|
Log-Analyse und Auswertung: GVU Trojaner hat meinen Laptop erwischt!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.08.2013, 17:07 | #16 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! was hab ich dir zu posts wie halllooo gesagt, lass das.. das nerft und wir sind nicht nur für dich hier. führe den fix von oben noch mal ausb
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
13.08.2013, 17:37 | #17 |
| GVU Trojaner hat meinen Laptop erwischt! so hab die Datei jetzt geschickt
__________________was soll ich jetzt machen? (nur zum aktualisieren) sind wir jetzt fertig oder wie? (nur zum aktualisieren) (nur zum aktualisieren) |
13.08.2013, 17:47 | #18 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! was soll das, ich habe dir gesagt du sollst die schaltfläche aktualisieren anklicken und hier nicht dauernd posten.
__________________die Taste f5 hilft auch.... oder geh ins kontrollcenter, und abbouniere das Thema, dann bekommst du eine Mail. es folgt gleich eine Anleitung zu FRST (im normalen Modus) wichtig ist, dass du in der Additions.txt die programme beschriftest, wie angefordert. Empfehlungen fürs Deinstallieren Bitte kopiere die Liste der installierten Programme aus der additions.txt hier in deinen Thread. Notiere mir bitte hinter jede Zeile, ob folgendes Kategorie zutrifft: Unbekannt, Nötig, Unnötig Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
13.08.2013, 17:53 | #19 |
| GVU Trojaner hat meinen Laptop erwischt! kannst du mir die Anweisungen mit den programen bitte nochmal sschicken, die werden bei mir nicht mehr angezeigt |
13.08.2013, 17:59 | #20 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! werden sie doch, in post 18
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
13.08.2013, 18:49 | #21 |
| GVU Trojaner hat meinen Laptop erwischt! welche additions.txt? FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-08-2013 01 Ran by Melanie (administrator) on 13-08-2013 19:25:38 Running from C:\Users\Melanie\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe (Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (Bandoo Media, inc) C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngrUI.exe (Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe () C:\Users\Melanie\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7938080 2009-07-24] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-07-24] (Realtek Semiconductor Corp.) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-08-03] (Alps Electric Co., Ltd.) HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-08-17] (Sun Microsystems, Inc.) HKCU\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [x] HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-09-07] (Google Inc.) MountPoints2: G - G:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {cd4fcd18-008d-11df-8f7f-002643ae2788} - G:\AutoRun.exe MountPoints2: {cd4fcd21-008d-11df-8f7f-002643ae2788} - G:\AutoRun.exe MountPoints2: {eaae7177-10fc-11df-9e03-002643ae2788} - G:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {eaae7183-10fc-11df-9e03-002643ae2788} - G:\setup_vmc_lite.exe /checkApplicationPresence HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [317288 2009-05-26] (Sony Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-10] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2009-09-07] (Sony Corporation) HKLM-x32\...\Run: [SHTtray.exe] - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe [99624 2009-07-27] (Sony Corporation) HKLM-x32\...\Run: [MobileConnect] - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe [2403840 2009-09-11] (Vodafone) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM-x32\...\Run: [SSDMonitor] - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-03-21] (PC Tools) HKLM-x32\...\Run: [RMAlert] - C:\Program Files (x86)\PC Tools Registry Mechanic\Alert.exe [1318872 2012-03-21] (PC Tools) HKLM-x32\...\Run: [DATAMNGR] - C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE [1890744 2012-09-02] (Bandoo Media, inc) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1644680 2013-02-08] (Ask) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) AppInit_DLLs: C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll [1528760 2012-09-02] (Bandoo Media, inc) AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll [1185208 2012-09-02] (Bandoo Media, inc) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.motio.de/Start/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01 URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=341&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=341&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {4449E5AC-B379-474B-BE40-4042C10B115A} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&rlz=1I7SVEA_deDE360 SearchScopes: HKCU - {06A34B30-752B-4910-93D7-21DA7A1864A3} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=45BCE79E-F6C3-461B-B975-37EB74B9D73D&apn_sauid=BDEA80F9-929D-4575-B1A3-71010BD2817F SearchScopes: HKCU - {191CE2A9-0EF4-4471-B1D2-81C3E7A3CD2E} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-0/4?satitle={searchTerms} SearchScopes: HKCU - {4449E5AC-B379-474B-BE40-4042C10B115A} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&rlz=1I7SVEA_deDE360 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=341&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=NIS&chn=retail&geo=DE&ver=18 SearchScopes: HKCU - {CEC0E897-BFD3-4306-98F2-0E3DEBECDF9A} URL = hxxp://services.zinio.com/search?s={selection}&rf=sonyslices BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\Datamngr\x64\BROWSE~1.DLL (Bandoo Media, inc) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll () BHO-x32: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL (Bandoo Media, inc) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll () Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/AT/Core/Player/2020PlayerAX_IKEA_Win32.cab DPF: HKLM-x32 {1C11B948-582A-433F-A98D-A8C4D5CC64F2} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_Win32.cab DPF: HKLM-x32 {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://www.navigram.com/engine/v911/Navigram.cab Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR HomePage: hxxp://www.searchnu.com/406 CHR RestoreOnStartup: "hxxp://www.searchnu.com/406", "hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=SVEA" CHR DefaultSearchURL: (Ask) - hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=45BCE79E-F6C3-461B-B975-37EB74B9D73D&apn_ptnrs=&apn_sauid=BDEA80F9-929D-4575-B1A3-71010BD2817F&apn_dtid=OSJ000&q={searchTerms} CHR DefaultSuggestURL: (Ask) - hxxp://ss.websearch.ask.com/query?qsrc=2922&li=ff&sstype=prefix&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Extension: (Google Search) - C:\Users\Melanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Norton Identity Protection) - C:\Users\Melanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Melanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0 CHR Extension: (Gmail) - C:\Users\Melanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Exts\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation) R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-03-21] (PC Tools) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-06-26] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-06-26] (Sonic Solutions) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [189984 2009-07-24] (Realtek Semiconductor) R2 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation) R2 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-07-23] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [642920 2009-07-22] (Sony Corporation) R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-07-23] (Sony Corporation) R2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-09-11] (Vodafone) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation) R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [206336 2009-07-23] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-08-13] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-08-13] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-13] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130810.001\IDSvia64.sys [513184 2013-07-31] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130810.001\IDSvia64.sys [513184 2013-07-31] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130813.002\ENG64.SYS [126040 2013-08-12] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130813.002\ENG64.SYS [126040 2013-08-12] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130813.002\EX64.SYS [2098776 2013-08-12] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130813.002\EX64.SYS [2098776 2013-08-12] (Symantec Corporation) R2 risdptsk; C:\Windows\system32\DRIVERS\risdsn64.sys [76288 2009-07-31] (REDC) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-07-24] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation) S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x] S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-13 18:40 - 2013-08-13 18:40 - 00011864 _____ C:\Users\Melanie\Desktop\AdwCleaner[R1].txt 2013-08-13 18:40 - 2013-08-13 18:40 - 00000345 _____ C:\AdwCleaner[S1].txt 2013-08-13 18:39 - 2013-08-13 18:39 - 00011864 _____ C:\AdwCleaner[R1].txt 2013-08-13 18:38 - 2013-08-13 18:39 - 00666633 _____ C:\Users\Melanie\Downloads\adwcleaner06.exe 2013-08-13 18:01 - 2013-08-13 18:01 - 00000000 ____D C:\Users\Melanie\AppData\Roaming\WinRAR 2013-08-13 18:01 - 2013-08-13 18:01 - 00000000 ____D C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-08-13 18:00 - 2013-08-13 18:00 - 00000000 ____D C:\Users\Melanie\Desktop\WinRAR 2013-08-13 17:45 - 2013-08-13 17:45 - 00000000 ____D C:\FRST 2013-08-12 22:01 - 2013-08-12 22:01 - 01084752 _____ C:\ProgramData\2433f433 2013-08-12 22:01 - 2013-08-12 22:01 - 01084742 _____ C:\Users\Melanie\AppData\Roaming\2433f433 2013-08-12 22:01 - 2013-08-12 22:01 - 01084711 _____ C:\Users\Melanie\AppData\Local\2433f433 2013-08-12 22:00 - 2013-08-12 22:00 - 00000000 ____D C:\Users\Melanie\AppData\Roaming\ArcSoft 2013-08-12 22:00 - 2013-08-12 22:00 - 00000000 ____D C:\Users\Melanie\AppData\Local\ArcSoft 2013-08-12 22:00 - 2013-08-12 22:00 - 00000000 ____D C:\ProgramData\ArcSoft 2013-08-04 19:09 - 2013-08-04 19:09 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-24 17:29 - 2013-07-24 17:29 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-07-15 03:10 - 2013-07-15 03:15 - 00000000 ____D C:\Windows\system32\MRT ==================== One Month Modified Files and Folders ======= 2013-08-13 19:24 - 2013-08-13 19:23 - 01575274 _____ (Farbar) C:\Users\Melanie\Desktop\FRST64 (1).exe 2013-08-13 19:09 - 2012-04-03 12:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-13 19:09 - 2009-12-28 12:48 - 01416138 _____ C:\Windows\WindowsUpdate.log 2013-08-13 19:01 - 2012-10-15 11:56 - 00000886 _____ C:\Windows\SysWOW64\AppLog.log 2013-08-13 19:01 - 2012-10-12 23:51 - 00000290 _____ C:\Windows\Tasks\RMSchedule.job 2013-08-13 18:54 - 2009-09-07 06:36 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-13 18:40 - 2013-08-13 18:40 - 00011864 _____ C:\Users\Melanie\Desktop\AdwCleaner[R1].txt 2013-08-13 18:40 - 2013-08-13 18:40 - 00000345 _____ C:\AdwCleaner[S1].txt 2013-08-13 18:39 - 2013-08-13 18:39 - 00011864 _____ C:\AdwCleaner[R1].txt 2013-08-13 18:39 - 2013-08-13 18:38 - 00666633 _____ C:\Users\Melanie\Downloads\adwcleaner06.exe 2013-08-13 18:05 - 2009-12-28 13:54 - 00003954 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C476D580-0E42-4B1B-9E37-1CEA4B77A5A9} 2013-08-13 18:04 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-13 18:04 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-13 18:03 - 2009-07-14 19:58 - 00659238 _____ C:\Windows\system32\perfh007.dat 2013-08-13 18:03 - 2009-07-14 19:58 - 00132776 _____ C:\Windows\system32\perfc007.dat 2013-08-13 18:03 - 2009-07-14 07:13 - 01512418 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-13 18:01 - 2013-08-13 18:01 - 00000000 ____D C:\Users\Melanie\AppData\Roaming\WinRAR 2013-08-13 18:01 - 2013-08-13 18:01 - 00000000 ____D C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-08-13 18:00 - 2013-08-13 18:00 - 00000000 ____D C:\Users\Melanie\Desktop\WinRAR 2013-08-13 17:57 - 2012-10-12 23:51 - 00000288 _____ C:\Windows\Tasks\RMAutoUpdate.job 2013-08-13 17:56 - 2012-10-12 23:51 - 00000000 ____D C:\Program Files (x86)\PC Tools Registry Mechanic 2013-08-13 17:56 - 2012-09-12 07:52 - 00033101 _____ C:\Windows\setupact.log 2013-08-13 17:56 - 2009-09-07 06:36 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-13 17:56 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-13 17:45 - 2013-08-13 17:45 - 00000000 ____D C:\FRST 2013-08-13 10:32 - 2012-10-13 22:23 - 00000000 ____D C:\Users\Melanie\AppData\Local\CrashDumps 2013-08-12 22:01 - 2013-08-12 22:01 - 01084752 _____ C:\ProgramData\2433f433 2013-08-12 22:01 - 2013-08-12 22:01 - 01084742 _____ C:\Users\Melanie\AppData\Roaming\2433f433 2013-08-12 22:01 - 2013-08-12 22:01 - 01084711 _____ C:\Users\Melanie\AppData\Local\2433f433 2013-08-12 22:01 - 2009-12-28 13:52 - 00000000 ___RD C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-12 22:01 - 2009-12-28 13:52 - 00000000 ___RD C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-08-12 22:01 - 2009-08-17 13:59 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-08-12 22:00 - 2013-08-12 22:00 - 00000000 ____D C:\Users\Melanie\AppData\Roaming\ArcSoft 2013-08-12 22:00 - 2013-08-12 22:00 - 00000000 ____D C:\Users\Melanie\AppData\Local\ArcSoft 2013-08-12 22:00 - 2013-08-12 22:00 - 00000000 ____D C:\ProgramData\ArcSoft 2013-08-06 16:32 - 2013-01-11 23:47 - 00018536 _____ C:\Windows\PFRO.log 2013-08-04 19:09 - 2013-08-04 19:09 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-04 19:09 - 2009-09-07 06:35 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-04 19:03 - 2011-08-22 11:33 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-24 17:29 - 2013-07-24 17:29 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-07-24 17:24 - 2009-12-28 15:19 - 00000000 ____D C:\ProgramData\Norton 2013-07-24 17:23 - 2012-08-30 18:14 - 00003234 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-07-24 17:23 - 2009-12-28 15:20 - 00002501 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk 2013-07-24 17:23 - 2009-12-28 15:20 - 00000000 ____D C:\Windows\system32\Drivers\NISx64 2013-07-24 17:18 - 2009-12-28 15:20 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-07-24 17:18 - 2009-12-28 15:20 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-07-24 17:15 - 2009-12-28 14:44 - 00000000 ____D C:\Users\Melanie\AppData\Local\Microsoft Help 2013-07-15 03:15 - 2013-07-15 03:10 - 00000000 ____D C:\Windows\system32\MRT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-04 21:02 ==================== End Of Log ============================ --- --- --- und: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-08-2013 01 Ran by Melanie at 2013-08-13 19:26:42 Running from C:\Users\Melanie\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) (x32) Adobe Flash Player 10 Plugin (x32 Version: 10.0.12.36) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7) Alps Pointing-device for VAIO ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.85) ArcSoft WebCam Companion 3 (x32 Version: 3.0.21.193) Ask Toolbar (x32 Version: 1.15.15.0)unnötig Ask Toolbar Updater (HKCU Version: 1.2.4.36191)unnötig ATI Catalyst Install Manager (Version: 3.0.732.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Core Implementation (x32 Version: 2009.0710.1127.18698) Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0710.1127.18698) Catalyst Control Center Graphics Full New (x32 Version: 2009.0710.1127.18698) Catalyst Control Center Graphics Light (x32 Version: 2009.0710.1127.18698) Catalyst Control Center Graphics Previews Common (x32 Version: 2009.0710.1127.18698) Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0710.1127.18698) Catalyst Control Center InstallProxy (x32 Version: 2009.0710.1127.18698) Catalyst Control Center Localization All (x32 Version: 2009.0710.1127.18698) CCC Help Chinese Standard (x32 Version: 2009.0720.2144.37243) CCC Help Chinese Traditional (x32 Version: 2009.0720.2144.37243) CCC Help Czech (x32 Version: 2009.0720.2144.37243) CCC Help Danish (x32 Version: 2009.0720.2144.37243) CCC Help Dutch (x32 Version: 2009.0720.2144.37243) CCC Help English (x32 Version: 2009.0720.2144.37243) CCC Help Finnish (x32 Version: 2009.0720.2144.37243) CCC Help French (x32 Version: 2009.0720.2144.37243) CCC Help German (x32 Version: 2009.0720.2144.37243) CCC Help Greek (x32 Version: 2009.0720.2144.37243) CCC Help Hungarian (x32 Version: 2009.0720.2144.37243) CCC Help Italian (x32 Version: 2009.0720.2144.37243) CCC Help Japanese (x32 Version: 2009.0720.2144.37243) CCC Help Korean (x32 Version: 2009.0720.2144.37243) CCC Help Norwegian (x32 Version: 2009.0720.2144.37243) CCC Help Polish (x32 Version: 2009.0720.2144.37243) CCC Help Portuguese (x32 Version: 2009.0720.2144.37243) CCC Help Russian (x32 Version: 2009.0720.2144.37243) CCC Help Spanish (x32 Version: 2009.0720.2144.37243) CCC Help Swedish (x32 Version: 2009.0720.2144.37243) CCC Help Thai (x32 Version: 2009.0720.2144.37243) CCC Help Turkish (x32 Version: 2009.0720.2144.37243) ccc-core-static (x32 Version: 2009.0710.1127.18698) ccc-utility64 (Version: 2009.0710.1127.18698) Click to Disc (x32 Version: 1.2.73.04270) Click to Disc Editor (x32 Version: 2.0.02) Click to Disc Editor (x32 Version: 2.0.03.04150) Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000) Corel WinDVD (x32 Version: 8.8.0.282) DivX-Setup (x32 Version: 2.6.1.9)unnötig eaner (Version: 3.22) Einstellungen für VAIO-Inhaltsüberwachung (x32 Version: 2.4.0.06120) Google Chrome (x32 Version: 28.0.1500.95) Google Earth (x32 Version: 7.1.1.1888) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358) Google Update Helper (x32 Version: 1.3.21.153) iLivid (x32 Version: 1.92)unnötig Intel PROSet Wireless Intel(R) PROSet/Wireless WiFi-Software (Version: 13.00.0000) Intel® Matrix Storage Manager Java 7 Update 15 (x32 Version: 7.0.150) Java Auto Updater (x32 Version: 2.1.9.0) Java(TM) 6 Update 14 (64-bit) (Version: 6.0.140) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.6612.1000) Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Suite Activation Assistant (x32 Version: 2.9) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft SQL Server Compact 3.5 SP1 English (x32 Version: 3.5.5692.0) Microsoft SQL Server Compact 3.5 SP1 x64 English (Version: 3.5.5692.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Works (x32 Version: 9.7.0621) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Music Transfer (x32 Version: 1.3.01.13160) MusicStation (x32 Version: 1.2.2.180) Norton Internet Security (x32 Version: 20.4.0.40) PC Tools Registry Mechanic 11.0 (x32 Version: 11.0) PDFCreator (x32 Version: 0.9.8) Primo (x32 Version: 1.00.0000) Realtek HDMI Audio Driver for ATI (x32 Version: 6.0.1.5897) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5886) Regi (Version: 1.00.0000) Roxio Central Audio (x32 Version: 3.8.0) Roxio Central Copy (x32 Version: 3.8.0) Roxio Central Core (x32 Version: 3.8.0) Roxio Central Data (x32 Version: 3.8.0) Roxio Central Tools (x32 Version: 3.8.0) Roxio Easy Media Creator 10 LJ (x32 Version: 10.3) Roxio Easy Media Creator Home (x32 Version: 10.3.121) Runtime (x32 Version: 1.00.0000) Searchqu Toolbar (x32 Version: 4.1.0.3114)unbekannt Setting Utility Series (x32 Version: 5.0.0.07300) Skype™ 5.10 (x32 Version: 5.10.116) Sony Home Network Library (x32 Version: 2.0.0.07280) Sony Picture Utility (x32 Version: 4.2.12.16210) Stress Pilot (x32 Version: 1.20.0000) Unterstützung für VAIO-Präsentation (x32 Version: 2.0.0.05270) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VAIO Content Metadata Intelligent Analyzing Manager (x32 Version: 3.6.1.12010) VAIO Content Metadata Intelligent Network Service Manager (x32 Version: 3.6.1.11040) VAIO Content Metadata Manager Settings (x32 Version: 3.5.0.06260) VAIO Content Metadata XML Interface Library (x32 Version: 3.5.0.06180) VAIO Content Monitoring Settings (x32 Version: 2.4.0.06120) VAIO Control Center (x32 Version: 4.0.0.06120) VAIO Data Restore Tool (x32 Version: 1.1.01.06290) VAIO DVD Menu Data Basic (x32 Version: 1.0.00.08130) VAIO Energie Verwaltung (x32 Version: 4.0.0.07160) VAIO Entertainment Platform (x32 Version: 3.5.0.07230) VAIO Event Service (x32 Version: 5.0.0.07010) VAIO Gate (x32 Version: 2.2.1.09131) VAIO Marketing Tools (x32) VAIO Media plus (x32 Version: 2.0.0.07280) VAIO Media plus Opening Movie (x32 Version: 1.2.0.09100) VAIO Movie Story (x32 Version: 1.5.00.06191) VAIO Movie Story (x32 Version: 1.5.01.05120) VAIO Movie Story 1.5 Upgrade (x32 Version: 1.5.01.05120) VAIO Movie Story Template Data (x32 Version: 1.5.01.05120) VAIO NW screensaver (x32 Version: 1.0.0.0) VAIO Original Function Settings (x32 Version: 2.0.0.07010) VAIO Original Funktion Einstellungen (x32 Version: 2.0.0.07010) VAIO Premium Partners 1.00 (x32) VAIO Quick Web Access (x32 Version: 1.1.2.4) VAIO Smart Network (x32 Version: 3.3.1.08110) VAIO Update (x32 Version: 6.1.1.10250) VAIO Wallpaper Contents (x32 Version: 2.0.0.06010) VAIO-Support für Übertragungen (x32 Version: 1.1.2.06030) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) Vodafone Mobile Connect Lite (x32 Version: 9.4.3.17550) VU5x64 (Version: 1.1.0) VU5x86 (x32 Version: 1.0.0) VU5x86 (x32 Version: 1.1.0) WIDCOMM Bluetooth Software (Version: 6.2.0.9600) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) Yahoo! Detect (x32)unnötig ==================== Restore Points ========================= 12-07-2013 23:02:38 Windows Update 13-07-2013 07:51:42 Windows Update 15-07-2013 01:00:23 Windows Update 04-08-2013 19:09:37 Geplanter Prüfpunkt 12-08-2013 20:01:23 Installed Connect Service ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0B195F04-E081-4CCB-BE99-44F9D2704035} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2012-10-26] (Sony Corporation) Task: {31F5B0E3-EC05-4E75-8B66-5751007B2CFE} - System32\Tasks\RMAutoUpdate => C:\Program Files (x86)\PC Tools Registry Mechanic\SULauncher.exe [2012-03-21] (PC Tools) Task: {335B5D78-F4CA-49CA-B99D-2C2765891797} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2012-10-26] (Sony Corporation) Task: {432C0397-6745-4093-B96A-D0D39C863519} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe [2012-10-26] (Sony Corporation) Task: {4B930A85-56EC-452F-AF73-686DC2B2A055} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-02-08] () Task: {5132F905-9E81-4EF0-BD78-B714DAF5BBE9} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-10-25] (Sony Corporation) Task: {51DCCCF5-25DA-4159-BDA3-17AC9B4D7534} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-03] (Symantec Corporation) Task: {563F6F3F-664F-42D4-BD89-0F1F333607CC} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {5B408F88-C811-45D9-9881-30928006B89E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-08-22] (Piriform Ltd) Task: {67022DB0-8045-44DC-9007-5DC7180AEC2D} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-10-25] (Sony Corporation) Task: {6792D5C9-3DB0-463B-9F47-FD8872DD8D63} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-09-07] (Google Inc.) Task: {774DD91E-C776-4EE6-A260-A4B6EFEEE09E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-09-07] (Google Inc.) Task: {A43FCBD5-3745-4D62-B7CE-774D6E82EC3E} - System32\Tasks\User_Feed_Synchronization-{0E626F3C-8A24-4FFB-84FD-07195C3D7244} => C:\Windows\system32\msfeedssync.exe [2013-05-01] (Microsoft Corporation) Task: {B6313466-9009-4F3F-9082-F0CECAA593D3} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation) Task: {B8E97695-7F49-4C4F-B690-580F14843343} - System32\Tasks\RMSchedule => C:\Program Files (x86)\PC Tools Registry Mechanic\RegMech.exe [2012-03-21] (PC Tools) Task: {D0EAC958-9819-431D-94E1-98E57B94B23F} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-03] (Symantec Corporation) Task: {D417C31C-700F-41D4-B0BF-D9C128CE6ECC} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {DCE15596-B6C5-444D-95F3-3E20401BF0CB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-16] (Adobe Systems Incorporated) Task: {E48D2F19-5911-4CD6-9CBC-1976ED316B21} - System32\Tasks\User_Feed_Synchronization-{C476D580-0E42-4B1B-9E37-1CEA4B77A5A9} => C:\Windows\system32\msfeedssync.exe [2013-05-01] (Microsoft Corporation) Task: {EB509480-569F-4FAE-8110-DFD962037A1F} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-03] (Symantec Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\RMAutoUpdate.job => C:\Program Files (x86)\PC Tools Registry Mechanic\SULauncher.exe Task: C:\Windows\Tasks\RMSchedule.job => C:\Program Files (x86)\PC Tools Registry Mechanic\RegMech.