|
Plagegeister aller Art und deren Bekämpfung: Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.09.2012, 18:07 | #31 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenCode:
ATTFilter # AdwCleaner v2.001 - Datei am 09/11/2012 um 19:06:21 erstellt # Aktualisiert am 09/09/2012 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzer : HeftigDerBoss - HEFTIGDERBOSS-P # Bootmodus : Normal # Ausgeführt unter : C:\Users\HeftigDerBoss\Desktop\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v8.0 (de) Profilname : default Datei : C:\Users\HeftigDerBoss\AppData\Roaming\Mozilla\Firefox\Profiles\wtqlaods.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [2569 octets] - [17/08/2012 22:55:05] AdwCleaner[S1].txt - [2741 octets] - [20/08/2012 23:24:15] AdwCleaner[R2].txt - [1518 octets] - [03/09/2012 18:51:59] AdwCleaner[S2].txt - [2080 octets] - [04/09/2012 15:54:11] AdwCleaner[R3].txt - [1144 octets] - [07/09/2012 19:03:02] AdwCleaner[R4].txt - [1070 octets] - [11/09/2012 19:06:21] ########## EOF - C:\AdwCleaner[R4].txt - [1130 octets] ########## |
11.09.2012, 22:30 | #32 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Hm, keine Funde mehr
__________________Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ |
15.09.2012, 14:51 | #33 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenCode:
ATTFilter OTL Logfile: |
16.09.2012, 15:37 | #34 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL FF - user.js - File not found [2012.07.26 18:14:30 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012.09.12 07:15:40 | 000,000,950 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-1.xml [2011.05.01 09:15:04 | 000,000,961 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-10.xml [2011.05.06 17:37:36 | 000,000,950 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-11.xml [2011.05.06 17:37:48 | 000,000,950 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-12.xml [2010.10.19 18:30:20 | 000,000,961 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-2.xml [2009.07.22 21:42:50 | 000,000,950 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-3.xml [2009.08.04 21:14:00 | 000,000,950 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-4.xml [2010.10.21 06:34:52 | 000,000,961 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-5.xml [2010.10.30 10:23:02 | 000,000,666 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-6.xml [2010.12.14 21:00:06 | 000,000,961 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-7.xml [2011.03.03 12:07:02 | 000,000,961 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-8.xml [2011.03.28 17:55:40 | 000,000,961 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-9.xml [2009.07.13 17:12:02 | 000,000,944 | ---- | M] () -- C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin.xml O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-3612399379-2078024685-110007940-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{865631b7-3bc4-11e1-a59b-0019dbe80e53}\Shell - "" = AutoRun O33 - MountPoints2\{865631b7-3bc4-11e1-a59b-0019dbe80e53}\Shell\AutoRun\command - "" = F:\Autorun.exe -- [2010.07.05 16:11:07 | 000,143,008 | RH-- | M] () O33 - MountPoints2\{c061ed0c-36e8-11e1-9c1d-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{c061ed0c-36e8-11e1-9c1d-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe -- [2010.08.24 03:51:12 | 000,345,896 | R--- | M] (Valve Corporation) :Files C:\Windows\Installer\{b65b4c48-e925-0df4-f466-1edc76a43dcd} C:\Users\HeftigDerBoss\AppData\Local\{b65b4c48-e925-0df4-f466-1edc76a43dcd} ipconfig /flushdns /c :Commands [purity] [emptytemp] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten |
17.09.2012, 15:04 | #35 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenCode:
ATTFilter All processes killed ========== OTL ========== C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\Firefox\Profiles\wtqlaods.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-1.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-10.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-11.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-12.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-2.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-3.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-4.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-5.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-6.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-7.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-8.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin-9.xml moved successfully. C:\Users\HeftigDerBoss\AppData\Roaming\mozilla\firefox\profiles\wtqlaods.default\searchplugins\icqplugin.xml moved successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-21-3612399379-2078024685-110007940-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{865631b7-3bc4-11e1-a59b-0019dbe80e53}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{865631b7-3bc4-11e1-a59b-0019dbe80e53}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{865631b7-3bc4-11e1-a59b-0019dbe80e53}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{865631b7-3bc4-11e1-a59b-0019dbe80e53}\ not found. File move failed. F:\Autorun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c061ed0c-36e8-11e1-9c1d-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c061ed0c-36e8-11e1-9c1d-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c061ed0c-36e8-11e1-9c1d-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c061ed0c-36e8-11e1-9c1d-806e6f6e6963}\ not found. File move failed. E:\Setup.exe scheduled to be moved on reboot. ========== FILES ========== C:\Windows\Installer\{b65b4c48-e925-0df4-f466-1edc76a43dcd}\U folder moved successfully. C:\Windows\Installer\{b65b4c48-e925-0df4-f466-1edc76a43dcd}\L folder moved successfully. C:\Windows\Installer\{b65b4c48-e925-0df4-f466-1edc76a43dcd} folder moved successfully. C:\Users\HeftigDerBoss\AppData\Local\{b65b4c48-e925-0df4-f466-1edc76a43dcd}\U folder moved successfully. C:\Users\HeftigDerBoss\AppData\Local\{b65b4c48-e925-0df4-f466-1edc76a43dcd}\L folder moved successfully. C:\Users\HeftigDerBoss\AppData\Local\{b65b4c48-e925-0df4-f466-1edc76a43dcd} folder moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\HeftigDerBoss\Desktop\cmd.bat deleted successfully. C:\Users\HeftigDerBoss\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: HeftigDerBoss ->Temp folder emptied: 2970811 bytes ->Temporary Internet Files folder emptied: 4839223 bytes ->Java cache emptied: 100767 bytes ->FireFox cache emptied: 1087691153 bytes ->Flash cache emptied: 10136 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes RecycleBin emptied: 227564624 bytes Total Files Cleaned = 1.262,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.61.4 log created on 09172012_155303 Files\Folders moved on Reboot... File move failed. F:\Autorun.exe scheduled to be moved on reboot. File move failed. E:\Setup.exe scheduled to be moved on reboot. C:\Users\HeftigDerBoss\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
17.09.2012, 19:34 | #36 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs. Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!
