|
Log-Analyse und Auswertung: System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-(Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
23.03.2011, 22:35 | #16 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( So war erfolgreich |
24.03.2011, 08:56 | #17 |
/// Winkelfunktion /// TB-Süch-Tiger™ | System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Dann bitte jetzt CF ausführen:
__________________ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ |
24.03.2011, 20:44 | #18 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( So gemacht das hier ist rausgekommen:
__________________Combofix Logfile: Code:
ATTFilter ComboFix 11-03-24.01 - media 24.03.2011 20:26:10.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3066.1595 [GMT 1:00] ausgeführt von:: c:\users\media\Desktop\Cofi.exe.exe AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\directory\CyberGate c:\program files\AutocompletePro c:\program files\AutocompletePro\AutocompletePro.dll c:\program files\AutocompletePro\chrome\autocompleteprochrome.crx c:\program files\AutocompletePro\FireFoxExtension.exe c:\program files\AutocompletePro\InstTracker.exe c:\program files\AutocompletePro\support@predictad.com\chrome.manifest c:\program files\AutocompletePro\support@predictad.com\chrome\content\browserOverlay.xul c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.js c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.xul c:\program files\AutocompletePro\support@predictad.com\chrome\content\utils.js c:\program files\AutocompletePro\support@predictad.com\defaults\preferences\predictad.js c:\program files\AutocompletePro\support@predictad.com\install.rdf c:\program files\AutocompletePro\unins000.dat c:\program files\AutocompletePro\unins000.exe c:\program files\BPK c:\program files\BPK\bpk.chm c:\program files\FunWebProducts c:\program files\MyWebSearch c:\program files\MyWebSearch\bar\Settings\s_pid.dat c:\programdata\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye Webcam Video Class Camera c:\programdata\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye Webcam Video Class Camera \Uninstall.lnk c:\users\Gast\AppData\Roaming\.# c:\users\Gast\AppData\Roaming\.#\MBX@12E0@1DC2928.### c:\users\Gast\AppData\Roaming\.#\MBX@12E0@1DC2958.### c:\users\Gast\AppData\Roaming\.#\MBX@12E0@1DC2988.### c:\users\Gast\AppData\Roaming\.#\MBX@620@1D52928.### c:\users\Gast\AppData\Roaming\.#\MBX@620@1D52958.### c:\users\Gast\AppData\Roaming\.#\MBX@620@1D52988.### c:\users\Gast\AppData\Roaming\.#\MBX@6D4@1DE2928.### c:\users\Gast\AppData\Roaming\.#\MBX@6D4@1DE2958.### c:\users\Gast\AppData\Roaming\.#\MBX@6D4@1DE2988.### c:\users\Gast\AppData\Roaming\.#\MBX@C10@1CE2928.### c:\users\Gast\AppData\Roaming\.#\MBX@C10@1CE2958.### c:\users\Gast\AppData\Roaming\.#\MBX@C10@1CE2988.### c:\users\Gast\AppData\Roaming\.#\MBX@D44@1DC2928.### c:\users\Gast\AppData\Roaming\.#\MBX@D44@1DC2958.### c:\users\Gast\AppData\Roaming\.#\MBX@D44@1DC2988.### c:\users\Gast\AppData\Roaming\.#\MBX@E3C@1782928.### c:\users\Gast\AppData\Roaming\.#\MBX@E3C@1782958.### c:\users\Gast\AppData\Roaming\.#\MBX@E3C@1782988.### c:\users\Gast\AppData\Roaming\.#\MBX@E98@742928.### c:\users\Gast\AppData\Roaming\.#\MBX@E98@742958.### c:\users\Gast\AppData\Roaming\.#\MBX@E98@742988.### c:\users\Gast\AppData\Roaming\.#\MBX@F6C@1D72928.### c:\users\Gast\AppData\Roaming\.#\MBX@F6C@1D72958.### c:\users\Gast\AppData\Roaming\.#\MBX@F6C@1D72988.### c:\users\media\AppData\Local\lame_enc.dll c:\users\media\AppData\Local\no23xwrapper.dll c:\users\media\AppData\Local\ogg.dll c:\users\media\AppData\Local\vorbis.dll c:\users\media\AppData\Local\vorbisenc.dll c:\users\media\AppData\Local\vorbisfile.dll c:\users\media\AppData\Roaming\.# c:\users\media\AppData\Roaming\.#\MBX@1D44@1CE2928.### c:\users\media\AppData\Roaming\.#\MBX@1D44@1CE2958.### c:\users\media\AppData\Roaming\.#\MBX@1D44@1CE2988.### c:\users\media\AppData\Roaming\addons.dat c:\users\media\AppData\Roaming\apocalyps32.exe c:\users\media\AppData\Roaming\Desktopicon c:\users\media\AppData\Roaming\Desktopicon\config.ini c:\users\media\AppData\Roaming\Desktopicon\eBayShortcuts.exe c:\users\media\AppData\Roaming\Sysutils_Update c:\users\media\AppData\Roaming\Sysutils_Update\tmp.exe . . ((((((((((((((((((((((( Dateien erstellt von 2011-02-24 bis 2011-03-24 )))))))))))))))))))))))))))))) . . 2011-03-24 19:36 . 2011-03-24 19:36 -------- d-----w- c:\users\Gast\AppData\Local\temp 2011-03-24 19:36 . 2011-03-24 19:36 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-03-23 21:06 . 2011-03-23 21:06 -------- d-----w- C:\_OTL 2011-03-23 21:03 . 2011-03-23 21:03 -------- d-----w- c:\users\media\AppData\Roaming\Avira 2011-03-22 15:04 . 2011-02-11 06:54 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8A11E4BD-7B53-4D30-B3A6-11E834AD6D7A}\mpengine.dll 2011-03-21 19:47 . 2011-03-21 19:47 -------- d-----w- c:\users\media\AppData\Roaming\Malwarebytes 2011-03-21 19:47 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-21 19:47 . 2011-03-21 19:47 -------- d-----w- c:\programdata\Malwarebytes 2011-03-21 19:47 . 2011-03-21 19:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-03-21 19:47 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-03-09 20:18 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll 2011-03-09 20:18 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll 2011-03-09 20:18 . 2010-12-29 18:28 429056 ----a-w- c:\windows\system32\EncDec.dll 2011-03-09 20:18 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax 2011-03-09 20:18 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll 2011-03-09 20:18 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe 2011-03-08 18:23 . 2011-03-24 19:35 -------- d-----w- C:\directory 2011-03-05 10:27 . 2011-03-05 10:27 -------- d-----w- c:\users\media\AppData\Roaming\Modelchance_38227BF2 2011-02-25 22:54 . 2011-02-25 22:54 -------- d-----w- c:\program files\Microsoft Silverlight . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-16 16:09 . 2010-01-05 16:58 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-02-02 16:11 . 2010-01-06 12:38 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-01-20 16:37 . 2011-02-09 13:27 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-01-20 16:08 . 2011-02-09 13:27 478720 ----a-w- c:\windows\system32\dxgi.dll 2011-01-20 16:08 . 2011-02-09 13:27 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2011-01-20 16:08 . 2011-02-09 13:27 189952 ----a-w- c:\windows\system32\d3d10core.dll 2011-01-20 16:08 . 2011-02-09 13:27 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2011-01-20 16:08 . 2011-02-09 13:27 1029120 ----a-w- c:\windows\system32\d3d10.dll 2011-01-20 16:07 . 2011-02-09 13:27 37376 ----a-w- c:\windows\system32\cdd.dll 2011-01-20 16:07 . 2011-02-09 13:27 258048 ----a-w- c:\windows\system32\winspool.drv 2011-01-20 16:07 . 2011-02-09 13:27 586240 ----a-w- c:\windows\system32\stobject.dll 2011-01-20 16:06 . 2011-02-09 13:27 2873344 ----a-w- c:\windows\system32\mf.dll 2011-01-20 16:06 . 2011-02-09 13:27 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 16:04 . 2011-02-09 13:27 209920 ----a-w- c:\windows\system32\mfplat.dll 2011-01-20 16:04 . 2011-02-09 13:27 98816 ----a-w- c:\windows\system32\mfps.dll 2011-01-20 14:28 . 2011-02-09 13:27 1554432 ----a-w- c:\windows\system32\xpsservices.dll 2011-01-20 14:27 . 2011-02-09 13:27 876032 ----a-w- c:\windows\system32\XpsPrint.dll 2011-01-20 14:26 . 2011-02-09 13:27 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 14:25 . 2011-02-09 13:27 847360 ----a-w- c:\windows\system32\OpcServices.dll 2011-01-20 14:24 . 2011-02-09 13:27 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2011-01-20 14:24 . 2011-02-09 13:27 135680 ----a-w- c:\windows\system32\XpsRasterService.dll 2011-01-20 14:15 . 2011-02-09 13:27 979456 ----a-w- c:\windows\system32\MFH264Dec.dll 2011-01-20 14:14 . 2011-02-09 13:27 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll 2011-01-20 14:14 . 2011-02-09 13:27 302592 ----a-w- c:\windows\system32\mfmp4src.dll 2011-01-20 14:14 . 2011-02-09 13:27 261632 ----a-w- c:\windows\system32\mfreadwrite.dll 2011-01-20 14:12 . 2011-02-09 13:27 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2011-01-20 14:11 . 2011-02-09 13:27 486400 ----a-w- c:\windows\system32\d3d10level9.dll 2011-01-20 13:47 . 2011-02-09 13:27 683008 ----a-w- c:\windows\system32\d2d1.dll 2011-01-20 13:44 . 2011-02-09 13:27 1068544 ----a-w- c:\windows\system32\DWrite.dll 2011-01-20 13:44 . 2011-02-09 13:27 797184 ----a-w- c:\windows\system32\FntCache.dll 2011-01-08 08:47 . 2011-02-09 13:27 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-01-08 06:28 . 2011-02-09 13:27 292352 ----a-w- c:\windows\system32\atmfd.dll 2010-12-31 13:57 . 2011-02-09 13:28 2039808 ----a-w- c:\windows\system32\win32k.sys 2010-12-28 15:55 . 2011-01-12 07:39 413696 ----a-w- c:\windows\system32\odbc32.dll 2010-07-22 21:40 . 2010-08-10 19:10 2944904 ----a-w- c:\program files\Common Files\AskToolbarInstaller.exe 2011-03-18 17:56 . 2011-03-21 19:03 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2010-07-02 21:22 . 