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/13/2013 05:57:31 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: msiexec.exe, Version: 5.0.7601.17514, Zeitstempel: 0x4ce79d93 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec4aa8e Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000009970a ID des fehlerhaften Prozesses: 0x1604 Startzeit der fehlerhaften Anwendung: 0xmsiexec.exe0 Pfad der fehlerhaften Anwendung: msiexec.exe1 Pfad des fehlerhaften Moduls: msiexec.exe2 Berichtskennung: msiexec.exe3 Error: (08/13/2013 05:56:48 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (08/13/2013 05:56:42 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (08/13/2013 05:47:20 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: GoogleCrashHandler64.exe, Version: 1.3.21.153, Zeitstempel: 0x51de19a7 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec4aa8e Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000009970a ID des fehlerhaften Prozesses: 0x1610 Startzeit der fehlerhaften Anwendung: 0xGoogleCrashHandler64.exe0 Pfad der fehlerhaften Anwendung: GoogleCrashHandler64.exe1 Pfad des fehlerhaften Moduls: GoogleCrashHandler64.exe2 Berichtskennung: GoogleCrashHandler64.exe3 Error: (08/13/2013 05:46:08 PM) (Source: MsiInstaller) (User: Melanie-VAIO) Description: Produkt: Vodafone Mobile Connect Lite -- Fehler 2711. The specified Feature name ('ByteMobile') not found in Feature table. Error: (08/13/2013 05:45:09 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (08/13/2013 05:45:08 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (08/13/2013 04:38:29 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (08/13/2013 04:37:56 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (08/13/2013 04:21:06 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) System errors: ============= Error: (08/13/2013 05:57:59 PM) (Source: DCOM) (User: ) Description: {000C101C-0000-0000-C000-000000000046} Error: (08/13/2013 05:57:33 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/13/2013 05:56:34 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (08/13/2013 05:56:28 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (08/13/2013 05:56:28 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (08/13/2013 05:44:02 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (08/13/2013 05:43:54 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (08/13/2013 05:43:54 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (08/13/2013 04:38:37 PM) (Source: Microsoft-Windows-DriverFrameworks-UserMode) (User: NT-AUTORITÄT) Description: Das Treiberpaket konnte nicht installiert werden. Der letzte Status war "1115". Error: (08/13/2013 04:38:31 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Microsoft Office Sessions: ========================= Error: (12/07/2010 08:29:46 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2262 seconds with 1980 seconds of active time. This session ended with a crash. Error: (05/05/2010 09:45:31 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 686 seconds with 480 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 45% Total physical RAM: 4063.03 MB Available physical RAM: 2213.78 MB Total Pagefile: 8124.24 MB Available Pagefile: 6071 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive b: (Daten Melli) (Fixed) (Total:221.35 GB) (Free:219.65 GB) NTFS (Disk=0 Partition=4) Drive c: () (Fixed) (Total:234.76 GB) (Free:156.13 GB) NTFS (Disk=0 Partition=3) Drive g: (MINI STICK) (Removable) (Total:3.78 GB) (Free:3.77 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 35EE29C6) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=235 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=221 GB) - (Type=OF Extended) ======================================================== Disk: 3 (Size: 4 GB) (Disk ID: 5F6C8792) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ |
13.08.2013, 19:32 | #22 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! edit, editiere gleich mehr
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
13.08.2013, 19:39 | #23 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! Hi, es sind 3 Arbeitsschritte auszuführen, und 2 Logs zu erstellen. Poste die Logs gleichzeitig. Falls es Probleme bei den nun folgenen Deinstalationen gibt, nutze Revo: Revo Uninstaller - Download - Filepony Wenn du Software instalierst, mache das immer beim hersteller, nicht auf seiten wie Chip. - Google die software, mit dem Stichwort, adware, prüfe ob es da bereits bekannte einträge gibt. - lies die Lizenzverträge und AGB's - instaliere immer benutzerdefiniert um adware, die dein Surfverhalten ausspähen kann, abwählen zu können, von dem Misst hast du nämlich eine Menge. 1. deinstaliere: Adobe Flash Player alle Adobe - Adobe Flash Player installieren neueste version laden, instalieren. adobe reader: Adobe - Adobe Reader herunterladen - Alle Versionen haken bei mcafee security scan raus nehmen bitte auch mal den adobe reader wie folgt konfigurieren: adobe reader öffnen, bearbeiten, voreinstellungen. allgemein: nur zertifizierte zusatz module verwenden, anhaken. Sicherheit (erweitert) Erweiterte Sicherheit anhaken und alle Dateien auswählen. internet: hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc. es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht. bei javascript den haken bei java script verwenden raus nehmen bei updater, automatisch instalieren wählen. übernehmen /ok deinstaliere: Ask : beide DivX Google Toolbar : verzichte bitte auf toolbars, sie sind nur ein zusätzliches Risiko, machen den Browser langsamer Beide Einträge deinstalieren. iLivid Java 7 Update 15 downloade Java jre: Java-Downloads für alle Betriebssysteme klicke: Download der Java-Software für Windows Offline laden, und instalieren Norton : scheint nicht aktuell zu sein, instaliere bitte die neueste von der Homepage: Norton Antivirus und Internet Security Software | Norton.de Upgrades sind kostenlos, teile mir mit, ob es geklappt hatt PC Tools Registry Mechanic : weg damit, unerfahrene nutzer haben an der REgistry nichts zu suchen, und registry Tuning ist quatsch, soetwas gibt es nicht... es bringt 0 Nutzen. Searchqu Yahoo Neustarten. 2. Scan mit Combofix
3. Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
13.08.2013, 19:44 | #24 |
| GVU Trojaner hat meinen Laptop erwischt! okay das ganze mach ich morgen, haben sie morgen auch zeit? |
13.08.2013, 19:45 | #25 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! du kannst es morgen machen, aber bin den halben Tag nicht da, Antwort bekommst du dann donnerstag oder evtl. morgen abend
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
13.08.2013, 19:46 | #26 |
| GVU Trojaner hat meinen Laptop erwischt! eine frage noch: das was du mir da aufgelistet hast sind jetzt sicherheitsmaßnahemen oder |
13.08.2013, 20:10 | #27 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! Programme die zu updaten sind, und adware, und weitere scans wie du siehst
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
14.08.2013, 15:44 | #28 |
| GVU Trojaner hat meinen Laptop erwischt! das erste programm habe ich mir runtergeladen alles hat geklappt (es wurde die fehlermeldung das ich noch ander scan programme aktiv habe angezeigt!) bei dem kaspersky programm habe ich auf den link geklickt welcher mich auf filepony gebracht habe dor habe ich download angeklickt dann stand unten "Download:TDSSKiller" Wenn ich darauf klicke kam eine Lehre Seite!? Was jetzt? hab nochne frage: die Datei die ich ihnen geschickt habe (die winrardatei) das war doch der Virus oder?, wenn ja sollte ich den nicht mal entfernen? (oder haben das die ganzen Programme gemacht? Combofix: Code:
ATTFilter ComboFix 13-08-13.03 - Melanie 14.08.2013 8:43.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4063.2100 [GMT 2:00] ausgeführt von:: c:\users\Melanie\Desktop\ComboFix.exe AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\2433f433 c:\users\Melanie\AppData\Roaming\.# c:\users\Melanie\AppData\Roaming\2433f433 c:\users\Melanie\AppData\Roaming\Skype c:\users\Melanie\AppData\Roaming\Skype\shared.lck c:\users\Melanie\AppData\Roaming\Skype\shared.xml . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-14 bis 2013-08-14 )))))))))))))))))))))))))))))) . . 2013-08-14 06:50 . 2013-08-14 06:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-14 06:31 . 2013-08-14 06:31 972712 ----a-w- c:\windows\system32\deployJava1.dll 2013-08-14 06:31 . 2013-08-14 06:31 312232 ----a-w- c:\windows\system32\javaws.exe 2013-08-14 06:31 . 2013-08-14 06:31 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-08-14 06:31 . 2013-08-14 06:31 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-08-14 06:31 . 2013-08-14 06:31 189352 ----a-w- c:\windows\system32\javaw.exe 2013-08-14 06:31 . 2013-08-14 06:31 188840 ----a-w- c:\windows\system32\java.exe 2013-08-14 06:31 . 2013-08-14 06:31 -------- d-----w- c:\program files\Java 2013-08-14 06:05 . 2013-08-14 06:05 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-08-14 06:05 . 2013-08-14 06:05 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-08-13 15:45 . 2013-08-13 15:45 -------- d-----w- C:\FRST 2013-08-12 20:01 . 2013-08-12 20:01 -------- d-sh--we c:\windows\SysWow64\config\systemprofile\Lokale Einstellungen 2013-08-12 20:01 . 2013-08-12 20:01 -------- d-sh--we c:\windows\SysWow64\config\systemprofile\Anwendungsdaten 2013-08-12 20:01 . 2013-08-12 20:01 -------- d-----w- c:\users\Melanie\AppData\Local\Programs 2013-08-12 20:00 . 2013-08-12 20:00 -------- d-----w- c:\users\Melanie\AppData\Local\ArcSoft 2013-08-12 20:00 . 2013-08-12 20:00 -------- d-----w- c:\programdata\ArcSoft 2013-08-12 20:00 . 2013-08-12 20:00 -------- d-----w- c:\users\Melanie\AppData\Roaming\ArcSoft 2013-07-24 15:17 . 2013-07-24 15:21 -------- d-----w- c:\windows\system32\drivers\NISx64\1404000.028 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-24 15:18 . 2009-12-28 13:20 177312 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2013-07-13 05:07 . 2013-07-13 05:07 4188160 ----a-w- c:\program files (x86)\GUTE77A.tmp 2013-06-23 22:57 . 2009-12-29 11:58 78277128 ----a-w- c:\windows\system32\MRT.exe 2013-06-11 23:43 . 2013-07-13 14:35 1767936 ----a-w- c:\windows\SysWow64\wininet.dll 2013-06-11 23:43 . 2013-07-13 14:35 2877440 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-06-11 23:42 . 2013-07-13 14:35 61440 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-06-11 23:42 . 2013-07-13 14:35 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-06-11 23:26 . 2013-07-13 14:35 51712 ----a-w- c:\windows\system32\ie4uinit.exe 2013-06-11 23:26 . 2013-07-13 14:35 2241024 ----a-w- c:\windows\system32\wininet.dll 2013-06-11 23:26 . 2013-07-13 14:35 1365504 ----a-w- c:\windows\system32\urlmon.dll 2013-06-11 23:25 . 2013-07-13 14:35 19238912 ----a-w- c:\windows\system32\mshtml.dll 2013-06-11 23:25 . 2013-07-13 14:35 603136 ----a-w- c:\windows\system32\msfeeds.dll 2013-06-11 23:25 . 2013-07-13 14:35 855552 ----a-w- c:\windows\system32\jscript.dll 2013-06-11 23:25 . 2013-07-13 14:35 3958784 ----a-w- c:\windows\system32\jscript9.dll 2013-06-11 23:25 . 2013-07-13 14:35 53248 ----a-w- c:\windows\system32\jsproxy.dll 2013-06-11 23:25 . 2013-07-13 14:35 526336 ----a-w- c:\windows\system32\ieui.dll 2013-06-11 23:25 . 2013-07-13 14:35 67072 ----a-w- c:\windows\system32\iesetup.dll 2013-06-11 23:25 . 2013-07-13 14:35 39936 ----a-w- c:\windows\system32\iernonce.dll 2013-06-11 23:25 . 2013-07-13 14:35 136704 ----a-w- c:\windows\system32\iesysprep.dll 2013-06-11 23:25 . 2013-07-13 14:35 2648576 ----a-w- c:\windows\system32\iertutil.dll 2013-06-11 23:25 . 2013-07-13 14:35 15404032 ----a-w- c:\windows\system32\ieframe.dll 2013-06-11 22:51 . 2013-07-13 14:35 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-06-11 22:50 . 2013-07-13 14:35 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-06-07 03:22 . 2013-07-13 14:35 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-06-07 02:37 . 2013-07-13 14:35 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-06-05 03:34 . 2013-07-12 21:48 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 06:00 . 2013-07-12 21:49 624128 ----a-w- c:\windows\system32\qedit.dll 2013-06-04 04:53 . 2013-07-12 21:49 509440 ----a-w- c:\windows\SysWow64\qedit.