|
Plagegeister aller Art und deren Bekämpfung: RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALLWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.04.2011, 13:38 | #16 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Danke, werd ich machen, nur gibt es Problemchen: EDIT: (Problem mit Zugriff auf Virenscanner gelöst, ist nun inaktiv) Combofix lädt sich runter, aber als Binary file, nicht als Ausführung exe - trotzdem ok? Geändert von ronze44 (01.04.2011 um 13:46 Uhr) |
01.04.2011, 14:08 | #17 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Hallo Arne, hier der Log.
__________________Hatte vergessen, als Admin zu starten, aber ich gehe davon aus, dass ich das ohnehin bin. Das Combofix Fenster zeigte auch nach dem Neustart oben "Administrator" an. Anfangs gabs noch Meckern wegen Skript konnte nicht ausgeführt werden, aber Combofix hat dann trotzdem weitergemacht. War wohl meine Firewall, die zunächst den Netz-Zugriff verweigerte. Der Log: Combofix Logfile: Code:
ATTFilter ComboFix 11-03-31.04 - *** 01.04.2011 14:49:11.1.2 - x86 ausgeführt von:: c:\users\***\Desktop\Cofi.exe.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\hpeB6C0.dll c:\users\***\AppData\Roaming\Desktopicon c:\users\***\AppData\Roaming\Desktopicon\config.ini c:\users\***\AppData\Roaming\EurekaLog c:\windows\Fonts\Guitar Amp.exe c:\windows\system32\Inetde.dll t:\temp\catchme.dll . . ((((((((((((((((((((((( Dateien erstellt von 2011-03-01 bis 2011-04-01 )))))))))))))))))))))))))))))) . . 2011-04-01 12:55 . 2011-04-01 12:55 -------- d-----w- c:\users\***\AppData\Local\temp 2011-04-01 12:55 . 2011-04-01 12:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-03-31 21:57 . 2004-03-08 22:00 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX 2011-03-31 21:57 . 2001-10-28 14:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll 2011-03-31 21:57 . 1998-06-23 22:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX 2011-03-31 21:57 . 2011-03-31 21:57 -------- d-----w- c:\program files\PDFCreator 2011-03-31 21:57 . 1998-07-06 15:55 64512 ----a-w- c:\windows\system32\MSCC2DE.DLL 2011-03-31 21:57 . 1998-07-05 22:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL 2011-03-31 20:06 . 2011-03-31 20:06 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys 2011-03-31 20:05 . 2011-03-31 20:05 -------- d-----w- C:\_OTL 2011-03-31 18:41 . 2011-03-31 18:41 -------- d-----w- c:\users\***\AppData\Roaming\www.shadowexplorer.com 2011-03-31 18:41 . 2011-03-31 18:41 -------- d-----w- c:\program files\ShadowExplorer 2011-03-31 18:32 . 2011-03-14 19:05 6792528 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\mpengine.dll 2011-03-27 23:04 . 2011-03-27 23:04 -------- d-----w- c:\users\***\AppData\Local\{3C914691-E3BD-430B-A3F4-1B460BCD316F} 2011-03-27 19:55 . 2011-03-27 19:55 -------- d-----w- c:\users\***\AppData\Local\MAGIX 2011-03-27 19:52 . 2011-03-27 19:52 -------- d-----w- c:\program files\Common Files\MAGIX Services 2011-03-27 18:28 . 2011-03-28 21:41 -------- d-----w- c:\program files\Sonne Screen Video Capture 2011-03-27 12:13 . 2011-03-27 12:48 -------- d-----w- c:\users\***\AppData\Roaming\Web Page Maker 2011-03-27 12:13 . 2011-03-27 12:13 -------- d-----w- c:\programdata\Web Page Maker 2011-03-27 10:45 . 2011-03-27 19:52 -------- d-----w- c:\program files\MAGIX 2011-03-26 15:04 . 2011-03-26 15:04 -------- d-----w- c:\program files\NetObjects 2011-03-26 14:15 . 2011-03-27 19:58 -------- d-----w- c:\programdata\MAGIX 2011-03-26 14:15 . 2011-03-27 19:55 -------- d-----w- c:\users\***\AppData\Local\Xara 2011-03-26 14:14 . 2011-03-26 14:14 -------- d-----w- c:\programdata\Xara 2011-03-26 14:14 . 2011-03-26 14:14 -------- d-----w- c:\program files\Xara 2011-03-26 14:10 . 2011-03-27 19:58 -------- d-----w- c:\users\***\AppData\Roaming\MAGIX 2011-03-26 13:52 . 2004-03-08 23:00 609824 ----a-w- c:\windows\system32\Comctl32.ocx 2011-03-26 13:52 . 2000-07-16 15:20 185856 ----a-w- c:\windows\system32\Bmp2Jpeg.dll 2011-03-26 00:45 . 2011-03-29 12:24 -------- d-----w- c:\users\***\VirtualBox VMs 2011-03-26 00:37 . 2011-02-17 17:06 160560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys 2011-03-26 00:37 . 2011-02-17 17:06 44784 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2011-03-26 00:37 . 2011-03-31 00:57 -------- dc----w- c:\windows\system32\DRVSTORE 2011-03-25 23:45 . 2011-03-29 01:46 -------- d-----w- c:\program files\Inkscape 2011-03-25 22:10 . 2011-01-30 13:29 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2011-03-25 00:06 . 2011-03-29 01:45 -------- d-----w- c:\program files\Oracle 2011-03-24 23:55 . 2011-03-25 23:51 -------- d-----w- c:\users\***\AppData\Roaming\inkscape 2011-03-23 20:37 . 2011-03-23 20:37 -------- d-----w- c:\program files\Macromedia 2011-03-23 19:23 . 2011-03-23 19:23 -------- d-----w- c:\programdata\Nitro PDF 2011-03-23 19:23 . 2011-03-23 19:23 -------- d-----w- c:\program files\Nitro PDF 2011-03-23 19:23 . 2011-03-23 19:23 -------- d-----w- c:\program files\Common Files\Nitro PDF 2011-03-23 17:51 . 2011-03-23 17:51 -------- d-----w- c:\users\***\AppData\Roaming\Nitro PDF 2011-03-23 17:36 . 2011-03-23 19:23 -------- d-----w- c:\program files\Common Files\BCL Technologies 2011-03-23 17:35 . 2011-03-23 17:35 -------- d-----w- c:\users\***\AppData\Local\Downloaded Installations 2011-03-23 00:16 . 2011-03-25 01:40 -------- d-----w- c:\users\***\HH Seiten 2011-03-22 23:01 . 2011-03-22 23:01 -------- d-----w- c:\users\***\AppData\Roaming\AdobeUM 2011-03-22 13:40 . 2011-03-22 13:40 -------- d-----w- c:\program files\Windows7FirewallControl 2011-03-21 23:20 . 2000-04-03 18:05 118784 ----a-w- c:\windows\system32\msstdfmt.dll 2011-03-21 23:20 . 1999-07-14 12:07 6656 ----a-w- c:\windows\system32\stdftde.dll 2011-03-21 23:20 . 1998-07-05 22:00 22528 ----a-w- c:\windows\system32\Tabctde.dll 2011-03-21 23:20 . 2011-03-21 23:21 -------- d-----w- c:\program files\Biet-O-Matic 2011-03-21 23:02 . 2006-05-31 14:35 190464 ----a-w- c:\windows\system32\sevImLib.dll 2011-03-21 23:02 . 2005-11-27 19:07 262144 ----a-w- c:\windows\system32\CoolXPFrame.ocx 2011-03-21 23:02 . 2005-11-27 19:06 360448 ----a-w- c:\windows\system32\CoolXPLabel.ocx 2011-03-21 23:02 . 2008-04-21 11:58 231424 ----a-w- c:\windows\system32\sevXPCtl.ocx 2011-03-21 23:02 . 2006-09-29 13:11 929792 ----a-w- c:\windows\system32\CoolXPTabStrip.ocx 2011-03-21 23:02 . 2004-03-17 08:19 86016 ----a-w- c:\windows\system32\sevGrip.ocx 2011-03-21 23:02 . 2008-04-24 07:02 361984 ----a-w- c:\windows\system32\sevDataGrid2.ocx 2011-03-21 23:02 . 2008-04-17 13:14 289280 ----a-w- c:\windows\system32\sevEin20.ocx 2011-03-21 23:02 . 2005-08-30 07:51 126976 ----a-w- c:\windows\system32\sevTrayIcon.ocx 2011-03-21 23:02 . 2008-04-17 11:00 139264 ----a-w- c:\windows\system32\sevCmd3.ocx 2011-03-21 23:02 . 2007-11-07 06:55 113664 ----a-w- c:\windows\system32\sevClb20.ocx 2011-03-21 23:00 . 2011-03-29 01:46 -------- d-----w- c:\windows\uninstall 2011-03-21 22:42 . 2011-03-29 01:46 -------- d-----w- c:\users\***\AppData\Roaming\BayHunter 2011-03-21 22:42 . 2011-03-29 01:46 -------- d-----w- c:\program files\BayHunter 2011-03-21 22:41 . 2011-03-25 22:03 -------- d-----w- c:\users\***\AppData\Roaming\GetRightToGo 2011-03-20 22:54 . 2011-03-20 22:54 -------- d-----w- c:\program files\Toon Boom Animation 2011-03-20 21:13 . 2011-03-25 22:03 -------- d-----w- c:\program files\Microangelo 2011-03-20 21:01 . 2011-03-30 21:21 -------- d-----w- c:\users\***\Install 2011-03-19 03:14 . 2011-03-29 01:45 -------- d-----w- C:\Plugins 2011-03-19 03:13 . 