|
Plagegeister aller Art und deren Bekämpfung: Haeufige Abstuerze und weiterleitungen im FirefoxWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.04.2013, 11:25 | #1 |
| Haeufige Abstuerze und weiterleitungen im Firefox Hallo, seit ca. 2 Wochen treibt mich der Firefox auf die Palme. Teilweise stuerzt der Browser in den unterschiedlichsten Situationen mehrmals am Stück ab um anschliessend wieder 1-2 Stunden stabil zu laufen, die Abstürze konnte ich nicht rekonstruieren. Zudem werde ich stets beim ersten Aufruf der pcgh.de Seite weitergeleitet, ueber pricerunner.de hin zu ihreit.de Dabei spielt es keine Rolle ob ich die URL direkt eingebe oder die Seite über google betrete. Auch eine komplette Deinstallation mit anschliessender Bereinigung der Registry brachte keinen Erfolg. Ich hoffe Ihr koennt mir helfen, Danke |
09.04.2013, 13:14 | #2 |
/// TB-Ausbilder | Haeufige Abstuerze und weiterleitungen im Firefox!! Hinweis an Mitlesende !! Dieses Thema und die Anweisungen sind nur für diesen speziellen Fall gedacht. Sie könnten andere Computer schwer beschädigen. Öffnet bitte euer eigenes Thema. Ich werde dir bei deinem Problem helfen. Die Bereinigung funktioniert nur, wenn du dich an die folgenden Regeln hälst: Bitte lesen: Regeln für die Bereinigung
Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Laufwerksemulationen abschalten mit Defogger Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop und starte es:Schritt 2: Scan mit aswMBR
Schritt 3: Scan mit dem TDSS-Killer Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen.
Schritt 4: Scan mit DDS+ (mit attach) Downloade dir bitte DDS (von sUBs) und speichere die Datei auf deinem Desktop.
__________________ |
09.04.2013, 15:02 | #3 |
| Haeufige Abstuerze und weiterleitungen im Firefox Danke fuer die Hilfe, hier alle benoetigten Logfiles.
__________________defogger_disable Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 15:00 on 09/04/2013 (admin) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- aswMBR Code:
ATTFilter aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-04-09 15:05:56 ----------------------------- 15:05:56.345 OS Version: Windows x64 6.1.7601 Service Pack 1 15:05:56.345 Number of processors: 4 586 0x1E05 15:05:56.345 ComputerName: MAURICE-PC UserName: admin 15:05:56.486 Initialize success 15:06:04.642 AVAST engine defs: 13040900 15:06:18.517 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T1L0-7 15:06:18.533 Disk 0 Vendor: OCZ-VERTEX2 1.11 Size: 114473MB BusType: 3 15:06:18.533 Disk 0 MBR read successfully 15:06:18.533 Disk 0 MBR scan 15:06:18.548 Disk 0 Windows 7 default MBR code 15:06:18.548 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 15:06:18.580 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 114371 MB offset 206848 15:06:18.626 Disk 0 scanning C:\Windows\system32\drivers 15:06:23.517 Service scanning 15:06:36.533 Modules scanning 15:06:36.533 Disk 0 trace - called modules: 15:06:36.548 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 15:06:36.548 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004209060] 15:06:36.548 3 CLASSPNP.SYS[fffff880018fe43f] -> nt!IofCallDriver -> [0xfffffa8003fbd670] 15:06:36.564 5 ACPI.sys[fffff88000ef97a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T1L0-7[0xfffffa8003fef060] 15:06:36.705 AVAST engine scan C:\Windows 15:06:37.486 AVAST engine scan C:\Windows\system32 15:08:36.543 AVAST engine scan C:\Windows\system32\drivers 15:08:42.184 AVAST engine scan C:\Users\admin 15:42:22.167 AVAST engine scan C:\ProgramData 15:46:41.706 Scan finished successfully 15:47:41.487 Disk 0 MBR has been saved successfully to "C:\Users\admin\Desktop\MBR.dat" 15:47:41.565 The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt" Code:
ATTFilter 15:04:44.0258 4196 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 15:04:44.0336 4196 ============================================================ 15:04:44.0336 4196 Current date / time: 2013/04/09 15:04:44.0336 15:04:44.0336 4196 SystemInfo: 15:04:44.0336 4196 15:04:44.0336 4196 OS Version: 6.1.7601 ServicePack: 1.0 15:04:44.0336 4196 Product type: Workstation 15:04:44.0336 4196 ComputerName: MAURICE-PC 15:04:44.0336 4196 UserName: admin 15:04:44.0336 4196 Windows directory: C:\Windows 15:04:44.0336 4196 System windows directory: C:\Windows 15:04:44.0336 4196 Running under WOW64 15:04:44.0336 4196 Processor architecture: Intel x64 15:04:44.0336 4196 Number of processors: 4 15:04:44.0336 4196 Page size: 0x1000 15:04:44.0336 4196 Boot type: Normal boot 15:04:44.0336 4196 ============================================================ 15:04:45.0024 4196 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 15:04:45.0040 4196 ============================================================ 15:04:45.0040 4196 \Device\Harddisk0\DR0: 15:04:45.0040 4196 MBR partitions: 15:04:45.0040 4196 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 15:04:45.0040 4196 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xDF61800 15:04:45.0040 4196 ============================================================ 15:04:45.0040 4196 C: <-> \Device\Harddisk0\DR0\Partition2 15:04:45.0040 4196 ============================================================ 15:04:45.0040 4196 Initialize success 15:04:45.0040 4196 ============================================================ 15:47:53.0285 3188 ============================================================ 15:47:53.0285 3188 Scan started 15:47:53.0285 3188 Mode: Manual; TDLFS; 15:47:53.0285 3188 ============================================================ 15:47:53.0582 3188 ================ Scan system memory ======================== 15:47:53.0582 3188 System memory - ok 15:47:53.0582 3188 ================ Scan services ============================= 15:47:53.0613 3188 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 15:47:53.0613 3188 1394ohci - ok 15:47:53.0644 3188 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 15:47:53.0644 3188 ACPI - ok 15:47:53.0644 3188 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 15:47:53.0644 3188 AcpiPmi - ok 15:47:53.0707 3188 [ DBD5934D88CDD8B8C255D857DF9F689B ] AddonsHelper C:\Users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe 15:47:53.0785 3188 AddonsHelper - ok 15:47:53.0785 3188 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 15:47:53.0785 3188 AdobeARMservice - ok 15:47:53.0800 3188 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 15:47:53.0816 3188 AdobeFlashPlayerUpdateSvc - ok 15:47:53.0832 3188 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 15:47:53.0847 3188 adp94xx - ok 15:47:53.0847 3188 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 15:47:53.0847 3188 adpahci - ok 15:47:53.0863 3188 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 15:47:53.0863 3188 adpu320 - ok 15:47:53.0863 3188 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 15:47:53.0863 3188 AeLookupSvc - ok 15:47:53.0878 3188 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 15:47:53.0878 3188 AFD - ok 15:47:53.0878 3188 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 15:47:53.0878 3188 agp440 - ok 15:47:53.0878 3188 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 15:47:53.0878 3188 ALG - ok 15:47:53.0894 3188 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 15:47:53.0894 3188 aliide - ok 15:47:53.0910 3188 ALSysIO - ok 15:47:53.0910 3188 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 15:47:53.0910 3188 amdide - ok 15:47:53.0910 3188 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 15:47:53.0910 3188 AmdK8 - ok 15:47:53.0925 3188 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 15:47:53.0925 3188 AmdPPM - ok 15:47:53.0925 3188 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 15:47:53.0925 3188 amdsata - ok 15:47:53.0925 3188 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 15:47:53.0925 3188 amdsbs - ok 15:47:53.0941 3188 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 15:47:53.0941 3188 amdxata - ok 15:47:53.0941 3188 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 15:47:53.0941 3188 AppID - ok 15:47:53.0941 3188 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 15:47:53.0941 3188 AppIDSvc - ok 15:47:53.0941 3188 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 15:47:53.0957 3188 Appinfo - ok 15:47:53.0957 3188 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll 15:47:53.0957 3188 AppMgmt - ok 15:47:53.0957 3188 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 15:47:53.0957 3188 arc - ok 15:47:53.0972 3188 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 15:47:53.0972 3188 arcsas - ok 15:47:53.0988 3188 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 15:47:53.0988 3188 aspnet_state - ok 15:47:53.0988 3188 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 15:47:53.0988 3188 AsyncMac - ok 15:47:53.0988 3188 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 15:47:53.0988 3188 atapi - ok 15:47:54.0003 3188 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 15:47:54.0003 3188 AudioEndpointBuilder - ok 15:47:54.0019 3188 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 15:47:54.0019 3188 AudioSrv - ok 15:47:54.0019 3188 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 15:47:54.0019 3188 AxInstSV - ok 15:47:54.0035 3188 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 15:47:54.0035 3188 b06bdrv - ok 15:47:54.0035 3188 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 15:47:54.0050 3188 b57nd60a - ok 15:47:54.0050 3188 [ 7729395761F4061A643B573BF7F19AA8 ] BackupReader C:\Windows\system32\DRIVERS\BackupReader.sys 15:47:54.0050 3188 BackupReader - ok 15:47:54.0050 3188 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 15:47:54.0050 3188 BDESVC - ok 15:47:54.0050 3188 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 15:47:54.0050 3188 Beep - ok 15:47:54.0066 3188 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 15:47:54.0082 3188 BFE - ok 15:47:54.0082 3188 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 15:47:54.0097 3188 BITS - ok 15:47:54.0097 3188 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 15:47:54.0097 3188 blbdrive - ok 15:47:54.0097 3188 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 15:47:54.0113 3188 bowser - ok 15:47:54.0113 3188 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 15:47:54.0113 3188 BrFiltLo - ok 15:47:54.0113 3188 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 15:47:54.0113 3188 BrFiltUp - ok 15:47:54.0113 3188 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 15:47:54.0113 3188 Browser - ok 15:47:54.0128 3188 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 15:47:54.0128 3188 Brserid - ok 15:47:54.0128 3188 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 15:47:54.0128 3188 BrSerWdm - ok 15:47:54.0128 3188 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 15:47:54.0128 3188 BrUsbMdm - ok 15:47:54.0128 3188 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 15:47:54.0128 3188 BrUsbSer - ok 15:47:54.0144 3188 