2009-12-07 13:04 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2009-05-14 21:02 120104 ----a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656] "BitTorrent DNA"="c:\users\media\Program Files\DNA\btdna.exe" [2009-10-19 323392] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-01-27 61440] "AmIcoSinglun"="c:\program files\AmIcoSingLun\AmIcoSinglun.exe" [2008-10-24 237568] "PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-05 1410344] "BackupManagerTray"="c:\program files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-04-11 249600] "Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2009-06-23 440864] "EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-05-13 199464] "mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-05-14 345384] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-02 30192] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392] "PLFSetL"="c:\windows\\PLFSetL.exe" [2007-07-05 94208] "Monitor"="c:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "LManager"="c:\program files\Launch Manager\LManager.exe" [2009-02-24 870920] . c:\users\media\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime "AVMWlanClient"=c:\program files\avmwlanstick\wlangui.exe "BRAVIS-{DC0F6114-52CD-420E-BAEB-ECC5BFB0B110}"="c:\program files\BRAVIS\Galaxee 4free\bravis.exe" --autostart "PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" "ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" "CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate1ca3efc34f091bb;Google Update Service (gupdate1ca3efc34f091bb);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-26 133104] R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2009-05-07 4352] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712] R3 fwlanusbn;FRITZ!WLAN N;c:\windows\system32\DRIVERS\fwlanusbn.sys [2009-05-07 440832] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-02 30192] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-10-11 721904] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2008-12-04 19504] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2008-12-04 16432] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2008-12-04 59952] S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};Power Control [2009/07/24 15:46];c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2009-09-18 16:23 87536] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-08-02 135336] S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2009-05-20 75048] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-06-23 707104] S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952] S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-05-14 305448] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-04-11 61184] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632] S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-05-21 173352] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608] S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-09-04 223232] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Inhalt des "geplante Tasks" Ordners . 2011-03-12 c:\windows\Tasks\1-Klick-Wartung.job - c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-03 18:27] . 2011-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-26 22:53] . 2011-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-26 22:53] . 2011-03-23 c:\windows\Tasks\User_Feed_Synchronization-{95697187-C0EB-4020-8E2F-0247A6A8063B}.job - c:\windows\system32\msfeedssync.exe [2011-02-09 04:47] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.hba-crew.to mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0709&m=aspire_7735 uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Free YouTube Download - c:\users\media\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\media\AppData\Roaming\Mozilla\Firefox\Profiles\980ntedn.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2843456&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Bigpoint Games DE Customized Web Search FF - prefs.js: browser.startup.homepage - www.google.de FF - prefs.js: keyword.URL - hxxp://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q= FF - user.js: yahoo.homepage.dontask - true FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: content.max.tokenizing.time - 200000 FF - user.js: content.notify.interval - 100000 FF - user.js: content.switch.threshold - 650000 FF - user.js: nglayout.initialpaint.delay - 300 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) HKCU-Run-apocalyps32 - c:\users\media\AppData\Roaming\apocalyps32.exe SafeBoot-mcmscsvc SafeBoot-MCODS AddRemove-AutocompletePro3_is1 - c:\program files\AutocompletePro\unins000.exe AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2011-03-24 20:36 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}] "ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Zeit der Fertigstellung: 2011-03-24 20:42:31 ComboFix-quarantined-files.txt 2011-03-24 19:42 . Vor Suchlauf: 24 Verzeichnis(se), 252.651.864.064 Bytes frei Nach Suchlauf: 29 Verzeichnis(se), 251.538.563.072 Bytes frei . - - End Of File - - 5BC9EC5CD886CBF53CCE98F89B5FCD60 |
24.03.2011, 21:04 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html
__________________ Logfiles bitte immer in CODE-Tags posten |
24.03.2011, 21:24 | #20 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( So war zwar bisschen anders als in der Anleitung aber hier ist die log: 2011/03/24 21:19:13.0786 4292 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28 2011/03/24 21:19:14.0179 4292 ================================================================================ 2011/03/24 21:19:14.0179 4292 SystemInfo: 2011/03/24 21:19:14.0180 4292 2011/03/24 21:19:14.0180 4292 OS Version: 6.0.6002 ServicePack: 2.0 2011/03/24 21:19:14.0180 4292 Product type: Workstation 2011/03/24 21:19:14.0180 4292 ComputerName: MEDIA-PC 2011/03/24 21:19:14.0180 4292 UserName: media 2011/03/24 21:19:14.0180 4292 Windows directory: C:\Windows 2011/03/24 21:19:14.0180 4292 System windows directory: C:\Windows 2011/03/24 21:19:14.0180 4292 Processor architecture: Intel x86 2011/03/24 21:19:14.0180 4292 Number of processors: 2 2011/03/24 21:19:14.0180 4292 Page size: 0x1000 2011/03/24 21:19:14.0180 4292 Boot type: Normal boot 2011/03/24 21:19:14.0180 4292 ================================================================================ 2011/03/24 21:19:19.0474 4292 Initialize success 2011/03/24 21:19:34.0964 5036 ================================================================================ 2011/03/24 21:19:34.0964 5036 Scan started 2011/03/24 21:19:34.0964 5036 Mode: Manual; 2011/03/24 21:19:34.0964 5036 ================================================================================ 2011/03/24 21:19:35.0613 5036 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/03/24 21:19:36.0191 5036 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2011/03/24 21:19:36.0817 5036 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2011/03/24 21:19:37.0056 5036 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2011/03/24 21:19:37.0354 5036 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2011/03/24 21:19:37.0864 5036 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys 2011/03/24 21:19:38.0020 5036 AgereSoftModem (38325c6aa8eae011897d61ce48ec6435) C:\Windows\system32\DRIVERS\AGRSM.sys 2011/03/24 21:19:38.0262 5036 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2011/03/24 21:19:38.0565 5036 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/03/24 21:19:38.0970 5036 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2011/03/24 21:19:39.0330 5036 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2011/03/24 21:19:39.0977 5036 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2011/03/24 21:19:40.0355 5036 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2011/03/24 21:19:40.0931 5036 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 2011/03/24 21:19:41.0262 5036 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2011/03/24 21:19:41.0671 5036 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2011/03/24 21:19:42.0002 5036 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/03/24 21:19:42.0101 5036 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/03/24 21:19:42.0369 5036 athr (acdb46b1a467752a2f280c68c8461556) C:\Windows\system32\DRIVERS\athr.sys 2011/03/24 21:19:42.0613 5036 atikmdag (6f2cc6403012375385d556bf39382b74) C:\Windows\system32\DRIVERS\atikmdag.sys 2011/03/24 21:19:42.0795 5036 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys 2011/03/24 21:19:42.0924 5036 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys 2011/03/24 21:19:43.0065 5036 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\Windows\system32\DRIVERS\avgntflt.sys 2011/03/24 21:19:43.0177 5036 avipbb (5fedef54757b34fb611b9ec8fb399364) C:\Windows\system32\DRIVERS\avipbb.sys 2011/03/24 21:19:43.0277 5036 avmeject (263cf9d248fd5e020a1333ed4f7eaa88) C:\Windows\system32\drivers\avmeject.sys 2011/03/24 21:19:43.0386 5036 b57nd60x (502f1c30bd50b32d00ce4dcaecc3d3c7) C:\Windows\system32\DRIVERS\b57nd60x.sys 2011/03/24 21:19:43.0493 5036 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/03/24 21:19:43.0629 5036 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2011/03/24 21:19:43.0739 5036 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2011/03/24 21:19:43.0772 5036 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/03/24 21:19:43.0855 5036 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/03/24 21:19:43.0990 5036 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/03/24 21:19:44.0062 5036 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/03/24 21:19:44.0143 5036 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/03/24 