2011-03-19 03:13 -------- d-----w- c:\program files\Jasc Software Inc 2011-03-19 02:53 . 2011-03-19 02:53 -------- d-----w- c:\program files\PhotoBrush 2011-03-18 23:26 . 2008-06-06 06:59 4887336 ----a-w- c:\windows\system32\WacomTablet.cpl 2011-03-18 23:26 . 2007-02-15 15:11 11440 ----a-w- c:\windows\system32\drivers\WacomVKHid.sys 2011-03-18 23:25 . 2008-06-06 07:08 3406120 ----a-w- c:\windows\system32\Wacom_Tablet.exe 2011-03-18 23:25 . 2008-06-06 07:00 159528 ----a-w- c:\windows\system32\Wacom_Tablet.dll 2011-03-18 23:13 . 2011-03-31 21:02 -------- d-----w- c:\users\***\pap_projects 2011-03-18 23:12 . 2011-03-25 22:03 -------- d-----w- c:\program files\PAP40 2011-03-15 10:45 . 2011-03-15 10:45 -------- d-----w- c:\users\***\AppData\Roaming\HighAndes 2011-03-15 10:45 . 2011-03-15 10:45 -------- d-----w- c:\users\***\AppData\Local\HighAndes 2011-03-15 10:45 . 2011-03-15 10:45 -------- d-----w- c:\programdata\HighAndes 2011-03-15 03:03 . 2009-06-07 12:20 61440 ----a-w- c:\windows\system32\NlsSrv32.exe 2011-03-15 03:02 . 2011-03-15 03:03 -------- d-----w- c:\users\***\AppData\Roaming\Blue Cat Audio 2011-03-15 03:02 . 2011-03-15 03:02 -------- d-----w- c:\program files\HighAndes 2011-03-13 18:43 . 2011-03-13 18:43 -------- d-----w- c:\program files\Line6 2011-03-12 15:00 . 2011-03-12 15:00 -------- d-----w- c:\windows\system32\SPReview 2011-03-12 15:00 . 2011-03-12 15:00 -------- d-----w- c:\windows\system32\EventProviders 2011-03-12 14:56 . 2010-11-20 12:30 3966848 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-03-12 14:55 . 2010-11-20 12:21 1227776 ----a-w- c:\windows\system32\wdc.dll 2011-03-12 14:54 . 2010-11-20 12:20 68096 ----a-w- c:\windows\system32\napdsnap.dll 2011-03-12 14:53 . 2010-11-20 12:18 323072 ----a-w- c:\windows\system32\drvstore.dll 2011-03-12 14:53 . 2010-11-20 12:18 257024 ----a-w- c:\windows\system32\dpx.dll 2011-03-11 23:01 . 2011-03-11 23:02 -------- d-----w- c:\program files\VirtualDub-1.9.11 2011-03-11 00:58 . 2011-03-31 20:09 -------- d-----r- c:\users\***\Dropbox 2011-03-11 00:52 . 2011-03-31 20:09 -------- d-----w- c:\users\***\AppData\Roaming\Dropbox 2011-03-09 11:44 . 2010-12-23 05:54 850944 ----a-w- c:\windows\system32\sbe.dll 2011-03-09 11:44 . 2010-12-23 05:54 642048 ----a-w- c:\windows\system32\CPFilters.dll 2011-03-09 11:44 . 2010-12-23 05:54 534528 ----a-w- c:\windows\system32\EncDec.dll 2011-03-09 11:44 . 2010-12-23 05:50 199680 ----a-w- c:\windows\system32\mpg2splt.ax 2011-03-08 14:04 . 2011-03-08 14:04 -------- d-----w- c:\program files\Lame For Audacity 2011-03-06 23:17 . 2011-03-06 23:17 -------- d-----w- c:\users\***\AppData\Roaming\DVDVideoSoft 2011-03-06 03:17 . 2011-03-06 03:17 -------- d-----w- c:\programdata\NCH Swift Sound 2011-03-06 01:49 . 2011-03-06 01:49 -------- d-----w- c:\users\***\AppData\Roaming\Thinstall 2011-03-06 01:49 . 2011-03-06 01:49 -------- d-----w- c:\users\***\AppData\Local\Thinstall 2011-03-06 01:05 . 2011-03-26 12:07 -------- d-----w- c:\users\***\AppData\Roaming\NCH Software . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-14 19:05 . 2010-10-15 00:57 6792528 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-03-12 15:07 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll 2011-01-30 00:52 . 2011-01-30 00:52 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-01-13 09:41 . 2011-01-30 13:03 5890896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll 2011-01-07 07:45 . 2011-02-09 10:18 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-01-07 06:01 . 2011-02-09 11:03 1638912 ----a-w- c:\windows\system32\mshtml.tlb 2011-01-07 05:43 . 2011-02-09 10:18 294400 ----a-w- c:\windows\system32\atmfd.dll 2011-01-05 05:55 . 2011-02-09 10:22 428032 ----a-w- c:\windows\system32\vbscript.dll 2011-01-05 03:51 . 2011-02-09 10:22 2330624 ----a-w- c:\windows\system32\win32k.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}] 2010-03-17 14:45 2355224 ----a-w- c:\program files\Winload\tbWinl.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{40C3CC16-7269-4B32-9531-17F2950FB06F}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\WebDavOverlayUpload] @="{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}" [HKEY_CLASSES_ROOT\CLSID\{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}] 2010-10-27 11:13 284304 ----a-w- c:\windows\System32\WebDAV.ShellExtension.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-03 15028104] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Buyertools Reminder"="c:\program files\Buyertools Reminder\Reminder.exe" [2008-12-22 6607872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504] "ACFanControl"="c:\program files\ACFanControl\ACFanControl.exe" [2010-10-04 249856] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520] "Windows7FirewallControl"="c:\program files\Windows7FirewallControl\Windows7FirewallControl.exe" [2010-11-01 802816] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976] . c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-3-31 23360040] Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [2010-10-12 4142448] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088] "{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll" [2010-03-24 511344] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "MIDI3"=timiditydrv.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TabUserW.exe.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TabUserW.exe.lnk backup=c:\windows\pss\TabUserW.exe.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^***^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Impulse Now.lnk] path=c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk backup=c:\windows\pss\Impulse Now.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePower Management] 2009-08-19 14:15 487424 ----a-w- c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service] 2007-12-03 10:06 140568 ----a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor] 2007-12-03 10:09 911184 ----a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Check Mail] 2007-04-18 21:37 2158080 ----a-w- c:\program files\CheckMail V2\CK_Mail.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Koma-Mail] 2010-03-12 14:14 2836992 ----a-w- c:\program files\KomaMail\Koma_Mail.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] 2009-09-15 13:24 883208 ----a-w- c:\program files\Launch Manager\LManager.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseExtender] 2010-09-23 01:26 455168 ----a-w- c:\users\***\Desktop\MouseExtender.1.9.7.2\MouseExtender.