976 HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted after reboot
2011/07/04 23:32:43.0718 0976 HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted after reboot
2011/07/04 23:32:43.0718 0976 HKLM\SYSTEM\ControlSet003\services\sptd - will be deleted after reboot
2011/07/04 23:32:43.0718 0976 HKLM\SYSTEM\ControlSet004\services\sptd - will be deleted after reboot
2011/07/04 23:32:43.0734 0976 C:\WINDOWS\system32\Drivers\sptd.sys - will be deleted after reboot
2011/07/04 23:32:43.0734 0976 LockedFile.Multi.Generic(sptd) - User select action: Delete
2011/07/04 23:32:43.0750 0976 HKLM\SYSTEM\ControlSet001\services\vaxscsi - will be deleted after reboot
2011/07/04 23:32:43.0750 0976 HKLM\SYSTEM\ControlSet002\services\vaxscsi - will be deleted after reboot
2011/07/04 23:32:43.0750 0976 HKLM\SYSTEM\ControlSet003\services\vaxscsi - will be deleted after reboot
2011/07/04 23:32:43.0750 0976 HKLM\SYSTEM\ControlSet004\services\vaxscsi - will be deleted after reboot
2011/07/04 23:32:43.0765 0976 C:\WINDOWS\System32\Drivers\vaxscsi.sys - will be deleted after reboot
2011/07/04 23:32:43.0765 0976 LockedFile.Multi.Generic(vaxscsi) - User select action: Delete
2011/07/04 23:33:01.0359 0800 Deinitialize success

Alt 07.07.2011, 19:25   #8
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Zitat:
2011/07/05 08:10:12.0531 1544 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
2011/07/05 08:10:12.0640 1544 ================================================================================
2011/07/05 08:10:12.0640 1544 SystemInfo:
2011/07/05 08:10:12.0640 1544
2011/07/05 08:10:12.0640 1544 OS Version: 5.1.2600 ServicePack: 3.0
2011/07/05 08:10:12.0640 1544 Product type: Workstation
2011/07/05 08:10:12.0640 1544 ComputerName: MAID
2011/07/05 08:10:12.0640 1544 UserName: Administrator
2011/07/05 08:10:12.0640 1544 Windows directory: C:\WINDOWS
2011/07/05 08:10:12.0640 1544 System windows directory: C:\WINDOWS
2011/07/05 08:10:12.0640 1544 Processor architecture: Intel x86
2011/07/05 08:10:12.0640 1544 Number of processors: 2
2011/07/05 08:10:12.0640 1544 Page size: 0x1000
2011/07/05 08:10:12.0640 1544 Boot type: Safe boot
2011/07/05 08:10:12.0640 1544 ================================================================================
2011/07/05 08:10:18.0109 1544 Initialize success
2011/07/05 08:10:20.0453 1564 ================================================================================
2011/07/05 08:10:20.0453 1564 Scan started
2011/07/05 08:10:20.0453 1564 Mode: Manual;
2011/07/05 08:10:20.0453 1564 ================================================================================
2011/07/05 08:10:23.0718 1564 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/07/05 08:10:24.0359 1564 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/07/05 08:10:25.0578 1564 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/07/05 08:10:26.0281 1564 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/07/05 08:10:26.0921 1564 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/07/05 08:10:30.0312 1564 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2011/07/05 08:10:31.0000 1564 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/07/05 08:10:31.0984 1564 arusb(TP-LINK) (d8aa72b3760402b4a30925d9778e4688) C:\WINDOWS\system32\DRIVERS\arusb.sys
2011/07/05 08:10:35.0078 1564 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/07/05 08:10:35.0625 1564 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/07/05 08:10:36.0703 1564 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/07/05 08:10:37.0281 1564 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/07/05 08:10:37.0468 1564 avgio (87828ecd657f81503465ac705e845076) C:\Programme\AntiVir PersonalEdition Classic\avgio.sys
2011/07/05 08:10:37.0656 1564 avgntflt (fcb30820bed1d3feb55e3dd55a3f947f) C:\Programme\AntiVir PersonalEdition Classic\avgntflt.sys
2011/07/05 08:10:38.0281 1564 avipbb (0b09df022250fb7ba91fb932eac6ea9b) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/07/05 08:10:38.0906 1564 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/07/05 08:10:39.0546 1564 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/07/05 08:10:40.0109 1564 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/07/05 08:10:41.0171 1564 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/07/05 08:10:41.0796 1564 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/07/05 08:10:42.0406 1564 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/07/05 08:10:43.0609 1564 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/07/05 08:10:44.0656 1564 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/07/05 08:10:45.0859 1564 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
2011/07/05 08:10:46.0625 1564 CVPNDRVA (18994842386fd3039279d7865740abbd) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
2011/07/05 08:10:48.0500 1564 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/07/05 08:10:49.0437 1564 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2011/07/05 08:10:50.0468 1564 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys
2011/07/05 08:10:51.0093 1564 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2011/07/05 08:10:51.0718 1564 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/07/05 08:10:52.0343 1564 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/07/05 08:10:52.0968 1564 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/07/05 08:10:54.0156 1564 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/07/05 08:10:54.0843 1564 E100B (5c940a174dfb2c42b9f6ba6edc2baa0b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/07/05 08:10:55.0546 1564 e1express (389cf2cded384be477c3b3f15747d495) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
2011/07/05 08:10:56.0500 1564 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/07/05 08:10:57.0140 1564 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/07/05 08:10:57.0734 1564 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2011/07/05 08:10:58.0296 1564 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/07/05 08:10:58.0875 1564 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/07/05 08:10:59.0578 1564 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2011/07/05 08:11:00.0156 1564 FsVga (1f943241f4963cd51e5f61c93d3f45c7) C:\WINDOWS\system32\DRIVERS\fsvga.sys
2011/07/05 08:11:00.0687 1564 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/07/05 08:11:01.0312 1564 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/07/05 08:11:01.0984 1564 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2011/07/05 08:11:02.0593 1564 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/07/05 08:11:03.0296 1564 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/07/05 08:11:04.0000 1564 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/07/05 08:11:04.0609 1564 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/07/05 08:11:05.0828 1564 HSFHWAZL (acc46dda7fece95a253ae88cea172e12) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/07/05 08:11:07.0015 1564 HSF_DPV (c9f4e7da78a02623abf78a4a34ce79b1) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/07/05 08:11:08.0203 1564 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/07/05 08:11:10.0031 1564 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/07/05 08:11:10.0765 1564 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/07/05 08:11:12.0406 1564 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/07/05 08:11:12.0968 1564 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/07/05 08:11:13.0546 1564 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/07/05 08:11:14.0078 1564 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/07/05 08:11:14.0734 1564 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/07/05 08:11:15.0515 1564 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/07/05 08:11:16.0109 1564 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/07/05 08:11:16.0671 1564 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/07/05 08:11:17.0343 1564 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/07/05 08:11:17.0937 1564 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/07/05 08:11:18.0593 1564 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/07/05 08:11:19.0906 1564 MBAMProtector (3d2c13377763eeac0ca6fb46f57217ed) C:\WINDOWS\system32\drivers\mbam.sys
2011/07/05 08:11:20.0515 1564 MBAMSwissArmy (b309912717c29fc67e1ba4730a82b6dd) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011/07/05 08:11:21.0187 1564 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/07/05 08:11:21.0796 1564 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2011/07/05 08:11:22.0359 1564 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/07/05 08:11:22.0953 1564 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2011/07/05 08:11:23.0515 1564 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/07/05 08:11:24.0078 1564 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/07/05 08:11:24.0640 1564 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/07/05 08:11:25.0828 1564 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/07/05 08:11:26.0687 1564 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/07/05 08:11:27.0562 1564 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/07/05 08:11:28.0156 1564 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/07/05 08:11:28.0687 1564 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/07/05 08:11:29.0234 1564 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/07/05 08:11:29.0765 1564 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/07/05 08:11:30.0375 1564 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/07/05 08:11:30.0984 1564 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/07/05 08:11:31.0625 1564 MXOPSWD (c29f284ff7ab4ed38ce419a9424e52a2) C:\WINDOWS\system32\DRIVERS\mxopswd.sys
2011/07/05 08:11:32.0187 1564 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/07/05 08:11:32.0953 1564 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/07/05 08:11:33.0546 1564 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/07/05 08:11:34.0125 1564 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/07/05 08:11:34.0656 1564 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/07/05 08:11:35.0265 1564 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/07/05 08:11:35.0875 1564 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/07/05 08:11:36.0468 1564 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/07/05 08:11:37.0109 1564 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/07/05 08:11:37.0906 1564 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/07/05 08:11:38.0562 1564 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/07/05 08:11:39.0359 1564 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/07/05 08:11:40.0250 1564 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/07/05 08:11:42.0609 1564 nv (24f48f02fa8d9efda3425440f9814057) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/07/05 08:11:44.0953 1564 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/07/05 08:11:45.0484 1564 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/07/05 08:11:46.0156 1564 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
2011/07/05 08:11:46.0765 1564 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
2011/07/05 08:11:47.0375 1564 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
2011/07/05 08:11:48.0031 1564 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/07/05 08:11:48.0703 1564 PalmUSBD (240c0d4049a833b16b63b636acf01672) C:\WINDOWS\system32\drivers\PalmUSBD.sys
2011/07/05 08:11:49.0265 1564 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2011/07/05 08:11:49.0828 1564 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/07/05 08:11:50.0421 1564 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/07/05 08:11:51.0015 1564 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/07/05 08:11:52.0125 1564 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/07/05 08:11:52.0765 1564 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/07/05 08:11:56.0687 1564 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/07/05 08:11:57.0546 1564 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/07/05 08:11:58.0437 1564 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/07/05 08:11:58.0968 1564 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/07/05 08:12:02.0578 1564 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/07/05 08:12:03.0093 1564 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/07/05 08:12:03.0796 1564 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/07/05 08:12:04.0562 1564 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/07/05 08:12:05.0296 1564 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/07/05 08:12:05.0921 1564 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/07/05 08:12:06.0750 1564 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/07/05 08:12:07.0578 1564 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/07/05 08:12:08.0359 1564 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/07/05 08:12:08.0921 1564 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/07/05 08:12:09.0625 1564 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/07/05 08:12:10.0343 1564 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/07/05 08:12:10.0937 1564 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2011/07/05 08:12:11.0656 1564 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/07/05 08:12:12.0359 1564 SI3132 (716a724a447c559f122ea140d636fa48) C:\WINDOWS\system32\DRIVERS\SI3132.sys
2011/07/05 08:12:12.0937 1564 SiFilter (72cf151fb410e544904dbc7d7f29b796) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
2011/07/05 08:12:14.0062 1564 SiRemFil (62fd549acf2943f89612a8777295fa57) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys
2011/07/05 08:12:14.0734 1564 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/07/05 08:12:15.0437 1564 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\Drivers\SonyNC.sys
2011/07/05 08:12:15.0968 1564 SonyImgF (b98be9c307a7f6695203a294276f9cd8) C:\WINDOWS\system32\DRIVERS\SonyImgF.sys
2011/07/05 08:12:17.0093 1564 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/07/05 08:12:17.0671 1564 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/07/05 08:12:18.0437 1564 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/07/05 08:12:19.0171 1564 sscdbus (2d4027c46b4c6e45875e3c4ba3f67492) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
2011/07/05 08:12:19.0718 1564 sscdmdfl (f548f1eba107bc19e91189e6a460bd0e) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
2011/07/05 08:12:20.0343 1564 sscdmdm (71d348d53597379dfe1de255d70af13c) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
2011/07/05 08:12:20.0906 1564 ssmdrv (71d609c5dff067906d930bde031c4cfe) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/07/05 08:12:21.0406 1564 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2011/07/05 08:12:22.0468 1564 STHDA (bbbc5bf9a5f1fb5d57e91b944d2e51a5) C:\WINDOWS\system32\drivers\sthda.sys
2011/07/05 08:12:23.0593 1564 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/07/05 08:12:24.0125 1564 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/07/05 08:12:24.0640 1564 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/07/05 08:12:27.0000 1564 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/07/05 08:12:27.0718 1564 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/07/05 08:12:28.0421 1564 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/07/05 08:12:28.0937 1564 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/07/05 08:12:29.0437 1564 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/07/05 08:12:30.0406 1564 ti21sony (3106074a87bd5a16e2a3af6902bb6d91) C:\WINDOWS\system32\drivers\ti21sony.sys
2011/07/05 08:12:31.0312 1564 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/07/05 08:12:32.0296 1564 tosporte (6a404454c6133e749be33892eb6ffa35) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/07/05 08:12:32.0859 1564 Tosrfbd (e4901804c4d8d613fa3560de2c2e0261) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/07/05 08:12:33.0406 1564 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/07/05 08:12:33.0953 1564 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/07/05 08:12:34.0546 1564 Tosrfhid (7726332391d8fca1a491a17f592fd6b3) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/07/05 08:12:35.0046 1564 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/07/05 08:12:35.0593 1564 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/07/05 08:12:36.0093 1564 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/07/05 08:12:36.0718 1564 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/07/05 08:12:37.0984 1564 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/07/05 08:12:38.0765 1564 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/07/05 08:12:39.0375 1564 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/07/05 08:12:39.0906 1564 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/07/05 08:12:40.0437 1564 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/07/05 08:12:41.0000 1564 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/07/05 08:12:41.0468 1564 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/07/05 08:12:41.0968 1564 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/07/05 08:12:42.0484 1564 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/07/05 08:12:43.0171 1564 usbvm321 (f9d550545afec1d581d2539f3488c4cd) C:\WINDOWS\system32\Drivers\usbvm321.sys
2011/07/05 08:12:43.0921 1564 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/07/05 08:12:44.0906 1564 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/07/05 08:12:46.0109 1564 w39n51 (73395a19fc86461a151d3c330604e8b3) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/07/05 08:12:47.0359 1564 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/07/05 08:12:48.0765 1564 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/07/05 08:12:49.0687 1564 winachsf (c1d5cbd8aa0d674da1ba1bb189696396) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/07/05 08:12:50.0625 1564 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/07/05 08:12:51.0187 1564 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/07/05 08:12:51.0703 1564 WSIMD (43f767d59bfc25d8f4fc2eb42043ec1e) C:\WINDOWS\system32\DRIVERS\wsimd.sys
2011/07/05 08:12:52.0234 1564 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/07/05 08:12:52.0812 1564 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/07/05 08:12:53.0359 1564 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/07/05 08:12:53.0515 1564 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
2011/07/05 08:12:53.0906 1564 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR4
2011/07/05 08:12:53.0921 1564 Boot (0x1200) (12803ab533efbaa260f979d134669071) \Device\Harddisk0\DR0\Partition0
2011/07/05 08:12:53.0953 1564 Boot (0x1200) (eb142777c4f384232b133eee9aadf225) \Device\Harddisk0\DR0\Partition1
2011/07/05 08:12:53.0953 1564 ================================================================================
2011/07/05 08:12:53.0953 1564 Scan finished
2011/07/05 08:12:53.0953 1564 ================================================================================
2011/07/05 08:12:53.0953 1556 Detected object count: 0
2011/07/05 08:12:53.0953 1556 Actual detected object count: 0

