TDSSKiller findet nichts:
Code:
Alles auswählen Aufklappen ATTFilter
13:03:35.0795 0x622f8 TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02
13:03:38.0969 0x622f8 ============================================================
13:03:38.0969 0x622f8 Current date / time: 2017/06/04 13:03:38.0969
13:03:38.0969 0x622f8 SystemInfo:
13:03:38.0969 0x622f8
13:03:38.0969 0x622f8 OS Version: 6.1.7601 ServicePack: 1.0
13:03:38.0969 0x622f8 Product type: Server
13:03:38.0970 0x622f8 ComputerName: CT114134
13:03:38.0970 0x622f8 UserName: Administrator
13:03:38.0970 0x622f8 Windows directory: C:\Windows
13:03:38.0970 0x622f8 System windows directory: C:\Windows
13:03:38.0970 0x622f8 Running under WOW64
13:03:38.0970 0x622f8 Processor architecture: Intel x64
13:03:38.0970 0x622f8 Number of processors: 8
13:03:38.0970 0x622f8 Page size: 0x1000
13:03:38.0970 0x622f8 Boot type: Normal boot
13:03:38.0970 0x622f8 CodeIntegrityOptions = 0x00000001
13:03:38.0970 0x622f8 ============================================================
13:03:39.0029 0x622f8 KLMD registered as C:\Windows\system32\drivers\94623626.sys
13:03:49.0015 0x622f8 System UUID: {9433FB39-3EAA-1951-E0CB-259AC2D298DA}
13:03:49.0366 0x622f8 !crdlk
13:03:49.0449 0x622f8 Initialize success
13:03:49.0449 0x622f8 ============================================================
13:04:26.0426 0x62640 ============================================================
13:04:26.0426 0x62640 Scan started
13:04:26.0426 0x62640 Mode: Manual; SigCheck; TDLFS;
13:04:26.0426 0x62640 ============================================================
13:04:26.0426 0x62640 KSN ping started
13:04:26.0548 0x62640 KSN ping finished: true
13:04:26.0555 0x62640 ================ Scan system memory ========================
13:04:26.0555 0x62640 System memory - ok
13:04:26.0556 0x62640 ================ Scan services =============================
13:04:26.0577 0x62640 1394ohci - ok
13:04:26.0585 0x62640 ACPI - ok
13:04:26.0593 0x62640 AcpiPmi - ok
13:04:26.0601 0x62640 adp94xx - ok
13:04:26.0608 0x62640 adpahci - ok
13:04:26.0613 0x62640 adpu320 - ok
13:04:26.0622 0x62640 AeLookupSvc - ok
13:04:26.0631 0x62640 AFD - ok
13:04:26.0639 0x62640 agp440 - ok
13:04:26.0647 0x62640 ALG - ok
13:04:26.0653 0x62640 aliide - ok
13:04:26.0658 0x62640 amdide - ok
13:04:26.0666 0x62640 AmdK8 - ok
13:04:26.0682 0x62640 AmdPPM - ok
13:04:26.0687 0x62640 amdsata - ok
13:04:26.0693 0x62640 amdsbs - ok
13:04:26.0698 0x62640 amdxata - ok
13:04:26.0708 0x62640 AppID - ok
13:04:26.0713 0x62640 AppIDSvc - ok
13:04:26.0719 0x62640 Appinfo - ok
13:04:26.0723 0x62640 AppMgmt - ok
13:04:26.0730 0x62640 arc - ok
13:04:26.0734 0x62640 arcsas - ok
13:04:26.0744 0x62640 AsyncMac - ok
13:04:26.0752 0x62640 atapi - ok
13:04:26.0760 0x62640 AudioEndpointBuilder - ok
13:04:26.0775 0x62640 AudioSrv - ok
13:04:26.0780 0x62640 b06bdrv - ok
