|
Log-Analyse und Auswertung: Internetverbindung, USB, Mails.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.01.2013, 23:49 | #1 |
| Internetverbindung, USB, Mails. allo an alle und vielen Dank im voraus für eure Hilfe!! Mein Problem hat vor ca. 1 Monat angefangen (ist es mir aufgefallen). Wir haben ne 2000 Leitung, die reicht uns auch, aber die Download Geschwindigkeit ist extrem eingebrochen. Wir können noch mit max. 0,50 Mbit Surfen (Youtube und co.), der Upload ist nach wie vor bei 0,42 Mbit stabil. Der Provider muss einem ja nicht die die volle Bandbreite der gebuchten Option zur Verfügung stellen, hat er aber getan bis vor 4 Wochen. Als ich mich im Forum angemeldet habe, stand auf euer Seite ich müsse den Aktivierungs link in der Email die Ihr mir geschickt habt um meinen Account zu aktivieren anklicken. Ich benutze Windows Live Mail und normalerweise wird JEDE Mail weitergeleitet, nur die vom TB nicht, eure Mail habe ich erst im Spam Ordner auf gmx.net gefunden. Ich finde das sehr merkwürdig mit der Mail weil es die einzige ist die nicht in Windows Mail aufgetaucht ist. Meine USB Geräte werden alle erkannt beim Hochfahren des Computers, außer der Maus, die funktioniert immer erste nach dem man den USB Stick entfernt hat und neu einsteckt. Seit ein paar Tagen bekomme ich von Google diese Meldung wenn ich etwas im Inet Suche: "Unsere Systeme haben ungewöhnlichen Datenverkehr aus Ihrem Computernetzwerk festgestellt. Diese Seite überprüft, ob die Anfragen wirklich von Ihnen und nicht von einem Robot gesendet werden" das kommt mir komisch vor. Ich Poste mal die Logs von meinen Virenscannern: HijackThis startuplist StartupList report, 13.01.2013, 16:20:43 StartupList version: 1.52.2 Started from : C:\Users\7\Desktop\HiJackThis204.EXE Detected: Windows 7 SP1 (WinNT 6.00.3505) Detected: Internet Explorer v9.00 (9.00.8112.16457) * Using default options * Including empty and uninteresting sections * Showing rarely important sections ================================================== Running processes: C:\Users\7\Desktop\HiJackThis204.exe C:\Program Files (x86)\Opera\Opera.exe -------------------------------------------------- Listing of startup folders: Shell folders Startup: [C:\Users\7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup] *No files* Shell folders AltStartup: *Folder not found* User shell folders Startup: *Folder not found* User shell folders AltStartup: *Folder not found* Shell folders Common Startup: [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup] *No files* Shell folders Common AltStartup: *Folder not found* User shell folders Common Startup: *Folder not found* User shell folders Alternate Common Startup: *Folder not found* -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = userinit.exe, [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] *Registry value not found* [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run Adobe ARM = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- File association entry for .EXE: HKEY_CLASSES_ROOT\exefile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .COM: HKEY_CLASSES_ROOT\comfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .BAT: HKEY_CLASSES_ROOT\batfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .PIF: HKEY_CLASSES_ROOT\piffile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .SCR: HKEY_CLASSES_ROOT\scrfile\shell\open\command (Default) = "%1" /S -------------------------------------------------- File association entry for .HTA: HKEY_CLASSES_ROOT\htafile\shell\open\command (Default) = C:\Windows\SysWOW64\mshta.exe "%1" %* -------------------------------------------------- File association entry for .TXT: HKEY_CLASSES_ROOT\txtfile\shell\open\command (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1 -------------------------------------------------- Enumerating Active Setup stub paths: HKLM\Software\Microsoft\Active Setup\Installed Components (* = disabled by HKCU twin) [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] StubPath = %SystemRoot%\system32\unregmp2.exe /ShowWMP [>{26923b43-4d38-484f-9b9e-de460746276c}] * StubPath = C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] * StubPath = "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] * StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] * StubPath = "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] * StubPath = %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI [{89820200-ECBD-11cf-8B85-00AA005B4340}] * StubPath = regsvr32.exe /s /n /i:U shell32.dll [{89820200-ECBD-11cf-8B85-00AA005B4383}] * StubPath = C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] * StubPath = C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install -------------------------------------------------- Enumerating ICQ Agent Autostart apps: HKCU\Software\Mirabilis\ICQ\Agent\Apps *Registry key not found* -------------------------------------------------- Load/Run keys from C:\Windows\WIN.INI: load=*INI section not found* run=*INI section not found* Load/Run keys from Registry: HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs= -------------------------------------------------- Shell & screensaver key from C:\Windows\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=explorer.exe SCRNSAVE.EXE=*Registry value not found* drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Checking for EXPLORER.EXE instances: C:\Windows\Explorer.exe: PRESENT! C:\Explorer.exe: not present C:\Windows\Explorer\Explorer.exe: not present C:\Windows\System\Explorer.exe: not present C:\Windows\System32\Explorer.exe: not present C:\Windows\Command\Explorer.exe: not present C:\Windows\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe: not hidden .com: not hidden .bat: not hidden .hta: not hidden .scr: not hidden .shs: *Registry key not found* .shb: *Registry key not found* .vbs: not hidden .vbe: not hidden .wsh: not hidden .scf: HIDDEN! (arrow overlay: NO!) .url: HIDDEN! (arrow overlay: yes) .js: not hidden .jse: not hidden -------------------------------------------------- Verifying REGEDIT.EXE integrity: - Regedit.exe found in