|
Log-Analyse und Auswertung: text enhance, Weiterleitungen von Google Links und Suchmaschinen-PluginWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.06.2013, 17:27 | #1 |
| text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin Hallo, seit gestern habe ich einige Probleme mit dem Computer, die alle auf einmal kamen. Ich befürchte, es handelt sich um einen Virus. :-( ---------- die Probleme: 1. Text-enhance ist aufgetaucht. Es unterstreicht Worte und lässt Werbung aufpoppen. 2. Mein Firefox startet nur langsam. Überhaupt ist der ganze PC sehr langsam geworden. 3. Ich werde von Google beim Anklicken normaler Suchergebnisse auf Werbeseiten weitergeleitet. Beispiel: survey-central meet-hot-girls bannersdontwork 4. Ich hatte plötzlich Delta Search als Startseite, die ich nie als Startseite eingetragen habe. Zuerst dachte ich, ich habe etwas verschusselt und wieder Google eingetragen, doch nach einem Neustart von Firefox erschien plötzlich die Delta Search Suchbar oben im Browser. 5. In den Firefox-Addons sind plötzlich die Erweiterungen FoxyDeal 6.2 und Lyrics Fan 1.114 und die Delta Toolbar 1.5.0 aufgetaucht. ---------- Vielleicht erklärt sich jemand bereit, mir zu helfen. Die Steps aus der Anleitung habe ich abgearbeitet. Vielen lieben Dank schonmal. :-) ---------- defogger.txt defogger_disable by jpshortstuff (23.02.10.1) Log created at 16:19 on 13/06/2013 (Mona) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. HKCU:DAEMON Tools Lite -> Removed Checking for services/drivers... SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- otl.txt OTL logfile created on: 13/06/2013 16:40:00 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Mona\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1014.05 Mb Total Physical Memory | 442.71 Mb Available Physical Memory | 43.66% Memory free 2.38 Gb Paging File | 1.92 Gb Available in Paging File | 80.55% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 74.53 Gb Total Space | 26.52 Gb Free Space | 35.58% Space Free | Partition Type: NTFS Computer Name: I | User Name: Mona | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/06/13 16:39:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mona\Desktop\OTL.exe PRC - [2013/06/12 08:53:44 | 027,994,056 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Mona\Application Data\Dropbox\bin\Dropbox.exe PRC - [2013/05/23 11:09:59 | 002,827,728 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe PRC - [2012/09/06 13:12:20 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe PRC - [2012/04/25 17:28:09 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe PRC - [2011/03/31 04:49:44 | 000,671,552 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe PRC - [2011/03/31 04:48:00 | 001,523,008 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe PRC - [2011/01/13 00:32:06 | 000,866,576 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe PRC - [2011/01/13 00:28:06 | 000,364,544 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe PRC - [2011/01/13 00:23:48 | 000,966,656 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe PRC - [2011/01/13 00:13:16 | 000,481,552 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe PRC - [2010/03/05 07:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe PRC - [2008/04/17 01:28:48 | 000,818,176 | ---- | M] (Jay Elaraj) -- C:\Program Files\TaskbarShuffle\taskbarshuffle.exe PRC - [2008/04/14 09:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/07/24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe PRC - [2005/10/19 02:11:08 | 000,061,440 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe PRC - [2004/06/11 06:48:04 | 000,286,720 | ---- | M] () -- C:\WINDOWS\vsnpstd.exe ========== Modules (No Company Name) ========== MOD - [2013/05/23 11:09:59 | 002,827,728 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe MOD - [2013/05/23 11:09:01 | 002,521,040 | ---- | M] () -- c:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll MOD - [2013/03/13 22:48:52 | 024,978,944 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Dropbox\bin\libcef.dll MOD - [2012/11/14 01:32:50 | 003,558,400 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Dropbox\bin\wxmsw28uh_vc.dll MOD - [2011/03/27 22:11:04 | 000,094,208 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll MOD - [2010/03/05 07:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe MOD - [2008/06/20 18:02:47 | 000,245,248 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll MOD - [2008/06/20 18:02:47 | 000,245,248 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll MOD - [2008/04/13 15:32:14 | 000,165,376 | ---- | M] () -- C:\Program Files\TaskbarShuffle\tbhookin.dll MOD - [2005/06/02 12:40:42 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\vsmon1.dll MOD - [2004/06/11 06:48:04 | 000,286,720 | ---- | M] () -- C:\WINDOWS\vsnpstd.exe ========== Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2013/06/09 19:34:20 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2013/05/23 11:09:59 | 002,827,728 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe -- (BrowserDefendert) SRV - [2013/01/27 12:11:46 | 000,020,456 | ---- | M] () [Auto | Stopped] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2011/03/31 04:48:00 | 001,523,008 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2011/03/31 04:45:32 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp) SRV - [2011/01/13 00:32:06 | 000,866,576 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) SRV - [2011/01/13 00:28:06 | 000,364,544 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe -- (WLANKEEPER) SRV - [2011/01/13 00:23:48 | 000,966,656 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe -- (S24EventMonitor) SRV - [2011/01/13 00:13:16 | 000,481,552 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) SRV - [2010/03/05 07:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess) SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2007/07/24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2) SRV - [2005/10/19 02:11:08 | 000,061,440 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe -- (ASFIPmon) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys) DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\\SystemRoot\System32\Drivers\sptd.sys -- (sptd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\snpstd.sys -- (snpstd) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | Boot | Stopped] -- -- (cerc6) DRV - [2013/06/09 20:26:31 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2011/05/02 05:52:18 | 000,071,680 | ---- | M] (Notebook Hardware Control) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nhcDriver.sys -- (nhcDriverDevice) DRV - [2011/04/15 01:18:08 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss) DRV - [2011/02/10 20:22:58 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2010/10/07 13:11:38 | 006,609,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETwLx32.sys -- (NETwLx32) DRV - [2010/05/20 06:15:04 | 000,013,952 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans) DRV - [2009/12/18 20:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv) DRV - [2009/11/12 22:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2009/10/26 14:47:30 | 004,221,952 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32) DRV - [2007/05/10 19:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2005/10/26 19:01:02 | 000,142,720 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2005/05/14 02:27:56 | 000,028,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbccid.sys -- (USBCCID) DRV - [2003/04/25 01:21:50 | 000,006,025 | ---- | M] (Broadcom Corporation) [Kernel | Auto | Running] -- C:\Program Files\Broadcom\ASFIPMon\BASFND.sys -- (BASFND) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search IE - HKLM\..\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = hxxp://www.startskins.com/startpage/0519266982/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=120007&babsrc=HP_ss&mntrId=683F00188BD68941 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=121845&babsrc=HP_ss&mntrId=683F00188BD68941 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 79 D8 61 ED 08 CC 01 [binary data] IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {C8C81311-2422-4E18-A58D-9A979110DB71} IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes\{04AEBAB1-2A7A-ACF3-A6E6-3EE698DFD0A8}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.delta-search.com/?q={searchTerms}&affID=121845&babsrc=SP_ss&mntrId=683F00188BD68941 IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\..\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.order.1: "Delta Search" FF - prefs.js..browser.search.selectedEngine: "Delta Search" FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de" FF - prefs.js..extensions.enabledAddons: %7Bdd3d7613-0246-469d-bc65-2a3cc1668adc%7D:0.7.1.1 FF - prefs.js..extensions.enabledAddons: %7Bdf4e4df5-5cb7-46b0-9aef-6c784c3249f8%7D:1.2.0 FF - prefs.js..extensions.enabledAddons: %7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10 FF - prefs.js..extensions.enabledAddons: %7B9fb8c270-7124-11dd-ad8b-0800200c9a66%7D:1.7.3 FF - prefs.js..extensions.enabledAddons: %7B5384767E-00D9-40E9-B72F-9CC39D655D6F%7D:1.4.2.1 FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.9 FF - prefs.js..extensions.enabledAddons: tineye%40ideeinc.com:1.1 FF - prefs.js..extensions.enabledAddons: en-GB%40dictionaries.addons.mozilla.org:1.19.1 FF - prefs.js..extensions.enabledAddons: lrcfan%40fansoft.br:1.114 FF - prefs.js..extensions.enabledAddons: ffxtlbr%40delta.com:1.5.0 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll File not found FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.3.37: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.3.37: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.3.37: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.3.37: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.3.37: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/05/03 03:30:59 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/05/03 03:30:59 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: F:\Programme\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/04/25 17:28:45 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/01/02 05:10:16 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\lrcfan@fansoft.br: C:\Program Files\LyricsFan\FF\ [2013/06/13 16:18:13 | 000,000,000 | ---D | M] [2012/05/16 23:23:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Extensions [2011/05/04 20:40:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/05/16 23:23:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Extensions\celtx@celtx.com [2013/06/13 16:18:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions [2013/06/13 10:24:53 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2013/06/13 10:24:53 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2013/06/13 16:18:17 | 000,000,000 | ---D | M] (FoxyDeal) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} [2013/06/13 10:24:53 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\en-GB@dictionaries.addons.mozilla.org [2013/06/13 16:18:44 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\ffxtlbr@delta.com [2013/06/13 10:07:54 | 000,023,197 | R--- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\tangofox-abouthome@haven667.xpi [2013/06/13 10:07:54 | 000,020,521 | R--- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\tangofox-pdf.js@haven667.xpi [2013/06/13 10:24:53 | 000,008,001 | ---- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\tineye@ideeinc.com.xpi [2013/06/13 10:24:48 | 000,023,197 | ---- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{9fb8c270-7124-11dd-ad8b-0800200c9a66}.xpi [2013/06/13 09:48:25 | 000,870,680 | ---- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013/06/13 10:24:48 | 000,434,392 | ---- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2013/06/13 10:03:18 | 000,016,192 | ---- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}.xpi [2013/06/13 10:24:48 | 000,026,136 | ---- | M] () (No name found) -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi [2013/06/13 16:18:33 | 000,006,470 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\searchplugins\babylon.xml [2013/06/13 16:18:33 | 000,006,470 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\searchplugins\BrowserDefender.xml [2013/06/13 16:18:53 | 000,001,294 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Mozilla\Firefox\Profiles\74e7v00t.default\searchplugins\delta.xml [2013/06/13 16:18:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2013/06/13 16:18:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2013/06/13 08:32:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2013/06/13 08:32:56 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2013/06/13 16:18:13 | 000,000,000 | ---D | M] ("Lyrics Fan") -- C:\PROGRAM FILES\LYRICSFAN\FF O1 HOSTS File: ([2011/05/04 16:03:57 | 000,433,234 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 14912 more lines... O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - F:\Programme\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll File not found O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (Lyrics Fan) - {A8720491-9558-4C0D-9E35-30EED15DFB2B} - C:\Program Files\LyricsFan\lrcfan.dll (FAN Software) O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com) O2 - BHO: (Social Extras Plugin) - {FF4E1D1D-705B-4379-AB33-22D98C1ABF55} - C:\Program Files\SocialExtras\socialx.dll (FBSkins.com) O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - F:\Programme\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll File not found O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com) O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe () O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe () O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.) O4 - HKCU..