|
Plagegeister aller Art und deren Bekämpfung: GVU Trojaner auf Laptop mit WIN XPWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.02.2013, 22:07 | #1 |
| GVU Trojaner auf Laptop mit WIN XP Guten Abend Zusammen, gestern habe ich mit den GVU Trojaner eingefangen hatte dies schon vor einiger Zeit auf meinem anderen Rechner den ich mit Kaspersky wieder heile machen konnte aber diesmal funktioniert es nicht. Kann mir bitte jemand weiter helfen was muss ich tun. Danke East |
26.02.2013, 22:08 | #2 |
/// Malware-holic | GVU Trojaner auf Laptop mit WIN XP hi
__________________Mit einem sauberen 2. Rechner eine OTLPE-CD erstellen und den infizierten Rechner dann von dieser CD booten: Falls Du kein Brennprogramm installiert hast, lade dir bitte ISOBurner herunter. Das Programm wird Dir erlauben, OTLPE auf eine CD zu brennen und sie bootfähig zu machen. Du brauchst das Tool nur zu installieren, der Rest läuft automatisch => Wie brenne ich eine ISO Datei auf CD/DVD. Lade OTLPENet.exe von OldTimer herunter und speichere sie auf Deinem Desktop. Anmerkung: Die Datei ist ca. 120 MB groß und es wird bei langsamer Internet-Verbindung ein wenig dauern, bis Du sie runtergeladen hast.
Bebilderte Anleitung: OTLpe-Scan
__________________ |
26.02.2013, 22:39 | #3 |
| GVU Trojaner auf Laptop mit WIN XP Hallo markusg,
__________________erstmal danke für die schnelle Antwort. im Anhang das gewünsche OTL.TXTOTL Logfile: Code:
ATTFilter OTL logfile created on: 2/26/2013 10:29:06 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: d.M.yyyy 1,014.00 Mb Total Physical Memory | 799.00 Mb Available Physical Memory | 79.00% Memory free 902.00 Mb Paging File | 830.00 Mb Available in Paging File | 92.00% Paging File free Paging file location(s): c:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 149.04 Gb Total Space | 106.02 Gb Free Space | 71.14% Space Free | Partition Type: NTFS Drive D: | 7.55 Gb Total Space | 7.55 Gb Free Space | 100.00% Space Free | Partition Type: FAT32 Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [Disabled] -- -- (HidServ) SRV - [2013/02/25 16:16:45 | 000,143,360 | ---- | M] () [Auto] -- C:\Dokumente und Einstellungen\Lena Münch\6694031.exe -- (winmgmt) SRV - [2012/07/23 06:14:20 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2010/06/10 14:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2010/06/02 09:58:20 | 000,246,520 | ---- | M] () [Auto] -- C:\Programme\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2008/10/30 15:27:00 | 000,068,865 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler) SRV - [2008/10/30 15:26:54 | 000,151,297 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService) SRV - [2008/10/21 12:10:50 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2008/02/05 12:22:36 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher) SRV - [2008/02/05 12:20:42 | 000,150,040 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv) SRV - [2008/02/05 12:18:48 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer) SRV - [2007/08/03 05:51:18 | 000,382,248 | ---- | M] (Nero AG) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe -- (NMIndexingService) SRV - [2006/12/19 07:16:20 | 000,079,432 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Programme\Broadcom\ASFIPMon\AsfIpMon.exe -- (ASFIPmon) SRV - [2006/10/26 12:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2006/10/26 07:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (UIUSys) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | System] -- -- (Changer) DRV - [2009/05/27 11:32:43 | 000,075,096 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2009/05/27 11:32:35 | 000,052,056 | ---- | M] (Avira GmbH) [File_System | On_Demand] -- C:\Programme\Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt) DRV - [2009/05/27 11:32:32 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Programme\Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio) DRV - [2008/10/21 11:28:00 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2008/08/27 10:22:24 | 004,754,432 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008/04/13 16:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE) DRV - [2008/02/05 21:21:25 | 000,041,752 | R--- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta) DRV - [2008/02/05 21:17:37 | 002,570,520 | R--- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI) DRV - [2008/02/05 21:17:26 | 000,013,848 | R--- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter) DRV - [2008/02/05 12:20:08 | 000,025,624 | ---- | M] () [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon) DRV - [2008/02/05 12:18:12 | 000,689,176 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap) DRV - [2007/12/05 22:41:38 | 000,327,296 | R--- | M] (AfaTech ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\AF15BDA.sys -- (AF15BDA) DRV - [2007/11/08 12:03:26 | 000,021,248 | ---- | M] (AVIRA GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2007/05/01 20:52:00 | 000,290,816 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21) DRV - [2007/04/30 14:37:00 | 002,206,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel(R) DRV - [2007/03/01 15:22:04 | 000,988,032 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV) DRV - [2007/03/01 15:21:24 | 000,210,688 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL) DRV - [2007/03/01 15:21:22 | 000,731,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2007/02/16 08:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2006/12/19 07:16:24 | 000,010,480 | ---- | M] (Broadcom Corporation) [Kernel | Auto] -- C:\Programme\Broadcom\ASFIPMon\BASFND.sys -- (BASFND) DRV - [2006/04/05 18:00:00 | 000,264,704 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\fwlanusb.sys -- (FWLANUSB) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Lena_Münch_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKU\Lena_Münch_ON_C\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\Lena_Münch_ON_C\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKU\Lena_Münch_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Lena_Münch_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012/07/23 06:14:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012/07/23 06:14:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010/03/18 12:07:52 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2012/07/23 05:54:34 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2009/03/09 20:00:44 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2011/10/16 13:11:49 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011/10/16 13:14:07 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2012/07/23 06:14:21 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2012/07/23 06:14:17 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/07/23 06:14:17 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2012/07/23 06:14:17 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2012/07/23 06:14:17 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/23 06:14:17 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/23 06:14:17 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2004/08/05 07:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKU\Lena_Münch_ON_C\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [AVMWlanClient] C:\Programme\avmwlanstick\FRITZWLANMini.exe (AVM Berlin GmbH) O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe () O4 - HKLM..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe () O4 - HKU\Lena_Münch_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\Lena_Münch_ON_C..\Run: [Center Agent] C:\Programme\X-TENSIONS Multimedia\HyperMediaCenter\DTVR\Scheduled.exe () O4 - HKU\Lena_Münch_ON_C..\Run: [Gadwin PrintScreen] C:\Programme\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc) O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] File not found O4 - HKU\Administrator_ON_C..\RunOnce: [nltide_2] File not found O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Logitech Desktop Messenger.lnk = C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.) O4 - Startup: C:\Dokumente und Einstellungen\Lena Münch\Startmenü\Programme\Autostart\runctf.lnk = X:\I386\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Lena_Münch_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 217.71.105.254 81.209.202.46 O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop BackupWallPaper: O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008/10/21 10:17:46 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22CE9D49-A4AF-E1E7-A740-3EEEA65532A8} - Microsoft .NET Framework 1.1 Security Update (KB2656353) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906) ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6C298884-91FD-408C-9D90-5A59D2C29FD1} - Microsoft .NET Framework 1.1 Security Update (KB2742597) ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install ActiveX: {9309DD7E-EBFE-3C95-8B47-30D3A012F606} - .NET Framework ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE ActiveX: Microsoft Base Smart Card Crypto Provider Package - NetSvcs: 6to4 - File not found NetSvcs: HidServ - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: winmgmt - C:\Dokumente und Einstellungen\Lena Münch\6694031.exe () MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Programme\DAEMON Tools Lite\daemon.exe (DT Soft Ltd) MsConfig - StartUpReg: ICQ - hkey= - key= - File not found MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Programme\iTunes\iTunesHelper.exe (Apple Inc.) MsConfig - StartUpReg: LogitechQuickCamRibbon - hkey= - key= - C:\Programme\Logitech\QuickCam\Quickcam.exe () MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe (Nero AG) MsConfig - StartUpReg: Skype - hkey= - key= - C:\Programme\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 0 MsConfig - State: "startup" - 2 ========== Files/Folders - Created Within 30 Days ========== [2013/02/26 04:31:31 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Administrator\IETldCache [2013/02/26 04:31:03 | 000,000,000 | --SD | C] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Microsoft [2013/02/26 04:31:03 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Administrator\SendTo [2013/02/26 04:31:03 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten [2013/02/26 04:31:03 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Zubehör [2013/02/26 04:31:03 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Administrator\Startmenü [2013/02/26 04:31:03 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Autostart [2013/02/26 04:31:03 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Administrator\Cookies [2013/02/26 04:31:03 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Administrator\Vorlagen [2013/02/26 04:31:03 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Administrator\Recent [2013/02/26 04:31:03 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Administrator\Netzwerkumgebung [2013/02/26 04:31:03 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen [2013/02/26 04:31:03 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Administrator\Druckumgebung [2013/02/26 04:31:03 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft [2013/02/26 04:31:03 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator\Favoriten [2013/02/26 04:31:03 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator\Desktop [2013/02/25 19:28:44 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0 [2013/02/22 17:49:27 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Lena Münch\IECompatCache [2013/02/21 16:24:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss [2013/01/29 09:39:02 | 000,375,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpnet.dll [2013/01/29 09:32:32 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\synceng.dll [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/02/26 16:08:59 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013/02/26 16:06:21 | 095,023,320 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.pad [2013/02/26 15:34:00 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013/02/25 16:17:55 | 000,002,865 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.js [2013/02/25 16:17:55 | 000,000,778 | ---- | M] () -- C:\Dokumente und Einstellungen\Lena Münch\Startmenü\Programme\Autostart\runctf.lnk [2013/02/25 16:16:45 | 000,143,360 | ---- | M] () -- C:\Dokumente und Einstellungen\Lena Münch\6694031.exe [2013/02/24 17:21:01 | 000,462,114 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat [2013/02/24 17:21:01 | 000,444,082 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013/02/24 17:21:01 | 000,086,570 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat [2013/02/24 17:21:01 | 000,072,998 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2013/02/23 16:42:17 | 001,564,984 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013/02/22 19:58:35 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2013/02/21 16:25:12 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2013/01/29 08:40:53 | 000,002,545 | ---- | M] () -- C:\Dokumente und Einstellungen\Lena Münch\Desktop\Microsoft Office PowerPoint 2007.lnk [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/02/26 04:31:03 | 000,001,599 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Remoteunterstützung.lnk [2013/02/26 04:31:03 | 000,000,768 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Windows Media Player.lnk [2013/02/25 16:17:55 | 000,002,865 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.js [2013/02/25 16:17:55 | 000,000,778 | ---- | C] () -- C:\Dokumente und Einstellungen\Lena Münch\Startmenü\Programme\Autostart\runctf.lnk [2013/02/25 16:17:51 | 095,023,320 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.pad [2013/02/25 16:16:44 | 000,143,360 | ---- | C] () -- C:\Dokumente und Einstellungen\Lena Münch\6694031.exe [2013/02/22 17:52:50 | 000,148,992 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mpg2splt.ax [2012/02/17 07:26:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011/11/29 15:35:10 | 000,066,482 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini [2011/02/24 17:17:44 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010/04/14 08:29:49 | 000,023,552 | ---- | C] () -- C:\Dokumente und Einstellungen\Lena Münch\Lokale Einstellungen\Anwendungsdaten\WebpageIcons.db [2010/03/26 11:57:16 | 000,299,008 | ---- | C] () -- C:\WINDOWS\afaunist.exe [2010/03/26 11:57:16 | 000,001,062 | ---- | C] () -- C:\WINDOWS\TVAfaDrv.ini [2010/03/26 11:57:08 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll [2010/03/26 11:57:04 | 000,000,224 | ---- | C] () -- C:\WINDOWS\System32\AF15IRTBL.bin [2010/03/16 17:38:32 | 000,000,048 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2009/10/22 08:10:38 | 000,275,968 | ---- | C] () -- C:\WINDOWS\System32\BH_DATA120VC8.dll [2009/10/15 15:22:48 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\FKStampPainter20.dll [2009/10/09 10:20:50 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\LXPrnUtil10.dll [2009/10/09 10:18:42 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\dnt27VC8.dll [2009/10/09 10:16:16 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27VC8.dll [2009/10/09 10:15:54 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvm27VC8.dll [2009/04/15 15:36:15 | 000,084,614 | ---- | C] () -- C:\Programme\SFXLogo.bmp [2009/04/15 15:36:15 | 000,038,274 | ---- | C] () -- C:\Programme\AboutLogo.bmp [2009/04/15 15:36:15 | 000,016,438 | ---- | C] () -- C:\Programme\WizardLogo.bmp [2009/04/15 15:36:15 | 000,009,270 | ---- | C] () -- C:\Programme\Estimate.bmp [2009/04/15 15:36:15 | 000,004,290 | ---- | C] () -- C:\Programme\DragCopy.cur [2009/04/15 15:36:15 | 000,001,286 | ---- | C] () -- C:\Programme\RarSmall.bmp [2009/04/15 15:36:15 | 000,000,824 | ---- | C] () -- C:\Programme\FolderUp.bmp [2009/04/15 15:36:15 | 000,000,576 | ---- | C] () -- C:\Programme\SortUp.bmp [2009/04/15 15:36:15 | 000,000,576 | ---- | C] () -- C:\Programme\SortDown.bmp [2009/03/20 05:02:02 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009/03/20 05:02:01 | 000,005,632 | ---- | C] () -- C:\Dokumente und Einstellungen\Lena Münch\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008/10/24 07:10:25 | 000,097,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\Fwusb1b.bin [2008/10/22 04:45:27 | 000,000,143 | ---- | C] () -- C:\Dokumente und Einstellungen\Lena Münch\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat [2008/10/21 12:45:07 | 000,910,464 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll [2008/10/21 12:45:07 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4837.dll [2008/10/21 12:23:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2008/10/21 11:11:39 | 000,000,008 | RHS- | C] () -- C:\WINDOWS\System32\Desktop_.ini [2008/10/21 10:45:37 | 000,394,752 | ---- | C] () -- C:\WINDOWS\System32\cygwinb19.dll [2008/10/21 10:40:19 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2008/10/21 10:39:09 | 001,564,984 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2008/10/21 10:20:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2008/10/21 10:14:36 | 000,022,880 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2008/06/20 04:55:48 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll [2008/04/14 03:06:26 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin [2008/02/05 12:20:08 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys [2006/12/31 02:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2004/08/05 07:00:00 | 000,462,114 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat [2004/08/05 07:00:00 | 000,444,082 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2004/08/05 07:00:00 | 000,086,570 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat [2004/08/05 07:00:00 | 000,072,998 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2004/08/05 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2004/08/04 09:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2004/08/04 09:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2004/08/04 09:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2004/08/04 09:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat [2004/08/04 09:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2004/08/04 09:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2004/08/04 09:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat [2004/08/04 09:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2004/08/04 09:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat ========== LOP Check ========== [2008/10/21 12:19:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\Any DVD Converter Professional [2010/01/07 15:02:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\Babylon [2008/10/21 11:27:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\DAEMON Tools [2008/10/21 12:58:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\F-Secure [2011/03/28 17:43:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\ICQ [2011/11/29 15:33:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\Leadertech [2010/05/12 06:52:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\Lexware [2008/10/22 05:05:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\RadioRipper [2008/10/21 12:28:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\Thunderbird [2010/03/26 11:50:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Lena Münch\Anwendungsdaten\X-TENSIONS Multimedia [2010/01/07 15:02:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Babylon [2008/10/21 11:11:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Broadcom [2010/05/12 06:52:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BTrieve [2008/10/22 03:57:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\f-secure [2008/10/21 12:14:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\fssg [2010/07/04 08:39:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ [2010/06/02 06:24:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lexware [2008/10/23 05:57:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP [2010/08/27 23:02:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2010/02/01 18:15:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD} ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2013/02/26 04:31:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen [2009/08/16 07:16:38 | 000,000,000 | ---D | M] -- C:\f7568db72e6ff6bc57be8c729b19a20a [2008/10/21 11:10:25 | 000,000,000 | ---D | M] -- C:\Intel [2013/02/26 01:54:03 | 000,000,000 | ---D | M] -- C:\Kaspersky Rescue Disk 10.0 [2008/10/21 12:23:52 | 000,000,000 | RH-D | M] -- C:\MSOCache [2012/07/23 06:14:26 | 000,000,000 | R--D | M] -- C:\Programme [2013/02/26 05:02:59 | 000,000,000 | -HSD | M] -- C:\RECYCLER [2008/10/21 14:04:59 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2013/02/25 16:26:44 | 000,000,000 | ---D | M] -- C:\WINDOWS < %PROGRAMFILES%\*.exe > Invalid Environment Variable: %LOCALAPPDATA%\*.exe < %systemroot%\*. /mp /s > < MD5 for: AGP440.SYS > [2008/06/20 05:02:10 | 018,304,314 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys [2008/06/20 05:02:10 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys < MD5 for: ATAPI.SYS > [2008/06/20 05:02:10 | 018,304,314 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2008/04/13 15:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys [2008/04/13 15:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys [2008/04/13 15:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys < MD5 for: EVENTLOG.DLL > [2008/04/14 02:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll < MD5 for: EXPLORER.EXE > [2008/04/14 02:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\explorer.exe < MD5 for: NETLOGON.DLL > [2008/06/20 04:55:40 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=B4D6D344EACDA356D4AAAC7757955F0C -- C:\WINDOWS\system32\netlogon.dll < MD5 for: SCECLI.DLL > [2008/04/14 02:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll < MD5 for: USER32.DLL > [2008/04/14 02:52:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll < MD5 for: USERINIT.EXE > [2008/04/14 02:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe < MD5 for: WINLOGON.EXE > [2008/04/14 02:53:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe < MD5 for: WS2IFSL.SYS > [2004/08/04 09:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2008/10/21 12:35:46 | 000,262,144 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2008/10/21 10:29:57 | 000,262,144 | ---- | M] () -- C:\WINDOWS\System32\config\security.sav [2008/10/21 12:35:46 | 009,175,040 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2008/10/21 12:35:46 | 002,359,296 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %systemroot%\system32\*.dll /lockedfiles > [2011/03/03 01:54:43 | 000,149,504 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dnsapi.dll [2012/12/26 15:06:40 | 011,111,424 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\ieframe.dll [2012/12/26 15:06:41 | 002,004,992 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\iertutil.dll [2008/04/14 02:52:20 | 000,280,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\mstask.dll [2008/06/20 04:55:40 | 000,068,096 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\ntdsapi.dll [2012/06/08 09:25:14 | 008,503,808 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] Invalid Environment Variable: %USERPROFILE%\*.* Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe ========== Alternate Data Streams ========== @Alternate Data Stream - 121 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:FB1B13D8 < End of report > |
26.02.2013, 22:41 | #4 |
/// Malware-holic | GVU Trojaner auf Laptop mit WIN XP hi, auf deinem zweiten pc gehe auf start, programme zubehör editor, kopiere dort rein: Code:
ATTFilter :OTL [2013/02/25 16:17:55 | 000,002,865 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.js [2013/02/25 16:17:55 | 000,000,778 | ---- | C] () -- C:\Dokumente und Einstellungen\Lena Münch\Startmenü\Programme\Autostart\runctf.lnk [2013/02/25 16:17:51 | 095,023,320 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.pad :Files C:\Dokumente und Einstellungen\Lena Münch\6694031.exe :Commands [EMPTYFLASH] [emptytemp] dieses speicherst du auf nem usb stick als fix.txt nutze nun wieder OTLPENet.exe (starte also von der erstellten cd) und hake alles an, wie es bereits im post zu OTLPENet.exe beschrieben ist. • Klicke nun bitte auf den Fix Button. es sollte nun eine meldung ähnlich dieser: "load fix from file" erscheinen, lade also die fix.txt von deinem stick. wenn dies nicht funktioniert, bitte den fix manuell eintragen. dann klicke erneut den fix buton. pc startet evtl. neu. wenn ja, nimm die cd aus dem laufwerk, windows sollte nun normal starten und die otl.txt öffnen, log posten bitte.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
26.02.2013, 22:51 | #5 |
| GVU Trojaner auf Laptop mit WIN XP Das geht ja alles wahnsinnig schnell!!! Error: Unable to interpret <TL> in the current context! Error: Unable to interpret <[2013/02/25 16:17:55 | 000,002,865 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.js> in the current context! Error: Unable to interpret <[2013/02/25 16:17:55 | 000,000,778 | ---- | C] () -- C:\Dokumente und Einstellungen\Lena Münch\Startmenü\Programme\Autostart\runctf.lnk> in the current context! Error: Unable to interpret <[2013/02/25 16:17:51 | 095,023,320 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1304966.pad> in the current context! ========== FILES ========== C:\Dokumente und Einstellungen\Lena Münch\6694031.exe moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Lena Münch User: Lena Münch ->Temp folder emptied: 728665309 bytes ->Temporary Internet Files folder emptied: 730970209 bytes ->FireFox cache emptied: 143642532 bytes ->Flash cache emptied: 20859 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 350734 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 703510 bytes Total Flash Files Cleaned = 1,530.00 mb [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Lena Münch User: Lena Münch ->Temp folder emptied: 19965 bytes ->Temporary Internet Files folder emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 4466966 bytes %systemroot%\System32 .tmp files removed: 2951 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 50426532 bytes Total Files Cleaned = 52.00 mb OTLPE by OldTimer - Version 3.1.48.0 log created on 02262013_224509 Files\Folders moved on Reboot... File\Folder C:\Dokumente und Einstellungen\Lena Münch\Lokale Einstellungen\Temp\Laut einer Studie der Nestle AG in Zusammenarbeit mit dem Institut für Demoskopie Allensbach beeinflussen Frische und Regionalität den Verbraucher wesentlich bei seiner Kaufentscheidung-1.docx not found! Registry entries deleted on Reboot... |
26.02.2013, 22:54 | #6 |
/// Malware-holic | GVU Trojaner auf Laptop mit WIN XP hi du hast den : bei :OTL vergessen, machs noch mal bitte
__________________ --> GVU Trojaner auf Laptop mit WIN XP |
26.02.2013, 22:54 | #7 |