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2] 2010-07-11 09:42 2199040 ----a-w- c:\program files\Rainlendar2\Rainlendar2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr] 2009-10-10 06:51 614400 ----a-w- c:\windows\Samsung\PanelMgr\SSMMgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] 2009-11-20 08:17 434176 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-05-14 10:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher] 2007-10-28 10:35 425984 ----a-w- c:\program files\Switcher\Switcher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe] 2007-12-03 10:06 2622104 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" -hide -runkey . R1 MpKslda63107b;MpKslda63107b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{66193AB5-5D42-498E-A3C9-EF5CAC0D8D2D}\MpKslda63107b.sys [x] R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-20 73728] R3 EchoIndigo;echondgo;c:\windows\system32\DRIVERS\echondgo.sys [2009-12-08 132544] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-05 13224] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360] R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [2008-10-21 86824] R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 15016] R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 114600] R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 108328] R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 26024] R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [2008-10-21 104616] R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [2008-10-21 109736] R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2007-10-24 23288] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 UDST7000BDA;TerraTec H7 service;c:\windows\system32\DRIVERS\TerraTecUsbBda.sys [2010-08-17 782840] R3 UDST7000HID;TerraTec H7/S7 HID service;c:\windows\system32\DRIVERS\TerraTecUsbHid.sys [2010-08-04 22136] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-09-15 16240] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-08 1343400] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 RRamdisk;Ramdisk Driver;c:\windows\system32\DRIVERS\rramdisk.sys [2009-04-30 12288] S1 cbfs3;cbfs3;c:\windows\system32\drivers\cbfs3.sys [2010-05-15 265800] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-30 218688] S1 MpKsl66cf2e2f;MpKsl66cf2e2f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys [2011-03-31 28752] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-03-19 2964312] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 136176] S2 MCSWASVR;Mediencenter Service;c:\program files\Telekom\Mediencenter\WebDAV.AdminService.exe [2010-07-09 16016] S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [2009-06-07 61440] S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112] S2 sesvc;ShadowExplorer Service;c:\program files\ShadowExplorer\sesvc.exe [2011-01-02 9216] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-11-30 5120] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-09-21 4867952] S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-06-06 3406120] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-09-21 414576] S2 Windows7FirewallService;Windows7FirewallService;c:\program files\Windows7FirewallControl\Windows7FirewallService.exe [2010-11-01 401408] S3 echondgo;Indigo Service;c:\windows\system32\drivers\echondgo.sys [2009-12-08 132544] S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632] . . Inhalt des "geplante Tasks" Ordners . 2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30] . 2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://google.de/ uInternet Settings,ProxyOverride = *.local IE: add to &BOM - c:\\PROGRA~1\\BIET-O~1\\\\AddToBOM.hta IE: Free YouTube Download - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm IE: Free YouTube to Mp3 Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm IE: {{27914077-B4D6-4A0E-9763-76B6E9DD9A81} - c:\program files\Buyertools Reminder\ReminderIE.exe Trusted Zone: ***-lieblein.de FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://google.de FF - prefs.js: keyword.URL - hxxp://go.gmx.net/tb/mff_keyurl_search/?su= FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - c:\program files\Mozilla Firefox\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6} FF - Ext: Dictionary Switcher: dictionary-switcher@design-noir.de - %profile%\extensions\dictionary-switcher@design-noir.de FF - Ext: Dictionary (EN/DE): dictlookup@arnhold.com - %profile%\extensions\dictlookup@arnhold.com FF - Ext: BabelFish: {ca0849e8-2c76-42ae-9abe-34e14d337acf} - %profile%\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf} FF - Ext: German Dictionary: de-DE@dictionaries.addons.mozilla.org - %profile%\extensions\de-DE@dictionaries.addons.mozilla.org FF - Ext: United States English Spellchecker: en-US@dictionaries.addons.mozilla.org - %profile%\extensions\en-US@dictionaries.addons.mozilla.org FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - %profile%\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A} FF - Ext: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - %profile%\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com FF - Ext: Vacuum Places Improved: VacuumPlacesImproved@lultimouomo-gmail.com - %profile%\extensions\VacuumPlacesImproved@lultimouomo-gmail.com FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com FF - Ext: Lazarus: Form Recovery: lazarus@interclue.com - %profile%\extensions\lazarus@interclue.com FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard FF - Ext: Fasterfox Lite: FasterFox_Lite@BigRedBrent - %profile%\extensions\FasterFox_Lite@BigRedBrent FF - Ext: WebMail Notifier: {37fa1426-b82d-11db-8314-0800200c9a66} - %profile%\extensions\{37fa1426-b82d-11db-8314-0800200c9a66} FF - Ext: Biet-O-Matic Firefox Erweiterung: {B0D70E72-2FC1-4b9f-A3D4-5921C854D906} - %profile%\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906} . - - - - Entfernte verwaiste Registrierungseinträge - - - - . MSConfigStartUp-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe MSConfigStartUp-vsc32cnf - c:\program files\Roland\VSC32\vsc32cnf.exe MSConfigStartUp-vscvol - c:\program files\Roland\VSC32\vscvol.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3FDF5132-F69F-04D1-7D21-68F96726F127}*] "maffhilkingdbkajjfklhanbdn"=hex:6b,61,6d,6c,67,67,6b,6d,61,6b,69,70,62,69,63, 70,66,6d,64,63,61,6f,00,77 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'Explorer.exe'(2272) c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll c:\windows\system32\CbFsNetRdr3.dll c:\program files\Stardock\Fences\FencesMenu.dll c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll c:\program files\stardock\fences\DesktopDock.dll . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe c:\windows\SYSTEM32\WISPTIS.EXE c:\program files\Common Files\Acronis\Schedule2\schedul2.exe c:\windows\SYSTEM32\WISPTIS.EXE c:\program files\Common Files\microsoft shared\ink\TabTip.exe c:\program files\Tablet\Pen\Pen_TouchUser.exe c:\windows\system32\taskhost.exe c:\program files\CDBurnerXP\NMSAccessU.exe c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe c:\program files\Tablet\Pen\Pen_TabletUser.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\WTablet\Wacom_TabletUser.exe c:\windows\system32\conhost.exe c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe c:\windows\system32\sppsvc.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Zeit der Fertigstellung: 2011-04-01 15:00:48 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2011-04-01 13:00 . Vor Suchlauf: 17 Verzeichnis(se), 72.745.836.544 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 72.300.859.392 Bytes frei . - - End Of File - - FECC1F8B8D47BF958290E5CF6D7FB27A |
01.04.2011, 14:44 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Combofix - Scripten
__________________1. Starte das Notepad (Start / Ausführen / notepad[Enter]) 2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein. Code:
ATTFilter Regnull:: [HKEY_USERS\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3FDF5132-F69F-04D1-7D21-68F96726F127}*] 4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall. (Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !) 5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet. 6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien: Combofix.txt Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ |
01.04.2011, 20:37 | #19 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL und wieder bin ich besorgt, alles richtig gemacht zu haben, hoffe man kann das erkenne, falls nicht. Habe ja diese WIN Firewall Control, die hab ich nicht aus gekriegt. Von daher hat diese sich wieder gemeldet, als nach dem Scan pev.cfxxe ins Netz wollte. Denke aber dass das Combofix gewesen sein müsste und dieses hat ja nach meiner Erlaubnis ins Netz zu gehen auch weiter gearbeitet. Ergebnis: Combofix Logfile: Code:
ATTFilter ComboFix 11-03-31.04 - *** 01.04.2011 21:20:58.2.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2973.1992 [GMT 2:00] ausgeführt von:: c:\users\***\Desktop\Cofi.exe.exe Benutzte Befehlsschalter :: c:\users\***\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . t:\temp\catchme.dll . . ((((((((((((((((((((((( Dateien erstellt von 2011-03-01 bis 2011-04-01 )))))))))))))))))))))))))))))) . . 2011-04-01 19:26 . 2011-04-01 19:26 -------- d-----w- c:\users\***\AppData\Local\temp 2011-04-01 19:26 . 2011-04-01 19:26 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-04-01 19:10 . 2011-04-01 19:10 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5E64436B-C2AC-415B-A79B-85CA355D720B}\MpKslf60824b1.sys 2011-04-01 19:10 . 2011-03-14 19:05 6792528 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5E64436B-C2AC-415B-A79B-85CA355D720B}\mpengine.dll 2011-03-31 21:57 . 2004-03-08 22:00 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX 2011-03-31 21:57 . 2001-10-28 14:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll 2011-03-31 21:57 . 1998-06-23 22:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX 2011-03-31 21:57 . 2011-03-31 21:57 -------- d-----w- c:\program files\PDFCreator 2011-03-31 21:57 . 1998-07-06 15:55 64512 ----a-w- c:\windows\system32\MSCC2DE.DLL 2011-03-31 21:57 . 1998-07-05 22:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL 2011-03-31 20:05 . 2011-03-31 20:05 -------- d-----w- C:\_OTL 2011-03-31 18:41 . 2011-03-31 18:41 -------- d-----w- c:\users\***\AppData\Roaming\www.shadowexplorer.com 2011-03-31 18:41 . 2011-03-31 18:41 -------- d-----w- c:\program files\ShadowExplorer 2011-03-27 23:04 . 2011-03-27 23:04 -------- d-----w- c:\users\***\AppData\Local\{3C914691-E3BD-430B-A3F4-1B460BCD316F} 2011-03-27 19:55 . 2011-03-27 19:55 -------- d-----w- c:\users\***\AppData\Local\MAGIX 2011-03-27 19:52 . 2011-03-27 19:52 -------- d-----w- c:\program files\Common Files\MAGIX Services 2011-03-27 18:28 . 2011-03-28 21:41 -------- d-----w- c:\program files\Sonne Screen Video Capture 2011-03-27 12:13 . 2011-03-27 12:48 -------- d-----w- c:\users\***\AppData\Roaming\Web Page Maker 2011-03-27 12:13 . 2011-03-27 12:13 -------- d-----w- c:\programdata\Web Page Maker 2011-03-27 10:45 . 2011-03-27 19:52 -------- d-----w- c:\program files\MAGIX 2011-03-26 15:04 . 2011-03-26 15:04 -------- d-----w- c:\program files\NetObjects 2011-03-26 14:15 . 2011-03-27 19:58 -------- d-----w- c:\programdata\MAGIX 2011-03-26 14:15 . 2011-03-27 19:55 -------- d-----w- c:\users\***\AppData\Local\Xara 2011-03-26 14:14 . 2011-03-26 14:14 -------- d-----w- c:\programdata\Xara 2011-03-26 14:14 . 2011-03-26 14:14 -------- d-----w- c:\program files\Xara 2011-03-26 14:10 . 2011-03-27 19:58 -------- d-----w- c:\users\***\AppData\Roaming\MAGIX 2011-03-26 13:52 . 2004-03-08 23:00 609824 ----a-w- c:\windows\system32\Comctl32.ocx 2011-03-26 13:52 . 2000-07-16 15:20 185856 ----a-w- c:\windows\system32\Bmp2Jpeg.dll 2011-03-26 00:45 . 2011-03-29 12:24 -------- d-----w- c:\users\***\VirtualBox VMs 2011-03-26 00:37 . 2011-02-17 17:06 160560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys 2011-03-26 00:37 . 2011-02-17 17:06 44784 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2011-03-26 00:37 . 2011-03-31 00:57 -------- dc----w- c:\windows\system32\DRVSTORE 2011-03-25 23:45 . 2011-03-29 01:46 -------- d-----w- c:\program files\Inkscape 2011-03-25 22:10 . 2011-01-30 13:29 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2011-03-25 00:06 . 2011-03-29 01:45 -------- d-----w- c:\program files\Oracle 2011-03-24 23:55 . 2011-03-25 23:51 -------- d-----w- c:\users\***\AppData\Roaming\inkscape 2011-03-23 20:37 . 2011-03-23 20:37 -------- d-----w- c:\program files\Macromedia 2011-03-23 19:23 . 2011-03-23 19:23 -------- d-----w- c:\programdata\Nitro PDF 2011-03-23 19:23 . 2011-03-23 19:23 -------- d-----w- c:\program files\Nitro PDF 2011-03-23 19:23 . 2011-03-23 19:23 -------- d-----w- c:\program files\Common Files\Nitro PDF 2011-03-23 17:51 . 2011-03-23 17:51 -------- d-----w- c:\users\***\AppData\Roaming\Nitro PDF 2011-03-23 17:36 . 2011-03-23 19:23 -------- d-----w- c:\program files\Common Files\BCL Technologies 2011-03-23 17:35 . 2011-03-23 17:35 -------- d-----w- c:\users\***\AppData\Local\Downloaded Installations 2011-03-23 00:16 . 2011-03-25 01:40 -------- d-----w- c:\users\***\HH Seiten 2011-03-22 23:01 . 2011-03-22 23:01 -------- d-----w- c:\users\***\AppData\Roaming\AdobeUM 2011-03-22 13:40 . 2011-03-22 13:40 -------- d-----w- c:\program files\Windows7FirewallControl 2011-03-21 23:20 . 2000-04-03 18:05 118784 ----a-w- c:\windows\system32\msstdfmt.dll 2011-03-21 23:20 . 1999-07-14 12:07 6656 ----a-w- c:\windows\system32\stdftde.dll 2011-03-21 23:20 . 1998-07-05 22:00 22528 ----a-w- c:\windows\system32\Tabctde.dll 2011-03-21 23:20 . 2011-03-21 23:21 -------- d-----w- c:\program files\Biet-O-Matic 2011-03-21 23:02 . 2006-05-31 14:35 190464 ----a-w- c:\windows\system32\sevImLib.dll 2011-03-21 23:02 . 2005-11-27 19:07 262144 ----a-w- c:\windows\system32\CoolXPFrame.ocx 2011-03-21 23:02 . 2005-11-27 19:06 360448 ----a-w- c:\windows\system32\CoolXPLabel.ocx 2011-03-21 23:02 . 2008-04-21 11:58 231424 ----a-w- c:\windows\system32\sevXPCtl.ocx 2011-03-21 23:02 . 2006-09-29 13:11 929792 ----a-w- c:\windows\system32\CoolXPTabStrip.ocx 2011-03-21 23:02 . 2004-03-17 08:19 86016 ----a-w- c:\windows\system32\sevGrip.ocx 2011-03-21 23:02 . 2008-04-24 07:02 361984 ----a-w- c:\windows\system32\sevDataGrid2.ocx 2011-03-21 23:02 . 2008-04-17 13:14 289280 ----a-w- c:\windows\system32\sevEin20.ocx 2011-03-21 23:02 . 2005-08-30 07:51 126976 ----a-w- c:\windows\system32\sevTrayIcon.ocx 2011-03-21 23:02 . 2008-04-17 11:00 139264 ----a-w- c:\windows\system32\sevCmd3.ocx 2011-03-21 23:02 . 2007-11-07 06:55 113664 ----a-w- c:\windows\system32\sevClb20.ocx 2011-03-21 23:00 . 2011-03-29 01:46 -------- d-----w- c:\windows\uninstall 2011-03-21 22:42 . 2011-03-29 01:46 -------- d-----w- c:\users\***\AppData\Roaming\BayHunter 2011-03-21 22:42 . 2011-03-29 01:46 -------- d-----w- c:\program files\BayHunter 2011-03-21 22:41 . 2011-03-25 22:03 -------- d-----w- c:\users\***\AppData\Roaming\GetRightToGo 2011-03-20 22:54 . 2011-03-20 22:54 -------- d-----w- c:\program files\Toon Boom Animation 2011-03-20 21:13 . 2011-03-25 22:03 -------- d-----w- c:\program files\Microangelo 2011-03-20 21:01 . 2011-03-30 21:21 -------- d-----w- c:\users\***\Install 2011-03-19 03:14 . 2011-03-29 01:45 -------- d-----w- C:\Plugins 2011-03-19 03:13 . 2011-03-19 03:13 -------- d-----w- c:\program files\Jasc Software Inc 2011-03-19 02:53 . 2011-03-19 02:53 -------- d-----w- c:\program files\PhotoBrush 2011-03-18 23:26 . 2008-06-06 06:59 4887336 ----a-w- c:\windows\system32\WacomTablet.cpl 2011-03-18 23:26 . 2007-02-15 15:11 11440 ----a-w- c:\windows\system32\drivers\WacomVKHid.sys 2011-03-18 23:25 . 2008-06-06 07:08 3406120 ----a-w- c:\windows\system32\Wacom_Tablet.exe 2011-03-18 23:25 . 2008-06-06 07:00 159528 ----a-w- c:\windows\system32\Wacom_Tablet.dll 2011-03-18 23:13 . 2011-03-31 21:02 -------- d-----w- c:\users\***\pap_projects 2011-03-18 23:12 . 2011-03-25 22:03 -------- d-----w- c:\program files\PAP40 2011-03-15 10:45 . 2011-03-15 10:45 -------- d-----w- c:\users\***\AppData\Roaming\HighAndes 2011-03-15 10:45 . 