Zitat:
2011/07/06 08:07:32.0140 3408 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
2011/07/06 08:07:33.0984 3408 ================================================================================
2011/07/06 08:07:33.0984 3408 SystemInfo:
2011/07/06 08:07:33.0984 3408
2011/07/06 08:07:33.0984 3408 OS Version: 5.1.2600 ServicePack: 3.0
2011/07/06 08:07:33.0984 3408 Product type: Workstation
2011/07/06 08:07:33.0984 3408 ComputerName: MAID
2011/07/06 08:07:33.0984 3408 UserName: Marian Kasprowski
2011/07/06 08:07:33.0984 3408 Windows directory: C:\WINDOWS
2011/07/06 08:07:33.0984 3408 System windows directory: C:\WINDOWS
2011/07/06 08:07:33.0984 3408 Processor architecture: Intel x86
2011/07/06 08:07:33.0984 3408 Number of processors: 2
2011/07/06 08:07:33.0984 3408 Page size: 0x1000
2011/07/06 08:07:33.0984 3408 Boot type: Normal boot
2011/07/06 08:07:33.0984 3408 ================================================================================
2011/07/06 08:08:01.0890 3408 Initialize success
2011/07/06 08:08:10.0343 2820 ================================================================================
2011/07/06 08:08:10.0343 2820 Scan started
2011/07/06 08:08:10.0343 2820 Mode: Manual;
2011/07/06 08:08:10.0343 2820 ================================================================================
2011/07/06 08:08:10.0781 2820 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/07/06 08:08:10.0843 2820 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/07/06 08:08:10.0953 2820 acwgrdrh (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\vlixpuhr.sys
2011/07/06 08:08:11.0078 2820 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/07/06 08:08:11.0265 2820 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/07/06 08:08:11.0375 2820 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/07/06 08:08:11.0812 2820 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2011/07/06 08:08:11.0953 2820 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/07/06 08:08:12.0093 2820 arusb(TP-LINK) (d8aa72b3760402b4a30925d9778e4688) C:\WINDOWS\system32\DRIVERS\arusb.sys
2011/07/06 08:08:12.0437 2820 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/07/06 08:08:12.0593 2820 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/07/06 08:08:12.0687 2820 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/07/06 08:08:12.0812 2820 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/07/06 08:08:12.0937 2820 avgio (87828ecd657f81503465ac705e845076) C:\Programme\AntiVir PersonalEdition Classic\avgio.sys
2011/07/06 08:08:13.0000 2820 avgntflt (fcb30820bed1d3feb55e3dd55a3f947f) C:\Programme\AntiVir PersonalEdition Classic\avgntflt.sys
2011/07/06 08:08:13.0109 2820 avipbb (0b09df022250fb7ba91fb932eac6ea9b) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/07/06 08:08:13.0234 2820 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/07/06 08:08:13.0343 2820 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/07/06 08:08:13.0437 2820 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/07/06 08:08:13.0546 2820 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/07/06 08:08:13.0671 2820 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/07/06 08:08:13.0718 2820 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/07/06 08:08:13.0859 2820 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/07/06 08:08:13.0921 2820 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/07/06 08:08:14.0000 2820 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
2011/07/06 08:08:14.0109 2820 CVPNDRVA (18994842386fd3039279d7865740abbd) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
2011/07/06 08:08:14.0343 2820 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/07/06 08:08:14.0406 2820 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2011/07/06 08:08:14.0625 2820 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys
2011/07/06 08:08:14.0718 2820 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2011/07/06 08:08:14.0875 2820 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/07/06 08:08:14.0984 2820 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/07/06 08:08:15.0109 2820 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/07/06 08:08:15.0250 2820 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/07/06 08:08:15.0328 2820 E100B (5c940a174dfb2c42b9f6ba6edc2baa0b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/07/06 08:08:15.0453 2820 e1express (389cf2cded384be477c3b3f15747d495) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
2011/07/06 08:08:15.0609 2820 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/07/06 08:08:15.0703 2820 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/07/06 08:08:15.0750 2820 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2011/07/06 08:08:15.0828 2820 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/07/06 08:08:15.0921 2820 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/07/06 08:08:16.0015 2820 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2011/07/06 08:08:16.0093 2820 FsVga (1f943241f4963cd51e5f61c93d3f45c7) C:\WINDOWS\system32\DRIVERS\fsvga.sys
2011/07/06 08:08:16.0203 2820 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/07/06 08:08:16.0296 2820 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/07/06 08:08:16.0390 2820 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2011/07/06 08:08:16.0484 2820 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/07/06 08:08:16.0640 2820 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/07/06 08:08:16.0765 2820 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/07/06 08:08:16.0796 2820 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/07/06 08:08:16.0968 2820 HSFHWAZL (acc46dda7fece95a253ae88cea172e12) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/07/06 08:08:17.0093 2820 HSF_DPV (c9f4e7da78a02623abf78a4a34ce79b1) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/07/06 08:08:17.0343 2820 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/07/06 08:08:17.0500 2820 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/07/06 08:08:17.0578 2820 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/07/06 08:08:17.0796 2820 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/07/06 08:08:17.0906 2820 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/07/06 08:08:18.0000 2820 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/07/06 08:08:18.0125 2820 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/07/06 08:08:18.0187 2820 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/07/06 08:08:18.0265 2820 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/07/06 08:08:18.0359 2820 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/07/06 08:08:18.0515 2820 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/07/06 08:08:18.0562 2820 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/07/06 08:08:18.0625 2820 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/07/06 08:08:18.0687 2820 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/07/06 08:08:18.0812 2820 MBAMProtector (3d2c13377763eeac0ca6fb46f57217ed) C:\WINDOWS\system32\drivers\mbam.sys
2011/07/06 08:08:18.0859 2820 MBAMSwissArmy (b309912717c29fc67e1ba4730a82b6dd) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011/07/06 08:08:18.0953 2820 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/07/06 08:08:19.0062 2820 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2011/07/06 08:08:19.0265 2820 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/07/06 08:08:19.0343 2820 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2011/07/06 08:08:19.0437 2820 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/07/06 08:08:19.0515 2820 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/07/06 08:08:19.0593 2820 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/07/06 08:08:19.0640 2820 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/07/06 08:08:19.0703 2820 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/07/06 08:08:19.0812 2820 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/07/06 08:08:19.0859 2820 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/07/06 08:08:19.0937 2820 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/07/06 08:08:20.0031 2820 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/07/06 08:08:20.0093 2820 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/07/06 08:08:20.0203 2820 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/07/06 08:08:20.0281 2820 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/07/06 08:08:20.0421 2820 MXOPSWD (c29f284ff7ab4ed38ce419a9424e52a2) C:\WINDOWS\system32\DRIVERS\mxopswd.sys
2011/07/06 08:08:20.0484 2820 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/07/06 08:08:20.0609 2820 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/07/06 08:08:20.0687 2820 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/07/06 08:08:20.0750 2820 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/07/06 08:08:20.0812 2820 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/07/06 08:08:20.0937 2820 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/07/06 08:08:21.0015 2820 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/07/06 08:08:21.0125 2820 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/07/06 08:08:21.0265 2820 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/07/06 08:08:21.0421 2820 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/07/06 08:08:21.0515 2820 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/07/06 08:08:21.0578 2820 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/07/06 08:08:21.0656 2820 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/07/06 08:08:21.0921 2820 nv (24f48f02fa8d9efda3425440f9814057) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/07/06 08:08:22.0250 2820 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/07/06 08:08:22.0328 2820 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/07/06 08:08:22.0406 2820 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
2011/07/06 08:08:22.0468 2820 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
2011/07/06 08:08:22.0546 2820 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
2011/07/06 08:08:22.0625 2820 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/07/06 08:08:22.0687 2820 PalmUSBD (240c0d4049a833b16b63b636acf01672) C:\WINDOWS\system32\drivers\PalmUSBD.sys
2011/07/06 08:08:22.0796 2820 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2011/07/06 08:08:22.0890 2820 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/07/06 08:08:22.0937 2820 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/07/06 08:08:22.0984 2820 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/07/06 08:08:23.0078 2820 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/07/06 08:08:23.0156 2820 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/07/06 08:08:23.0375 2820 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/07/06 08:08:23.0437 2820 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/07/06 08:08:23.0578 2820 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/07/06 08:08:23.0703 2820 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/07/06 08:08:23.0875 2820 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/07/06 08:08:23.0953 2820 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/07/06 08:08:24.0031 2820 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/07/06 08:08:24.0125 2820 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/07/06 08:08:24.0250 2820 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/07/06 08:08:24.0390 2820 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/07/06 08:08:24.0531 2820 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/07/06 08:08:24.0656 2820 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/07/06 08:08:24.0765 2820 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/07/06 08:08:24.0906 2820 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/07/06 08:08:25.0031 2820 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/07/06 08:08:25.0125 2820 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/07/06 08:08:25.0234 2820 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2011/07/06 08:08:25.0328 2820 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/07/06 08:08:25.0453 2820 SI3132 (716a724a447c559f122ea140d636fa48) C:\WINDOWS\system32\DRIVERS\SI3132.sys
2011/07/06 08:08:25.0484 2820 SiFilter (72cf151fb410e544904dbc7d7f29b796) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
2011/07/06 08:08:25.0546 2820 SiRemFil (62fd549acf2943f89612a8777295fa57) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys
2011/07/06 08:08:25.0578 2820 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/07/06 08:08:25.0718 2820 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\Drivers\SonyNC.sys
2011/07/06 08:08:25.0796 2820 SonyImgF (b98be9c307a7f6695203a294276f9cd8) C:\WINDOWS\system32\DRIVERS\SonyImgF.sys
2011/07/06 08:08:25.0921 2820 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/07/06 08:08:26.0031 2820 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/07/06 08:08:26.0281 2820 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/07/06 08:08:26.0406 2820 sscdbus (2d4027c46b4c6e45875e3c4ba3f67492) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
2011/07/06 08:08:26.0484 2820 sscdmdfl (f548f1eba107bc19e91189e6a460bd0e) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
2011/07/06 08:08:26.0578 2820 sscdmdm (71d348d53597379dfe1de255d70af13c) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
2011/07/06 08:08:26.0687 2820 ssmdrv (71d609c5dff067906d930bde031c4cfe) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/07/06 08:08:26.0859 2820 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2011/07/06 08:08:27.0031 2820 STHDA (bbbc5bf9a5f1fb5d57e91b944d2e51a5) C:\WINDOWS\system32\drivers\sthda.sys
2011/07/06 08:08:27.0234 2820 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/07/06 08:08:27.0343 2820 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/07/06 08:08:27.0468 2820 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/07/06 08:08:27.0765 2820 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/07/06 08:08:27.0921 2820 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/07/06 08:08:28.0078 2820 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/07/06 08:08:28.0171 2820 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/07/06 08:08:28.0281 2820 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/07/06 08:08:28.0437 2820 ti21sony (3106074a87bd5a16e2a3af6902bb6d91) C:\WINDOWS\system32\drivers\ti21sony.sys
2011/07/06 08:08:28.0531 2820 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/07/06 08:08:28.0687 2820 tosporte (6a404454c6133e749be33892eb6ffa35) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/07/06 08:08:28.0750 2820 Tosrfbd (e4901804c4d8d613fa3560de2c2e0261) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/07/06 08:08:28.0812 2820 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/07/06 08:08:28.0875 2820 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/07/06 08:08:28.0953 2820 Tosrfhid (7726332391d8fca1a491a17f592fd6b3) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/07/06 08:08:29.0015 2820 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/07/06 08:08:29.0140 2820 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/07/06 08:08:29.0265 2820 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/07/06 08:08:29.0406 2820 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/07/06 08:08:29.0593 2820 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/07/06 08:08:29.0734 2820 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/07/06 08:08:29.0875 2820 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/07/06 08:08:29.0953 2820 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/07/06 08:08:30.0062 2820 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/07/06 08:08:30.0156 2820 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/07/06 08:08:30.0250 2820 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/07/06 08:08:30.0328 2820 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/07/06 08:08:30.0390 2820 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/07/06 08:08:30.0453 2820 usbvm321 (f9d550545afec1d581d2539f3488c4cd) C:\WINDOWS\system32\Drivers\usbvm321.sys
2011/07/06 08:08:30.0671 2820 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/07/06 08:08:30.0906 2820 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/07/06 08:08:31.0046 2820 w39n51 (73395a19fc86461a151d3c330604e8b3) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/07/06 08:08:31.0359 2820 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/07/06 08:08:31.0562 2820 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/07/06 08:08:31.0734 2820 winachsf (c1d5cbd8aa0d674da1ba1bb189696396) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/07/06 08:08:32.0078 2820 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/07/06 08:08:32.0234 2820 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/07/06 08:08:32.0343 2820 WSIMD (43f767d59bfc25d8f4fc2eb42043ec1e) C:\WINDOWS\system32\DRIVERS\wsimd.sys
2011/07/06 08:08:32.0421 2820 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/07/06 08:08:32.0593 2820 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/07/06 08:08:32.0687 2820 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/07/06 08:08:32.0812 2820 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
2011/07/06 08:08:33.0046 2820 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR6
2011/07/06 08:08:33.0062 2820 MBR (0x1B8) (ddae9d649db12f6aff24483f2c298989) \Device\Harddisk4\DR10
2011/07/06 08:08:33.0093 2820 Boot (0x1200) (12803ab533efbaa260f979d134669071) \Device\Harddisk0\DR0\Partition0
2011/07/06 08:08:33.0140 2820 Boot (0x1200) (eb142777c4f384232b133eee9aadf225) \Device\Harddisk0\DR0\Partition1
2011/07/06 08:08:33.0156 2820 Boot (0x1200) (9a35b70b786cb52b35b28a2f1e3923ac) \Device\Harddisk4\DR10\Partition0
2011/07/06 08:08:33.0156 2820 ================================================================================
2011/07/06 08:08:33.0156 2820 Scan finished
2011/07/06 08:08:33.0156 2820 ================================================================================
2011/07/06 08:08:33.0171 1140 Detected object count: 0
2011/07/06 08:08:33.0171 1140 Actual detected object count: 0
2011/07/06 16:50:40.0000 0956 Deinitialize success