13:04:26.0787 0x62640 b57nd60a - ok
13:04:26.0797 0x62640 Beep - ok
13:04:26.0803 0x62640 BFE - ok
13:04:26.0808 0x62640 BITS - ok
13:04:26.0812 0x62640 blbdrive - ok
13:04:26.0819 0x62640 bowser - ok
13:04:26.0825 0x62640 BrFiltLo - ok
13:04:26.0829 0x62640 BrFiltUp - ok
13:04:26.0834 0x62640 Browser - ok
13:04:26.0840 0x62640 Brserid - ok
13:04:26.0845 0x62640 BrSerWdm - ok
13:04:26.0850 0x62640 BrUsbMdm - ok
13:04:26.0855 0x62640 BrUsbSer - ok
13:04:26.0860 0x62640 cdfs - ok
13:04:26.0865 0x62640 cdrom - ok
13:04:26.0888 0x62640 CertPropSvc - ok
13:04:26.0894 0x62640 CLFS - ok
13:04:26.0898 0x62640 clr_optimization_v2.0.50727_32 - ok
13:04:26.0903 0x62640 clr_optimization_v2.0.50727_64 - ok
13:04:26.0913 0x62640 CmBatt - ok
13:04:26.0918 0x62640 cmdide - ok
13:04:26.0922 0x62640 CNG - ok
13:04:26.0928 0x62640 Compbatt - ok
13:04:26.0933 0x62640 CompositeBus - ok
13:04:26.0938 0x62640 COMSysApp - ok
13:04:26.0944 0x62640 crcdisk - ok
13:04:26.0952 0x62640 CryptSvc - ok
13:04:26.0961 0x62640 DcomLaunch - ok
13:04:26.0980 0x62640 defragsvc - ok
13:04:26.0985 0x62640 DfsC - ok
13:04:26.0991 0x62640 Dhcp - ok
13:04:26.0996 0x62640 discache - ok
13:04:27.0001 0x62640 Disk - ok
13:04:27.0006 0x62640 dmvsc - ok
13:04:27.0011 0x62640 Dnscache - ok
13:04:27.0016 0x62640 dot3svc - ok
13:04:27.0021 0x62640 DPS - ok
13:04:27.0025 0x62640 DXGKrnl - ok
13:04:27.0029 0x62640 E1G60 - ok
13:04:27.0036 0x62640 EapHost - ok
13:04:27.0040 0x62640 ebdrv - ok
13:04:27.0045 0x62640 EFS - ok
13:04:27.0050 0x62640 elxstor - ok
13:04:27.0056 0x62640 ErrDev - ok
13:04:27.0065 0x62640 EventSystem - ok
13:04:27.0069 0x62640 exfat - ok
13:04:27.0076 0x62640 fastfat - ok
13:04:27.0081 0x62640 FCRegSvc - ok
13:04:27.0116 0x62640 fdc - ok
13:04:27.0121 0x62640 fdPHost - ok
13:04:27.0125 0x62640 FDResPub - ok
13:04:27.0130 0x62640 FileInfo - ok
13:04:27.0135 0x62640 Filetrace - ok
13:04:27.0140 0x62640 flpydisk - ok
13:04:27.0145 0x62640 FltMgr - ok
13:04:27.0150 0x62640 FontCache - ok
13:04:27.0155 0x62640 FsDepends - ok
13:04:27.0160 0x62640 Fs_Rec - ok
13:04:27.0165 0x62640 gagp30kx - ok
13:04:27.0167 0x62640 gpsvc - ok
13:04:27.0173 0x62640 HDAudBus - ok
13:04:27.0177 0x62640 HidBatt - ok
13:04:27.0204 0x62640 hidserv - ok
13:04:27.0209 0x62640 HidUsb - ok
13:04:27.0217 0x62640 hkmsvc - ok
13:04:27.0227 0x62640 HpSAMD - ok
13:04:27.0237 0x62640 HTTP - ok
13:04:27.0246 0x62640 hwpolicy - ok
13:04:27.0254 0x62640 i8042prt - ok
13:04:27.0261 0x62640 iaStorV - ok
13:04:27.0274 0x62640 iirsp - ok
13:04:27.0281 0x62640 IKEEXT - ok
13:04:27.0298 0x62640 intelide - ok
13:04:27.0300 0x62640 intelppm - ok
13:04:27.0308 0x62640 ioatdma - ok
13:04:27.0312 0x62640 IPBusEnum - ok
13:04:27.0319 0x62640 IpFilterDriver - ok
13:04:27.0327 0x62640 iphlpsvc - ok
13:04:27.0337 0x62640 IPMIDRV - ok
13:04:27.0348 0x62640 IPNAT - ok
13:04:27.0357 0x62640 isapnp - ok
13:04:27.0368 0x62640 iScsiPrt - ok