C:\Windows - .reg open command is normal (regedit.exe %1) - Company name OK: 'Microsoft Corporation' - Original filename NOT OK: 'REGEDIT.EXE.MUI' - File description: 'Registrierungs-Editor' Registry check failed! -------------------------------------------------- Enumerating Browser Helper Objects: HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll - {0347C33E-8762-4905-BF09-768834316C61} AcroIEHelperStub - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} Increase performance and video formats for your HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll - {326E768D-4182-46FD-9C16-1449A49795F4} (no name) - C:\Program Files (x86)\Java\jre7\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (no name) - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6} (no name) - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9} HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -------------------------------------------------- Enumerating Task Scheduler jobs: Adobe Flash Player Updater.job GoogleUpdateTaskUserS-1-5-21-1394040420-131216282-2665522858-1000Core.job GoogleUpdateTaskUserS-1-5-21-1394040420-131216282-2665522858-1000UA.job -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #1: C:\Windows\system32\NLAapi.dll NameSpace #2: C:\Windows\system32\napinsp.dll NameSpace #3: C:\Windows\system32\pnrpnsp.dll NameSpace #4: C:\Windows\system32\pnrpnsp.dll NameSpace #5: C:\Windows\System32\mswsock.dll NameSpace #6: C:\Windows\System32\winrnr.dll NameSpace #7: C:\Program Files (x86)\Bonjour\mdnsNSP.dll NameSpace #8: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL NameSpace #9: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Protocol #1: C:\Windows\system32\mswsock.dll Protocol #2: C:\Windows\system32\mswsock.dll Protocol #3: C:\Windows\system32\mswsock.dll Protocol #4: C:\Windows\system32\mswsock.dll Protocol #5: C:\Windows\system32\mswsock.dll Protocol #6: C:\Windows\system32\mswsock.dll Protocol #7: C:\Windows\system32\mswsock.dll Protocol #8: C:\Windows\system32\mswsock.dll Protocol #9: C:\Windows\system32\mswsock.dll Protocol #10: C:\Windows\system32\mswsock.dll -------------------------------------------------- Enumerating Windows NT/2000/XP services 1394 OHCI Compliant Host Controller: \SystemRoot\system32\drivers\1394ohci.sys (manual start) Microsoft ACPI-Treiber: system32\drivers\ACPI.sys (system) ACPI Power Meter Driver: \SystemRoot\system32\drivers\acpipmi.sys (manual start) Ad-Aware Service: "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe" (autostart) Adobe Acrobat Update Service: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" (autostart) Adobe Flash Player Update Service: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (manual start) adp94xx: \SystemRoot\system32\drivers\adp94xx.sys (manual start) adpahci: \SystemRoot\system32\drivers\adpahci.sys (manual start) adpu320: \SystemRoot\system32\drivers\adpu320.sys (manual start) @%SystemRoot%\system32\aelupsvc.dll,-1: %systemroot%\system32\svchost.exe -k netsvcs (manual start) @%systemroot%\system32\drivers\afd.sys,-1000: \SystemRoot\system32\drivers\afd.sys (system) Intel AGP Bus Filter: \SystemRoot\system32\drivers\agp440.sys (manual start) @%SystemRoot%\system32\Alg.exe,-112: %SystemRoot%\System32\alg.exe (manual start) aliide: \SystemRoot\system32\drivers\aliide.sys (manual start) amdide: \SystemRoot\system32\drivers\amdide.sys (manual start) AMD K8 Processor Driver: \SystemRoot\system32\drivers\amdk8.sys (manual start) AMD-Prozessortreiber: system32\DRIVERS\amdppm.sys (manual start) amdsata: \SystemRoot\system32\drivers\amdsata.sys (manual start) amdsbs: \SystemRoot\system32\drivers\amdsbs.sys (manual start) amdxata: system32\drivers\amdxata.sys (system) @%systemroot%\system32\appidsvc.dll,-102: \SystemRoot\system32\drivers\appid.sys (manual start) @%systemroot%\system32\appidsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) @%systemroot%\system32\appinfo.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) @appmgmts.dll,-3250: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) arc: \SystemRoot\system32\drivers\arc.sys (manual start) arcsas: \SystemRoot\system32\drivers\arcsas.sys (manual start) @%systemroot%\system32\rascfg.dll,-32000: system32\DRIVERS\asyncmac.sys (manual start) IDE-Kanal: system32\drivers\atapi.sys (system) @%SystemRoot%\system32\audiosrv.dll,-204: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\audiosrv.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (autostart) @%SystemRoot%\system32\AxInstSV.dll,-103: %SystemRoot%\system32\svchost.exe -k AxInstSVGroup (manual start) Broadcom NetXtreme II VBD: \SystemRoot\system32\drivers\bxvbda.sys (manual start) Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0: system32\DRIVERS\b57nd60a.sys (manual start) @%SystemRoot%\system32\bdesvc.dll,-100: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\system32\bfe.dll,-1001: %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork (autostart) @%SystemRoot%\system32\qmgr.dll,-1000: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) blbdrive: system32\DRIVERS\blbdrive.sys (system) Dienst "Bonjour": "C:\Program Files (x86)\Bonjour\mDNSResponder.exe" (autostart) @%systemroot%\system32\browser.dll,-102: system32\DRIVERS\bowser.sys (manual start) Brother USB Mass-Storage Lower Filter Driver: \SystemRoot\system32\drivers\BrFiltLo.sys (manual start) Brother USB Mass-Storage Upper Filter Driver: \SystemRoot\system32\drivers\BrFiltUp.sys (manual start) @%systemroot%\system32\browser.dll,-100: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Brother MFC Serial Port Interface Driver (WDM): \SystemRoot\System32\Drivers\Brserid.sys (manual start) Brother WDM Serial driver: \SystemRoot\System32\Drivers\BrSerWdm.sys (manual start) Brother MFC USB Fax Only Modem: \SystemRoot\System32\Drivers\BrUsbMdm.sys (manual start) Brother MFC USB Serial WDM Driver: \SystemRoot\System32\Drivers\BrUsbSer.sys (manual start) Bluetooth Serial Communications Driver: \SystemRoot\system32\drivers\bthmodem.sys (manual start) @%SystemRoot%\System32\bthserv.dll,-101: %SystemRoot%\system32\svchost.exe -k bthsvcs (manual start) CD/DVD File System Reader: system32\DRIVERS\cdfs.sys (disabled) CD-ROM-Laufwerktreiber: system32\DRIVERS\cdrom.sys (system) @%SystemRoot%\System32\certprop.dll,-11: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) Consumer IR Devices: \SystemRoot\system32\drivers\circlass.sys (manual start) @%SystemRoot%\system32\clfs.sys,-100: System32\CLFS.sys (system) Microsoft .NET Framework NGEN v2.0.50727_X86: %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (disabled) Microsoft .NET Framework NGEN v2.0.50727_X64: %systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (disabled) Microsoft .NET Framework NGEN v4.0.30319_X86: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (autostart) Microsoft .NET Framework NGEN v4.0.30319_X64: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (autostart) Microsoft ACPI Control Method Battery Driver: \SystemRoot\system32\drivers\CmBatt.sys (manual start) cmdide: \SystemRoot\system32\drivers\cmdide.sys (manual start) : System32\Drivers\cng.sys (system) Compbatt: \SystemRoot\system32\drivers\compbatt.sys (manual start) Busenumeratortreiber für Verbundgeräte: system32\DRIVERS\CompositeBus.sys (manual start) @comres.dll,-947: %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start) cpuz135: \??\C:\Windows\system32\drivers\cpuz135_x64.sys (autostart) Crcdisk Filter Driver: \SystemRoot\system32\drivers\crcdisk.sys (disabled) @%SystemRoot%\system32\cryptsvc.dll,-1001: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart) @%systemroot%\system32\cscsvc.dll,-202: system32\drivers\csc.sys (system) @%systemroot%\system32\cscsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @oleres.dll,-5012: %SystemRoot%\system32\svchost.exe -k DcomLaunch (autostart) @%SystemRoot%\system32\defragsvc.dll,-101: %SystemRoot%\system32\svchost.exe -k defragsvc (manual start) @%systemroot%\system32\drivers\dfsc.sys,-101: System32\Drivers\dfsc.sys (system) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.): system32\DRIVERS\ssudbus.sys (manual start) @%SystemRoot%\system32\dhcpcore.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (autostart) @%systemroot%\system32\drivers\discache.sys,-102: System32\drivers\discache.sys (system) Laufwerktreiber: system32\drivers\disk.sys (system) dmvsc: \SystemRoot\system32\drivers\dmvsc.sys (manual start) @%SystemRoot%\System32\dnsapi.dll,-101: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart) @%systemroot%\system32\dot3svc.dll,-1102: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) MS IEEE-1284.4 Driver: system32\DRIVERS\Dot4.sys (manual start) Print Class Driver for IEEE-1284.4: system32\DRIVERS\Dot4Prt.sys (manual start) MS Dot4USB Filter Dot4USB Filter: system32\DRIVERS\dot4usb.sys (manual start) @%systemroot%\system32\dps.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork (autostart) Microsoft Trusted Audio Drivers: system32\drivers\drmkaud.sys (manual start) LDDM Graphics Subsystem: \SystemRoot\System32\drivers\dxgkrnl.sys (manual start) eamonm: system32\DRIVERS\eamonm.sys (system) @%systemroot%\system32\eapsvc.dll,-1: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Broadcom NetXtreme II 10 GigE VBD: \SystemRoot\system32\drivers\evbda.sys (manual start) @%SystemRoot%\system32\efssvc.dll,-100: %SystemRoot%\System32\lsass.exe (manual start) ehdrv: system32\DRIVERS\ehdrv.sys (system) @%SystemRoot%\ehome\ehrecvr.exe,-101: %systemroot%\ehome\ehRecvr.exe (manual start) @%SystemRoot%\ehome\ehsched.exe,-101: %systemroot%\ehome\ehsched.exe (manual start) ESET Service: "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" (autostart) elxstor: \SystemRoot\system32\drivers\elxstor.sys (manual start) epfwwfpr: system32\DRIVERS\epfwwfpr.sys (autostart) Microsoft Hardware Error Device Driver: \SystemRoot\system32\drivers\errdev.sys (manual start) @%SystemRoot%\system32\wevtsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (autostart) @comres.dll,-2450: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) @%systemroot%\system32\fxsresm.dll,-118: %systemroot%\system32\fxssvc.exe (manual start) Floppy Disk Controller Driver: \SystemRoot\system32\drivers\fdc.sys (manual start) @%systemroot%\system32\fdPHost.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%systemroot%\system32\fdrespub.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) @%SystemRoot%\system32\drivers\fileinfo.sys,-100: system32\drivers\fileinfo.sys (system) @%SystemRoot%\system32\drivers\filetrace.sys,-10001: system32\drivers\filetrace.sys (manual start) Floppy Disk Driver: \SystemRoot\system32\drivers\flpydisk.sys (manual start) @%SystemRoot%\system32\drivers\fltmgr.sys,-10001: system32\drivers\fltmgr.sys (system) @%systemroot%\system32\FntCache.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (autostart) @%SystemRoot%\system32\PresentationHost.exe,-3309: %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (manual start) @%SystemRoot%\system32\drivers\fsdepends.sys,-10001: System32\drivers\FsDepends.sys (manual start) @%SystemRoot%\system32\drivers\fvevol.sys,-100: System32\DRIVERS\fvevol.sys (system) Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms: \SystemRoot\system32\drivers\gagp30kx.sys (manual start) gfibto: system32\drivers\gfibto.sys (system) @gpapi.dll,-112: %windir%\system32\svchost.exe -k GPSvcGroup (autostart) Hauppauge Consumer Infrared Receiver: \SystemRoot\system32\drivers\hcw85cir.sys (manual start) Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst: system32\drivers\HdAudio.sys (manual start) Microsoft-UAA-Bustreiber für High Definition Audio: system32\DRIVERS\HDAudBus.sys (manual start) HID UPS Battery Driver: \SystemRoot\system32\drivers\HidBatt.sys (manual start) Microsoft Bluetooth HID Miniport: \SystemRoot\system32\drivers\hidbth.sys (manual start) Microsoft Infrared HID Driver: \SystemRoot\system32\drivers\hidir.sys (manual start) @%SystemRoot%\System32\hidserv.