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2009-05-26 317288] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-10 98304] "MarketingTools"="c:\program files (x86)\Sony\Marketing Tools\MarketingTools.exe" [2009-09-07 26624] "SHTtray.exe"="c:\program files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe" [2009-07-27 99624] "MobileConnect"="c:\program files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2009-09-11 2403840] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 1079584] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2009-07-01 09:49 98304 ----a-w- c:\windows\System32\VESWinlogon.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x] R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbfake.sys [x] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys;c:\windows\SYSNATIVE\drivers\IntcHdmi.sys [x] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x] R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x] R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\SYMEFA64.SYS [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [x] S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\ccSetx64.sys [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130813.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130813.001\IDSvia64.sys [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NISx64\1404000.028\SYMNETS.SYS [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe;c:\program files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [x] S2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x] S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x] S2 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x] S2 SOHDBSvr;VAIO Media plus Database Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [x] S2 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [x] S2 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x] S2 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [x] S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x] S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe;c:\program files\Sony\VAIO Power Management\SPMService.exe [x] S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x] S2 VMCService;Vodafone Mobile Connect Service;c:\program files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe;c:\program files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [x] S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 NETw5s64;Intel(R) Wireless WiFi Link Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x] S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x] S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\VUAgent.exe;c:\program files\Sony\VAIO Update\VUAgent.exe [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-08-04 17:03 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-08-14 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-14 06:05] . 2013-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-09-07 04:35] . 2013-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-09-07 04:35] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-24 7938080] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-24 1833504] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.2.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-10 - (no file) SafeBoot-mcmscsvc SafeBoot-MCODS HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-10 - (no file) HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\20.4.0.40\diMaster.dll\" /prefetch:1" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-14 08:53:42 ComboFix-quarantined-files.txt 2013-08-14 06:53 . Vor Suchlauf: 12 Verzeichnis(se), 166.995.697.664 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 166.651.944.960 Bytes frei . - - End Of File - - C739F2DC8FF2AF63C05AAA381348DE4F A36C5E4F47E84449FF07ED3517B43A31 Code:
ATTFilter 16:30:12.0755 3280 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 16:30:14.0034 3280 ============================================================ 16:30:14.0034 3280 Current date / time: 2013/08/14 16:30:14.0034 16:30:14.0034 3280 SystemInfo: 16:30:14.0034 3280 16:30:14.0034 3280 OS Version: 6.1.7601 ServicePack: 1.0 16:30:14.0034 3280 Product type: Workstation 16:30:14.0034 3280 ComputerName: MELANIE-VAIO 16:30:14.0034 3280 UserName: Melanie 16:30:14.0034 3280 Windows directory: C:\Windows 16:30:14.0034 3280 System windows directory: C:\Windows 16:30:14.0034 3280 Running under WOW64 16:30:14.0034 3280 Processor architecture: Intel x64 16:30:14.0034 3280 Number of processors: 2 16:30:14.0034 3280 Page size: 0x1000 16:30:14.0034 3280 Boot type: Normal boot 16:30:14.0034 3280 ============================================================ 16:30:14.0627 3280 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 16:30:14.0642 3280 Drive \Device\Harddisk3\DR3 - Size: 0xF2700000 (3.79 Gb), SectorSize: 0x200, Cylinders: 0x1EE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 16:30:14.0642 3280 ============================================================ 16:30:14.0642 3280 \Device\Harddisk0\DR0: 16:30:14.0642 3280 MBR partitions: 16:30:14.0642 3280 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x131B000, BlocksNum 0x32000 16:30:14.0642 3280 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x134D000, BlocksNum 0x1D585830 16:30:14.0674 3280 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1E8D3800, BlocksNum 0x1BAB2000 16:30:14.0674 3280 \Device\Harddisk3\DR3: 16:30:14.0674 3280 MBR partitions: 16:30:14.0674 3280 \Device\Harddisk3\DR3\Partition1: MBR, Type 0xB, StartLBA 0x2000, BlocksNum 0x791800 16:30:14.0674 3280 ============================================================ 16:30:14.0720 3280 C: <-> \Device\Harddisk0\DR0\Partition2 16:30:14.0767 3280 B: <-> \Device\Harddisk0\DR0\Partition3 16:30:14.0767 3280 ============================================================ 16:30:14.0767 3280 Initialize success 16:30:14.0767 3280 ============================================================ 16:30:31.0943 1152 ============================================================ 16:30:31.0943 1152 Scan started 16:30:31.0943 1152 Mode: Manual; SigCheck; TDLFS; 16:30:31.0943 1152 ============================================================ 16:30:32.0270 1152 ================ Scan system memory ======================== 16:30:32.0270 1152 System memory - ok 16:30:32.0270 1152 ================ Scan services ============================= 16:30:32.0504 1152 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 16:30:32.0645 1152 1394ohci - ok 16:30:32.0770 1152 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 16:30:32.0848 1152 ACDaemon - ok 16:30:32.0894 1152 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 16:30:32.0957 1152 ACPI - ok 16:30:33.0004 1152 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 16:30:33.0082 1152 AcpiPmi - ok 16:30:33.0175 1152 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 16:30:33.0206 1152 AdobeARMservice - ok 16:30:33.0581 1152 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 16:30:33.0612 1152 AdobeFlashPlayerUpdateSvc - ok 16:30:33.0799 1152 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 16:30:33.0815 1152 adp94xx - ok 16:30:33.0862 1152 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 16:30:33.0877 1152 adpahci - ok 16:30:33.0924 1152 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 16:30:33.0940 1152 adpu320 - ok 16:30:33.0971 1152 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 16:30:34.0033 1152 AeLookupSvc - ok 16:30:34.0096 1152 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 16:30:34.0158 1152 AFD - ok 16:30:34.0189 1152 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 16:30:34.0220 1152 agp440 - ok 16:30:34.0236 1152 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 16:30:34.0314 1152 ALG - ok 16:30:34.0345 1152 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 16:30:34.0361 1152 aliide - ok 16:30:34.0392 1152 [ 322A2C5D390109A4E50679AB58DEA870 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 16:30:34.0470 1152 AMD External Events Utility - ok 16:30:34.0501 1152 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 16:30:34.0517 1152 amdide - ok 16:30:34.0548 1152 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 16:30:34.0595 1152 AmdK8 - ok 16:30:34.0626 1152 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 16:30:34.0673 1152 AmdPPM - ok 16:30:34.0704 1152 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 16:30:34.0720 1152 amdsata - ok 16:30:34.0766 1152 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 16:30:34.0798 1152 amdsbs - ok 16:30:34.0813 1152 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 16:30:34.0829 1152 amdxata - ok 16:30:34.0876 1152 [ 56BD886820C4AEDF493CFCDF1CCFB004 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys 16:30:34.0907 1152 ApfiltrService - ok 16:30:34.0969 1152 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 16:30:35.0078 1152 AppID - ok 16:30:35.0110 1152 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 16:30:35.0203 1152 AppIDSvc - ok 16:30:35.0234 1152 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll 16:30:35.0281 1152 Appinfo - ok 16:30:35.0359 1152 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 16:30:35.0375 1152 arc - ok 16:30:35.0406 1152 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 16:30:35.0437 1152 arcsas - ok 16:30:35.0500 1152 [ C130BC4A51B1382B2BE8E44579EC4C0A ] ArcSoftKsUFilter C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys 16:30:35.0531 1152 ArcSoftKsUFilter - ok 16:30:35.0546 1152 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 16:30:35.0609 1152 AsyncMac - ok 16:30:35.0656 1152 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 16:30:35.0671 1152 atapi - ok 16:30:35.0749 1152 [ 5D4529AC4156E16BEDB01441AE0CF984 ] athr C:\Windows\system32\DRIVERS\athrx.sys 16:30:35.0827 1152 athr - ok 16:30:35.0999 1152 [ DE0EDE41BC530F1759C6FFFCB8C7A0CF ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys 16:30:36.0217 1152 atikmdag - ok 16:30:36.0295 1152 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 16:30:36.0358 1152 AudioEndpointBuilder - ok 16:30:36.0373 1152 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 16:30:36.0420 1152 AudioSrv - ok 16:30:36.0514 1152 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 16:30:36.0592 1152 AxInstSV - ok 16:30:36.0638 1152 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 16:30:36.0701 1152 b06bdrv - ok 16:30:36.0748 1152 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 16:30:36.0794 1152 b57nd60a - ok 16:30:36.0841 1152 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 16:30:36.0872 1152 BDESVC - ok 16:30:36.0888 1152 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 16:30:36.0950 1152 Beep - ok 16:30:37.0028 1152 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 16:30:37.0122 1152 BFE - ok 16:30:37.0372 1152 [ 6E10DB69DB1AA96207F4B14B18FF12F8 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys 16:30:37.0403 1152 BHDrvx64 - ok 16:30:37.0450 1152 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll 16:30:37.0512 1152 BITS - ok 16:30:37.0559 1152 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 16:30:37.0621 1152 blbdrive - ok 16:30:37.0668 1152 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 16:30:37.0730 1152 bowser - ok 16:30:37.0762 1152 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 16:30:37.0808 1152 BrFiltLo - ok 16:30:37.0824 1152 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 16:30:37.0840 1152 BrFiltUp - ok 16:30:37.0886 1152 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 16:30:37.0980 1152 BridgeMP - ok 16:30:37.0996 1152 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 16:30:38.0042 1152 Browser - ok 16:30:38.0058 1152 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 16:30:38.0120 1152 Brserid - ok 16:30:38.0136 1152 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 16:30:38.0167 1152 BrSerWdm - ok 16:30:38.0198 1152 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 16:30:38.0276 1152 BrUsbMdm - ok 16:30:38.0292 1152 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 16:30:38.0308 1152 BrUsbSer - ok 16:30:38.0354 1152 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 16:30:38.0432 1152 BthEnum - ok 16:30:38.0464 1152 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 16:30:38.0479 1152 BTHMODEM - ok 