| GVU Trojaner auf Laptop mit WIN XP Sehr schön er läd wieder ganz normal. Ist der Trojaner jetzt weg? Kann ich was oder muss ich noch was tun damit er endgültig weg ist Der Pc hat mir nur diese Datei geöffnet plus eine fehlermeldung das er eindokument nicht mehr findet |
26.02.2013, 22:59 | #8 |
/// Malware-holic | GVU Trojaner auf Laptop mit WIN XP hi, weiter gehts: Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
26.02.2013, 23:16 | #9 |
| GVU Trojaner auf Laptop mit WIN XP 23:07:38.0000 9616 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 23:07:38.0203 9616 ============================================================ 23:07:38.0203 9616 Current date / time: 2013/02/26 23:07:38.0203 23:07:38.0203 9616 SystemInfo: 23:07:38.0203 9616 23:07:38.0203 9616 OS Version: 5.1.2600 ServicePack: 3.0 23:07:38.0203 9616 Product type: Workstation 23:07:38.0203 9616 ComputerName: LENA-MÜNCH 23:07:38.0203 9616 UserName: Lena Münch 23:07:38.0203 9616 Windows directory: C:\WINDOWS 23:07:38.0203 9616 System windows directory: C:\WINDOWS 23:07:38.0203 9616 Processor architecture: Intel x86 23:07:38.0203 9616 Number of processors: 2 23:07:38.0203 9616 Page size: 0x1000 23:07:38.0203 9616 Boot type: Normal boot 23:07:38.0203 9616 ============================================================ 23:07:40.0781 9616 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 23:07:40.0781 9616 Drive \Device\Harddisk1\DR4 - Size: 0x1E4700000 (7.57 Gb), SectorSize: 0x200, Cylinders: 0x3DC, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 23:07:40.0796 9616 ============================================================ 23:07:40.0796 9616 \Device\Harddisk0\DR0: 23:07:40.0796 9616 MBR partitions: 23:07:40.0796 9616 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1 23:07:40.0796 9616 \Device\Harddisk1\DR4: 23:07:40.0796 9616 MBR partitions: 23:07:40.0796 9616 \Device\Harddisk1\DR4\Partition1: MBR, Type 0xB, StartLBA 0x1F80, BlocksNum 0xF21880 23:07:40.0796 9616 ============================================================ 23:07:40.0828 9616 C: <-> \Device\Harddisk0\DR0\Partition1 23:07:40.0828 9616 ============================================================ 23:07:40.0828 9616 Initialize success 23:07:40.0828 9616 ============================================================ 23:08:08.0531 10048 ============================================================ 23:08:08.0531 10048 Scan started 23:08:08.0531 10048 Mode: Manual; SigCheck; TDLFS; 23:08:08.0531 10048 ============================================================ 23:08:10.0015 10048 ================ Scan system memory ======================== 23:08:10.0015 10048 System memory - ok 23:08:10.0031 10048 ================ Scan services ============================= 23:08:10.0140 10048 Abiosdsk - ok 23:08:10.0140 10048 abp480n5 - ok 23:08:10.0203 10048 [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 23:08:12.0437 10048 ACPI - ok 23:08:12.0468 10048 [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 23:08:12.0718 10048 ACPIEC - ok 23:08:12.0718 10048 adpu160m - ok 23:08:12.0828 10048 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 23:08:13.0015 10048 aec - ok 23:08:13.0078 10048 [ 6E1CC5AA9817CD13FBCEB35DAC0A77F7 ] AF15BDA C:\WINDOWS\system32\DRIVERS\AF15BDA.sys 23:08:13.0187 10048 AF15BDA - ok 23:08:13.0250 10048 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 23:08:13.0359 10048 AFD - ok 23:08:13.0359 10048 Aha154x - ok 23:08:13.0375 10048 aic78u2 - ok 23:08:13.0375 10048 aic78xx - ok 23:08:13.0421 10048 [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter C:\WINDOWS\system32\alrsvc.dll 23:08:13.0640 10048 Alerter - ok 23:08:13.0718 10048 [ 190CD73D4984F94D823F9444980513E5 ] ALG C:\WINDOWS\System32\alg.exe 23:08:13.0843 10048 ALG - ok 23:08:13.0859 10048 AliIde - ok 23:08:13.0859 10048 amsint - ok 23:08:13.0984 10048 [ D6C8942BEA3698A2E7559BD423BFA5D7 ] AntiVirScheduler C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe 23:08:14.0093 10048 AntiVirScheduler ( UnsignedFile.Multi.Generic ) - warning 23:08:14.0093 10048 AntiVirScheduler - detected UnsignedFile.Multi.Generic (1) 23:08:14.0125 10048 [ 335A142923FE7F97E8C8388ACD067568 ] AntiVirService C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe 23:08:14.0171 10048 AntiVirService ( UnsignedFile.Multi.Generic ) - warning 23:08:14.0171 10048 AntiVirService - detected UnsignedFile.Multi.Generic (1) 23:08:14.0312 10048 [ 2E3E53A6AEF23E24F402C7855B9B1542 ] Apple Mobile Device C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe 23:08:14.0406 10048 Apple Mobile Device - ok 23:08:14.0500 10048 [ D45960BE52C3C610D361977057F98C54 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 23:08:14.0625 10048 AppMgmt - ok 23:08:14.0687 10048 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys 23:08:14.0906 10048 Arp1394 - ok 23:08:14.0906 10048 asc - ok 23:08:14.0921 10048 asc3350p - ok 23:08:14.0921 10048 asc3550 - ok 23:08:14.0937 10048 ASFIPmon - ok 23:08:15.0062 10048 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 23:08:15.0125 10048 aspnet_state - ok 23:08:15.0171 10048 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 23:08:15.0328 10048 AsyncMac - ok 23:08:15.0390 10048 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 23:08:15.0515 10048 atapi - ok 23:08:15.0546 10048 Atdisk - ok 23:08:15.0593 10048 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 23:08:15.0765 10048 Atmarpc - ok 23:08:15.0828 10048 [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 23:08:16.0046 10048 AudioSrv - ok 23:08:16.0093 10048 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 23:08:16.0296 10048 audstub - ok 23:08:16.0421 10048 [ 87828ECD657F81503465AC705E845076 ] avgio C:\Programme\Avira\AntiVir PersonalEdition Classic\avgio.sys 23:08:16.0437 10048 avgio - ok 23:08:16.0500 10048 [ FCB30820BED1D3FEB55E3DD55A3F947F ] avgntflt C:\Programme\Avira\AntiVir PersonalEdition Classic\avgntflt.sys 23:08:16.0531 10048 avgntflt - ok 23:08:16.0593 10048 [ 0B09DF022250FB7BA91FB932EAC6EA9B ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys 23:08:16.0640 10048 avipbb - ok 23:08:16.0671 10048 [ F96038AA1EC4013A93D2420FC689D1E9 ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys 23:08:16.0718 10048 b57w2k - ok 23:08:16.0734 10048 [ 5C68AC6F3E5B3E6D6A78E97D05E42C3A ] BASFND C:\Programme\Broadcom\ASFIPMon\BASFND.sys 23:08:17.0140 10048 BASFND ( UnsignedFile.Multi.Generic ) - warning 23:08:17.0140 10048 BASFND - detected UnsignedFile.Multi.Generic (1) 23:08:17.0187 10048 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 23:08:17.0359 10048 Beep - ok 23:08:17.0406 10048 [ D6F603772A789BB3228F310D650B8BD1 ] BITS C:\WINDOWS\system32\qmgr.dll 23:08:17.0671 10048 BITS - ok 23:08:17.0828 10048 [ 5AB58C337AC65837FE404462AD6265AB ] Bonjour Service C:\Programme\Bonjour\mDNSResponder.exe 23:08:17.0890 10048 Bonjour Service - ok 23:08:18.0000 10048 [ B71549F23736ADF83A571061C47777FD ] Browser C:\WINDOWS\System32\browser.dll 23:08:18.0093 10048 Browser - ok 23:08:18.0140 10048 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 23:08:18.0281 10048 cbidf2k - ok 23:08:18.0328 10048 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 23:08:18.0500 10048 CCDECODE - ok 23:08:18.0500 10048 cd20xrnt - ok 23:08:18.0515 10048 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 23:08:18.0656 10048 Cdaudio - ok 23:08:18.0703 10048 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 23:08:18.0875 10048 Cdfs - ok 23:08:18.0906 10048 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 23:08:19.0109 10048 Cdrom - ok 23:08:19.0109 10048 Changer - ok 23:08:19.0187 10048 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc C:\WINDOWS\system32\cisvc.exe 23:08:19.0343 10048 CiSvc - ok 23:08:19.0359 10048 [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 23:08:19.0546 10048 ClipSrv - ok 23:08:19.0593 10048 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 23:08:19.0781 10048 clr_optimization_v2.0.50727_32 - ok 23:08:19.0875 10048 [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 23:08:20.0046 10048 CmBatt - ok 23:08:20.0062 10048 CmdIde - ok 23:08:20.0109 10048 [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 23:08:20.0250 10048 Compbatt - ok 23:08:20.0281 10048 COMSysApp - ok 23:08:20.0328 10048 Cpqarray - ok 23:08:20.0406 10048 [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 23:08:20.0546 10048 CryptSvc - ok 23:08:20.0562 10048 dac2w2k - ok 23:08:20.0562 10048 dac960nt - ok 23:08:20.0640 10048 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 23:08:20.0734 10048 DcomLaunch - ok 23:08:20.0796 10048 [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 23:08:21.0015 10048 Dhcp - ok 23:08:21.0046 10048 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 23:08:21.0234 10048 Disk - ok 23:08:21.0234 10048 dmadmin - ok 23:08:21.0296 10048 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 23:08:21.0531 10048 dmboot - ok 23:08:21.0546 10048 [ 53720AB12B48719D00E327DA470A619A ] dmio C:\WINDOWS\system32\DRIVERS\dmio.sys 23:08:21.0718 10048 dmio - ok 23:08:21.0781 10048 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 23:08:21.0921 10048 dmload - ok 23:08:21.0937 10048 [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver C:\WINDOWS\System32\dmserver.dll 23:08:22.0125 10048 dmserver - ok 23:08:22.0187 10048 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 23:08:22.0375 10048 DMusic - ok 23:08:22.0421 10048 [ 407F3227AC618FD1CA54B335B083DE07 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 23:08:22.0546 10048 Dnscache - ok 23:08:22.0734 10048 [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 23:08:23.0125 10048 Dot3svc - ok 23:08:23.0156 10048 dpti2o - ok 23:08:23.0187 10048 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 23:08:23.0312 10048 drmkaud - ok 23:08:23.0343 10048 [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost C:\WINDOWS\System32\eapsvc.dll 23:08:23.0468 10048 EapHost - ok 23:08:23.0515 10048 [ 877C18558D70587AA7823A1A308AC96B ] ERSvc C:\WINDOWS\System32\ersvc.dll 23:08:23.0687 10048 ERSvc - ok 23:08:23.0812 10048 [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog C:\WINDOWS\system32\services.exe 23:08:23.0843 10048 Eventlog - ok 23:08:23.0906 10048 [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem C:\WINDOWS\system32\es.dll 23:08:24.0000 10048 EventSystem - ok 23:08:24.0062 10048 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 23:08:24.0234 10048 Fastfat - ok 23:08:24.0281 10048 [ 2DB7D303C36DDD055215052F118E8E75 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 23:08:24.0328 10048 FastUserSwitchingCompatibility - ok 23:08:24.0390 10048 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 23:08:24.0531 10048 Fdc - ok 23:08:24.0593 10048 [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 23:08:24.0734 10048 Fips - ok 23:08:24.0796 10048 [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 23:08:24.0906 10048 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning 23:08:24.0906 10048 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1) 23:08:24.0968 10048 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 23:08:25.0140 10048 Flpydisk - ok 23:08:25.0187 10048 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 23:08:25.0328 10048 FltMgr - ok 23:08:25.0421 10048 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 23:08:25.0531 10048 FontCache3.0.0.0 - ok 23:08:25.0593 10048 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 23:08:25.0765 10048 Fs_Rec - ok 23:08:25.0781 10048 [ 8F1955CE42E1484714B542F341647778 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 23:08:25.0968 10048 Ftdisk - ok 23:08:26.0046 10048 [ B45F1DF1CCE34E2AF422F0ED78CD70EF ] FWLANUSB C:\WINDOWS\system32\DRIVERS\fwlanusb.sys 23:08:26.0093 10048 FWLANUSB - ok 23:08:26.0140 10048 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 23:08:26.0156 10048 GEARAspiWDM - ok 23:08:26.0218 10048 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 23:08:26.0359 10048 Gpc - ok 23:08:26.0421 10048 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 23:08:26.0546 10048 HDAudBus - ok 23:08:26.0640 10048 [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 23:08:26.0796 10048 helpsvc - ok 23:08:26.0796 10048 HidServ - ok 23:08:26.0906 10048 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 23:08:27.0078 10048 HidUsb - ok 23:08:27.0109 10048 [ ED29F14101523A6E0E808107405D452C ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 23:08:27.0265 10048 hkmsvc - ok 23:08:27.0265 10048 hpn - ok 23:08:27.0328 10048 [ 7D33D2B81BD8B4BC51B536B113295D51 ] HSFHWAZL C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 23:08:27.0421 10048 HSFHWAZL - ok 23:08:27.0468 10048 [ FB6AD8A16E22C91D5978B26E0300A331 ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 23:08:27.0640 10048 HSF_DPV - ok 23:08:27.0687 10048 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 23:08:27.0734 10048 HTTP - ok 23:08:27.0796 10048 [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 23:08:27.0937 10048 HTTPFilter - ok 23:08:27.0937 10048 i2omgmt - ok 23:08:27.0953 10048 i2omp - ok 23:08:27.0984 10048 [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 23:08:28.0187 10048 i8042prt - ok 23:08:28.0562 10048 [ 12C7F8D581C4A9F126F5F8F5683A1C29 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 23:08:29.0312 10048 ialm - ok 23:08:29.0390 10048 [ 5C7D72EAB04B1DF8C5D2ACC6551FDE49 ] ICQ Service C:\Programme\ICQ6Toolbar\ICQ Service.exe 23:08:29.0437 