\Run: [Taskbar Shuffle] C:\Program Files\TaskbarShuffle\taskbarshuffle.exe (Jay Elaraj) O4 - Startup: C:\Documents and Settings\Mona\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Mona\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Mona\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm File not found O8 - Extra context menu item: Sothink Flash Downloader For IE - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Mona\Start Menu\Programs\IMVU\Run IMVU.lnk File not found O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: Sothink Flash Downloader For IE - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra 'Tools' menuitem : Sothink Flash Downloader For IE - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1304387599703 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB (DellSystem.Scanner) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab (SysInfo Class) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{788A38D0-BB34-498C-AA6C-D96A3DC033CD}: DhcpNameServer = 192.168.178.1 O20 - AppInit_DLLs: (c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll) - c:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll () O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\Mona\My Documents\My Pictures\Ramona\JackRussell.png O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mona\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011/04/02 05:50:10 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013/06/13 16:38:58 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mona\Desktop\OTL.exe [2013/06/13 16:18:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Application Data\BabSolution [2013/06/13 16:18:44 | 000,000,000 | ---D | C] -- C:\Program Files\Delta [2013/06/13 16:18:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Babylon [2013/06/13 16:18:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Application Data\Babylon [2013/06/13 16:18:16 | 000,000,000 | ---D | C] -- C:\Program Files\FoxyDeal [2013/06/13 16:18:13 | 000,000,000 | ---D | C] -- C:\Program Files\LyricsFan [2013/06/13 13:36:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT [2013/06/13 13:36:21 | 000,000,000 | ---D | C] -- C:\JRT [2013/06/13 13:29:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Start Menu\Programs\BrowserDefender [2013/06/13 13:29:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BrowserDefender [2013/06/13 13:26:50 | 000,000,000 | ---D | C] -- C:\Program Files\YourFileDownloader [2013/06/13 12:20:21 | 000,000,000 | -H-D | C] -- C:\WINDOWS\Icons [2013/06/13 12:11:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Application Data\Malwarebytes [2013/06/13 12:11:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2013/06/13 12:11:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2013/06/13 12:11:19 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2013/06/13 12:11:19 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2013/06/13 11:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\BookME [2013/06/13 11:37:23 | 000,000,000 | ---D | C] -- C:\Program Files\BookME4 [2013/06/13 11:37:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\My Documents\BookME [2013/06/13 11:07:37 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013/06/13 11:06:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard [2013/06/13 09:26:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Anvisoft [2013/06/13 09:26:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Start Menu\Programs\Anvisoft [2013/06/13 09:26:21 | 000,000,000 | ---D | C] -- C:\Program Files\Anvisoft [2013/06/13 09:03:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Local Settings\Application Data\Opera [2013/06/13 09:03:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Application Data\Opera [2013/06/13 09:02:58 | 000,000,000 | ---D | C] -- C:\Program Files\Opera [2013/06/13 08:32:53 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013/06/12 07:38:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Application Data\saSoftware [2013/06/12 07:31:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia [2013/06/12 07:05:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Application Data\Obsidium [2013/06/12 07:05:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AllMyBooks [2013/06/09 20:19:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DAEMON Tools Lite [2013/06/09 20:19:19 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2013/06/09 20:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\Application Data\DAEMON Tools Lite [2013/06/09 20:18:55 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite [2013/06/09 20:17:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite [2013/06/09 20:10:35 | 000,000,000 | ---D | C] -- C:\Program Files\Alcohol Soft [2013/06/09 20:05:04 | 000,466,008 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys [2013/06/09 19:34:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FLEXnet [2013/06/09 19:34:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared [2013/06/09 19:34:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Rosetta Stone [2013/06/09 19:33:07 | 000,000,000 | ---D | C] -- C:\Program Files\Rosetta Stone [2013/06/09 19:33:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone [2013/06/09 19:14:59 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes [2013/06/06 15:50:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mona\My Documents\Scribus_Vorlagen [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/06/13 16:44:00 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\BrowserDefendert.job [2013/06/13 16:39:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mona\Desktop\OTL.exe [2013/06/13 16:32:00 | 000,001,190 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1343024091-1606980848-1003UA.job [2013/06/13 16:32:00 | 000,001,138 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1343024091-1606980848-1003Core.job [2013/06/13 16:27:21 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013/06/13 16:22:23 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1960408961-1343024091-1606980848-1004.job [2013/06/13 16:22:22 | 000,000,324 | ---- | M] () -- C:\WINDOWS\tasks\YourFile DownloaderUpdate.job [2013/06/13 16:22:17 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2013/06/13 16:22:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013/06/13 16:20:05 | 000,000,176 | ---- | M] () -- C:\Documents and Settings\Mona\defogger_reenable [2013/06/13 16:19:01 | 000,000,262 | ---- | M] () -- C:\WINDOWS\tasks\EPUpdater.job [2013/06/13 16:17:19 | 000,609,336 | ---- | M] () -- C:\Documents and Settings\Mona\Desktop\setup.exe [2013/06/13 16:03:04 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2013/06/13 15:49:01 | 000,001,094 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2013/06/13 12:23:38 | 000,000,109 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf [2013/06/13 12:11:25 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\ Malwarebytes Anti-Malware .lnk [2013/06/13 11:38:09 | 000,000,616 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\BookME.lnk [2013/06/13 08:32:59 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2013/06/13 08:04:42 | 000,001,001 | ---- | M] () -- C:\Documents and Settings\Mona\Start Menu\Programs\Startup\Dropbox.lnk [2013/06/12 08:18:29 | 000,513,897 | ---- | M] () -- C:\Documents and Settings\Mona\Desktop\joyland_king_stephen.epub [2013/06/12 07:57:21 | 000,414,690 | ---- | M] () -- C:\Documents and Settings\Mona\Desktop\criminal_slaughter_karin.epub [2013/06/12 07:19:42 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\calibre - E-book management.lnk [2013/06/12 07:01:43 | 002,902,836 | ---- | M] () -- C:\Documents and Settings\Mona\Desktop\calibre_das_e_book_multi_tool_das_grosse_handbuch_.epub [2013/06/12 06:42:55 | 000,026,221 | ---- | M] () -- C:\Documents and Settings\Mona\My Documents\AmE.odt [2013/06/12 04:05:37 | 003,383,001 | R--- | M] () -- C:\Documents and Settings\Mona\Desktop\The_Polyglot_Project.pdf [2013/06/12 02:00:47 | 000,000,340 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-I-Mona.job [2013/06/11 04:52:17 | 020,412,287 | ---- | M] () -- C:\Documents and Settings\Mona\My Documents\Modernes_Webdesign_mit_CSS_-_Schritt_fuer_Schrit_nodrm.pdf [2013/06/11 03:39:34 | 000,012,991 | ---- | M] () -- C:\Documents and Settings\Mona\Desktop\testt.jpg [2013/06/10 06:34:46 | 000,040,590 | ---- | M] () -- C:\Documents and Settings\Mona\Desktop\Strommast.jpg.gif [2013/06/09 21:23:18 | 000,001,613 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\DAEMON Tools Lite.lnk [2013/06/09 21:22:24 | 000,000,873 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to RosettaStoneVersion3.exe.lnk [2013/06/09 20:27:41 | 000,494,330 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013/06/09 20:27:41 | 000,084,874 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2013/06/09 20:26:31 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2013/06/09 20:12:01 | 000,000,124 | ---- | M] () -- C:\Documents and Settings\Mona\My Documents\ax_files.xml [2013/06/09 20:04:09 | 000,000,030 | ---- | M] () -- C:\Program Files\Exiferupdate.ini [2013/06/07 17:38:34 | 000,328,574 | ---- | M] () -- C:\Documents and Settings\Mona\Desktop\ich_koch_dich_tot_k_ein_liebes_roman_berg_ellen.epub [2013/06/06 15:54:21 | 000,000,108 | -H-- | M] () -- C:\Documents and Settings\Mona\Desktop\.~lock.Scribus.odt# [2013/05/17 22:52:18 | 003,500,720 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013/05/17 03:07:05 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2013/05/17 01:35:05 | 000,000,983 | ---- | M] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\Dropbox.lnk [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/06/13 16:22:23 | 000,000,296 | ---- | C] () -- C:\WINDOWS\tasks\BrowserDefendert.job [2013/06/13 16:19:47 | 000,000,176 | ---- | C] () -- C:\Documents and Settings\Mona\defogger_reenable [2013/06/13 16:17:16 | 000,609,336 | ---- | C] () -- C:\Documents and Settings\Mona\Desktop\setup.exe [2013/06/13 13:28:37 | 000,000,262 | ---- | C] () -- C:\WINDOWS\tasks\EPUpdater.job [2013/06/13 13:26:52 | 000,000,324 | ---- | C] () -- C:\WINDOWS\tasks\YourFile DownloaderUpdate.job [2013/06/13 12:11:25 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\ Malwarebytes Anti-Malware .lnk [2013/06/13 11:38:09 | 000,000,616 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\BookME.lnk [2013/06/13 08:32:59 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2013/06/13 08:32:59 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk [2013/06/13 08:04:42 | 000,001,001 | ---- | C] () -- C:\Documents and Settings\Mona\Start Menu\Programs\Startup\Dropbox.lnk [2013/06/12 08:18:37 | 000,513,897 | ---- | C] () -- C:\Documents and Settings\Mona\Desktop\joyland_king_stephen.epub [2013/06/12 07:57:31 | 000,414,690 | ---- | C] () -- C:\Documents and Settings\Mona\Desktop\criminal_slaughter_karin.epub [2013/06/12 07:19:42 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\calibre - E-book management.lnk [2013/06/12 07:02:42 | 002,902,836 | ---- | C] () -- C:\Documents and Settings\Mona\Desktop\calibre_das_e_book_multi_tool_das_grosse_handbuch_.epub [2013/06/12 04:07:16 | 003,383,001 | R--- | C] () -- C:\Documents and Settings\Mona\Desktop\The_Polyglot_Project.pdf [2013/06/11 04:50:30 | 020,412,287 | ---- | C] () -- C:\Documents and Settings\Mona\My Documents\Modernes_Webdesign_mit_CSS_-_Schritt_fuer_Schrit_nodrm.pdf [2013/06/11 03:39:29 | 000,012,991 | ---- | C] () -- C:\Documents and Settings\Mona\Desktop\testt.jpg [2013/06/10 06:34:35 | 000,040,590 | ---- | C] () -- C:\Documents and Settings\Mona\Desktop\Strommast.jpg.gif [2013/06/09 21:23:18 | 000,001,613 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\DAEMON Tools Lite.lnk [2013/06/09 21:22:24 | 000,000,873 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to RosettaStoneVersion3.exe.lnk [2013/06/09 20:12:01 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Mona\My Documents\ax_files.xml [2013/06/07 17:38:50 | 000,328,574 | ---- | C] () -- C:\Documents and Settings\Mona\Desktop\ich_koch_dich_tot_k_ein_liebes_roman_berg_ellen.epub [2013/06/06 15:54:21 | 000,000,108 | -H-- | C] () -- C:\Documents and Settings\Mona\Desktop\.~lock.Scribus.odt# [2013/05/17 01:35:05 | 000,000,983 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Microsoft\Internet Explorer\Quick Launch\Dropbox.lnk [2012/11/16 21:56:04 | 000,000,218 | ---- | C] () -- C:\Documents and Settings\Mona\.recently-used.xbel [2012/05/25 11:35:23 | 000,000,030 | ---- | C] () -- C:\Program Files\Exiferupdate.ini [2012/05/17 22:55:08 | 000,002,374 | ---- | C] () -- C:\WINDOWS\MANUTIUS.INI [2012/04/25 17:51:45 | 000,402,235 | ---- | C] () -- C:\Documents and Settings\Mona\Local Settings\Application Data\SearchDial.crx [2012/03/15 12:05:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2012/03/15 03:25:46 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\06224bc38b738610a3c7ae371476c97f_c [2012/02/16 03:45:04 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012/02/09 14:51:52 | 000,286,720 | ---- | C] () -- C:\WINDOWS\vsnpstd.exe [2012/02/09 14:25:01 | 000,843,776 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe [2012/02/09 14:25:00 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini [2012/02/09 14:24:56 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll [2012/02/09 14:24:55 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll [2012/02/09 14:24:55 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll [2012/02/09 14:24:55 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll [2011/09/01 15:59:49 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Mona\Local Settings\Application Data\PUTTY.RND [2011/08/29 02:43:38 | 000,003,088 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys [2011/08/29 02:43:38 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\688625C979.sys [2011/05/15 13:37:12 | 000,015,872 | ---- | C] () -- C:\Documents and Settings\Mona\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/05/06 05:21:48 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Mona\Application Data\Adobe PNG Format CS5 Prefs ========== ZeroAccess Check ========== [2010/12/09 17:15:09 | 000,002,048 | -HS- | M] () -- C:\WINDOWS\Installer\{82bb308a-83b0-977a-405c-61167da674d4}\@ [2010/12/09 17:15:09 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\{82bb308a-83b0-977a-405c-61167da674d4}\L [2012/12/28 16:42:45 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\{82bb308a-83b0-977a-405c-61167da674d4}\U [2012/12/05 13:51:24 | 000,002,048 | -HS- | M] () -- C:\Documents and Settings\Mona\Local Settings\Application Data\{82bb308a-83b0-977a-405c-61167da674d4}\@ [2010/12/09 17:15:09 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Mona\Local Settings\Application Data\{82bb308a-83b0-977a-405c-61167da674d4}\L [2010/12/09 17:15:09 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Mona\Local Settings\Application Data\{82bb308a-83b0-977a-405c-61167da674d4}\U [2011/05/03 04:01:28 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2011/02/17 15:51:57 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 14:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 09:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2013/06/12 07:32:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AllMyBooks [2011/05/19 04:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AutoHideIP [2013/06/13 16:18:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon [2013/06/13 13:29:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BrowserDefender [2011/05/03 05:04:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited [2013/06/09 20:24:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite [2011/10/22 13:46:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\elsterformular [2011/05/04 13:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eXPert PDF [2011/05/04 20:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eXPert PDF 4 [2011/05/04 13:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eXPert PDF Jobs [2011/05/19 03:41:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeHideIP [2011/10/15 13:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters [2011/08/28 19:49:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe [2013/06/13 10:21:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone [2011/05/03 05:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software [2013/06/13 07:08:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TVgenial [2011/10/15 13:18:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UAB [2012/02/09 14:28:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\webcam 7 [2011/05/03 05:20:19 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} [2012/10/20 11:03:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\7-PDFWebsiteConverter [2011/05/27 19:17:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Amazon [2011/05/19 04:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\AutoHideIP [2013/06/13 16:18:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\BabSolution [2013/06/13 16:18:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Babylon [2013/06/12 07:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\calibre [2011/05/28 18:02:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2011/05/04 17:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\com.adobe.dmp.contentviewer [2013/06/09 20:22:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\DAEMON Tools Lite [2013/03/15 22:21:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\DDMSettings [2013/06/13 16:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Dropbox [2012/01/03 03:29:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\DVDVideoSoft [2011/10/22 13:30:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\elsterformular [2012/02/15 22:57:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\EssentialPIM [2011/05/04 15:34:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\eXPert PDF Editor [2013/03/25 02:54:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\FileZilla [2012/05/19 22:55:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Foxit Software [2011/05/19 03:41:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\FreeHideIP [2011/05/04 14:33:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Games [2011/05/09 13:57:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\GetRightToGo [2012/05/16 23:23:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Greyfirst [2012/07/02 01:22:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\gtk-2.0 [2012/04/25 17:41:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\HTML Executable [2011/12/07 04:35:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\inkscape [2011/05/14 13:03:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\KeePass [2012/05/01 02:58:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Lernkartei [2011/05/02 19:36:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\LibreOffice [2012/05/01 03:10:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\MemoryLifter [2011/05/22 22:28:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Mobipocket [2011/05/03 21:28:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Notebook Hardware Control [2013/06/12 07:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Obsidium [2013/06/13 09:18:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Opera [2012/05/17 00:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Papyrus Autor [2013/06/12 07:38:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\saSoftware [2013/05/18 03:34:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Scribus [2012/03/02 01:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Spacejock Software [2012/05/18 00:42:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\SystemUpdaterApp [2011/05/04 20:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Thunderbird [2012/03/14 23:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\TuneUp Software [2011/05/14 13:17:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Weaverslave [2012/05/18 02:33:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\Writer's Cafe 2 [2012/05/25 11:30:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mona\Application Data\XnView ========== Purity Check ========== ========== Hard Links - Junction Points - Mount Points - Symbolic Links ========== [C:\WINDOWS\$NtUninstallKB40659$] -> Error: Cannot create file handle -> Unknown point type < End of report > extras.txt OTL Extras logfile created on: 13/06/2013 16:40:00 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Mona\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1014.05 Mb Total Physical Memory | 442.71 Mb Available Physical Memory | 43.66% Memory free 2.38 Gb Paging File | 1.92 Gb Available in Paging File | 80.55% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 74.53 Gb Total Space | 26.52 Gb Free Space | 35.58% Space Free | Partition Type: NTFS Computer Name: I | User Name: Mona | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = Opera.HTML] -- "C:\Program Files\Opera\Opera.exe" "%1" [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htafile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [Betrachten mit XnView] -- "C:\Program Files\XnView\xnview.exe" "%1" (XnView, hxxp://www.xnview.com) Directory [Bridge] -- F:\Programme\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{18355D5F-FABE-49A2-B359-92020DBD51B1}" = Corel DESIGNER Technical Suite X4 - Windows Shell Extension "_{870DCAE9-E488-48C9-A512-F67914695750}" = Corel DESIGNER Technical Suite X4 "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 "{071B9AFA-EBE8-4ABF-8F4A-9F92612F517E}" = Broadcom ASF Management Applications "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{0E95DA08-2514-4399-AD87-349C350FA9DE}" = Intel(R) PROSet/Wireless WiFi-Software "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86 "{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack "{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = BrowserDefender "{1635620D-E548-406C-A74E-7492DC23AE71}" = Corel Designer Technical Suite X4 - IPM "{18355D5F-FABE-49A2-B359-92020DBD51B1}" = Corel DESIGNER Technical Suite X4 - Windows Shell Extension "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{230442A6-5D8E-468D-9142-1CE0C11CB044}" = Visual Basic for Applications (R) Core - German "{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011 "{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java(TM) 6 Update 30 "{26A24AE4-039D-4CA4-87B4-2F83216029F0}" = Java(TM) 6 Update 29 "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2 "{34B32B70-8081-11E2-89AF-B8AC6F98CCE3}" = Google Earth Plug-in "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client "{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU "{3BF317C6-64FF-4931-91B3-6DE4BD5989C8}" = Corel DESIGNER Technical Suite X4 - Lang DE "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4640FDE1-B83A-4376-84ED-86F86BEE2D41}" = Driver Detective "{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E33D05D-76CF-5D3C-4D5D-7727530FA161}" = Adobe Content Viewer "{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client DE-DE Language Pack "{55638FF1-18DA-4440-B457-2670BF3E39C6}" = Mathematik 5 und 6 "{5C81B189-5456-40C4-9313-7FE6FA6DD64C}" = Duden-Bibliothek "{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE) "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 "{6D63CBA6-3563-45E7-8D0C-97E92259542D}" = Visual Basic for Applications (R) Core "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{784218A0-6164-42DC-A17C-78C693327073}" = LibreOffice 3.4 Help Pack (German) "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.9.0 "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{870DCAE9-E488-48C9-A512-F67914695750}" = Corel DESIGNER Technical Suite X4 - ICA "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{99011A6E-5200-11DE-BDB8-7ACD56D89593}" = Rosetta Stone Version 3 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BB86A32-E255-40F8-97CD-F65FD7BA5180}" = Visual Basic for Applications (R) Core - English "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9CF4A37B-A8C4-44D7-8C53-13B9D9594BB2}" = Paint.NET v3.5.8 "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio "{A6E92CAB-9E63-46DC-8ABF-0CAFF7B7CD02}" = eXPert PDF 4 "{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{B0FE14F0-85BB-4CBF-A7C5-FE95475C1D1B}" = Corel DESIGNER Technical Suite X4 - Lang EN "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86 "{B7F54262-AB66-44B3-88BF-9FC69941B643}" = Broadcom Gigabit Integrated Controller "{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C4C8C083-F1F2-4BA5-9863-D52A34B4ED22}" = LibreOffice 3.4 "{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}" = System Requirements Lab for Intel "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D4328CA9-E332-456F-B68D-3D3DE90E50B5}" = calibre "{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{E9E9C6AE-1D9D-4A6F-B5F4-AA673E9861BD}" = Deep Exploration 5 CE "{EC421A14-0A27-44A1-BB85-21605935F15A}" = Corel DESIGNER Technical Suite X4 "{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera Plus "{EF147A9D-D94E-4875-910D-2AF98CBDFE2E}" = Corel DESIGNER Technical Suite X4 - Lang FR "{F3220F3E-3B12-4B65-861D-B8EFCCA44A39}" = VideoCAM Trek "{FD95FDC1-418F-4C6A-B8B8-658707875D59}" = Corel DESIGNER Technical Suite X4 - VBA "1489-3350-5074-6281" = JDownloader 0.9 "7-Zip" = 7-Zip 9.20 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Amazon Kindle" = Amazon Kindle "Ampps_is1" = Ampps 1.9 "BookME_is1" = BookME 4.6.0.1 "CamStudio" = CamStudio "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem "com.adobe.dmp.contentviewer" = Adobe Content Viewer "com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser "DAEMON Tools Lite" = DAEMON Tools Lite "delta" = Delta toolbar "Delta Chrome Toolbar" = Delta Chrome Toolbar "DivX Setup.divx.com" = DivX-Setup "FileZilla Client" = FileZilla Client 3.4.0 "Foxit Reader_is1" = Foxit Reader "FoxyDeal" = FoxyDeal "Free YouTube Download_is1" = Free YouTube Download version 3.0.20.1228 "GPL Ghostscript 9.06" = GPL Ghostscript "HDMI" = Intel(R) Graphics Media Accelerator Driver "ie8" = Windows Internet Explorer 8 "KeePass Password Safe_is1" = KeePass Password Safe 1.19b "Kopfrechnen trainieren_is1" = Kopfrechnen trainieren 2.0 "lrcfan@fansoft.br" = Lyrics Fan "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft Security Client" = Microsoft Security Essentials "Mozilla Firefox 21.0 (x86 de)" = Mozilla Firefox 21.0 (x86 de) "Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "RealPlayer 15.0" = RealPlayer "Scribus 1.4.1" = Scribus 1.4.1 "Scrivener 1030" = Scrivener "Sigil_is1" = Sigil 0.5.3 "Taskbar Shuffle_is1" = Taskbar Shuffle version 2.5 "TuneUp Utilities 2011" = TuneUp Utilities 2011 "VLC media player" = VLC media player 1.1.9 "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WinGimp-2.0_is1" = GIMP 2.6.11 "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Writer's Café_is1" = Writer's Café 2.30 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XnView_is1" = XnView 1.98.1 "yWriter5_is1" = yWriter5 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "KindlePreviewer" = Kindle Previewer "YourFileDownloader" = YourFileDownloader ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 04/05/2013 20:54:39 | Computer Name = I | Source = Google Update | ID = 20 Description = Error - 17/05/2013 16:53:47 | Computer Name = I | Source = .NET Runtime Optimization Service | ID = 1103 Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown Error - 27/05/2013 15:48:26 | Computer Name = I | Source = Broadcom ASF IP Monitor | ID = 0 Description = !ERROR 53 Refreshing BMAPI data Error - 06/06/2013 09:55:42 | Computer Name = I | Source = Application Hang | ID = 1002 Description = Hanging application soffice.bin, version 3.4.602.500, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 09/06/2013 13:14:47 | Computer Name = I | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Error - 09/06/2013 13:14:47 | Computer Name = I | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Error - 09/06/2013 13:51:33 | Computer Name = I | Source = Application Error | ID = 1000 Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module , version 0.0.0.0, fault address 0x00000000. Error - 09/06/2013 13:52:03 | Computer Name = I | Source = Application Error | ID = 1000 Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d. Error - 13/06/2013 03:22:11 | Computer Name = I | Source = MsiInstaller | ID = 11325 Description = Produkt: Duden-Bibliothek -- Fehler 1325. "Programme" ist kein gültiger kurzer Dateiname. Error - 13/06/2013 03:37:32 | Computer Name = I | Source = MsiInstaller | ID = 11325 Description = Produkt: Duden-Bibliothek -- Fehler 1325. "Programme" ist kein gültiger kurzer Dateiname. [ System Events ] Error - 13/06/2013 10:22:37 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:27:23 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:27:29 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:27:31 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:33:34 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:45:00 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:51:00 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:52:57 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 10:58:06 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 Error - 13/06/2013 11:02:28 | Computer Name = I | Source = Service Control Manager | ID = 7023 Description = The Network Location Awareness (NLA) service terminated with the following error: %%127 < End of report > gmer.exe GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-06-13 17:56:16 Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 Hitachi_HTS542580K9SA00 rev.BBBOC39P 74.53GB Running: gmer_2.1.19163.exe; Driver: C:\DOCUME~1\Mona\LOCALS~1\Temp\pxtdrpob.sys ---- Kernel