2011-03-15 10:45 -------- d-----w- c:\users\***\AppData\Local\HighAndes 2011-03-15 10:45 . 2011-03-15 10:45 -------- d-----w- c:\programdata\HighAndes 2011-03-15 03:03 . 2009-06-07 12:20 61440 ----a-w- c:\windows\system32\NlsSrv32.exe 2011-03-15 03:02 . 2011-03-15 03:03 -------- d-----w- c:\users\***\AppData\Roaming\Blue Cat Audio 2011-03-15 03:02 . 2011-03-15 03:02 -------- d-----w- c:\program files\HighAndes 2011-03-13 18:43 . 2011-03-13 18:43 -------- d-----w- c:\program files\Line6 2011-03-12 15:00 . 2011-03-12 15:00 -------- d-----w- c:\windows\system32\SPReview 2011-03-12 15:00 . 2011-03-12 15:00 -------- d-----w- c:\windows\system32\EventProviders 2011-03-12 14:56 . 2010-11-20 12:30 3966848 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-03-12 14:55 . 2010-11-20 12:21 1227776 ----a-w- c:\windows\system32\wdc.dll 2011-03-12 14:54 . 2010-11-20 12:20 68096 ----a-w- c:\windows\system32\napdsnap.dll 2011-03-12 14:53 . 2010-11-20 12:18 323072 ----a-w- c:\windows\system32\drvstore.dll 2011-03-12 14:53 . 2010-11-20 12:18 257024 ----a-w- c:\windows\system32\dpx.dll 2011-03-11 23:01 . 2011-03-11 23:02 -------- d-----w- c:\program files\VirtualDub-1.9.11 2011-03-11 00:58 . 2011-03-31 20:09 -------- d-----r- c:\users\***\Dropbox 2011-03-11 00:52 . 2011-03-31 20:09 -------- d-----w- c:\users\***\AppData\Roaming\Dropbox 2011-03-09 11:44 . 2010-12-23 05:54 850944 ----a-w- c:\windows\system32\sbe.dll 2011-03-09 11:44 . 2010-12-23 05:54 642048 ----a-w- c:\windows\system32\CPFilters.dll 2011-03-09 11:44 . 2010-12-23 05:54 534528 ----a-w- c:\windows\system32\EncDec.dll 2011-03-09 11:44 . 2010-12-23 05:50 199680 ----a-w- c:\windows\system32\mpg2splt.ax 2011-03-08 14:04 . 2011-03-08 14:04 -------- d-----w- c:\program files\Lame For Audacity 2011-03-06 23:17 . 2011-03-06 23:17 -------- d-----w- c:\users\***\AppData\Roaming\DVDVideoSoft 2011-03-06 03:17 . 2011-03-06 03:17 -------- d-----w- c:\programdata\NCH Swift Sound 2011-03-06 01:49 . 2011-03-06 01:49 -------- d-----w- c:\users\***\AppData\Roaming\Thinstall 2011-03-06 01:49 . 2011-03-06 01:49 -------- d-----w- c:\users\***\AppData\Local\Thinstall 2011-03-06 01:05 . 2011-03-26 12:07 -------- d-----w- c:\users\***\AppData\Roaming\NCH Software . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-14 19:05 . 2010-10-15 00:57 6792528 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-03-12 15:07 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll 2011-01-30 00:52 . 2011-01-30 00:52 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-01-13 09:41 . 2011-01-30 13:03 5890896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll 2011-01-07 07:45 . 2011-02-09 10:18 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-01-07 06:01 . 2011-02-09 11:03 1638912 ----a-w- c:\windows\system32\mshtml.tlb 2011-01-07 05:43 . 2011-02-09 10:18 294400 ----a-w- c:\windows\system32\atmfd.dll 2011-01-05 05:55 . 2011-02-09 10:22 428032 ----a-w- c:\windows\system32\vbscript.dll 2011-01-05 03:51 . 2011-02-09 10:22 2330624 ----a-w- c:\windows\system32\win32k.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}] 2010-03-17 14:45 2355224 ----a-w- c:\program files\Winload\tbWinl.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{40C3CC16-7269-4B32-9531-17F2950FB06F}"= "c:\program files\Winload\tbWinl.dll" [2010-03-17 2355224] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\WebDavOverlayUpload] @="{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}" [HKEY_CLASSES_ROOT\CLSID\{0774B5A9-ADB5-4D3A-915F-72C7EF9CD262}] 2010-10-27 11:13 284304 ----a-w- c:\windows\System32\WebDAV.ShellExtension.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-03 15028104] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Buyertools Reminder"="c:\program files\Buyertools Reminder\Reminder.exe" [2008-12-22 6607872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504] "ACFanControl"="c:\program files\ACFanControl\ACFanControl.exe" [2010-10-04 249856] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520] "Windows7FirewallControl"="c:\program files\Windows7FirewallControl\Windows7FirewallControl.exe" [2010-11-01 802816] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976] . c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-3-31 23360040] Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [2010-10-12 4142448] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088] "{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll" [2010-03-24 511344] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "MIDI3"=timiditydrv.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TabUserW.exe.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TabUserW.exe.lnk backup=c:\windows\pss\TabUserW.exe.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^***^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Impulse Now.lnk] path=c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk backup=c:\windows\pss\Impulse Now.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePower Management] 2009-08-19 14:15 487424 ----a-w- c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service] 2007-12-03 10:06 140568 ----a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor] 2007-12-03 10:09 911184 ----a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Check Mail] 2007-04-18 21:37 2158080 ----a-w- c:\program files\CheckMail V2\CK_Mail.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Koma-Mail] 2010-03-12 14:14 2836992 ----a-w- c:\program files\KomaMail\Koma_Mail.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] 2009-09-15 13:24 883208 ----a-w- c:\program files\Launch Manager\LManager.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseExtender] 2010-09-23 01:26 455168 ----a-w- c:\users\***\Desktop\MouseExtender.1.9.7.2\MouseExtender.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2] 2010-07-11 09:42 2199040 ----a-w- c:\program files\Rainlendar2\Rainlendar2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr] 2009-10-10 06:51 614400 ----a-w- c:\windows\Samsung\PanelMgr\SSMMgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] 2009-11-20 08:17 434176 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-05-14 10:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher] 2007-10-28 10:35 425984 ----a-w- c:\program files\Switcher\Switcher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe] 2007-12-03 10:06 2622104 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" -hide -runkey . R1 MpKslda63107b;MpKslda63107b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{66193AB5-5D42-498E-A3C9-EF5CAC0D8D2D}\MpKslda63107b.sys [x] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 136176] R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112] R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-20 73728] R3 EchoIndigo;echondgo;c:\windows\system32\DRIVERS\echondgo.sys [2009-12-08 132544] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-05 13224] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360] R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [2008-10-21 86824] R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 15016] R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 114600] R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 108328] R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 26024] R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [2008-10-21 104616] R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [2008-10-21 109736] R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2007-10-24 23288] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 