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 15:47:54.0144 3188 BTHMODEM - ok 15:47:54.0144 3188 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 15:47:54.0144 3188 bthserv - ok 15:47:54.0144 3188 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 15:47:54.0144 3188 cdfs - ok 15:47:54.0160 3188 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 15:47:54.0160 3188 cdrom - ok 15:47:54.0160 3188 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 15:47:54.0160 3188 CertPropSvc - ok 15:47:54.0160 3188 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 15:47:54.0160 3188 circlass - ok 15:47:54.0175 3188 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 15:47:54.0175 3188 CLFS - ok 15:47:54.0175 3188 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 15:47:54.0191 3188 clr_optimization_v2.0.50727_32 - ok 15:47:54.0191 3188 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 15:47:54.0191 3188 clr_optimization_v2.0.50727_64 - ok 15:47:54.0191 3188 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 15:47:54.0207 3188 clr_optimization_v4.0.30319_32 - ok 15:47:54.0207 3188 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 15:47:54.0207 3188 clr_optimization_v4.0.30319_64 - ok 15:47:54.0207 3188 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 15:47:54.0207 3188 CmBatt - ok 15:47:54.0222 3188 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 15:47:54.0222 3188 cmdide - ok 15:47:54.0222 3188 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 15:47:54.0222 3188 CNG - ok 15:47:54.0238 3188 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 15:47:54.0238 3188 Compbatt - ok 15:47:54.0238 3188 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 15:47:54.0238 3188 CompositeBus - ok 15:47:54.0238 3188 COMSysApp - ok 15:47:54.0238 3188 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 15:47:54.0238 3188 crcdisk - ok 15:47:54.0253 3188 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 15:47:54.0253 3188 CryptSvc - ok 15:47:54.0253 3188 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys 15:47:54.0269 3188 CSC - ok 15:47:54.0269 3188 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll 15:47:54.0285 3188 CscService - ok 15:47:54.0300 3188 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 15:47:54.0300 3188 DcomLaunch - ok 15:47:54.0300 3188 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 15:47:54.0300 3188 defragsvc - ok 15:47:54.0316 3188 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 15:47:54.0316 3188 DfsC - ok 15:47:54.0316 3188 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 15:47:54.0316 3188 Dhcp - ok 15:47:54.0332 3188 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 15:47:54.0332 3188 discache - ok 15:47:54.0332 3188 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 15:47:54.0332 3188 Disk - ok 15:47:54.0332 3188 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 15:47:54.0332 3188 Dnscache - ok 15:47:54.0347 3188 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 15:47:54.0347 3188 dot3svc - ok 15:47:54.0347 3188 [ B42ED0320C6E41102FDE0005154849BB ] dot4 C:\Windows\system32\DRIVERS\Dot4.sys 15:47:54.0347 3188 dot4 - ok 15:47:54.0347 3188 [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print C:\Windows\system32\drivers\Dot4Prt.sys 15:47:54.0347 3188 Dot4Print - ok 15:47:54.0363 3188 [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 15:47:54.0363 3188 dot4usb - ok 15:47:54.0363 3188 [ B18F7E12C3967E7B855DF0FB548E54D5 ] dplazsvr C:\Windows\system32\clbcatqd.exe 15:47:54.0394 3188 dplazsvr - ok 15:47:54.0394 3188 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 15:47:54.0394 3188 DPS - ok 15:47:54.0394 3188 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 15:47:54.0394 3188 drmkaud - ok 15:47:54.0410 3188 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 15:47:54.0425 3188 DXGKrnl - ok 15:47:54.0425 3188 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 15:47:54.0425 3188 EapHost - ok 15:47:54.0457 3188 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 15:47:54.0488 3188 ebdrv - ok 15:47:54.0488 3188 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 15:47:54.0488 3188 EFS - ok 15:47:54.0503 3188 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 15:47:54.0503 3188 ehRecvr - ok 15:47:54.0519 3188 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 15:47:54.0519 3188 ehSched - ok 15:47:54.0519 3188 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 15:47:54.0535 3188 elxstor - ok 15:47:54.0535 3188 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 15:47:54.0535 3188 ErrDev - ok 15:47:54.0535 3188 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 15:47:54.0550 3188 EventSystem - ok 15:47:54.0550 3188 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 15:47:54.0550 3188 exfat - ok 15:47:54.0566 3188 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 15:47:54.0566 3188 fastfat - ok 15:47:54.0566 3188 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 15:47:54.0582 3188 Fax - ok 15:47:54.0582 3188 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 15:47:54.0582 3188 fdc - ok 15:47:54.0582 3188 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 15:47:54.0582 3188 fdPHost - ok 15:47:54.0582 3188 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 15:47:54.0582 3188 FDResPub - ok 15:47:54.0597 3188 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 15:47:54.0597 3188 FileInfo - ok 15:47:54.0597 3188 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 15:47:54.0597 3188 Filetrace - ok 15:47:54.0597 3188 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 15:47:54.0597 3188 flpydisk - ok 15:47:54.0597 3188 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 15:47:54.0613 3188 FltMgr - ok 15:47:54.0628 3188 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 15:47:54.0628 3188 FontCache - ok 15:47:54.0628 3188 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 15:47:54.0644 3188 FontCache3.0.0.0 - ok 15:47:54.0644 3188 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 15:47:54.0644 3188 FsDepends - ok 15:47:54.0644 3188 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 15:47:54.0644 3188 Fs_Rec - ok 15:47:54.0644 3188 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 15:47:54.0660 3188 fvevol - ok 15:47:54.0660 3188 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 15:47:54.0660 3188 gagp30kx - ok 15:47:54.0660 3188 [ A37909A904A94E8201A04050548719DF ] GFilterSvc C:\Windows\System32\GFilterSvc.exe 15:47:54.0691 3188 GFilterSvc - ok 15:47:54.0707 3188 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 15:47:54.0722 3188 gpsvc - ok 15:47:54.0722 3188 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 15:47:54.0722 3188 gupdate - ok 15:47:54.0722 3188 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 15:47:54.0722 3188 gupdatem - ok 15:47:54.0738 3188 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 15:47:54.0738 3188 gusvc - ok 15:47:54.0738 3188 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 15:47:54.0738 3188 hcw85cir - ok 15:47:54.0738 3188 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 15:47:54.0738 3188 HdAudAddService - ok 15:47:54.0753 3188 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 15:47:54.0753 3188 HDAudBus - ok 15:47:54.0753 3188 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 15:47:54.0753 3188 HidBatt - ok 15:47:54.0753 3188 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 15:47:54.0753 3188 HidBth - ok 15:47:54.0769 3188 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 15:47:54.0769 3188 HidIr - ok 15:47:54.0769 3188 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 15:47:54.0769 3188 hidserv - ok 15:47:54.0769 3188 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 15:47:54.0769 3188 HidUsb - ok 15:47:54.0769 3188 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 15:47:54.0769 3188 hkmsvc - ok 15:47:54.0785 3188 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 15:47:54.0785 3188 HomeGroupListener - ok 15:47:54.0785 3188 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 15:47:54.0785 3188 HomeGroupProvider - ok 15:47:54.0800 3188 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 15:47:54.0800 3188 HpSAMD - ok 15:47:54.0800 3188 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 15:47:54.0816 3188 HTTP - ok 15:47:54.0816 3188 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 15:47:54.0816 3188 hwpolicy - ok 15:47:54.0816 3188 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 15:47:54.0816 3188 i8042prt - ok 15:47:54.0832 3188 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 15:47:54.0832 3188 iaStorV - ok 15:47:54.0847 3188 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 15:47:54.0847 3188 idsvc - ok 15:47:54.0863 3188 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 15:47:54.0863 3188 iirsp - ok 15:47:54.0863 3188 [ 2F95BEF56AEEEB45DE55EC44668E2695 ] IJPLMSVC C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 15:47:54.0894 3188 IJPLMSVC - ok 15:47:54.0894 3188 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 15:47:54.0910 3188 IKEEXT - ok 15:47:54.0910 3188 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 15:47:54.0910 3188 intelide - ok 15:47:54.0910 3188 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 15:47:54.0925 3188 intelppm - ok 15:47:54.0925 3188 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 15:47:54.0925 3188 IPBusEnum - ok 15:47:54.0925 3188 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 15:47:54.0925 3188 IpFilterDriver - ok 15:47:54.0941 3188 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 15:47:54.0941 3188 iphlpsvc - ok 15:47:54.0941 3188 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 15:47:54.0941 3188 IPMIDRV - ok 15:47:54.0957 3188 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 15:47:54.0957 3188 IPNAT - ok 15:47:54.0957 3188 [ 05360B1EA5A2ABF620D1D96EBD8BD8F1 ] irda C:\Windows\system32\DRIVERS\irda.sys 15:47:54.0957 3188 irda - ok 15:47:54.0957 3188 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 15:47:54.0957 3188 IRENUM - ok 15:47:54.0957 3188 [ 3848384AB383F0A8F506C4370635C1F9 ] Irmon C:\Windows\System32\irmon.dll 15:47:54.0957 3188 Irmon - ok 15:47:54.0972 3188 [ D2CA12736624BA636F8357DC3EF0757E ] irsir C:\Windows\system32\DRIVERS\irsir.sys 15:47:54.0972 3188 irsir - ok 15:47:54.0972 3188 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 15:47:54.0972 3188 isapnp - ok 15:47:54.0972 3188 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 15:47:54.0988 3188 iScsiPrt - ok 15:47:54.0988 3188 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 15:47:54.0988 3188 kbdclass - ok 15:47:54.0988 3188 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 15:47:54.0988 3188 kbdhid - ok 15:47:54.0988 3188 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 15:47:54.0988 3188 KeyIso - ok 15:47:55.0003 3188 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 15:47:55.0003 3188 KSecDD - ok 15:47:55.0003 3188 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 15:47:55.0003 3188 KSecPkg - ok 15:47:55.0003 3188 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 15:47:55.0003 3188 ksthunk - ok 15:47:55.0019 3188 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 15:47:55.0019 3188 KtmRm - ok 15:47:55.0019 3188 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 15:47:55.0035 3188 LanmanServer - ok 15:47:55.0035 3188 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 15:47:55.0035 3188 LanmanWorkstation - ok 15:47:55.0035 3188 [ B6552D382FF070B4ED34CBD6737277C0 ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys 15:47:55.0035 3188 LHidFilt - ok 15:47:55.0050 3188 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 15:47:55.0050 3188 lltdio - ok 15:47:55.0050 3188 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 15:47:55.0050 3188 lltdsvc - ok 15:47:55.0050 3188 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 15:47:55.0050 3188 lmhosts - ok 15:47:55.0066 3188 [ 73C1F563AB73D459DFFE682D66476558 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys 15:47:55.0066 3188 LMouFilt - ok 15:47:55.0066 3188 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 15:47:55.0066 3188 LSI_FC - ok 15:47:55.0066 3188 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 15:47:55.0066 3188 LSI_SAS - ok 15:47:55.0082 3188 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 15:47:55.0082 3188 LSI_SAS2 - ok 15:47:55.0082 3188 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 15:47:55.0082 3188 LSI_SCSI - ok 15:47:55.0082 3188 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 15:47:55.0097 3188 luafv - ok 15:47:55.0097 3188 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 15:47:55.0097 3188 Mcx2Svc - ok 15:47:55.0097 3188 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 15:47:55.0097 3188 megasas - ok 15:47:55.0097 3188 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 15:47:55.0113 3188 MegaSR - ok 15:47:55.0113 3188 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 15:47:55.0113 3188 MMCSS - ok 15:47:55.0113 3188 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 15:47:55.0113 3188 Modem - ok 15:47:55.0113 3188 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 15:47:55.0113 3188 monitor - ok 15:47:55.0128 3188 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 15:47:55.0128 3188 mouclass - ok 15:47:55.0128 3188 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 15:47:55.0128 3188 mouhid - ok 15:47:55.0128 3188 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 15:47:55.0128 3188 mountmgr - ok 15:47:55.0144 3188 [ 1C9B83F6A2D1F414F0ACD28D75605607 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 15:47:55.0144 3188 MozillaMaintenance - ok 15:47:55.0144 3188 [ F8A10560B35C66F9DE212F03DAD5BFA7 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys 15:47:55.0144 3188 MpFilter - ok 15:47:55.0160 3188 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 15:47:55.0160 3188 mpio - ok 15:47:55.0160 3188 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 15:47:55.0160 3188 mpsdrv - ok 15:47:55.0175 3188 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 15:47:55.0191 3188 MpsSvc - ok 15:47:55.0191 3188 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 15:47:55.0191 3188 MRxDAV - ok 15:47:55.0191 3188 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 15:47:55.0191 3188 mrxsmb - ok 15:47:55.0207 3188 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 15:47:55.0207 3188 mrxsmb10 - ok 15:47:55.0207 3188 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 15:47:55.0207 3188 mrxsmb20 - ok 15:47:55.0207 3188 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 15:47:55.0222 3188 msahci - ok 15:47:55.0222 3188 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 15:47:55.0222 3188 msdsm - ok 15:47:55.0222 3188 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 15:47:55.0222 3188 MSDTC - ok 15:47:55.0238 3188 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 15:47:55.0238 3188 Msfs - ok 15:47:55.0238 3188 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 15:47:55.0238 3188 mshidkmdf - ok 15:47:55.0238 3188 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 15:47:55.0238 3188 msisadrv - ok 15:47:55.0238 3188 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 15:47:55.0253 3188 MSiSCSI - ok 15:47:55.0253 3188 msiserver - ok 15:47:55.0253 3188 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 15:47:55.0253 3188 MSKSSRV - ok 15:47:55.0253 3188 [ E07DEC52FF801841BA9B6878A60304FB ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe 15:47:55.0253 3188 MsMpSvc - ok 15:47:55.0253 3188 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 15:47:55.0253 3188 MSPCLOCK - ok 15:47:55.0269 3188 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 15:47:55.0269 3188 MSPQM - ok 15:47:55.0269 3188 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 15:47:55.0269 3188 MsRPC - ok 15:47:55.0285 3188 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 15:47:55.0285 3188 mssmbios - ok 15:47:55.0285 3188 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 15:47:55.0285 3188 MSTEE - ok 15:47:55.0285 3188 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 15:47:55.0285 3188 MTConfig - ok 15:47:55.0285 3188 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 15:47:55.0285 3188 Mup - ok 15:47:55.0300 3188 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 15:47:55.0300 3188 napagent - ok 15:47:55.0300 3188 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 15:47:55.0316 3188 NativeWifiP - ok 15:47:55.0316 3188 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys 15:47:55.0332 3188 NDIS - ok 15:47:55.0332 3188 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 15:47:55.0332 3188 NdisCap - ok 15:47:55.0347 3188 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 15:47:55.0347 3188 NdisTapi - ok 15:47:55.0347 3188 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 15:47:55.0347 3188 Ndisuio - ok 15:47:55.0347 3188 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 15:47:55.0347 3188 NdisWan - ok 15:47:55.0347 3188 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 15:47:55.0363 3188 NDProxy - ok 15:47:55.0363 3188 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 15:47:55.0363 3188 NetBIOS - ok 15:47:55.0363 3188 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 15:47:55.0363 3188 NetBT - ok 15:47:55.0363 3188 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 15:47:55.0378 3188 Netlogon - ok 15:47:55.0378 3188 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 15:47:55.0378 3188 Netman - ok 15:47:55.0378 3188 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:47:55.0394 3188 NetMsmqActivator - ok 15:47:55.0394 3188 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:47:55.0394 3188 NetPipeActivator - ok 15:47:55.0394 3188 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 15:47:55.0410 3188 netprofm - ok 15:47:55.0410 3188 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:47:55.0410 3188 NetTcpActivator - ok 15:47:55.0410 3188 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:47:55.0410 3188 NetTcpPortSharing - ok 15:47:55.0410 3188 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 15:47:55.0410 3188 nfrd960 - ok 15:47:55.0425 3188 [ 162100E0BC8377710F9D170631921C03 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys 15:47:55.0425 3188 NisDrv - ok 15:47:55.0425 3188 [ C6E15F2F95F9C0A6098D43510B604E52 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe 15:47:55.0425 3188 NisSrv - ok 15:47:55.0441 3188 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 15:47:55.0441 3188 NlaSvc - ok 15:47:55.0441 3188 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 15:47:55.0441 3188 Npfs - ok 15:47:55.0457 3188 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 15:47:55.0457 3188 nsi - ok 15:47:55.0457 3188 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 15:47:55.0457 3188 nsiproxy - ok 15:47:55.0472 3188 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 15:47:55.0488 3188 Ntfs - ok 15:47:55.0488 3188 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 15:47:55.0488 3188 Null - ok 15:47:55.0628 3188 [ FE2909F7DFB12B9A20AD207FE23B7E96 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 15:47:55.0738 3188 nvlddmkm - ok 15:47:55.0753 3188 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 15:47:55.0753 3188 nvraid - ok 15:47:55.0753 3188 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 15:47:55.0753 3188 nvstor - ok 15:47:55.0769 3188 [ 3341D2C91989BC87C3C0BAA97C27253B ] nvsvc C:\Windows\system32\nvvsvc.exe 15:47:55.0785 3188 nvsvc - ok 15:47:55.0785 3188 [ 551CE34DAD2DFF0A480781E68B286E4D ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 15:47:55.0800 3188 nvUpdatusService - ok 15:47:55.0800 3188 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 15:47:55.0816 3188 nv_agp - ok 15:47:55.0816 3188 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 15:47:55.0816 3188 ohci1394 - ok 15:47:55.0816 3188 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 15:47:55.0816 3188 p2pimsvc - ok 15:47:55.0832 3188 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 15:47:55.0832 3188 p2psvc - ok 15:47:55.0847 3188 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 15:47:55.0847 3188 Parport - ok 15:47:55.0847 3188 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 15:47:55.0847 3188 partmgr - ok 15:47:55.0847 3188 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 15:47:55.0847 3188 PcaSvc - ok 15:47:55.0863 3188 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 15:47:55.0863 3188 pci - ok 15:47:55.0863 3188 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 15:47:55.0863 3188 pciide - ok 15:47:55.0863 3188 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 15:47:55.0863 3188 pcmcia - ok 15:47:55.0878 3188 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 15:47:55.0878 3188 pcw - ok 15:47:55.0878 3188 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 15:47:55.0894 3188 PEAUTH - ok 15:47:55.0910 3188 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 15:47:55.0925 3188 PeerDistSvc - ok 15:47:55.0941 3188 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 15:47:55.0941 3188 PerfHost - ok 15:47:55.0957 3188 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 15:47:55.0972 3188 pla - ok 15:47:55.0988 3188 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 15:47:55.0988 3188 PlugPlay - ok 15:47:55.0988 3188 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 15:47:55.0988 3188 PNRPAutoReg - ok 15:47:56.0003 3188 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 15:47:56.0003 3188 PNRPsvc - ok 15:47:56.0003 3188 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 15:47:56.0019 3188 PolicyAgent - ok 15:47:56.0019 3188 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 15:47:56.0019 3188 Power - ok 15:47:56.0035 3188 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 