13:04:27.0379 0x62640 kbdclass - ok
13:04:27.0389 0x62640 kbdhid - ok
13:04:27.0402 0x62640 KeyIso - ok
13:04:27.0412 0x62640 KSecDD - ok
13:04:27.0422 0x62640 KSecPkg - ok
13:04:27.0429 0x62640 ksthunk - ok
13:04:27.0434 0x62640 KtmRm - ok
13:04:27.0435 0x62640 LanmanServer - ok
13:04:27.0435 0x62640 LanmanWorkstation - ok
13:04:27.0451 0x62640 lltdio - ok
13:04:27.0453 0x62640 lltdsvc - ok
13:04:27.0461 0x62640 lmhosts - ok
13:04:27.0469 0x62640 LSI_FC - ok
13:04:27.0490 0x62640 LSI_SAS - ok
13:04:27.0511 0x62640 LSI_SAS2 - ok
13:04:27.0519 0x62640 LSI_SCSI - ok
13:04:27.0550 0x62640 luafv - ok
13:04:27.0557 0x62640 megasas - ok
13:04:27.0565 0x62640 MegaSR - ok
13:04:27.0573 0x62640 MMCSS - ok
13:04:27.0582 0x62640 Modem - ok
13:04:27.0590 0x62640 monitor - ok
13:04:27.0597 0x62640 mouclass - ok
13:04:27.0603 0x62640 mouhid - ok
13:04:27.0610 0x62640 mountmgr - ok
13:04:27.0619 0x62640 mpio - ok
13:04:27.0627 0x62640 mpsdrv - ok
13:04:27.0633 0x62640 MpsSvc - ok
13:04:27.0638 0x62640 mrxsmb - ok
13:04:27.0676 0x62640 mrxsmb10 - ok
13:04:27.0686 0x62640 mrxsmb20 - ok
13:04:27.0696 0x62640 msahci - ok
13:04:27.0705 0x62640 msdsm - ok
13:04:27.0709 0x62640 MSDTC - ok
13:04:27.0714 0x62640 Msfs - ok
13:04:27.0718 0x62640 mshidkmdf - ok
13:04:27.0726 0x62640 msisadrv - ok
13:04:27.0727 0x62640 MSiSCSI - ok
13:04:27.0734 0x62640 msiserver - ok
13:04:27.0742 0x62640 MsRPC - ok
13:04:27.0747 0x62640 mssmbios - ok
13:04:27.0752 0x62640 MTConfig - ok
13:04:27.0758 0x62640 Mup - ok
13:04:27.0763 0x62640 napagent - ok
13:04:27.0768 0x62640 NDIS - ok
13:04:27.0774 0x62640 NdisCap - ok
13:04:27.0776 0x62640 NdisTapi - ok
13:04:27.0785 0x62640 Ndisuio - ok
13:04:27.0785 0x62640 NdisWan - ok
13:04:27.0793 0x62640 NDProxy - ok
13:04:27.0801 0x62640 NetBIOS - ok
13:04:27.0801 0x62640 NetBT - ok
13:04:27.0808 0x62640 Netlogon - ok
13:04:27.0816 0x62640 Netman - ok
13:04:27.0821 0x62640 netprofm - ok
13:04:27.0825 0x62640 nfrd960 - ok
13:04:27.0831 0x62640 NlaSvc - ok
13:04:27.0838 0x62640 Npfs - ok
13:04:27.0852 0x62640 nsi - ok
13:04:27.0860 0x62640 nsiproxy - ok
13:04:27.0871 0x62640 Ntfs - ok
13:04:27.0876 0x62640 Null - ok
13:04:27.0882 0x62640 nvraid - ok
13:04:27.0887 0x62640 nvstor - ok
13:04:27.0892 0x62640 nv_agp - ok
13:04:27.0897 0x62640 ohci1394 - ok
13:04:27.0902 0x62640 Parport - ok
13:04:27.0907 0x62640 partmgr - ok
13:04:27.0913 0x62640 pci - ok
13:04:27.0917 0x62640 pciide - ok
13:04:27.0922 0x62640 pcmcia - ok
13:04:27.0928 0x62640 pcw - ok
13:04:27.0933 0x62640 PEAUTH - ok
13:04:27.0940 0x62640 PerfHost - ok
13:04:27.0953 0x62640 pla - ok
13:04:27.0978 0x62640 PlugPlay - ok
13:04:27.0983 0x62640 PolicyAgent - ok
13:04:27.0990 0x62640 Power - ok
13:04:27.0995 0x62640 PptpMiniport - ok
13:04:28.0000 0x62640 Processor - ok
13:04:28.0005 0x62640 ProfSvc - ok
13:04:28.0013 0x62640 ProtectedStorage - ok