UDST7000BDA;TerraTec H7 service;c:\windows\system32\DRIVERS\TerraTecUsbBda.sys [2010-08-17 782840] R3 UDST7000HID;TerraTec H7/S7 HID service;c:\windows\system32\DRIVERS\TerraTecUsbHid.sys [2010-08-04 22136] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-09-15 16240] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-08 1343400] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 RRamdisk;Ramdisk Driver;c:\windows\system32\DRIVERS\rramdisk.sys [2009-04-30 12288] S1 cbfs3;cbfs3;c:\windows\system32\drivers\cbfs3.sys [2010-05-15 265800] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-30 218688] S1 MpKsl66cf2e2f;MpKsl66cf2e2f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys [x] S1 MpKslf60824b1;MpKslf60824b1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5E64436B-C2AC-415B-A79B-85CA355D720B}\MpKslf60824b1.sys [2011-04-01 28752] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-03-19 2964312] S2 MCSWASVR;Mediencenter Service;c:\program files\Telekom\Mediencenter\WebDAV.AdminService.exe [2010-07-09 16016] S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [2009-06-07 61440] S2 sesvc;ShadowExplorer Service;c:\program files\ShadowExplorer\sesvc.exe [2011-01-02 9216] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-11-30 5120] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-09-21 4867952] S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-06-06 3406120] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-09-21 414576] S2 Windows7FirewallService;Windows7FirewallService;c:\program files\Windows7FirewallControl\Windows7FirewallService.exe [2010-11-01 401408] S3 echondgo;Indigo Service;c:\windows\system32\drivers\echondgo.sys [2009-12-08 132544] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392] S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - MPKSLF60824B1 . Inhalt des "geplante Tasks" Ordners . 2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30] . 2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 19:30] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://google.de/ uInternet Settings,ProxyOverride = *.local IE: add to &BOM - c:\\PROGRA~1\\BIET-O~1\\\\AddToBOM.hta IE: Free YouTube Download - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm IE: Free YouTube to Mp3 Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm IE: {{27914077-B4D6-4A0E-9763-76B6E9DD9A81} - c:\program files\Buyertools Reminder\ReminderIE.exe Trusted Zone: ***-lieblein.de FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://google.de FF - prefs.js: keyword.URL - hxxp://go.gmx.net/tb/mff_keyurl_search/?su= FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - c:\program files\Mozilla Firefox\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6} FF - Ext: Dictionary Switcher: dictionary-switcher@design-noir.de - %profile%\extensions\dictionary-switcher@design-noir.de FF - Ext: Dictionary (EN/DE): dictlookup@arnhold.com - %profile%\extensions\dictlookup@arnhold.com FF - Ext: BabelFish: {ca0849e8-2c76-42ae-9abe-34e14d337acf} - %profile%\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf} FF - Ext: German Dictionary: de-DE@dictionaries.addons.mozilla.org - %profile%\extensions\de-DE@dictionaries.addons.mozilla.org FF - Ext: United States English Spellchecker: en-US@dictionaries.addons.mozilla.org - %profile%\extensions\en-US@dictionaries.addons.mozilla.org FF - Ext: Buyertools: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A} - %profile%\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A} FF - Ext: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - %profile%\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com FF - Ext: Vacuum Places Improved: VacuumPlacesImproved@lultimouomo-gmail.com - %profile%\extensions\VacuumPlacesImproved@lultimouomo-gmail.com FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com FF - Ext: Lazarus: Form Recovery: lazarus@interclue.com - %profile%\extensions\lazarus@interclue.com FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard FF - Ext: Fasterfox Lite: FasterFox_Lite@BigRedBrent - %profile%\extensions\FasterFox_Lite@BigRedBrent FF - Ext: WebMail Notifier: {37fa1426-b82d-11db-8314-0800200c9a66} - %profile%\extensions\{37fa1426-b82d-11db-8314-0800200c9a66} FF - Ext: Biet-O-Matic Firefox Erweiterung: {B0D70E72-2FC1-4b9f-A3D4-5921C854D906} - %profile%\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906} . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2011-04-01 21:27:41 ComboFix-quarantined-files.txt 2011-04-01 19:27 ComboFix2.txt 2011-04-01 13:00 . Vor Suchlauf: 21 Verzeichnis(se), 72.211.468.288 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 72.157.392.896 Bytes frei . - - End Of File - - ADDCA751A69EA0B5BBFCC830681AD85C Geändert von ronze44 (01.04.2011 um 20:52 Uhr) |
02.04.2011, 13:26 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html
__________________ Logfiles bitte immer in CODE-Tags posten |
02.04.2011, 21:34 | #21 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Danke Arne, no infections found - LOG: 2011/04/02 22:29:33.0884 5520 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28 2011/04/02 22:29:34.0055 5520 ================================================================================ 2011/04/02 22:29:34.0055 5520 SystemInfo: 2011/04/02 22:29:34.0055 5520 2011/04/02 22:29:34.0055 5520 OS Version: 6.1.7601 ServicePack: 1.0 2011/04/02 22:29:34.0055 5520 Product type: Workstation 2011/04/02 22:29:34.0055 5520 ComputerName: ***-PC 2011/04/02 22:29:34.0055 5520 UserName: *** 2011/04/02 22:29:34.0055 5520 Windows directory: C:\Windows 2011/04/02 22:29:34.0055 5520 System windows directory: C:\Windows 2011/04/02 22:29:34.0055 5520 Processor architecture: Intel x86 2011/04/02 22:29:34.0055 5520 Number of processors: 2 2011/04/02 22:29:34.0055 5520 Page size: 0x1000 2011/04/02 22:29:34.0055 5520 Boot type: Normal boot 2011/04/02 22:29:34.0055 5520 ================================================================================ 2011/04/02 22:29:34.0773 5520 Initialize success 2011/04/02 22:29:49.0794 4844 ================================================================================ 2011/04/02 22:29:49.0794 4844 Scan started 2011/04/02 22:29:49.0794 4844 Mode: Manual; 2011/04/02 22:29:49.0794 4844 ================================================================================ 2011/04/02 22:29:50.0308 4844 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 2011/04/02 22:29:50.0433 4844 a2acc (71574a98093d94bdbb3cb74e272d29a5) C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys 2011/04/02 22:29:50.0574 4844 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 2011/04/02 22:29:50.0698 4844 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 2011/04/02 22:29:50.0839 4844 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 2011/04/02 22:29:50.0886 4844 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 2011/04/02 22:29:50.0995 4844 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 2011/04/02 22:29:51.0073 4844 AFD (1151fd4fb0216cfed887bfde29ebd516) C:\Windows\system32\drivers\afd.sys 2011/04/02 22:29:51.0166 4844 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 2011/04/02 22:29:51.0229 4844 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 2011/04/02 22:29:51.0385 4844 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 2011/04/02 22:29:51.0416 4844 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 2011/04/02 22:29:51.0447 4844 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 2011/04/02 22:29:51.0572 4844 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 