21:19:44.0195 5036 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/03/24 21:19:44.0313 5036 BthEnum (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys 2011/03/24 21:19:44.0428 5036 BTHMODEM (9a966a8e86d1771911ae34a20d11bff3) C:\Windows\system32\DRIVERS\bthmodem.sys 2011/03/24 21:19:44.0495 5036 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys 2011/03/24 21:19:44.0596 5036 BTHPORT (5a3abaa2f8eece7aefb942773766e3db) C:\Windows\system32\Drivers\BTHport.sys 2011/03/24 21:19:44.0716 5036 BTHUSB (94e2941280e3756a5e0bcb467865c43a) C:\Windows\system32\Drivers\BTHUSB.sys 2011/03/24 21:19:44.0929 5036 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/03/24 21:19:45.0068 5036 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/03/24 21:19:45.0126 5036 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2011/03/24 21:19:45.0198 5036 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/03/24 21:19:45.0367 5036 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/03/24 21:19:45.0403 5036 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2011/03/24 21:19:45.0480 5036 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/03/24 21:19:45.0572 5036 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2011/03/24 21:19:45.0624 5036 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2011/03/24 21:19:45.0810 5036 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys 2011/03/24 21:19:46.0001 5036 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/03/24 21:19:46.0094 5036 DKbFltr (73baf270d24fe726b9cd7f80bb17a23d) C:\Windows\system32\DRIVERS\DKbFltr.sys 2011/03/24 21:19:46.0248 5036 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/03/24 21:19:46.0325 5036 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 2011/03/24 21:19:46.0444 5036 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/03/24 21:19:46.0604 5036 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/03/24 21:19:46.0670 5036 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2011/03/24 21:19:46.0792 5036 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2011/03/24 21:19:46.0886 5036 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/03/24 21:19:47.0021 5036 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/03/24 21:19:47.0081 5036 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2011/03/24 21:19:47.0105 5036 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/03/24 21:19:47.0139 5036 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/03/24 21:19:47.0241 5036 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/03/24 21:19:47.0350 5036 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/03/24 21:19:47.0490 5036 FsUsbExDisk (cbe5f69a5e5b918225f420ba748f3742) C:\Windows\system32\FsUsbExDisk.SYS 2011/03/24 21:19:47.0548 5036 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/03/24 21:19:47.0587 5036 fwlanusbn (161f20685595eddc06c0ea1f1d7bc92b) C:\Windows\system32\DRIVERS\fwlanusbn.sys 2011/03/24 21:19:47.0692 5036 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2011/03/24 21:19:47.0896 5036 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 2011/03/24 21:19:47.0973 5036 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/03/24 21:19:48.0082 5036 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/03/24 21:19:48.0122 5036 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/03/24 21:19:48.0274 5036 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/03/24 21:19:48.0351 5036 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2011/03/24 21:19:48.0425 5036 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/03/24 21:19:48.0530 5036 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2011/03/24 21:19:48.0601 5036 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/03/24 21:19:48.0700 5036 iaStor (71ecc07bc7c5e24c3dd01d8a29a24054) C:\Windows\system32\DRIVERS\iaStor.sys 2011/03/24 21:19:48.0743 5036 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2011/03/24 21:19:48.0863 5036 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/03/24 21:19:48.0939 5036 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/03/24 21:19:48.0988 5036 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/03/24 21:19:49.0061 5036 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/03/24 21:19:49.0132 5036 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2011/03/24 21:19:49.0192 5036 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/03/24 21:19:49.0281 5036 irda (e50a95179211b12946f7e035d60af560) C:\Windows\system32\DRIVERS\irda.sys 2011/03/24 21:19:49.0321 5036 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/03/24 21:19:49.0375 5036 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2011/03/24 21:19:49.0437 5036 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/03/24 21:19:49.0496 5036 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/03/24 21:19:49.0559 5036 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/03/24 21:19:49.0654 5036 k57nd60x (eac21e8014c7e6ee341afffb7e2bbd54) C:\Windows\system32\DRIVERS\k57nd60x.sys 2011/03/24 21:19:49.0752 5036 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/03/24 21:19:49.0849 5036 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/03/24 21:19:49.0966 5036 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/03/24 21:19:50.0095 5036 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys 2011/03/24 21:19:50.0145 5036 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/03/24 21:19:50.0246 5036 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2011/03/24 21:19:50.0353 5036 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2011/03/24 21:19:50.0443 5036 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2011/03/24 21:19:50.0525 5036 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/03/24 21:19:50.0627 5036 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2011/03/24 21:19:50.0697 5036 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2011/03/24 21:19:50.0786 5036 mfeavfk (bafdd5e28baea99d7f4772af2f5ec7ee) C:\Windows\system32\drivers\mfeavfk.sys 2011/03/24 21:19:50.0853 5036 mfebopk (1d003e3056a43d881597d6763e83b943) C:\Windows\system32\drivers\mfebopk.sys 2011/03/24 21:19:50.0929 5036 mfehidk (3f138a1c8a0659f329f242d1e389b2cf) C:\Windows\system32\drivers\mfehidk.sys 2011/03/24 21:19:50.0994 5036 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\Windows\system32\drivers\mferkdk.sys 2011/03/24 21:19:51.0081 5036 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\Windows\system32\drivers\mfesmfk.sys 2011/03/24 21:19:51.0141 5036 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/03/24 21:19:51.0187 5036 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/03/24 21:19:51.0281 5036 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/03/24 21:19:51.0341 5036 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/03/24 21:19:51.0370 5036 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/03/24 21:19:51.0468 5036 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2011/03/24 21:19:51.0520 5036 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/03/24 21:19:51.0555 5036 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/03/24 21:19:51.0672 5036 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/03/24 21:19:51.0707 5036 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/03/24 21:19:51.0733 5036 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/03/24 21:19:51.0812 5036 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/03/24 21:19:51.0861 5036 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 2011/03/24 21:19:51.0948 5036 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2011/03/24 21:19:52.0007 5036 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/03/24 21:19:52.0067 5036 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/03/24 21:19:52.0151 5036 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/03/24 21:19:52.0196 5036 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/03/24 21:19:52.0222 5036 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/03/24 21:19:52.0337 5036 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/03/24 21:19:52.0420 5036 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/03/24 21:19:52.0486 5036 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/03/24 21:19:52.0577 5036 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/03/24 21:19:52.0647 5036 mwlPSDFilter (2de94e435c3efde58c7b1856d4f20724) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys 2011/03/24 21:19:52.0684 5036 mwlPSDNServ (61920a7146eed3d903dbbb8ec295af76) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys 2011/03/24 21:19:52.0722 5036 mwlPSDVDisk (e0f49721e68ebd2983e84c44fada6665) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys 2011/03/24 21:19:52.0818 5036 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/03/24 21:19:52.0946 5036 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/03/24 21:19:53.0039 5036 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/03/24 21:19:53.0091 5036 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/03/24 21:19:53.0170 5036 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/03/24 21:19:53.0263 5036 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/03/24 21:19:53.0337 5036 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/03/24 21:19:53.0440 5036 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/03/24 