Das sind alle Protokolle die ich habe.

Alt 07.07.2011, 21:35   #9
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 08.07.2011, 08:10   #10
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Combofix log
Combofix Logfile:
Code:
ATTFilter
ComboFix 11-07-07.05 - Marian Kasprowski 08.07.2011   1:15.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.1022.537 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\Marian Kasprowski\Desktop\ComboFix.exe
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {846DB3F4-FFA4-00EF-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {86212634-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {8623ADDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {86262C1C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Outdated* {00000000-0000-0000-0000-000000000000}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84105154-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84746654-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {847545DC-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84780054-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84892B6C-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8494DDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84972BCC-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {849D0054-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {857AF93C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {857D0DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {85858DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {85894054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {85E997DC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86188B1C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8618EDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861C3054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861CE3A4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861DC7CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861EACAC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861F63FC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861F8224-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8620CDB4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86225DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86229364-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8622C7F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8622CDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86230694-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86233514-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8623B81C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8623DC64-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862413BC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8624298C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86242DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86250DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862522CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86257DB4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86259264-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8625A98C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626360C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626493C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626A3CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862743CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8627577C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86275964-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86275A5C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8627D4EC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8627DDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628193C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628B65C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628E4C4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86291824-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86291A84-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86293054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8629598C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86297DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8629E58C-FFA4-00EF-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862A2C74-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862A54FC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862A553C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862AEDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862AFDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862B0DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862B25D4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862B7DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862C03A4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862C198C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862C468C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862CA34C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862CE60C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862D1BA4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862D7634-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862DEC44-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862E5824-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EAC44-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EC4EC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EC8EC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EE964-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862F53CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862F99DC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862FB58C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862FD96C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863016DC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86309534-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86309964-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863131B4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863135AC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86316A5C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86317594-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863177F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86319594-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631A9BC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631CDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631E674-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632044C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632168C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863293EC-FFA4-00EF-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86329624-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86329824-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632EDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632F754-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863396AC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8633A594-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8633E464-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86340DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8634458C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8634F66C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8634FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8635FB5C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86368DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8636988C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86376DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8637BDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86386DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86388DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86399C4C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8639CB64-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8639CC54-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863A7614-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863A7DAC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863AFA3C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863B0DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863B2054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863B3DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C3B64-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C59F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C68BC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C6DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863D75C4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863DB32C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863F1DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86405DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86406B2C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86414054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8641E95C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8641F2F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8641F614-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8642181C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864233A4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8642693C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864534AC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8645538C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8645F054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864F485C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864F76C4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865BB2E4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865C4AB4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865CE744-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865D258C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865D5A2C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865DC4B4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {BADB0D00-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {F78A2540-FFA4-00DE-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tiger Install
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tiger Install\{EBD1D465-0DD2-4F71-A4A1-16B219FF4252}
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tiger Install\{EBD1D465-0DD2-4F71-A4A1-16B219FF4252}.Dat
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\1.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\a.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\b.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\c.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\d.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\e.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\f.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\g.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\h.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\i.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\J.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\k.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\l.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\m.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\mru.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\n.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\o.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\p.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\q.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\r.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\s.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\t.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\u.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\v.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\w.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\x.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\y.xml
c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\PriceGong\Data\z.xml
c:\dokumente und einstellungen\Marian Kasprowski\Desktop\Windows XP Repair.lnk
c:\dokumente und einstellungen\Marian Kasprowski\Eigene Dateien\explorer.exe
c:\dokumente und einstellungen\Marian Kasprowski\Startmenü\Programme\Windows XP Repair
c:\dokumente und einstellungen\Marian Kasprowski\Startmenü\Programme\Windows XP Repair\Uninstall Windows XP Repair.lnk
c:\dokumente und einstellungen\Marian Kasprowski\Startmenü\Programme\Windows XP Repair\Windows XP Repair.lnk
c:\dokumente und einstellungen\Marian Kasprowski\WINDOWS
c:\programme\Internet Explorer\SET13D.tmp
c:\programme\Internet Explorer\SET142.tmp
c:\windows\IsUn0407.exe
J:\eXplorer.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-06-07 bis 2011-07-07  ))))))))))))))))))))))))))))))
.
.
2074-05-18 09:44 . 2008-03-21 06:46	607296	---ha-w-	c:\programme\Microsoft Games\Age of Empires III\deformerdllyD.dll
2011-07-07 23:37 . 2011-07-07 23:37	--------	d-sh--w-	c:\dokumente und einstellungen\LocalService\IETldCache
2011-07-07 23:36 . 2011-07-07 23:36	--------	d-sh--w-	c:\dokumente und einstellungen\Marian Kasprowski\IETldCache
2011-07-06 20:03 . 2011-07-06 20:06	--------	dc-h--w-	c:\windows\ie8
2011-07-06 19:57 . 2010-10-18 11:10	7680	-c----w-	c:\windows\system32\dllcache\iecompat.dll
2011-07-06 19:57 . 2011-04-25 16:05	602112	-c----w-	c:\windows\system32\dllcache\msfeeds.dll
2011-07-06 19:57 . 2011-04-25 16:05	55296	-c----w-	c:\windows\system32\dllcache\msfeedsbs.dll
2011-07-06 19:56 . 2011-04-25 16:05	12800	-c----w-	c:\windows\system32\dllcache\xpshims.dll
2011-07-06 19:56 . 2011-04-25 16:05	247808	-c----w-	c:\windows\system32\dllcache\ieproxy.dll
2011-07-06 19:56 . 2011-04-25 16:05	743424	-c----w-	c:\windows\system32\dllcache\iedvtool.dll
2011-07-06 19:56 . 2011-04-25 16:05	1991680	-c----w-	c:\windows\system32\dllcache\iertutil.dll
2011-07-06 19:56 . 2011-04-26 08:05	11081728	-c----w-	c:\windows\system32\dllcache\ieframe.dll
2011-07-05 20:38 . 2011-07-05 20:38	711728	---ha-w-	c:\windows\is-43G4D.exe
2011-07-04 22:43 . 2011-07-04 22:43	--------	d--h--w-	c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Mozilla
2011-07-04 22:31 . 2011-07-04 22:32	--------	d--h--w-	c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Adobe
2011-07-04 22:31 . 2011-07-04 22:31	--------	d--h--w-	c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Apple Computer
2011-07-04 20:19 . 2011-07-04 20:19	--------	d--h--w-	c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\Malwarebytes
2011-07-04 20:03 . 2011-07-04 20:03	--------	d-----w-	C:\TDSSKiller_Quarantine
2011-07-04 19:56 . 2011-07-04 22:43	--------	d--h--w-	c:\dokumente und einstellungen\Administrator\Anwendungsdaten
2011-07-04 17:21 . 2011-07-04 17:21	--------	d-----w-	C:\Malwarebytes
2011-07-04 17:20 . 2011-05-29 07:11	39984	---ha-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-04 17:20 . 2011-07-04 17:20	--------	d--h--w-	c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2011-07-04 17:20 . 2011-07-04 20:45	--------	d--h--w-	c:\programme\Malwarebytes' Anti-Malware
2011-07-04 17:20 . 2011-05-29 07:11	22712	---ha-w-	c:\windows\system32\drivers\mbam.sys
2011-07-04 17:18 . 2011-07-04 19:55	--------	d--h--r-	c:\dokumente und einstellungen\Administrator\Eigene Dateien
2011-07-04 17:13 . 2011-07-04 17:13	--------	d--h--r-	c:\dokumente und einstellungen\Administrator\Favoriten
2011-06-19 20:29 . 2011-04-21 13:37	105472	-c-h--w-	c:\windows\system32\dllcache\mup.sys
2011-06-19 20:29 . 2009-03-08 02:33	759296	-c-ha-w-	c:\windows\system32\dllcache\VGX.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-05 20:38 . 2011-07-05 20:38	711728	---ha-w-	c:\windows\isRS-000.tmp
2011-07-03 23:20 . 2006-08-13 17:26	96384	---ha-w-	c:\windows\system32\drivers\sptd5677.sys
2011-05-02 15:31 . 2005-12-12 16:37	692736	---ha-w-	c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2005-12-12 08:23	151552	---ha-w-	c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2005-12-12 08:22	456320	---h--w-	c:\windows\system32\drivers\mrxsmb.sys
2011-04-29 15:36 . 2010-11-27 21:39	0	---ha-w-	c:\windows\system32\ConduitEngine.tmp
2011-04-25 16:05 . 2005-12-12 08:23	916480	----a-w-	c:\windows\system32\wininet.dll
2011-04-25 16:05 . 2005-12-12 08:22	43520	------w-	c:\windows\system32\licmgr10.dll
2011-04-25 16:05 . 2005-12-12 08:22	1469440	------w-	c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2005-12-12 08:22	385024	------w-	c:\windows\system32\html.iec
2011-04-21 13:37 . 2005-12-12 08:23	105472	---h--w-	c:\windows\system32\drivers\mup.sys
2007-07-03 14:31 . 2007-01-23 20:51	319	---ha-w-	c:\programme\drmHeader.bin
2007-08-03 20:23 . 2007-07-03 14:01	135680	---ha-w-	c:\programme\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programme\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\programme\mipony-plugin\prxtbmip2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54	175912	---ha-w-	c:\programme\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
2011-01-17 14:54	175912	---ha-w-	c:\programme\mipony-plugin\prxtbmip2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 14:54	175912	---ha-w-	c:\programme\Vuze_Remote\prxtbVuz0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programme\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\programme\mipony-plugin\prxtbmip2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\programme\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6EDCCE69-14A2-4E9F-826B-DC523B82167E}"= "c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll" [2007-02-02 591360]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\programme\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{90D46C30-9F25-4104-AEA9-35C3F84477FF}"= "c:\programme\mipony-plugin\prxtbmip2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{6edcce69-14a2-4e9f-826b-dc523b82167e}]
[HKEY_CLASSES_ROOT\IexploreOmea.Band.1]
[HKEY_CLASSES_ROOT\TypeLib\{633820F7-C04E-4152-B64F-1147B881F998}]
[HKEY_CLASSES_ROOT\IexploreOmea.Band]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-13 68856]
"SpybotSD TeaTimer"="c:\programme\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PPS Accelerator"="c:\programme\PPStream\ppsap.exe" [2009-07-22 210312]
"googletalk"="c:\programme\Google\Google Talk\googletalk.exe" [2007-11-21 3293184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-15 7331840]
"Apoint"="c:\programme\Apoint\Apoint.exe" [2004-11-17 118784]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 45056]
"SonyPowerCfg"="c:\programme\Sony\VAIO Power Management\SPMgr.exe" [2005-11-28 217088]
"ISBMgr.exe"="c:\programme\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"VAIOCameraUtility"="c:\programme\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-09-27 81920]
"avgnt"="c:\programme\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"TkBellExe"="c:\programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2007-03-14 185896]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"VAIO Update 4"="c:\programme\Sony\VAIO Update 4\VAIOUpdt.exe" [2008-08-24 870240]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"TWCU"="c:\programme\TP-LINK\TL-WN821N\TWCU.exe" [2008-10-20 557186]
"PDFPrint"="c:\programme\pdf24\pdf24.exe" [2011-04-08 220552]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"LogMeIn Hamachi Ui"="c:\programme\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-03-28 1910152]
"Malwarebytes' Anti-Malware"="c:\programme\Malwarebytes' Anti-Malwaren\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"MySpaceIM"="c:\programme\MySpace\IM\MySpaceIM.exe" [2007-01-12 4898816]
.
c:\dokumente und einstellungen\Marian Kasprowski\Startmen\Programme\Autostart\
ERUNT AutoBackup.lnk - c:\programme\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Microsoft Office OneNote 2003 Schnellstart.lnk - c:\programme\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 64864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Taskman"=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 16:42	73728	---ha-w-	c:\windows\system32\VESWinlogon.dll
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^HOTSYNCSHORTCUTNAME.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^InterVideo WinCinema Manager.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Quicken 2006 Zahlungserinnerung.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Quicken 2006 Zahlungserinnerung.lnk
backup=c:\windows\pss\Quicken 2006 Zahlungserinnerung.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^Marian Kasprowski^Startmenü^Programme^Autostart^Kremlin Sentry.LNK]
path=c:\dokumente und einstellungen\Marian Kasprowski\Startmenü\Programme\Autostart\Kremlin Sentry.LNK
backup=c:\windows\pss\Kremlin Sentry.LNKStartup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^Marian Kasprowski^Startmenü^Programme^Autostart^Yahoo! Widget Engine.lnk]
path=c:\dokumente und einstellungen\Marian Kasprowski\Startmenü\Programme\Autostart\Yahoo! Widget Engine.lnk
backup=c:\windows\pss\Yahoo! Widget Engine.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50	155648	---ha-w-	c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 14:16	421888	---ha-w-	c:\programme\QuickTime\QTTask.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Programme\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Programme\\ICQLite\\ICQLite.exe"=
"c:\\Programme\\Miranda IM\\miranda32.exe"=
"c:\\Programme\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Dokumente und Einstellungen\\Marian Kasprowski\\Eigene Dateien\\Downloads\\ppstreamsetup.exe"=
"c:\\Programme\\PPStream\\PPStream.exe"=
"c:\\Programme\\PPStream\\PPSAP.exe"=
"c:\\Programme\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"c:\\Programme\\Google\\Google Talk\\googletalk.exe"=
"c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programme\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
.
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\programme\LogMeIn Hamachi\hamachi-2.exe [28.03.2011 15:41 1242504]
R2 MBAMService;MBAMService;c:\programme\Malwarebytes' Anti-Malwaren\mbamservice.exe [04.07.2011 22:46 366640]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R2 wwEngineSvc;Window Washer Engine;c:\programme\Webroot\Washer\WasherSvc.exe [17.10.2007 17:41 598856]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [04.07.2011 19:20 22712]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [12.12.2005 10:24 28800]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [12.12.2005 10:24 808448]
S2 gupdate;Google Update Service (gupdate);c:\programme\Google\Update\GoogleUpdate.exe [12.07.2010 14:34 135664]
S3 arusb(TP-LINK);Atheros Wireless Network Adapter Service(TP-LINK);c:\windows\system32\drivers\arusb.sys [15.09.2010 15:47 458240]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\programme\Google\Update\GoogleUpdate.exe [12.07.2010 14:34 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [04.07.2011 19:20 39984]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys --> c:\windows\system32\DRIVERS\wdcsam.sys [?]
S4 ASKService;ASKService;c:\programme\AskBarDis\bar\bin\AskService.exe [16.11.2008 06:15 460168]
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - IPFILTERDRIVER
.
Inhalt des "geplante Tasks" Ordners
.
2011-06-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-07-12 12:34]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-07-12 12:34]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.club-vaio.com/de/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Clip and Edit - c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll/1000
IE: Clip and Save - c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll/1001
IE: Download all with Free Download Manager - file://c:\programme\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\programme\Free Download Manager\dlselected.htm
IE: Download web site with Free Download Manager - file://c:\programme\Free Download Manager\dlpage.htm
IE: Download with &FileFactory Turbo - c:\programme\FileFactory Turbo\Plugins\IE\FileFactoryIE.html
IE: Download with Free Download Manager - file://c:\programme\Free Download Manager\dllink.htm
IE: Google Sidewiki... - c:\programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: Mit Mipony herunterladen - file://c:\programme\MiPony\Browser\IEContext.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Subscribe in Desktop Sidebar - c:\programme\Desktop Sidebar\sbhelp.dll/menuhandler.html
IE: Subscribe to Feed - c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll/1002
IE: ¨¹bertragen mit Image Converter 2 Plus
IE: Übertragen mit Image Converter 2 Plus - c:\programme\Sony\Image Converter 2\menu.htm
IE: ?ertragen mit Image Converter 2 Plus
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
TCP: DhcpNameServer = 192.168.1.130 192.168.1.10
Handler: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - c:\programme\Haufe\HaufeReader\HRInstmon.dll
FF - ProfilePath - c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\Mozilla\Firefox\Profiles\24drnrac.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.stratfor.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&q=
FF - Ext: NASA Night Launch: nasanightlaunch@example.com - %profile%\extensions\nasanightlaunch@example.com
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: OldFactory Black: {69D30031-F4A8-452a-A5B3-5D6787C3C5CF} - %profile%\extensions\{69D30031-F4A8-452a-A5B3-5D6787C3C5CF}
FF - Ext: Vuze Toolbar: {E9A1DEE0-C623-4439-8932-001E7D17607D} - %profile%\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Wild Pockets Loader: wildpocketsloader@simopsstudios.com - %profile%\extensions\wildpocketsloader@simopsstudios.com
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
FF - Ext: FireShot: {0b457cAA-602d-484a-8fe7-c1d894a011ba} - %profile%\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
FF - Ext: printpdf: printpdf@pavlov.net - %profile%\extensions\printpdf@pavlov.net
FF - Ext: mipony-plugin Community Toolbar: {90d46c30-9f25-4104-aea9-35c3f84477ff} - %profile%\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programme\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Veoh Browser Plug-in: videofinder@veoh.com - c:\programme\Veoh Networks\Veoh\Plugins\noreg\videofinder4
FF - Ext: FileFactory Turbo: {5b9fd6af-b36b-47d5-88fc-8398bab59411} - c:\programme\FileFactory Turbo\Plugins\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programme\Java\jre6\lib\deploy\jqs\ff
 