10048 ICQ Service - ok 23:08:29.0515 10048 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 23:08:29.0671 10048 idsvc - ok 23:08:29.0718 10048 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 23:08:29.0906 10048 Imapi - ok 23:08:29.0968 10048 [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService C:\WINDOWS\system32\imapi.exe 23:08:30.0093 10048 ImapiService - ok 23:08:30.0109 10048 ini910u - ok 23:08:30.0359 10048 [ 927CF2BE4E57FF55E23759AC0CA57AA3 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 23:08:30.0890 10048 IntcAzAudAddService - ok 23:08:30.0906 10048 IntelIde - ok 23:08:30.0953 10048 [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 23:08:31.0140 10048 intelppm - ok 23:08:31.0171 10048 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 23:08:31.0343 10048 Ip6Fw - ok 23:08:31.0375 10048 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 23:08:31.0546 10048 IpFilterDriver - ok 23:08:31.0578 10048 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 23:08:31.0750 10048 IpInIp - ok 23:08:31.0765 10048 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 23:08:31.0937 10048 IpNat - ok 23:08:32.0015 10048 [ 630D74599070824AF3DC63A894ADCDFC ] iPod Service C:\Programme\iPod\bin\iPodService.exe 23:08:32.0109 10048 iPod Service - ok 23:08:32.0156 10048 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 23:08:32.0343 10048 IPSec - ok 23:08:32.0406 10048 [ ACA5E7B54409F9CB5EED97ED0C81120E ] irda C:\WINDOWS\system32\DRIVERS\irda.sys 23:08:32.0484 10048 irda - ok 23:08:32.0531 10048 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 23:08:32.0609 10048 IRENUM - ok 23:08:32.0625 10048 [ 2EFE1DB1EC58A26B0C14BFDA122E246F ] Irmon C:\WINDOWS\System32\irmon.dll 23:08:32.0703 10048 Irmon - ok 23:08:32.0765 10048 [ 6DFB88F64135C525433E87648BDA30DE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 23:08:32.0906 10048 isapnp - ok 23:08:32.0937 10048 [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 23:08:33.0093 10048 Kbdclass - ok 23:08:33.0156 10048 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 23:08:33.0343 10048 kmixer - ok 23:08:33.0406 10048 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 23:08:33.0546 10048 KSecDD - ok 23:08:33.0593 10048 [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 23:08:33.0671 10048 lanmanserver - ok 23:08:33.0718 10048 [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 23:08:33.0781 10048 lanmanworkstation - ok 23:08:33.0781 10048 lbrtfdc - ok 23:08:33.0843 10048 [ 636714B7D43C8D0C80449123FD266920 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 23:08:33.0984 10048 LmHosts - ok 23:08:34.0093 10048 [ 9CE361764C5DD5FA5506510FE5D2297B ] LVcKap C:\WINDOWS\system32\DRIVERS\LVcKap.sys 23:08:34.0171 10048 LVcKap - ok 23:08:34.0296 10048 [ 1D28B53C50CC57062692862B8E083020 ] LVCOMSer C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe 23:08:34.0328 10048 LVCOMSer - ok 23:08:34.0343 10048 [ 94D03B31F36BB362FA5713470FCF1C79 ] LVPr2Mon C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys 23:08:34.0359 10048 LVPr2Mon - ok 23:08:34.0421 10048 [ 5A9679D184A408982D5F0BD79874B44F ] LVPrcSrv C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe 23:08:34.0484 10048 LVPrcSrv - ok 23:08:34.0515 10048 [ A87BAA316538E526760353FF52742756 ] LVSrvLauncher C:\Programme\Gemeinsame Dateien\LogiShrd\SrvLnch\SrvLnch.exe 23:08:34.0546 10048 LVSrvLauncher - ok 23:08:34.0593 10048 [ 8B79A50360FC31DF6B7B979B686B4AA2 ] LVUSBSta C:\WINDOWS\system32\drivers\LVUSBSta.sys 23:08:34.0640 10048 LVUSBSta - ok 23:08:34.0687 10048 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 23:08:34.0765 10048 mdmxsdk - ok 23:08:34.0812 10048 [ B7550A7107281D170CE85524B1488C98 ] Messenger C:\WINDOWS\System32\msgsvc.dll 23:08:35.0000 10048 Messenger - ok 23:08:35.0171 10048 [ FAFE367D032ED82E9332B4C741A20216 ] Microsoft Office Groove Audit Service C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe 23:08:35.0203 10048 Microsoft Office Groove Audit Service - ok 23:08:35.0265 10048 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 23:08:35.0406 10048 mnmdd - ok 23:08:35.0453 10048 [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 23:08:35.0609 10048 mnmsrvc - ok 23:08:35.0687 10048 [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 23:08:35.0843 10048 Modem - ok 23:08:35.0875 10048 [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 23:08:36.0031 10048 Mouclass - ok 23:08:36.0093 10048 [ 66A6F73C74E1791464160A7065CE711A ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 23:08:36.0281 10048 mouhid - ok 23:08:36.0375 10048 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 23:08:36.0578 10048 MountMgr - ok 23:08:36.0687 10048 [ 96AA8BA23142CC8E2B30F3CAE0C80254 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe 23:08:36.0750 10048 MozillaMaintenance - ok 23:08:36.0781 10048 [ C0F8E0C2C3C0437CF37C6781896DC3EC ] MPE C:\WINDOWS\system32\DRIVERS\MPE.sys 23:08:36.0953 10048 MPE - ok 23:08:36.0968 10048 mraid35x - ok 23:08:37.0093 10048 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 23:08:37.0265 10048 MRxDAV - ok 23:08:37.0328 10048 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 23:08:37.0421 10048 MRxSmb - ok 23:08:37.0468 10048 [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC C:\WINDOWS\system32\msdtc.exe 23:08:37.0656 10048 MSDTC - ok 23:08:37.0718 10048 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 23:08:37.0875 10048 Msfs - ok 23:08:37.0890 10048 MSIServer - ok 23:08:37.0937 10048 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 23:08:38.0078 10048 MSKSSRV - ok 23:08:38.0140 10048 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 23:08:38.0312 10048 MSPCLOCK - ok 23:08:38.0312 10048 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 23:08:38.0453 10048 MSPQM - ok 23:08:38.0500 10048 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 23:08:38.0687 10048 mssmbios - ok 23:08:38.0781 10048 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 23:08:38.0937 10048 MSTEE - ok 23:08:38.0984 10048 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 23:08:39.0062 10048 Mup - ok 23:08:39.0093 10048 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 23:08:39.0234 10048 NABTSFEC - ok 23:08:39.0250 10048 [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent C:\WINDOWS\System32\qagentrt.dll 23:08:39.0453 10048 napagent - ok 23:08:39.0515 10048 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 23:08:39.0671 10048 NDIS - ok 23:08:39.0781 10048 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 23:08:39.0937 10048 NdisIP - ok 23:08:39.0984 10048 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 23:08:40.0062 10048 NdisTapi - ok 23:08:40.0109 10048 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 23:08:40.0296 10048 Ndisuio - ok 23:08:40.0328 10048 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 23:08:40.0500 10048 NdisWan - ok 23:08:40.0531 10048 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 23:08:40.0578 10048 NDProxy - ok 23:08:40.0609 10048 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 23:08:40.0734 10048 NetBIOS - ok 23:08:40.0796 10048 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 23:08:41.0031 10048 NetBT - ok 23:08:41.0062 10048 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE C:\WINDOWS\system32\netdde.exe 23:08:41.0234 10048 NetDDE - ok 23:08:41.0234 10048 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 23:08:41.0359 10048 NetDDEdsdm - ok 23:08:41.0468 10048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon C:\WINDOWS\system32\lsass.exe 23:08:41.0640 10048 Netlogon - ok 23:08:41.0671 10048 [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman C:\WINDOWS\System32\netman.dll 23:08:41.0859 10048 Netman - ok 23:08:41.0890 10048 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 23:08:41.0921 10048 NetTcpPortSharing - ok 23:08:42.0062 10048 [ 18B2D3E11ED7A3C898ADE6A6692B6929 ] NETw4x32 C:\WINDOWS\system32\DRIVERS\NETw4x32.sys 23:08:42.0343 10048 NETw4x32 - ok 23:08:42.0375 10048 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys 23:08:42.0703 10048 NIC1394 - ok 23:08:42.0750 10048 [ F1B67B6B0751AE0E6E964B02821206A3 ] Nla C:\WINDOWS\System32\mswsock.dll 23:08:42.0781 10048 Nla - ok 23:08:42.0906 10048 [ 6EF0506CE1F553E9BD085645933C8686 ] NMIndexingService C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe 23:08:42.0937 10048 NMIndexingService - ok 23:08:42.0984 10048 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 23:08:43.0171 10048 Npfs - ok 23:08:43.0234 10048 [ 2ADC0CA9945C65284B3D19BC18765974 ] NSCIRDA C:\WINDOWS\system32\DRIVERS\nscirda.sys 23:08:43.0375 10048 NSCIRDA - ok 23:08:43.0453 10048 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 23:08:43.0687 10048 Ntfs - ok 23:08:43.0703 10048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 23:08:43.0859 10048 NtLmSsp - ok 23:08:43.0921 10048 [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 23:08:44.0125 10048 NtmsSvc - ok 23:08:44.0171 10048 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 23:08:44.0312 10048 Null - ok 23:08:44.0343 10048 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 23:08:44.0500 10048 NwlnkFlt - ok 23:08:44.0500 10048 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 23:08:44.0671 10048 NwlnkFwd - ok 23:08:44.0843 10048 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE 23:08:44.0906 10048 odserv - ok 23:08:44.0953 10048 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys 23:08:45.0171 10048 ohci1394 - ok 23:08:45.0265 10048 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE 23:08:45.0312 10048 ose - ok 23:08:45.0375 10048 [ F84785660305B9B903FB3BCA8BA29837 ] Parport C:\WINDOWS\system32\drivers\Parport.sys 23:08:45.0531 10048 Parport - ok 23:08:45.0531 10048 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 23:08:45.0703 10048 PartMgr - ok 23:08:45.0765 10048 [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 23:08:45.0921 10048 ParVdm - ok 23:08:46.0015 10048 [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 23:08:46.0187 10048 PCI - ok 23:08:46.0203 10048 PCIDump - ok 23:08:46.0203 10048 [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 23:08:46.0359 10048 PCIIde - ok 23:08:46.0484 10048 [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 23:08:46.0671 10048 Pcmcia - ok 23:08:46.0687 10048 PDCOMP - ok 23:08:46.0687 10048 PDFRAME - ok 23:08:46.0703 10048 PDRELI - ok 23:08:46.0703 10048 PDRFRAME - ok 23:08:46.0750 10048 [ B071495101DF7DD946CC6850F0203C8A ] pepifilter C:\WINDOWS\system32\DRIVERS\lv302af.sys 23:08:46.0781 10048 pepifilter - ok 23:08:46.0796 10048 perc2 - ok 23:08:46.0796 10048 perc2hib - ok 23:08:46.0937 10048 [ 39C3CDF1F845E8CC14331BBD3799C7CB ] PID_PEPI C:\WINDOWS\system32\DRIVERS\LV302V32.SYS 23:08:47.0187 10048 PID_PEPI - ok 23:08:47.0218 10048 [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay C:\WINDOWS\system32\services.exe 23:08:47.0250 10048 PlugPlay - ok 23:08:47.0265 10048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 23:08:47.0390 10048 PolicyAgent - ok 23:08:47.0453 10048 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 23:08:47.0609 10048 PptpMiniport - ok 23:08:47.0625 10048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 23:08:47.0750 10048 ProtectedStorage - ok 23:08:47.0828 10048 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 23:08:47.0984 10048 PSched - ok 23:08:48.0046 10048 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 23:08:48.0203 10048 Ptilink - ok 23:08:48.0265 10048 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 23:08:48.0296 10048 PxHelp20 - ok 23:08:48.0312 10048 ql1080 - ok 23:08:48.0312 10048 Ql10wnt - ok 23:08:48.0312 10048 ql12160 - ok 23:08:48.0328 10048 ql1240 - ok 23:08:48.0328 10048 ql1280 - ok 23:08:48.0390 10048 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 23:08:48.0562 10048 RasAcd - ok 23:08:48.0593 10048 [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto C:\WINDOWS\System32\rasauto.dll 23:08:48.0781 10048 RasAuto - ok 23:08:48.0859 10048 [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys 23:08:48.0984 10048 Rasirda - ok 23:08:49.0000 10048 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 23:08:49.0171 10048 Rasl2tp - ok 23:08:49.0250 10048 [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan C:\WINDOWS\System32\rasmans.dll 23:08:49.0437 10048 RasMan - ok 23:08:49.0468 10048 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 23:08:49.0640 10048 RasPppoe - ok 23:08:49.0687 10048 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 23:08:49.0843 10048 Raspti - ok 23:08:49.0968 10048 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 23:08:50.0187 10048 Rdbss - ok 23:08:50.0218 10048 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 23:08:50.0406 10048 RDPCDD - ok 23:08:50.0421 10048 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 23:08:50.0625 10048 rdpdr - ok 23:08:50.0687 10048 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 23:08:50.0734 10048 RDPWD - ok 23:08:50.0812 10048 [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 23:08:50.0968 10048 RDSessMgr - ok 23:08:50.0984 10048 [ ED761D453856F795A7FE056E42C36365 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 23:08:51.0156 10048 redbook - ok 23:08:51.0265 10048 [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 23:08:51.0453 10048 RemoteAccess - ok 23:08:51.0546 10048 [ E4CD1F3D84E1C2CA0B8CF7501E201593 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 