16:30:38.0510 1152 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 16:30:38.0557 1152 BthPan - ok 16:30:38.0620 1152 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 16:30:38.0698 1152 BTHPORT - ok 16:30:38.0744 1152 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 16:30:38.0807 1152 bthserv - ok 16:30:38.0838 1152 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 16:30:38.0900 1152 BTHUSB - ok 16:30:38.0947 1152 [ 6BCFDC2B5B7F66D484486D4BD4B39A6B ] btwaudio C:\Windows\system32\drivers\btwaudio.sys 16:30:38.0963 1152 btwaudio - ok 16:30:39.0010 1152 [ 82DC8B7C626E526681C1BEBED2BC3FF9 ] btwavdt C:\Windows\system32\drivers\btwavdt.sys 16:30:39.0041 1152 btwavdt - ok 16:30:39.0150 1152 [ D65AA164ACD0F6706DBCFBBCC9731584 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe 16:30:39.0197 1152 btwdins - ok 16:30:39.0228 1152 [ 6149301DC3F81D6F9667A3FBAC410975 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys 16:30:39.0228 1152 btwl2cap - ok 16:30:39.0259 1152 [ 28E105AD3B79F440BF94780F507BF66A ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys 16:30:39.0275 1152 btwrchid - ok 16:30:39.0322 1152 catchme - ok 16:30:39.0400 1152 [ 56685951208AC81CF923B9B08BEDF3B7 ] ccSet_NIS C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys 16:30:39.0415 1152 ccSet_NIS - ok 16:30:39.0446 1152 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 16:30:39.0493 1152 cdfs - ok 16:30:39.0540 1152 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 16:30:39.0602 1152 cdrom - ok 16:30:39.0649 1152 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 16:30:39.0696 1152 CertPropSvc - ok 16:30:39.0743 1152 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 16:30:39.0805 1152 circlass - ok 16:30:39.0852 1152 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 16:30:39.0868 1152 CLFS - ok 16:30:39.0946 1152 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 16:30:39.0977 1152 clr_optimization_v2.0.50727_32 - ok 16:30:40.0024 1152 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 16:30:40.0039 1152 clr_optimization_v2.0.50727_64 - ok 16:30:40.0133 1152 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 16:30:40.0164 1152 clr_optimization_v4.0.30319_32 - ok 16:30:40.0226 1152 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 16:30:40.0258 1152 clr_optimization_v4.0.30319_64 - ok 16:30:40.0289 1152 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 16:30:40.0320 1152 CmBatt - ok 16:30:40.0336 1152 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 16:30:40.0351 1152 cmdide - ok 16:30:40.0398 1152 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 16:30:40.0445 1152 CNG - ok 16:30:40.0492 1152 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 16:30:40.0523 1152 Compbatt - ok 16:30:40.0570 1152 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 16:30:40.0632 1152 CompositeBus - ok 16:30:40.0663 1152 COMSysApp - ok 16:30:40.0694 1152 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 16:30:40.0726 1152 crcdisk - ok 16:30:40.0772 1152 [ 6B400F211BEE880A37A1ED0368776BF4 ] CryptSvc C:\Windows\system32\cryptsvc.dll 16:30:40.0804 1152 CryptSvc - ok 16:30:40.0835 1152 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 16:30:40.0897 1152 DcomLaunch - ok 16:30:40.0944 1152 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 16:30:41.0006 1152 defragsvc - ok 16:30:41.0069 1152 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 16:30:41.0147 1152 DfsC - ok 16:30:41.0209 1152 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 16:30:41.0240 1152 Dhcp - ok 16:30:41.0272 1152 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 16:30:41.0334 1152 discache - ok 16:30:41.0365 1152 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 16:30:41.0381 1152 Disk - ok 16:30:41.0412 1152 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 16:30:41.0474 1152 Dnscache - ok 16:30:41.0506 1152 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 16:30:41.0568 1152 dot3svc - ok 16:30:41.0599 1152 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 16:30:41.0693 1152 DPS - ok 16:30:41.0724 1152 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 16:30:41.0740 1152 drmkaud - ok 16:30:41.0786 1152 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 16:30:41.0833 1152 DXGKrnl - ok 16:30:41.0864 1152 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 16:30:41.0927 1152 EapHost - ok 16:30:42.0020 1152 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 16:30:42.0130 1152 ebdrv - ok 16:30:42.0223 1152 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 16:30:42.0254 1152 eeCtrl - ok 16:30:42.0286 1152 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 16:30:42.0332 1152 EFS - ok 16:30:42.0410 1152 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 16:30:42.0473 1152 ehRecvr - ok 16:30:42.0504 1152 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 16:30:42.0566 1152 ehSched - ok 16:30:42.0613 1152 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 16:30:42.0660 1152 elxstor - ok 16:30:42.0707 1152 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 16:30:42.0738 1152 EraserUtilRebootDrv - ok 16:30:42.0754 1152 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 16:30:42.0785 1152 ErrDev - ok 16:30:42.0832 1152 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 16:30:42.0910 1152 EventSystem - ok 16:30:43.0034 1152 [ 51643EE2712D9212E1E53CA7E8D8EB4A ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 16:30:43.0081 1152 EvtEng - ok 16:30:43.0081 1152 ewusbnet - ok 16:30:43.0112 1152 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 16:30:43.0175 1152 exfat - ok 16:30:43.0190 1152 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 16:30:43.0253 1152 fastfat - ok 16:30:43.0315 1152 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 16:30:43.0362 1152 Fax - ok 16:30:43.0393 1152 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 16:30:43.0409 1152 fdc - ok 16:30:43.0440 1152 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 16:30:43.0502 1152 fdPHost - ok 16:30:43.0518 1152 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 16:30:43.0565 1152 FDResPub - ok 16:30:43.0612 1152 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 16:30:43.0627 1152 FileInfo - ok 16:30:43.0643 1152 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 16:30:43.0690 1152 Filetrace - ok 16:30:43.0721 1152 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 16:30:43.0752 1152 flpydisk - ok 16:30:43.0799 1152 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 16:30:43.0846 1152 FltMgr - ok 16:30:43.0892 1152 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll 16:30:43.0924 1152 FontCache - ok 16:30:43.0970 1152 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 16:30:44.0002 1152 FontCache3.0.0.0 - ok 16:30:44.0033 1152 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 16:30:44.0048 1152 FsDepends - ok 16:30:44.0080 1152 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 16:30:44.0095 1152 Fs_Rec - ok 16:30:44.0142 1152 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 16:30:44.0158 1152 fvevol - ok 16:30:44.0189 1152 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 16:30:44.0204 1152 gagp30kx - ok 16:30:44.0251 1152 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 16:30:44.0314 1152 gpsvc - ok 16:30:44.0392 1152 [ 626A24ED1228580B9518C01930936DF9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 16:30:44.0423 1152 gupdate - ok 16:30:44.0454 1152 [ 626A24ED1228580B9518C01930936DF9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 16:30:44.0470 1152 gupdatem - ok 16:30:44.0470 1152 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 16:30:44.0516 1152 hcw85cir - ok 16:30:44.0548 1152 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 16:30:44.0594 1152 HdAudAddService - ok 16:30:44.0641 1152 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 16:30:44.0688 1152 HDAudBus - ok 16:30:44.0719 1152 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 16:30:44.0750 1152 HidBatt - ok 16:30:44.0782 1152 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 16:30:44.0828 1152 HidBth - ok 16:30:44.0844 1152 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 16:30:44.0906 1152 HidIr - ok 16:30:44.0938 1152 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 16:30:45.0000 1152 hidserv - ok 16:30:45.0047 1152 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 16:30:45.0078 1152 HidUsb - ok 16:30:45.0109 1152 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 16:30:45.0172 1152 hkmsvc - ok 16:30:45.0203 1152 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 16:30:45.0234 1152 HomeGroupListener - ok 16:30:45.0265 1152 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 16:30:45.0312 1152 HomeGroupProvider - ok 16:30:45.0328 1152 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 16:30:45.0343 1152 HpSAMD - ok 16:30:45.0390 1152 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 16:30:45.0468 1152 HTTP - ok 16:30:45.0499 1152 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 16:30:45.0515 1152 hwpolicy - ok 16:30:45.0546 1152 hwusbfake - ok 16:30:45.0577 1152 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 16:30:45.0608 1152 i8042prt - ok 16:30:45.0702 1152 [ 7548066DF68A8A1A56B043359F915F37 ] IAANTMON C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe 16:30:45.0733 1152 IAANTMON - ok 16:30:45.0780 1152 [ 1D004CB1DA6323B1F55CAEF7F94B61D9 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 16:30:45.0796 1152 iaStor - ok 16:30:45.0827 1152 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 16:30:45.0858 1152 iaStorV - ok 16:30:45.0905 1152 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 16:30:45.0952 1152 idsvc - ok 16:30:46.0076 1152 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130813.001\IDSvia64.sys 16:30:46.0108 1152 IDSVia64 - ok 16:30:46.0295 1152 [ DFEAF0A1D98D397035012C8E28D1520F ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 16:30:46.0529 1152 igfx ( UnsignedFile.Multi.Generic ) - warning 16:30:46.0529 1152 igfx - detected UnsignedFile.Multi.Generic (1) 16:30:46.0576 1152 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 16:30:46.0607 1152 iirsp - ok 16:30:46.0638 1152 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 16:30:46.0716 1152 IKEEXT - ok 16:30:46.0810 1152 [ B16FC828CE7A76A8F1CE682E6EAD2627 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 16:30:46.0856 1152 IntcAzAudAddService - ok 16:30:46.0934 1152 [ 88A20FA54C73DED4E8DAC764E9130AE9 ] IntcHdmiAddService C:\Windows\system32\drivers\IntcHdmi.sys 16:30:46.0966 1152 IntcHdmiAddService ( UnsignedFile.Multi.Generic ) - warning 16:30:46.0966 1152 IntcHdmiAddService - detected UnsignedFile.Multi.Generic (1) 16:30:46.0997 1152 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 16:30:47.0028 1152 intelide - ok 16:30:47.0059 1152 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 16:30:47.0106 1152 intelppm - ok 16:30:47.0137 1152 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 16:30:47.0200 1152 IPBusEnum - ok 16:30:47.0231 1152 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 16:30:47.0293 1152 IpFilterDriver - ok 16:30:47.0340 1152 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 16:30:47.0356 1152 iphlpsvc - ok 16:30:47.0387 1152 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 16:30:47.0402 1152 IPMIDRV - ok 16:30:47.0434 1152 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 16:30:47.0480 1152 IPNAT - ok 16:30:47.0512 1152 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 16:30:47.0543 1152 IRENUM - ok 16:30:47.0574 1152 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 16:30:47.0590 1152 isapnp - ok 16:30:47.0605 1152 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 16:30:47.0621 1152 iScsiPrt - ok 16:30:47.0683 1152 [ F415A88162D23977B5EDAE4F0410E903 ] IviRegMgr C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe 16:30:47.0714 1152 IviRegMgr - ok 16:30:47.0730 1152 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 16:30:47.0746 1152 kbdclass - ok 16:30:47.0777 1152 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 16:30:47.0792 1152 kbdhid - ok 16:30:47.0808 1152 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 16:30:47.0824 1152 KeyIso - ok 16:30:47.0855 1152 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 