15:47:56.0035 3188 PptpMiniport - ok 15:47:56.0035 3188 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 15:47:56.0035 3188 Processor - ok 15:47:56.0035 3188 [ 5C78838B4D166D1A27DB3A8A820C799A ] ProfSvc C:\Windows\system32\profsvc.dll 15:47:56.0035 3188 ProfSvc - ok 15:47:56.0050 3188 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 15:47:56.0050 3188 ProtectedStorage - ok 15:47:56.0050 3188 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 15:47:56.0050 3188 Psched - ok 15:47:56.0316 3188 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 15:47:56.0332 3188 ql2300 - ok 15:47:56.0332 3188 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 15:47:56.0332 3188 ql40xx - ok 15:47:56.0347 3188 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 15:47:56.0347 3188 QWAVE - ok 15:47:56.0347 3188 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 15:47:56.0347 3188 QWAVEdrv - ok 15:47:56.0347 3188 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 15:47:56.0363 3188 RasAcd - ok 15:47:56.0363 3188 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 15:47:56.0363 3188 RasAgileVpn - ok 15:47:56.0363 3188 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 15:47:56.0363 3188 RasAuto - ok 15:47:56.0363 3188 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 15:47:56.0363 3188 Rasl2tp - ok 15:47:56.0378 3188 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 15:47:56.0378 3188 RasMan - ok 15:47:56.0378 3188 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 15:47:56.0378 3188 RasPppoe - ok 15:47:56.0394 3188 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 15:47:56.0394 3188 RasSstp - ok 15:47:56.0394 3188 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 15:47:56.0394 3188 rdbss - ok 15:47:56.0410 3188 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 15:47:56.0410 3188 rdpbus - ok 15:47:56.0410 3188 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 15:47:56.0410 3188 RDPCDD - ok 15:47:56.0410 3188 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 15:47:56.0410 3188 RDPDR - ok 15:47:56.0410 3188 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 15:47:56.0410 3188 RDPENCDD - ok 15:47:56.0425 3188 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 15:47:56.0425 3188 RDPREFMP - ok 15:47:56.0425 3188 [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 15:47:56.0425 3188 RdpVideoMiniport - ok 15:47:56.0425 3188 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 15:47:56.0425 3188 RDPWD - ok 15:47:56.0441 3188 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 15:47:56.0441 3188 rdyboost - ok 15:47:56.0441 3188 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 15:47:56.0441 3188 RemoteAccess - ok 15:47:56.0457 3188 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 15:47:56.0457 3188 RemoteRegistry - ok 15:47:56.0457 3188 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 15:47:56.0457 3188 RpcEptMapper - ok 15:47:56.0457 3188 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 15:47:56.0457 3188 RpcLocator - ok 15:47:56.0472 3188 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 15:47:56.0472 3188 RpcSs - ok 15:47:56.0472 3188 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 15:47:56.0472 3188 rspndr - ok 15:47:56.0488 3188 [ 3B01789EE4EAEE97F5EB46B711387D5E ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 15:47:56.0488 3188 RTL8167 - ok 15:47:56.0488 3188 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 15:47:56.0488 3188 s3cap - ok 15:47:56.0488 3188 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 15:47:56.0488 3188 SamSs - ok 15:47:56.0488 3188 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 15:47:56.0488 3188 sbp2port - ok 15:47:56.0503 3188 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 15:47:56.0503 3188 SCardSvr - ok 15:47:56.0503 3188 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 15:47:56.0503 3188 scfilter - ok 15:47:56.0519 3188 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 15:47:56.0535 3188 Schedule - ok 15:47:56.0535 3188 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 15:47:56.0535 3188 SCPolicySvc - ok 15:47:56.0582 3188 [ 3E1152BF8ADD19B3169BC8E31C29C844 ] SDFirewallService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe 15:47:56.0613 3188 SDFirewallService - ok 15:47:56.0660 3188 [ ABF83CF4BCCEA547AA285E74F89990A3 ] SDMonitorService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe 15:47:56.0691 3188 SDMonitorService - ok 15:47:56.0707 3188 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 15:47:56.0707 3188 SDRSVC - ok 15:47:56.0722 3188 [ 43D29ECB8137EEAE30B0970BBC7A5500 ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe 15:47:56.0722 3188 SDScannerService - ok 15:47:56.0738 3188 [ 6B859B122E85C2C833E6D8C5DC4B07F3 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe 15:47:56.0753 3188 SDUpdateService - ok 15:47:56.0753 3188 [ 59DCE6783F9ED27EB72C81466E363BF8 ] SDWSCService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe 15:47:56.0753 3188 SDWSCService - ok 15:47:56.0769 3188 [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe 15:47:56.0785 3188 SearchAnonymizer - ok 15:47:56.0785 3188 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 15:47:56.0785 3188 secdrv - ok 15:47:56.0785 3188 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 15:47:56.0785 3188 seclogon - ok 15:47:56.0785 3188 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 15:47:56.0785 3188 SENS - ok 15:47:56.0800 3188 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 15:47:56.0800 3188 SensrSvc - ok 15:47:56.0800 3188 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 15:47:56.0800 3188 Serenum - ok 15:47:56.0800 3188 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 15:47:56.0800 3188 Serial - ok 15:47:56.0800 3188 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 15:47:56.0800 3188 sermouse - ok 15:47:56.0816 3188 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 15:47:56.0816 3188 SessionEnv - ok 15:47:56.0816 3188 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 15:47:56.0816 3188 sffdisk - ok 15:47:56.0816 3188 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 15:47:56.0832 3188 sffp_mmc - ok 15:47:56.0832 3188 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 15:47:56.0832 3188 sffp_sd - ok 15:47:56.0832 3188 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 15:47:56.0832 3188 sfloppy - ok 15:47:56.0832 3188 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 15:47:56.0847 3188 SharedAccess - ok 15:47:56.0847 3188 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 15:47:56.0847 3188 ShellHWDetection - ok 15:47:56.0847 3188 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 15:47:56.0847 3188 SiSRaid2 - ok 15:47:56.0863 3188 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 15:47:56.0863 3188 SiSRaid4 - ok 15:47:56.0863 3188 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 15:47:56.0863 3188 Smb - ok 15:47:56.0863 3188 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 15:47:56.0863 3188 SNMPTRAP - ok 15:47:56.0878 3188 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 15:47:56.0878 3188 spldr - ok 15:47:56.0878 3188 [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler C:\Windows\System32\spoolsv.exe 15:47:56.0894 3188 Spooler - ok 15:47:56.0925 3188 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 15:47:56.0972 3188 sppsvc - ok 15:47:56.0972 3188 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 15:47:56.0972 3188 sppuinotify - ok 15:47:56.0988 3188 [ 602884696850C86434530790B110E8EB ] sptd C:\Windows\System32\Drivers\sptd.sys 15:47:57.0003 3188 sptd - ok 15:47:57.0003 3188 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 15:47:57.0003 3188 srv - ok 15:47:57.0019 3188 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 15:47:57.0019 3188 srv2 - ok 15:47:57.0019 3188 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 15:47:57.0019 3188 srvnet - ok 15:47:57.0035 3188 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 15:47:57.0035 3188 SSDPSRV - ok 15:47:57.0035 3188 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 15:47:57.0035 3188 SstpSvc - ok 15:47:57.0035 3188 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 15:47:57.0035 3188 stexstor - ok 15:47:57.0050 3188 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys 15:47:57.0050 3188 StillCam - ok 15:47:57.0050 3188 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 15:47:57.0066 3188 stisvc - ok 15:47:57.0066 3188 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 15:47:57.0066 3188 storflt - ok 15:47:57.0066 3188 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys 15:47:57.0066 3188 storvsc - ok 15:47:57.0066 3188 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 15:47:57.0066 3188 swenum - ok 15:47:57.0082 3188 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 15:47:57.0082 3188 SwitchBoard - ok 15:47:57.0097 3188 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 15:47:57.0097 3188 swprv - ok 15:47:57.0097 3188 Synth3dVsc - ok 15:47:57.0128 3188 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 15:47:57.0144 3188 SysMain - ok 15:47:57.0144 3188 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 15:47:57.0144 3188 TabletInputService - ok 15:47:57.0222 3188 [ 7C7E4D7EAC200630DE8581C8B67D36AB ] TabletServicePen C:\Program Files\Tablet\Pen\Pen_Tablet.exe 15:47:57.0316 3188 TabletServicePen - ok 15:47:57.0332 3188 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 15:47:57.0332 3188 TapiSrv - ok 15:47:57.0332 3188 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 15:47:57.0332 3188 TBS - ok 15:47:57.0347 3188 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 15:47:57.0378 3188 Tcpip - ok 15:47:57.0394 3188 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 15:47:57.0394 3188 TCPIP6 - ok 15:47:57.0410 3188 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 15:47:57.0410 3188 tcpipreg - ok 15:47:57.0410 3188 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 15:47:57.0410 3188 TDPIPE - ok 15:47:57.0410 3188 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 15:47:57.0410 3188 TDTCP - ok 15:47:57.0410 3188 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 15:47:57.0425 3188 tdx - ok 15:47:57.0457 3188 [ 6B1B2F8D62D606B200C2072564090104 ] TeamViewer8 C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe 15:47:57.0488 3188 TeamViewer8 - ok 15:47:57.0488 3188 [ F5520DBB47C60EE83024B38720ABDA24 ] teamviewervpn C:\Windows\system32\DRIVERS\teamviewervpn.sys 15:47:57.0488 3188 teamviewervpn - ok 15:47:57.0488 3188 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 15:47:57.0503 3188 TermDD - ok 15:47:57.0503 3188 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 15:47:57.0519 3188 TermService - ok 15:47:57.0519 3188 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 15:47:57.0519 3188 Themes - ok 15:47:57.0519 3188 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 15:47:57.0519 3188 