13:04:28.0042 0x62640 Psched - ok
13:04:28.0049 0x62640 ql2300 - ok
13:04:28.0059 0x62640 ql40xx - ok
13:04:28.0067 0x62640 RasAcd - ok
13:04:28.0075 0x62640 RasAgileVpn - ok
13:04:28.0084 0x62640 RasAuto - ok
13:04:28.0092 0x62640 Rasl2tp - ok
13:04:28.0100 0x62640 RasMan - ok
13:04:28.0110 0x62640 RasPppoe - ok
13:04:28.0119 0x62640 RasSstp - ok
13:04:28.0128 0x62640 rdbss - ok
13:04:28.0138 0x62640 rdpbus - ok
13:04:28.0147 0x62640 RDPCDD - ok
13:04:28.0160 0x62640 RDPDR - ok
13:04:28.0168 0x62640 RDPENCDD - ok
13:04:28.0179 0x62640 RDPREFMP - ok
13:04:28.0189 0x62640 RDPWD - ok
13:04:28.0197 0x62640 RemoteAccess - ok
13:04:28.0205 0x62640 RemoteRegistry - ok
13:04:28.0210 0x62640 RpcEptMapper - ok
13:04:28.0215 0x62640 RpcLocator - ok
13:04:28.0221 0x62640 RpcSs - ok
13:04:28.0226 0x62640 RSoPProv - ok
13:04:28.0229 0x62640 rspndr - ok
13:04:28.0234 0x62640 s3cap - ok
13:04:28.0240 0x62640 sacdrv - ok
13:04:28.0245 0x62640 sacsvr - ok
13:04:28.0253 0x62640 SamSs - ok
13:04:28.0260 0x62640 sbp2port - ok
13:04:28.0265 0x62640 SCardSvr - ok
13:04:28.0271 0x62640 scfilter - ok
13:04:28.0277 0x62640 Schedule - ok
13:04:28.0288 0x62640 SCPolicySvc - ok
13:04:28.0294 0x62640 secdrv - ok
13:04:28.0304 0x62640 seclogon - ok
13:04:28.0312 0x62640 SENS - ok
13:04:28.0319 0x62640 Serenum - ok
13:04:28.0327 0x62640 Serial - ok
13:04:28.0334 0x62640 sermouse - ok
13:04:28.0350 0x62640 SessionEnv - ok
13:04:28.0357 0x62640 sffdisk - ok
13:04:28.0366 0x62640 sffp_mmc - ok
13:04:28.0374 0x62640 sffp_sd - ok
13:04:28.0383 0x62640 sfloppy - ok
13:04:28.0388 0x62640 SharedAccess - ok
13:04:28.0393 0x62640 ShellHWDetection - ok
13:04:28.0398 0x62640 SiSRaid2 - ok
13:04:28.0403 0x62640 SiSRaid4 - ok
13:04:28.0409 0x62640 Smb - ok
13:04:28.0414 0x62640 SNMPTRAP - ok
13:04:28.0419 0x62640 spldr - ok
13:04:28.0425 0x62640 Spooler - ok
13:04:28.0430 0x62640 sppsvc - ok
13:04:28.0438 0x62640 sppuinotify - ok
13:04:28.0444 0x62640 srv - ok
13:04:28.0450 0x62640 srv2 - ok
13:04:28.0459 0x62640 srvnet - ok
13:04:28.0463 0x62640 SSDPSRV - ok
13:04:28.0469 0x62640 SstpSvc - ok
13:04:28.0474 0x62640 stexstor - ok
13:04:28.0478 0x62640 storflt - ok
13:04:28.0484 0x62640 storvsc - ok
13:04:28.0493 0x62640 storvsp - ok
13:04:28.0499 0x62640 swenum - ok
13:04:28.0502 0x62640 swprv - ok
13:04:28.0512 0x62640 TapiSrv - ok
13:04:28.0517 0x62640 TBS - ok
13:04:28.0520 0x62640 Tcpip - ok
13:04:28.0526 0x62640 TCPIP6 - ok
13:04:28.0534 0x62640 tcpipreg - ok
13:04:28.0542 0x62640 TDPIPE - ok
13:04:28.0547 0x62640 TDTCP - ok
13:04:28.0552 0x62640 tdx - ok
13:04:28.0557 0x62640 TermDD - ok
13:04:28.0563 0x62640 TermService - ok
13:04:28.0568 0x62640 THREADORDER - ok
13:04:28.0573 0x62640 TrkWks - ok
13:04:28.0579 0x62640 TrustedInstaller - ok
13:04:28.0596 0x62640 tssecsrv - ok
13:04:28.0605 0x62640 TsUsbFlt - ok
13:04:28.0611 0x62640 TsUsbGD - ok
13:04:28.0616 0x62640 tunnel - ok