21:19:53.0504 5036 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/03/24 21:19:53.0608 5036 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/03/24 21:19:53.0675 5036 NSCIRDA (6d8d2e5652fc2442c810c5d8be784148) C:\Windows\system32\DRIVERS\nscirda.sys 2011/03/24 21:19:53.0716 5036 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/03/24 21:19:53.0814 5036 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/03/24 21:19:53.0947 5036 NTIDrvr (6dcaa65f49ef3b97a5cffc0cb5de1c2f) C:\Windows\system32\Drivers\NTIDrvr.sys 2011/03/24 21:19:54.0022 5036 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/03/24 21:19:54.0069 5036 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/03/24 21:19:54.0123 5036 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2011/03/24 21:19:54.0191 5036 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2011/03/24 21:19:54.0272 5036 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2011/03/24 21:19:54.0405 5036 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/03/24 21:19:54.0502 5036 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/03/24 21:19:54.0602 5036 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/03/24 21:19:54.0659 5036 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/03/24 21:19:54.0788 5036 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/03/24 21:19:54.0864 5036 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 2011/03/24 21:19:54.0934 5036 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys 2011/03/24 21:19:55.0039 5036 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/03/24 21:19:55.0225 5036 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/03/24 21:19:55.0269 5036 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2011/03/24 21:19:55.0429 5036 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/03/24 21:19:55.0496 5036 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\Windows\system32\Drivers\PxHelp20.sys 2011/03/24 21:19:55.0617 5036 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2011/03/24 21:19:55.0741 5036 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/03/24 21:19:55.0780 5036 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/03/24 21:19:55.0834 5036 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/03/24 21:19:55.0900 5036 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/03/24 21:19:56.0001 5036 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/03/24 21:19:56.0091 5036 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/03/24 21:19:56.0185 5036 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/03/24 21:19:56.0247 5036 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/03/24 21:19:56.0308 5036 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2011/03/24 21:19:56.0398 5036 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/03/24 21:19:56.0477 5036 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/03/24 21:19:56.0637 5036 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys 2011/03/24 21:19:56.0688 5036 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/03/24 21:19:56.0796 5036 RT73 (da4980fad2b7d86d6ed8e35e3874f65e) C:\Windows\system32\DRIVERS\rt73.sys 2011/03/24 21:19:56.0955 5036 RTSTOR (9b09f336de36a7a6ca871de8a7847b65) C:\Windows\system32\drivers\RTSTOR.SYS 2011/03/24 21:19:57.0001 5036 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/03/24 21:19:57.0130 5036 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys 2011/03/24 21:19:57.0167 5036 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/03/24 21:19:57.0284 5036 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/03/24 21:19:57.0338 5036 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/03/24 21:19:57.0429 5036 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/03/24 21:19:57.0536 5036 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2011/03/24 21:19:57.0576 5036 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2011/03/24 21:19:57.0659 5036 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2011/03/24 21:19:57.0697 5036 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/03/24 21:19:57.0790 5036 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2011/03/24 21:19:57.0835 5036 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2011/03/24 21:19:57.0864 5036 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2011/03/24 21:19:58.0005 5036 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/03/24 21:19:58.0299 5036 SNPSTD3 (11bb0e11d42cc3a43d741d9b30839be1) C:\Windows\system32\DRIVERS\snpstd3.sys 2011/03/24 21:19:58.0580 5036 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/03/24 21:19:58.0700 5036 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\Windows\system32\Drivers\sptd.sys 2011/03/24 21:19:58.0701 5036 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9 2011/03/24 21:19:58.0712 5036 sptd - detected Locked file (1) 2011/03/24 21:19:58.0855 5036 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys 2011/03/24 21:19:58.0872 5036 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys 2011/03/24 21:19:58.0890 5036 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys 2011/03/24 21:19:58.0925 5036 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys 2011/03/24 21:19:59.0042 5036 ss_bus (54946449a0eb74915a4bb34f7ee51a5a) C:\Windows\system32\DRIVERS\ss_bus.sys 2011/03/24 21:19:59.0074 5036 ss_mdfl (4450bc0b2e9d7d9b90e3c3de4ea00a78) C:\Windows\system32\DRIVERS\ss_mdfl.sys 2011/03/24 21:19:59.0108 5036 ss_mdm (30b8d0dd01ead1243f329caf7d7d1517) C:\Windows\system32\DRIVERS\ss_mdm.sys 2011/03/24 21:19:59.0248 5036 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/03/24 21:19:59.0294 5036 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/03/24 21:19:59.0324 5036 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/03/24 21:19:59.0422 5036 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/03/24 21:19:59.0478 5036 SynTP (aee6e411a915f50101895ba8dc5c15d4) C:\Windows\system32\DRIVERS\SynTP.sys 2011/03/24 21:19:59.0629 5036 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys 2011/03/24 21:19:59.0762 5036 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys 2011/03/24 21:19:59.0894 5036 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2011/03/24 21:19:59.0938 5036 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/03/24 21:20:00.0035 5036 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/03/24 21:20:00.0110 5036 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/03/24 21:20:00.0246 5036 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/03/24 21:20:00.0314 5036 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/03/24 21:20:00.0432 5036 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/03/24 21:20:00.0469 5036 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/03/24 21:20:00.0569 5036 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2011/03/24 21:20:00.0608 5036 UBHelper (f763e070843ee2803de1395002b42938) C:\Windows\system32\drivers\UBHelper.sys 2011/03/24 21:20:00.0743 5036 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/03/24 21:20:00.0804 5036 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2011/03/24 21:20:00.0905 5036 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2011/03/24 21:20:01.0019 5036 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/03/24 21:20:01.0073 5036 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/03/24 21:20:01.0161 5036 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/03/24 21:20:01.0255 5036 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/03/24 21:20:01.0292 5036 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/03/24 21:20:01.0436 5036 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/03/24 21:20:01.0519 5036 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/03/24 21:20:01.0555 5036 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/03/24 21:20:01.0655 5036 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2011/03/24 21:20:01.0734 5036 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/03/24 21:20:01.0837 5036 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/03/24 21:20:01.0875 5036 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2011/03/24 21:20:01.0997 5036 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/03/24 21:20:02.0045 5036 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/03/24 21:20:02.0125 5036 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2011/03/24 21:20:02.0161 5036 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2011/03/24 21:20:02.0215 5036 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2011/03/24 21:20:02.0327 5036 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/03/24 21:20:02.0404 5036 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/03/24 21:20:02.0455 5036 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/03/24 21:20:02.0563 5036 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2011/03/24 21:20:02.0622 5036 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/03/24 21:20:02.0711 5036 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/03/24 21:20:02.0726 5036 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/03/24 21:20:02.0773 5036 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2011/03/24 21:20:02.0893 5036 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/03/24 21:20:03.0069 5036 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/03/24 21:20:03.0131 5036 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/03/24 21:20:03.0232 5036 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/03/24 21:20:03.0356 5036 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl 2011/03/24 21:20:03.0556 5036 ================================================================================ 2011/03/24 21:20:03.0556 5036 Scan finished 2011/03/24 21:20:03.0556 5036 ================================================================================ 2011/03/24 21:20:03.0569 0560 Detected object count: 1 2011/03/24 21:20:20.0130 0560 Locked file(sptd) - User select action: Skip 2011/03/24 21:21:21.0726 5988 Deinitialize success |