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\programme\AskBarDis\bar\bin\askBar.dll
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\programme\AskBarDis\bar\bin\askBar.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-Nonoh - c:\programme\Nonoh.net\Nonoh\Nonoh.exe
HKLM-Run-Acrobat Assistant 7.0 - c:\programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
HKLM-Run-UDC Integration - (no file)
HKLM-Run-RDesc - (no file)
SafeBoot-79780010.sys
SafeBoot-98327771.sys
MSConfigStartUp-Evidence Eliminator - c:\programme\Evidence Eliminator\ee.exe
AddRemove-Checklist_is1 - c:\program files\Papertrl\Checklist\unins000.exe
AddRemove-conduitEngine - c:\programme\ConduitEngine\ConduitEngineUninstall.exe
AddRemove-Half-Life - c:\sierra\Half-Life\Uninst.isu
AddRemove-HaufeReader - c:\windows\IsUn0407.exe
AddRemove-InterActual Player - c:\program files\InterActual\InterActual Player\inuninst.exe
AddRemove-QUICKEN - c:\windows\IsUn0407.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\UninstFl.exe
AddRemove-Sierra Utilities - c:\programme\Sierra On-Line\sutil32.exe
AddRemove-UnityWebPlayer - c:\dokumente und einstellungen\Marian Kasprowski\Lokale Einstellungen\Anwendungsdaten\Unity\WebPlayer\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-07-08 01:38
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
Scanne versteckte Dateien... 
.
.
c:\windows\isRS-000.tmp 711728 bytes executable
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1145596925-3625438031-3511041855-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2150B2E5-F6E4-CF96-5940-10E02899DFE3}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abkgnbbpipkgmnfiejmaclappdflpepngf"=hex:61,61,00,00
"bbkgnbbpipkgmnfiejhiplcppnoapmaamdoh"=hex:61,61,00,00
.
[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\E„;*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Anwendungsdaten\\Intel\\Wireless\\"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(1596)
c:\windows\system32\VESWinlogon.dll
.
- - - - - - - > 'explorer.exe'(2572)
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\programme\Intel\Wireless\Bin\EvtEng.exe
c:\programme\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\acs.exe
c:\programme\AntiVir PersonalEdition Classic\sched.exe
c:\programme\AntiVir PersonalEdition Classic\avguard.exe
c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programme\Bonjour\mDNSResponder.exe
c:\programme\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\programme\Intel\Wireless\Bin\RegSrvc.exe
c:\programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\programme\Sony\VAIO Event Service\VESMgr.exe
c:\programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\ICO.EXE
c:\programme\Apoint\Apntex.exe
c:\windows\eHome\ehmsas.exe
c:\programme\iPod\bin\iPodService.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-07-08  02:04:16 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-07-08 00:04
.
Vor Suchlauf: 1 Verzeichnis(se), 20.867.182.592 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 21.227.212.800 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=""
multi(0)disk(0)rdisk(0)partition(1)\Minint=""
.
- - End Of File - - 2CBD2F5ED1A378C427C36FA2FFE0B8D4
         
--- --- ---


zusätzliche Info: an einem Punkt hat Combofix meinen Computer neu gestartet, nach dem Neustart war Antivir wieder aktiv und als ich irgendwann zurückkam und die Logfile sah, war auch eine Warnmeldung von AntiVir Guard zu sehen, die aussagte: C:\System Volume Information\...\A0110256.exe
Ist das Trojanische Pferd TR/Trash.Gen

Diese Meldung hatte ich auch früher schon von AntiVir bekommen, doch egal ob man Zugriff verweigern, Löschen oder In Quarantäne verschieben wählt sie taucht immer wieder auf.

Alt 08.07.2011, 08:14   #11
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Nach der Anwendung von Combofix sind übrigens alle unsichtbaren Dateien wieder zu sehen?! Es bedarf also keiner zusätzlichen Anwendung mehr, Combofix hat alles wieder sichtbar gemacht.

Mein Notebook ist auch schneller als er in den letzten paar Jahren war.

Das wichtigste: WIndows Xp Repair scheint tatsächlich gebannt! Endlich.

Was kann ich jetzt noch machen um auch in Zukunft diesen und ähnlich gravierende Malware von Anfang an fernzuhalten?

Alt 08.07.2011, 15:57   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Wir sind noch nicht fertig!!



Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.


Code:
ATTFilter
File::
c:\windows\is-43G4D.exe
c:\windows\isRS-000.tmp
c:\windows\system32\ConduitEngine.tmp

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Taskman"=-

Regnull::
[HKEY_USERS\S-1-5-21-1145596925-3625438031-3511041855-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2150B2E5-F6E4-CF96-5940-10E02899DFE3}*]
         
3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.



6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 08.07.2011, 17:56   #13
fangshi
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Alles klar. Allerdings muss ich anmerken, dass ich nicht nach einem Neustart gefragt wurde. Nur am Anfang ob ich Combofix updaten will, was ich einfach mal bejaht habe.

Hier die Logfile:

Combofix Logfile:
Code:
ATTFilter
ComboFix 11-07-07.06 - Marian Kasprowski 08.07.2011  18:28:43.2.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.1022.337 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\Marian Kasprowski\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\dokumente und einstellungen\Marian Kasprowski\Desktop\CFScript.txt
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {846DB3F4-FFA4-00EF-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {86212634-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {8623ADDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Disabled/Updated* {86262C1C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Outdated* {00000000-0000-0000-0000-000000000000}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84105154-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84746654-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {847545DC-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84780054-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84892B6C-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8494DDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {84972BCC-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {849D0054-FFA4-00EE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {857AF93C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {857D0DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {85858DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {85894054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {85E997DC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86188B1C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8618EDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861C3054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861CE3A4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861DC7CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861EACAC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861F63FC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {861F8224-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8620CDB4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86225DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86229364-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8622C7F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8622CDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86230694-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86233514-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8623B81C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8623DC64-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862413BC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8624298C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86242DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86250DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862522CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86257DB4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86259264-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8625A98C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626360C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626493C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626A3CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8626FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862743CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8627577C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86275964-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86275A5C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8627D4EC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8627DDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628193C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628B65C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628E4C4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8628FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86291824-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86291A84-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86293054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8629598C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86297DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8629E58C-FFA4-00EF-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862A2C74-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862A54FC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862A553C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862AEDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862AFDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862B0DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862B25D4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862B7DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862C03A4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862C198C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862C468C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862CA34C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862CE60C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862D1BA4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862D7634-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862DEC44-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862E5824-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EAC44-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EC4EC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EC8EC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862EE964-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862F53CC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862F99DC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862FB58C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {862FD96C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863016DC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86309534-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86309964-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863131B4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863135AC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86316A5C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86317594-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863177F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86319594-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631A9BC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631CDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631E674-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8631FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632044C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632168C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863293EC-FFA4-00EF-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86329624-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86329824-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632EDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632F754-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8632FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863396AC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8633A594-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8633E464-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86340DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8634458C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8634F66C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8634FDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8635FB5C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86368DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8636988C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86376DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8637BDDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86386DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86388DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86399C4C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8639CB64-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8639CC54-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863A7614-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863A7DAC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863AFA3C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863B0DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863B2054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863B3DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C3B64-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C59F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C68BC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863C6DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863D75C4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863DB32C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {863F1DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86405DDC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86406B2C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {86414054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8641E95C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8641F2F4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8641F614-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8642181C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864233A4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8642693C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864534AC-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8645538C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {8645F054-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864F485C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {864F76C4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865BB2E4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865C4AB4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865CE744-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865D258C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865D5A2C-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {865DC4B4-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {BADB0D00-FFA4-00DE-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virenschutz *Enabled/Updated* {F78A2540-FFA4-00DE-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
FILE ::
"c:\windows\is-43G4D.exe"
"c:\windows\isRS-000.tmp"
"c:\windows\system32\ConduitEngine.tmp"
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\ConduitEngine.tmp
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-06-08 bis 2011-07-08  ))))))))))))))))))))))))))))))
.
.
2074-05-18 09:44 . 2008-03-21 06:46	607296	----a-w-	c:\programme\Microsoft Games\Age of Empires III\deformerdllyD.dll
2011-07-08 07:39 . 2011-07-08 07:42	--------	dc-h--w-	c:\windows\ie8
2011-07-07 23:37 . 2011-07-07 23:37	--------	d-sh--w-	c:\dokumente und einstellungen\LocalService\IETldCache
2011-07-07 23:36 . 2011-07-07 23:36	--------	d-sh--w-	c:\dokumente und einstellungen\Marian Kasprowski\IETldCache
2011-07-06 19:57 . 2010-10-18 11:10	7680	-c----w-	c:\windows\system32\dllcache\iecompat.dll
2011-07-06 19:57 . 2011-04-25 16:05	602112	-c----w-	c:\windows\system32\dllcache\msfeeds.dll
2011-07-06 19:57 . 2011-04-25 16:05	55296	-c----w-	c:\windows\system32\dllcache\msfeedsbs.dll
2011-07-06 19:56 . 2011-04-25 16:05	12800	-c----w-	c:\windows\system32\dllcache\xpshims.dll
2011-07-06 19:56 . 2011-04-25 16:05	247808	-c----w-	c:\windows\system32\dllcache\ieproxy.dll
2011-07-06 19:56 . 2011-04-25 16:05	743424	-c----w-	c:\windows\system32\dllcache\iedvtool.dll
2011-07-06 19:56 . 2011-04-25 16:05	1991680	-c----w-	c:\windows\system32\dllcache\iertutil.dll
2011-07-06 19:56 . 2011-04-26 08:05	11081728	-c----w-	c:\windows\system32\dllcache\ieframe.dll
2011-07-04 22:43 . 2011-07-04 22:43	--------	d-----w-	c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Mozilla
2011-07-04 22:31 . 2011-07-04 22:32	--------	d-----w-	c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Adobe
2011-07-04 22:31 . 2011-07-04 22:31	--------	d-----w-	c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Apple Computer
2011-07-04 20:19 . 2011-07-04 20:19	--------	d-----w-	c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\Malwarebytes
2011-07-04 20:03 . 2011-07-04 20:03	--------	d-----w-	C:\TDSSKiller_Quarantine
2011-07-04 19:56 . 2011-07-04 22:43	--------	d-----w-	c:\dokumente und einstellungen\Administrator\Anwendungsdaten
2011-07-04 17:21 . 2011-07-04 17:21	--------	d-----w-	C:\Malwarebytes
2011-07-04 17:20 . 2011-05-29 07:11	39984	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-04 17:20 . 2011-07-04 17:20	--------	d-----w-	c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2011-07-04 17:20 . 2011-07-04 20:45	--------	d-----w-	c:\programme\Malwarebytes' Anti-Malware
2011-07-04 17:20 . 2011-05-29 07:11	22712	----a-w-	c:\windows\system32\drivers\mbam.sys
2011-07-04 17:18 . 2011-07-04 19:55	--------	d-----r-	c:\dokumente und einstellungen\Administrator\Eigene Dateien
2011-07-04 17:13 . 2011-07-04 17:13	--------	d-----r-	c:\dokumente und einstellungen\Administrator\Favoriten
2011-06-19 20:29 . 2011-04-21 13:37	105472	-c----w-	c:\windows\system32\dllcache\mup.sys
2011-06-19 20:29 . 2009-03-08 02:33	759296	-c--a-w-	c:\windows\system32\dllcache\VGX.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-03 23:20 . 2006-08-13 17:26	96384	----a-w-	c:\windows\system32\drivers\sptd5677.sys
2011-05-02 15:31 . 2005-12-12 16:37	692736	----a-w-	c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2005-12-12 08:23	151552	----a-w-	c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2005-12-12 08:22	456320	------w-	c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:05 . 2005-12-12 08:23	916480	----a-w-	c:\windows\system32\wininet.dll
2011-04-25 16:05 . 2005-12-12 08:22	43520	------w-	c:\windows\system32\licmgr10.dll
2011-04-25 16:05 . 2005-12-12 08:22	1469440	------w-	c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2005-12-12 08:22	385024	------w-	c:\windows\system32\html.iec
2011-04-21 13:37 . 2005-12-12 08:23	105472	------w-	c:\windows\system32\drivers\mup.sys
2007-07-03 14:31 . 2007-01-23 20:51	319	----a-w-	c:\programme\drmHeader.bin