code sections - GMER 2.1 ---- .rdata C:\WINDOWS\system32\DRIVERS\mrxsmb.sys unknown last section [0xA9893000, 0x267B, 0x48000040] ? C:\WINDOWS\system32\DRIVERS\mrxsmb.sys suspicious PE modification ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\winlogon.exe[156] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\WINDOWS\system32\services.exe[260] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\WINDOWS\system32\lsass.exe[280] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\WINDOWS\system32\ctfmon.exe[460] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\WINDOWS\system32\svchost.exe[524] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text ... .text C:\WINDOWS\System32\svchost.exe[1552] USER32.dll!DialogBoxIndirectParamAorW 7E4249D0 5 Bytes JMP 00C7000A .text C:\WINDOWS\System32\svchost.exe[1552] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 00C6000A .text C:\WINDOWS\System32\svchost.exe[1552] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 00C5000A .text C:\WINDOWS\system32\wbem\wmiprvse.exe[1576] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\Program Files\Real\RealPlayer\update\realsched.exe[1712] kernel32.dll!SetUnhandledExceptionFilter 7C8449CD 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4} .text C:\Program Files\Real\RealPlayer\update\realsched.exe[1712] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\Program Files\PDF24\pdf24.exe[1772] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 00984970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\WINDOWS\system32\spoolsv.exe[2040] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2308] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2368] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10004970 c:\docume~1\alluse~1\applic~1\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text ... ---- Trace I/O - GMER 2.1 ---- Trace ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x84f87698]<< 84f87698 Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86549ab8] 86549ab8 Trace 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> [0x84f32a70] 84f32a70 Trace \Driver\00001468[0x8623ba30] -> IRP_MJ_CREATE -> 0x84f87698 84f87698 ---- Modules - GMER 2.1 ---- Module (noname) (*** hidden *** ) AA358000-AA36E000 (90112 bytes) ---- Processes - GMER 2.1 ---- Process C:\WINDOWS\System32\svchost.exe (*** hidden *** ) 1552 ---- EOF - GMER 2.1 ---- Ich wünsche allen einen sonnigen Donnerstag. |
13.06.2013, 17:41 | #2 |
/// Malware-holic | text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin Hi,
__________________Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ |
13.06.2013, 18:00 | #3 |
| Inhalt der TDSSKiller-Datei Hallo markusg,
__________________hier ist der Inhalt der Datei: TDSSKiller.2.8.16.0_13.06.2013_18.46.36_log 18:46:36.0578 1396 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 18:46:36.0890 1396 ============================================================ 18:46:36.0890 1396 Current date / time: 2013/06/13 18:46:36.0890 18:46:36.0890 1396 SystemInfo: 18:46:36.0890 1396 18:46:36.0890 1396 OS Version: 5.1.2600 ServicePack: 3.0 18:46:36.0890 1396 Product type: Workstation 18:46:36.0890 1396 ComputerName: I 18:46:36.0890 1396 UserName: Mona 18:46:36.0890 1396 Windows directory: C:\WINDOWS 18:46:36.0890 1396 System windows directory: C:\WINDOWS 18:46:36.0890 1396 Processor architecture: Intel x86 18:46:36.0890 1396 Number of processors: 2 18:46:36.0890 1396 Page size: 0x1000 18:46:36.0890 1396 Boot type: Normal boot 18:46:36.0890 1396 ============================================================ 18:46:38.0859 1396 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 18:46:38.0875 1396 ============================================================ 18:46:38.0875 1396 \Device\Harddisk0\DR0: 18:46:38.0875 1396 MBR partitions: 18:46:38.0875 1396 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x950E482 18:46:38.0875 1396 ============================================================ 18:46:38.0921 1396 C: <-> \Device\Harddisk0\DR0\Partition1 18:46:38.0921 1396 ============================================================ 18:46:38.0921 1396 Initialize success 18:46:38.0921 1396 ============================================================ 18:48:06.0546 2532 ============================================================ 18:48:06.0546 2532 Scan started 18:48:06.0546 2532 Mode: Manual; SigCheck; TDLFS; 18:48:06.0546 2532 ============================================================ 18:48:07.0890 2532 ================ Scan system memory ======================== 18:48:11.0265 2532 System memory - ok 18:48:11.0265 2532 ================ Scan services ============================= 18:48:11.0796 2532 Abiosdsk - ok 18:48:11.0796 2532 abp480n5 - ok 18:48:11.0921 2532 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 18:48:16.0562 2532 ACPI - ok 18:48:16.0609 2532 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 18:48:16.0734 2532 ACPIEC - ok 18:48:16.0750 2532 adpu160m - ok 18:48:16.0859 2532 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 18:48:17.0062 2532 aec - ok 18:48:17.0171 2532 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 18:48:17.0296 2532 AFD - ok 18:48:17.0312 2532 Aha154x - ok 18:48:17.0312 2532 aic78u2 - ok 18:48:17.0328 2532 aic78xx - ok 18:48:17.0359 2532 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 18:48:17.0500 2532 Alerter - ok 18:48:17.0546 2532 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 18:48:17.0640 2532 ALG - ok 18:48:17.0640 2532 AliIde - ok 18:48:17.0656 2532 amsint - ok 18:48:17.0750 2532 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 18:48:17.0906 2532 AppMgmt - ok 18:48:17.0921 2532 asc - ok 18:48:17.0921 2532 asc3350p - ok 18:48:17.0921 2532 asc3550 - ok 18:48:18.0046 2532 [ A8FD25A183FAEDD810EFCDDB8118CA50 ] ASFIPmon C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe 18:48:18.0109 2532 ASFIPmon ( UnsignedFile.Multi.Generic ) - warning 18:48:18.0109 2532 ASFIPmon - detected UnsignedFile.Multi.Generic (1) 18:48:18.0296 2532 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 18:48:18.0390 2532 aspnet_state - ok 18:48:18.0437 2532 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 18:48:18.0640 2532 AsyncMac - ok 18:48:18.0765 2532 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 18:48:18.0968 2532 atapi - ok 18:48:18.0984 2532 Atdisk - ok 18:48:19.0031 2532 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 18:48:19.0203 2532 Atmarpc - ok 18:48:19.0281 2532 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 18:48:19.0437 2532 AudioSrv - ok 18:48:19.0484 2532 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 18:48:19.0593 2532 audstub - ok 18:48:19.0703 2532 [ C0ACD392ECE55784884CC208AAFA06CE ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys 18:48:19.0843 2532 b57w2k - ok 18:48:19.0890 2532 [ 3D87B0484BE1093C6614062701F375C5 ] BASFND C:\Program Files\Broadcom\ASFIPMon\BASFND.sys 18:48:19.0906 2532 BASFND ( UnsignedFile.Multi.Generic ) - warning 18:48:19.0906 2532 BASFND - detected UnsignedFile.Multi.Generic (1) 18:48:19.0953 2532 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 18:48:20.0109 2532 Beep - ok 18:48:20.0281 2532 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 18:48:20.0421 2532 Browser - ok 18:48:21.0968 2532 [ 013A330F16B1CECBDE5CB6F921689523 ] BrowserDefendert C:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe 18:48:24.0828 2532 BrowserDefendert - ok 18:48:24.0875 2532 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 18:48:25.0015 2532 cbidf2k - ok 18:48:25.0062 2532 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 18:48:25.0203 2532 CCDECODE - ok 18:48:25.0203 2532 cd20xrnt - ok 18:48:25.0296 2532 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 18:48:25.0453 2532 Cdaudio - ok 18:48:25.0515 2532 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 18:48:25.0687 2532 Cdfs - ok 18:48:25.0781 2532 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 18:48:25.0968 2532 Cdrom - ok 18:48:25.0984 2532 cerc6 - ok 18:48:25.0984 2532 Changer - ok 18:48:26.0015 2532 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 18:48:26.0187 2532 CiSvc - ok 18:48:26.0234 2532 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 18:48:26.0406 2532 ClipSrv - ok 18:48:26.0609 2532 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:48:26.0703 2532 clr_optimization_v2.0.50727_32 - ok 18:48:26.0796 2532 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 18:48:26.0984 2532 clr_optimization_v4.0.30319_32 - ok 18:48:27.0031 2532 [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 18:48:27.0265 2532 CmBatt - ok 18:48:27.0281 2532 CmdIde - ok 18:48:27.0312 2532 [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 18:48:27.0453 2532 Compbatt - ok 18:48:27.0453 2532 COMSysApp - ok 18:48:27.0468 2532 Cpqarray - ok 18:48:27.0515 2532 [ D01F685F8B4598D144B0CCE9FF95D8D5 ] cpudrv C:\Program Files\SystemRequirementsLab\cpudrv.sys 18:48:27.0562 2532 cpudrv - ok 18:48:27.0640 2532 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 18:48:27.0796 2532 CryptSvc - ok 18:48:27.0812 2532 dac2w2k - ok 18:48:27.0812 2532 dac960nt - ok 18:48:28.0078 2532 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 18:48:28.0546 2532 DcomLaunch - ok 18:48:28.0640 2532 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 18:48:28.0843 2532 Dhcp - ok 18:48:28.0890 2532 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 18:48:29.0109 2532 Disk - ok 18:48:29.0125 2532 dmadmin - ok 18:48:29.0593 2532 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 18:48:30.0453 2532 dmboot - ok 18:48:30.0562 2532 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 18:48:30.0812 2532 dmio - ok 18:48:30.0890 2532 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 18:48:31.0031 2532 dmload - ok 18:48:31.0078 2532 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 18:48:31.0218 2532 dmserver - ok 18:48:31.0265 2532 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 18:48:31.0453 2532 DMusic - ok 18:48:31.0515 2532 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 18:48:31.0578 2532 Dnscache - ok 18:48:31.0687 2532 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 18:48:31.0890 2532 Dot3svc - ok 18:48:31.0890 2532 dpti2o - ok 18:48:31.0984 2532 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 18:48:32.0156 2532 drmkaud - ok 18:48:32.0359 2532 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys 18:48:32.0515 2532 dtsoftbus01 - ok 18:48:32.0562 2532 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 18:48:32.0703 2532 EapHost - ok 18:48:32.0734 2532 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 18:48:32.0890 2532 ERSvc - ok 18:48:33.0046 2532 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 18:48:33.0140 2532 Eventlog - ok 18:48:33.0296 2532 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 18:48:33.0515 2532 EventSystem - ok 18:48:34.0046 2532 [ 8759748B9A5FA3C1257A22EFED056B83 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 18:48:34.0953 2532 EvtEng - ok 18:48:35.0078 2532 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 18:48:35.0281 2532 Fastfat - ok 18:48:35.0453 2532 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 18:48:35.0609 2532 FastUserSwitchingCompatibility - ok 18:48:35.0656 2532 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 18:48:35.0875 2532 Fdc - ok 18:48:35.0937 2532 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 18:48:36.0078 2532 Fips - ok 18:48:36.0515 2532 [ BB0667B0171B632B97EA759515476F07 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 18:48:37.0187 2532 FLEXnet Licensing Service - ok 18:48:37.0203 2532 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 18:48:37.0375 2532 Flpydisk - ok 18:48:37.0468 2532 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 18:48:37.0656 2532 FltMgr - ok 18:48:37.0734 2532 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 18:48:37.0796 2532 FontCache3.0.0.0 - ok 18:48:37.0812 2532 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 18:48:37.0984 2532 Fs_Rec - ok 18:48:38.0046 2532 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 18:48:38.0234 2532 Ftdisk - ok 18:48:38.0281 2532 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 18:48:38.0453 2532 Gpc - ok 18:48:38.0578 2532 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 18:48:38.0656 2532 gupdate - ok 18:48:38.0734 2532 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 18:48:38.0765 2532 gupdatem - ok 18:48:38.0875 2532 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 18:48:39.0078 2532 HDAudBus - ok 18:48:39.0250 2532 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 18:48:39.0468 2532 helpsvc - ok 18:48:39.0468 2532 HidServ - ok 18:48:39.0515 2532 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 18:48:39.0656 2532 HidUsb - ok 18:48:39.0703 2532 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 18:48:39.0906 2532 hkmsvc - ok 18:48:39.0906 2532 hpn - ok 18:48:40.0453 2532 [ E8EC1767EA315A39A0DD8989952CA0E9 ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys 18:48:41.0390 2532 HSF_DPV - ok 18:48:41.0500 2532 [ 61478FA42EE04562E7F11F4DCA87E9C8 ] HSXHWAZL C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys 18:48:41.0640 2532 HSXHWAZL - ok 18:48:41.0812 2532 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 18:48:41.0984 2532 HTTP - ok 18:48:42.0031 2532 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 18:48:42.0234 2532 HTTPFilter - ok 18:48:42.0234 2532 i2omgmt - ok 18:48:42.0234 2532 i2omp - ok 18:48:42.0312 2532 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 18:48:42.0562 2532 i8042prt - ok 18:48:45.0531 2532 [ E8C7CC369C2FB657E0792AF70DF529E6 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 18:48:51.0359 2532 ialm - ok 18:48:51.0890 2532 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 18:48:52.0765 2532 idsvc - ok 18:48:52.0812 2532 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 18:48:52.0968 2532 Imapi - ok 18:48:53.0125 2532 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 18:48:53.0343 2532 ImapiService - ok 18:48:53.0343 2532 ini910u - ok 18:48:53.0359 2532 IntelIde - ok 18:48:53.0484 2532 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 18:48:53.0640 2532 intelppm - ok 18:48:53.0671 2532 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 18:48:53.0828 2532 Ip6Fw - ok 18:48:53.0875 2532 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 18:48:54.0031 2532 IpFilterDriver - ok 18:48:54.0046 2532 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 18:48:54.0171 2532 IpInIp - ok 18:48:54.0265 2532 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 