16:30:47.0870 1152 KSecDD - ok 16:30:47.0902 1152 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 16:30:47.0917 1152 KSecPkg - ok 16:30:47.0948 1152 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 16:30:48.0011 1152 ksthunk - ok 16:30:48.0042 1152 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 16:30:48.0120 1152 KtmRm - ok 16:30:48.0167 1152 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 16:30:48.0245 1152 LanmanServer - ok 16:30:48.0276 1152 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 16:30:48.0338 1152 LanmanWorkstation - ok 16:30:48.0370 1152 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 16:30:48.0432 1152 lltdio - ok 16:30:48.0479 1152 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 16:30:48.0588 1152 lltdsvc - ok 16:30:48.0604 1152 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 16:30:48.0650 1152 lmhosts - ok 16:30:48.0682 1152 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 16:30:48.0713 1152 LSI_FC - ok 16:30:48.0728 1152 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 16:30:48.0744 1152 LSI_SAS - ok 16:30:48.0760 1152 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 16:30:48.0775 1152 LSI_SAS2 - ok 16:30:48.0806 1152 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 16:30:48.0822 1152 LSI_SCSI - ok 16:30:48.0869 1152 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 16:30:48.0931 1152 luafv - ok 16:30:48.0962 1152 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 16:30:48.0994 1152 Mcx2Svc - ok 16:30:49.0025 1152 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 16:30:49.0040 1152 megasas - ok 16:30:49.0056 1152 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 16:30:49.0087 1152 MegaSR - ok 16:30:49.0103 1152 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 16:30:49.0196 1152 MMCSS - ok 16:30:49.0212 1152 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 16:30:49.0274 1152 Modem - ok 16:30:49.0306 1152 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 16:30:49.0352 1152 monitor - ok 16:30:49.0399 1152 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys 16:30:49.0415 1152 mouclass - ok 16:30:49.0446 1152 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 16:30:49.0477 1152 mouhid - ok 16:30:49.0508 1152 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 16:30:49.0524 1152 mountmgr - ok 16:30:49.0555 1152 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 16:30:49.0571 1152 mpio - ok 16:30:49.0586 1152 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 16:30:49.0633 1152 mpsdrv - ok 16:30:49.0680 1152 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 16:30:49.0727 1152 MpsSvc - ok 16:30:49.0758 1152 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 16:30:49.0805 1152 MRxDAV - ok 16:30:49.0836 1152 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 16:30:49.0867 1152 mrxsmb - ok 16:30:49.0898 1152 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 16:30:49.0930 1152 mrxsmb10 - ok 16:30:49.0961 1152 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 16:30:49.0992 1152 mrxsmb20 - ok 16:30:50.0008 1152 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 16:30:50.0039 1152 msahci - ok 16:30:50.0054 1152 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 16:30:50.0086 1152 msdsm - ok 16:30:50.0101 1152 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 16:30:50.0148 1152 MSDTC - ok 16:30:50.0179 1152 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 16:30:50.0226 1152 Msfs - ok 16:30:50.0242 1152 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 16:30:50.0288 1152 mshidkmdf - ok 16:30:50.0320 1152 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 16:30:50.0335 1152 msisadrv - ok 16:30:50.0366 1152 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 16:30:50.0413 1152 MSiSCSI - ok 16:30:50.0429 1152 msiserver - ok 16:30:50.0460 1152 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 16:30:50.0522 1152 MSKSSRV - ok 16:30:50.0538 1152 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 16:30:50.0600 1152 MSPCLOCK - ok 16:30:50.0616 1152 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 16:30:50.0663 1152 MSPQM - ok 16:30:50.0710 1152 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 16:30:50.0725 1152 MsRPC - ok 16:30:50.0772 1152 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 16:30:50.0772 1152 mssmbios - ok 16:30:50.0803 1152 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 16:30:50.0850 1152 MSTEE - ok 16:30:50.0881 1152 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 16:30:50.0928 1152 MTConfig - ok 16:30:50.0975 1152 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 16:30:51.0006 1152 Mup - ok 16:30:51.0037 1152 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 16:30:51.0100 1152 napagent - ok 16:30:51.0146 1152 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 16:30:51.0193 1152 NativeWifiP - ok 16:30:51.0271 1152 [ 56540E526B46E379A476FB5BC381B290 ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130814.002\ENG64.SYS 16:30:51.0318 1152 NAVENG - ok 16:30:51.0380 1152 [ 8A19D3991F9F14B885CDE8BC640F6B68 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130814.002\EX64.SYS 16:30:51.0427 1152 NAVEX15 - ok 16:30:51.0490 1152 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 16:30:51.0521 1152 NDIS - ok 16:30:51.0536 1152 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 16:30:51.0599 1152 NdisCap - ok 16:30:51.0646 1152 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 16:30:51.0724 1152 NdisTapi - ok 16:30:51.0755 1152 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 16:30:51.0848 1152 Ndisuio - ok 16:30:51.0880 1152 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 16:30:51.0973 1152 NdisWan - ok 16:30:52.0004 1152 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 16:30:52.0082 1152 NDProxy - ok 16:30:52.0114 1152 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 16:30:52.0160 1152 NetBIOS - ok 16:30:52.0192 1152 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 16:30:52.0254 1152 NetBT - ok 16:30:52.0285 1152 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 16:30:52.0285 1152 Netlogon - ok 16:30:52.0332 1152 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 16:30:52.0410 1152 Netman - ok 16:30:52.0441 1152 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 16:30:52.0504 1152 netprofm - ok 16:30:52.0535 1152 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 16:30:52.0550 1152 NetTcpPortSharing - ok 16:30:52.0722 1152 [ 4D85A450EDEF10C38882182753A49AAE ] NETw5s64 C:\Windows\system32\DRIVERS\NETw5s64.sys 16:30:52.0972 1152 NETw5s64 - ok 16:30:53.0128 1152 [ 705283C02177809CA9FA7CC58A4F1E77 ] netw5v64 C:\Windows\system32\DRIVERS\netw5v64.sys 16:30:53.0315 1152 netw5v64 - ok 16:30:53.0346 1152 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 16:30:53.0362 1152 nfrd960 - ok 16:30:53.0455 1152 [ 1BF9D6476061B31CD7FC2BF848529A56 ] NIS C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe 16:30:53.0471 1152 NIS - ok 16:30:53.0502 1152 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 16:30:53.0533 1152 NlaSvc - ok 16:30:53.0564 1152 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 16:30:53.0611 1152 Npfs - ok 16:30:53.0658 1152 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 16:30:53.0752 1152 nsi - ok 16:30:53.0752 1152 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 16:30:53.0814 1152 nsiproxy - ok 16:30:53.0861 1152 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 16:30:53.0908 1152 Ntfs - ok 16:30:53.0923 1152 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 16:30:53.0954 1152 Null - ok 16:30:53.0986 1152 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 16:30:54.0001 1152 nvraid - ok 16:30:54.0032 1152 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 16:30:54.0048 1152 nvstor - ok 16:30:54.0095 1152 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 16:30:54.0110 1152 nv_agp - ok 16:30:54.0204 1152 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 16:30:54.0235 1152 odserv - ok 16:30:54.0282 1152 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 16:30:54.0298 1152 ohci1394 - ok 16:30:54.0313 1152 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 16:30:54.0329 1152 ose - ok 16:30:54.0376 1152 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 16:30:54.0438 1152 p2pimsvc - ok 16:30:54.0485 1152 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 16:30:54.0500 1152 p2psvc - ok 16:30:54.0532 1152 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 16:30:54.0547 1152 Parport - ok 16:30:54.0594 1152 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 16:30:54.0625 1152 partmgr - ok 16:30:54.0656 1152 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 16:30:54.0688 1152 PcaSvc - ok 16:30:54.0719 1152 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 16:30:54.0734 1152 pci - ok 16:30:54.0766 1152 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 16:30:54.0781 1152 pciide - ok 16:30:54.0812 1152 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 16:30:54.0828 1152 pcmcia - ok 16:30:54.0859 1152 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 16:30:54.0875 1152 pcw - ok 16:30:54.0906 1152 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 16:30:54.0968 1152 PEAUTH - ok 16:30:55.0078 1152 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 16:30:55.0109 1152 PerfHost - ok 16:30:55.0171 1152 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 16:30:55.0249 1152 pla - ok 16:30:55.0312 1152 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 16:30:55.0358 1152 PlugPlay - ok 16:30:55.0405 1152 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 16:30:55.0421 1152 PNRPAutoReg - ok 16:30:55.0452 1152 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 16:30:55.0468 1152 PNRPsvc - ok 16:30:55.0514 1152 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 16:30:55.0577 1152 PolicyAgent - ok 16:30:55.0608 1152 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 16:30:55.0670 1152 Power - ok 16:30:55.0686 1152 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 16:30:55.0733 1152 PptpMiniport - ok 16:30:55.0748 1152 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 16:30:55.0795 1152 Processor - ok 16:30:55.0826 1152 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 16:30:55.0858 1152 ProfSvc - ok 16:30:55.0873 1152 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 16:30:55.0889 1152 ProtectedStorage - ok 16:30:55.0936 1152 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 16:30:55.0998 1152 Psched - ok 16:30:56.0045 1152 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe 16:30:56.0060 1152 PSI_SVC_2 - ok 16:30:56.0092 1152 [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys 16:30:56.0107 1152 PxHlpa64 - ok 16:30:56.0138 1152 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 16:30:56.0185 1152 ql2300 - ok 16:30:56.0216 1152 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 16:30:56.0248 1152 ql40xx - ok 16:30:56.0263 1152 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 16:30:56.0294 1152 QWAVE - ok 16:30:56.0326 1152 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 16:30:56.0357 1152 QWAVEdrv - ok 16:30:56.0372 1152 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 16:30:56.0435 1152 RasAcd - ok 16:30:56.0450 1152 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 16:30:56.0497 1152 RasAgileVpn - ok 16:30:56.0513 1152 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 16:30:56.0560 1152 RasAuto - ok 16:30:56.0591 1152 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 16:30:56.0638 1152 Rasl2tp - ok 16:30:56.0684 1152 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 16:30:56.0778 1152 RasMan - ok 16:30:56.0809 1152 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 16:30:56.0856 1152 RasPppoe - ok 16:30:56.0872 1152 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 16:30:56.0934 1152 RasSstp - ok 16:30:56.0981 1152 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 16:30:57.0028 1152 rdbss - ok 16:30:57.0043 1152 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 16:30:57.0106 1152 rdpbus - ok 16:30:57.0121 1152 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 16:30:57.0152 1152 RDPCDD - ok 16:30:57.0199 1152 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 