THREADORDER - ok 15:47:57.0535 3188 [ C4F3C11A5C4F413D16B09A33DCF7554C ] TouchServicePen C:\Program Files\Tablet\Pen\Pen_TouchService.exe 15:47:57.0550 3188 TouchServicePen - ok 15:47:57.0550 3188 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 15:47:57.0550 3188 TrkWks - ok 15:47:57.0550 3188 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 15:47:57.0566 3188 TrustedInstaller - ok 15:47:57.0566 3188 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 15:47:57.0566 3188 tssecsrv - ok 15:47:57.0566 3188 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 15:47:57.0566 3188 TsUsbFlt - ok 15:47:57.0566 3188 tsusbhub - ok 15:47:57.0582 3188 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 15:47:57.0582 3188 tunnel - ok 15:47:57.0582 3188 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 15:47:57.0582 3188 uagp35 - ok 15:47:57.0582 3188 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 15:47:57.0597 3188 udfs - ok 15:47:57.0597 3188 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 15:47:57.0597 3188 UI0Detect - ok 15:47:57.0597 3188 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 15:47:57.0597 3188 uliagpkx - ok 15:47:57.0597 3188 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 15:47:57.0613 3188 umbus - ok 15:47:57.0613 3188 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 15:47:57.0613 3188 UmPass - ok 15:47:57.0613 3188 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll 15:47:57.0613 3188 UmRdpService - ok 15:47:57.0628 3188 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 15:47:57.0628 3188 upnphost - ok 15:47:57.0628 3188 [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 15:47:57.0644 3188 USBAAPL64 - ok 15:47:57.0644 3188 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 15:47:57.0644 3188 usbccgp - ok 15:47:57.0644 3188 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 15:47:57.0660 3188 usbcir - ok 15:47:57.0660 3188 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 15:47:57.0660 3188 usbehci - ok 15:47:57.0660 3188 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 15:47:57.0660 3188 usbhub - ok 15:47:57.0675 3188 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 15:47:57.0675 3188 usbohci - ok 15:47:57.0675 3188 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 15:47:57.0675 3188 usbprint - ok 15:47:57.0675 3188 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 15:47:57.0675 3188 USBSTOR - ok 15:47:57.0675 3188 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 15:47:57.0675 3188 usbuhci - ok 15:47:57.0691 3188 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 15:47:57.0691 3188 UxSms - ok 15:47:57.0691 3188 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 15:47:57.0691 3188 VaultSvc - ok 15:47:57.0691 3188 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 15:47:57.0691 3188 vdrvroot - ok 15:47:57.0707 3188 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 15:47:57.0707 3188 vds - ok 15:47:57.0707 3188 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 15:47:57.0707 3188 vga - ok 15:47:57.0707 3188 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 15:47:57.0707 3188 VgaSave - ok 15:47:57.0707 3188 VGPU - ok 15:47:57.0753 3188 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 15:47:57.0769 3188 vhdmp - ok 15:47:57.0785 3188 [ 906A7C6B6659A650648CF21998270945 ] VIAHdAudAddService C:\Windows\system32\drivers\viahduaa.sys 15:47:57.0800 3188 VIAHdAudAddService - ok 15:47:57.0816 3188 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 15:47:57.0816 3188 viaide - ok 15:47:57.0816 3188 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys 15:47:57.0816 3188 vmbus - ok 15:47:57.0816 3188 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 15:47:57.0816 3188 VMBusHID - ok 15:47:57.0832 3188 [ 091E009EF749C9D65CF9ADFAD316D251 ] vmm C:\Windows\system32\Treiber\vmm.sys 15:47:57.0832 3188 vmm - ok 15:47:57.0832 3188 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 15:47:57.0832 3188 volmgr - ok 15:47:57.0847 3188 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 15:47:57.0847 3188 volmgrx - ok 15:47:57.0847 3188 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 15:47:57.0863 3188 volsnap - ok 15:47:57.0863 3188 [ BC2EA40B98B5E866D9A4F98AFB66B682 ] VPCNetS2 C:\Windows\system32\DRIVERS\VMNetSrv.sys 15:47:57.0863 3188 VPCNetS2 - ok 15:47:57.0863 3188 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 15:47:57.0863 3188 vsmraid - ok 15:47:57.0894 3188 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 15:47:57.0910 3188 VSS - ok 15:47:57.0910 3188 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 15:47:57.0910 3188 vwifibus - ok 15:47:57.0925 3188 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 15:47:57.0925 3188 W32Time - ok 15:47:57.0925 3188 [ E04D43C7D1641E95D35CAE6086C7E350 ] wacommousefilter C:\Windows\system32\DRIVERS\wacommousefilter.sys 15:47:57.0925 3188 wacommousefilter - ok 15:47:57.0941 3188 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 15:47:57.0941 3188 WacomPen - ok 15:47:57.0941 3188 [ EC1CEB237E365330C1FCFC4876AA0AC0 ] wacomvhid C:\Windows\system32\DRIVERS\wacomvhid.sys 15:47:57.0941 3188 wacomvhid - ok 15:47:57.0941 3188 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 15:47:57.0941 3188 WANARP - ok 15:47:57.0941 3188 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 15:47:57.0941 3188 Wanarpv6 - ok 15:47:57.0972 3188 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 15:47:57.0988 3188 wbengine - ok 15:47:57.0988 3188 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 15:47:57.0988 3188 WbioSrvc - ok 15:47:58.0003 3188 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 15:47:58.0003 3188 wcncsvc - ok 15:47:58.0003 3188 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 15:47:58.0003 3188 WcsPlugInService - ok 15:47:58.0003 3188 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 15:47:58.0003 3188 Wd - ok 15:47:58.0019 3188 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 15:47:58.0019 3188 Wdf01000 - ok 15:47:58.0035 3188 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 15:47:58.0035 3188 WdiServiceHost - ok 15:47:58.0035 3188 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 15:47:58.0035 3188 WdiSystemHost - ok 15:47:58.0035 3188 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 15:47:58.0050 3188 WebClient - ok 15:47:58.0050 3188 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 15:47:58.0050 3188 Wecsvc - ok 15:47:58.0066 3188 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 15:47:58.0066 3188 wercplsupport - ok 15:47:58.0066 3188 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 15:47:58.0066 3188 WerSvc - ok 15:47:58.0066 3188 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 15:47:58.0066 3188 WfpLwf - ok 15:47:58.0066 3188 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 15:47:58.0066 3188 WIMMount - ok 15:47:58.0082 3188 WinDefend - ok 15:47:58.0082 3188 WinHttpAutoProxySvc - ok 15:47:58.0082 3188 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 15:47:58.0097 3188 Winmgmt - ok 15:47:58.0113 3188 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 15:47:58.0128 3188 WinRM - ok 15:47:58.0144 3188 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 15:47:58.0144 3188 WinUsb - ok 15:47:58.0160 3188 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 15:47:58.0160 3188 Wlansvc - ok 15:47:58.0160 3188 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 15:47:58.0160 3188 WmiAcpi - ok 15:47:58.0175 3188 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 15:47:58.0175 3188 wmiApSrv - ok 15:47:58.0175 3188 WMPNetworkSvc - ok 15:47:58.0175 3188 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 15:47:58.0191 3188 WPCSvc - ok 15:47:58.0191 3188 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 15:47:58.0191 3188 WPDBusEnum - ok 15:47:58.0191 3188 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 15:47:58.0191 3188 ws2ifsl - ok 15:47:58.0191 3188 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 15:47:58.0207 3188 wscsvc - ok 15:47:58.0207 3188 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 15:47:58.0207 3188 WSDPrintDevice - ok 15:47:58.0207 3188 WSearch - ok 15:47:58.0238 3188 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 15:47:58.0253 3188 wuauserv - ok 15:47:58.0269 3188 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 15:47:58.0269 3188 WudfPf - ok 15:47:58.0269 3188 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 15:47:58.0269 3188 WUDFRd - ok 15:47:58.0269 3188 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 15:47:58.0285 3188 wudfsvc - ok 15:47:58.0285 3188 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 15:47:58.0285 3188 WwanSvc - ok 15:47:58.0285 3188 ================ Scan global =============================== 15:47:58.0300 3188 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 15:47:58.0300 3188 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 15:47:58.0300 3188 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 15:47:58.0316 3188 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 15:47:58.0316 3188 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 15:47:58.0316 3188 [Global] - ok 15:47:58.0316 3188 ================ Scan MBR ================================== 15:47:58.0316 3188 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 15:47:58.0410 3188 \Device\Harddisk0\DR0 - ok 15:47:58.0410 3188 ================ Scan VBR ================================== 15:47:58.0425 3188 [ 9F7F1E1DE59BE7FC6D1F76367EB552EE ] \Device\Harddisk0\DR0\Partition1 15:47:58.0425 3188 \Device\Harddisk0\DR0\Partition1 - ok 15:47:58.0425 3188 [ 67A937CE03893D8730F631B97C9D4A13 ] \Device\Harddisk0\DR0\Partition2 15:47:58.0425 3188 \Device\Harddisk0\DR0\Partition2 - ok 15:47:58.0425 3188 ============================================================ 15:47:58.0425 3188 Scan finished 15:47:58.0425 3188 ============================================================ 15:47:58.0425 1060 Detected object count: 0 15:47:58.0425 1060 Actual detected object count: 0 dds DDS Logfile: DDS Logfile: Code:
ATTFilter DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16470 BrowserJavaVersion: 10.17.2 Run by admin at 15:53:37 on 2013-04-09 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.4087.1950 [GMT 2:00] . AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Spybot - Search and Destroy *Disabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Tablet\Pen\Pen_TouchService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Windows\system32\taskhost.exe C:\Program Files\Tablet\Pen\Pen_TouchUser.exe C:\Users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\clbcatqd.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\GFilterSvc.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe C:\Program Files\Tablet\Pen\Pen_TabletUser.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe C:\Program Files (x86)\Bamboo Dock\BambooCore.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\PSD Temp\Acrobat 11.0\Acrobat\acrotray.exe C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Windows\system32\SearchIndexer.exe c:\Program Files\Microsoft Security Client\NisSrv.exe C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.de/ mWinlogon: Userinit = userinit.exe, BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: DNS Error Helper: {9B6B03F1-16CF-4491-BBBB-E872802DD717} - C:\ProgramData\DNSErrorHelper\bho.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Adobe Acrobat Create PDF Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll EB: Developer Tools: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll uRun: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [AdobeBridge] <no file> mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin mRun: [Acrobat Assistant 8.0] "C:\PSD Temp\Acrobat 11.0\Acrobat\Acrotray.exe" mRun: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC} - C:\Program Files (x86)\Java\jre7\bin\jp2iexp.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab TCP: NameServer = 192.168.178.1 TCP: Interfaces\{EC6C48CC-AACA-4FBB-8D2E-E299CA8E61B1} : DHCPNameServer = 192.168.178.1 Notify: SDWinLogon - SDWinLogon.dll SSODL: WebCheck - <orphaned> x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey x64-Run: [Ocs_SM] C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizer.exe x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" . INFO: x64-HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . x64-SSODL: WebCheck - <orphaned> Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\ FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll FF - plugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll FF - plugin: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll FF - plugin: C:\PSD Temp\Acrobat 11.0\Acrobat\Air\nppdf32.dll FF - plugin: C:\Users\admin\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-02-20 09:57; dnshelp@dnshelp.com; C:\Users\admin\AppData\Roaming\Helper FF - ExtSQL: 2013-03-06 10:27; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF - ExtSQL: 2013-03-06 10:34; firebug@software.joehewitt.com; C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\firebug@software.joehewitt.com.xpi FF - ExtSQL: 2013-03-15 11:37; web2pdfextension@web2pdf.adobedotcom; C:\PSD Temp\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320] R2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344] R2 AddonsHelper;AddonsHelper;C:\Users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [2013-2-20 896512] R2 dplazsvr;Konfiguration Machine Bluetooth;C:\Windows\System32\clbcatqd.exe [2013-2-20 114176] R2 GFilterSvc;G-Filter Service;C:\Windows\System32\GFilterSvc.exe [2013-2-20 121856] R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2010-10-24 130008] R2 SDFirewallService;Spybot-S&D 2 Firewall Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe [2011-7-27 3585696] R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-4-2 166528] R2 SearchAnonymizer;SearchAnonymizer;C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2013-2-20 40960] R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2013-1-7 6581624] R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-3-5 3560288] R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2013-1-7 528760] R3 NisSrv;Microsoft-Netzwerkinspektion;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-9-28 239616] R3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2011-2-2 35112] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2010-9-28 1250816] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SDMonitorService;Spybot-S&D 2 Monitoring Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe [2011-7-27 3834456] S2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-4-2 1188896] S2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-4-2 1395736] S3 BackupReader;BackupReader;C:\Windows\System32\drivers\BackupReader.sys [2011-3-2 63872] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-6-9 20992] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-9 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712] . =============== File Associations =============== . FileExt: .js: jsfile="C:\PSD Temp\Adobe Dreamweaver CS6\Dreamweaver.exe","%1" ShellExec: dreamweaver.exe: Open="C:\PSD Temp\Adobe Dreamweaver CS6\dreamweaver.exe", "%1" . =============== Created Last 30 ================ . 2013-04-09 13:13:29 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{67657373-B52E-4FEB-ACFF-90C9B74582D1}\mpengine.dll 2013-04-09 09:00:16 -------- d-----w- C:\_OTL 2013-04-08 09:39:55 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-04-06 09:44:36 -------- d-----w- C:\Program Files (x86)\JTL-Software 2013-04-04 09:07:13 26520 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2013-04-03 08:53:00 -------- d-----w- C:\Users\admin\AppData\Local\WinZip 2013-03-26 07:57:18 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys 2013-03-25 08:12:50 73432 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-25 08:12:50 693976 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-03-22 07:43:37 972264 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{01CFE287-B1EE-415B-94AF-FAF5B56EE9A5}\gapaengine.dll 2013-03-21 10:37:16 -------- d-----w- C:\Users\admin\AppData\Roaming\SolidDocuments 2013-03-19 15:56:49 -------- d-----w- C:\Users\admin\AppData\Roaming\PC-FAX TX 2013-03-19 12:59:01 73728 ------w- C:\Windows\SysWow64\BRCrypt.dll 2013-03-15 12:33:18 -------- d-----w- C:\Users\admin\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat 2013-03-15 10:35:47 -------- d-----w- C:\ProgramData\ALM . ==================== Find3M ==================== . 2013-04-02 10:34:28 282744 ------w- C:\Windows\System32\MpSigStub.exe 2013-03-05 08:05:00 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-03-05 08:04:59 861088 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll 2013-03-05 08:04:58 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll 2013-02-21 08:30:12 108448 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll 2013-02-21 08:30:10 963488 ----a-w- C:\Windows\System32\deployJava1.dll 2013-02-21 08:30:10 1085344 ----a-w- C:\Windows\System32\npDeployJava1.dll 2013-02-20 08:54:47 121856 ----a-w- C:\Windows\System32\GFilterSvc.exe 2013-02-20 08:54:46 114176 ----a-w- C:\Windows\System32\clbcatqd.exe 2013-02-02 06:57:02 2312704 ----a-w- C:\Windows\System32\jscript9.dll 2013-02-02 06:47:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl 2013-02-02 06:47:19 1392128 ----a-w- C:\Windows\System32\wininet.dll 2013-02-02 06:42:18 173056 ----a-w- C:\Windows\System32\ieUnatt.exe 2013-02-02 06:41:51 599040 ----a-w- C:\Windows\System32\vbscript.dll 2013-02-02 06:38:01 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2013-02-02 03:38:35 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll 2013-02-02 03:30:32 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2013-02-02 03:30:21 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll 2013-02-02 03:26:47 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe 2013-02-02 03:26:21 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll 2013-02-02 03:23:28 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2013-01-20 14:59:04 230320 ----a-w- C:\Windows\System32\drivers\MpFilter.sys 2013-01-20 14:59:04 130008 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys . ============= FINISH: 15:53:47,00 =============== --- --- --- dds-attach Code:
ATTFilter . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 28.09.2010 14:14:01 System Uptime: 09.04.2013 15:01:28 (0 hours ago) . Motherboard: ASRock | | P55M Pro Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz | CPUSocket | 2668/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 112 GiB total, 19,818 GiB free. D: is CDROM () F: is Removable G: is Removable H: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP417: 26.03.2013 18:08:24 - Windows Update RP418: 02.04.2013 08:41:49 - Windows Update RP419: 06.04.2013 10:33:51 - Windows Update RP420: 09.04.2013 11:02:54 - OTL Restore Point - 09.04.2013 11:02:54 RP421: 09.04.2013 15:13:10 - Windows Update . ==== Installed Programs ====================== . 3.4.0.9271.1 ABBYY FineReader 10 Corporate Edition Adobe Acrobat XI Pro Adobe AIR Adobe Dreamweaver CS6 Adobe Flash Player 11 Plugin Adobe Help Manager Adobe Illustrator CS6 Adobe InDesign CS6 Adobe Media Player Adobe Photoshop CS6 Adobe Reader XI (11.0.02) - Deutsch Adobe Shockwave Player 12.0 Adobe Widget Browser Bamboo Bamboo Dock BenVista PhotoZoom Pro 4.1.2 Brother MFL-Pro Suite MFC-9840CDW CDBurnerXP CINEMA 4D 12.016 Crazybump (remove only) DebugMode Wink DiffDaff Version 1.0 EditPlus 3 erLT Evrsoft First Page 2006 ffdshow x64 v1.2.4422 [2012-04-09] FileZilla Client 3.6.0.2 Flash Slideshow Maker Pro 5.00 FlashSlider 4.3.1 FolderVisualizer G-Filter Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper Haali Media Splitter HD Tune Pro 5.00 HiJackThis IcoFX 1.6.4 J2SE Runtime Environment 5.0 Update 21 Java 7 Update 15 (64-bit) Java 7 Update 17 Java Auto Updater JavaFX 2.1.1 JDownloader JTL-Wawi Logitech SetPoint 5.20 Malwarebytes Anti-Malware Version 1.70.0.1100 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft .NET Framework 4 Extended Microsoft Antimalware Service DE-DE Language Pack Microsoft Security Client Microsoft Security Client DE-DE Language Pack Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server Management Studio Express Microsoft SQL Server Native Client Microsoft Virtual PC 2007 Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft_VC80_ATL_x86_x64 Microsoft_VC80_CRT_x86 Microsoft_VC80_CRT_x86_x64 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFC_x86_x64 Microsoft_VC80_MFCLOC_x86 Microsoft_VC80_MFCLOC_x86_x64 Microsoft_VC90_ATL_x86 Microsoft_VC90_ATL_x86_x64 Microsoft_VC90_CRT_x86 Microsoft_VC90_CRT_x86_x64 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFC_x86_x64 Mozilla Firefox 20.0 (x86 de) Mozilla Maintenance Service Mozilla Thunderbird 17.0.5 (x86 de) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Notepad++ NVIDIA Display Control Panel NVIDIA Grafiktreiber 310.70 NVIDIA Install Application NVIDIA Photoshop Plug-ins 64 bit NVIDIA Systemsteuerung 310.70 NVIDIA Update 1.10.8 NVIDIA Update Components Nvu 1.0 OpenOffice.org 3.2 PandoraRecovery (Remove Only) PDF-Viewer PDF Editor 3 PDF Settings CS6 PDF24 Creator 4.5.0 PDFCreator PhotoRescue PC v3.2.2.12903 PIXMA Extended Survey Program PixPlant 2.0.50 Platform PSPad editor QuickTime RAR Password Recovery Magic v6.1.1.386 Realtek Ethernet Controller Driver For Windows Vista and Later Safari SearchAnonymizer Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft .NET Framework 4 Extended (KB2736428) Security Update for Microsoft .NET Framework 4 Extended (KB2742595) Sothink SWF Quicker Spybot - Search & Destroy Spybot - Search & Destroy 2 SuperMailer 5.66 swMSM TeamViewer 8 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) User's Guides VIA Plattform-Geräte-Manager VLC media player 2.0.5 Webocton - Scriptly 0.8.95.6 WebTablet FB Plugin WebTablet IE Plugin WebTablet Netscape Plugin WinHTTrack Website Copier 3.45-3 WinMerge 2.12.4 WinRAR WinZip 17.0 . ==== End Of File =========================== |