18:48:54.0468 2532 IpNat - ok 18:48:54.0593 2532 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 18:48:54.0765 2532 IPSec - ok 18:48:54.0796 2532 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 18:48:54.0875 2532 IRENUM - ok 18:48:54.0937 2532 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 18:48:55.0078 2532 isapnp - ok 18:48:55.0250 2532 [ 9AA67569D5257462E230767510B0C815 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe 18:48:55.0375 2532 JavaQuickStarterService - ok 18:48:55.0421 2532 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 18:48:55.0640 2532 Kbdclass - ok 18:48:55.0765 2532 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 18:48:55.0968 2532 kmixer - ok 18:48:56.0046 2532 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 18:48:56.0203 2532 KSecDD - ok 18:48:56.0296 2532 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 18:48:56.0406 2532 LanmanServer - ok 18:48:56.0515 2532 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 18:48:56.0687 2532 lanmanworkstation - ok 18:48:56.0687 2532 lbrtfdc - ok 18:48:56.0765 2532 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 18:48:56.0953 2532 LmHosts - ok 18:48:56.0953 2532 [ E246A32C445056996074A397DA56E815 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 18:48:57.0062 2532 mdmxsdk - ok 18:48:57.0093 2532 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 18:48:57.0250 2532 Messenger - ok 18:48:57.0375 2532 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 18:48:57.0484 2532 mnmdd - ok 18:48:57.0546 2532 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 18:48:57.0734 2532 mnmsrvc - ok 18:48:57.0765 2532 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 18:48:57.0906 2532 Modem - ok 18:48:57.0937 2532 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 18:48:58.0078 2532 Mouclass - ok 18:48:58.0125 2532 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 18:48:58.0250 2532 mouhid - ok 18:48:58.0296 2532 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 18:48:58.0437 2532 MountMgr - ok 18:48:58.0640 2532 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys 18:48:58.0765 2532 MpFilter - ok 18:48:58.0765 2532 mraid35x - ok 18:48:58.0906 2532 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 18:48:59.0187 2532 MRxDAV - ok 18:48:59.0484 2532 [ 477B313691BAF04C23445CB55345466A ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 18:48:59.0781 2532 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\mrxsmb.sys. Real md5: 477B313691BAF04C23445CB55345466A, Fake md5: 7D304A5EB4344EBEEAB53A2FE3FFB9F0 18:48:59.0796 2532 MRxSmb ( Virus.Win32.ZAccess.aml ) - infected 18:48:59.0796 2532 MRxSmb - detected Virus.Win32.ZAccess.aml (0) 18:48:59.0828 2532 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 18:48:59.0953 2532 MSDTC - ok 18:49:00.0046 2532 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 18:49:00.0218 2532 Msfs - ok 18:49:00.0234 2532 MSIServer - ok 18:49:00.0921 2532 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 18:49:01.0062 2532 MSKSSRV - ok 18:49:01.0156 2532 MsMpSvc - ok 18:49:01.0187 2532 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 18:49:01.0328 2532 MSPCLOCK - ok 18:49:01.0359 2532 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 18:49:01.0484 2532 MSPQM - ok 18:49:01.0531 2532 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 18:49:01.0750 2532 mssmbios - ok 18:49:01.0796 2532 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 18:49:01.0906 2532 MSTEE - ok 18:49:02.0000 2532 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 18:49:02.0093 2532 Mup - ok 18:49:02.0156 2532 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 18:49:02.0343 2532 NABTSFEC - ok 18:49:02.0593 2532 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 18:49:03.0015 2532 napagent - ok 18:49:03.0125 2532 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 18:49:03.0343 2532 NDIS - ok 18:49:03.0437 2532 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 18:49:03.0578 2532 NdisIP - ok 18:49:03.0625 2532 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 18:49:03.0687 2532 NdisTapi - ok 18:49:03.0750 2532 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 18:49:03.0921 2532 Ndisuio - ok 18:49:04.0000 2532 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 18:49:04.0203 2532 NdisWan - ok 18:49:04.0265 2532 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 18:49:04.0328 2532 NDProxy - ok 18:49:04.0375 2532 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 18:49:04.0531 2532 NetBIOS - ok 18:49:04.0703 2532 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 18:49:04.0968 2532 NetBT - ok 18:49:05.0046 2532 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 18:49:05.0265 2532 NetDDE - ok 18:49:05.0328 2532 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 18:49:05.0453 2532 NetDDEdsdm - ok 18:49:05.0515 2532 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 18:49:05.0656 2532 Netlogon - ok 18:49:05.0781 2532 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 18:49:06.0359 2532 Netman - ok 18:49:06.0453 2532 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 18:49:06.0578 2532 NetTcpPortSharing - ok 18:49:08.0843 2532 [ 91F027C242D3FF6E5C09F92A0518297F ] NETw5x32 C:\WINDOWS\system32\DRIVERS\NETw5x32.sys 18:49:13.0171 2532 NETw5x32 - ok 18:49:16.0625 2532 [ 72062B53186E4A3F5FCBC41EBB62B905 ] NETwLx32 C:\WINDOWS\system32\DRIVERS\NETwLx32.sys 18:49:23.0375 2532 NETwLx32 - ok 18:49:23.0437 2532 [ 9F967A6DB0E6E0E01F898C26FEDD418B ] nhcDriverDevice C:\WINDOWS\system32\drivers\nhcDriver.sys 18:49:23.0484 2532 nhcDriverDevice ( UnsignedFile.Multi.Generic ) - warning 18:49:23.0484 2532 nhcDriverDevice - detected UnsignedFile.Multi.Generic (1) 18:49:23.0625 2532 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 18:49:23.0796 2532 Nla - ok 18:49:23.0921 2532 [ 7AEA4DF1CA68FD45DD4BBE1F0243CE7F ] NMSAccess C:\Program Files\CDBurnerXP\NMSAccessU.exe 18:49:24.0000 2532 NMSAccess - ok 18:49:24.0062 2532 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 18:49:24.0265 2532 Npfs - ok 18:49:24.0593 2532 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 18:49:25.0187 2532 Ntfs - ok 18:49:25.0218 2532 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 18:49:25.0375 2532 NtLmSsp - ok 18:49:25.0609 2532 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 18:49:26.0078 2532 NtmsSvc - ok 18:49:26.0109 2532 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 18:49:26.0250 2532 Null - ok 18:49:26.0296 2532 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 18:49:26.0437 2532 NwlnkFlt - ok 18:49:26.0453 2532 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 18:49:26.0593 2532 NwlnkFwd - ok 18:49:26.0718 2532 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys 18:49:26.0890 2532 Parport - ok 18:49:27.0000 2532 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 18:49:27.0140 2532 PartMgr - ok 18:49:27.0171 2532 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 18:49:27.0343 2532 ParVdm - ok 18:49:27.0421 2532 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 18:49:27.0593 2532 PCI - ok 18:49:27.0593 2532 PCIDump - ok 18:49:27.0609 2532 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 18:49:27.0734 2532 PCIIde - ok 18:49:27.0812 2532 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 18:49:27.0984 2532 Pcmcia - ok 18:49:28.0000 2532 PDCOMP - ok 18:49:28.0000 2532 PDFRAME - ok 18:49:28.0000 2532 PDRELI - ok 18:49:28.0015 2532 PDRFRAME - ok 18:49:28.0015 2532 perc2 - ok 18:49:28.0031 2532 perc2hib - ok 18:49:28.0140 2532 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 18:49:28.0203 2532 PlugPlay - ok 18:49:28.0218 2532 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 18:49:28.0390 2532 PolicyAgent - ok 18:49:28.0421 2532 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 18:49:28.0593 2532 PptpMiniport - ok 18:49:28.0609 2532 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 18:49:28.0718 2532 ProtectedStorage - ok 18:49:28.0765 2532 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 18:49:28.0921 2532 PSched - ok 18:49:29.0046 2532 [ A6A7AD767BF5141665F5C675F671B3E1 ] PSI_SVC_2 c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe 18:49:29.0171 2532 PSI_SVC_2 - ok 18:49:29.0187 2532 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 18:49:29.0328 2532 Ptilink - ok 18:49:29.0406 2532 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 18:49:29.0437 2532 PxHelp20 - ok 18:49:29.0453 2532 ql1080 - ok 18:49:29.0453 2532 Ql10wnt - ok 18:49:29.0453 2532 ql12160 - ok 18:49:29.0468 2532 ql1240 - ok 18:49:29.0468 2532 ql1280 - ok 18:49:29.0515 2532 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 18:49:29.0640 2532 RasAcd - ok 18:49:29.0718 2532 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 18:49:29.0906 2532 RasAuto - ok 18:49:30.0000 2532 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 18:49:30.0171 2532 Rasl2tp - ok 18:49:30.0281 2532 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 18:49:30.0578 2532 RasMan - ok 18:49:30.0609 2532 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 18:49:30.0781 2532 RasPppoe - ok 18:49:30.0796 2532 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 18:49:30.0921 2532 Raspti - ok 18:49:31.0015 2532 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 18:49:31.0250 2532 Rdbss - ok 18:49:31.0265 2532 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 18:49:31.0390 2532 RDPCDD - ok 18:49:31.0578 2532 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 18:49:31.0796 2532 rdpdr - ok 18:49:31.0968 2532 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 18:49:32.0187 2532 RDPWD - ok 18:49:32.0296 2532 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 18:49:32.0484 2532 RDSessMgr - ok 18:49:32.0531 2532 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 18:49:32.0703 2532 redbook - ok 18:49:33.0078 2532 [ 3A4959BA4774A55199AC4AE7FFD71924 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 18:49:33.0484 2532 RegSrvc - ok 18:49:33.0593 2532 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 18:49:33.0968 2532 RemoteAccess - ok 18:49:34.0015 2532 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 18:49:34.0218 2532 RemoteRegistry - ok 18:49:34.0281 2532 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 18:49:34.0437 2532 RpcLocator - ok 18:49:34.0656 2532 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll 18:49:34.0812 2532 RpcSs - ok 18:49:34.0906 2532 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 18:49:35.0125 2532 RSVP - ok 18:49:35.0687 2532 [ 1FD4A7B6087C98BC27344BD3973F2031 ] S24EventMonitor C:\Program Files\Intel\WiFi\bin\S24EvMon.exe 18:49:36.0578 2532 S24EventMonitor ( UnsignedFile.Multi.Generic ) - warning 18:49:36.0578 2532 S24EventMonitor - detected UnsignedFile.Multi.Generic (1) 18:49:36.0609 2532 [ 27FC71DA659305E260ACBDA15A318399 ] s24trans C:\WINDOWS\system32\DRIVERS\s24trans.sys 18:49:36.0671 2532 s24trans - ok 18:49:36.0687 2532 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 18:49:36.0812 2532 SamSs - ok 18:49:36.0906 2532 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 18:49:37.0093 2532 SCardSvr - ok 18:49:37.0250 2532 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 18:49:37.0468 2532 Schedule - ok 18:49:37.0500 2532 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 18:49:37.0578 2532 Secdrv - ok 18:49:37.0625 2532 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 18:49:37.0765 2532 seclogon - ok 18:49:37.0796 2532 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 18:49:37.0968 2532 SENS - ok 18:49:38.0000 2532 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 18:49:38.0140 2532 serenum - ok 18:49:38.0203 2532 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 18:49:38.0359 2532 Serial - ok 18:49:38.0468 2532 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 18:49:38.0625 2532 Sfloppy - ok 18:49:38.0718 2532 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 18:49:38.0781 2532 ShellHWDetection - ok 18:49:38.0781 2532 Simbad - ok 18:49:38.0843 2532 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 18:49:38.0984 2532 SLIP - ok 18:49:39.0000 2532 snpstd - ok 18:49:39.0000 2532 Sparrow - ok 18:49:39.0093 2532 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 18:49:39.0250 2532 splitter - ok 18:49:39.0328 2532 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 18:49:39.0390 2532 Spooler - ok 18:49:39.0406 2532 sptd - ok 18:49:39.0484 2532 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 18:49:39.0609 2532 sr - ok 18:49:39.0718 2532 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 18:49:39.0875 2532 srservice - ok 18:49:40.0093 2532 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 18:49:40.0453 2532 Srv - ok 18:49:40.0531 2532 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 18:49:40.0671 2532 SSDPSRV - ok 18:49:40.0703 2532 [ F92254B0BCFCD10CAAC7BCCC7CB7F467 ] StarOpen C:\WINDOWS\system32\drivers\StarOpen.sys 18:49:40.0734 2532 StarOpen ( UnsignedFile.Multi.Generic ) - warning 18:49:40.0734 2532 StarOpen - detected UnsignedFile.Multi.Generic (1) 18:49:41.0437 2532 [ 951801DFB54D86F611F0AF47825476F9 ] STHDA C:\WINDOWS\system32\drivers\sthda.sys 18:49:42.0718 2532 STHDA - ok 18:49:42.0937 2532 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 18:49:43.0359 2532 stisvc - ok 18:49:43.0375 2532 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 18:49:43.0515 2532 streamip - ok 18:49:43.0546 2532 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 18:49:43.0687 2532 swenum - ok 18:49:44.0281 2532 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 18:49:45.0031 2532 SwitchBoard ( UnsignedFile.Multi.Generic ) - warning 18:49:45.0031 2532 SwitchBoard - detected UnsignedFile.Multi.Generic (1) 18:49:45.0078 2532 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 18:49:45.0265 2532 swmidi - ok 18:49:45.0265 2532 SwPrv - ok 18:49:45.0265 2532 symc810 - ok 18:49:45.0281 2532 symc8xx - ok 18:49:45.0281 2532 sym_hi - ok 18:49:45.0296 2532 sym_u3 - ok 18:49:45.0390 2532 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 18:49:45.0578 2532 sysaudio - ok 18:49:45.0671 2532 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 18:49:46.0109 2532 SysmonLog - ok 18:49:46.0312 2532 [ 0C3B2A9C4BD2DD9A6C2E4084314DD719 ] taphss C:\WINDOWS\system32\DRIVERS\taphss.sys 18:49:46.0406 2532 taphss - ok 18:49:46.0734 2532 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 18:49:47.0031 2532 TapiSrv - ok 18:49:47.0343 2532 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 18:49:47.0734 2532 Tcpip - ok 18:49:47.0781 