23:08:51.0718 10048 RemoteRegistry - ok 23:08:51.0750 10048 [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator C:\WINDOWS\system32\locator.exe 23:08:51.0937 10048 RpcLocator - ok 23:08:51.0968 10048 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs C:\WINDOWS\system32\rpcss.dll 23:08:52.0031 10048 RpcSs - ok 23:08:52.0093 10048 [ A3B23FB3F295694091F51865F98588B2 ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys 23:08:52.0140 10048 rspndr ( UnsignedFile.Multi.Generic ) - warning 23:08:52.0140 10048 rspndr - detected UnsignedFile.Multi.Generic (1) 23:08:52.0171 10048 [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP C:\WINDOWS\system32\rsvp.exe 23:08:52.0390 10048 RSVP - ok 23:08:52.0406 10048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs C:\WINDOWS\system32\lsass.exe 23:08:52.0546 10048 SamSs - ok 23:08:52.0640 10048 [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 23:08:52.0828 10048 SCardSvr - ok 23:08:52.0875 10048 [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule C:\WINDOWS\system32\schedsvc.dll 23:08:53.0062 10048 Schedule - ok 23:08:53.0125 10048 [ 8D04819A3CE51B9EB47E5689B44D43C4 ] sdbus C:\WINDOWS\system32\DRIVERS\sdbus.sys 23:08:53.0359 10048 sdbus - ok 23:08:53.0421 10048 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 23:08:53.0515 10048 Secdrv - ok 23:08:53.0546 10048 [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon C:\WINDOWS\System32\seclogon.dll 23:08:53.0687 10048 seclogon - ok 23:08:53.0734 10048 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS C:\WINDOWS\system32\sens.dll 23:08:54.0062 10048 SENS - ok 23:08:54.0109 10048 [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial C:\WINDOWS\system32\drivers\Serial.sys 23:08:54.0234 10048 Serial - ok 23:08:54.0281 10048 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 23:08:54.0421 10048 Sfloppy - ok 23:08:54.0562 10048 [ F96D196D81A92A6C55178F3F49B227A1 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 23:08:54.0656 10048 SharedAccess ( UnsignedFile.Multi.Generic ) - warning 23:08:54.0656 10048 SharedAccess - detected UnsignedFile.Multi.Generic (1) 23:08:54.0671 10048 [ 2DB7D303C36DDD055215052F118E8E75 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 23:08:54.0718 10048 ShellHWDetection - ok 23:08:54.0718 10048 Simbad - ok 23:08:54.0765 10048 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 23:08:54.0921 10048 SLIP - ok 23:08:54.0937 10048 Sparrow - ok 23:08:55.0046 10048 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 23:08:55.0234 10048 splitter - ok 23:08:55.0296 10048 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 23:08:55.0359 10048 Spooler - ok 23:08:55.0453 10048 [ 71E276F6D189413266EA22171806597B ] sptd C:\WINDOWS\system32\Drivers\sptd.sys 23:08:55.0453 10048 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71E276F6D189413266EA22171806597B 23:08:55.0453 10048 sptd ( LockedFile.Multi.Generic ) - warning 23:08:55.0453 10048 sptd - detected LockedFile.Multi.Generic (1) 23:08:55.0500 10048 [ 50FA898F8C032796D3B1B9951BB5A90F ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 23:08:55.0593 10048 sr - ok 23:08:55.0625 10048 [ FE77A85495065F3AD59C5C65B6C54182 ] srservice C:\WINDOWS\system32\srsvc.dll 23:08:55.0750 10048 srservice - ok 23:08:55.0828 10048 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 23:08:55.0890 10048 Srv - ok 23:08:55.0953 10048 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 23:08:56.0031 10048 SSDPSRV - ok 23:08:56.0062 10048 [ 71D609C5DFF067906D930BDE031C4CFE ] ssmdrv C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 23:08:56.0125 10048 ssmdrv ( UnsignedFile.Multi.Generic ) - warning 23:08:56.0125 10048 ssmdrv - detected UnsignedFile.Multi.Generic (1) 23:08:56.0203 10048 [ BC2C5985611C5356B24AEB370953DED9 ] stisvc C:\WINDOWS\system32\wiaservc.dll 23:08:56.0421 10048 stisvc - ok 23:08:56.0437 10048 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 23:08:56.0609 10048 streamip - ok 23:08:56.0671 10048 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 23:08:56.0796 10048 swenum - ok 23:08:56.0812 10048 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 23:08:56.0984 10048 swmidi - ok 23:08:56.0984 10048 SwPrv - ok 23:08:57.0000 10048 symc810 - ok 23:08:57.0046 10048 symc8xx - ok 23:08:57.0062 10048 sym_hi - ok 23:08:57.0062 10048 sym_u3 - ok 23:08:57.0156 10048 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 23:08:57.0281 10048 sysaudio - ok 23:08:57.0328 10048 [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 23:08:57.0484 10048 SysmonLog - ok 23:08:57.0515 10048 [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 23:08:57.0687 10048 TapiSrv - ok 23:08:57.0734 10048 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 23:08:57.0765 10048 Tcpip - ok 23:08:57.0812 10048 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 23:08:58.0015 10048 TDPIPE - ok 23:08:58.0046 10048 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 23:08:58.0218 10048 TDTCP - ok 23:08:58.0250 10048 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 23:08:58.0437 10048 TermDD - ok 23:08:58.0500 10048 [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService C:\WINDOWS\System32\termsrv.dll 23:08:58.0656 10048 TermService - ok 23:08:58.0687 10048 [ 2DB7D303C36DDD055215052F118E8E75 ] Themes C:\WINDOWS\System32\shsvcs.dll 23:08:58.0703 10048 Themes - ok 23:08:58.0781 10048 [ 78213F01CE781F93180BEF5EB5B3AD81 ] tifm21 C:\WINDOWS\system32\drivers\tifm21.sys 23:08:58.0875 10048 tifm21 - ok 23:08:58.0906 10048 [ 03681A1CE77F51586903869A5AB1DEAB ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 23:08:59.0046 10048 TlntSvr - ok 23:08:59.0062 10048 TosIde - ok 23:08:59.0109 10048 [ 626504572B175867F30F3215C04B3E2F ] TrkWks C:\WINDOWS\system32\trkwks.dll 23:08:59.0296 10048 TrkWks - ok 23:08:59.0343 10048 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 23:08:59.0515 10048 Udfs - ok 23:08:59.0515 10048 UIUSys - ok 23:08:59.0515 10048 ultra - ok 23:08:59.0625 10048 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 23:08:59.0890 10048 Update - ok 23:08:59.0937 10048 [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost C:\WINDOWS\System32\upnphost.dll 23:09:00.0031 10048 upnphost - ok 23:09:00.0046 10048 [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS C:\WINDOWS\System32\ups.exe 23:09:00.0218 10048 UPS - ok 23:09:00.0250 10048 [ 4B8A9C16B6D9258ED99C512AECB8C555 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys 23:09:00.0328 10048 USBAAPL - ok 23:09:00.0375 10048 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 23:09:00.0531 10048 usbaudio - ok 23:09:00.0640 10048 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 23:09:00.0796 10048 usbccgp - ok 23:09:00.0859 10048 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 23:09:01.0015 10048 usbehci - ok 23:09:01.0031 10048 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 23:09:01.0203 10048 usbhub - ok 23:09:01.0218 10048 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 23:09:01.0390 10048 usbprint - ok 23:09:01.0453 10048 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 23:09:01.0593 10048 USBSTOR - ok 23:09:01.0656 10048 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 23:09:01.0781 10048 usbuhci - ok 23:09:01.0828 10048 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 23:09:02.0031 10048 VgaSave - ok 23:09:02.0031 10048 ViaIde - ok 23:09:02.0109 10048 [ A5A712F4E880874A477AF790B5186E1D ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 23:09:02.0250 10048 VolSnap - ok 23:09:02.0281 10048 [ 68F106273BE29E7B7EF8266977268E78 ] VSS C:\WINDOWS\System32\vssvc.exe 23:09:02.0390 10048 VSS - ok 23:09:02.0453 10048 [ 39247D93BE13E0C67A996A837EAB8E02 ] W32Time C:\WINDOWS\system32\w32time.dll 23:09:02.0468 10048 W32Time ( UnsignedFile.Multi.Generic ) - warning 23:09:02.0468 10048 W32Time - detected UnsignedFile.Multi.Generic (1) 23:09:02.0531 10048 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 23:09:02.0703 10048 Wanarp - ok 23:09:02.0703 10048 WDICA - ok 23:09:02.0734 10048 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 23:09:02.0890 10048 wdmaud - ok 23:09:02.0953 10048 [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient C:\WINDOWS\System32\webclnt.dll 23:09:03.0109 10048 WebClient - ok 23:09:03.0187 10048 [ 9692AB8BA2DCD649A86B1B9B81154278 ] winachsf C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 23:09:03.0296 10048 winachsf - ok 23:09:03.0390 10048 winmgmt - ok 23:09:03.0437 10048 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 23:09:03.0468 10048 WmdmPmSN ( UnsignedFile.Multi.Generic ) - warning 23:09:03.0468 10048 WmdmPmSN - detected UnsignedFile.Multi.Generic (1) 23:09:03.0546 10048 [ FFA4D901D46D07A5BAB2D8307FBB51A6 ] Wmi C:\WINDOWS\System32\advapi32.dll 23:09:03.0593 10048 Wmi - ok 23:09:03.0656 10048 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 23:09:03.0843 10048 WmiAcpi - ok 23:09:03.0968 10048 [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 23:09:04.0171 10048 WmiApSrv - ok 23:09:04.0250 10048 [ BF05650BB7DF5E9EBDD25974E22403BB ] WMPNetworkSvc C:\Programme\Windows Media Player\WMPNetwk.exe 23:09:04.0375 10048 WMPNetworkSvc ( UnsignedFile.Multi.Generic ) - warning 23:09:04.0375 10048 WMPNetworkSvc - detected UnsignedFile.Multi.Generic (1) 23:09:04.0437 10048 [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc C:\WINDOWS\system32\wscsvc.dll 23:09:04.0578 10048 wscsvc - ok 23:09:04.0609 10048 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 23:09:04.0781 10048 WSTCODEC - ok 23:09:04.0843 10048 [ 727F02F3B19BAB3639E9358FFDD295E0 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 23:09:04.0890 10048 wuauserv - ok 23:09:04.0906 10048 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 23:09:04.0937 10048 WudfPf ( UnsignedFile.Multi.Generic ) - warning 23:09:04.0937 10048 WudfPf - detected UnsignedFile.Multi.Generic (1) 23:09:04.0953 10048 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 23:09:05.0015 10048 WudfRd ( UnsignedFile.Multi.Generic ) - warning 23:09:05.0015 10048 WudfRd - detected UnsignedFile.Multi.Generic (1) 23:09:05.0015 10048 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 23:09:05.0078 10048 WudfSvc ( UnsignedFile.Multi.Generic ) - warning 23:09:05.0078 10048 WudfSvc - detected UnsignedFile.Multi.Generic (1) 23:09:05.0156 10048 [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 23:09:05.0328 10048 WZCSVC - ok 23:09:05.0343 10048 [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 23:09:05.0546 10048 xmlprov - ok 23:09:05.0562 10048 ================ Scan global =============================== 23:09:05.0625 10048 [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WINDOWS\system32\basesrv.dll 23:09:05.0734 10048 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 23:09:05.0781 10048 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 23:09:05.0812 10048 [ A3EDBE9053889FB24AB22492472B39DC ] C:\WINDOWS\system32\services.exe 23:09:05.0812 10048 [Global] - ok 23:09:05.0812 10048 ================ Scan MBR ================================== 23:09:05.0843 10048 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0 23:09:06.0125 10048 \Device\Harddisk0\DR0 - ok 23:09:06.0125 10048 [ 65E858A8A0293BE11A920B0BC99D695E ] \Device\Harddisk1\DR4 23:09:07.0875 10048 \Device\Harddisk1\DR4 - ok 23:09:07.0875 10048 ================ Scan VBR ================================== 23:09:07.0875 10048 [ 5EE8E042B00DA1D443D7D40557749855 ] \Device\Harddisk0\DR0\Partition1 23:09:07.0890 10048 \Device\Harddisk0\DR0\Partition1 - ok 23:09:07.0890 10048 [ 7F96BE49507407BE5903063879D2C523 ] \Device\Harddisk1\DR4\Partition1 23:09:07.0890 10048 \Device\Harddisk1\DR4\Partition1 - ok 23:09:07.0890 10048 ============================================================ 23:09:07.0890 10048 Scan finished 23:09:07.0890 10048 ============================================================ 23:09:08.0031 10012 Detected object count: 14 23:09:08.0031 10012 Actual detected object count: 14 23:10:43.0234 10012 AntiVirScheduler ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0234 10012 AntiVirScheduler ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0234 10012 AntiVirService ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0234 10012 AntiVirService ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0234 10012 BASFND ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0234 10012 BASFND ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 rspndr ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 rspndr ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 SharedAccess ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 SharedAccess ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 sptd ( LockedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 ssmdrv ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 ssmdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 W32Time ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 W32Time ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 WmdmPmSN ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 WmdmPmSN ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 WMPNetworkSvc ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 WMPNetworkSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0250 10012 WudfPf ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0250 10012 WudfPf ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0265 10012 WudfRd ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0265 