__________________ --> Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen |
18.09.2012, 13:27 | #37 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenCode:
ATTFilter 14:23:29.0760 2928 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24 14:23:29.0773 2928 ============================================================ 14:23:29.0773 2928 Current date / time: 2012/09/18 14:23:29.0773 14:23:29.0773 2928 SystemInfo: 14:23:29.0773 2928 14:23:29.0773 2928 OS Version: 6.1.7601 ServicePack: 1.0 14:23:29.0773 2928 Product type: Workstation 14:23:29.0773 2928 ComputerName: HEFTIGDERBOSS-P 14:23:29.0773 2928 UserName: HeftigDerBoss 14:23:29.0773 2928 Windows directory: C:\Windows 14:23:29.0773 2928 System windows directory: C:\Windows 14:23:29.0773 2928 Running under WOW64 14:23:29.0773 2928 Processor architecture: Intel x64 14:23:29.0773 2928 Number of processors: 2 14:23:29.0773 2928 Page size: 0x1000 14:23:29.0773 2928 Boot type: Normal boot 14:23:29.0773 2928 ============================================================ 14:23:30.0586 2928 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:23:30.0596 2928 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:23:30.0601 2928 ============================================================ 14:23:30.0601 2928 \Device\Harddisk1\DR1: 14:23:30.0601 2928 MBR partitions: 14:23:30.0601 2928 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xFDE8000 14:23:30.0601 2928 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0xFDE8800, BlocksNum 0x2A59D000 14:23:30.0601 2928 \Device\Harddisk0\DR0: 14:23:30.0601 2928 MBR partitions: 14:23:30.0601 2928 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x74705982 14:23:30.0601 2928 ============================================================ 14:23:30.0624 2928 C: <-> \Device\Harddisk1\DR1\Partition1 14:23:30.0661 2928 D: <-> \Device\Harddisk1\DR1\Partition2 14:23:30.0674 2928 G: <-> \Device\Harddisk0\DR0\Partition1 14:23:30.0674 2928 ============================================================ 14:23:30.0674 2928 Initialize success 14:23:30.0674 2928 ============================================================ 14:24:24.0320 1780 ============================================================ 14:24:24.0320 1780 Scan started 14:24:24.0321 1780 Mode: Manual; SigCheck; TDLFS; 14:24:24.0321 1780 ============================================================ 14:24:24.0505 1780 ================ Scan system memory ======================== 14:24:24.0505 1780 System memory - ok 14:24:24.0505 1780 ================ Scan services ============================= 14:24:24.0634 1780 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 14:24:24.0748 1780 1394ohci - ok 14:24:24.0783 1780 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 14:24:24.0807 1780 ACPI - ok 14:24:24.0823 1780 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 14:24:24.0894 1780 AcpiPmi - ok 14:24:24.0968 1780 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 14:24:24.0984 1780 AdobeARMservice - ok 14:24:25.0021 1780 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 14:24:25.0052 1780 adp94xx - ok 14:24:25.0080 1780 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 14:24:25.0104 1780 adpahci - ok 14:24:25.0123 1780 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 14:24:25.0144 1780 adpu320 - ok 14:24:25.0175 1780 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 14:24:25.0295 1780 AeLookupSvc - ok 14:24:25.0334 1780 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 14:24:25.0397 1780 AFD - ok 14:24:25.0435 1780 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 14:24:25.0454 1780 agp440 - ok 14:24:25.0467 1780 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 14:24:25.0522 1780 ALG - ok 14:24:25.0549 1780 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 14:24:25.0566 1780 aliide - ok 14:24:25.0592 1780 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 14:24:25.0610 1780 amdide - ok 14:24:25.0638 1780 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 14:24:25.0692 1780 AmdK8 - ok 14:24:25.0704 1780 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 14:24:25.0738 1780 AmdPPM - ok 14:24:25.0756 1780 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 14:24:25.0775 1780 amdsata - ok 14:24:25.0791 1780 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 14:24:25.0812 1780 amdsbs - ok 14:24:25.0823 1780 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 14:24:25.0839 1780 amdxata - ok 14:24:25.0876 1780 [ 4DE0D5D747A73797C95A97DCCE5018B5 ] androidusb C:\Windows\system32\Drivers\ssadadb.sys 14:24:25.0927 1780 androidusb - ok 14:24:25.0993 1780 [ 0A1CC583E8147004E4AD4625D7FBF88C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 14:24:26.0009 1780 AntiVirSchedulerService - ok 14:24:26.0028 1780 [ C9A36EF935ACED86AEDF93E97E606911 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 14:24:26.0042 1780 AntiVirService - ok 14:24:26.0093 1780 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 14:24:26.0214 1780 AppID - ok 14:24:26.0233 1780 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 14:24:26.0300 1780 AppIDSvc - ok 14:24:26.0322 1780 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 14:24:26.0369 1780 Appinfo - ok 14:24:26.0403 1780 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll 14:24:26.0464 1780 AppMgmt - ok 14:24:26.0496 1780 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 14:24:26.0514 1780 arc - ok 14:24:26.0524 1780 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 14:24:26.0542 1780 arcsas - ok 14:24:26.0565 1780 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 14:24:26.0626 1780 AsyncMac - ok 14:24:26.0653 1780 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 14:24:26.0669 1780 atapi - ok 14:24:26.0705 1780 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 14:24:26.0781 1780 AudioEndpointBuilder - ok 14:24:26.0793 1780 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 14:24:26.0848 1780 AudioSrv - ok 14:24:26.0883 1780 [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 14:24:26.0901 1780 avgntflt - ok 14:24:26.0930 1780 [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 14:24:26.0949 1780 avipbb - ok 14:24:26.0958 1780 [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 14:24:26.0975 1780 avkmgr - ok 14:24:27.0005 1780 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 14:24:27.0073 1780 AxInstSV - ok 14:24:27.0125 1780 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 14:24:27.0181 1780 b06bdrv - ok 14:24:27.0209 1780 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 14:24:27.0270 1780 b57nd60a - ok 14:24:27.0302 1780 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 14:24:27.0341 1780 BDESVC - ok 14:24:27.0355 1780 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 14:24:27.0432 1780 Beep - ok 14:24:27.0461 1780 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 14:24:27.0545 1780 BITS - ok 14:24:27.0571 1780 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 14:24:27.0595 1780 blbdrive - ok 14:24:27.0619 1780 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 14:24:27.0648 1780 bowser - ok 14:24:27.0671 1780 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 14:24:27.0729 1780 BrFiltLo - ok 14:24:27.0744 1780 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 14:24:27.0764 1780 BrFiltUp - ok 14:24:27.0791 1780 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 14:24:27.0815 1780 Browser - ok 14:24:27.0837 1780 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 14:24:27.0887 1780 Brserid - ok 14:24:27.0896 1780 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 14:24:27.0925 1780 BrSerWdm - ok 14:24:27.0938 1780 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 14:24:27.0972 1780 BrUsbMdm - ok 14:24:27.0978 1780 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 14:24:27.0996 1780 BrUsbSer - ok 14:24:28.0015 1780 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 14:24:28.0045 1780 BTHMODEM - ok 14:24:28.0083 1780 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 14:24:28.0144 1780 bthserv - ok 