2011/04/02 22:29:51.0588 4844 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 2011/04/02 22:29:51.0681 4844 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys 2011/04/02 22:29:51.0712 4844 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 2011/04/02 22:29:51.0728 4844 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys 2011/04/02 22:29:51.0868 4844 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 2011/04/02 22:29:51.0962 4844 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 2011/04/02 22:29:52.0040 4844 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 2011/04/02 22:29:52.0118 4844 Aspi32 (5b01af89d16d562825c4db4530f20cbb) C:\Windows\system32\drivers\aspi32.sys 2011/04/02 22:29:52.0165 4844 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/04/02 22:29:52.0258 4844 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 2011/04/02 22:29:52.0336 4844 athr (76bab0c824e2d05b940c4dd40a9b08bf) C:\Windows\system32\DRIVERS\athr.sys 2011/04/02 22:29:52.0524 4844 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 2011/04/02 22:29:52.0586 4844 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 2011/04/02 22:29:52.0726 4844 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 2011/04/02 22:29:52.0789 4844 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 2011/04/02 22:29:52.0820 4844 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 2011/04/02 22:29:52.0851 4844 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2011/04/02 22:29:52.0945 4844 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2011/04/02 22:29:52.0992 4844 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 2011/04/02 22:29:53.0023 4844 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 2011/04/02 22:29:53.0054 4844 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 2011/04/02 22:29:53.0163 4844 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 2011/04/02 22:29:53.0179 4844 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 2011/04/02 22:29:53.0335 4844 cbfs3 (afab1d4cab04218cbab0ae69625d0d65) C:\Windows\system32\drivers\cbfs3.sys 2011/04/02 22:29:53.0444 4844 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 2011/04/02 22:29:53.0600 4844 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys 2011/04/02 22:29:53.0678 4844 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 2011/04/02 22:29:53.0772 4844 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 2011/04/02 22:29:53.0881 4844 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/04/02 22:29:53.0928 4844 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 2011/04/02 22:29:54.0037 4844 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 2011/04/02 22:29:54.0099 4844 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 2011/04/02 22:29:54.0177 4844 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys 2011/04/02 22:29:54.0286 4844 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 2011/04/02 22:29:54.0411 4844 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 2011/04/02 22:29:54.0583 4844 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 2011/04/02 22:29:54.0645 4844 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 2011/04/02 22:29:54.0754 4844 DKbFltr (c701324c9e0c25dd9d60311bd87fbc84) C:\Windows\system32\DRIVERS\DKbFltr.sys 2011/04/02 22:29:54.0848 4844 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 2011/04/02 22:29:54.0957 4844 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys 2011/04/02 22:29:55.0035 4844 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 2011/04/02 22:29:55.0269 4844 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 2011/04/02 22:29:55.0472 4844 EchoIndigo (aa9d3951465cff3137c6b531e19fb21b) C:\Windows\system32\DRIVERS\echondgo.sys 2011/04/02 22:29:55.0534 4844 echondgo (aa9d3951465cff3137c6b531e19fb21b) C:\Windows\system32\drivers\echondgo.sys 2011/04/02 22:29:55.0612 4844 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 2011/04/02 22:29:55.0722 4844 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 2011/04/02 22:29:55.0831 4844 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 2011/04/02 22:29:55.0878 4844 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 2011/04/02 22:29:55.0924 4844 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 2011/04/02 22:29:56.0034 4844 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 2011/04/02 22:29:56.0080 4844 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 2011/04/02 22:29:56.0112 4844 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/04/02 22:29:56.0236 4844 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 2011/04/02 22:29:56.0299 4844 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 2011/04/02 22:29:56.0346 4844 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 2011/04/02 22:29:56.0455 4844 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 2011/04/02 22:29:56.0564 4844 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 2011/04/02 22:29:56.0658 4844 ggflt (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys 2011/04/02 22:29:56.0720 4844 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys 2011/04/02 22:29:56.0860 4844 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 2011/04/02 22:29:56.0938 4844 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 2011/04/02 22:29:57.0032 4844 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys 2011/04/02 22:29:57.0126 4844 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 2011/04/02 22:29:57.0141 4844 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 2011/04/02 22:29:57.0219 4844 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 2011/04/02 22:29:57.0344 4844 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys 2011/04/02 22:29:57.0469 4844 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 2011/04/02 22:29:57.0594 4844 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 2011/04/02 22:29:57.0703 4844 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 2011/04/02 22:29:57.0765 4844 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys 2011/04/02 22:29:57.0890 4844 iaStor (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\DRIVERS\iaStor.sys 2011/04/02 22:29:57.0968 4844 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys 2011/04/02 22:29:58.0327 4844 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/04/02 22:29:58.0686 4844 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 2011/04/02 22:29:58.0842 4844 IntcAzAudAddService (f2baa4ff548f7f0317f7638951c1cd9c) C:\Windows\system32\drivers\RTKVHDA.sys 2011/04/02 22:29:59.0013 4844 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 2011/04/02 22:29:59.0091 4844 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 2011/04/02 22:29:59.0200 4844 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/04/02 22:29:59.0263 4844 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 2011/04/02 22:29:59.0294 4844 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 2011/04/02 22:29:59.0434 4844 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 2011/04/02 22:29:59.0466 4844 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 2011/04/02 22:29:59.0497 4844 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 2011/04/02 22:29:59.0622 4844 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/04/02 22:29:59.0684 4844 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/04/02 22:29:59.0731 4844 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys 2011/04/02 22:29:59.0840 4844 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 