10012 WudfRd ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:10:43.0265 10012 WudfSvc ( UnsignedFile.Multi.Generic ) - skipped by user 23:10:43.0265 10012 WudfSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:11:00.0718 9612 ============================================================ 23:11:00.0718 9612 Scan started 23:11:00.0718 9612 Mode: Manual; SigCheck; TDLFS; 23:11:00.0718 9612 ============================================================ 23:11:01.0218 9612 ================ Scan system memory ======================== 23:11:01.0218 9612 System memory - ok 23:11:01.0218 9612 ================ Scan services ============================= 23:11:01.0265 9612 Abiosdsk - ok 23:11:01.0281 9612 abp480n5 - ok 23:11:01.0343 9612 [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 23:11:01.0859 9612 ACPI - ok 23:11:01.0937 9612 [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 23:11:02.0078 9612 ACPIEC - ok 23:11:02.0078 9612 adpu160m - ok 23:11:02.0140 9612 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 23:11:02.0265 9612 aec - ok 23:11:02.0312 9612 [ 6E1CC5AA9817CD13FBCEB35DAC0A77F7 ] AF15BDA C:\WINDOWS\system32\DRIVERS\AF15BDA.sys 23:11:02.0343 9612 AF15BDA - ok 23:11:02.0390 9612 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 23:11:02.0406 9612 AFD - ok 23:11:02.0421 9612 Aha154x - ok 23:11:02.0421 9612 aic78u2 - ok 23:11:02.0421 9612 aic78xx - ok 23:11:02.0468 9612 [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter C:\WINDOWS\system32\alrsvc.dll 23:11:02.0625 9612 Alerter - ok 23:11:02.0671 9612 [ 190CD73D4984F94D823F9444980513E5 ] ALG C:\WINDOWS\System32\alg.exe 23:11:02.0750 9612 ALG - ok 23:11:02.0750 9612 AliIde - ok 23:11:02.0750 9612 amsint - ok 23:11:02.0875 9612 [ D6C8942BEA3698A2E7559BD423BFA5D7 ] AntiVirScheduler C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe 23:11:02.0890 9612 AntiVirScheduler ( UnsignedFile.Multi.Generic ) - warning 23:11:02.0890 9612 AntiVirScheduler - detected UnsignedFile.Multi.Generic (1) 23:11:02.0921 9612 [ 335A142923FE7F97E8C8388ACD067568 ] AntiVirService C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe 23:11:02.0921 9612 AntiVirService ( UnsignedFile.Multi.Generic ) - warning 23:11:02.0921 9612 AntiVirService - detected UnsignedFile.Multi.Generic (1) 23:11:03.0000 9612 [ 2E3E53A6AEF23E24F402C7855B9B1542 ] Apple Mobile Device C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe 23:11:03.0015 9612 Apple Mobile Device - ok 23:11:03.0140 9612 [ D45960BE52C3C610D361977057F98C54 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 23:11:03.0218 9612 AppMgmt - ok 23:11:03.0281 9612 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys 23:11:03.0421 9612 Arp1394 - ok 23:11:03.0421 9612 asc - ok 23:11:03.0437 9612 asc3350p - ok 23:11:03.0437 9612 asc3550 - ok 23:11:03.0515 9612 ASFIPmon - ok 23:11:03.0625 9612 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 23:11:03.0640 9612 aspnet_state - ok 23:11:03.0687 9612 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 23:11:03.0843 9612 AsyncMac - ok 23:11:03.0953 9612 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 23:11:04.0093 9612 atapi - ok 23:11:04.0093 9612 Atdisk - ok 23:11:04.0125 9612 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 23:11:04.0265 9612 Atmarpc - ok 23:11:04.0312 9612 [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 23:11:04.0468 9612 AudioSrv - ok 23:11:04.0515 9612 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 23:11:04.0656 9612 audstub - ok 23:11:04.0703 9612 [ 87828ECD657F81503465AC705E845076 ] avgio C:\Programme\Avira\AntiVir PersonalEdition Classic\avgio.sys 23:11:04.0718 9612 avgio - ok 23:11:04.0781 9612 [ FCB30820BED1D3FEB55E3DD55A3F947F ] avgntflt C:\Programme\Avira\AntiVir PersonalEdition Classic\avgntflt.sys 23:11:04.0796 9612 avgntflt - ok 23:11:04.0812 9612 [ 0B09DF022250FB7BA91FB932EAC6EA9B ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys 23:11:04.0828 9612 avipbb - ok 23:11:04.0875 9612 [ F96038AA1EC4013A93D2420FC689D1E9 ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys 23:11:04.0906 9612 b57w2k - ok 23:11:04.0921 9612 [ 5C68AC6F3E5B3E6D6A78E97D05E42C3A ] BASFND C:\Programme\Broadcom\ASFIPMon\BASFND.sys 23:11:04.0937 9612 BASFND ( UnsignedFile.Multi.Generic ) - warning 23:11:04.0937 9612 BASFND - detected UnsignedFile.Multi.Generic (1) 23:11:04.0984 9612 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 23:11:05.0125 9612 Beep - ok 23:11:05.0234 9612 [ D6F603772A789BB3228F310D650B8BD1 ] BITS C:\WINDOWS\system32\qmgr.dll 23:11:05.0359 9612 BITS - ok 23:11:05.0468 9612 [ 5AB58C337AC65837FE404462AD6265AB ] Bonjour Service C:\Programme\Bonjour\mDNSResponder.exe 23:11:05.0500 9612 Bonjour Service - ok 23:11:05.0546 9612 [ B71549F23736ADF83A571061C47777FD ] Browser C:\WINDOWS\System32\browser.dll 23:11:05.0578 9612 Browser - ok 23:11:05.0609 9612 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 23:11:05.0765 9612 cbidf2k - ok 23:11:05.0812 9612 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 23:11:05.0968 9612 CCDECODE - ok 23:11:05.0968 9612 cd20xrnt - ok 23:11:05.0984 9612 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 23:11:06.0109 9612 Cdaudio - ok 23:11:06.0171 9612 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 23:11:06.0281 9612 Cdfs - ok 23:11:06.0312 9612 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 23:11:06.0468 9612 Cdrom - ok 23:11:06.0468 9612 Changer - ok 23:11:06.0500 9612 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc C:\WINDOWS\system32\cisvc.exe 23:11:06.0625 9612 CiSvc - ok 23:11:06.0640 9612 [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 23:11:06.0828 9612 ClipSrv - ok 23:11:06.0875 9612 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 23:11:06.0890 9612 clr_optimization_v2.0.50727_32 - ok 23:11:06.0937 9612 [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 23:11:07.0062 9612 CmBatt - ok 23:11:07.0062 9612 CmdIde - ok 23:11:07.0078 9612 [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 23:11:07.0203 9612 Compbatt - ok 23:11:07.0218 9612 COMSysApp - ok 23:11:07.0218 9612 Cpqarray - ok 23:11:07.0281 9612 [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 23:11:07.0421 9612 CryptSvc - ok 23:11:07.0421 9612 dac2w2k - ok 23:11:07.0421 9612 dac960nt - ok 23:11:07.0562 9612 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 23:11:07.0609 9612 DcomLaunch - ok 23:11:07.0656 9612 [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 23:11:07.0796 9612 Dhcp - ok 23:11:07.0796 9612 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 23:11:07.0937 9612 Disk - ok 23:11:07.0937 9612 dmadmin - ok 23:11:07.0984 9612 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 23:11:08.0140 9612 dmboot - ok 23:11:08.0171 9612 [ 53720AB12B48719D00E327DA470A619A ] dmio C:\WINDOWS\system32\DRIVERS\dmio.sys 23:11:08.0343 9612 dmio - ok 23:11:08.0375 9612 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 23:11:08.0515 9612 dmload - ok 23:11:08.0609 9612 [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver C:\WINDOWS\System32\dmserver.dll 23:11:08.0734 9612 dmserver - ok 23:11:08.0828 9612 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 23:11:08.0968 9612 DMusic - ok 23:11:09.0015 9612 [ 407F3227AC618FD1CA54B335B083DE07 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 23:11:09.0062 9612 Dnscache - ok 23:11:09.0156 9612 [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 23:11:09.0312 9612 Dot3svc - ok 23:11:09.0312 9612 dpti2o - ok 23:11:09.0406 9612 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 23:11:09.0531 9612 drmkaud - ok 23:11:09.0609 9612 [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost C:\WINDOWS\System32\eapsvc.dll 23:11:09.0718 9612 EapHost - ok 23:11:09.0828 9612 [ 877C18558D70587AA7823A1A308AC96B ] ERSvc C:\WINDOWS\System32\ersvc.dll 23:11:09.0968 9612 ERSvc - ok 23:11:10.0031 9612 [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog C:\WINDOWS\system32\services.exe 23:11:10.0062 9612 Eventlog - ok 23:11:10.0125 9612 [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem C:\WINDOWS\system32\es.dll 23:11:10.0156 9612 EventSystem - ok 23:11:10.0250 9612 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 23:11:10.0375 9612 Fastfat - ok 23:11:10.0421 9612 [ 2DB7D303C36DDD055215052F118E8E75 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 23:11:10.0453 9612 FastUserSwitchingCompatibility - ok 23:11:10.0515 9612 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 23:11:10.0640 9612 Fdc - ok 23:11:10.0703 9612 [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 23:11:10.0828 9612 Fips - ok 23:11:10.0890 9612 [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 23:11:10.0953 9612 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning 23:11:10.0953 9612 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1) 23:11:11.0015 9612 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 23:11:11.0156 9612 Flpydisk - ok 23:11:11.0218 9612 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 23:11:11.0343 9612 FltMgr - ok 23:11:11.0437 9612 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 23:11:11.0453 9612 FontCache3.0.0.0 - ok 23:11:11.0468 9612 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 23:11:11.0625 9612 Fs_Rec - ok 23:11:11.0625 9612 [ 8F1955CE42E1484714B542F341647778 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 23:11:11.0750 9612 Ftdisk - ok 23:11:11.0796 9612 [ B45F1DF1CCE34E2AF422F0ED78CD70EF ] FWLANUSB C:\WINDOWS\system32\DRIVERS\fwlanusb.sys 23:11:11.0812 9612 FWLANUSB - ok 23:11:11.0843 9612 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 23:11:11.0859 9612 GEARAspiWDM - ok 23:11:11.0921 9612 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 23:11:12.0062 9612 Gpc - ok 23:11:12.0125 9612 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 23:11:12.0250 9612 HDAudBus - ok 23:11:12.0328 9612 [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 23:11:12.0468 9612 helpsvc - ok 23:11:12.0468 9612 HidServ - ok 23:11:12.0515 9612 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 23:11:12.0640 9612 HidUsb - ok 23:11:12.0656 9612 [ ED29F14101523A6E0E808107405D452C ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 23:11:12.0796 9612 hkmsvc - ok 23:11:12.0796 9612 hpn - ok 23:11:12.0875 9612 [ 7D33D2B81BD8B4BC51B536B113295D51 ] HSFHWAZL C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 23:11:12.0906 9612 HSFHWAZL - ok 23:11:12.0953 9612 [ FB6AD8A16E22C91D5978B26E0300A331 ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 23:11:13.0000 9612 HSF_DPV - ok 23:11:13.0062 9612 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 23:11:13.0078 9612 HTTP - ok 23:11:13.0156 9612 [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 23:11:13.0281 9612 HTTPFilter - ok 23:11:13.0296 9612 i2omgmt - ok 23:11:13.0296 9612 i2omp - ok 23:11:13.0343 9612 [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 23:11:13.0468 9612 i8042prt - ok 23:11:13.0781 9612 [ 12C7F8D581C4A9F126F5F8F5683A1C29 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 23:11:14.0109 9612 ialm - ok 23:11:14.0250 9612 [ 5C7D72EAB04B1DF8C5D2ACC6551FDE49 ] ICQ Service C:\Programme\ICQ6Toolbar\ICQ Service.exe 23:11:14.0265 9612 ICQ Service - ok 23:11:14.0375 9612 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 23:11:14.0421 9612 idsvc - ok 23:11:14.0468 9612 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 23:11:14.0609 9612 Imapi - ok 23:11:14.0718 9612 [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService C:\WINDOWS\system32\imapi.exe 23:11:14.0843 9612 ImapiService - ok 23:11:14.0843 9612 ini910u - ok 23:11:15.0140 9612 [ 927CF2BE4E57FF55E23759AC0CA57AA3 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 23:11:15.0484 9612 IntcAzAudAddService - ok 23:11:15.0500 9612 IntelIde - ok 23:11:15.0546 9612 [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 23:11:15.0687 9612 intelppm - ok 23:11:15.0718 9612 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 23:11:15.0859 9612 Ip6Fw - ok 23:11:15.0890 9612 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 23:11:16.0046 9612 IpFilterDriver - ok 23:11:16.0078 9612 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 23:11:16.0234 9612 IpInIp - ok 23:11:16.0250 9612 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 23:11:16.0375 9612 IpNat - ok 23:11:16.0437 9612 [ 630D74599070824AF3DC63A894ADCDFC ] iPod Service C:\Programme\iPod\bin\iPodService.exe 23:11:16.0468 9612 iPod Service - ok 23:11:16.0546 9612 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 23:11:16.0671 9612 IPSec - ok 23:11:16.0718 9612 [ ACA5E7B54409F9CB5EED97ED0C81120E ] irda C:\WINDOWS\system32\DRIVERS\irda.sys 23:11:16.0781 9612 irda - ok 23:11:16.0843 9612 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 23:11:16.0906 9612 IRENUM - ok 23:11:16.0921 9612 [ 2EFE1DB1EC58A26B0C14BFDA122E246F ] Irmon C:\WINDOWS\System32\irmon.dll 23:11:16.0984 9612 Irmon - ok 23:11:17.0031 9612 [ 6DFB88F64135C525433E87648BDA30DE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 23:11:17.0171 9612 isapnp - ok 23:11:17.0187 9612 [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 23:11:17.0343 9612 Kbdclass - ok 23:11:17.0406 9612 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 23:11:17.0531 9612 kmixer - ok 23:11:17.0562 9612 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 23:11:17.0609 9612 KSecDD - ok 23:11:17.0656 9612 [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 23:11:17.0687 