14:24:28.0159 1780 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 14:24:28.0217 1780 cdfs - ok 14:24:28.0261 1780 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 14:24:28.0290 1780 cdrom - ok 14:24:28.0324 1780 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 14:24:28.0381 1780 CertPropSvc - ok 14:24:28.0410 1780 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 14:24:28.0442 1780 circlass - ok 14:24:28.0465 1780 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 14:24:28.0491 1780 CLFS - ok 14:24:28.0541 1780 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 14:24:28.0557 1780 clr_optimization_v2.0.50727_32 - ok 14:24:28.0593 1780 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 14:24:28.0610 1780 clr_optimization_v2.0.50727_64 - ok 14:24:28.0670 1780 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 14:24:28.0703 1780 clr_optimization_v4.0.30319_32 - ok 14:24:28.0738 1780 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 14:24:28.0753 1780 clr_optimization_v4.0.30319_64 - ok 14:24:28.0781 1780 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 14:24:28.0825 1780 CmBatt - ok 14:24:28.0848 1780 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 14:24:28.0865 1780 cmdide - ok 14:24:28.0899 1780 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 14:24:28.0946 1780 CNG - ok 14:24:28.0958 1780 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 14:24:28.0975 1780 Compbatt - ok 14:24:29.0001 1780 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 14:24:29.0035 1780 CompositeBus - ok 14:24:29.0049 1780 COMSysApp - ok 14:24:29.0056 1780 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 14:24:29.0074 1780 crcdisk - ok 14:24:29.0100 1780 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll 14:24:29.0144 1780 CryptSvc - ok 14:24:29.0176 1780 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys 14:24:29.0233 1780 CSC - ok 14:24:29.0262 1780 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll 14:24:29.0298 1780 CscService - ok 14:24:29.0325 1780 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 14:24:29.0395 1780 DcomLaunch - ok 14:24:29.0419 1780 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 14:24:29.0480 1780 defragsvc - ok 14:24:29.0511 1780 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 14:24:29.0563 1780 DfsC - ok 14:24:29.0591 1780 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 14:24:29.0663 1780 Dhcp - ok 14:24:29.0681 1780 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 14:24:29.0736 1780 discache - ok 14:24:29.0752 1780 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 14:24:29.0770 1780 Disk - ok 14:24:29.0797 1780 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 14:24:29.0830 1780 Dnscache - ok 14:24:29.0853 1780 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 14:24:29.0912 1780 dot3svc - ok 14:24:29.0935 1780 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 14:24:29.0995 1780 DPS - ok 14:24:30.0034 1780 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 14:24:30.0063 1780 drmkaud - ok 14:24:30.0104 1780 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 14:24:30.0139 1780 DXGKrnl - ok 14:24:30.0169 1780 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 14:24:30.0226 1780 EapHost - ok 14:24:30.0303 1780 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 14:24:30.0382 1780 ebdrv - ok 14:24:30.0408 1780 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 14:24:30.0454 1780 EFS - ok 14:24:30.0502 1780 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 14:24:30.0557 1780 ehRecvr - ok 14:24:30.0585 1780 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 14:24:30.0619 1780 ehSched - ok 14:24:30.0646 1780 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 14:24:30.0676 1780 elxstor - ok 14:24:30.0698 1780 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 14:24:30.0723 1780 ErrDev - ok 14:24:30.0758 1780 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 14:24:30.0822 1780 EventSystem - ok 14:24:30.0842 1780 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 14:24:30.0894 1780 exfat - ok 14:24:30.0906 1780 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 14:24:30.0971 1780 fastfat - ok 14:24:31.0025 1780 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 14:24:31.0093 1780 Fax - ok 14:24:31.0111 1780 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 14:24:31.0128 1780 fdc - ok 14:24:31.0147 1780 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 14:24:31.0203 1780 fdPHost - ok 14:24:31.0227 1780 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 14:24:31.0276 1780 FDResPub - ok 14:24:31.0298 1780 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 14:24:31.0317 1780 FileInfo - ok 14:24:31.0330 1780 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 14:24:31.0391 1780 Filetrace - ok 14:24:31.0409 1780 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 14:24:31.0427 1780 flpydisk - ok 14:24:31.0450 1780 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 14:24:31.0472 1780 FltMgr - ok 14:24:31.0514 1780 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 14:24:31.0570 1780 FontCache - ok 14:24:31.0616 1780 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 14:24:31.0629 1780 FontCache3.0.0.0 - ok 14:24:31.0648 1780 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 14:24:31.0666 1780 FsDepends - ok 14:24:31.0691 1780 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 14:24:31.0708 1780 Fs_Rec - ok 14:24:31.0746 1780 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 14:24:31.0770 1780 fvevol - ok 14:24:31.0781 1780 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 14:24:31.0799 1780 gagp30kx - ok 14:24:31.0833 1780 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 14:24:31.0897 1780 gpsvc - ok 14:24:31.0908 1780 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 14:24:31.0956 1780 hcw85cir - ok 14:24:32.0007 1780 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 14:24:32.0034 1780 HdAudAddService - ok 14:24:32.0052 1780 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 14:24:32.0082 1780 HDAudBus - ok 14:24:32.0110 1780 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 14:24:32.0137 1780 HidBatt - ok 14:24:32.0155 1780 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 14:24:32.0177 1780 HidBth - ok 14:24:32.0193 1780 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 14:24:32.0228 1780 HidIr - ok 14:24:32.0257 1780 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 14:24:32.0314 1780 hidserv - ok 14:24:32.0340 1780 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 14:24:32.0358 1780 HidUsb - ok 14:24:32.0381 1780 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 14:24:32.0456 1780 hkmsvc - ok 14:24:32.0484 1780 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 14:24:32.0517 1780 HomeGroupListener - ok 14:24:32.0532 1780 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 14:24:32.0563 1780 HomeGroupProvider - ok 14:24:32.0583 1780 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 14:24:32.0600 1780 HpSAMD - ok 14:24:32.0638 1780 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 14:24:32.0712 1780 HTTP - ok 14:24:32.0730 1780 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 14:24:32.0748 1780 hwpolicy - ok 14:24:32.0770 1780 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 14:24:32.0790 1780 i8042prt - ok 14:24:32.0819 1780 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 14:24:32.0844 1780 iaStorV - ok 14:24:32.0888 1780 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 14:24:32.0923 1780 idsvc - ok 14:24:32.0955 1780 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 14:24:32.0972 1780 iirsp - ok 14:24:33.0010 1780 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 14:24:33.0073 1780 IKEEXT - ok 14:24:33.0093 1780 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 14:24:33.0111 1780 intelide - ok 14:24:33.0135 1780 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 14:24:33.0166 1780 intelppm - ok 14:24:33.0198 1780 