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) Microsoft HID Class-Treiber: system32\DRIVERS\hidusb.sys (manual start) @%SystemRoot%\system32\kmsvc.dll,-6: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\System32\ListSvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%SystemRoot%\System32\provsvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (manual start) hpqcxs08: %SystemRoot%\system32\svchost.exe -k hpdevmgmt (manual start) HP CUE DeviceDiscovery Service: %SystemRoot%\system32\svchost.exe -k hpdevmgmt (autostart) HpSAMD: \SystemRoot\system32\drivers\HpSAMD.sys (manual start) HP Network Devices Support: %SystemRoot%\system32\svchost.exe -k HPService (autostart) @%SystemRoot%\system32\drivers\http.sys,-1: system32\drivers\HTTP.sys (manual start) @%systemroot%\system32\drivers\hwpolicy.sys,-101: System32\drivers\hwpolicy.sys (system) i8042 Keyboard and PS/2 Mouse Port Driver: \SystemRoot\system32\drivers\i8042prt.sys (manual start) Intel RAID-Controller Windows 7: \SystemRoot\system32\drivers\iaStorV.sys (manual start) InstallDriver Table Manager: "C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start) @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193: "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe" (manual start) iirsp: \SystemRoot\system32\drivers\iirsp.sys (manual start) @%SystemRoot%\system32\ikeext.dll,-501: %systemroot%\system32\svchost.exe -k netsvcs (manual start) intelide: \SystemRoot\system32\drivers\intelide.sys (manual start) Intel Processor Driver: \SystemRoot\system32\drivers\intelppm.sys (manual start) @%systemroot%\system32\IPBusEnum.dll,-102: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%systemroot%\system32\rascfg.dll,-32013: system32\DRIVERS\ipfltdrv.sys (manual start) @%SystemRoot%\system32\iphlpsvc.dll,-500: %SystemRoot%\System32\svchost.exe -k NetSvcs (autostart) IPMIDRV: \SystemRoot\system32\drivers\IPMIDrv.sys (manual start) IP Network Address Translator: System32\drivers\ipnat.sys (manual start) @%SystemRoot%\system32\drivers\irenum.sys,-100: system32\drivers\irenum.sys (manual start) isapnp: \SystemRoot\system32\drivers\isapnp.sys (manual start) iScsiPort Driver: \SystemRoot\system32\drivers\msiscsi.sys (manual start) Jabra Bluecore headset DFU driver: System32\Drivers\JabraMobileCsrDfuX64.sys (manual start) Tastaturklassentreiber: system32\DRIVERS\kbdclass.sys (manual start) Tastatur-HID-Treiber: system32\DRIVERS\kbdhid.sys (manual start) @keyiso.dll,-100: %SystemRoot%\system32\lsass.exe (manual start) HIDServiceDesc: system32\DRIVERS\KMWDFILTER.sys (manual start) : System32\Drivers\ksecdd.sys (system) : System32\Drivers\ksecpkg.sys (system) Kernel Streaming Thunks: \SystemRoot\system32\drivers\ksthunk.sys (manual start) @comres.dll,-2946: %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation (manual start) @%systemroot%\system32\srvsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) @%systemroot%\system32\wkssvc.dll,-100: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart) Link-Layer Topology Discovery Mapper I/O Driver: system32\DRIVERS\lltdio.sys (autostart) @%SystemRoot%\system32\lltdres.dll,-1: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\lmhsvc.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (autostart) LSI_FC: \SystemRoot\system32\drivers\lsi_fc.sys (manual start) LSI_SAS: \SystemRoot\system32\drivers\lsi_sas.sys (manual start) LSI_SAS2: \SystemRoot\system32\drivers\lsi_sas2.sys (manual start) LSI_SCSI: \SystemRoot\system32\drivers\lsi_scsi.sys (manual start) @%systemroot%\system32\drivers\luafv.sys,-100: \SystemRoot\system32\drivers\luafv.sys (autostart) @%SystemRoot%\ehome\ehres.dll,-15501: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (disabled) megasas: \SystemRoot\system32\drivers\megasas.sys (manual start) MegaSR: \SystemRoot\system32\drivers\MegaSR.sys (manual start) @%systemroot%\system32\mmcss.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) : system32\drivers\modem.sys (manual start) Microsoft Monitor-Klassenfunktionstreiber-Dienst: system32\DRIVERS\monitor.sys (manual start) Mausklassentreiber: system32\DRIVERS\mouclass.sys (manual start) Maus-HID-Treiber: system32\DRIVERS\mouhid.sys (manual start) @%SystemRoot%\system32\drivers\mountmgr.sys,-100: System32\drivers\mountmgr.sys (system) Mozilla Maintenance Service: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (manual start) mpio: \SystemRoot\system32\drivers\mpio.sys (manual start) @%SystemRoot%\system32\FirewallAPI.dll,-23092: System32\drivers\mpsdrv.sys (manual start) @%SystemRoot%\system32\FirewallAPI.dll,-23090: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork (autostart) @%systemroot%\system32\webclnt.dll,-104: \SystemRoot\system32\drivers\mrxdav.sys (manual start) @%systemroot%\system32\wkssvc.dll,-1002: system32\DRIVERS\mrxsmb.sys (manual start) @%systemroot%\system32\wkssvc.dll,-1004: system32\DRIVERS\mrxsmb10.sys (manual start) @%systemroot%\system32\wkssvc.dll,-1006: system32\DRIVERS\mrxsmb20.sys (manual start) msahci: \SystemRoot\system32\drivers\msahci.sys (manual start) msdsm: \SystemRoot\system32\drivers\msdsm.sys (manual start) @comres.dll,-2797: %SystemRoot%\System32\msdtc.exe (manual start) @%SystemRoot%\system32\drivers\mshidkmdf.sys,-100: \SystemRoot\System32\drivers\mshidkmdf.sys (manual start) msisadrv: system32\drivers\msisadrv.sys (system) @%SystemRoot%\system32\iscsidsc.dll,-5000: %systemroot%\system32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\system32\msimsg.dll,-27: %systemroot%\system32\msiexec.exe /V (manual start) Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start) Microsoft Proxy für Streaming Clock: system32\drivers\MSPCLOCK.sys (manual start) Microsoft Proxy für Streaming Quality Manager: system32\drivers\MSPQM.sys (manual start) Microsoft-Systemverwaltungs-BIOS-Treiber: system32\DRIVERS\mssmbios.sys (system) Microsoft Streaming Tee/Sink-to-Sink-Konvertierung: system32\drivers\MSTEE.sys (manual start) Microsoft Input Configuration Driver: \SystemRoot\system32\drivers\MTConfig.sys (manual start) ATK0110 ACPI UTILITY: system32\DRIVERS\ASACPI.sys (manual start) @%systemroot%\system32\drivers\mup.sys,-101: System32\Drivers\mup.sys (system) @%SystemRoot%\system32\qagentrt.dll,-6: %SystemRoot%\System32\svchost.exe -k NetworkService (manual start) NativeWiFi Filter: system32\DRIVERS\nwifi.sys (manual start) @%SystemRoot%\system32\drivers\ndis.sys,-200: system32\drivers\ndis.sys (system) NDIS Capture LightWeight Filter: system32\DRIVERS\ndiscap.sys (manual start) @%systemroot%\system32\rascfg.dll,-32001: system32\DRIVERS\ndistapi.sys (manual start) NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start) @%systemroot%\system32\rascfg.dll,-32002: system32\DRIVERS\ndiswan.sys (manual start) Net Driver HPZ12: %SystemRoot%\System32\svchost.exe -k HPZ12 (autostart) NetBIOS Interface: system32\DRIVERS\netbios.sys (system) @%SystemRoot%\system32\drivers\netbt.sys,-2: System32\DRIVERS\netbt.sys (system) @%SystemRoot%\System32\netlogon.dll,-102: %systemroot%\system32\lsass.exe (manual start) @%SystemRoot%\system32\netman.dll,-109: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%SystemRoot%\system32\netprofm.dll,-202: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201: "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" (disabled) nfrd960: \SystemRoot\system32\drivers\nfrd960.sys (manual start) @%SystemRoot%\System32\nlasvc.dll,-1: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart) @%SystemRoot%\system32\nsisvc.dll,-200: %systemroot%\system32\svchost.exe -k LocalService (autostart) @%SystemRoot%\system32\drivers\nsiproxy.sys,-2: system32\drivers\nsiproxy.sys (system) Renesas Electronics USB 3.0 Hub Driver: system32\DRIVERS\nusb3hub.sys (manual start) Renesas Electronics USB 3.0 Host Controller Driver: system32\DRIVERS\nusb3xhc.sys (manual start) Service for NVIDIA High Definition Audio Driver: system32\drivers\nvhda64v.sys (manual start) nvlddmkm: system32\DRIVERS\nvlddmkm.sys (manual start) nvraid: \SystemRoot\system32\drivers\nvraid.sys (manual start) nvstor: \SystemRoot\system32\drivers\nvstor.sys (manual start) NVIDIA Display Driver Service: %SystemRoot%\system32\nvvsvc.exe (autostart) NVIDIA Update Service Daemon: C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (autostart) NVIDIA nForce AGP Bus Filter: \SystemRoot\system32\drivers\nv_agp.sys (manual start) 1394 OHCI Compliant Host Controller (Legacy): \SystemRoot\system32\drivers\ohci1394.sys (manual start) @%SystemRoot%\system32\pnrpsvc.dll,-8004: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet (manual start) @%SystemRoot%\system32\p2psvc.dll,-8006: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet (manual start) Parallel port driver: \SystemRoot\system32\drivers\parport.sys (manual start) @%SystemRoot%\system32\drivers\partmgr.sys,-100: System32\drivers\partmgr.sys (system) @%SystemRoot%\system32\pcasvc.dll,-1: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) PCI-Bus-Treiber: system32\drivers\pci.sys (system) pciide: system32\drivers\pciide.sys (system) pcmcia: \SystemRoot\system32\drivers\pcmcia.sys (manual start) Performance Counters for Windows Driver: System32\drivers\pcw.sys (system) PEAUTH: system32\drivers\peauth.sys (autostart) @%SystemRoot%\system32\peerdistsvc.dll,-9000: %SystemRoot%\System32\svchost.exe -k PeerDist (manual start) @%systemroot%\sysWow64\perfhost.exe,-2: %SystemRoot%\SysWow64\perfhost.exe (manual start) @%systemroot%\system32\pla.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork (manual start) @%SystemRoot%\system32\umpnpmgr.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch (autostart) Pml Driver HPZ12: %SystemRoot%\System32\svchost.exe -k HPZ12 (autostart) @%SystemRoot%\system32\pnrpauto.dll,-8002: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet (manual start) @%SystemRoot%\system32\pnrpsvc.dll,-8000: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet (manual start) @%SystemRoot%\System32\polstore.dll,-5010: %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted (manual start) @%SystemRoot%\system32\umpo.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch (autostart) @%systemroot%\system32\rascfg.dll,-32006: system32\DRIVERS\raspptp.sys (manual start) Processor Driver: \SystemRoot\system32\drivers\processr.sys (manual start) @%systemroot%\system32\profsvc.dll,-300: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%systemroot%\system32\psbase.dll,-300: %SystemRoot%\system32\lsass.exe (manual start) @%SystemRoot%\System32\drivers\pacer.sys,-101: system32\DRIVERS\pacer.sys (system) ql2300: \SystemRoot\system32\drivers\ql2300.sys (manual start) ql40xx: \SystemRoot\system32\drivers\ql40xx.sys (manual start) @%SystemRoot%\system32\qwave.dll,-1: %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) @%SystemRoot%\system32\drivers\qwavedrv.sys,-1: \SystemRoot\system32\drivers\qwavedrv.sys (manual start) Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (manual start) WAN Miniport (IKEv2): system32\DRIVERS\AgileVpn.sys (manual start) @%Systemroot%\system32\rasauto.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) @%systemroot%\system32\rascfg.dll,-32005: system32\DRIVERS\rasl2tp.sys (manual start) @%Systemroot%\system32\rasmans.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) @%systemroot%\system32\rascfg.dll,-32007: system32\DRIVERS\raspppoe.sys (manual start) @%systemroot%\system32\sstpsvc.dll,-202: system32\DRIVERS\rassstp.sys (manual start) @%systemroot%\system32\wkssvc.dll,-1000: system32\DRIVERS\rdbss.sys (system) Remote Desktop Device Redirector Bus Driver: system32\DRIVERS\rdpbus.sys (manual start) @%systemroot%\system32\DRIVERS\RDPCDD.sys,-100: System32\DRIVERS\RDPCDD.sys (system) Terminal Server Device Redirector Driver: System32\drivers\rdpdr.sys (manual start) @%systemroot%\system32\drivers\RDPENCDD.sys,-101: system32\drivers\rdpencdd.sys (system) @%systemroot%\system32\drivers\RdpRefMp.sys,-101: system32\drivers\rdprefmp.sys (system) Remote Desktop Video Miniport Driver: System32\drivers\rdpvideominiport.sys (manual start) ReadyBoost: System32\drivers\rdyboost.sys (system) @%Systemroot%\system32\mprdim.