13:04:28.0622 0x62640 uagp35 - ok
13:04:28.0627 0x62640 udfs - ok
13:04:28.0632 0x62640 UI0Detect - ok
13:04:28.0635 0x62640 uliagpkx - ok
13:04:28.0642 0x62640 umbus - ok
13:04:28.0650 0x62640 UmPass - ok
13:04:28.0657 0x62640 UmRdpService - ok
13:04:28.0663 0x62640 upnphost - ok
13:04:28.0668 0x62640 usbccgp - ok
13:04:28.0673 0x62640 usbehci - ok
13:04:28.0681 0x62640 usbhub - ok
13:04:28.0688 0x62640 usbohci - ok
13:04:28.0693 0x62640 usbprint - ok
13:04:28.0699 0x62640 USBSTOR - ok
13:04:28.0704 0x62640 usbuhci - ok
13:04:28.0709 0x62640 UxSms - ok
13:04:28.0716 0x62640 VaultSvc - ok
13:04:28.0721 0x62640 vdrvroot - ok
13:04:28.0727 0x62640 vds - ok
13:04:28.0729 0x62640 vga - ok
13:04:28.0735 0x62640 VgaSave - ok
13:04:28.0736 0x62640 vhdmp - ok
13:04:28.0745 0x62640 viaide - ok
13:04:28.0746 0x62640 Vid - ok
13:04:28.0751 0x62640 vmbus - ok
13:04:28.0767 0x62640 VMBusHID - ok
13:04:28.0767 0x62640 volmgr - ok
13:04:28.0776 0x62640 volmgrx - ok
13:04:28.0783 0x62640 volsnap - ok
13:04:28.0790 0x62640 vsmraid - ok
13:04:28.0796 0x62640 VSS - ok
13:04:28.0801 0x62640 W32Time - ok
13:04:28.0808 0x62640 WacomPen - ok
13:04:28.0820 0x62640 WANARP - ok
13:04:28.0827 0x62640 Wanarpv6 - ok
13:04:28.0831 0x62640 WcsPlugInService - ok
13:04:28.0838 0x62640 Wd - ok
13:04:28.0843 0x62640 Wdf01000 - ok
13:04:28.0850 0x62640 WdiServiceHost - ok
13:04:28.0857 0x62640 WdiSystemHost - ok
13:04:28.0863 0x62640 Wecsvc - ok
13:04:28.0868 0x62640 wercplsupport - ok
13:04:28.0873 0x62640 WerSvc - ok
13:04:28.0877 0x62640 WfpLwf - ok
13:04:28.0882 0x62640 WIMMount - ok
13:04:28.0888 0x62640 WinHttpAutoProxySvc - ok
13:04:28.0891 0x62640 Winmgmt - ok
13:04:28.0897 0x62640 WinRM - ok
13:04:28.0906 0x62640 WmiAcpi - ok
13:04:28.0914 0x62640 wmiApSrv - ok
13:04:28.0919 0x62640 WPDBusEnum - ok
13:04:28.0924 0x62640 ws2ifsl - ok
13:04:28.0929 0x62640 wuauserv - ok
13:04:28.0934 0x62640 WudfPf - ok
13:04:28.0939 0x62640 wudfsvc - ok
13:04:28.0944 0x62640 Suspicious service (Hidden): {7DE6CEBB-73DB-4A0B-BDC7-EEBDE6D6B98E}
13:04:28.0945 0x62640 Suspicious service (Hidden): {FB869FB7-AAAC-4490-A2DB-0C480D3CA136}
13:04:28.0948 0x62640 ================ Scan global ===============================
13:04:28.0948 0x62640 [ Global ] - ok
13:04:28.0949 0x62640 ================ Scan MBR ==================================
13:04:28.0949 0x62640 ================ Scan VBR ==================================
13:04:28.0949 0x62640 ================ Scan generic autorun ======================
13:04:28.0987 0x62640 Win FW state via NFP2: enabled ( trusted )
13:04:29.0245 0x62640 ============================================================
13:04:29.0245 0x62640 Scan finished
13:04:29.0245 0x62640 ============================================================
13:04:29.0255 0x5ce40 Detected object count: 0
13:04:29.0255 0x5ce40 Actual detected object count: 0