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 14:24:33.0252 1780 IPBusEnum - ok 14:24:33.0279 1780 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 14:24:33.0341 1780 IpFilterDriver - ok 14:24:33.0363 1780 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 14:24:33.0387 1780 IPMIDRV - ok 14:24:33.0405 1780 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 14:24:33.0461 1780 IPNAT - ok 14:24:33.0479 1780 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 14:24:33.0538 1780 IRENUM - ok 14:24:33.0561 1780 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 14:24:33.0578 1780 isapnp - ok 14:24:33.0595 1780 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 14:24:33.0619 1780 iScsiPrt - ok 14:24:33.0645 1780 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 14:24:33.0663 1780 kbdclass - ok 14:24:33.0685 1780 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 14:24:33.0723 1780 kbdhid - ok 14:24:33.0742 1780 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 14:24:33.0759 1780 KeyIso - ok 14:24:33.0800 1780 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 14:24:33.0818 1780 KSecDD - ok 14:24:33.0847 1780 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 14:24:33.0867 1780 KSecPkg - ok 14:24:33.0875 1780 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 14:24:33.0941 1780 ksthunk - ok 14:24:33.0974 1780 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 14:24:34.0036 1780 KtmRm - ok 14:24:34.0070 1780 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 14:24:34.0134 1780 LanmanServer - ok 14:24:34.0162 1780 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 14:24:34.0218 1780 LanmanWorkstation - ok 14:24:34.0244 1780 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 14:24:34.0305 1780 lltdio - ok 14:24:34.0336 1780 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 14:24:34.0391 1780 lltdsvc - ok 14:24:34.0405 1780 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 14:24:34.0453 1780 lmhosts - ok 14:24:34.0474 1780 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 14:24:34.0495 1780 LSI_FC - ok 14:24:34.0506 1780 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 14:24:34.0526 1780 LSI_SAS - ok 14:24:34.0542 1780 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 14:24:34.0560 1780 LSI_SAS2 - ok 14:24:34.0573 1780 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 14:24:34.0592 1780 LSI_SCSI - ok 14:24:34.0616 1780 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 14:24:34.0667 1780 luafv - ok 14:24:34.0708 1780 [ 79D51E7F5926E8CE1B3EBECEBAE28CFF ] mcdbus C:\Windows\system32\DRIVERS\mcdbus.sys 14:24:34.0734 1780 mcdbus - ok 14:24:34.0769 1780 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 14:24:34.0804 1780 Mcx2Svc - ok 14:24:34.0817 1780 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 14:24:34.0835 1780 megasas - ok 14:24:34.0855 1780 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 14:24:34.0879 1780 MegaSR - ok 14:24:34.0899 1780 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 14:24:34.0958 1780 MMCSS - ok 14:24:34.0972 1780 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 14:24:35.0036 1780 Modem - ok 14:24:35.0067 1780 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 14:24:35.0101 1780 monitor - ok 14:24:35.0121 1780 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 14:24:35.0138 1780 mouclass - ok 14:24:35.0170 1780 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 14:24:35.0201 1780 mouhid - ok 14:24:35.0229 1780 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 14:24:35.0247 1780 mountmgr - ok 14:24:35.0272 1780 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 14:24:35.0292 1780 mpio - ok 14:24:35.0310 1780 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 14:24:35.0359 1780 mpsdrv - ok 14:24:35.0377 1780 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 14:24:35.0405 1780 MRxDAV - ok 14:24:35.0432 1780 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 14:24:35.0485 1780 mrxsmb - ok 14:24:35.0503 1780 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 14:24:35.0535 1780 mrxsmb10 - ok 14:24:35.0554 1780 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 14:24:35.0573 1780 mrxsmb20 - ok 14:24:35.0596 1780 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 14:24:35.0614 1780 msahci - ok 14:24:35.0630 1780 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 14:24:35.0651 1780 msdsm - ok 14:24:35.0665 1780 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 14:24:35.0699 1780 MSDTC - ok 14:24:35.0722 1780 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 14:24:35.0771 1780 Msfs - ok 14:24:35.0785 1780 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 14:24:35.0842 1780 mshidkmdf - ok 14:24:35.0864 1780 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 14:24:35.0880 1780 msisadrv - ok 14:24:35.0902 1780 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 14:24:35.0963 1780 MSiSCSI - ok 14:24:35.0969 1780 msiserver - ok 14:24:35.0995 1780 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 14:24:36.0048 1780 MSKSSRV - ok 14:24:36.0060 1780 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 14:24:36.0137 1780 MSPCLOCK - ok 14:24:36.0143 1780 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 14:24:36.0206 1780 MSPQM - ok 14:24:36.0238 1780 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 14:24:36.0262 1780 MsRPC - ok 14:24:36.0281 1780 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 14:24:36.0297 1780 mssmbios - ok 14:24:36.0307 1780 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 14:24:36.0356 1780 MSTEE - ok 14:24:36.0368 1780 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 14:24:36.0385 1780 MTConfig - ok 14:24:36.0399 1780 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 14:24:36.0416 1780 Mup - ok 14:24:36.0449 1780 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 14:24:36.0508 1780 napagent - ok 14:24:36.0536 1780 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 14:24:36.0575 1780 NativeWifiP - ok 14:24:36.0625 1780 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 14:24:36.0666 1780 NDIS - ok 14:24:36.0679 1780 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 14:24:36.0729 1780 NdisCap - ok 14:24:36.0760 1780 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 14:24:36.0813 1780 NdisTapi - ok 14:24:36.0835 1780 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 14:24:36.0881 1780 Ndisuio - ok 14:24:36.0907 1780 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 14:24:36.0968 1780 NdisWan - ok 14:24:36.0985 1780 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 14:24:37.0032 1780 NDProxy - ok 14:24:37.0042 1780 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 14:24:37.0095 1780 NetBIOS - ok 14:24:37.0110 1780 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 14:24:37.0173 1780 NetBT - ok 14:24:37.0192 1780 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 14:24:37.0209 1780 Netlogon - ok 14:24:37.0240 1780 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 14:24:37.0307 1780 Netman - ok 14:24:37.0333 1780 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 14:24:37.0399 1780 netprofm - ok 14:24:37.0426 1780 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 14:24:37.0442 1780 NetTcpPortSharing - ok 14:24:37.0455 1780 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 14:24:37.0472 1780 nfrd960 - ok 14:24:37.0500 1780 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 14:24:37.0557 1780 NlaSvc - ok 14:24:37.0577 1780 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 14:24:37.0625 1780 Npfs - ok 14:24:37.0638 1780 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 14:24:37.0694 1780 nsi - ok 14:24:37.0705 1780 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 14:24:37.0758 1780 nsiproxy - ok 14:24:37.0823 1780 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 14:24:37.0879 1780 Ntfs - ok 14:24:37.0899 1780 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 14:24:37.0956 1780 Null - ok 14:24:37.0994 1780 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys 14:24:38.0035 1780 NVENETFD - ok 14:24:38.0353 1780 [ BF7A24A71E1932200D864BC1CE15E596 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 14:24:38.0639 1780 nvlddmkm - ok 14:24:38.0709 1780 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 14:24:38.0726 1780 nvraid - ok 14:24:38.0745 1780 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 14:24:38.0762 1780 nvstor - ok 14:24:38.0808 1780 [ 43F91595049DE14C4B61D1E76436164F ] nvsvc C:\Windows\system32\nvvsvc.exe 14:24:38.0840 1780 nvsvc - ok 14:24:38.0911 1780 [ 322B69422836F97B76F4AA59B47507BA ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 14:24:38.0956 1780 nvUpdatusService - ok 14:24:38.0973 1780 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 14:24:38.0993 1780 nv_agp - ok 14:24:39.0005 1780 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 14:24:39.0025 1780 ohci1394 - ok 14:24:39.0055 1780 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 14:24:39.0102 1780 p2pimsvc - ok 14:24:39.0126 1780 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 14:24:39.0152 1780 p2psvc - ok 14:24:39.0166 1780 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 14:24:39.0187 1780 Parport - ok 14:24:39.0208 1780 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 14:24:39.0225 1780 partmgr - ok 14:24:39.0242 1780 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 14:24:39.0278 1780 PcaSvc - ok 14:24:39.0293 1780 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 14:24:39.0314 1780 pci - ok 14:24:39.0334 1780 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 14:24:39.0351 1780 pciide - ok 14:24:39.0368 1780 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 14:24:39.0389 1780 pcmcia - ok 14:24:39.0400 1780 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 14:24:39.0416 1780 pcw - ok 14:24:39.0446 1780 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 14:24:39.0505 1780 PEAUTH - ok 14:24:39.0563 1780 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 14:24:39.0626 1780 PeerDistSvc - ok 14:24:39.0688 1780 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 14:24:39.0713 1780 PerfHost - ok 14:24:39.0777 1780 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 14:24:39.0858 1780 pla - ok 14:24:39.0889 1780 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 14:24:39.0918 1780 PlugPlay - ok 14:24:39.0942 1780 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 14:24:39.0977 1780 PNRPAutoReg - ok 14:24:40.0000 1780 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 14:24:40.0022 1780 PNRPsvc - ok 14:24:40.0049 1780 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 14:24:40.0120 1780 PolicyAgent - ok 14:24:40.0158 1780 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 14:24:40.0227 1780 Power - ok 14:24:40.0260 1780 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 14:24:40.0316 1780 PptpMiniport - ok 14:24:40.0329 1780 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 14:24:40.0356 1780 Processor - ok 14:24:40.0389 1780 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 14:24:40.0430 1780 ProfSvc - ok 14:24:40.0443 1780 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 14:24:40.0460 1780 ProtectedStorage - ok 14:24:40.0496 1780 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 14:24:40.0548 1780 Psched - ok 14:24:40.0596 1780 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 14:24:40.0649 1780 ql2300 - ok 14:24:40.0662 1780 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 14:24:40.0682 1780 ql40xx - ok 14:24:40.0708 1780 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 14:24:40.0736 1780 QWAVE - ok 14:24:40.0750 1780 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 14:24:40.0784 1780 QWAVEdrv - ok 14:24:40.0797 1780 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 14:24:40.0845 1780 RasAcd - ok 14:24:40.0869 1780 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 14:24:40.0917 1780 RasAgileVpn - ok 14:24:40.0933 1780 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 14:24:40.0998 1780 RasAuto - ok 14:24:41.0017 1780 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 14:24:41.0077 1780 Rasl2tp - ok 14:24:41.0103 1780 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 14:24:41.0158 1780 RasMan - ok 14:24:41.0178 1780 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 14:24:41.0238 1780 RasPppoe - ok 14:24:41.0253 1780 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 14:24:41.0315 1780 RasSstp - ok 14:24:41.0339 1780 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 14:24:41.0390 1780 rdbss - ok 14:24:41.0405 1780 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 14:24:41.0438 1780 rdpbus - ok 14:24:41.0454 1780 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 14:24:41.0501 1780 RDPCDD - ok 14:24:41.0540 1780 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 14:24:41.0569 1780 RDPDR - ok 14:24:41.0581 1780 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 14:24:41.0635 1780 RDPENCDD - ok 14:24:41.0653 1780 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 14:24:41.0701 1780 RDPREFMP - ok 14:24:41.0776 1780 [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 14:24:41.0806 1780 RdpVideoMiniport - ok 14:24:41.0833 1780 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 14:24:41.0876 1780 RDPWD - ok 14:24:41.0895 1780 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 14:24:41.0916 1780 rdyboost - ok 14:24:41.0946 1780 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 14:24:42.0009 1780 RemoteAccess - ok 14:24:42.0036 1780 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 14:24:42.0100 1780 RemoteRegistry - ok 14:24:42.0127 1780 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 14:24:42.0191 1780 RpcEptMapper - ok 14:24:42.0211 1780 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 14:24:42.0231 1780 RpcLocator - ok 14:24:42.0254 1780 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 14:24:42.0309 1780 RpcSs - ok 14:24:42.0334 1780 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 14:24:42.0382 1780 rspndr - ok 14:24:42.0405 1780 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 14:24:42.0443 1780 s3cap - ok 14:24:42.0450 1780 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 14:24:42.0467 1780 SamSs - ok 14:24:42.0484 1780 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 14:24:42.0503 1780 sbp2port - ok 14:24:42.0524 1780 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 14:24:42.0586 1780 SCardSvr - ok 14:24:42.0612 1780 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 14:24:42.0667 1780 scfilter - ok 14:24:42.0713 1780 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 14:24:42.0792 1780 Schedule - ok 14:24:42.0820 1780 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 14:24:42.0866 1780 SCPolicySvc - ok 14:24:42.0891 1780 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 14:24:42.0917 1780 SDRSVC - ok 14:24:42.0943 1780 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 14:24:42.0991 1780 secdrv - ok 14:24:43.0026 1780 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 14:24:43.0087 1780 seclogon - ok 14:24:43.0107 1780 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 14:24:43.0171 1780 SENS - ok 14:24:43.0187 1780 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 14:24:43.0230 1780 SensrSvc - ok 14:24:43.0239 1780 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 14:24:43.0267 1780 Serenum - ok 14:24:43.0289 1780 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 14:24:43.0316 1780 Serial - ok 14:24:43.0339 1780 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 14:24:43.0369 1780 sermouse - ok 14:24:43.0391 1780 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 14:24:43.0440 1780 SessionEnv - ok 14:24:43.0460 1780 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 14:24:43.0496 1780 sffdisk - ok 14:24:43.0509 1780 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 14:24:43.0535 1780 sffp_mmc - ok 14:24:43.0547 1780 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 14:24:43.0569 1780 sffp_sd - ok 14:24:43.0583 1780 