09.04.2013, 15:14 | #4 |
/// TB-Ausbilder | Haeufige Abstuerze und weiterleitungen im Firefox Also etwas sehr schlimmes ist nicht dabei. Machen wir mal weiter: Scan mit Combofix
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
09.04.2013, 15:32 | #5 |
| Haeufige Abstuerze und weiterleitungen im Firefox Da ist sie ComboFix Code:
ATTFilter ComboFix 13-04-08.04 - admin 09.04.2013 16:24:21.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.4087.1641 [GMT 2:00] ausgeführt von:: c:\users\admin\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Spybot - Search and Destroy *Disabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\admin\g2mdlhlpx.exe c:\windows\pkunzip.pif c:\windows\pkzip.pif . . ((((((((((((((((((((((( Dateien erstellt von 2013-03-09 bis 2013-04-09 )))))))))))))))))))))))))))))) . . 2013-04-09 14:27 . 2013-04-09 14:27 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-04-09 14:27 . 2013-04-09 14:27 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-04-09 13:13 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{67657373-B52E-4FEB-ACFF-90C9B74582D1}\mpengine.dll 2013-04-09 09:00 . 2013-04-09 09:00 -------- d-----w- C:\_OTL 2013-04-08 09:39 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-04-06 09:44 . 2013-04-06 09:44 -------- d-----w- c:\program files (x86)\JTL-Software 2013-04-03 08:53 . 2013-04-03 08:53 -------- d-----w- c:\users\admin\AppData\Local\WinZip 2013-04-03 07:47 . 2013-04-04 06:03 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2013-03-26 07:57 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys 2013-03-25 08:12 . 2013-03-25 08:12 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-25 08:12 . 2013-03-25 08:12 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-22 07:43 . 2012-12-03 08:51 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01CFE287-B1EE-415B-94AF-FAF5B56EE9A5}\gapaengine.dll 2013-03-21 10:37 . 2013-03-21 10:37 -------- d-----w- c:\users\admin\AppData\Roaming\SolidDocuments 2013-03-19 15:56 . 2013-03-21 08:30 -------- d-----w- c:\users\admin\AppData\Roaming\PC-FAX TX 2013-03-19 12:59 . 2006-07-07 11:40 73728 ------w- c:\windows\SysWow64\BRCrypt.dll 2013-03-15 12:33 . 2013-03-15 12:33 -------- d-----w- c:\users\admin\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat 2013-03-15 10:35 . 2013-03-15 10:35 -------- d-----w- c:\programdata\ALM . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-02 10:34 . 2010-09-28 13:49 282744 ------w- c:\windows\system32\MpSigStub.exe 2013-03-13 16:08 . 2010-09-30 06:45 72013344 ----a-w- c:\windows\system32\MRT.exe 2013-03-05 08:05 . 2013-03-05 08:05 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-03-05 08:04 . 2012-05-07 14:22 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-03-05 08:04 . 2010-09-29 07:46 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-02-21 08:30 . 2013-02-21 08:30 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-02-21 08:30 . 2013-02-21 08:30 310688 ----a-w- c:\windows\system32\javaws.exe 2013-02-21 08:30 . 2013-02-21 08:30 188832 ----a-w- c:\windows\system32\javaw.exe 2013-02-21 08:30 . 2013-02-21 08:30 188320 ----a-w- c:\windows\system32\java.exe 2013-02-21 08:30 . 2012-06-22 08:43 963488 ----a-w- c:\windows\system32\deployJava1.dll 2013-02-21 08:30 . 2012-06-22 08:43 1085344 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-02-20 08:54 . 2013-02-20 08:54 121856 ----a-w- c:\windows\system32\GFilterSvc.exe 2013-02-20 08:54 . 2013-02-20 08:54 114176 ----a-w- c:\windows\system32\clbcatqd.exe 2013-01-20 14:59 . 2013-01-20 14:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 14:59 . 2010-10-24 20:25 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717}] 2013-02-20 08:54 138752 ----a-w- c:\programdata\DNSErrorHelper\bho.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-23 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-07-04 3921432] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2012-10-16 646744] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "Acrobat Assistant 8.0"="c:\psd temp\Acrobat 11.0\Acrobat\Acrotray.exe" [2012-12-18 3478752] "BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 AddonsHelper;AddonsHelper;c:\users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SDMonitorService;Spybot-S&D 2 Monitoring Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe [2011-05-10 3834456] R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-07-04 1188896] R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-07-04 1395736] R3 ALSysIO;ALSysIO;c:\users\admin\AppData\Local\Temp\ALSysIO64.sys [x] R3 BackupReader;BackupReader;c:\windows\system32\DRIVERS\BackupReader.sys [2011-03-02 63872] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-29 834544] S2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344] S2 dplazsvr;Konfiguration Machine Bluetooth;c:\windows\system32\clbcatqd.exe [2013-02-20 114176] S2 GFilterSvc;G-Filter Service;c:\windows\System32\GFilterSvc.exe [2013-02-20 121856] S2 SDFirewallService;Spybot-S&D 2 Firewall Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe [2011-05-10 3585696] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-03-22 166528] S2 SearchAnonymizer;SearchAnonymizer;c:\users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2013-02-20 40960] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-07-05 6581624] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-07-05 528760] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616] S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-01-12 35112] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-09-17 1250816] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - 58143583 *Deregistered* - 58143583 *Deregistered* - aswMBR . Inhalt des "geplante Tasks" Ordners . 2013-04-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-25 08:12] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001Core.job - c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001UA.job - c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512] "Ocs_SM"="c:\users\admin\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2013-02-20 106496] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-01-24 477600] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\ FF - ExtSQL: 2013-02-20 09:57; dnshelp@dnshelp.com; c:\users\admin\AppData\Roaming\Helper FF - ExtSQL: 2013-03-06 10:27; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF - ExtSQL: 2013-03-06 10:34; firebug@software.joehewitt.com; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\firebug@software.joehewitt.com.xpi FF - ExtSQL: 2013-03-15 11:37; web2pdfextension@web2pdf.adobedotcom; c:\psd temp\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) Notify-SDWinLogon - SDWinLogon.dll AddRemove-PandoraRecovery - g:\pandora recovery\Uninstall.exe AddRemove-PhotoRescue PC_is1 - g:\datenrettung\PhotoRescue PC v3.2.2.12903\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-04-09 16:29:15 ComboFix-quarantined-files.txt 2013-04-09 14:29 . Vor Suchlauf: 21 Verzeichnis(se), 21.298.053.120 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 21.851.488.256 Bytes frei . - - End Of File - - 9373DAFF21AC00FBC24974B5A7BA0643 |
09.04.2013, 15:38 | #6 |
/// TB-Ausbilder | Haeufige Abstuerze und weiterleitungen im Firefox Fein, wir machen noch den Rest weg. Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Deinstallation von Programmen
Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3: AdwCleaner wiederholen Die vorliegende Version der Werbeprogramme ist ziemlich hartnäckig und kann von AdwCleaner erfahrungsgemäss nur bei zweimaliger Anwendung entfernt werden. Also wiederhole diesen Schritt bitte und poste auch das Logfile. Schritt 4: Combofix-Skript
__________________ --> Haeufige Abstuerze und weiterleitungen im Firefox |
09.04.2013, 16:48 | #7 |
| Haeufige Abstuerze und weiterleitungen im Firefox Spybot & SearchAnonymizer wurden geloescht. AdwCleaner[S1] Code:
ATTFilter # AdwCleaner v2.200 - Datei am 09/04/2013 um 17:25:09 erstellt # Aktualisiert am 02/04/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzer : admin - MAURICE-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\admin\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Code:
ATTFilter # AdwCleaner v2.200 - Datei am 09/04/2013 um 17:25:25 erstellt # Aktualisiert am 02/04/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzer : admin - MAURICE-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\admin\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : GFilterSvc Gestoppt & Gelöscht : SearchAnonymizer ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\ProgramData\DeviceVM Ordner Gelöscht : C:\Users\admin\AppData\Roaming\DesktopIconForAmazon Ordner Gelöscht : C:\Users\admin\AppData\Roaming\OCS ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{206a7328-437f-4bd9-b53e-12bfee24d588} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16470 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0 (de) Datei : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v26.0.1410.43 Datei : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [331 octets] - [09/04/2013 17:25:09] AdwCleaner[S2].txt - [1839 octets] - [09/04/2013 17:25:25] ########## EOF - C:\AdwCleaner[S2].txt - [1899 octets] ########## AdwCleaner[S3] Code:
ATTFilter # AdwCleaner v2.200 - Datei am 09/04/2013 um 17:28:40 erstellt # Aktualisiert am 02/04/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzer : admin - MAURICE-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\admin\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16470 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0 (de) Datei : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v26.0.1410.43 Datei : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [331 octets] - [09/04/2013 17:25:09] AdwCleaner[S2].txt - [1966 octets] - [09/04/2013 17:25:25] AdwCleaner[S3].txt - [1003 octets] - [09/04/2013 17:28:40] ########## EOF - C:\AdwCleaner[S3].txt - [1063 octets] ########## ComboFix Code:
ATTFilter ComboFix 13-04-09.01 - admin 09.04.2013 17:35:36.2.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.4087.2401 [GMT 2:00] ausgeführt von:: c:\users\admin\Downloads\ComboFix.exe Benutzte Befehlsschalter :: c:\users\admin\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\windows\system32\clbcatqd.exe" "c:\windows\System32\GFilterSvc.exe" . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\clbcatqd.exe c:\windows\System32\GFilterSvc.exe . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_dplazsvr . . ((((((((((((((((((((((( Dateien erstellt von 2013-03-09 bis 2013-04-09 )))))))))))))))))))))))))))))) . . 2013-04-09 15:38 . 2013-04-09 15:38 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-04-09 13:13 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{67657373-B52E-4FEB-ACFF-90C9B74582D1}\mpengine.dll 2013-04-09 09:00 . 2013-04-09 09:00 -------- d-----w- C:\_OTL 2013-04-08 09:39 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-04-06 09:44 . 2013-04-06 09:44 -------- d-----w- c:\program files (x86)\JTL-Software 2013-04-03 08:53 . 2013-04-03 08:53 -------- d-----w- c:\users\admin\AppData\Local\WinZip 2013-04-03 07:47 . 2013-04-04 06:03 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2013-03-26 07:57 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys 2013-03-25 08:12 . 2013-03-25 08:12 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-25 08:12 . 2013-03-25 08:12 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-22 07:43 . 2012-12-03 08:51 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01CFE287-B1EE-415B-94AF-FAF5B56EE9A5}\gapaengine.dll 2013-03-21 10:37 . 2013-03-21 10:37 -------- d-----w- c:\users\admin\AppData\Roaming\SolidDocuments 2013-03-19 15:56 . 2013-03-21 08:30 -------- d-----w- c:\users\admin\AppData\Roaming\PC-FAX TX 2013-03-19 12:59 . 2006-07-07 11:40 73728 ------w- c:\windows\SysWow64\BRCrypt.dll 2013-03-15 12:33 . 2013-03-15 12:33 -------- d-----w- c:\users\admin\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat 2013-03-15 10:35 . 2013-03-15 10:35 -------- d-----w- c:\programdata\ALM . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-02 10:34 . 2010-09-28 13:49 282744 ------w- c:\windows\system32\MpSigStub.exe 2013-03-13 16:08 . 2010-09-30 06:45 72013344 ----a-w- c:\windows\system32\MRT.exe 2013-03-05 08:05 . 2013-03-05 08:05 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-03-05 08:04 . 2012-05-07 14:22 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-03-05 08:04 . 2010-09-29 07:46 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-02-21 08:30 . 2013-02-21 08:30 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-02-21 08:30 . 2013-02-21 08:30 310688 ----a-w- c:\windows\system32\javaws.exe 2013-02-21 08:30 . 2013-02-21 08:30 188832 ----a-w- c:\windows\system32\javaw.exe 2013-02-21 08:30 . 2013-02-21 08:30 188320 ----a-w- c:\windows\system32\java.exe 2013-02-21 08:30 . 2012-06-22 08:43 963488 ----a-w- c:\windows\system32\deployJava1.dll 2013-02-21 08:30 . 2012-06-22 08:43 1085344 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-01-20 14:59 . 2013-01-20 14:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 14:59 . 2010-10-24 20:25 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717}] 2013-02-20 08:54 138752 ----a-w- c:\programdata\DNSErrorHelper\bho.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2012-10-16 646744] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "Acrobat Assistant 8.0"="c:\psd temp\Acrobat 11.0\Acrobat\Acrotray.exe" [2012-12-18 3478752] "BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 AddonsHelper;AddonsHelper;c:\users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 ALSysIO;ALSysIO;c:\users\admin\AppData\Local\Temp\ALSysIO64.sys [x] R3 BackupReader;BackupReader;c:\windows\system32\DRIVERS\BackupReader.sys [2011-03-02 63872] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-29 834544] S2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-07-05 6581624] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-07-05 528760] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616] S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-01-12 35112] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-09-17 1250816] . . Inhalt des "geplante Tasks" Ordners . 2013-04-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-25 08:12] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001Core.job - c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10] . 2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001UA.job - c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-01-24 477600] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\ FF - ExtSQL: 2013-02-20 09:57; dnshelp@dnshelp.com; c:\users\admin\AppData\Roaming\Helper FF - ExtSQL: 2013-03-06 10:27; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF - ExtSQL: 2013-03-06 10:34; firebug@software.joehewitt.com; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\firebug@software.joehewitt.com.xpi FF - ExtSQL: 2013-03-15 11:37; web2pdfextension@web2pdf.adobedotcom; c:\psd temp\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM-Run-Ocs_SM - c:\users\admin\AppData\Roaming\OCS\SM\SearchAnonymizer.exe AddRemove-PandoraRecovery - g:\pandora recovery\Uninstall.exe AddRemove-PhotoRescue PC_is1 - g:\datenrettung\PhotoRescue PC v3.2.2.12903\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe c:\program files (x86)\TeamViewer\Version8\tv_w32.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-04-09 17:40:49 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-04-09 15:40 ComboFix2.txt 2013-04-09 14:29 . Vor Suchlauf: 23 Verzeichnis(se), 22.976.995.328 Bytes frei Nach Suchlauf: 25 Verzeichnis(se), 22.413.819.904 Bytes frei . - - End Of File - - 3E76A0C09AB26283556D6CB25347808B |
09.04.2013, 16:55 | #8 |
/// TB-Ausbilder | Haeufige Abstuerze und weiterleitungen im Firefox Gut! Soweit ich das sehe haben wir damit alles Schädliche entfernt. Um sicher sein zu können müssen jetzt noch ein paar Kontrollen machen und werden dann deinen Computer noch auf einen sicheren Stand bringen. Da diese Scans jetzt sehr lange dauern können bitte ich dich mir erst wieder zu schreiben, wenn du auch wirklich alles erledigt hast oder Probleme auftreten sollten. Schritt 1: Quick-Scan mit Malwarebytes Downloade Dir bitte Malwarebytes Anti-MalwareSchritt 2: Hinweis: Der Scan kann sehr lange (einige Stunden) dauern! Schritt 3: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck und:
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
10.04.2013, 09:26 | #9 |
| Haeufige Abstuerze und weiterleitungen im Firefox Moin, es scheint schon einiges gebracht zu haben, bisher keine abstuerze oder weiterleitungen mbam-log Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.04.10.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 admin :: MAURICE-PC [Administrator] 10.04.2013 08:53:02 mbam-log-2013-04-10 (08-53-02).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 243058 Laufzeit: 1 Minute(n), 26 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=afc0c8404aac814a9ba2ecd641380693 # engine=13585 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-10 08:15:04 # local_time=2013-04-10 10:15:04 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5892 16777213 88 94 4672757 16414932 0 0 # scanned=356854 # found=0 # cleaned=0 # scan_time=1931 Security Check Code:
ATTFilter book Results of screen317's Security Check version 0.99.61 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials (On Access scanning disabled!) Error obtaining update status for antivirus! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 JavaFX 2.1.1 Java 7 Update 17 Adobe Flash Player 11.6.602.180 Adobe Reader XI Mozilla Firefox (20.0) Mozilla Thunderbird (17.0.5) Google Chrome 25.0.1364.172 Google Chrome 26.0.1410.43 Google Chrome plugins... ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
10.04.2013, 13:33 | #10 |
/// TB-Ausbilder | Haeufige Abstuerze und weiterleitungen im Firefox Prima! Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich. Schritt 1: Tools deinstallieren Die Reihenfolge ist hier entscheidend.
Schritt 2: ESET deinstallieren (Optional)
Abschließend noch Tipps zu folgenden Themen:
Lesestoff: Systemupdates Man kann es gar nicht oft genug erwähnen, wie wichtig es ist, sein System aktuell zu halten. Dein Auto bringst du ja auch regelmässig zur Inspektion in die Werkstatt. Stelle also bitte sicher, dass die Systemupdates aktiviert sind:
Lesestoff: Softwareupdates Ebenso wichtig wie die Systemprogramme ist auch die Software, die du täglich nutzt. Die folgende Liste gibt dir einen kleinen Überblick mit Links zu den Updates, welche Programme dringend aktuell gehalten werden müssen (falls du sie überhaupt installiert hast und nutzt), weil durch deren Sicherheitslücken oft Malware auf die Computer gelangen kann:
Lesestoff: Sicherheitssoftware Würde dich jemand nackt auf dem Motorrad auf der Autobahn überholen würdest du auch den Kopf schütteln. Dein Computer braucht auch einen Schutz vor den täglichen kleinen Angriffen durch Schädlinge. Neben hervorragenden kommerziellen Anti-Viren-Lösungen gibt es auch durchaus gute Schutzprogramme, die kostenfrei mit reduziertem Funktionsumfang erhältlich sind. Aber vorsicht, hier gilt nicht "je mehr desto besser". Was du brauchst ist genau einen Virenscanner mit Hintergrundwächter. Nicht mehr und nicht weniger. Es gibt hier viele Produkte auf dem Markt, die einem gute Dienste leisten. Ich persönlich empfehle dir Avast Free Antivirus. Es bietet relativ guten Schutz, bei wenig nerviger Werbung und installiert dir ein Browserplugin, das dich vor gefährlichen Webseiten warnt.
Lesestoff: Sicheres Surfen Zunächst muss man sagen, dass es üblicherweise immer der menschliche Faktor ist, der es Malware ermöglicht auf einen Computer zu gelangen. Kaufst du Leuten, die an deiner Haustür klingeln, auch sofort ohne nachzudenken irgendwelches Zeug ab? Gewöhne dir daher zunächst einige Verhaltensregeln beim Surfen im Internet an:
Aber selbst bei der peinlichen Einhaltung dieser Regeln kann es dennoch zu einer sogenannten Drive-By-Infektion kommen, bei der ein Schädling aus dem Schutzmechanismus des Webbrowsers ausbricht. Um die Sicherheit noch weiter zu erhöhen gibt es spezielle Schutzsoftware, die deinen Browser noch weiter absichert.
Zuletzt denke bitte über die Benutzung eines alternativen Browsers nach. Programme, die nicht so oft verwendet werden, sind auch nicht so sehr im Focus der "bösen Jungs". D.h. du bist mit einem exotischen Browser eher auf der sicheren Seite. Grundsätzlich bist du erst einmal deutlich sicherer, wenn du nicht den Internet Explorer benutzt.
Damit wünsche ich dir noch viel Spaß beim Surfen im Internet ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Eine Bitte: Gib mir eine kurze Rückmeldung, wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
10.04.2013, 14:40 | #11 |
| Haeufige Abstuerze und weiterleitungen im Firefox Alles erledigt ... keine Spur mehr von irgendwelchen Probleme Danke fuer den super support, das ist auch eine Spede wert! |
10.04.2013, 16:45 | #12 |
/// TB-Ausbilder | Haeufige Abstuerze und weiterleitungen im Firefox Schön, dass wir helfen konnten Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen Falls du noch Lob oder Kritik loswerden möchtest, dann gibt es diesen Bereich hier: http://www.trojaner-board.de/lob-kritik-wuensche/
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
Themen zu Haeufige Abstuerze und weiterleitungen im Firefox |
abstürze, aufruf, browser, deinstallation, direkt, eingebe, firefox, gen, google, hoffe, komplette, konnte, laufen, registry, seite, spiel, stabil, stets, stuerzt, stunde, stunden, treibt, weitergeleitet, woche, wochen |