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) @regsvc.dll,-1: %SystemRoot%\system32\svchost.exe -k regsvc (disabled) @%windir%\system32\RpcEpMap.dll,-1001: %SystemRoot%\system32\svchost.exe -k RPCSS (autostart) @%systemroot%\system32\Locator.exe,-2: %SystemRoot%\system32\locator.exe (manual start) @oleres.dll,-5010: %SystemRoot%\system32\svchost.exe -k rpcss (autostart) Link-Layer Topology Discovery Responder: system32\DRIVERS\rspndr.sys (autostart) Ralink 802.11n USB Wireless LAN Card Driver: system32\DRIVERS\rt2870.sys (manual start) Cinergy T Stick RC BDA service: system32\drivers\RTL2832UBDA.sys (manual start) Cinergy T Stick RC USB service: System32\Drivers\RTL2832UUSB.sys (manual start) Cinergy T Stick HID: system32\DRIVERS\RTL2832U_IRHID.sys (manual start) Realtek 8167 NT Driver: system32\DRIVERS\Rt64win7.sys (manual start) Realtek 10/100/1000 PCI-E NIC Family NDIS XP(x64) Driver: system32\DRIVERS\Rtenic64.sys (manual start) s3cap: \SystemRoot\system32\drivers\vms3cap.sys (manual start) @%SystemRoot%\system32\samsrv.dll,-1: %SystemRoot%\system32\lsass.exe (autostart) Ad-Aware: "C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe" (autostart) sbp2port: \SystemRoot\system32\drivers\sbp2port.sys (manual start) @%SystemRoot%\System32\SCardSvr.dll,-1: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) @%SystemRoot%\System32\drivers\scfilter.sys,-11: System32\DRIVERS\scfilter.sys (manual start) @%SystemRoot%\system32\schedsvc.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%SystemRoot%\System32\certprop.dll,-13: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\system32\sdrsvc.dll,-107: %SystemRoot%\system32\svchost.exe -k SDRSVC (manual start) Spybot-S&D 2 Scanner Service: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (autostart) Spybot-S&D 2 Updating Service: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (autostart) Spybot-S&D 2 Security Center Service: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (autostart) @%SystemRoot%\system32\seclogon.dll,-7001: %windir%\system32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\system32\Sens.dll,-200: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) @%SystemRoot%\System32\sensrsvc.dll,-1000: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) Serenum-Filtertreiber: system32\DRIVERS\serenum.sys (manual start) Treiber für seriellen Anschluss: system32\DRIVERS\serial.sys (system) Serial Mouse Driver: \SystemRoot\system32\drivers\sermouse.sys (manual start) @%SystemRoot%\System32\SessEnv.dll,-1026: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) SFF Storage Class Driver: \SystemRoot\system32\drivers\sffdisk.sys (manual start) SFF Storage Protocol Driver for MMC: \SystemRoot\system32\drivers\sffp_mmc.sys (manual start) SFF Storage Protocol Driver for SDBus: \SystemRoot\system32\drivers\sffp_sd.sys (manual start) High-Capacity Floppy Disk Drive: \SystemRoot\system32\drivers\sfloppy.sys (manual start) @%SystemRoot%\system32\ipnathlp.dll,-106: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) @%SystemRoot%\System32\shsvcs.dll,-12288: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) SiSRaid2: \SystemRoot\system32\drivers\SiSRaid2.sys (manual start) SiSRaid4: \SystemRoot\system32\drivers\sisraid4.sys (manual start) @%SystemRoot%\system32\tcpipcfg.dll,-50005: system32\DRIVERS\smb.sys (manual start) @%SystemRoot%\system32\snmptrap.exe,-3: %SystemRoot%\System32\snmptrap.exe (manual start) @%systemroot%\system32\spoolsv.exe,-1: %SystemRoot%\System32\spoolsv.exe (autostart) @%SystemRoot%\system32\sppsvc.exe,-101: %SystemRoot%\system32\sppsvc.exe (autostart) @%SystemRoot%\system32\sppuinotify.dll,-103: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%systemroot%\system32\srvsvc.dll,-102: System32\DRIVERS\srv.sys (manual start) @%systemroot%\system32\srvsvc.dll,-104: System32\DRIVERS\srv2.sys (manual start) : System32\DRIVERS\srvnet.sys (manual start) @%systemroot%\system32\ssdpsrv.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) @%SystemRoot%\system32\sstpsvc.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.): system32\DRIVERS\ssudmdm.sys (manual start) NVIDIA Stereoscopic 3D Driver Service: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (autostart) stexstor: \SystemRoot\system32\drivers\stexstor.sys (manual start) @%SystemRoot%\system32\wiaservc.dll,-9: %SystemRoot%\system32\svchost.exe -k imgsvc (autostart) @%SystemRoot%\system32\vmstorfltres.dll,-1000: system32\drivers\vmstorfl.sys (system) @%SystemRoot%\System32\StorSvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) storvsc: \SystemRoot\system32\drivers\storvsc.sys (manual start) Software-Bus-Treiber: system32\DRIVERS\swenum.sys (manual start) @%SystemRoot%\System32\swprv.dll,-103: %SystemRoot%\System32\svchost.exe -k swprv (manual start) @%SystemRoot%\system32\sysmain.dll,-1000: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\TabSvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%SystemRoot%\system32\tapisrv.dll,-10100: %SystemRoot%\System32\svchost.exe -k NetworkService (manual start) Audials Sound Capturing: system32\drivers\tbhsd.sys (manual start) @%SystemRoot%\system32\tbssvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) @%SystemRoot%\system32\tcpipcfg.dll,-50003: System32\drivers\tcpip.sys (system) Microsoft IPv6 Protocol Driver: system32\DRIVERS\tcpip.sys (manual start) TCP/IP Registry Compatibility: System32\drivers\tcpipreg.sys (autostart) TDPIPE: system32\drivers\tdpipe.sys (manual start) TDTCP: system32\drivers\tdtcp.sys (manual start) @%SystemRoot%\system32\tcpipcfg.dll,-50004: system32\DRIVERS\tdx.sys (system) Terminal-Gerätetreiber: system32\DRIVERS\termdd.sys (system) @%SystemRoot%\System32\termsrv.dll,-268: %SystemRoot%\System32\svchost.exe -k NetworkService (manual start) @%SystemRoot%\System32\themeservice.dll,-8192: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) @%systemroot%\system32\mmcss.dll,-102: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\trkwks.dll,-1: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\servicing\TrustedInstaller.exe,-100: %SystemRoot%\servicing\TrustedInstaller.exe (manual start) @%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101: System32\DRIVERS\tssecsrv.sys (manual start) : system32\drivers\tsusbflt.sys (manual start) Remote Desktop Generic USB Device: \SystemRoot\system32\drivers\TsUsbGD.sys (manual