2007-08-03 20:23 . 2007-07-03 14:01	135680	----a-w-	c:\programme\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
(((((((((((((((((((((((((((((   SnapShot@2011-07-07_23.37.56   )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-07-08 07:54 . 2011-07-08 07:54	16384              c:\windows\Temp\Perflib_Perfdata_c64.dat
+ 2011-07-08 07:54 . 2011-07-08 07:54	16384              c:\windows\Temp\Perflib_Perfdata_45c.dat
+ 2011-07-08 15:33 . 2011-07-08 15:33	19968              c:\windows\Installer\1a4d8d7.msi
- 2011-07-06 20:09 . 2009-03-08 02:33	12288              c:\windows\ie8updates\KB982381-IE8\xpshims.dll
+ 2011-07-08 07:46 . 2009-03-08 02:33	12288              c:\windows\ie8updates\KB982381-IE8\xpshims.dll
+ 2011-07-08 07:46 . 2008-07-08 13:00	18808              c:\windows\ie8updates\KB982381-IE8\spmsg.dll
+ 2011-07-08 07:46 . 2008-07-08 13:00	26488              c:\windows\ie8updates\KB982381-IE8\spcustom.dll
- 2011-07-06 20:09 . 2009-03-08 02:31	55296              c:\windows\ie8updates\KB982381-IE8\msfeedsbs.dll
+ 2011-07-08 07:46 . 2009-03-08 02:31	55296              c:\windows\ie8updates\KB982381-IE8\msfeedsbs.dll
- 2011-07-06 20:09 . 2009-03-08 02:33	25600              c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
+ 2011-07-08 07:46 . 2009-03-08 02:33	25600              c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	12800              c:\windows\ie8updates\KB2530548-IE8\xpshims.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	12800              c:\windows\ie8updates\KB2530548-IE8\xpshims.dll
+ 2011-07-08 07:48 . 2010-07-05 13:14	18808              c:\windows\ie8updates\KB2530548-IE8\spmsg.dll
+ 2011-07-08 07:48 . 2010-07-05 13:14	26488              c:\windows\ie8updates\KB2530548-IE8\spcustom.dll
+ 2011-07-08 07:48 . 2009-03-08 02:31	66560              c:\windows\ie8updates\KB2530548-IE8\mshtmled.dll
- 2011-07-06 20:10 . 2009-03-08 02:31	66560              c:\windows\ie8updates\KB2530548-IE8\mshtmled.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	55296              c:\windows\ie8updates\KB2530548-IE8\msfeedsbs.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	55296              c:\windows\ie8updates\KB2530548-IE8\msfeedsbs.dll
- 2011-07-06 20:10 . 2009-03-08 02:34	43008              c:\windows\ie8updates\KB2530548-IE8\licmgr10.dll
+ 2011-07-08 07:48 . 2009-03-08 02:34	43008              c:\windows\ie8updates\KB2530548-IE8\licmgr10.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	25600              c:\windows\ie8updates\KB2530548-IE8\jsproxy.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	25600              c:\windows\ie8updates\KB2530548-IE8\jsproxy.dll
+ 2011-07-08 07:47 . 2010-02-22 14:22	18808              c:\windows\ie8updates\KB2447568-IE8\spmsg.dll
+ 2011-07-08 07:47 . 2010-02-22 14:22	26488              c:\windows\ie8updates\KB2447568-IE8\spcustom.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	37888              c:\windows\ie8\url.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	37888              c:\windows\ie8\url.dll
+ 2011-07-08 07:41 . 2009-03-08 17:18	58464              c:\windows\ie8\spuninst\iecustom.dll
- 2011-07-06 20:04 . 2009-03-08 17:18	58464              c:\windows\ie8\spuninst\iecustom.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	39424              c:\windows\ie8\pngfilt.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	39424              c:\windows\ie8\pngfilt.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	97792              c:\windows\ie8\occache.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	97792              c:\windows\ie8\occache.dll
- 2011-07-06 20:03 . 2008-04-14 01:52	57344              c:\windows\ie8\mshtmler.dll
+ 2011-07-08 07:40 . 2008-04-14 01:52	57344              c:\windows\ie8\mshtmler.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	29184              c:\windows\ie8\mshta.exe
+ 2011-07-08 07:40 . 2008-04-14 02:22	29184              c:\windows\ie8\mshta.exe
+ 2011-07-08 07:40 . 2008-04-14 02:22	22016              c:\windows\ie8\licmgr10.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	22016              c:\windows\ie8\licmgr10.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	15872              c:\windows\ie8\jsproxy.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	15872              c:\windows\ie8\jsproxy.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	96768              c:\windows\ie8\inseng.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	96768              c:\windows\ie8\inseng.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	35840              c:\windows\ie8\imgutil.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	35840              c:\windows\ie8\imgutil.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	93184              c:\windows\ie8\iexplore.exe
- 2011-07-06 20:03 . 2008-04-14 02:22	93184              c:\windows\ie8\iexplore.exe
- 2011-07-06 20:03 . 2008-04-14 02:22	64000              c:\windows\ie8\iesetup.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	64000              c:\windows\ie8\iesetup.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	49152              c:\windows\ie8\iernonce.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	49152              c:\windows\ie8\iernonce.dll
- 2011-07-06 20:03 . 2011-04-25 14:47	81920              c:\windows\ie8\ieencode.dll
+ 2011-07-08 07:39 . 2011-04-25 14:47	81920              c:\windows\ie8\ieencode.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	34304              c:\windows\ie8\ie4uinit.exe
- 2011-07-06 20:03 . 2008-04-14 02:22	34304              c:\windows\ie8\ie4uinit.exe
- 2011-07-06 20:03 . 2008-04-14 02:22	38912              c:\windows\ie8\hmmapi.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	38912              c:\windows\ie8\hmmapi.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	35328              c:\windows\ie8\corpol.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	35328              c:\windows\ie8\corpol.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	61440              c:\windows\ie8\admparse.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	61440              c:\windows\ie8\admparse.dll
- 2011-07-06 20:09 . 2009-03-08 02:35	2048              c:\windows\ie8updates\KB2447568-IE8\iecompat.dll
+ 2011-07-08 07:47 . 2009-03-08 02:35	2048              c:\windows\ie8updates\KB2447568-IE8\iecompat.dll
- 2011-07-06 20:09 . 2009-03-08 02:34	914944              c:\windows\ie8updates\KB982381-IE8\wininet.dll
+ 2011-07-08 07:46 . 2009-03-08 02:34	914944              c:\windows\ie8updates\KB982381-IE8\wininet.dll
+ 2011-07-08 07:46 . 2010-02-22 14:22	388984              c:\windows\ie8updates\KB982381-IE8\updspapi.dll
+ 2011-07-08 07:46 . 2009-05-26 11:40	765304              c:\windows\ie8updates\KB982381-IE8\update.exe
+ 2011-07-08 07:46 . 2010-02-22 14:22	388984              c:\windows\ie8updates\KB982381-IE8\spuninst\updspapi.dll
- 2011-07-06 20:09 . 2010-02-22 14:22	388984              c:\windows\ie8updates\KB982381-IE8\spuninst\updspapi.dll
- 2011-07-06 20:09 . 2008-07-08 13:00	234872              c:\windows\ie8updates\KB982381-IE8\spuninst\spuninst.exe
+ 2011-07-08 07:46 . 2008-07-08 13:00	234872              c:\windows\ie8updates\KB982381-IE8\spuninst\spuninst.exe
+ 2011-07-08 07:46 . 2008-07-08 13:00	234872              c:\windows\ie8updates\KB982381-IE8\spuninst.exe
+ 2011-07-08 07:46 . 2009-03-08 02:34	109568              c:\windows\ie8updates\KB982381-IE8\occache.dll
- 2011-07-06 20:09 . 2009-03-08 02:34	109568              c:\windows\ie8updates\KB982381-IE8\occache.dll
+ 2011-07-08 07:46 . 2009-03-08 02:32	611840              c:\windows\ie8updates\KB982381-IE8\mstime.dll
- 2011-07-06 20:09 . 2009-03-08 02:32	611840              c:\windows\ie8updates\KB982381-IE8\mstime.dll
+ 2011-07-08 07:46 . 2009-03-08 02:32	594432              c:\windows\ie8updates\KB982381-IE8\msfeeds.dll
- 2011-07-06 20:09 . 2009-03-08 02:32	594432              c:\windows\ie8updates\KB982381-IE8\msfeeds.dll
- 2011-07-06 20:09 . 2009-03-08 02:33	246784              c:\windows\ie8updates\KB982381-IE8\ieproxy.dll
+ 2011-07-08 07:46 . 2009-03-08 02:33	246784              c:\windows\ie8updates\KB982381-IE8\ieproxy.dll
+ 2011-07-08 07:46 . 2009-03-08 02:31	183808              c:\windows\ie8updates\KB982381-IE8\iepeers.dll
- 2011-07-06 20:09 . 2009-03-08 02:31	183808              c:\windows\ie8updates\KB982381-IE8\iepeers.dll
- 2011-07-06 20:09 . 2009-03-08 02:35	742912              c:\windows\ie8updates\KB982381-IE8\iedvtool.dll
+ 2011-07-08 07:46 . 2009-03-08 02:35	742912              c:\windows\ie8updates\KB982381-IE8\iedvtool.dll
+ 2011-07-08 07:46 . 2009-03-08 12:09	391536              c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
- 2011-07-06 20:09 . 2009-03-08 12:09	391536              c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
+ 2011-07-08 07:46 . 2009-03-08 02:32	173056              c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
- 2011-07-06 20:09 . 2009-03-08 02:32	173056              c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
- 2011-07-06 20:10 . 2010-05-06 10:31	916480              c:\windows\ie8updates\KB2530548-IE8\wininet.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	916480              c:\windows\ie8updates\KB2530548-IE8\wininet.dll
+ 2011-07-08 07:48 . 2010-07-05 13:14	388984              c:\windows\ie8updates\KB2530548-IE8\updspapi.dll
+ 2011-07-08 07:48 . 2010-07-05 13:14	765304              c:\windows\ie8updates\KB2530548-IE8\update.exe
+ 2011-07-08 07:48 . 2010-07-05 13:14	388984              c:\windows\ie8updates\KB2530548-IE8\spuninst\updspapi.dll
- 2011-07-06 20:10 . 2010-07-05 13:14	388984              c:\windows\ie8updates\KB2530548-IE8\spuninst\updspapi.dll
- 2011-07-06 20:10 . 2010-07-05 13:14	234872              c:\windows\ie8updates\KB2530548-IE8\spuninst\spuninst.exe
+ 2011-07-08 07:48 . 2010-07-05 13:14	234872              c:\windows\ie8updates\KB2530548-IE8\spuninst\spuninst.exe
+ 2011-07-08 07:48 . 2010-07-05 13:14	234872              c:\windows\ie8updates\KB2530548-IE8\spuninst.exe
- 2011-07-06 20:10 . 2010-05-06 10:31	206848              c:\windows\ie8updates\KB2530548-IE8\occache.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	206848              c:\windows\ie8updates\KB2530548-IE8\occache.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	611840              c:\windows\ie8updates\KB2530548-IE8\mstime.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	611840              c:\windows\ie8updates\KB2530548-IE8\mstime.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	599040              c:\windows\ie8updates\KB2530548-IE8\msfeeds.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	599040              c:\windows\ie8updates\KB2530548-IE8\msfeeds.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	247808              c:\windows\ie8updates\KB2530548-IE8\ieproxy.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	247808              c:\windows\ie8updates\KB2530548-IE8\ieproxy.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	184320              c:\windows\ie8updates\KB2530548-IE8\iepeers.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	184320              c:\windows\ie8updates\KB2530548-IE8\iepeers.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	743424              c:\windows\ie8updates\KB2530548-IE8\iedvtool.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	743424              c:\windows\ie8updates\KB2530548-IE8\iedvtool.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	387584              c:\windows\ie8updates\KB2530548-IE8\iedkcs32.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	387584              c:\windows\ie8updates\KB2530548-IE8\iedkcs32.dll
+ 2011-07-08 07:48 . 2010-05-05 13:30	173056              c:\windows\ie8updates\KB2530548-IE8\ie4uinit.exe
- 2011-07-06 20:10 . 2010-05-05 13:30	173056              c:\windows\ie8updates\KB2530548-IE8\ie4uinit.exe
+ 2011-07-08 07:47 . 2010-02-22 14:22	388984              c:\windows\ie8updates\KB2447568-IE8\updspapi.dll
+ 2011-07-08 07:47 . 2010-02-22 14:21	765304              c:\windows\ie8updates\KB2447568-IE8\update.exe
+ 2011-07-08 07:47 . 2010-02-22 14:22	388984              c:\windows\ie8updates\KB2447568-IE8\spuninst\updspapi.dll
- 2011-07-06 20:09 . 2010-02-22 14:22	388984              c:\windows\ie8updates\KB2447568-IE8\spuninst\updspapi.dll
+ 2011-07-08 07:47 . 2010-02-22 14:22	234872              c:\windows\ie8updates\KB2447568-IE8\spuninst\spuninst.exe
- 2011-07-06 20:09 . 2010-02-22 14:22	234872              c:\windows\ie8updates\KB2447568-IE8\spuninst\spuninst.exe
+ 2011-07-08 07:47 . 2010-02-22 14:22	234872              c:\windows\ie8updates\KB2447568-IE8\spuninst.exe
+ 2011-07-08 07:39 . 2011-04-25 14:47	672768              c:\windows\ie8\wininet.dll
- 2011-07-06 20:03 . 2011-04-25 14:47	672768              c:\windows\ie8\wininet.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	281088              c:\windows\ie8\webcheck.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	281088              c:\windows\ie8\webcheck.dll
- 2011-07-06 20:03 . 2011-04-29 19:07	852480              c:\windows\ie8\vgx.dll
+ 2011-07-08 07:39 . 2011-04-29 19:07	852480              c:\windows\ie8\vgx.dll
+ 2011-07-08 07:39 . 2011-03-04 06:44	434176              c:\windows\ie8\vbscript.dll
- 2011-07-06 20:03 . 2011-03-04 06:44	434176              c:\windows\ie8\vbscript.dll
- 2011-07-06 20:03 . 2011-04-25 14:47	628736              c:\windows\ie8\urlmon.dll
+ 2011-07-08 07:39 . 2011-04-25 14:47	628736              c:\windows\ie8\urlmon.dll
- 2011-07-06 20:04 . 2009-01-07 16:20	388640              c:\windows\ie8\spuninst\updspapi.dll
+ 2011-07-08 07:41 . 2009-01-07 16:20	388640              c:\windows\ie8\spuninst\updspapi.dll
+ 2011-07-08 07:41 . 2009-01-07 16:20	235040              c:\windows\ie8\spuninst\spuninst.exe
- 2011-07-06 20:04 . 2009-01-07 16:20	235040              c:\windows\ie8\spuninst\spuninst.exe
- 2011-07-06 20:03 . 2011-04-25 14:47	532480              c:\windows\ie8\mstime.dll