16:30:57.0277 1152 RDPENCDD - ok 16:30:57.0293 1152 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 16:30:57.0340 1152 RDPREFMP - ok 16:30:57.0355 1152 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 16:30:57.0402 1152 RDPWD - ok 16:30:57.0449 1152 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 16:30:57.0464 1152 rdyboost - ok 16:30:57.0511 1152 [ 4D9AFDDDA0EFE97CDBFD3B5FA48B05F6 ] regi C:\Windows\system32\drivers\regi.sys 16:30:57.0511 1152 regi - ok 16:30:57.0620 1152 [ 3B71B5B91E7DCA93585D5A86C897ADC4 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 16:30:57.0652 1152 RegSrvc - ok 16:30:57.0683 1152 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 16:30:57.0730 1152 RemoteAccess - ok 16:30:57.0761 1152 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 16:30:57.0823 1152 RemoteRegistry - ok 16:30:57.0854 1152 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 16:30:57.0886 1152 RFCOMM - ok 16:30:57.0917 1152 [ 258AADB43E3F3468B5CF8CB0F84872C2 ] rimsptsk C:\Windows\system32\DRIVERS\rimssn64.sys 16:30:57.0948 1152 rimsptsk - ok 16:30:57.0995 1152 [ 71E182A0DE1CECB3F912960716345405 ] risdptsk C:\Windows\system32\DRIVERS\risdsn64.sys 16:30:58.0026 1152 risdptsk - ok 16:30:58.0104 1152 [ D02E5A46F77C182CA1964080BCD586F7 ] Roxio UPnP Renderer 10 C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe 16:30:58.0135 1152 Roxio UPnP Renderer 10 - ok 16:30:58.0151 1152 [ E5809597278802D09273EE07B5FC56E1 ] Roxio Upnp Server 10 C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe 16:30:58.0182 1152 Roxio Upnp Server 10 - ok 16:30:58.0198 1152 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 16:30:58.0260 1152 RpcEptMapper - ok 16:30:58.0291 1152 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 16:30:58.0338 1152 RpcLocator - ok 16:30:58.0385 1152 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 16:30:58.0432 1152 RpcSs - ok 16:30:58.0463 1152 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 16:30:58.0541 1152 rspndr - ok 16:30:58.0588 1152 [ 34F05C417F038FFA3BEF69B798D7D7DD ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys 16:30:58.0619 1152 RTHDMIAzAudService - ok 16:30:58.0697 1152 [ 01E6A1E53E39A0B1E2B6AE62BF52E8EC ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe 16:30:58.0728 1152 RtkAudioService - ok 16:30:58.0728 1152 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 16:30:58.0744 1152 SamSs - ok 16:30:58.0775 1152 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 16:30:58.0822 1152 sbp2port - ok 16:30:58.0837 1152 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 16:30:58.0884 1152 SCardSvr - ok 16:30:58.0915 1152 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 16:30:58.0962 1152 scfilter - ok 16:30:59.0024 1152 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 16:30:59.0102 1152 Schedule - ok 16:30:59.0134 1152 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 16:30:59.0196 1152 SCPolicySvc - ok 16:30:59.0243 1152 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\drivers\sdbus.sys 16:30:59.0305 1152 sdbus - ok 16:30:59.0336 1152 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 16:30:59.0383 1152 SDRSVC - ok 16:30:59.0430 1152 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 16:30:59.0492 1152 secdrv - ok 16:30:59.0524 1152 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 16:30:59.0570 1152 seclogon - ok 16:30:59.0602 1152 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll 16:30:59.0648 1152 SENS - ok 16:30:59.0680 1152 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 16:30:59.0695 1152 SensrSvc - ok 16:30:59.0726 1152 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 16:30:59.0742 1152 Serenum - ok 16:30:59.0773 1152 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 16:30:59.0789 1152 Serial - ok 16:30:59.0804 1152 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 16:30:59.0820 1152 sermouse - ok 16:30:59.0867 1152 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 16:30:59.0929 1152 SessionEnv - ok 16:30:59.0976 1152 [ 70F9C476B62DE4F2823E918A6C181ADE ] SFEP C:\Windows\system32\DRIVERS\SFEP.sys 16:31:00.0023 1152 SFEP - ok 16:31:00.0054 1152 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 16:31:00.0116 1152 sffdisk - ok 16:31:00.0132 1152 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 16:31:00.0163 1152 sffp_mmc - ok 16:31:00.0179 1152 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 16:31:00.0226 1152 sffp_sd - ok 16:31:00.0257 1152 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 16:31:00.0319 1152 sfloppy - ok 16:31:00.0350 1152 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 16:31:00.0413 1152 SharedAccess - ok 16:31:00.0460 1152 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 16:31:00.0522 1152 ShellHWDetection - ok 16:31:00.0553 1152 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 16:31:00.0600 1152 SiSRaid2 - ok 16:31:00.0631 1152 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 16:31:00.0647 1152 SiSRaid4 - ok 16:31:00.0709 1152 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 16:31:00.0740 1152 SkypeUpdate - ok 16:31:00.0772 1152 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 16:31:00.0850 1152 Smb - ok 16:31:00.0896 1152 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 16:31:00.0943 1152 SNMPTRAP - ok 16:31:01.0006 1152 [ 98886C88A1CB13D61672AE2C638B7E1C ] SOHCImp C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe 16:31:01.0037 1152 SOHCImp - ok 16:31:01.0037 1152 [ 442A13F395546F4564C377296D43B564 ] SOHDBSvr C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe 16:31:01.0052 1152 SOHDBSvr - ok 16:31:01.0068 1152 [ 556681BE668D71DC162391A45422B52C ] SOHDms C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe 16:31:01.0084 1152 SOHDms - ok 16:31:01.0115 1152 [ 72B46103E4111439109ACF5882627C24 ] SOHDs C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe 16:31:01.0115 1152 SOHDs - ok 16:31:01.0146 1152 [ 725B6E9CD1959271AC993DC035E1606D ] SOHPlMgr C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe 16:31:01.0162 1152 SOHPlMgr - ok 16:31:01.0177 1152 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 16:31:01.0193 1152 spldr - ok 16:31:01.0240 1152 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 16:31:01.0271 1152 Spooler - ok 16:31:01.0396 1152 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 16:31:01.0505 1152 sppsvc - ok 16:31:01.0552 1152 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 16:31:01.0630 1152 sppuinotify - ok 16:31:01.0723 1152 [ 2FD9346F9D76CB4192D37329CFA47A82 ] SRTSP C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS 16:31:01.0770 1152 SRTSP - ok 16:31:01.0770 1152 [ 0E76CEF892C45734F7AED09FDDF35D4D ] SRTSPX C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS 16:31:01.0786 1152 SRTSPX - ok 16:31:01.0817 1152 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 16:31:01.0864 1152 srv - ok 16:31:01.0910 1152 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 16:31:01.0942 1152 srv2 - ok 16:31:01.0988 1152 [ 0C4540311E11664B245A263E1154CEF8 ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL6.SYS 16:31:02.0051 1152 SrvHsfHDA - ok 16:31:02.0098 1152 [ 02071D207A9858FBE3A48CBFD59C4A04 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV6.SYS 16:31:02.0144 1152 SrvHsfV92 - ok 16:31:02.0176 1152 [ 18E40C245DBFAF36FD0134A7EF2DF396 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT6.SYS 16:31:02.0207 1152 SrvHsfWinac - ok 16:31:02.0254 1152 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 16:31:02.0300 1152 srvnet - ok 16:31:02.0347 1152 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 16:31:02.0410 1152 SSDPSRV - ok 16:31:02.0441 1152 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 16:31:02.0472 1152 SstpSvc - ok 16:31:02.0488 1152 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 16:31:02.0519 1152 stexstor - ok 16:31:02.0566 1152 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 16:31:02.0612 1152 stisvc - ok 16:31:02.0644 1152 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 16:31:02.0659 1152 swenum - ok 16:31:02.0675 1152 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 16:31:02.0737 1152 swprv - ok 16:31:02.0768 1152 [ 52DC0048D667757A8A2E4C87182890AC ] SymDS C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS 16:31:02.0784 1152 SymDS - ok 16:31:02.0831 1152 [ 599872BAD7CFB45C7CE47CDED4B726D8 ] SymEFA C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS 16:31:02.0862 1152 SymEFA - ok 16:31:02.0909 1152 [ F19E5E37ED8134B9E5F6287F2D3A75D7 ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 16:31:02.0940 1152 SymEvent - ok 16:31:02.0956 1152 [ ADF37F1A715D6C56C8E065FD8569A9A4 ] SymIRON C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS 16:31:02.0971 1152 SymIRON - ok 16:31:03.0002 1152 [ 9CDCA70485BD6B9D230365F67C31F132 ] SymNetS C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS 16:31:03.0049 1152 SymNetS - ok 16:31:03.0096 1152 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 16:31:03.0143 1152 SysMain - ok 16:31:03.0190 1152 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 16:31:03.0221 1152 TabletInputService - ok 16:31:03.0252 1152 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 16:31:03.0330 1152 TapiSrv - ok 16:31:03.0346 1152 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 16:31:03.0424 1152 TBS - ok 16:31:03.0502 1152 [ DB74544B75566C974815E79A62433F29 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 16:31:03.0564 1152 Tcpip - ok 16:31:03.0611 1152 [ DB74544B75566C974815E79A62433F29 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 16:31:03.0658 1152 TCPIP6 - ok 16:31:03.0689 1152 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 16:31:03.0736 1152 tcpipreg - ok 16:31:03.0782 1152 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 16:31:03.0814 1152 TDPIPE - ok 16:31:03.0845 1152 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 16:31:03.0892 1152 TDTCP - ok 16:31:03.0954 1152 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 16:31:04.0032 1152 tdx - ok 16:31:04.0063 1152 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 16:31:04.0079 1152 TermDD - ok 16:31:04.0141 1152 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 16:31:04.0204 1152 TermService - ok 16:31:04.0235 1152 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 16:31:04.0282 1152 Themes - ok 16:31:04.0313 1152 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 16:31:04.0360 1152 THREADORDER - ok 16:31:04.0360 1152 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 16:31:04.0422 1152 TrkWks - ok 16:31:04.0484 1152 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 16:31:04.0547 1152 TrustedInstaller - ok 16:31:04.0578 1152 [ 4CE278FC9671BA81A138D70823FCAA09 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 16:31:04.0625 1152 tssecsrv - ok 16:31:04.0687 1152 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 16:31:04.0750 1152 TsUsbFlt - ok 16:31:04.0812 1152 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 16:31:04.0890 1152 tunnel - ok 16:31:04.0921 1152 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 16:31:04.0952 1152 uagp35 - ok 16:31:05.0015 1152 [ 63F6D08C54D5B3C1B12A6172032055C7 ] uCamMonitor C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe 16:31:05.0062 1152 uCamMonitor - ok 16:31:05.0093 1152 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 16:31:05.0140 1152 udfs - ok 16:31:05.0171 1152 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 16:31:05.0202 1152 UI0Detect - ok 16:31:05.0218 1152 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 16:31:05.0233 1152 uliagpkx - ok 16:31:05.0280 1152 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 16:31:05.0342 1152 umbus - ok 16:31:05.0389 1152 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 16:31:05.0420 1152 UmPass - ok 16:31:05.0436 1152 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 16:31:05.0483 1152 upnphost - ok 16:31:05.0498 1152 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 16:31:05.0530 1152 usbccgp - ok 16:31:05.0576 1152 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 16:31:05.0592 1152 usbcir - ok 16:31:05.0623 1152 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 16:31:05.0654 1152 usbehci - ok 16:31:05.0686 1152 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 