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 14:24:43.0601 1780 sfloppy - ok 14:24:43.0629 1780 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 14:24:43.0681 1780 ShellHWDetection - ok 14:24:43.0699 1780 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 14:24:43.0716 1780 SiSRaid2 - ok 14:24:43.0734 1780 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 14:24:43.0752 1780 SiSRaid4 - ok 14:24:43.0784 1780 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 14:24:43.0843 1780 Smb - ok 14:24:43.0891 1780 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 14:24:43.0923 1780 SNMPTRAP - ok 14:24:43.0938 1780 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 14:24:43.0955 1780 spldr - ok 14:24:43.0994 1780 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 14:24:44.0046 1780 Spooler - ok 14:24:44.0138 1780 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 14:24:44.0250 1780 sppsvc - ok 14:24:44.0272 1780 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 14:24:44.0335 1780 sppuinotify - ok 14:24:44.0368 1780 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 14:24:44.0408 1780 srv - ok 14:24:44.0438 1780 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 14:24:44.0473 1780 srv2 - ok 14:24:44.0487 1780 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 14:24:44.0518 1780 srvnet - ok 14:24:44.0552 1780 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys 14:24:44.0590 1780 ssadbus - ok 14:24:44.0622 1780 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys 14:24:44.0645 1780 ssadmdfl - ok 14:24:44.0660 1780 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys 14:24:44.0694 1780 ssadmdm - ok 14:24:44.0712 1780 [ D33D1BD3EC0E766211A234F56A12726D ] ssadserd C:\Windows\system32\DRIVERS\ssadserd.sys 14:24:44.0736 1780 ssadserd - ok 14:24:44.0764 1780 [ ED161B91FDF7EAA39469D72D463D5F4E ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys 14:24:44.0783 1780 sscdbus - ok 14:24:44.0800 1780 [ 4CB09E77593DBD8D7AF33B37375CA715 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys 14:24:44.0816 1780 sscdmdfl - ok 14:24:44.0836 1780 [ C7B4CF53497A6E5363F3439427663882 ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys 14:24:44.0855 1780 sscdmdm - ok 14:24:44.0884 1780 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 14:24:44.0948 1780 SSDPSRV - ok 14:24:44.0966 1780 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 14:24:45.0018 1780 SstpSvc - ok 14:24:45.0046 1780 Steam Client Service - ok 14:24:45.0106 1780 [ A766CCAD980235FF34E7F8089D3175A3 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 14:24:45.0129 1780 Stereo Service - ok 14:24:45.0165 1780 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 14:24:45.0181 1780 stexstor - ok 14:24:45.0230 1780 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 14:24:45.0267 1780 stisvc - ok 14:24:45.0283 1780 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 14:24:45.0300 1780 storflt - ok 14:24:45.0322 1780 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys 14:24:45.0338 1780 storvsc - ok 14:24:45.0357 1780 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 14:24:45.0374 1780 swenum - ok 14:24:45.0399 1780 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 14:24:45.0467 1780 swprv - ok 14:24:45.0484 1780 Synth3dVsc - ok 14:24:45.0545 1780 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 14:24:45.0610 1780 SysMain - ok 14:24:45.0633 1780 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 14:24:45.0670 1780 TabletInputService - ok 14:24:45.0693 1780 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 14:24:45.0753 1780 TapiSrv - ok 14:24:45.0771 1780 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 14:24:45.0821 1780 TBS - ok 14:24:45.0877 1780 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys 14:24:45.0940 1780 Tcpip - ok 14:24:45.0981 1780 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 14:24:46.0036 1780 TCPIP6 - ok 14:24:46.0072 1780 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 14:24:46.0124 1780 tcpipreg - ok 14:24:46.0154 1780 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 14:24:46.0192 1780 TDPIPE - ok 14:24:46.0216 1780 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 14:24:46.0249 1780 TDTCP - ok 14:24:46.0279 1780 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 14:24:46.0327 1780 tdx - ok 14:24:46.0337 1780 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 14:24:46.0355 1780 TermDD - ok 14:24:46.0390 1780 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 14:24:46.0475 1780 TermService - ok 14:24:46.0499 1780 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 14:24:46.0533 1780 Themes - ok 14:24:46.0551 1780 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 14:24:46.0600 1780 THREADORDER - ok 14:24:46.0617 1780 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 14:24:46.0676 1780 TrkWks - ok 14:24:46.0707 1780 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 14:24:46.0766 1780 TrustedInstaller - ok 14:24:46.0800 1780 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 14:24:46.0854 1780 tssecsrv - ok 14:24:46.0886 1780 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 14:24:46.0927 1780 TsUsbFlt - ok 14:24:46.0932 1780 tsusbhub - ok 14:24:46.0982 1780 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 14:24:47.0042 1780 tunnel - ok 14:24:47.0065 1780 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 14:24:47.0083 1780 uagp35 - ok 14:24:47.0114 1780 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 14:24:47.0166 1780 udfs - ok 14:24:47.0191 1780 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 14:24:47.0224 1780 UI0Detect - ok 14:24:47.0237 1780 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 14:24:47.0254 1780 uliagpkx - ok 14:24:47.0280 1780 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 14:24:47.0305 1780 umbus - ok 14:24:47.0322 1780 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 14:24:47.0339 1780 UmPass - ok 14:24:47.0363 1780 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll 14:24:47.0396 1780 UmRdpService - ok 14:24:47.0414 1780 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 14:24:47.0487 1780 upnphost - ok 14:24:47.0507 1780 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 14:24:47.0547 1780 usbccgp - ok 14:24:47.0571 1780 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 14:24:47.0594 1780 usbcir - ok 14:24:47.0606 1780 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 14:24:47.0624 1780 usbehci - ok 14:24:47.0638 1780 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 14:24:47.0674 1780 usbhub - ok 14:24:47.0688 1780 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 14:24:47.0709 1780 usbohci - ok 14:24:47.0726 1780 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 14:24:47.0758 1780 usbprint - ok 14:24:47.0779 1780 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 14:24:47.0816 1780 USBSTOR - ok 14:24:47.0829 1780 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 14:24:47.0852 1780 usbuhci - ok 14:24:47.0872 1780 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 14:24:47.0933 1780 UxSms - ok 14:24:47.0949 1780 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 14:24:47.0967 1780 VaultSvc - ok 14:24:47.0988 1780 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 14:24:48.0004 1780 vdrvroot - ok 14:24:48.0039 1780 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 14:24:48.0106 1780 vds - ok 14:24:48.0131 1780 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 14:24:48.0153 1780 vga - ok 14:24:48.0167 1780 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 14:24:48.0216 1780 VgaSave - ok 14:24:48.0229 1780 VGPU - ok 14:24:48.0284 1780 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 14:24:48.0317 1780 vhdmp - ok 14:24:48.0366 1780 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 14:24:48.0382 1780 viaide - ok 14:24:48.0412 1780 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys 14:24:48.0432 1780 vmbus - ok 14:24:48.0455 1780 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 