start) Microsoft-Tunnelminiport-Adaptertreiber: system32\DRIVERS\tunnel.sys (manual start) Microsoft AGPv3.5 Filter: \SystemRoot\system32\drivers\uagp35.sys (manual start) udfs: system32\DRIVERS\udfs.sys (disabled) @%SystemRoot%\system32\ui0detect.exe,-101: %SystemRoot%\system32\UI0Detect.exe (manual start) Uli AGP Bus Filter: \SystemRoot\system32\drivers\uliagpkx.sys (manual start) UMBusenumerator-Treiber: system32\DRIVERS\umbus.sys (manual start) Microsoft UMPass Driver: \SystemRoot\system32\drivers\umpass.sys (manual start) @%SystemRoot%\system32\umrdp.dll,-1000: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%systemroot%\system32\upnphost.dll,-213: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) USB-Audiotreiber (WDM): system32\drivers\usbaudio.sys (manual start) Microsoft Standard-USB-Haupttreiber: system32\DRIVERS\usbccgp.sys (manual start) eHome Infrared Receiver (USBCIR): \SystemRoot\system32\drivers\usbcir.sys (manual start) Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller: system32\DRIVERS\usbehci.sys (manual start) Microsoft USB-Standardhubtreiber: system32\DRIVERS\usbhub.sys (manual start) Miniporttreiber für Microsoft USB Open Host-Controller: system32\DRIVERS\usbohci.sys (manual start) Microsoft USB-Druckerklasse: system32\DRIVERS\usbprint.sys (manual start) USB-Scannertreiber: system32\DRIVERS\usbscan.sys (manual start) USB-Massenspeichertreiber: system32\DRIVERS\USBSTOR.SYS (manual start) Miniporttreiber für universellen Microsoft USB-Hostcontroller: \SystemRoot\system32\drivers\usbuhci.sys (manual start) USB-RNDIS-Adapter: system32\DRIVERS\usb8023x.sys (manual start) @%SystemRoot%\system32\dwm.exe,-2000: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\vaultsvc.dll,-1003: %SystemRoot%\system32\lsass.exe (manual start) Enumerator-Treiber für Microsoft Virtual Drive: system32\drivers\vdrvroot.sys (system) @%SystemRoot%\system32\vds.exe,-100: %SystemRoot%\System32\vds.exe (manual start) vga: system32\DRIVERS\vgapnp.sys (manual start) : \SystemRoot\System32\drivers\vga.sys (system) vhdmp: \SystemRoot\system32\drivers\vhdmp.sys (manual start) VIA High Definition Audio Driver Service: system32\drivers\viahduaa.sys (manual start) viaide: \SystemRoot\system32\drivers\viaide.sys (manual start) vmbus: \SystemRoot\system32\drivers\vmbus.sys (manual start) VMBusHID: \SystemRoot\system32\drivers\VMBusHID.sys (manual start) Treiber für Volume-Manager: system32\drivers\volmgr.sys (system) @%SystemRoot%\system32\drivers\volmgrx.sys,-100: System32\drivers\volmgrx.sys (system) Speichervolumes: system32\drivers\volsnap.sys (system) vsmraid: \SystemRoot\system32\drivers\vsmraid.sys (manual start) @%systemroot%\system32\vssvc.exe,-102: %systemroot%\system32\vssvc.exe (manual start) @%SystemRoot%\System32\drivers\vwifibus.sys,-257: \SystemRoot\System32\drivers\vwifibus.sys (manual start) @%SystemRoot%\system32\w32time.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) Wacom Serial Pen HID Driver: \SystemRoot\system32\drivers\wacompen.sys (manual start) @%systemroot%\system32\rascfg.dll,-32011: system32\DRIVERS\wanarp.sys (manual start) @%systemroot%\system32\rascfg.dll,-32012: system32\DRIVERS\wanarp.sys (system) @%systemroot%\system32\wbengine.exe,-104: "%systemroot%\system32\wbengine.exe" (manual start) @%systemroot%\system32\wbiosrvc.dll,-100: %SystemRoot%\system32\svchost.exe -k WbioSvcGroup (manual start) @%SystemRoot%\system32\wcncsvc.dll,-3: %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation (manual start) @%SystemRoot%\system32\WcsPlugInService.dll,-200: %SystemRoot%\system32\svchost.exe -k wcssvc (manual start) Wd: \SystemRoot\system32\drivers\wd.sys (manual start) @%SystemRoot%\system32\drivers\Wdf01000.sys,-1000: system32\drivers\Wdf01000.sys (system) @%systemroot%\system32\wdi.dll,-502: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) @%systemroot%\system32\wdi.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%systemroot%\system32\webclnt.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\wecsvc.dll,-200: %SystemRoot%\system32\svchost.exe -k NetworkService (manual start) @%SystemRoot%\System32\wercplsupport.dll,-101: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\System32\wersvc.dll,-100: %SystemRoot%\System32\svchost.exe -k WerSvcGroup (manual start) WFP Lightweight Filter: system32\DRIVERS\wfplwf.sys (system) WIMMount: system32\drivers\wimmount.sys (manual start) @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103: %SystemRoot%\System32\svchost.exe -k secsvcs (manual start) @%SystemRoot%\system32\winhttp.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%Systemroot%\system32\wbem\wmisvc.dll,-205: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%Systemroot%\system32\wsmsvc.dll,-101: %SystemRoot%\System32\svchost.exe -k NetworkService (manual start) SAMSUNG Android USB Driver: system32\DRIVERS\WinUsb.sys (manual start) @%SystemRoot%\System32\wlansvc.dll,-257: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) Windows Live ID Sign-in Assistant: "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" (autostart) Microsoft Windows Management Interface for ACPI: system32\DRIVERS\wmiacpi.sys (manual start) @%Systemroot%\system32\wbem\wmiapsrv.exe,-110: %systemroot%\system32\wbem\WmiApSrv.exe (manual start) @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101: "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" (autostart) @%SystemRoot%\system32\wpcsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (manual start) @%SystemRoot%\system32\wpdbusenum.