16:31:05.0717 1152 usbhub - ok 16:31:05.0732 1152 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 16:31:05.0764 1152 usbohci - ok 16:31:05.0795 1152 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 16:31:05.0857 1152 usbprint - ok 16:31:05.0920 1152 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 16:31:05.0966 1152 usbscan - ok 16:31:05.0966 1152 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 16:31:05.0998 1152 USBSTOR - ok 16:31:06.0013 1152 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 16:31:06.0076 1152 usbuhci - ok 16:31:06.0107 1152 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 16:31:06.0154 1152 usbvideo - ok 16:31:06.0185 1152 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 16:31:06.0232 1152 UxSms - ok 16:31:06.0278 1152 [ 4E7135D6D0127067E4CFEE12259F895D ] VAIO Entertainment TV Device Arbitration Service C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe 16:31:06.0294 1152 VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - warning 16:31:06.0294 1152 VAIO Entertainment TV Device Arbitration Service - detected UnsignedFile.Multi.Generic (1) 16:31:06.0403 1152 [ 6B31C9CB94927DBEEB62E15275F4CC54 ] VAIO Event Service C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe 16:31:06.0434 1152 VAIO Event Service - ok 16:31:06.0512 1152 [ 2D6605C1F0BBD0F71A4CB3A5B1E07240 ] VAIO Power Management C:\Program Files\Sony\VAIO Power Management\SPMService.exe 16:31:06.0559 1152 VAIO Power Management - ok 16:31:06.0575 1152 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 16:31:06.0590 1152 VaultSvc - ok 16:31:06.0668 1152 [ 06FE5BEDDADB158D84E6DE33CBE19F3E ] VCFw C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe 16:31:06.0715 1152 VCFw - ok 16:31:06.0778 1152 [ FD03AC6CD1571AA8B2FF56D3C600E26E ] VcmIAlzMgr C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe 16:31:06.0809 1152 VcmIAlzMgr - ok 16:31:06.0840 1152 [ 9D9B34B430B4DC683112F59C80D20AB8 ] VcmINSMgr C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe 16:31:06.0887 1152 VcmINSMgr - ok 16:31:06.0934 1152 [ DB544B487F360128DC1C383E0A6FCC2F ] VcmXmlIfHelper C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe 16:31:06.0949 1152 VcmXmlIfHelper - ok 16:31:06.0965 1152 Vcsw - ok 16:31:06.0996 1152 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 16:31:07.0043 1152 vdrvroot - ok 16:31:07.0074 1152 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 16:31:07.0136 1152 vds - ok 16:31:07.0168 1152 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 16:31:07.0183 1152 vga - ok 16:31:07.0214 1152 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 16:31:07.0261 1152 VgaSave - ok 16:31:07.0292 1152 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 16:31:07.0308 1152 vhdmp - ok 16:31:07.0339 1152 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 16:31:07.0355 1152 viaide - ok 16:31:07.0448 1152 [ 1B0D441D8AB264D39C2B09130CC28045 ] VMCService C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe 16:31:07.0480 1152 VMCService ( UnsignedFile.Multi.Generic ) - warning 16:31:07.0480 1152 VMCService - detected UnsignedFile.Multi.Generic (1) 16:31:07.0495 1152 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 16:31:07.0511 1152 volmgr - ok 16:31:07.0542 1152 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 16:31:07.0573 1152 volmgrx - ok 16:31:07.0620 1152 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 16:31:07.0636 1152 volsnap - ok 16:31:07.0667 1152 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 16:31:07.0682 1152 vsmraid - ok 16:31:07.0776 1152 [ 047F22BDFDAE6DF6F1E47E747A1237A2 ] VSNService C:\Program Files\Sony\VAIO Smart Network\VSNService.exe 16:31:07.0838 1152 VSNService ( UnsignedFile.Multi.Generic ) - warning 16:31:07.0838 1152 VSNService - detected UnsignedFile.Multi.Generic (1) 16:31:07.0901 1152 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 16:31:07.0994 1152 VSS - ok 16:31:08.0119 1152 [ D2D646D4D686C6996BA1FF96E11BE570 ] VUAgent C:\Program Files\Sony\VAIO Update\VUAgent.exe 16:31:08.0166 1152 VUAgent - ok 16:31:08.0182 1152 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 16:31:08.0197 1152 vwifibus - ok 16:31:08.0228 1152 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 16:31:08.0291 1152 vwififlt - ok 16:31:08.0322 1152 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 16:31:08.0338 1152 vwifimp - ok 16:31:08.0353 1152 [ D8BEF4AC1EAC809DBDBD441D6CFF6C4C ] VzCdbSvc C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe 16:31:08.0369 1152 VzCdbSvc ( UnsignedFile.Multi.Generic ) - warning 16:31:08.0369 1152 VzCdbSvc - detected UnsignedFile.Multi.Generic (1) 16:31:08.0400 1152 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 16:31:08.0447 1152 W32Time - ok 16:31:08.0462 1152 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 16:31:08.0494 1152 WacomPen - ok 16:31:08.0540 1152 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 16:31:08.0650 1152 WANARP - ok 16:31:08.0665 1152 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 16:31:08.0696 1152 Wanarpv6 - ok 16:31:08.0759 1152 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 16:31:08.0821 1152 wbengine - ok 16:31:08.0852 1152 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 16:31:08.0884 1152 WbioSrvc - ok 16:31:08.0899 1152 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 16:31:08.0946 1152 wcncsvc - ok 16:31:08.0962 1152 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 16:31:08.0977 1152 WcsPlugInService - ok 16:31:09.0008 1152 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 16:31:09.0024 1152 Wd - ok 16:31:09.0055 1152 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 16:31:09.0086 1152 Wdf01000 - ok 16:31:09.0102 1152 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 16:31:09.0164 1152 WdiServiceHost - ok 16:31:09.0164 1152 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 16:31:09.0196 1152 WdiSystemHost - ok 16:31:09.0227 1152 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 16:31:09.0274 1152 WebClient - ok 16:31:09.0305 1152 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 16:31:09.0383 1152 Wecsvc - ok 16:31:09.0414 1152 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 16:31:09.0445 1152 wercplsupport - ok 16:31:09.0476 1152 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 16:31:09.0508 1152 WerSvc - ok 16:31:09.0554 1152 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 16:31:09.0601 1152 WfpLwf - ok 16:31:09.0617 1152 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 16:31:09.0632 1152 WIMMount - ok 16:31:09.0695 1152 WinDefend - ok 16:31:09.0710 1152 WinHttpAutoProxySvc - ok 16:31:09.0773 1152 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 16:31:09.0835 1152 Winmgmt - ok 16:31:09.0913 1152 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 16:31:10.0007 1152 WinRM - ok 16:31:10.0100 1152 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 16:31:10.0163 1152 WinUsb - ok 16:31:10.0210 1152 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 16:31:10.0272 1152 Wlansvc - ok 16:31:10.0303 1152 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 16:31:10.0350 1152 WmiAcpi - ok 16:31:10.0381 1152 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 16:31:10.0444 1152 wmiApSrv - ok 16:31:10.0490 1152 WMPNetworkSvc - ok 16:31:10.0506 1152 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 16:31:10.0522 1152 WPCSvc - ok 16:31:10.0553 1152 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 16:31:10.0568 1152 WPDBusEnum - ok 16:31:10.0615 1152 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 16:31:10.0693 1152 ws2ifsl - ok 16:31:10.0771 1152 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 16:31:10.0849 1152 wscsvc - ok 16:31:10.0849 1152 WSearch - ok 16:31:10.0943 1152 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 16:31:11.0005 1152 wuauserv - ok 16:31:11.0036 1152 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 16:31:11.0068 1152 WudfPf - ok 16:31:11.0099 1152 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 16:31:11.0130 1152 WUDFRd - ok 16:31:11.0161 1152 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 16:31:11.0177 1152 wudfsvc - ok 16:31:11.0208 1152 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll 16:31:11.0224 1152 WwanSvc - ok 16:31:11.0286 1152 [ 6AFFD75C6807B3DD3AB018E27B88EF95 ] yukonw7 C:\Windows\system32\DRIVERS\yk62x64.sys 16:31:11.0317 1152 yukonw7 - ok 16:31:11.0364 1152 ================ Scan global =============================== 16:31:11.0380 1152 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 16:31:11.0411 1152 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 16:31:11.0426 1152 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 16:31:11.0458 1152 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 16:31:11.0504 1152 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 16:31:11.0504 1152 [Global] - ok 16:31:11.0504 1152 ================ Scan MBR ================================== 16:31:11.0520 1152 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 16:31:11.0988 1152 \Device\Harddisk0\DR0 - ok 16:31:12.0004 1152 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk3\DR3 16:31:12.0893 1152 \Device\Harddisk3\DR3 - ok 16:31:12.0893 1152 ================ Scan VBR ================================== 16:31:12.0908 1152 [ 683BD57D7ACF160784453381565F31B8 ] \Device\Harddisk0\DR0\Partition1 16:31:12.0908 1152 \Device\Harddisk0\DR0\Partition1 - ok 16:31:12.0924 1152 [ 33B1EA4F844F6647F2E8562CB926FDB2 ] \Device\Harddisk0\DR0\Partition2 16:31:12.0940 1152 \Device\Harddisk0\DR0\Partition2 - ok 16:31:12.0971 1152 [ 09BB25B26ABE4BF89A59BF43FA2D95B8 ] \Device\Harddisk0\DR0\Partition3 16:31:13.0002 1152 \Device\Harddisk0\DR0\Partition3 - ok 16:31:13.0002 1152 [ 066BE30ABA114A296CAF21E6CD5D3964 ] \Device\Harddisk3\DR3\Partition1 16:31:13.0002 1152 \Device\Harddisk3\DR3\Partition1 - ok 16:31:13.0018 1152 ============================================================ 16:31:13.0018 1152 Scan finished 16:31:13.0018 1152 ============================================================ 16:31:13.0018 5208 Detected object count: 6 16:31:13.0018 5208 Actual detected object count: 6 16:31:59.0116 5208 igfx ( UnsignedFile.Multi.Generic ) - skipped by user 16:31:59.0116 5208 igfx ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:31:59.0116 5208 IntcHdmiAddService ( UnsignedFile.Multi.Generic ) - skipped by user 16:31:59.0116 5208 IntcHdmiAddService ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:31:59.0116 5208 VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - skipped by user 16:31:59.0116 5208 VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:31:59.0116 5208 VMCService ( UnsignedFile.Multi.Generic ) - skipped by user 16:31:59.0116 5208 VMCService ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:31:59.0116 5208 VSNService ( UnsignedFile.Multi.Generic ) - skipped by user 16:31:59.0116 5208 VSNService ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:31:59.0116 5208 VzCdbSvc ( UnsignedFile.Multi.Generic ) - skipped by user 16:31:59.0116 5208 VzCdbSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:40.0018 5864 Deinitialize success |
15.08.2013, 13:16 | #29 |
/// Malware-holic | GVU Trojaner hat meinen Laptop erwischt! Hi, das Archiv meinst du? das kannst du gerne entfernen. Es sind 4 Logs zu erstellen, bitte gleichzeitig posten. 1. Downloade Dir bitte Malwarebytes Anti-Malware
2. Downloade Dir bitte AdwCleaner auf deinen Desktop.
Neustarten. 3. Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
4. Hitmanpro laden,: http://filepony.de/download-hitmanpro_64/ Doppelklicken, Scan klicken. Log speichern und posten, bzw als XML exportieren, packen und anhängen.b
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
15.08.2013, 14:37 | #30 |
| GVU Trojaner hat meinen Laptop erwischt! bei dem Malwarebytes steht das ich es in dem angegebenen pfad installieren soll, muss ich diesen pfad manuell raussuchen bzw erstellen oder macht das das Programm von allein? |
Themen zu GVU Trojaner hat meinen Laptop erwischt! |
absolut, bild, bundespolizei, erwischt, explorer, film, filme, gvu trojaner, interne, internet, internet explorer, klicke, klicken, konnte, laptop, namen, nicht mehr, nichts, relativ, schließe, schließen, strg, taskmanager, trojaner, ukash, werbefenster, wirklich, öffnen |