+ 2011-07-08 07:39 . 2011-04-25 14:47	532480              c:\windows\ie8\mstime.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	146432              c:\windows\ie8\msrating.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	146432              c:\windows\ie8\msrating.dll
+ 2011-07-08 07:40 . 2004-08-10 12:00	146432              c:\windows\ie8\msls31.dll
- 2011-07-06 20:03 . 2004-08-10 12:00	146432              c:\windows\ie8\msls31.dll
- 2011-07-06 20:03 . 2011-04-25 14:47	449536              c:\windows\ie8\mshtmled.dll
+ 2011-07-08 07:39 . 2011-04-25 14:47	449536              c:\windows\ie8\mshtmled.dll
+ 2011-07-08 07:39 . 2011-03-04 06:44	512000              c:\windows\ie8\jscript.dll
- 2011-07-06 20:03 . 2011-03-04 06:44	512000              c:\windows\ie8\jscript.dll
+ 2011-07-08 07:39 . 2011-04-25 14:47	251904              c:\windows\ie8\iepeers.dll
- 2011-07-06 20:03 . 2011-04-25 14:47	251904              c:\windows\ie8\iepeers.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	323584              c:\windows\ie8\iedkcs32.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	323584              c:\windows\ie8\iedkcs32.dll
+ 2011-07-08 07:40 . 2004-08-10 12:00	237568              c:\windows\ie8\ieakui.dll
- 2011-07-06 20:03 . 2004-08-10 12:00	237568              c:\windows\ie8\ieakui.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	220672              c:\windows\ie8\ieaksie.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	220672              c:\windows\ie8\ieaksie.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	143360              c:\windows\ie8\ieakeng.dll
+ 2011-07-08 07:40 . 2008-04-14 02:22	143360              c:\windows\ie8\ieakeng.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	205312              c:\windows\ie8\dxtrans.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	205312              c:\windows\ie8\dxtrans.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	357888              c:\windows\ie8\dxtmsft.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	357888              c:\windows\ie8\dxtmsft.dll
- 2011-07-06 20:03 . 2008-04-14 02:22	102400              c:\windows\ie8\advpack.dll
+ 2011-07-08 07:39 . 2008-04-14 02:22	102400              c:\windows\ie8\advpack.dll
+ 2011-07-08 07:26 . 2005-10-20 10:02	163328              c:\windows\ERDNT\AutoBackup\08.07.2011\ERDNT.EXE
+ 2011-07-08 07:46 . 2009-03-08 02:34	1206784              c:\windows\ie8updates\KB982381-IE8\urlmon.dll
- 2011-07-06 20:09 . 2009-03-08 02:34	1206784              c:\windows\ie8updates\KB982381-IE8\urlmon.dll
+ 2011-07-08 07:46 . 2009-03-08 02:41	5937152              c:\windows\ie8updates\KB982381-IE8\mshtml.dll
- 2011-07-06 20:09 . 2009-03-08 02:41	5937152              c:\windows\ie8updates\KB982381-IE8\mshtml.dll
- 2011-07-06 20:09 . 2009-03-08 02:32	1985024              c:\windows\ie8updates\KB982381-IE8\iertutil.dll
+ 2011-07-08 07:46 . 2009-03-08 02:32	1985024              c:\windows\ie8updates\KB982381-IE8\iertutil.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	1209344              c:\windows\ie8updates\KB2530548-IE8\urlmon.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	1209344              c:\windows\ie8updates\KB2530548-IE8\urlmon.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	5950976              c:\windows\ie8updates\KB2530548-IE8\mshtml.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	5950976              c:\windows\ie8updates\KB2530548-IE8\mshtml.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	1985536              c:\windows\ie8updates\KB2530548-IE8\iertutil.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	1985536              c:\windows\ie8updates\KB2530548-IE8\iertutil.dll
- 2011-07-06 20:03 . 2011-04-25 14:47	3100672              c:\windows\ie8\mshtml.dll
+ 2011-07-08 07:39 . 2011-04-25 14:47	3100672              c:\windows\ie8\mshtml.dll
+ 2011-07-08 07:26 . 2011-07-08 07:26	3317760              c:\windows\ERDNT\AutoBackup\08.07.2011\Users\00000002\UsrClass.dat
+ 2011-07-08 07:46 . 2009-03-08 02:39	11063808              c:\windows\ie8updates\KB982381-IE8\ieframe.dll
- 2011-07-06 20:09 . 2009-03-08 02:39	11063808              c:\windows\ie8updates\KB982381-IE8\ieframe.dll
+ 2011-07-08 07:48 . 2010-05-06 10:31	11076096              c:\windows\ie8updates\KB2530548-IE8\ieframe.dll
- 2011-07-06 20:10 . 2010-05-06 10:31	11076096              c:\windows\ie8updates\KB2530548-IE8\ieframe.dll
+ 2011-07-08 07:26 . 2011-07-08 07:26	19677184              c:\windows\ERDNT\AutoBackup\08.07.2011\Users\00000001\NTUSER.DAT
.
-- Snapshot auf jetziges Datum zurückgesetzt --
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programme\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\programme\mipony-plugin\prxtbmip2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54	175912	----a-w-	c:\programme\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
2011-01-17 14:54	175912	----a-w-	c:\programme\mipony-plugin\prxtbmip2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 14:54	175912	----a-w-	c:\programme\Vuze_Remote\prxtbVuz0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programme\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\programme\mipony-plugin\prxtbmip2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\programme\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6EDCCE69-14A2-4E9F-826B-DC523B82167E}"= "c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll" [2007-02-02 591360]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\programme\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{90D46C30-9F25-4104-AEA9-35C3F84477FF}"= "c:\programme\mipony-plugin\prxtbmip2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{6edcce69-14a2-4e9f-826b-dc523b82167e}]
[HKEY_CLASSES_ROOT\IexploreOmea.Band.1]
[HKEY_CLASSES_ROOT\TypeLib\{633820F7-C04E-4152-B64F-1147B881F998}]
[HKEY_CLASSES_ROOT\IexploreOmea.Band]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-13 68856]
"SpybotSD TeaTimer"="c:\programme\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PPS Accelerator"="c:\programme\PPStream\ppsap.exe" [2009-07-22 210312]
"googletalk"="c:\programme\Google\Google Talk\googletalk.exe" [2007-11-21 3293184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-15 7331840]
"Apoint"="c:\programme\Apoint\Apoint.exe" [2004-11-17 118784]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 45056]
"SonyPowerCfg"="c:\programme\Sony\VAIO Power Management\SPMgr.exe" [2005-11-28 217088]
"ISBMgr.exe"="c:\programme\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"VAIOCameraUtility"="c:\programme\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-09-27 81920]
"avgnt"="c:\programme\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"TkBellExe"="c:\programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2007-03-14 185896]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"VAIO Update 4"="c:\programme\Sony\VAIO Update 4\VAIOUpdt.exe" [2008-08-24 870240]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"TWCU"="c:\programme\TP-LINK\TL-WN821N\TWCU.exe" [2008-10-20 557186]
"PDFPrint"="c:\programme\pdf24\pdf24.exe" [2011-04-08 220552]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"LogMeIn Hamachi Ui"="c:\programme\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-03-28 1910152]
"Malwarebytes' Anti-Malware"="c:\programme\Malwarebytes' Anti-Malwaren\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"MySpaceIM"="c:\programme\MySpace\IM\MySpaceIM.exe" [2007-01-12 4898816]
.
c:\dokumente und einstellungen\Marian Kasprowski\Startmen\Programme\Autostart\
ERUNT AutoBackup.lnk - c:\programme\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Microsoft Office OneNote 2003 Schnellstart.lnk - c:\programme\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 64864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 16:42	73728	----a-w-	c:\windows\system32\VESWinlogon.dll
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^HOTSYNCSHORTCUTNAME.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^InterVideo WinCinema Manager.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Quicken 2006 Zahlungserinnerung.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Quicken 2006 Zahlungserinnerung.lnk
backup=c:\windows\pss\Quicken 2006 Zahlungserinnerung.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^Marian Kasprowski^Startmenü^Programme^Autostart^Kremlin Sentry.LNK]
path=c:\dokumente und einstellungen\Marian Kasprowski\Startmenü\Programme\Autostart\Kremlin Sentry.LNK
backup=c:\windows\pss\Kremlin Sentry.LNKStartup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^Marian Kasprowski^Startmenü^Programme^Autostart^Yahoo! Widget Engine.lnk]
path=c:\dokumente und einstellungen\Marian Kasprowski\Startmenü\Programme\Autostart\Yahoo! Widget Engine.lnk
backup=c:\windows\pss\Yahoo! Widget Engine.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50	155648	----a-w-	c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 14:16	421888	----a-w-	c:\programme\QuickTime\QTTask.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Programme\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Programme\\ICQLite\\ICQLite.exe"=
"c:\\Programme\\Miranda IM\\miranda32.exe"=
"c:\\Programme\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Dokumente und Einstellungen\\Marian Kasprowski\\Eigene Dateien\\Downloads\\ppstreamsetup.exe"=
"c:\\Programme\\PPStream\\PPStream.exe"=
"c:\\Programme\\PPStream\\PPSAP.exe"=
"c:\\Programme\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"c:\\Programme\\Google\\Google Talk\\googletalk.exe"=
"c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programme\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
.
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\programme\LogMeIn Hamachi\hamachi-2.exe [28.03.2011 15:41 1242504]
R2 MBAMService;MBAMService;c:\programme\Malwarebytes' Anti-Malwaren\mbamservice.exe [04.07.2011 22:46 366640]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R2 wwEngineSvc;Window Washer Engine;c:\programme\Webroot\Washer\WasherSvc.exe [17.10.2007 17:41 598856]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [04.07.2011 19:20 22712]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [12.12.2005 10:24 28800]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [12.12.2005 10:24 808448]
S2 gupdate;Google Update Service (gupdate);c:\programme\Google\Update\GoogleUpdate.exe [12.07.2010 14:34 135664]
S3 arusb(TP-LINK);Atheros Wireless Network Adapter Service(TP-LINK);c:\windows\system32\drivers\arusb.sys [15.09.2010 15:47 458240]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\programme\Google\Update\GoogleUpdate.exe [12.07.2010 14:34 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [04.07.2011 19:20 39984]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\programme\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys --> c:\windows\system32\DRIVERS\wdcsam.sys [?]
S4 ASKService;ASKService;c:\programme\AskBarDis\bar\bin\AskService.exe [16.11.2008 06:15 460168]
.
Inhalt des "geplante Tasks" Ordners
.
2011-06-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-07-12 12:34]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-07-12 12:34]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.club-vaio.com/de/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Clip and Edit - c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll/1000
IE: Clip and Save - c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll/1001
IE: Download all with Free Download Manager - file://c:\programme\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\programme\Free Download Manager\dlselected.htm
IE: Download web site with Free Download Manager - file://c:\programme\Free Download Manager\dlpage.htm
IE: Download with &FileFactory Turbo - c:\programme\FileFactory Turbo\Plugins\IE\FileFactoryIE.html
IE: Download with Free Download Manager - file://c:\programme\Free Download Manager\dllink.htm
IE: Google Sidewiki... - c:\programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: Mit Mipony herunterladen - file://c:\programme\MiPony\Browser\IEContext.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Subscribe in Desktop Sidebar - c:\programme\Desktop Sidebar\sbhelp.dll/menuhandler.html
IE: Subscribe to Feed - c:\programme\JetBrains\Omea Reader\IexploreOmeaW.dll/1002
IE: ¨¹bertragen mit Image Converter 2 Plus
IE: Übertragen mit Image Converter 2 Plus - c:\programme\Sony\Image Converter 2\menu.htm
IE: ?ertragen mit Image Converter 2 Plus
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
TCP: DhcpNameServer = 192.168.1.130 192.168.1.10
TCP: Interfaces\{85A73874-1983-41F4-95EA-855B09005769}: NameServer = 192.168.1.10 192.168.1.130
Handler: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - c:\programme\Haufe\HaufeReader\HRInstmon.dll
FF - ProfilePath - c:\dokumente und einstellungen\Marian Kasprowski\Anwendungsdaten\Mozilla\Firefox\Profiles\24drnrac.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.stratfor.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&q=
FF - Ext: NASA Night Launch: nasanightlaunch@example.com - %profile%\extensions\nasanightlaunch@example.com
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: OldFactory Black: {69D30031-F4A8-452a-A5B3-5D6787C3C5CF} - %profile%\extensions\{69D30031-F4A8-452a-A5B3-5D6787C3C5CF}
FF - Ext: Vuze Toolbar: {E9A1DEE0-C623-4439-8932-001E7D17607D} - %profile%\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Wild Pockets Loader: wildpocketsloader@simopsstudios.com - %profile%\extensions\wildpocketsloader@simopsstudios.com
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
FF - Ext: FireShot: {0b457cAA-602d-484a-8fe7-c1d894a011ba} - %profile%\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
FF - Ext: printpdf: printpdf@pavlov.net - %profile%\extensions\printpdf@pavlov.net
FF - Ext: mipony-plugin Community Toolbar: {90d46c30-9f25-4104-aea9-35c3f84477ff} - %profile%\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programme\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Veoh Browser Plug-in: videofinder@veoh.com - c:\programme\Veoh Networks\Veoh\Plugins\noreg\videofinder4
FF - Ext: FileFactory Turbo: {5b9fd6af-b36b-47d5-88fc-8398bab59411} - c:\programme\FileFactory Turbo\Plugins\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programme\Java\jre6\lib\deploy\jqs\ff
 