24.03.2011, 22:10 | #21 |
/// Winkelfunktion /// TB-Süch-Tiger™ | System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________ --> System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( |
25.03.2011, 20:09 | #22 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Sooo hier die 3 Log's: GMER Logfile: Code:
ATTFilter GMER 1.0.15.15570 - hxxp://www.gmer.net Rootkit scan 2011-03-25 19:37:13 Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB4O Running: 2r5eroi9.exe; Driver: C:\Users\media\AppData\Local\Temp\kwdoypod.sys ---- System - GMER 1.0.15 ---- INT 0x72 ? 875EBF00 INT 0x72 ? 875EBF00 INT 0x72 ? 875EBF00 INT 0x72 ? 875EBF00 INT 0x82 ? 875EBF00 INT 0x92 ? 875EBF00 INT 0xA2 ? 85923BF8 INT 0xB2 ? 875EBF00 ---- Kernel code sections - GMER 1.0.15 ---- ? System32\Drivers\spjp.sys Das System kann den angegebenen Pfad nicht finden. ! .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EE0E000, 0x24DD0C, 0xE8000020] .text USBPORT.SYS!DllUnload 8F3EE41B 5 Bytes JMP 875EB4E0 .text ad9qukby.SYS 8F583000 22 Bytes [82, 33, 9D, 82, 6C, 32, 9D, ...] .text ad9qukby.SYS 8F583017 137 Bytes [00, 32, B7, 79, 80, 3D, B5, ...] .text ad9qukby.SYS 8F5830A1 43 Bytes [B0, 6B, 82, 74, A6, 65, 82, ...] .text ad9qukby.SYS 8F5830CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...] .text ad9qukby.SYS 8F5830DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...] .text ... .text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0x9EA6C300, 0x3B6D8, 0xE8000020] .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x9EAAF300, 0x1BEE, 0xE8000020] .text C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl section is writeable [0x9EBA9000, 0x2892, 0xE8000020] .vmp2 C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl entry point in ".vmp2" section [0x9EBCC050] ? C:\Windows\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. ! ? C:\Users\media\AppData\Local\Temp\catchme.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Windows\explorer.exe[3020] SHELL32.dll!SHGetFolderPathAndSubDirW + 81C5 75A5B37C 4 Bytes [20, 28, 00, 10] {AND [EAX], CH; ADD [EAX], DL} .text C:\Windows\explorer.exe[3020] SHELL32.dll!ShellExecuteExW + 18B7 75A8DA0C 4 Bytes [10, 1B, 00, 10] {ADC [EBX], BL; ADD [EAX], DL} ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806916D6] \SystemRoot\System32\Drivers\spjp.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80691042] \SystemRoot\System32\Drivers\spjp.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80691800] \SystemRoot\System32\Drivers\spjp.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806910C0] \SystemRoot\System32\Drivers\spjp.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069113E] \SystemRoot\System32\Drivers\spjp.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A0E9C] \SystemRoot\System32\Drivers\spjp.sys IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortNotification] CC358B04 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortWritePortUchar] 838F5A8F IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 100D8BA5 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F8F5A60 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortStallExecution] 54771129 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortRequestCallback] 8B55CC00 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortMoveMemory] 8B108910 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortInitialize] B18D0502 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8 IAT \SystemRoot\System32\Drivers\ad9qukby.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[2388] @ C:\Windows\system32\SHELL32.dll [USER32.dll!ExitWindowsEx] [01B81210] C:\Program Files\NewTech Infosystems\Acer Backup Manager\Pehook.dll (Backup Manager Module/NewTech Infosystems, Inc.) IAT C:\Windows\explorer.exe[3020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [10002A00] C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (PSD DragDrop Protection/Egis Technology Inc.) IAT C:\Windows\explorer.exe[3020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibraryAndExitThread] [10001E00] C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (PSD DragDrop Protection/Egis Technology Inc.) IAT C:\Windows\explorer.exe[3020] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [10002D50] C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (PSD DragDrop Protection/Egis Technology Inc.) IAT C:\Windows\explorer.exe[3020] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [100011D0] C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (PSD DragDrop Protection/Egis Technology Inc.) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 859261F8 Device \FileSystem\fastfat \FatCdrom 87EE9500 Device \Driver\netbt \Device\NetBT_Tcpip_{847A802C-FADB-43EC-A88C-7D478309B2B8} 87EC11F8 AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4@0023451f340a 0xE7 0xC6 0x0E 0x3B ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4@c87e75ba8b62 0x55 0x76 0x05 0x90 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4@001698fcfeaa 0x4B 0x62 0x58 0xCA ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4@001a8a9abe30 0x9A 0x54 0x96 0x73 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4@0023f126989c 0x14 0xAF 0xE5 0x63 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4@68ebae6a92a4 0x59 0x79 0x8D 0xF6 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508dd4@001a7d1181d3 0xD8 0x1E 0x21 0xD4 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001a7d1181d3 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE0 0xEA 0x67 0xF1 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC6 0x42 0x75 0x8D ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x30 0x9D 0x53 0x41 ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4@0023451f340a 0xE7 0xC6 0x0E 0x3B ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4@c87e75ba8b62 0x55 0x76 0x05 0x90 ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4@001698fcfeaa 0x4B 0x62 0x58 0xCA ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4@001a8a9abe30 0x9A 0x54 0x96 0x73 ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4@0023f126989c 0x14 0xAF 0xE5 0x63 ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4@68ebae6a92a4 0x59 0x79 0x8D 0xF6 ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd508dd4@001a7d1181d3 0xD8 0x1E 0x21 0xD4 ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001a7d1181d3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE0 0xEA 0x67 0xF1 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC6 0x42 0x75 0x8D ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x30 0x9D 0x53 0x41 ... ---- EOF - GMER 1.0.15 ---- OSAM Logfile: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 19:51:27 on 25.03.2011 OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit Default Browser: Mozilla Corporation Firefox 4.0 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [AppInit DLLs] -----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )----- "AppInit_DLLs" - "Google" - C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll [Control Panel Objects] -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "Adobe Gamma" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma.cpl "QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "ad9qukby" (ad9qukby) - "Microsoft Corporation" - C:\Windows\system32\drivers\ad9qukby.sys (Hidden registry entry, rootkit activity | File signed by Microsoft) "atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys (File found, but it contains no detailed information) "avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys "avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys "avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys "AVM Eject" (avmeject) - "AVM Berlin" - C:\Windows\System32\drivers\avmeject.sys "catchme" (catchme) - ? - C:\Users\media\AppData\Local\Temp\catchme.sys (File not found) "FsUsbExDisk" (FsUsbExDisk) - ? - C:\Windows\system32\FsUsbExDisk.SYS (File found, but it contains no detailed information) "IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys (File not found) "IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys (File not found) "IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys (File not found) "kwdoypod" (kwdoypod) - ? - C:\Users\media\AppData\Local\Temp\kwdoypod.sys (Hidden registry entry, rootkit activity | File not found) "lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys (File found, but it contains no detailed information) "mbr" (mbr) - ? - C:\Cofi.exe\mbr.sys (Hidden registry entry, rootkit activity | File not found) "McAfee Inc. mfeavfk" (mfeavfk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfeavfk.sys "McAfee Inc. mfebopk" (mfebopk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfebopk.sys "McAfee Inc. mfehidk" (mfehidk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfehidk.sys "McAfee Inc. mferkdk" (mferkdk) - "McAfee, Inc." - C:\Windows\System32\drivers\mferkdk.sys "McAfee Inc. mfesmfk" (mfesmfk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfesmfk.sys "mwlPSDFilter" (mwlPSDFilter) - "Egis Incorporated." - C:\Windows\System32\DRIVERS\mwlPSDFilter.sys "mwlPSDNServ" (mwlPSDNServ) - "Egis Incorporated." - C:\Windows\System32\DRIVERS\mwlPSDNServ.sys "mwlPSDVDisk" (mwlPSDVDisk) - "Egis Incorporated." - C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys "PCCS Mode Change Filter Driver" (pccsmcfd) - ? - C:\Windows\System32\DRIVERS\pccsmcfd.sys (File not found) "PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys "Service for HDMI" (RTHDMIAzAudService) - ? - C:\Windows\System32\drivers\RtHDMIV.sys (File not found) "Service for Realtek HD Audio (WDM)" (IntcAzAudAddService) - ? - C:\Windows\System32\drivers\RTKVHDA.sys (File not found) "sptd" (sptd) - ? - C:\Windows\System32\Drivers\sptd.sys (File not found) "ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys "UBHelper" (UBHelper) - "NewTech Infosystems Corporation" - C:\Windows\system32\drivers\UBHelper.sys "Upper Class Filter Driver" (NTIDrvr) - "NewTech Infosystems, Inc." - C:\Windows\System32\Drivers\NTIDrvr.sys [Explorer] -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll -----( HKLM\Software\Classes\Protocols\Filter )----- {807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL -----( HKLM\Software\Classes\Protocols\Handler )----- {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL {828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll {828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found) {1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found) {34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found) {0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found) {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} "DragDropProtect Class" - "Egis Technology Inc." - C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll {2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found) {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found) {00020d75-0000-0000-c000-000000000046} "lnkfile" - ? - (File not found | COM-object registry key not found) {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found) {E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found) {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll {5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} "TuneUp Shredder Shell Extension" - "TuneUp Software GmbH" - C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll {44440D00-FF19-4AFC-B765-9A0970567D97} "TuneUp Theme Extension" - "TuneUp Software GmbH" - C:\Windows\System32\uxtuneup.dll {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found) {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll {06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8100D56A-5661-482C-BEE8-AFECE305D968} "Facebook Photo Uploader 5 Control" - "The Facebook" - C:\Windows\Downloaded Program Files\PhotoUploader55.ocx / hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_23.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab {C3F79A2B-B9B4-4A66-B012-3EE46475B072} "MessengerStatsClient Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\MessengerStatsPAClient.dll / hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab {166B1BCA-3F9C-11CF-8075-444553540000} "Shockwave ActiveX Control" - "Adobe Systems, Inc." - C:\Windows\system32\Adobe\Director\SwDir.dll / hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab {5D6F45B3-9043-443D-A792-115447494D24} "UnoCtrl Class" - "Microsoft" - C:\Windows\Downloaded Program Files\GAME_UNO1.dll / hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} "ClsidExtension" - "Google Inc." - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll "ICQ7.2" - "ICQ, LLC." - C:\Program Files\ICQ7.2\ICQ.exe {5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} "Google Gears Helper" - "Google Inc." - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll {9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll {02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" - ? - (File not found | COM-object registry key not found) {0FB6A909-6086-458F-BD92-1F8EE10042A0} "{0FB6A909-6086-458F-BD92-1F8EE10042A0}" - ? - (File not found | COM-object registry key not found) {5C255C8A-E604-49b4-9D64-90988571CECB} "{5C255C8A-E604-49b4-9D64-90988571CECB}" - ? - (File not found | COM-object registry key not found) [Logon] -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "AutoStartNPSAgent" - "Samsung Electronics Co., Ltd." - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe "BitTorrent DNA" - "BitTorrent, Inc." - "C:\Users\media\Program Files\DNA\btdna.exe" "DAEMON Tools Lite" - "DT Soft Ltd" - "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun -----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )----- "StartupPrograms" - ? - rdpclip (File not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "Acer ePower Management" - "Acer Incorporated" - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe "Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "AmIcoSinglun" - "AlcorMicro Co., Ltd." - C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe "avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min "BackupManagerTray" - "NewTech Infosystems, Inc." - "C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -k "DivXUpdate" - ? - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW "EgisTecLiveUpdate" - "Egis Technology Inc." - "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" "Google Desktop Search" - "Google" - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup "LManager" - "Dritek System Inc." - C:\Program Files\Launch Manager\LManager.exe "mwlDaemon" - "Egis Technology Inc." - C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe "PLFSetI" - ? - C:\Windows\PLFSetI.exe "QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime "StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" "WinampAgent" - ? - "C:\Program Files\Winamp\winampa.exe" (File found, but it contains no detailed information) [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "@%SystemRoot%\System32\TuneUpDefragService.exe,-1" (TuneUp.Defrag) - "TuneUp Software GmbH" - C:\Windows\System32\TuneUpDefragService.exe "@%SystemRoot%\System32\uxtuneup.dll,-4096" (UxTuneUp) - "TuneUp Software GmbH" - C:\Windows\System32\uxtuneup.dll "@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe "Acer ePower Service" (ePowerSvc) - "Acer Incorporated" - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe "Adobe LM Service" (Adobe LM Service) - "Adobe Systems" - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe "Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe "Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe "AVM WLAN Connection Service" (AVM WLAN Connection Service) - "AVM Berlin" - C:\Program Files\avmwlanstick\WlanNetService.exe "CLHNService" (CLHNService) - ? - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe "FsUsbExService" (FsUsbExService) - "Teruten" - C:\Windows\system32\FsUsbExService.Exe "Google Desktop Manager 5.9.1005.12335" (GoogleDesktopManager-051210-111108) - "Google" - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe "Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe "Google Update Service (gupdate1ca3efc34f091bb)" (gupdate1ca3efc34f091bb) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe "HP Network Devices Support" (HPSLPSVC) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL "InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE "MyWinLocker Service" (MWLService) - "Egis Technology Inc." - C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe "Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll "NTI Backup Now 5 Backup Service" (NTIBackupSvc) - "NewTech InfoSystems, Inc." - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe "NTI Backup Now 5 Scheduler Service" (NTISchedulerSvc) - "NewTech Infosystems, Inc." - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe "NTI IScheduleSvc" (NTI IScheduleSvc) - "NewTech Infosystems, Inc." - C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll "TeamViewer 5" (TeamViewer5) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 2 (build 6002), 32-bit Base Board Manufacturer: Acer BIOS Manufacturer: Phoenix Technologies LTD System Manufacturer: Acer System Product Name: Aspire 7735 Logical Drives Mask: 0x0000001c Kernel Drivers (total 163): 0x82612000 \SystemRoot\system32\ntkrnlpa.exe 0x829CC000 \SystemRoot\system32\hal.dll 0x80401000 \SystemRoot\system32\kdcom.dll 0x80408000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x80478000 \SystemRoot\system32\PSHED.dll 0x80489000 \SystemRoot\system32\BOOTVID.dll 0x80491000 \SystemRoot\system32\CLFS.SYS 0x804D2000 \SystemRoot\system32\CI.dll 0x80606000 \SystemRoot\system32\drivers\Wdf01000.sys 0x80682000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x8068F000 \SystemRoot\System32\Drivers\spjp.sys 0x80790000 \SystemRoot\System32\Drivers\WMILIB.SYS 0x80799000 \SystemRoot\System32\Drivers\SCSIPORT.SYS 0x805B2000 \SystemRoot\system32\drivers\acpi.sys 0x807BF000 \SystemRoot\system32\drivers\msisadrv.sys 0x807C7000 \SystemRoot\system32\drivers\pci.sys 0x807EE000 \SystemRoot\System32\drivers\partmgr.sys 0x807FD000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x8A605000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x8A60F000 \SystemRoot\system32\drivers\volmgr.sys 0x8A61E000 \SystemRoot\System32\drivers\volmgrx.sys 0x8A668000 \SystemRoot\System32\drivers\mountmgr.sys 0x8A678000 \SystemRoot\System32\Drivers\UBHelper.sys 0x8A680000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x8A75B000 \SystemRoot\system32\drivers\atapi.sys 0x8A763000 \SystemRoot\system32\drivers\ataport.SYS 0x8A781000 \SystemRoot\system32\drivers\msahci.sys 0x8A78B000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x8A799000 \SystemRoot\system32\drivers\fltmgr.sys 0x8A7CB000 \SystemRoot\system32\drivers\fileinfo.sys 0x8A7DB000 \SystemRoot\System32\Drivers\PxHelp20.sys 0x8A80F000 \SystemRoot\System32\Drivers\ksecdd.sys 0x8A880000 \SystemRoot\system32\drivers\ndis.sys 0x8A98B000 \SystemRoot\system32\drivers\msrpc.sys 0x8A9B6000 \SystemRoot\system32\drivers\NETIO.SYS 0x8AA06000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8AB16000 \SystemRoot\system32\drivers\volsnap.sys 0x8AB4F000 \SystemRoot\System32\Drivers\spldr.sys 0x8AB57000 \SystemRoot\System32\Drivers\mup.sys 0x8AB66000 \SystemRoot\System32\drivers\ecache.sys 0x8AB8D000 \SystemRoot\system32\drivers\disk.sys 0x8AB9E000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x8ABBF000 \SystemRoot\system32\drivers\crcdisk.sys 0x8E8E7000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8E8F2000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x8EE0D000 \SystemRoot\system32\DRIVERS\atikmdag.sys 0x8F27A000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8F31A000 \SystemRoot\System32\drivers\watchdog.sys 0x8F326000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8F3B3000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x8F3BE000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8E8FB000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8E90A000 \SystemRoot\system32\DRIVERS\k57nd60x.sys 0x8F408000 \SystemRoot\system32\DRIVERS\athr.sys 0x8F4F8000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x8F4FC000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x8F50F000 \SystemRoot\system32\DRIVERS\DKbFltr.sys 0x8F519000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8F524000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x8F555000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x8F557000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8F562000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8F57A000 \SystemRoot\system32\Drivers\NTIDrvr.sys 0x8F582000 \SystemRoot\System32\Drivers\ad9qukby.SYS 0x8F5BA000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x8F5C3000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x8E944000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x8E973000 \SystemRoot\system32\DRIVERS\storport.sys 0x8F5D2000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8F5DD000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8F5F4000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8E9B4000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8E9D7000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8E9E6000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8ABD5000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8ABEA000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8F400000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8FA06000 \SystemRoot\system32\DRIVERS\ks.sys 0x8FA30000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8FA3A000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8FA47000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8FA7C000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8FA8D000 \SystemRoot\system32\drivers\HdAudio.sys 0x8FACC000 \SystemRoot\system32\drivers\portcls.sys 0x8FAF9000 \SystemRoot\system32\drivers\drmk.sys 0x8FC0C000 \SystemRoot\system32\DRIVERS\AGRSM.sys 0x8FD32000 \SystemRoot\system32\drivers\modem.sys 0x8FD3F000 \SystemRoot\system32\DRIVERS\mwlPSDFilter.sys 0x8FD48000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x8FD51000 \SystemRoot\System32\Drivers\Null.SYS 0x8FD58000 \SystemRoot\System32\Drivers\Beep.SYS 0x8FD68000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x8FD6F000 \SystemRoot\System32\drivers\vga.sys 0x8FD7B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8FD9C000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8FDA4000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8FDAC000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8FDB7000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8FDC5000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x90202000 \SystemRoot\System32\drivers\tcpip.sys 0x902EC000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x90307000 \SystemRoot\system32\DRIVERS\tdx.sys 0x9031D000 \SystemRoot\system32\DRIVERS\smb.sys 0x90331000 \SystemRoot\system32\drivers\afd.sys 0x90379000 \SystemRoot\System32\DRIVERS\netbt.sys 0x903AB000 \SystemRoot\system32\DRIVERS\pacer.sys 0x903C1000 \SystemRoot\system32\DRIVERS\netbios.sys 0x903CF000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x903E2000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0x8FB1E000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x903E8000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8FDCE000 \SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys 0x903F2000 \SystemRoot\system32\DRIVERS\mwlPSDNServ.sys 0x8FB5A000 \SystemRoot\system32\drivers\mfehidk.sys 0x8FDE0000 \SystemRoot\System32\Drivers\dfsc.sys 0x8FB8D000 \SystemRoot\system32\DRIVERS\avipbb.sys 0x903FB000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys 0x8FBB3000 \SystemRoot\System32\Drivers\fastfat.SYS 0x8FBDB000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x90804000 \SystemRoot\System32\Drivers\usbvideo.sys 0x90825000 \SystemRoot\System32\Drivers\BTHUSB.sys 0x90832000 \SystemRoot\System32\Drivers\bthport.sys 0x908B2000 \SystemRoot\System32\Drivers\crashdmp.sys 0x908BF000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x81800000 \SystemRoot\System32\win32k.sys 0x9099A000 \SystemRoot\System32\drivers\Dxapi.sys 0x909A4000 \SystemRoot\system32\DRIVERS\rfcomm.sys 0x909CD000 \SystemRoot\system32\DRIVERS\BthEnum.sys 0x909D7000 \SystemRoot\system32\DRIVERS\bthpan.sys 0x909F1000 \SystemRoot\system32\DRIVERS\bthmodem.sys 0x81A20000 \SystemRoot\System32\TSDDD.dll 0x81A40000 \SystemRoot\System32\cdd.dll 0x8E80F000 \SystemRoot\system32\drivers\luafv.sys 0x8E82A000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0x9B801000 \SystemRoot\system32\drivers\spsys.sys 0x9B8B1000 \SystemRoot\system32\DRIVERS\irda.sys 0x9B8CF000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x9B8DF000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x9B909000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x9B913000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x9B926000 \SystemRoot\system32\drivers\HTTP.sys 0x9B993000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x9B9B0000 \SystemRoot\system32\DRIVERS\bowser.sys 0x9B9C9000 \SystemRoot\System32\drivers\mpsdrv.sys 0x9B9DE000 \SystemRoot\system32\drivers\mrxdav.sys 0x8E83F000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x8E85E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x8E897000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x8E8AF000 \SystemRoot\System32\DRIVERS\srv2.sys 0x9EA06000 \SystemRoot\System32\DRIVERS\srv.sys 0x9EA6C000 \SystemRoot\system32\DRIVERS\atksgt.sys 0x9EAAF000 \SystemRoot\system32\DRIVERS\lirsgt.sys 0x9EAB4000 \SystemRoot\system32\drivers\peauth.sys 0x9EB92000 \SystemRoot\System32\Drivers\secdrv.SYS 0x9EB9C000 \SystemRoot\System32\drivers\tcpipreg.sys 0x9EBA8000 \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl 0x9EBD4000 \??\C:\Windows\system32\FsUsbExDisk.SYS 0x9EBDD000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x9EBF3000 \??\C:\Windows\system32\Drivers\PROCEXP113.SYS 0x9EBF5000 \??\C:\Users\media\AppData\Local\Temp\catchme.sys 0x9EA54000 \SystemRoot\system32\DRIVERS\monitor.sys 0x8A7E4000 \??