14:24:48.0479 1780 VMBusHID - ok 14:24:48.0494 1780 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 14:24:48.0511 1780 volmgr - ok 14:24:48.0541 1780 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 14:24:48.0564 1780 volmgrx - ok 14:24:48.0579 1780 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 14:24:48.0602 1780 volsnap - ok 14:24:48.0626 1780 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 14:24:48.0647 1780 vsmraid - ok 14:24:48.0695 1780 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 14:24:48.0792 1780 VSS - ok 14:24:48.0808 1780 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 14:24:48.0839 1780 vwifibus - ok 14:24:48.0869 1780 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 14:24:48.0933 1780 W32Time - ok 14:24:48.0951 1780 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 14:24:48.0982 1780 WacomPen - ok 14:24:49.0006 1780 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 14:24:49.0067 1780 WANARP - ok 14:24:49.0072 1780 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 14:24:49.0119 1780 Wanarpv6 - ok 14:24:49.0171 1780 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 14:24:49.0252 1780 wbengine - ok 14:24:49.0268 1780 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 14:24:49.0296 1780 WbioSrvc - ok 14:24:49.0324 1780 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 14:24:49.0362 1780 wcncsvc - ok 14:24:49.0381 1780 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 14:24:49.0405 1780 WcsPlugInService - ok 14:24:49.0419 1780 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 14:24:49.0436 1780 Wd - ok 14:24:49.0461 1780 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 14:24:49.0495 1780 Wdf01000 - ok 14:24:49.0507 1780 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 14:24:49.0581 1780 WdiServiceHost - ok 14:24:49.0585 1780 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 14:24:49.0612 1780 WdiSystemHost - ok 14:24:49.0633 1780 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 14:24:49.0673 1780 WebClient - ok 14:24:49.0688 1780 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 14:24:49.0744 1780 Wecsvc - ok 14:24:49.0757 1780 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 14:24:49.0819 1780 wercplsupport - ok 14:24:49.0846 1780 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 14:24:49.0897 1780 WerSvc - ok 14:24:49.0925 1780 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 14:24:49.0972 1780 WfpLwf - ok 14:24:49.0986 1780 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 14:24:50.0008 1780 WIMMount - ok 14:24:50.0014 1780 WinHttpAutoProxySvc - ok 14:24:50.0075 1780 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 14:24:50.0125 1780 Winmgmt - ok 14:24:50.0181 1780 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 14:24:50.0278 1780 WinRM - ok 14:24:50.0336 1780 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 14:24:50.0385 1780 Wlansvc - ok 14:24:50.0403 1780 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 14:24:50.0429 1780 WmiAcpi - ok 14:24:50.0452 1780 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 14:24:50.0486 1780 wmiApSrv - ok 14:24:50.0518 1780 WMPNetworkSvc - ok 14:24:50.0535 1780 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 14:24:50.0568 1780 WPCSvc - ok 14:24:50.0587 1780 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 14:24:50.0610 1780 WPDBusEnum - ok 14:24:50.0629 1780 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 14:24:50.0689 1780 ws2ifsl - ok 14:24:50.0694 1780 WSearch - ok 14:24:50.0768 1780 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 14:24:50.0844 1780 wuauserv - ok 14:24:50.0877 1780 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 14:24:50.0925 1780 WudfPf - ok 14:24:50.0961 1780 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 14:24:51.0024 1780 WUDFRd - ok 14:24:51.0050 1780 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 14:24:51.0099 1780 wudfsvc - ok 14:24:51.0131 1780 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 14:24:51.0162 1780 WwanSvc - ok 14:24:51.0198 1780 [ 2EE48CFCE7CA8E0DB4C44C7476C0943B ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys 14:24:51.0221 1780 xusb21 - ok 14:24:51.0225 1780 ================ Scan global =============================== 14:24:51.0250 1780 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 14:24:51.0275 1780 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 14:24:51.0286 1780 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 14:24:51.0309 1780 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 14:24:51.0342 1780 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 14:24:51.0347 1780 [Global] - ok 14:24:51.0347 1780 ================ Scan MBR ================================== 14:24:51.0360 1780 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk1\DR1 14:24:51.0416 1780 \Device\Harddisk1\DR1 - ok 14:24:51.0419 1780 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 14:24:51.0891 1780 \Device\Harddisk0\DR0 - ok 14:24:51.0891 1780 ================ Scan VBR ================================== 14:24:51.0918 1780 [ 2BEBDFDDEE481CE2AE9E0679E70459CE ] \Device\Harddisk1\DR1\Partition1 14:24:51.0919 1780 \Device\Harddisk1\DR1\Partition1 - ok 14:24:51.0937 1780 [ 59AA407565D0CEF57D3AA9726BFDEBC4 ] \Device\Harddisk1\DR1\Partition2 14:24:51.0938 1780 \Device\Harddisk1\DR1\Partition2 - ok 14:24:51.0942 1780 [ 9DE75C04EA8F39CF9EE04AAC50DFA51A ] \Device\Harddisk0\DR0\Partition1 14:24:51.0943 1780 \Device\Harddisk0\DR0\Partition1 - ok 14:24:51.0944 1780 ============================================================ 14:24:51.0944 1780 Scan finished 14:24:51.0944 1780 ============================================================ 14:24:51.0956 3444 Detected object count: 0 14:24:51.0956 3444 Actual detected object count: 0 Okay, das Problem mit mystart konnte ich teilweise beheben, habe im about:config die browser.newtab.url & browser.search.defaultenginename zurück gesetzt. Ich vermute allerdings trotzdem, dass da noch Adware läuft !? |
19.09.2012, 12:30 | #38 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenZitat:
Warum verschweigst du was genau du dir aus dem Netz gezogen hast und warum die genaue Meldung des Virenscanners! Mit dem Schädlingsnamen allein ist es nicht getan....
__________________ Logfiles bitte immer in CODE-Tags posten |
19.09.2012, 12:45 | #39 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Entschuldigung, da steckte keine Absicht hinter. Ich wollte mir via torrent ein Spiel für den Dolphin Emulator ziehen, ein Spiel von der Nintendo Wii. Auf der Suche nach einem Anbieter klickte ich auf einen link, nachdem eine einige kb große Datein installiert wurde. Sofort darauf piepte antivir hektisch drei- bis viermal und es meldete, dass Adware.Gen detektiert wurde. Beim kurzen Nachlesen im Netz las ich, dass antivir diesen Schädling zumindest in Quarantäne verschieben kann. Also habe ich antivir komplett durchlaufen lassen und anschließend teilte mir antivir mit, dass eine vollständige Löschung der Plagegeister einen Neustart bräuchte. Ich startete anschließend den Rechner neu und ließ antivir erneut komplett durchlaufen, allerdings ohne einen eizigen Fund. Den log habe ich nicht gespeichert, da ich vorher gelesen hatte, antivir könne das Problem beseitigen. |
19.09.2012, 16:07 | #40 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Genau deswegen lässt man ja auch die Finger von so einem Dreck aus unseriösen Quellen! Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
20.09.2012, 16:53 | #41 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenCode:
ATTFilter Combofix Logfile: |
20.09.2012, 20:19 | #42 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Combofix - Scripten 1. Starte das Notepad (Start / Ausführen / notepad[Enter]) 2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein. Code:
ATTFilter File:: C:\user.js Firefox:: FF - ProfilePath - c:\users\HeftigDerBoss\AppData\Roaming\Mozilla\Firefox\Profiles\wtqlaods.default\ FF - prefs.js: browser.search.selectedEngine - MyStart Search FF - prefs.js: keyword.URL - http://mystart.incredibar.com/mb139/?loc=IB_DS&a=6R8Fy0314c&&i=26&search= FF - user.js: extensions.incredibar_i.ms_url_id - FF - user.js: extensions.incredibar_i.upn2 - 6R8Fy0314c FF - user.js: extensions.incredibar_i.upn2n - 92825077749324784 FF - user.js: extensions.incredibar_i.productid - 26 FF - user.js: extensions.incredibar_i.installerproductid - 26 FF - user.js: extensions.incredibar_i.did - 10650 FF - user.js: extensions.incredibar_i.ppd - 140%5F5 FF - user.js: extensions.incredibar_i.newTab - false FF - user.js: extensions.incredibar_i.tlbrSrchUrl - http://mystart.Incredibar.com/?a=6R8Fy0314c&loc=IB_TB&i=26&search= FF - user.js: extensions.incredibar_i.id - 94805e8a0000000000000019dbe80e53 FF - user.js: extensions.incredibar_i.instlDay - 15601 FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14 FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14 FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1415:34 FF - user.js: extensions.incredibar_i.prtnrId - Incredibar FF - user.js: extensions.incredibar_i.prdct - incredibar FF - user.js: extensions.incredibar_i.aflt - orgnl FF - user.js: extensions.incredibar_i.smplGrp - none FF - user.js: extensions.incredibar_i.tlbrId - base FF - user.js: extensions.incredibar_i.instlRef - FF - user.js: extensions.incredibar_i.dfltLng - FF - user.js: extensions.incredibar_i.excTlbr - false 4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall. (Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !) 5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet. 6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien: Combofix.txt Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten |
21.09.2012, 15:16 | #43 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.GenCode:
ATTFilter Combofix Logfile: |
21.09.2012, 20:31 | #44 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM! Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes: Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________ Logfiles bitte immer in CODE-Tags posten |
27.09.2012, 08:27 | #45 |
| Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen Sorry, ich war ein paar Tage bei meiner Freundin, erst seit gestern abend wieder zu Hause. Code:
ATTFilter GMER Logfile: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 09:35:22 on 27.09.2012 OS: Windows 7 Ultimate Edition Service Pack 1 (Build 7601), 64-bit Default Browser: Mozilla Corporation Firefox 15.0.1 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "WxDFastUpdaterTask{AF875C55-DECD-4BB6-BD69-4807323F9A4C}.job" - ? - C:\ProgramData\Premium\WxDFast\WxDFast.exe (File found, but it contains no detailed information) [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "@%SystemRoot%\system32\drivers\tsusbhub.sys,-1" (tsusbhub) - ? - C:\Windows\System32\drivers\tsusbhub.sys (File not found) "avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys "avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys "avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys "catchme" (catchme) - ? - C:\ComboFix\catchme.sys (File not found) "Driver for MagicISO SCSI Host Controller" (mcdbus) - "MagicISO, Inc." - C:\Windows\System32\DRIVERS\mcdbus.sys "Synth3dVsc" (Synth3dVsc) - ? - C:\Windows\System32\drivers\synth3dvsc.sys (File not found) "VGPU" (VGPU) - ? - C:\Windows\System32\drivers\rdvgkmd.sys (File not found) [Explorer] -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll -----( HKLM\Software\Classes\Protocols\Handler )----- {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {E6FB5E20-DE35-11CF-9C87-00AA005127ED} "WebCheck" - ? - (File not found | COM-object registry key not found) {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - D:\Programme\rarext.dll {B41DB860-64E4-11D2-9906-E49FADC173CA} "WinRAR shell extension" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad )----- {E6FB5E20-DE35-11CF-9C87-00AA005127ED} "WebCheck" - ? - (File not found | COM-object registry key not found) [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- {F9639E4A-801B-4843-AEE3-03D9DA199E77} "Incredibar Toolbar" - ? - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll (File not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} "Incredibar.com Helper Object" - ? - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll (File not found) {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\HeftigDerBoss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "MagicDisc.lnk" - "MagicISO, Inc." - D:\Program Files (x86)\MagicDisc\MagicDisc.exe (Shortcut exists | File exists) -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "KiesHelper" - "Samsung" - C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s "KiesPDLR" - ? - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe "Steam" - "Valve Corporation" - "G:\Steam\steam.exe" -silent -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min "KiesTrayAgent" - "Samsung Electronics Co., Ltd." - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll (File not found) "@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe" (File not found) "Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe "Avira Realtime Protection" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe "Avira Scheduler" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe "Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe "NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe "NVIDIA Stereoscopic 3D Driver Service" (Stereo Service) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe "NVIDIA Update Service Daemon" (nvUpdatusService) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe "Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files (x86)\Common Files\Steam\SteamService.exe ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Code:
ATTFilter aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-09-27 09:39:53 ----------------------------- 09:39:53.637 OS Version: Windows x64 6.1.7601 Service Pack 1 09:39:53.637 Number of processors: 2 586 0xF06 09:39:53.637 ComputerName: HEFTIGDERBOSS-P UserName: HeftigDerBoss 09:39:54.168 Initialize success 09:59:49.331 AVAST engine defs: 12092601 10:23:46.734 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T1L0-6 10:23:46.737 Disk 0 Vendor: SAMSUNG_HD103SJ 1AJ10001 Size: 953869MB BusType: 3 10:23:46.740 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-3 10:23:46.743 Disk 1 Vendor: SAMSUNG_HD501LJ CR100-12 Size: 476940MB BusType: 3 10:23:46.752 Disk 1 MBR read successfully 10:23:46.755 Disk 1 MBR scan 10:23:46.762 Disk 1 Windows VISTA default MBR code 10:23:46.771 Disk 1 Partition 1 00 07 HPFS/NTFS NTFS 130000 MB offset 2048 10:23:46.790 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 346938 MB offset 266242048 10:23:46.823 Disk 1 scanning C:\Windows\system32\drivers 10:23:54.752 Service scanning 10:24:11.005 Modules scanning 10:24:11.015 Disk 1 trace - called modules: 10:24:11.417 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 10:24:11.423 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa80033f2730] 10:24:11.429 3 CLASSPNP.SYS[fffff8800191943f] -> nt!IofCallDriver -> [0xfffffa8002443e40] 10:24:11.436 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0xfffffa800307c680] 10:24:11.954 AVAST engine scan C:\Windows 10:24:13.572 AVAST engine scan C:\Windows\system32 10:26:40.714 AVAST engine scan C:\Windows\system32\drivers 10:26:49.258 AVAST engine scan C:\Users\HeftigDerBoss 10:30:04.049 AVAST engine scan C:\ProgramData 10:30:33.945 Scan finished successfully 10:33:30.562 Disk 1 MBR has been saved successfully to "C:\Users\HeftigDerBoss\Desktop\MBR.dat" 10:33:30.569 The log file has been saved successfully to "C:\Users\HeftigDerBoss\Desktop\aswMBR.txt" Geändert von copatin (27.09.2012 um 08:39 Uhr) |
Themen zu Avira meldet TR/Jorik.Totem.vz, TR/ATRAPS.Gen2, T/ATRAPS.Gen |
administrator, adobe, antivir, autorun, avg, avira, bho, explorer, firefox, format, google, helper, herunterfahren, log, logfile, löschen, neu aufgesetzt, neustart, nvidia, opera, plug-in, programme, registry, software, suchmaschine, temp, trojaner-board |