2532 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 18:49:47.0906 2532 TDPIPE - ok 18:49:47.0937 2532 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 18:49:48.0140 2532 TDTCP - ok 18:49:48.0203 2532 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 18:49:48.0343 2532 TermDD - ok 18:49:48.0531 2532 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 18:49:48.0875 2532 TermService - ok 18:49:48.0953 2532 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 18:49:48.0984 2532 Themes - ok 18:49:49.0046 2532 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 18:49:49.0250 2532 TlntSvr - ok 18:49:49.0250 2532 TosIde - ok 18:49:49.0328 2532 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 18:49:49.0515 2532 TrkWks - ok 18:49:50.0437 2532 [ 022EDFF8E6F42A6866CB199786A522AB ] TuneUp.UtilitiesSvc C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe 18:49:52.0593 2532 TuneUp.UtilitiesSvc - ok 18:49:52.0640 2532 [ F2107C9D85EC0DF116939CCCE06AE697 ] TuneUpUtilitiesDrv C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys 18:49:52.0671 2532 TuneUpUtilitiesDrv - ok 18:49:52.0734 2532 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 18:49:52.0906 2532 Udfs - ok 18:49:52.0906 2532 UIUSys - ok 18:49:52.0921 2532 ultra - ok 18:49:53.0125 2532 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 18:49:53.0593 2532 Update - ok 18:49:53.0718 2532 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 18:49:54.0296 2532 upnphost - ok 18:49:54.0343 2532 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 18:49:54.0546 2532 UPS - ok 18:49:54.0593 2532 [ 6B5E4D5E6E5ECD6ACD14AED59768CE5C ] USBCCID C:\WINDOWS\system32\DRIVERS\usbccid.sys 18:49:54.0656 2532 USBCCID - ok 18:49:54.0703 2532 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 18:49:54.0843 2532 usbehci - ok 18:49:54.0968 2532 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 18:49:55.0218 2532 usbhub - ok 18:49:55.0328 2532 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 18:49:55.0484 2532 USBSTOR - ok 18:49:55.0546 2532 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 18:49:55.0687 2532 usbuhci - ok 18:49:55.0750 2532 [ 9DA488B563051BACFF04E718F5BF6333 ] UxTuneUp C:\WINDOWS\System32\uxtuneup.dll 18:49:55.0781 2532 UxTuneUp - ok 18:49:55.0843 2532 [ B252DD05C8B1D64239EE8A93C4BC5AD4 ] VClone C:\WINDOWS\system32\DRIVERS\VClone.sys 18:49:55.0890 2532 VClone ( UnsignedFile.Multi.Generic ) - warning 18:49:55.0890 2532 VClone - detected UnsignedFile.Multi.Generic (1) 18:49:55.0921 2532 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 18:49:56.0109 2532 VgaSave - ok 18:49:56.0109 2532 ViaIde - ok 18:49:56.0187 2532 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 18:49:56.0359 2532 VolSnap - ok 18:49:56.0546 2532 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 18:49:56.0765 2532 VSS - ok 18:49:56.0906 2532 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 18:49:57.0250 2532 W32Time - ok 18:49:57.0312 2532 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 18:49:57.0453 2532 Wanarp - ok 18:49:57.0453 2532 WDICA - ok 18:49:57.0609 2532 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 18:49:57.0765 2532 wdmaud - ok 18:49:57.0828 2532 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 18:49:57.0984 2532 WebClient - ok 18:49:58.0375 2532 [ BA6B6FB242A6BA4068C8B763063BEB63 ] winachsf C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 18:49:59.0015 2532 winachsf - ok 18:49:59.0218 2532 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 18:49:59.0421 2532 winmgmt - ok 18:49:59.0656 2532 [ 3F76E8DA2AD0AF23167D173FB213F10A ] WLANKEEPER C:\Program Files\Intel\WiFi\bin\WLKeeper.exe 18:49:59.0968 2532 WLANKEEPER ( UnsignedFile.Multi.Generic ) - warning 18:49:59.0968 2532 WLANKEEPER - detected UnsignedFile.Multi.Generic (1) 18:50:00.0015 2532 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 18:50:00.0156 2532 WmdmPmSN - ok 18:50:00.0515 2532 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 18:50:01.0265 2532 Wmi - ok 18:50:01.0296 2532 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 18:50:01.0406 2532 WmiAcpi - ok 18:50:01.0515 2532 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 18:50:01.0718 2532 WmiApSrv - ok 18:50:02.0281 2532 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 18:50:03.0187 2532 WMPNetworkSvc - ok 18:50:03.0671 2532 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 18:50:04.0375 2532 WPFFontCache_v0400 - ok 18:50:04.0421 2532 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 18:50:04.0546 2532 WSTCODEC - ok 18:50:04.0625 2532 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 18:50:04.0718 2532 WudfPf - ok 18:50:04.0765 2532 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 18:50:04.0828 2532 WudfRd - ok 18:50:04.0890 2532 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 18:50:04.0953 2532 WudfSvc - ok 18:50:05.0218 2532 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 18:50:06.0062 2532 WZCSVC - ok 18:50:06.0156 2532 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 18:50:06.0437 2532 xmlprov - ok 18:50:06.0453 2532 ================ Scan global =============================== 18:50:06.0515 2532 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 18:50:06.0718 2532 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 18:50:07.0015 2532 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 18:50:07.0093 2532 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 18:50:07.0093 2532 [Global] - ok 18:50:07.0093 2532 ================ Scan MBR ================================== 18:50:07.0140 2532 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 18:50:07.0750 2532 \Device\Harddisk0\DR0 - ok 18:50:07.0750 2532 ================ Scan VBR ================================== 18:50:07.0750 2532 [ B1B9D5673FDE126340CF44CFC0BF0B2C ] \Device\Harddisk0\DR0\Partition1 18:50:07.0765 2532 \Device\Harddisk0\DR0\Partition1 - ok 18:50:07.0765 2532 ============================================================ 18:50:07.0765 2532 Scan finished 18:50:07.0765 2532 ============================================================ 18:50:07.0875 1052 Detected object count: 9 18:50:07.0875 1052 Actual detected object count: 9 18:50:25.0968 1052 ASFIPmon ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0968 1052 ASFIPmon ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:50:25.0968 1052 BASFND ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0968 1052 BASFND ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:50:25.0968 1052 MRxSmb ( Virus.Win32.ZAccess.aml ) - skipped by user 18:50:25.0968 1052 MRxSmb ( Virus.Win32.ZAccess.aml ) - User select action: Skip 18:50:25.0984 1052 nhcDriverDevice ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0984 1052 nhcDriverDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:50:25.0984 1052 S24EventMonitor ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0984 1052 S24EventMonitor ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:50:25.0984 1052 StarOpen ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0984 1052 StarOpen ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:50:25.0984 1052 SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0984 1052 SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:50:25.0984 1052 VClone ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0984 1052 VClone ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:50:25.0984 1052 WLANKEEPER ( UnsignedFile.Multi.Generic ) - skipped by user 18:50:25.0984 1052 WLANKEEPER ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:51:26.0421 1940 Deinitialize success LG Mona |
13.06.2013, 18:16 | #4 |
/// Malware-holic | text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin Hi, tdss kiler konfigurieren wie eben. wähle Win32.ZAccess dort cure. falls nicht möglich, delete. dann neustarten, konfigurieren wie eben, und neues TDSS killer log
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
13.06.2013, 19:18 | #5 |
| text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin Mit cure hat es sofort funktioniert. Inhalt der neuev TDSS-Datei: 20:08:01.0890 2696 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 20:08:03.0890 2696 ============================================================ 20:08:03.0921 2696 Current date / time: 2013/06/13 20:08:03.0890 20:08:03.0921 2696 SystemInfo: 20:08:03.0921 2696 20:08:03.0921 2696 OS Version: 5.1.2600 ServicePack: 3.0 20:08:03.0921 2696 Product type: Workstation 20:08:03.0953 2696 ComputerName: I 20:08:03.0953 2696 UserName: Mona 20:08:03.0953 2696 Windows directory: C:\WINDOWS 20:08:03.0953 2696 System windows directory: C:\WINDOWS 20:08:03.0953 2696 Processor architecture: Intel x86 20:08:03.0953 2696 Number of processors: 2 20:08:03.0953 2696 Page size: 0x1000 20:08:03.0953 2696 Boot type: Normal boot 20:08:03.0953 2696 ============================================================ 20:08:08.0343 2696 BG loaded 20:08:09.0437 2696 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:08:09.0484 2696 ============================================================ 20:08:09.0484 2696 \Device\Harddisk0\DR0: 20:08:09.0718 2696 MBR partitions: 20:08:09.0718 2696 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x950E482 20:08:09.0718 2696 ============================================================ 20:08:09.0968 2696 C: <-> \Device\Harddisk0\DR0\Partition1 20:08:09.0968 2696 ============================================================ 20:08:09.0968 2696 Initialize success 20:08:09.0968 2696 ============================================================ 20:08:25.0343 3192 ============================================================ 20:08:25.0343 3192 Scan started 20:08:25.0343 3192 Mode: Manual; SigCheck; TDLFS; 20:08:25.0343 3192 ============================================================ 20:08:27.0906 3192 ================ Scan system memory ======================== 20:08:33.0671 3192 System memory - ok 20:08:33.0671 3192 ================ Scan services ============================= 20:08:35.0781 3192 Abiosdsk - ok 20:08:35.0796 3192 abp480n5 - ok 20:08:35.0968 3192 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 20:09:08.0750 3192 ACPI - ok 20:09:08.0906 3192 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 20:09:09.0281 3192 ACPIEC - ok 20:09:09.0359 3192 adpu160m - ok 20:09:09.0687 3192 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 20:09:09.0890 3192 aec - ok 20:09:10.0187 3192 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 20:09:10.0546 3192 AFD - ok 20:09:10.0546 3192 Aha154x - ok 20:09:10.0578 3192 aic78u2 - ok 20:09:10.0671 3192 aic78xx - ok 20:09:10.0921 3192 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 20:09:11.0296 3192 Alerter - ok 20:09:11.0546 3192 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 20:09:11.0750 3192 ALG - ok 20:09:11.0750 3192 AliIde - ok 20:09:11.0781 3192 amsint - ok 20:09:12.0078 3192 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 20:09:12.0656 3192 AppMgmt - ok 20:09:12.0687 3192 asc - ok 20:09:12.0687 3192 asc3350p - ok 20:09:12.0781 3192 asc3550 - ok 20:09:13.0812 3192 [ A8FD25A183FAEDD810EFCDDB8118CA50 ] ASFIPmon C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe 20:09:14.0015 3192 ASFIPmon ( UnsignedFile.Multi.Generic ) - warning 20:09:14.0015 3192 ASFIPmon - detected UnsignedFile.Multi.Generic (1) 20:09:15.0453 3192 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 20:09:16.0125 3192 aspnet_state - ok 20:09:16.0203 3192 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 20:09:16.0468 3192 AsyncMac - ok 20:09:16.0703 3192 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 20:09:17.0234 3192 atapi - ok 20:09:17.0250 3192 Atdisk - ok 20:09:17.0421 3192 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 20:09:17.0859 3192 Atmarpc - ok 20:09:17.0984 3192 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 20:09:18.0296 3192 AudioSrv - ok 20:09:18.0437 3192 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 20:09:18.0703 3192 audstub - ok 20:09:19.0140 3192 [ C0ACD392ECE55784884CC208AAFA06CE ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys 20:09:19.0593 3192 b57w2k - ok 20:09:20.0484 3192 [ 3D87B0484BE1093C6614062701F375C5 ] BASFND C:\Program Files\Broadcom\ASFIPMon\BASFND.sys 20:09:20.0578 3192 BASFND ( UnsignedFile.Multi.Generic ) - warning 20:09:20.0578 3192 BASFND - detected UnsignedFile.Multi.Generic (1) 20:09:21.0062 3192 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 20:09:21.0265 3192 Beep - ok 20:09:21.0890 3192 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 20:09:22.0171 3192 Browser - ok 20:09:24.0765 3192 [ 013A330F16B1CECBDE5CB6F921689523 ] BrowserDefendert C:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe 20:09:27.0078 3192 BrowserDefendert - ok 20:09:27.0156 3192 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 20:09:28.0093 3192 cbidf2k - ok 20:09:28.0250 3192 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 20:09:28.0515 3192 CCDECODE - ok 20:09:28.0515 3192 cd20xrnt - ok 20:09:28.0593 3192 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 20:09:28.0812 3192 Cdaudio - ok 20:09:28.0937 3192 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 20:09:29.0140 3192 Cdfs - ok 20:09:29.0203 3192 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 20:09:29.0406 3192 Cdrom - ok 20:09:29.0437 3192 cerc6 - ok 20:09:29.0437 3192 Changer - ok 20:09:29.0546 3192 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 20:09:29.0781 3192 CiSvc - ok 20:09:29.0812 3192 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 20:09:29.0968 3192 ClipSrv - ok 20:09:30.0109 3192 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:09:30.0187 3192 clr_optimization_v2.0.50727_32 - ok 20:09:30.0296 3192 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:09:30.0484 3192 clr_optimization_v4.0.30319_32 - ok 20:09:30.0531 3192 [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 20:09:30.0750 3192 CmBatt - ok 20:09:30.0765 3192 CmdIde - ok 20:09:30.0796 3192 [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 20:09:31.0015 3192 Compbatt - ok 20:09:31.0031 3192 COMSysApp - ok 20:09:31.0046 3192 Cpqarray - ok 20:09:31.0140 3192 [ D01F685F8B4598D144B0CCE9FF95D8D5 ] cpudrv C:\Program Files\SystemRequirementsLab\cpudrv.sys 20:09:31.0218 3192 cpudrv - ok 20:09:31.0312 3192 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 20:09:31.0468 3192 CryptSvc - ok 20:09:31.0468 3192 dac2w2k - ok 20:09:31.0500 3192 dac960nt - ok 20:09:31.0828 3192 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 20:09:32.0187 3192 DcomLaunch - ok 20:09:32.0281 3192 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 