\C:\Users\media\AppData\Local\Temp\kwdoypod.sys 0x76F70000 \Windows\System32\ntdll.dll Processes (total 86): 0 System Idle Process 4 SYSTEM 456 C:\Windows\System32\smss.exe 592 csrss.exe 656 csrss.exe 664 C:\Windows\System32\wininit.exe 704 C:\Windows\System32\services.exe 716 C:\Windows\System32\lsass.exe 724 C:\Windows\System32\lsm.exe 804 C:\Windows\System32\winlogon.exe 952 C:\Windows\System32\svchost.exe 1036 C:\Windows\System32\svchost.exe 1084 C:\Windows\System32\svchost.exe 1208 C:\Windows\System32\Ati2evxx.exe 1240 C:\Windows\System32\svchost.exe 1276 C:\Windows\System32\svchost.exe 1308 C:\Windows\System32\svchost.exe 1384 C:\Windows\System32\audiodg.exe 1412 C:\Windows\System32\svchost.exe 1432 C:\Windows\System32\SLsvc.exe 1480 C:\Windows\System32\svchost.exe 1648 C:\Windows\System32\svchost.exe 1932 C:\Windows\System32\spoolsv.exe 1948 C:\Windows\System32\dwm.exe 1988 C:\Windows\System32\taskeng.exe 304 C:\Program Files\Avira\AntiVir Desktop\sched.exe 308 C:\Windows\System32\svchost.exe 508 C:\Windows\System32\taskeng.exe 676 C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe 960 C:\Windows\System32\Ati2evxx.exe 340 C:\Windows\System32\agrsmsvc.exe 1032 C:\Program Files\Avira\AntiVir Desktop\avguard.exe 1464 C:\Program Files\avmwlanstick\WLanNetService.exe 2068 C:\Windows\System32\svchost.exe 2088 C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe 2148 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe 2268 C:\Windows\System32\FsUsbExService.Exe 2276 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe 2312 C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe 2388 C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe 2420 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 2516 C:\Windows\System32\svchost.exe 2564 C:\Windows\System32\svchost.exe 2580 C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe 2620 C:\Windows\System32\svchost.exe 2644 C:\Windows\System32\SearchIndexer.exe 3336 WmiPrvSE.exe 3504 C:\Program Files\Windows Defender\MSASCui.exe 3532 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 3584 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 3620 C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe 3716 C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe 3736 C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe 3804 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 3952 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 4012 WmiPrvSE.exe 4060 C:\Program Files\Common Files\Java\Java Update\jusched.exe 4080 C:\Program Files\DivX\DivX Update\DivXUpdate.exe 1188 C:\Program Files\Launch Manager\LManager.exe 1672 C:\Windows\ehome\ehtray.exe 2684 C:\Program Files\DAEMON Tools Lite\daemon.exe 3816 C:\Windows\ehome\ehmsas.exe 3040 C:\Windows\System32\wbem\unsecapp.exe 4004 C:\Users\media\Program Files\DNA\btdna.exe 3996 C:\Program Files\Windows Sidebar\sidebar.exe 4008 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe 3488 C:\Program Files\Windows Media Player\wmpnscfg.exe 2204 C:\Program Files\Windows Media Player\wmpnetwk.exe 4432 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe 4468 C:\Program Files\Windows Sidebar\sidebar.exe 4568 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe 5072 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 5436 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe 5492 C:\Windows\System32\svchost.exe 5596 C:\Windows\System32\svchost.exe 3472 C:\Windows\System32\conime.exe 3020 C:\Windows\explorer.exe 2804 C:\Windows\System32\wbem\unsecapp.exe 4620 C:\Windows\System32\mobsync.exe 5460 C:\Windows\System32\taskeng.exe 4100 C:\Program Files\TuneUp Utilities 2008\OneClick.exe 2220 C:\Windows\System32\TuneUpDefragService.exe 4288 C:\Program Files\Mozilla Firefox\firefox.exe 5940 C:\Windows\System32\SearchProtocolHost.exe 5052 C:\Windows\System32\SearchFilterHost.exe 5720 C:\Users\media\Desktop\MBRCheck.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`71100000 (NTFS) PhysicalDrive0 Model Number: HitachiHTS545050B9A300, Rev: PB4OC60F Size Device Name MBR Status -------------------------------------------- 465 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: 00DA077E92625BC67BBA239DB4218A4A12648922 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: |
26.03.2011, 18:02 | #23 |
/// Winkelfunktion /// TB-Süch-Tiger™ | System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!!
__________________ Logfiles bitte immer in CODE-Tags posten |
26.03.2011, 23:21 | #24 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Also mit http://www.trojaner-board.de/51187-a...i-malware.html kann ich nicht scannen stürzt immer ab und crasht den Pc. das Andere Programm hat 3 Std. gebraucht hier die log: SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 03/26/2011 at 10:49 PM Application Version : 4.50.1002 Core Rules Database Version : 6680 Trace Rules Database Version: 4492 Scan type : Complete Scan Total Scan Time : 02:21:55 Memory items scanned : 888 Memory threats detected : 0 Registry items scanned : 9436 Registry threats detected : 10 File items scanned : 251411 File threats detected : 15 Adware.Tracking Cookie C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@bs.serving-sys[3].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@atdmt[4].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@doubleclick[1].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@clicksor[6].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@revsci[1].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@serving-sys[8].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@CAWCOYAU.txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@atdmt.combing[3].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@CA5QE99S.txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@ads.lzjl[5].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@myroitracking[6].txt C:\Users\media\AppData\Roaming\Microsoft\Windows\Cookies\media@CA2TIUGV.txt media.rofl.to [ C:\Users\media\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\7K3C4CB7 ] Adware.MyWebSearch/FunWebProducts HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC} HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32 HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF} HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32 HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version Trojan.Agent/Gen C:\USERS\MEDIA\DESKTOP\COMPUTERFIXES\_OTL\MOVEDFILES\03232011_220622\C_USERS\MEDIA\APPDATA\ROAMING\APOCALYPS32.EXE C:\_OTL\MOVEDFILES\03232011_220622\C_USERS\MEDIA\APPDATA\ROAMING\APOCALYPS32.EXE |
27.03.2011, 19:30 | #25 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-(Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
27.03.2011, 20:13 | #26 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Also bein Fullscan stürzt er immer direkt am Anfang ab. Der Qickscan läuft in etwa so ab: Suchen Keine Reaktion,... kurz warten Suchen Keine Reaktion,... ,... ,... ,... immer so weiter und dann plötzlich Bluescreen bevor der Bluescreen kam war da noch 1 infizierte Datei angezeigt worden dann isser noch kurz gelaufen dann isser abgestüzt,... _________________________________________________________________________________________________________________ Die Prozesse laufen auch schon besser aber seit neustem ist der Arbeitsspeicher also der Ram immer dauehaft über 50 % ausgelastet,... Edit: bist du noch da Cosinus? Geändert von Shuyin (27.03.2011 um 21:05 Uhr) |
27.03.2011, 21:18 | #27 |
/// Winkelfunktion /// TB-Süch-Tiger™ | System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Was passiert im abgesicherten Modus? Stürzt Malwarebytes da auch ab?
__________________ Logfiles bitte immer in CODE-Tags posten |
27.03.2011, 21:22 | #28 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( werd ich mal ausprobieren morgen ein Quickscan oder fullscan? was soll ich ausprobieren? |
27.03.2011, 21:32 | #29 |
/// Winkelfunktion /// TB-Süch-Tiger™ | System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Probier erst den Quickscan. Wenn der geht machst du den Vollscan. Damit du einen Internetzugang hast, wählst du den abgesicherten Modus mit Netzwerktreibern. Sollte Malwarebytes da auch abstürzen nimmst du den einfachen abgesicherten Modus, aber versuch dann wenigstens Malwarebytes vorher zu updaten.
__________________ Logfiles bitte immer in CODE-Tags posten |
28.03.2011, 22:10 | #30 |
| System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( Sooo, im abgesicherten Modus mit Netzwerktreibern hat es geklappt mit dem Malwarebytes. Hab zuerst den quickscan dann den Fullscan, beide erfolgreich. Hier die Log's: Quickscan: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6198 Windows 6.0.6002 Service Pack 2 (Safe Mode) Internet Explorer 8.0.6001.19019 28.03.2011 21:51:45 mbam-log-2011-03-28 (21-51-45).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 167438 Laufzeit: 3 Minute(n), 6 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 1 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\Users\media\downloads\Info_PDF.scr (Heuristics.Shuriken) -> Quarantined and deleted successfully. Fullscan: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6198 Windows 6.0.6002 Service Pack 2 (Safe Mode) Internet Explorer 8.0.6001.19019 28.03.2011 22:59:57 mbam-log-2011-03-28 (22-59-57).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 414520 Laufzeit: 1 Stunde(n), 2 Minute(n), 27 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 7 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\Qoobox\quarantine\C\Users\media\AppData\Roaming\apocalyps32.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully. c:\Qoobox\quarantine\C\Users\media\AppData\Roaming\desktopicon\ebayshortcuts.exe.vir (Adware.ADON) -> Quarantined and deleted successfully. c:\Qoobox\quarantine\C\Users\media\AppData\Roaming\sysutils_update\tmp.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\media\Desktop\computerfixes\_OTL\movedfiles\03232011_220622\c_directory\cybergate\install\server.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully. c:\Users\media\Desktop\computerfixes\_OTL\movedfiles\03232011_220622\C_Users\media\AppData\Roaming\neu.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully. c:\_OTL\movedfiles\03232011_220622\c_directory\cybergate\install\server.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully. c:\_OTL\movedfiles\03232011_220622\C_Users\media\AppData\Roaming\neu.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully. |
Themen zu System dauerhaft über 50 % ausgelastet, Pc läuft somit super langsam ;-( |
arbeitsspeicher, ausgelastet, auslastung, dauerhaft, dringend, hilfe!, langsam, liebe, pc läuft, problem, profis, recht, super, system, teilweise, warum |