9612 lanmanserver - ok 23:11:17.0734 9612 [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 23:11:17.0765 9612 lanmanworkstation - ok 23:11:17.0765 9612 lbrtfdc - ok 23:11:17.0828 9612 [ 636714B7D43C8D0C80449123FD266920 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 23:11:17.0968 9612 LmHosts - ok 23:11:18.0015 9612 [ 9CE361764C5DD5FA5506510FE5D2297B ] LVcKap C:\WINDOWS\system32\DRIVERS\LVcKap.sys 23:11:18.0046 9612 LVcKap - ok 23:11:18.0140 9612 [ 1D28B53C50CC57062692862B8E083020 ] LVCOMSer C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe 23:11:18.0156 9612 LVCOMSer - ok 23:11:18.0218 9612 [ 94D03B31F36BB362FA5713470FCF1C79 ] LVPr2Mon C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys 23:11:18.0234 9612 LVPr2Mon - ok 23:11:18.0250 9612 [ 5A9679D184A408982D5F0BD79874B44F ] LVPrcSrv C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe 23:11:18.0265 9612 LVPrcSrv - ok 23:11:18.0343 9612 [ A87BAA316538E526760353FF52742756 ] LVSrvLauncher C:\Programme\Gemeinsame Dateien\LogiShrd\SrvLnch\SrvLnch.exe 23:11:18.0359 9612 LVSrvLauncher - ok 23:11:18.0406 9612 [ 8B79A50360FC31DF6B7B979B686B4AA2 ] LVUSBSta C:\WINDOWS\system32\drivers\LVUSBSta.sys 23:11:18.0421 9612 LVUSBSta - ok 23:11:18.0484 9612 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 23:11:18.0500 9612 mdmxsdk - ok 23:11:18.0546 9612 [ B7550A7107281D170CE85524B1488C98 ] Messenger C:\WINDOWS\System32\msgsvc.dll 23:11:18.0703 9612 Messenger - ok 23:11:18.0843 9612 [ FAFE367D032ED82E9332B4C741A20216 ] Microsoft Office Groove Audit Service C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe 23:11:18.0859 9612 Microsoft Office Groove Audit Service - ok 23:11:18.0906 9612 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 23:11:19.0031 9612 mnmdd - ok 23:11:19.0109 9612 [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 23:11:19.0250 9612 mnmsrvc - ok 23:11:19.0281 9612 [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 23:11:19.0421 9612 Modem - ok 23:11:19.0437 9612 [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 23:11:19.0578 9612 Mouclass - ok 23:11:19.0625 9612 [ 66A6F73C74E1791464160A7065CE711A ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 23:11:19.0765 9612 mouhid - ok 23:11:19.0812 9612 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 23:11:19.0953 9612 MountMgr - ok 23:11:20.0015 9612 [ 96AA8BA23142CC8E2B30F3CAE0C80254 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe 23:11:20.0031 9612 MozillaMaintenance - ok 23:11:20.0062 9612 [ C0F8E0C2C3C0437CF37C6781896DC3EC ] MPE C:\WINDOWS\system32\DRIVERS\MPE.sys 23:11:20.0203 9612 MPE - ok 23:11:20.0218 9612 mraid35x - ok 23:11:20.0250 9612 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 23:11:20.0390 9612 MRxDAV - ok 23:11:20.0468 9612 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 23:11:20.0500 9612 MRxSmb - ok 23:11:20.0546 9612 [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC C:\WINDOWS\system32\msdtc.exe 23:11:20.0671 9612 MSDTC - ok 23:11:20.0687 9612 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 23:11:20.0843 9612 Msfs - ok 23:11:20.0859 9612 MSIServer - ok 23:11:20.0906 9612 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 23:11:21.0031 9612 MSKSSRV - ok 23:11:21.0031 9612 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 23:11:21.0171 9612 MSPCLOCK - ok 23:11:21.0171 9612 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 23:11:21.0296 9612 MSPQM - ok 23:11:21.0343 9612 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 23:11:21.0468 9612 mssmbios - ok 23:11:21.0515 9612 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 23:11:21.0625 9612 MSTEE - ok 23:11:21.0671 9612 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 23:11:21.0703 9612 Mup - ok 23:11:21.0750 9612 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 23:11:21.0859 9612 NABTSFEC - ok 23:11:21.0890 9612 [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent C:\WINDOWS\System32\qagentrt.dll 23:11:22.0015 9612 napagent - ok 23:11:22.0062 9612 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 23:11:22.0187 9612 NDIS - ok 23:11:22.0218 9612 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 23:11:22.0359 9612 NdisIP - ok 23:11:22.0390 9612 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 23:11:22.0421 9612 NdisTapi - ok 23:11:22.0468 9612 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 23:11:22.0593 9612 Ndisuio - ok 23:11:22.0625 9612 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 23:11:22.0765 9612 NdisWan - ok 23:11:22.0812 9612 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 23:11:22.0828 9612 NDProxy - ok 23:11:22.0890 9612 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 23:11:23.0015 9612 NetBIOS - ok 23:11:23.0078 9612 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 23:11:23.0203 9612 NetBT - ok 23:11:23.0234 9612 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE C:\WINDOWS\system32\netdde.exe 23:11:23.0375 9612 NetDDE - ok 23:11:23.0375 9612 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 23:11:23.0500 9612 NetDDEdsdm - ok 23:11:23.0546 9612 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon C:\WINDOWS\system32\lsass.exe 23:11:23.0687 9612 Netlogon - ok 23:11:23.0718 9612 [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman C:\WINDOWS\System32\netman.dll 23:11:23.0843 9612 Netman - ok 23:11:23.0890 9612 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 23:11:23.0906 9612 NetTcpPortSharing - ok 23:11:24.0046 9612 [ 18B2D3E11ED7A3C898ADE6A6692B6929 ] NETw4x32 C:\WINDOWS\system32\DRIVERS\NETw4x32.sys 23:11:24.0203 9612 NETw4x32 - ok 23:11:24.0234 9612 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys 23:11:24.0375 9612 NIC1394 - ok 23:11:24.0437 9612 [ F1B67B6B0751AE0E6E964B02821206A3 ] Nla C:\WINDOWS\System32\mswsock.dll 23:11:24.0468 9612 Nla - ok 23:11:24.0593 9612 [ 6EF0506CE1F553E9BD085645933C8686 ] NMIndexingService C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe 23:11:24.0625 9612 NMIndexingService - ok 23:11:24.0671 9612 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 23:11:24.0796 9612 Npfs - ok 23:11:24.0812 9612 [ 2ADC0CA9945C65284B3D19BC18765974 ] NSCIRDA C:\WINDOWS\system32\DRIVERS\nscirda.sys 23:11:24.0890 9612 NSCIRDA - ok 23:11:24.0953 9612 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 23:11:25.0093 9612 Ntfs - ok 23:11:25.0125 9612 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 23:11:25.0250 9612 NtLmSsp - ok 23:11:25.0296 9612 [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 23:11:25.0468 9612 NtmsSvc - ok 23:11:25.0531 9612 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 23:11:25.0640 9612 Null - ok 23:11:25.0687 9612 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 23:11:25.0828 9612 NwlnkFlt - ok 23:11:25.0828 9612 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 23:11:25.0953 9612 NwlnkFwd - ok 23:11:26.0062 9612 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE 23:11:26.0093 9612 odserv - ok 23:11:26.0171 9612 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys 23:11:26.0296 9612 ohci1394 - ok 23:11:26.0359 9612 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE 23:11:26.0390 9612 ose - ok 23:11:26.0453 9612 [ F84785660305B9B903FB3BCA8BA29837 ] Parport C:\WINDOWS\system32\drivers\Parport.sys 23:11:26.0562 9612 Parport - ok 23:11:26.0578 9612 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 23:11:26.0703 9612 PartMgr - ok 23:11:26.0750 9612 [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 23:11:26.0890 9612 ParVdm - ok 23:11:26.0937 9612 [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 23:11:27.0078 9612 PCI - ok 23:11:27.0078 9612 PCIDump - ok 23:11:27.0078 9612 [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 23:11:27.0203 9612 PCIIde - ok 23:11:27.0250 9612 [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 23:11:27.0359 9612 Pcmcia - ok 23:11:27.0375 9612 PDCOMP - ok 23:11:27.0375 9612 PDFRAME - ok 23:11:27.0375 9612 PDRELI - ok 23:11:27.0390 9612 PDRFRAME - ok 23:11:27.0437 9612 [ B071495101DF7DD946CC6850F0203C8A ] pepifilter C:\WINDOWS\system32\DRIVERS\lv302af.sys 23:11:27.0453 9612 pepifilter - ok 23:11:27.0453 9612 perc2 - ok 23:11:27.0468 9612 perc2hib - ok 23:11:27.0593 9612 [ 39C3CDF1F845E8CC14331BBD3799C7CB ] PID_PEPI C:\WINDOWS\system32\DRIVERS\LV302V32.SYS 23:11:27.0703 9612 PID_PEPI - ok 23:11:27.0734 9612 [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay C:\WINDOWS\system32\services.exe 23:11:27.0750 9612 PlugPlay - ok 23:11:27.0765 9612 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 23:11:27.0875 9612 PolicyAgent - ok 23:11:27.0921 9612 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 23:11:28.0062 9612 PptpMiniport - ok 23:11:28.0062 9612 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 23:11:28.0187 9612 ProtectedStorage - ok 23:11:28.0218 9612 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 23:11:28.0359 9612 PSched - ok 23:11:28.0421 9612 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 23:11:28.0546 9612 Ptilink - ok 23:11:28.0609 9612 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 23:11:28.0640 9612 PxHelp20 - ok 23:11:28.0640 9612 ql1080 - ok 23:11:28.0656 9612 Ql10wnt - ok 23:11:28.0656 9612 ql12160 - ok 23:11:28.0656 9612 ql1240 - ok 23:11:28.0671 9612 ql1280 - ok 23:11:28.0718 9612 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 23:11:28.0843 9612 RasAcd - ok 23:11:28.0875 9612 [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto C:\WINDOWS\System32\rasauto.dll 23:11:29.0000 9612 RasAuto - ok 23:11:29.0031 9612 [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys 23:11:29.0093 9612 Rasirda - ok 23:11:29.0125 9612 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 23:11:29.0250 9612 Rasl2tp - ok 23:11:29.0296 9612 [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan C:\WINDOWS\System32\rasmans.dll 23:11:29.0421 9612 RasMan - ok 23:11:29.0453 9612 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 23:11:29.0562 9612 RasPppoe - ok 23:11:29.0593 9612 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 23:11:29.0703 9612 Raspti - ok 23:11:29.0734 9612 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 23:11:29.0859 9612 Rdbss - ok 23:11:29.0875 9612 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 23:11:30.0000 9612 RDPCDD - ok 23:11:30.0062 9612 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 23:11:30.0187 9612 rdpdr - ok 23:11:30.0250 9612 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 23:11:30.0296 9612 RDPWD - ok 23:11:30.0359 9612 [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 23:11:30.0515 9612 RDSessMgr - ok 23:11:30.0578 9612 [ ED761D453856F795A7FE056E42C36365 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 23:11:30.0703 9612 redbook - ok 23:11:30.0750 9612 [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 23:11:30.0906 9612 RemoteAccess - ok 23:11:30.0953 9612 [ E4CD1F3D84E1C2CA0B8CF7501E201593 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 23:11:31.0078 9612 RemoteRegistry - ok 23:11:31.0109 9612 [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator C:\WINDOWS\system32\locator.exe 23:11:31.0234 9612 RpcLocator - ok 23:11:31.0281 9612 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs C:\WINDOWS\system32\rpcss.dll 23:11:31.0343 9612 RpcSs - ok 23:11:31.0437 9612 [ A3B23FB3F295694091F51865F98588B2 ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys 23:11:31.0437 9612 rspndr ( UnsignedFile.Multi.Generic ) - warning 23:11:31.0437 9612 rspndr - detected UnsignedFile.Multi.Generic (1) 23:11:31.0484 9612 [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP C:\WINDOWS\system32\rsvp.exe 23:11:31.0609 9612 RSVP - ok 23:11:31.0640 9612 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs C:\WINDOWS\system32\lsass.exe 23:11:31.0750 9612 SamSs - ok 23:11:31.0796 9612 [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 23:11:31.0937 9612 SCardSvr - ok 23:11:32.0000 9612 [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule C:\WINDOWS\system32\schedsvc.dll 23:11:32.0140 9612 Schedule - ok 23:11:32.0156 9612 [ 8D04819A3CE51B9EB47E5689B44D43C4 ] sdbus C:\WINDOWS\system32\DRIVERS\sdbus.sys 23:11:32.0296 9612 sdbus - ok 23:11:32.0328 9612 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 23:11:32.0390 9612 Secdrv - ok 23:11:32.0406 9612 [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon C:\WINDOWS\System32\seclogon.dll 23:11:32.0531 9612 seclogon - ok 23:11:32.0562 9612 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS C:\WINDOWS\system32\sens.dll 23:11:32.0687 9612 SENS - ok 23:11:32.0718 9612 [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial C:\WINDOWS\system32\drivers\Serial.sys 23:11:32.0843 9612 Serial - ok 23:11:32.0859 9612 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 23:11:32.0984 9612 Sfloppy - ok 23:11:33.0062 9612 [ F96D196D81A92A6C55178F3F49B227A1 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 23:11:33.0062 9612 SharedAccess ( UnsignedFile.Multi.Generic ) - warning 23:11:33.0062 9612 SharedAccess - detected UnsignedFile.Multi.Generic (1) 23:11:33.0093 9612 [ 2DB7D303C36DDD055215052F118E8E75 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 23:11:33.0109 9612 ShellHWDetection - ok 23:11:33.0125 9612 Simbad - ok 23:11:33.0187 9612 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 23:11:33.0312 9612 SLIP - ok 23:11:33.0312 9612 Sparrow - ok 23:11:33.0359 9612 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 23:11:33.0484 