20:09:32.0421 3192 Dhcp - ok 20:09:32.0468 3192 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 20:09:32.0640 3192 Disk - ok 20:09:32.0656 3192 dmadmin - ok 20:09:33.0140 3192 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 20:09:34.0109 3192 dmboot - ok 20:09:34.0265 3192 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 20:09:34.0562 3192 dmio - ok 20:09:34.0609 3192 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 20:09:34.0796 3192 dmload - ok 20:09:34.0828 3192 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 20:09:35.0000 3192 dmserver - ok 20:09:35.0093 3192 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 20:09:35.0250 3192 DMusic - ok 20:09:35.0312 3192 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 20:09:35.0359 3192 Dnscache - ok 20:09:35.0546 3192 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 20:09:35.0765 3192 Dot3svc - ok 20:09:35.0781 3192 dpti2o - ok 20:09:35.0828 3192 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 20:09:36.0031 3192 drmkaud - ok 20:09:36.0203 3192 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys 20:09:36.0296 3192 dtsoftbus01 - ok 20:09:36.0390 3192 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 20:09:36.0625 3192 EapHost - ok 20:09:36.0718 3192 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 20:09:37.0015 3192 ERSvc - ok 20:09:37.0125 3192 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 20:09:37.0187 3192 Eventlog - ok 20:09:37.0375 3192 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 20:09:37.0500 3192 EventSystem - ok 20:09:38.0140 3192 [ 8759748B9A5FA3C1257A22EFED056B83 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 20:09:38.0750 3192 EvtEng - ok 20:09:38.0937 3192 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 20:09:39.0296 3192 Fastfat - ok 20:09:39.0406 3192 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 20:09:39.0562 3192 FastUserSwitchingCompatibility - ok 20:09:39.0640 3192 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 20:09:40.0281 3192 Fdc - ok 20:09:40.0343 3192 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 20:09:40.0765 3192 Fips - ok 20:09:41.0234 3192 [ BB0667B0171B632B97EA759515476F07 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 20:09:42.0343 3192 FLEXnet Licensing Service - ok 20:09:42.0437 3192 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 20:09:42.0859 3192 Flpydisk - ok 20:09:43.0031 3192 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 20:09:43.0468 3192 FltMgr - ok 20:09:43.0953 3192 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 20:09:44.0093 3192 FontCache3.0.0.0 - ok 20:09:44.0140 3192 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 20:09:44.0375 3192 Fs_Rec - ok 20:09:44.0500 3192 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 20:09:44.0734 3192 Ftdisk - ok 20:09:44.0828 3192 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 20:09:45.0156 3192 Gpc - ok 20:09:45.0343 3192 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 20:09:45.0390 3192 gupdate - ok 20:09:45.0484 3192 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 20:09:45.0531 3192 gupdatem - ok 20:09:45.0687 3192 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 20:09:45.0906 3192 HDAudBus - ok 20:09:46.0015 3192 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 20:09:46.0203 3192 helpsvc - ok 20:09:46.0203 3192 HidServ - ok 20:09:46.0265 3192 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 20:09:46.0437 3192 HidUsb - ok 20:09:46.0593 3192 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 20:09:46.0843 3192 hkmsvc - ok 20:09:46.0859 3192 hpn - ok 20:09:48.0187 3192 [ E8EC1767EA315A39A0DD8989952CA0E9 ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys 20:09:48.0984 3192 HSF_DPV - ok 20:09:49.0265 3192 [ 61478FA42EE04562E7F11F4DCA87E9C8 ] HSXHWAZL C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys 20:09:49.0328 3192 HSXHWAZL - ok 20:09:49.0718 3192 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 20:09:49.0828 3192 HTTP - ok 20:09:49.0890 3192 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 20:09:50.0062 3192 HTTPFilter - ok 20:09:50.0078 3192 i2omgmt - ok 20:09:50.0078 3192 i2omp - ok 20:09:50.0281 3192 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 20:09:50.0500 3192 i8042prt - ok 20:10:00.0343 3192 [ E8C7CC369C2FB657E0792AF70DF529E6 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 20:10:07.0140 3192 ialm - ok 20:10:08.0890 3192 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 20:10:10.0312 3192 idsvc - ok 20:10:10.0468 3192 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 20:10:10.0656 3192 Imapi - ok 20:10:11.0046 3192 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 20:10:11.0218 3192 ImapiService - ok 20:10:11.0250 3192 ini910u - ok 20:10:11.0265 3192 IntelIde - ok 20:10:11.0406 3192 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 20:10:11.0625 3192 intelppm - ok 20:10:11.0796 3192 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 20:10:12.0046 3192 Ip6Fw - ok 20:10:12.0171 3192 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 20:10:12.0406 3192 IpFilterDriver - ok 20:10:12.0640 3192 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 20:10:12.0843 3192 IpInIp - ok 20:10:13.0109 3192 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 20:10:13.0375 3192 IpNat - ok 20:10:13.0687 3192 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 20:10:13.0859 3192 IPSec - ok 20:10:14.0000 3192 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 20:10:14.0125 3192 IRENUM - ok 20:10:14.0328 3192 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 20:10:14.0609 3192 isapnp - ok 20:10:14.0859 3192 [ 9AA67569D5257462E230767510B0C815 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe 20:10:14.0921 3192 JavaQuickStarterService - ok 20:10:14.0984 3192 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 20:10:15.0187 3192 Kbdclass - ok 20:10:15.0296 3192 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 20:10:15.0468 3192 kmixer - ok 20:10:15.0578 3192 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 20:10:15.0843 3192 KSecDD - ok 20:10:15.0937 3192 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 20:10:16.0062 3192 LanmanServer - ok 20:10:16.0203 3192 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 20:10:16.0359 3192 lanmanworkstation - ok 20:10:16.0359 3192 lbrtfdc - ok 20:10:16.0421 3192 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 20:10:16.0625 3192 LmHosts - ok 20:10:16.0656 3192 [ E246A32C445056996074A397DA56E815 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 20:10:16.0703 3192 mdmxsdk - ok 20:10:16.0765 3192 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 20:10:16.0968 3192 Messenger - ok 20:10:17.0046 3192 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 20:10:17.0203 3192 mnmdd - ok 20:10:17.0265 3192 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 20:10:17.0500 3192 mnmsrvc - ok 20:10:17.0546 3192 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 20:10:17.0703 3192 Modem - ok 20:10:17.0750 3192 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 20:10:17.0984 3192 Mouclass - ok 20:10:18.0046 3192 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 20:10:18.0218 3192 mouhid - ok 20:10:18.0281 3192 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 20:10:18.0515 3192 MountMgr - ok 20:10:18.0656 3192 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys 20:10:18.0828 3192 MpFilter - ok 20:10:18.0843 3192 mraid35x - ok 20:10:18.0968 3192 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 20:10:19.0203 3192 MRxDAV - ok 20:10:19.0531 3192 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 20:10:19.0796 3192 MRxSmb - ok 20:10:19.0859 3192 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 20:10:20.0031 3192 MSDTC - ok 20:10:20.0125 3192 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 20:10:20.0312 3192 Msfs - ok 20:10:20.0328 3192 MSIServer - ok 20:10:20.0359 3192 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 20:10:20.0531 3192 MSKSSRV - ok 20:10:20.0609 3192 MsMpSvc - ok 20:10:20.0625 3192 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 20:10:20.0796 3192 MSPCLOCK - ok 20:10:20.0828 3192 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 20:10:21.0015 3192 MSPQM - ok 20:10:21.0078 3192 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 20:10:21.0250 3192 mssmbios - ok 20:10:21.0296 3192 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 20:10:21.0546 3192 MSTEE - ok 20:10:21.0750 3192 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 20:10:22.0046 3192 Mup - ok 20:10:22.0156 3192 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 20:10:22.0484 3192 NABTSFEC - ok 20:10:23.0828 3192 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 20:10:24.0281 3192 napagent - ok 20:10:24.0781 3192 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 20:10:25.0171 3192 NDIS - ok 20:10:25.0437 3192 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 20:10:25.0671 3192 NdisIP - ok 20:10:26.0078 3192 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 20:10:26.0265 3192 NdisTapi - ok 20:10:26.0593 3192 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 20:10:26.0812 3192 Ndisuio - ok 20:10:27.0015 3192 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 20:10:27.0203 3192 NdisWan - ok 20:10:27.0593 3192 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 20:10:27.0750 3192 NDProxy - ok 20:10:27.0921 3192 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 20:10:28.0187 3192 NetBIOS - ok 20:10:29.0093 3192 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 20:10:29.0281 3192 NetBT - ok 20:10:29.0421 3192 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 20:10:29.0781 3192 NetDDE - ok 20:10:29.0953 3192 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 20:10:30.0125 3192 NetDDEdsdm - ok 20:10:30.0562 3192 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 20:10:30.0812 3192 Netlogon - ok 20:10:31.0890 3192 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 20:10:32.0125 3192 Netman - ok 20:10:32.0468 3192 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 20:10:32.0875 3192 NetTcpPortSharing - ok 20:10:39.0250 3192 [ 91F027C242D3FF6E5C09F92A0518297F ] NETw5x32 C:\WINDOWS\system32\DRIVERS\NETw5x32.sys 20:10:48.0390 3192 NETw5x32 - ok 20:10:52.0890 3192 [ 72062B53186E4A3F5FCBC41EBB62B905 ] NETwLx32 C:\WINDOWS\system32\DRIVERS\NETwLx32.sys 20:10:58.0281 3192 NETwLx32 - ok 20:10:58.0468 3192 [ 9F967A6DB0E6E0E01F898C26FEDD418B ] nhcDriverDevice C:\WINDOWS\system32\drivers\nhcDriver.sys 20:10:58.0546 3192 nhcDriverDevice ( UnsignedFile.Multi.Generic ) - warning 20:10:58.0546 3192 nhcDriverDevice - detected UnsignedFile.Multi.Generic (1) 20:10:58.0718 3192 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 20:10:58.0812 3192 Nla - ok 20:10:59.0015 3192 [ 7AEA4DF1CA68FD45DD4BBE1F0243CE7F ] NMSAccess C:\Program Files\CDBurnerXP\NMSAccessU.exe 20:10:59.0046 3192 NMSAccess - ok 20:10:59.0109 3192 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 20:10:59.0375 3192 Npfs - ok 20:10:59.0750 3192 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 20:11:00.0718 3192 Ntfs - ok 20:11:00.0781 3192 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 20:11:00.0984 3192 NtLmSsp - ok 20:11:01.0265 3192 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 20:11:01.0906 3192 NtmsSvc - ok 20:11:01.0953 3192 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 20:11:02.0140 3192 Null - ok 20:11:02.0187 3192 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 20:11:02.0375 3192 NwlnkFlt - ok 20:11:02.0484 3192 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 20:11:02.0687 3192 NwlnkFwd - ok 20:11:02.0750 3192 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys 20:11:02.0921 3192 Parport - ok 20:11:02.0953 3192 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 20:11:03.0140 3192 PartMgr - ok 20:11:03.0203 3192 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 20:11:03.0390 3192 ParVdm - ok 20:11:03.0484 3192 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 20:11:03.0718 3192 PCI - ok 20:11:03.0718 3192 PCIDump - ok 20:11:03.0765 3192 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 20:11:03.0953 3192 PCIIde - ok 20:11:04.0046 3192 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 20:11:04.0296 3192 Pcmcia - ok 20:11:04.0296 3192 PDCOMP - ok 20:11:04.0312 3192 PDFRAME - ok 20:11:04.0312 3192 PDRELI - ok 20:11:04.0312 3192 PDRFRAME - ok 20:11:04.0343 3192 perc2 - ok 20:11:04.0343 3192 perc2hib - ok 20:11:04.0453 3192 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 20:11:04.0500 3192 PlugPlay - ok 20:11:04.0531 3192 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 20:11:04.0656 3192 PolicyAgent - ok 20:11:04.0703 3192 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 20:11:04.0921 3192 PptpMiniport - ok 20:11:04.0953 3192 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 20:11:05.0125 3192 ProtectedStorage - ok 20:11:05.0171 3192 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 20:11:05.0421 3192 PSched - ok 20:11:05.0593 3192 [ A6A7AD767BF5141665F5C675F671B3E1 ] PSI_SVC_2 c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe 20:11:06.0140 3192 PSI_SVC_2 - ok 20:11:06.0187 3192 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 20:11:06.0406 3192 Ptilink - ok 20:11:06.0484 3192 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 20:11:06.0562 3192 PxHelp20 - ok 20:11:06.0578 3192 ql1080 - ok 20:11:06.0578 3192 Ql10wnt - ok 20:11:06.0593 3192 ql12160 - ok 20:11:06.0593 3192 ql1240 - ok 20:11:06.0609 3192 ql1280 - ok 20:11:06.0687 3192 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 20:11:06.0828 3192 RasAcd - ok 20:11:06.0968 3192 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 20:11:07.0250 3192 RasAuto - ok 20:11:07.0312 3192 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 20:11:07.0468 3192 Rasl2tp - ok 20:11:07.0609 3192 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 20:11:07.0765 3192 RasMan - ok 20:11:07.0812 3192 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 20:11:07.0953 3192 RasPppoe - ok 20:11:08.0015 3192 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 20:11:08.0203 3192 Raspti - ok 20:11:08.0375 3192 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 20:11:08.0546 3192 Rdbss - ok 20:11:08.0609 3192 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 20:11:08.0796 3192 RDPCDD - ok 20:11:08.0968 3192 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 20:11:09.0156 3192 rdpdr - ok 20:11:09.0296 3192 