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%systemroot%\System32\drivers\ws2ifsl.sys,-1000: \SystemRoot\system32\drivers\ws2ifsl.sys (disabled) @%SystemRoot%\System32\wscsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (autostart) WSD-Druckunterstützung durch UMB: system32\DRIVERS\WSDPrint.sys (manual start) @%systemroot%\system32\SearchIndexer.exe,-103: %systemroot%\system32\SearchIndexer.exe /Embedding (autostart) @%systemroot%\system32\wuaueng.dll,-105: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%SystemRoot%\system32\drivers\Wudfpf.sys,-1000: system32\drivers\WudfPf.sys (manual start) WUDFRd: system32\DRIVERS\WUDFRd.sys (manual start) @%SystemRoot%\system32\wudfsvc.dll,-1000: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\System32\wwansvc.dll,-257: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork (manual start) -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: *Registry value not found* -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: WebCheck: *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- End of report, 53.327 bytes Report generated in 0,218 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only Hijackthis HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:50:42, on 14.01.2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16457) Boot mode: Safe mode Running processes: C:\Users\7\Desktop\HiJackThis204.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.googel.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll O2 - BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file) O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe O9 - Extra button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O17 - HKLM\System\CCS\Services\Tcpip\..\{C02FC623-EE75-48B2-B8AB-5506A0908421}: NameServer = 89.246.64.8,82.145.9.8 O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing) O23 - Service: Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Ad-Aware (SBAMSvc) - GFI Software - C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 8077 bytes Gmer GMER 2.0.18444 - hxxp://www.gmer.net Rootkit scan 2013-01-14 22:10:57 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-3 Hitachi_HDS5C3020ALA632 rev.ML6OA580 1863,02GB Running: gmer-2.0.18444.exe; Driver: C:\Users\7\AppData\Local\Temp\pxldapog.sys ---- Threads - GMER 2.0 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3308:3612] 000007fefc3a2a7c Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3308:3628] 000007fef21fd618 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3308:3344] 000007fef8985124 Thread C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3372:1244] 0000000075557587 Thread C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3372:1492] 0000000077c52e25 Thread C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3372:1848] 000000000fb2200e Thread C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3372:3952] 0000000077c53e45 ---- Processes - GMER 2.0 ---- Library ? (*** suspicious ***) @ C:\Program Files\Windows Media Player\wmpnetwk.exe [3308] 000007fefd750000 ---- EOF - GMER 2.0 ---- Nod 32 25.10.2012 18:37:03 HTTP-Prüfung Datei hxxp://divisions.news788.com/t/pricelist.php JS/Exploit.Pdfka.PTI Trojaner Verbindung getrennt - in Quarantäne kopiert 7-PC\7 Bedrohung erkannt beim Zugriff auf das Web durch die Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe. Hitman Pro Code:
ATTFilter HitmanPro 3.7.0.185 www.hitmanpro.com Computer name . . . . : 7-PC Windows . . . . . . . : 6.1.1.7601.X64/6 User name . . . . . . : 7-PC\7 UAC . . . . . . . . . : Enabled License . . . . . . . : Trial (28 days left) Scan date . . . . . . : 2013-01-15 23:35:10 Scan mode . . . . . . : Normal Scan duration . . . . : 1m 39s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 1 Traces . . . . . . . : 19 Objects scanned . . . : 1.098.807 Files scanned . . . . : 11.720 Remnants scanned . . : 207.322 files / 879.765 keys Malware _____________________________________________________________________ C:\Users\7\Desktop\gmer-2.0.18444.exe -> Quarantined Size . . . . . . . : 365.568 bytes Age . . . . . . . : 2.2 days (2013-01-13 17:47:07) Entropy . . . . . : 7.9 SHA-256 . . . . . : 89F77203700A4C347816D175B605DEAAF34B582D084B39AFBDCF9A7A4E1B50EC Version . . . . . : 2.0.18444 > G Data . . . . . . : Trojan.Generic.8557653 (Engine A) Fuzzy . . . . . . : 113.0 References HKU\S-1-5-21-1394040420-131216282-2665522858-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\7\Desktop\gmer-2.0.18444.exe Cookies _____________________________________________________________________ C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:adbrite.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.creative-serving.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:conrad.122.2o7.net C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:specificclick.net C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:wspgroupplc.112.2o7.net C:\Users\7\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com Mein System System -------------------------------------------------------------------------------- Hersteller System manufacturer Modell System Product Name Gesamter Systemspeicher 8,00 GB RAM Systemtyp 64 Bit-Betriebssystem Anzahl der Prozessorkerne 6 Speicher -------------------------------------------------------------------------------- Gesamtgröße der Festplatte(n) 1863 GB Datenträgerpartition (C 1798 GB frei (1863 GB gesamt) Medienlaufwerk (D CD/DVD Grafik -------------------------------------------------------------------------------- Grafikkartentyp NVIDIA GeForce GTX 550 Ti Insgesamt verfügbarer Grafikspeicher 4096 MB Dedizierter Grafikspeicher 1024 MB Dedizierter Systemarbeitsspeicher 0 MB Gemeinsam genutzter Systemspeicher 3072 MB Grafikkarten-Treiberversion 9.18.13.697 Auflösung des primären Monitors 1920x1080 DirectX-Version DirectX 10 Netzwerk -------------------------------------------------------------------------------- Netzwerkadapter Realtek PCIe GBE Family Controller Netzwerkadapter Sitecom Wireless Micro USB Adapter 300N X3 WL-364 Vielen Dank fürs Lesen und helfen (evtl.beruhigen wenn es doch kein Trojaner/Virus ist) Danke Danke Danke : |
Themen zu Internetverbindung, USB, Mails. |
.com, acrobat update, antivirus, association, bho, bonjour, cloud, desktop, device driver, dllhost.exe, dnsapi.dll, email, error, eset nod32, failed, festplatte, firefox, flash player, frage, gmx.net, google, hdaudio.sys, helper, localsystemnetworkrestricted, maus, msiexec.exe, presentationhost.exe, problem, proxy, registry, registry key, registry value, robot, scan, secsvcs, security, server, software, svchost.exe, traces, trojan.generic., trojaner/virus, windows |