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-07-08 18:43
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
Scanne versteckte Dateien... 
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\E„;*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Anwendungsdaten\\Intel\\Wireless\\"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(1568)
c:\windows\system32\VESWinlogon.dll
.
Zeit der Fertigstellung: 2011-07-08  18:48:17
ComboFix-quarantined-files.txt  2011-07-08 16:48
ComboFix2.txt  2011-07-08 00:04
.
Vor Suchlauf: 16 Verzeichnis(se), 20.941.021.184 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 20.919.996.416 Bytes frei
.
Current=4 Default=4 Failed=1 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - EBAF9CD0DB091B1D5EB0BA7BC643E014
         
--- --- ---

Alt 10.07.2011, 18:24   #14
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows XP Repair Malware - Standard

Windows XP Repair Malware



Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Windows XP Repair Malware
aktiv, dateien, detected, einstellungen, fake, file, folge, frage, ics, infected, langsam, log file, malwar, malware, malwarebytes, microsoft, neu, problem, programme, security, seite, software, system, trojan.agent, windows, windows xp




Ähnliche Themen: Windows XP Repair Malware


  1. Repair-windows-now.com entfernen
    Anleitungen, FAQs & Links - 30.10.2015 (2)
  2. Windows Repair v.3.6.0 Ordner
    Alles rund um Windows - 13.10.2015 (1)
  3. Windows 7 Startup Repair Endlosschleife
    Alles rund um Windows - 13.12.2014 (5)
  4. Windows 8, Windows PC-Repair Virus und wohl noch andere
    Log-Analyse und Auswertung - 07.05.2014 (27)
  5. Windows 7 Startup Repair Virus
    Plagegeister aller Art und deren Bekämpfung - 02.04.2013 (2)
  6. System repair Virus Windows 7 Starter
    Plagegeister aller Art und deren Bekämpfung - 28.02.2013 (23)
  7. Windows System Repair Virus
    Log-Analyse und Auswertung - 26.02.2013 (17)
  8. Anleitung: Windows Repair (AIO)
    Anleitungen, FAQs & Links - 28.10.2012 (1)
  9. S.M.A.R.T Repair Malware auf VISTA
    Log-Analyse und Auswertung - 17.06.2012 (36)
  10. Schwarzer Desktop wegen Windows XP Repair
    Plagegeister aller Art und deren Bekämpfung - 25.07.2011 (1)
  11. Windows XP Repair
    Plagegeister aller Art und deren Bekämpfung - 23.06.2011 (2)
  12. Windows XP Repair entfernen
    Anleitungen, FAQs & Links - 17.06.2011 (2)
  13. Windows 7 Repair entfernen
    Anleitungen, FAQs & Links - 17.06.2011 (2)
  14. Windows Vista Repair entfernen
    Anleitungen, FAQs & Links - 17.06.2011 (2)
  15. Windows Repair entfernen
    Anleitungen, FAQs & Links - 01.04.2011 (2)

Zum Thema Windows XP Repair Malware - Hallo liebe Community, ich wurde vor einigen Tagen von Windows Xp Repair befallen. Fake Security Center, unsichtbare Dateien, extrem langsam, ungefragte Reboots, etc. Ich habe mich einer Empfehlung dieser Seite - Windows XP Repair Malware...
Archiv
Du betrachtest: Windows XP Repair Malware auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.