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 20:11:09.0593 3192 RDPWD - ok 20:11:09.0750 3192 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 20:11:10.0062 3192 RDSessMgr - ok 20:11:10.0125 3192 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 20:11:10.0265 3192 redbook - ok 20:11:10.0703 3192 [ 3A4959BA4774A55199AC4AE7FFD71924 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 20:11:10.0906 3192 RegSrvc - ok 20:11:10.0968 3192 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 20:11:11.0156 3192 RemoteAccess - ok 20:11:11.0234 3192 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 20:11:11.0437 3192 RemoteRegistry - ok 20:11:11.0531 3192 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 20:11:11.0734 3192 RpcLocator - ok 20:11:12.0015 3192 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll 20:11:12.0187 3192 RpcSs - ok 20:11:12.0343 3192 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 20:11:12.0609 3192 RSVP - ok 20:11:13.0203 3192 [ 1FD4A7B6087C98BC27344BD3973F2031 ] S24EventMonitor C:\Program Files\Intel\WiFi\bin\S24EvMon.exe 20:11:13.0734 3192 S24EventMonitor ( UnsignedFile.Multi.Generic ) - warning 20:11:13.0734 3192 S24EventMonitor - detected UnsignedFile.Multi.Generic (1) 20:11:13.0796 3192 [ 27FC71DA659305E260ACBDA15A318399 ] s24trans C:\WINDOWS\system32\DRIVERS\s24trans.sys 20:11:13.0906 3192 s24trans - ok 20:11:13.0937 3192 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 20:11:14.0062 3192 SamSs - ok 20:11:14.0171 3192 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 20:11:14.0328 3192 SCardSvr - ok 20:11:14.0500 3192 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 20:11:14.0656 3192 Schedule - ok 20:11:14.0718 3192 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 20:11:14.0843 3192 Secdrv - ok 20:11:14.0906 3192 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 20:11:15.0093 3192 seclogon - ok 20:11:15.0171 3192 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 20:11:15.0343 3192 SENS - ok 20:11:15.0406 3192 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 20:11:15.0593 3192 serenum - ok 20:11:15.0656 3192 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 20:11:15.0843 3192 Serial - ok 20:11:15.0921 3192 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 20:11:16.0093 3192 Sfloppy - ok 20:11:16.0203 3192 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 20:11:16.0250 3192 ShellHWDetection - ok 20:11:16.0265 3192 Simbad - ok 20:11:16.0312 3192 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 20:11:16.0515 3192 SLIP - ok 20:11:16.0531 3192 snpstd - ok 20:11:16.0546 3192 Sparrow - ok 20:11:16.0609 3192 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 20:11:16.0750 3192 splitter - ok 20:11:16.0828 3192 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 20:11:16.0921 3192 Spooler - ok 20:11:16.0937 3192 sptd - ok 20:11:17.0015 3192 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 20:11:17.0171 3192 sr - ok 20:11:17.0296 3192 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 20:11:17.0437 3192 srservice - ok 20:11:17.0687 3192 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 20:11:17.0906 3192 Srv - ok 20:11:18.0000 3192 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 20:11:18.0093 3192 SSDPSRV - ok 20:11:18.0140 3192 [ F92254B0BCFCD10CAAC7BCCC7CB7F467 ] StarOpen C:\WINDOWS\system32\drivers\StarOpen.sys 20:11:18.0156 3192 StarOpen ( UnsignedFile.Multi.Generic ) - warning 20:11:18.0156 3192 StarOpen - detected UnsignedFile.Multi.Generic (1) 20:11:18.0937 3192 [ 951801DFB54D86F611F0AF47825476F9 ] STHDA C:\WINDOWS\system32\drivers\sthda.sys 20:11:19.0828 3192 STHDA - ok 20:11:20.0046 3192 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 20:11:20.0375 3192 stisvc - ok 20:11:20.0421 3192 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 20:11:20.0656 3192 streamip - ok 20:11:20.0687 3192 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 20:11:20.0875 3192 swenum - ok 20:11:21.0250 3192 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 20:11:21.0812 3192 SwitchBoard ( UnsignedFile.Multi.Generic ) - warning 20:11:21.0812 3192 SwitchBoard - detected UnsignedFile.Multi.Generic (1) 20:11:21.0875 3192 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 20:11:22.0078 3192 swmidi - ok 20:11:22.0093 3192 SwPrv - ok 20:11:22.0093 3192 symc810 - ok 20:11:22.0125 3192 symc8xx - ok 20:11:22.0125 3192 sym_hi - ok 20:11:22.0140 3192 sym_u3 - ok 20:11:22.0187 3192 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 20:11:22.0375 3192 sysaudio - ok 20:11:22.0468 3192 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 20:11:22.0718 3192 SysmonLog - ok 20:11:22.0781 3192 [ 0C3B2A9C4BD2DD9A6C2E4084314DD719 ] taphss C:\WINDOWS\system32\DRIVERS\taphss.sys 20:11:22.0859 3192 taphss - ok 20:11:23.0046 3192 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 20:11:23.0187 3192 TapiSrv - ok 20:11:23.0453 3192 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 20:11:23.0703 3192 Tcpip - ok 20:11:23.0765 3192 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 20:11:23.0937 3192 TDPIPE - ok 20:11:23.0984 3192 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 20:11:24.0187 3192 TDTCP - ok 20:11:24.0250 3192 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 20:11:24.0437 3192 TermDD - ok 20:11:24.0718 3192 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 20:11:24.0890 3192 TermService - ok 20:11:25.0000 3192 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 20:11:25.0031 3192 Themes - ok 20:11:25.0109 3192 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 20:11:25.0218 3192 TlntSvr - ok 20:11:25.0234 3192 TosIde - ok 20:11:25.0296 3192 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 20:11:25.0531 3192 TrkWks - ok 20:11:26.0640 3192 [ 022EDFF8E6F42A6866CB199786A522AB ] TuneUp.UtilitiesSvc C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe 20:11:27.0640 3192 TuneUp.UtilitiesSvc - ok 20:11:27.0671 3192 [ F2107C9D85EC0DF116939CCCE06AE697 ] TuneUpUtilitiesDrv C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys 20:11:27.0734 3192 TuneUpUtilitiesDrv - ok 20:11:27.0843 3192 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 20:11:28.0078 3192 Udfs - ok 20:11:28.0078 3192 UIUSys - ok 20:11:28.0093 3192 ultra - ok 20:11:28.0359 3192 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 20:11:28.0718 3192 Update - ok 20:11:28.0921 3192 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 20:11:29.0156 3192 upnphost - ok 20:11:29.0203 3192 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 20:11:29.0593 3192 UPS - ok 20:11:29.0671 3192 [ 6B5E4D5E6E5ECD6ACD14AED59768CE5C ] USBCCID C:\WINDOWS\system32\DRIVERS\usbccid.sys 20:11:29.0828 3192 USBCCID - ok 20:11:29.0875 3192 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 20:11:30.0093 3192 usbehci - ok 20:11:30.0140 3192 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 20:11:30.0281 3192 usbhub - ok 20:11:30.0328 3192 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 20:11:30.0484 3192 USBSTOR - ok 20:11:30.0515 3192 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20:11:30.0671 3192 usbuhci - ok 20:11:30.0734 3192 [ 9DA488B563051BACFF04E718F5BF6333 ] UxTuneUp C:\WINDOWS\System32\uxtuneup.dll 20:11:30.0750 3192 UxTuneUp - ok 20:11:30.0796 3192 [ B252DD05C8B1D64239EE8A93C4BC5AD4 ] VClone C:\WINDOWS\system32\DRIVERS\VClone.sys 20:11:30.0843 3192 VClone ( UnsignedFile.Multi.Generic ) - warning 20:11:30.0843 3192 VClone - detected UnsignedFile.Multi.Generic (1) 20:11:30.0859 3192 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 20:11:31.0000 3192 VgaSave - ok 20:11:31.0000 3192 ViaIde - ok 20:11:31.0046 3192 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 20:11:31.0218 3192 VolSnap - ok 20:11:31.0421 3192 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 20:11:31.0687 3192 VSS - ok 20:11:31.0812 3192 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 20:11:32.0000 3192 W32Time - ok 20:11:32.0031 3192 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 20:11:32.0171 3192 Wanarp - ok 20:11:32.0171 3192 WDICA - ok 20:11:32.0296 3192 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 20:11:32.0437 3192 wdmaud - ok 20:11:32.0500 3192 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 20:11:32.0703 3192 WebClient - ok 20:11:33.0062 3192 [ BA6B6FB242A6BA4068C8B763063BEB63 ] winachsf C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 20:11:33.0375 3192 winachsf - ok 20:11:33.0531 3192 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 20:11:33.0687 3192 winmgmt - ok 20:11:33.0906 3192 [ 3F76E8DA2AD0AF23167D173FB213F10A ] WLANKEEPER C:\Program Files\Intel\WiFi\bin\WLKeeper.exe 20:11:34.0062 3192 WLANKEEPER ( UnsignedFile.Multi.Generic ) - warning 20:11:34.0062 3192 WLANKEEPER - detected UnsignedFile.Multi.Generic (1) 20:11:34.0109 3192 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 20:11:34.0203 3192 WmdmPmSN - ok 20:11:34.0562 3192 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 20:11:34.0921 3192 Wmi - ok 20:11:34.0953 3192 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 20:11:35.0062 3192 WmiAcpi - ok 20:11:35.0171 3192 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 20:11:35.0359 3192 WmiApSrv - ok 20:11:35.0953 3192 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 20:11:36.0921 3192 WMPNetworkSvc - ok 20:11:37.0437 3192 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 20:11:38.0140 3192 WPFFontCache_v0400 - ok 20:11:38.0156 3192 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 20:11:38.0312 3192 WSTCODEC - ok 20:11:38.0390 3192 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 20:11:38.0484 3192 WudfPf - ok 20:11:38.0546 3192 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 20:11:38.0625 3192 WudfRd - ok 20:11:38.0671 3192 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 20:11:38.0781 3192 WudfSvc - ok 20:11:39.0062 3192 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 20:11:39.0359 3192 WZCSVC - ok 20:11:39.0437 3192 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 20:11:39.0671 3192 xmlprov - ok 20:11:39.0687 3192 ================ Scan global =============================== 20:11:39.0734 3192 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 20:11:39.0906 3192 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 20:11:40.0046 3192 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 20:11:40.0125 3192 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 20:11:40.0140 3192 [Global] - ok 20:11:40.0140 3192 ================ Scan MBR ================================== 20:11:40.0171 3192 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 20:11:40.0656 3192 \Device\Harddisk0\DR0 - ok 20:11:40.0656 3192 ================ Scan VBR ================================== 20:11:40.0671 3192 [ B1B9D5673FDE126340CF44CFC0BF0B2C ] \Device\Harddisk0\DR0\Partition1 20:11:40.0671 3192 \Device\Harddisk0\DR0\Partition1 - ok 20:11:40.0671 3192 ============================================================ 20:11:40.0671 3192 Scan finished 20:11:40.0671 3192 ============================================================ 20:11:40.0796 3188 Detected object count: 8 20:11:40.0796 3188 Actual detected object count: 8 20:12:15.0203 3188 ASFIPmon ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0203 3188 ASFIPmon ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:15.0203 3188 BASFND ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0203 3188 BASFND ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:15.0203 3188 nhcDriverDevice ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0203 3188 nhcDriverDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:15.0218 3188 S24EventMonitor ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0218 3188 S24EventMonitor ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:15.0218 3188 StarOpen ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0218 3188 StarOpen ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:15.0218 3188 SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0218 3188 SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:15.0218 3188 VClone ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0218 3188 VClone ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:15.0218 3188 WLANKEEPER ( UnsignedFile.Multi.Generic ) - skipped by user 20:12:15.0218 3188 WLANKEEPER ( UnsignedFile.Multi.Generic ) - User select action: Skip 20:12:40.0359 2388 Deinitialize success |
13.06.2013, 19:21 | #6 |
/// Malware-holic | text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin Das war der Plan, aber sags niemandem weiter :-) am ende, alle passwörter ändern. Scan mit Combofix
__________________ --> text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin |
14.06.2013, 07:49 | #7 |
| Alles ist gut! Dickes Dankeschön an markusg! :-) Hallo Markusg, ich glaube es fast selbst nicht, aber alles ist gut. Die Anleitung war perfekt. :-)) Zuerst habe ich Microsoft Security Essentials deinstalliert, weil ich den Ausknopf nicht gefunden habe. Combofix hat sich daher bei mir beschwert, ich habe es aber auf eigene Gefahr gestartet (so wichtig sind mir die Daten nicht gewesen). Anschließend erhielt ich die Meldung, dass der PC im Ordner tcp/ip stack den Virus Rootkit Zero Access enthielt und ich neu starten solle. Danach waren Delta Search und Text Enhance weg. Die seltsamen Addons sind auch verschwunden. Alles ist wieder ganz normal. Leider hat mir Combofix überhaupt keine Datei erstellt, die ich hier posten kann. Ich schicke einfach mal ein ganz dickes Dankeschön über den Äther! Ich habe riesigen Respekt davor, dass du aus all dem Buchstabensalat herauslesen konntest, was zu tun ist. Daumen hoch, dass du mir so nett und uneigennützig geholfen hast. :-) Vielen Dank. LG Mona |
14.06.2013, 11:15 | #8 |
/// Malware-holic | text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin hi, combofix oder log.txt liegen direkt auf c: bzw sollten sie dies. wenn nich cf noch mal starten, das log sollte sich eig von selbst öffnen, wenn das Programm fertig istb
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
Themen zu text enhance, Weiterleitungen von Google Links und Suchmaschinen-Plugin |
7-zip, adobe, application/pdf:, bereit, browserdefendert, cdburnerxp, classpnp.sys, computer, delta chrome toolbar, downloader, error, failed, firefox, flash player, format, foxydeal, google, installation, launch, monitor, msiinstaller, object, plug-in, registry, required, rundll, safer networking, security, sehr langsam, services.exe, software, suchbar, suchmaschine, svchost.exe, virus.win32.zaccess.aml, werbung, windows internet |