9612 splitter - ok 23:11:33.0531 9612 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 23:11:33.0546 9612 Spooler - ok 23:11:33.0656 9612 [ 71E276F6D189413266EA22171806597B ] sptd C:\WINDOWS\system32\Drivers\sptd.sys 23:11:33.0656 9612 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71E276F6D189413266EA22171806597B 23:11:33.0671 9612 sptd ( LockedFile.Multi.Generic ) - warning 23:11:33.0671 9612 sptd - detected LockedFile.Multi.Generic (1) 23:11:33.0718 9612 [ 50FA898F8C032796D3B1B9951BB5A90F ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 23:11:33.0781 9612 sr - ok 23:11:33.0812 9612 [ FE77A85495065F3AD59C5C65B6C54182 ] srservice C:\WINDOWS\system32\srsvc.dll 23:11:33.0890 9612 srservice - ok 23:11:33.0953 9612 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 23:11:34.0031 9612 Srv - ok 23:11:34.0078 9612 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 23:11:34.0171 9612 SSDPSRV - ok 23:11:34.0218 9612 [ 71D609C5DFF067906D930BDE031C4CFE ] ssmdrv C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 23:11:34.0234 9612 ssmdrv ( UnsignedFile.Multi.Generic ) - warning 23:11:34.0234 9612 ssmdrv - detected UnsignedFile.Multi.Generic (1) 23:11:34.0296 9612 [ BC2C5985611C5356B24AEB370953DED9 ] stisvc C:\WINDOWS\system32\wiaservc.dll 23:11:34.0437 9612 stisvc - ok 23:11:34.0468 9612 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 23:11:34.0609 9612 streamip - ok 23:11:34.0687 9612 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 23:11:34.0796 9612 swenum - ok 23:11:34.0812 9612 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 23:11:34.0937 9612 swmidi - ok 23:11:34.0937 9612 SwPrv - ok 23:11:34.0953 9612 symc810 - ok 23:11:34.0953 9612 symc8xx - ok 23:11:34.0968 9612 sym_hi - ok 23:11:34.0968 9612 sym_u3 - ok 23:11:34.0984 9612 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 23:11:35.0109 9612 sysaudio - ok 23:11:35.0156 9612 [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 23:11:35.0265 9612 SysmonLog - ok 23:11:35.0312 9612 [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 23:11:35.0437 9612 TapiSrv - ok 23:11:35.0453 9612 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 23:11:35.0484 9612 Tcpip - ok 23:11:35.0515 9612 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 23:11:35.0656 9612 TDPIPE - ok 23:11:35.0687 9612 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 23:11:35.0796 9612 TDTCP - ok 23:11:35.0843 9612 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 23:11:35.0968 9612 TermDD - ok 23:11:36.0000 9612 [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService C:\WINDOWS\System32\termsrv.dll 23:11:36.0109 9612 TermService - ok 23:11:36.0140 9612 [ 2DB7D303C36DDD055215052F118E8E75 ] Themes C:\WINDOWS\System32\shsvcs.dll 23:11:36.0156 9612 Themes - ok 23:11:36.0250 9612 [ 78213F01CE781F93180BEF5EB5B3AD81 ] tifm21 C:\WINDOWS\system32\drivers\tifm21.sys 23:11:36.0265 9612 tifm21 - ok 23:11:36.0312 9612 [ 03681A1CE77F51586903869A5AB1DEAB ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 23:11:36.0406 9612 TlntSvr - ok 23:11:36.0406 9612 TosIde - ok 23:11:36.0468 9612 [ 626504572B175867F30F3215C04B3E2F ] TrkWks C:\WINDOWS\system32\trkwks.dll 23:11:36.0578 9612 TrkWks - ok 23:11:36.0656 9612 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 23:11:36.0796 9612 Udfs - ok 23:11:36.0796 9612 UIUSys - ok 23:11:36.0796 9612 ultra - ok 23:11:36.0859 9612 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 23:11:37.0000 9612 Update - ok 23:11:37.0031 9612 [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost C:\WINDOWS\System32\upnphost.dll 23:11:37.0093 9612 upnphost - ok 23:11:37.0125 9612 [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS C:\WINDOWS\System32\ups.exe 23:11:37.0281 9612 UPS - ok 23:11:37.0328 9612 [ 4B8A9C16B6D9258ED99C512AECB8C555 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys 23:11:37.0375 9612 USBAAPL - ok 23:11:37.0421 9612 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 23:11:37.0531 9612 usbaudio - ok 23:11:37.0578 9612 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 23:11:37.0718 9612 usbccgp - ok 23:11:37.0765 9612 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 23:11:37.0890 9612 usbehci - ok 23:11:37.0906 9612 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 23:11:38.0046 9612 usbhub - ok 23:11:38.0078 9612 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 23:11:38.0218 9612 usbprint - ok 23:11:38.0281 9612 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 23:11:38.0406 9612 USBSTOR - ok 23:11:38.0468 9612 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 23:11:38.0578 9612 usbuhci - ok 23:11:38.0640 9612 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 23:11:38.0796 9612 VgaSave - ok 23:11:38.0796 9612 ViaIde - ok 23:11:38.0812 9612 [ A5A712F4E880874A477AF790B5186E1D ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 23:11:38.0937 9612 VolSnap - ok 23:11:38.0968 9612 [ 68F106273BE29E7B7EF8266977268E78 ] VSS C:\WINDOWS\System32\vssvc.exe 23:11:39.0031 9612 VSS - ok 23:11:39.0078 9612 [ 39247D93BE13E0C67A996A837EAB8E02 ] W32Time C:\WINDOWS\system32\w32time.dll 23:11:39.0093 9612 W32Time ( UnsignedFile.Multi.Generic ) - warning 23:11:39.0093 9612 W32Time - detected UnsignedFile.Multi.Generic (1) 23:11:39.0156 9612 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 23:11:39.0296 9612 Wanarp - ok 23:11:39.0296 9612 WDICA - ok 23:11:39.0312 9612 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 23:11:39.0437 9612 wdmaud - ok 23:11:39.0500 9612 [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient C:\WINDOWS\System32\webclnt.dll 23:11:39.0625 9612 WebClient - ok 23:11:39.0703 9612 [ 9692AB8BA2DCD649A86B1B9B81154278 ] winachsf C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 23:11:39.0734 9612 winachsf - ok 23:11:39.0843 9612 winmgmt - ok 23:11:39.0890 9612 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 23:11:39.0890 9612 WmdmPmSN ( UnsignedFile.Multi.Generic ) - warning 23:11:39.0890 9612 WmdmPmSN - detected UnsignedFile.Multi.Generic (1) 23:11:39.0968 9612 [ FFA4D901D46D07A5BAB2D8307FBB51A6 ] Wmi C:\WINDOWS\System32\advapi32.dll 23:11:40.0031 9612 Wmi - ok 23:11:40.0093 9612 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 23:11:40.0218 9612 WmiAcpi - ok 23:11:40.0312 9612 [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 23:11:40.0453 9612 WmiApSrv - ok 23:11:40.0531 9612 [ BF05650BB7DF5E9EBDD25974E22403BB ] WMPNetworkSvc C:\Programme\Windows Media Player\WMPNetwk.exe 23:11:40.0593 9612 WMPNetworkSvc ( UnsignedFile.Multi.Generic ) - warning 23:11:40.0593 9612 WMPNetworkSvc - detected UnsignedFile.Multi.Generic (1) 23:11:40.0656 9612 [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc C:\WINDOWS\system32\wscsvc.dll 23:11:40.0781 9612 wscsvc - ok 23:11:40.0812 9612 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 23:11:40.0968 9612 WSTCODEC - ok 23:11:41.0015 9612 [ 727F02F3B19BAB3639E9358FFDD295E0 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 23:11:41.0046 9612 wuauserv - ok 23:11:41.0078 9612 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 23:11:41.0078 9612 WudfPf ( UnsignedFile.Multi.Generic ) - warning 23:11:41.0078 9612 WudfPf - detected UnsignedFile.Multi.Generic (1) 23:11:41.0093 9612 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 23:11:41.0093 9612 WudfRd ( UnsignedFile.Multi.Generic ) - warning 23:11:41.0093 9612 WudfRd - detected UnsignedFile.Multi.Generic (1) 23:11:41.0093 9612 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 23:11:41.0109 9612 WudfSvc ( UnsignedFile.Multi.Generic ) - warning 23:11:41.0109 9612 WudfSvc - detected UnsignedFile.Multi.Generic (1) 23:11:41.0156 9612 [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 23:11:41.0343 9612 WZCSVC - ok 23:11:41.0359 9612 [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 23:11:41.0500 9612 xmlprov - ok 23:11:41.0515 9612 ================ Scan global =============================== 23:11:41.0578 9612 [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WINDOWS\system32\basesrv.dll 23:11:41.0609 9612 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 23:11:41.0625 9612 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 23:11:41.0640 9612 [ A3EDBE9053889FB24AB22492472B39DC ] C:\WINDOWS\system32\services.exe 23:11:41.0656 9612 [Global] - ok 23:11:41.0656 9612 ================ Scan MBR ================================== 23:11:41.0687 9612 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0 23:11:41.0968 9612 \Device\Harddisk0\DR0 - ok 23:11:41.0968 9612 [ 65E858A8A0293BE11A920B0BC99D695E ] \Device\Harddisk1\DR4 23:11:43.0031 9612 \Device\Harddisk1\DR4 - ok 23:11:43.0031 9612 ================ Scan VBR ================================== 23:11:43.0046 9612 [ 5EE8E042B00DA1D443D7D40557749855 ] \Device\Harddisk0\DR0\Partition1 23:11:43.0046 9612 \Device\Harddisk0\DR0\Partition1 - ok 23:11:43.0062 9612 [ 7F96BE49507407BE5903063879D2C523 ] \Device\Harddisk1\DR4\Partition1 23:11:43.0062 9612 \Device\Harddisk1\DR4\Partition1 - ok 23:11:43.0062 9612 ============================================================ 23:11:43.0062 9612 Scan finished 23:11:43.0062 9612 ============================================================ 23:11:43.0062 9640 Detected object count: 14 23:11:43.0062 9640 Actual detected object count: 14 Ist es so schlimm!!! Hab ich was falsch gemacht? |
27.02.2013, 12:58 | #10 |
/// Malware-holic | GVU Trojaner auf Laptop mit WIN XP Hi, Scan mit Combofix
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.02.2013, 22:29 | #11 |
| GVU Trojaner auf Laptop mit WIN XP Hallo, seit heute auf meinem anderm Rechner. Avira meldet immer wieder trotz löschen Virus oder unerwünschtes Programm. C:\test.exe TR/Inject. 391680.1 was kann ich tun Danke schon mal im voraus!!! Hallo, Avira meldet immer wieder trotz löschen Virus oder unerwünschtes Programm. C:\test.exe TR/Inject. 391680.1 was kann ich tun Danke schon mal im voraus!!! Malwarebytes Anti-Malware 1.70.0.1100 Malwarebytes : Free Anti-Malware download Datenbank Version: v2013.02.27.11 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Dell :: GX280 [Administrator] 27.02.2013 22:16:22 MBAM-log-2013-02-27 (22-27-09).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 199900 Laufzeit: 10 Minute(n), 17 Sekunde(n) Infizierte Speicherprozesse: 1 C:\WINDOWS\system32\dmwu.exe (PUP.InstallBrain) -> 2008 -> Keine Aktion durchgeführt. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 3 HKCR\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750} (Trojan.BHO) -> Keine Aktion durchgeführt. HKCR\PNGFilter.CoPNGFilter.1 (Trojan.BHO) -> Keine Aktion durchgeführt. HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 2 HKCR\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32| (Trojan.0Access) -> Bösartig: (C:\RECYCLER\S-1-5-18\$9209ea2984704f1fa44854f1aebced54\n.) Gut: (fastprox.dll) -> Keine Aktion durchgeführt. HKCR\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\InProcServer32| (Trojan.0Access) -> Bösartig: (C:\RECYCLER\S-1-5-21-1177238915-920026266-1417001333-1003\$9209ea2984704f1fa44854f1aebced54\n.) Gut: (shell32.dll) -> Keine Aktion durchgeführt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 6 C:\Dokumente und Einstellungen\Dell\Lokale Einstellungen\Temp\35.tmp (Trojan.BHO) -> Keine Aktion durchgeführt. C:\Dokumente und Einstellungen\Dell\Anwendungsdaten\msconfig.dat (Trojan.Zbot) -> Keine Aktion durchgeführt. C:\RECYCLER\S-1-5-21-1177238915-920026266-1417001333-1003\Dc158.exe (PUP.Adware.Agent) -> Keine Aktion durchgeführt. C:\Dokumente und Einstellungen\Dell\Lokale Einstellungen\Temp\wzb4d7\Key-Generator\keygen.exe (RiskWare.Tool.HCK) -> Keine Aktion durchgeführt. C:\Dokumente und Einstellungen\Dell\Anwendungsdaten\msconfig.ini (Trojan.Agent) -> Keine Aktion durchgeführt. C:\WINDOWS\system32\dmwu.exe (PUP.InstallBrain) -> Keine Aktion durchgeführt. (Ende) |
27.02.2013, 22:34 | #12 |
/// Malware-holic | GVU Trojaner auf Laptop mit WIN XP ist das Malwarebytes Log vom dem pc den wir bearbeiten?
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.02.2013, 22:36 | #13 |
| GVU Trojaner auf Laptop mit WIN XP Ja ist es!! Ich wüsste gar nicht was ich ohne Sie machen würde!!! Warum fang ich mir das überhaupt ein. jetzt meldet Avia noch zwei TR/spy.ZBot.irttea |
27.02.2013, 23:28 | #14 |
/// Malware-holic | GVU Trojaner auf Laptop mit WIN XP hi C:\Dokumente und Einstellungen\Dell\Lokale Einstellungen\Temp\wzb4d7\Key-Generator\keygen.exe (RiskWare.Tool.HCK) -> Keine Aktion durchgeführt. http://www.trojaner-board.de/95393-c...-software.html dies unterstützen wir nicht. wenn du onlinebanking nutzt, lasse es sperren. der pc muss neu aufgesetzt und dann abgesichert werden 1. Datenrettung:
ich werde außerdem noch weitere punkte dazu posten. 4. alle Passwörter ändern! 5. nach PC Absicherung, die gesicherten Daten prüfen und falls sauber: zurückspielen. 6. werde ich dann noch was zum absichern von Onlinebanking mit Chip Card Reader + Star Money sagen.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
28.02.2013, 11:53 | #15 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | GVU Trojaner auf Laptop mit WIN XPZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu GVU Trojaner auf Laptop mit WIN XP |
abend, andere, anderen, eingefangen, einiger, funktionier, funktioniert, gefangen, gen, guten, gvu trojaner, kaspersky, konnte, laptop, rechner, troja, trojaner, trojaner - ihr computer wurde gesperrt, trojaner eingefangen, win, win xp, zusammen |