Ich habe jetzt den TDSSKiller Scan machen lassen.
Ich hab das 2 logs stehen.
TDSSKiller.3.0.0.41_15.11.2014_14.10.30_log
Code:
Alles auswählen Aufklappen ATTFilter
14:10:30.0389 0x1afc TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34
14:10:46.0938 0x1afc ============================================================
14:10:46.0938 0x1afc Current date / time: 2014/11/15 14:10:46.0938
14:10:46.0938 0x1afc SystemInfo:
14:10:46.0938 0x1afc
14:10:46.0938 0x1afc OS Version: 6.1.7601 ServicePack: 1.0
14:10:46.0938 0x1afc Product type: Workstation
14:10:46.0938 0x1afc ComputerName: REDMAX
14:10:46.0938 0x1afc UserName: RedMax
14:10:46.0938 0x1afc Windows directory: C:\Windows
14:10:46.0938 0x1afc System windows directory: C:\Windows
14:10:46.0938 0x1afc Running under WOW64
14:10:46.0938 0x1afc Processor architecture: Intel x64
14:10:46.0938 0x1afc Number of processors: 8
14:10:46.0938 0x1afc Page size: 0x1000
14:10:46.0938 0x1afc Boot type: Normal boot
14:10:46.0938 0x1afc ============================================================
14:10:47.0548 0x1afc KLMD registered as C:\Windows\system32\drivers\91458155.sys
14:10:47.0786 0x1afc System UUID: {1E9C894B-DA18-E373-1C6F-B4F12BFC9B96}
14:10:48.0101 0x1afc Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
14:10:48.0110 0x1afc Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
14:10:48.0114 0x1afc Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
14:10:50.0480 0x1afc ============================================================
14:10:50.0480 0x1afc \Device\Harddisk0\DR0:
14:10:50.0480 0x1afc MBR partitions:
14:10:50.0480 0x1afc \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x712D2800
14:10:50.0481 0x1afc \Device\Harddisk1\DR1:
14:10:50.0481 0x1afc MBR partitions:
14:10:50.0481 0x1afc \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
14:10:50.0481 0x1afc \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1866D800
14:10:50.0481 0x1afc \Device\Harddisk1\DR1\Partition3: MBR, Type 0x7, StartLBA 0x186A0000, BlocksNum 0x5C066000
14:10:50.0481 0x1afc \Device\Harddisk2\DR2:
14:10:50.0488 0x1afc MBR partitions:
14:10:50.0488 0x1afc \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x40, BlocksNum 0x74705980
14:10:50.0488 0x1afc ============================================================
14:10:50.0507 0x1afc C: <-> \Device\Harddisk1\DR1\Partition2
14:10:50.0544 0x1afc D: <-> \Device\Harddisk0\DR0\Partition1
14:10:50.0562 0x1afc E: <-> \Device\Harddisk1\DR1\Partition3
14:10:50.0634 0x1afc K: <-> \Device\Harddisk2\DR2\Partition1
14:10:50.0634 0x1afc ============================================================
14:10:50.0634 0x1afc Initialize success
14:10:50.0634 0x1afc ============================================================
14:11:07.0247 0x07dc Deinitialize success