2011/04/02 22:29:59.0949 4844 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/04/02 22:30:00.0090 4844 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 2011/04/02 22:30:00.0105 4844 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 2011/04/02 22:30:00.0136 4844 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2011/04/02 22:30:00.0152 4844 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2011/04/02 22:30:00.0214 4844 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 2011/04/02 22:30:00.0386 4844 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 2011/04/02 22:30:00.0433 4844 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 2011/04/02 22:30:00.0464 4844 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 2011/04/02 22:30:00.0511 4844 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 2011/04/02 22:30:00.0620 4844 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 2011/04/02 22:30:00.0714 4844 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 2011/04/02 22:30:00.0745 4844 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 2011/04/02 22:30:00.0901 4844 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\Windows\system32\DRIVERS\MpFilter.sys 2011/04/02 22:30:00.0932 4844 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 2011/04/02 22:30:01.0150 4844 MpKsl8deaba55 (5f53edfead46fa7adb78eee9ecce8fdf) C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{873FC184-6AD4-4794-8ECA-AE39170733D4}\MpKsl8deaba55.sys 2011/04/02 22:30:01.0306 4844 MpNWMon (f32e2d6a1640a469a9ed4f1929a4a861) C:\Windows\system32\DRIVERS\MpNWMon.sys 2011/04/02 22:30:01.0353 4844 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 2011/04/02 22:30:01.0416 4844 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 2011/04/02 22:30:01.0540 4844 mrxsmb (b272b4c3e085ea860c12f2e4faf2ffa2) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/04/02 22:30:01.0572 4844 mrxsmb10 (9ac33ef26c8a3ad0f117d00eb7301d03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/04/02 22:30:01.0603 4844 mrxsmb20 (e0abdb5ed7e199e242a7d028e76c1d3a) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/04/02 22:30:01.0634 4844 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 2011/04/02 22:30:01.0728 4844 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 2011/04/02 22:30:01.0790 4844 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 2011/04/02 22:30:01.0821 4844 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 2011/04/02 22:30:01.0837 4844 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 2011/04/02 22:30:01.0962 4844 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 2011/04/02 22:30:02.0040 4844 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/04/02 22:30:02.0055 4844 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 2011/04/02 22:30:02.0149 4844 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 2011/04/02 22:30:02.0196 4844 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys 2011/04/02 22:30:02.0242 4844 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 2011/04/02 22:30:02.0289 4844 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 2011/04/02 22:30:02.0367 4844 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 2011/04/02 22:30:02.0445 4844 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 2011/04/02 22:30:02.0601 4844 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 2011/04/02 22:30:02.0726 4844 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 2011/04/02 22:30:02.0773 4844 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/04/02 22:30:02.0835 4844 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/04/02 22:30:02.0944 4844 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/04/02 22:30:03.0022 4844 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 2011/04/02 22:30:03.0132 4844 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 2011/04/02 22:30:03.0178 4844 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 2011/04/02 22:30:03.0334 4844 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 2011/04/02 22:30:03.0444 4844 NisDrv (17e2c08c5ecfbe94a7c67b1c275ee9d9) C:\Windows\system32\DRIVERS\NisDrvWFP.sys 2011/04/02 22:30:03.0615 4844 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 2011/04/02 22:30:03.0646 4844 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 2011/04/02 22:30:03.0802 4844 Ntfs (33c3093d09017cfe2e219f2472bff6eb) C:\Windows\system32\drivers\Ntfs.sys 2011/04/02 22:30:03.0912 4844 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 2011/04/02 22:30:03.0990 4844 nvraid (af2eec9580c1d32fb7eaf105d9784061) C:\Windows\system32\drivers\nvraid.sys 2011/04/02 22:30:04.0021 4844 nvstor (9283c58ebaa2618f93482eb5dabcec82) C:\Windows\system32\drivers\nvstor.sys 2011/04/02 22:30:04.0114 4844 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 2011/04/02 22:30:04.0161 4844 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 2011/04/02 22:30:04.0317 4844 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 2011/04/02 22:30:04.0364 4844 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys 2011/04/02 22:30:04.0395 4844 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 2011/04/02 22:30:04.0426 4844 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 2011/04/02 22:30:04.0520 4844 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 2011/04/02 22:30:04.0582 4844 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 2011/04/02 22:30:04.0614 4844 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 2011/04/02 22:30:04.0660 4844 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 2011/04/02 22:30:04.0785 4844 PenClass (4a108cc9cc0e0605e68cce7021479879) C:\Windows\system32\Drivers\PenClass.sys 2011/04/02 22:30:04.0926 4844 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 2011/04/02 22:30:05.0035 4844 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 2011/04/02 22:30:05.0113 4844 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 2011/04/02 22:30:05.0238 4844 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 2011/04/02 22:30:05.0347 4844 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 2011/04/02 22:30:05.0394 4844 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 2011/04/02 22:30:05.0409 4844 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 2011/04/02 22:30:05.0487 4844 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 2011/04/02 22:30:05.0565 4844 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/04/02 22:30:05.0628 4844 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/04/02 22:30:05.0674 4844 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 2011/04/02 22:30:05.0784 4844 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 2011/04/02 22:30:05.0846 4844 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 2011/04/02 22:30:05.0893 4844 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/04/02 22:30:06.0002 4844 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 2011/04/02 22:30:06.0033 4844 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 2011/04/02 22:30:06.0080 4844 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys 2011/04/02 22:30:06.0142 4844 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 2011/04/02 22:30:06.0298 4844 RRamdisk (519d3c83d04bc3e0289e80f61d2febc0) C:\Windows\system32\DRIVERS\rramdisk.sys 2011/04/02 22:30:06.0376 4844 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 2011/04/02 22:30:06.0501 4844 s0017bus (594ff5620661d1386475406e78cb6f2f) C:\Windows\system32\DRIVERS\s0017bus.sys 2011/04/02 22:30:06.0548 4844 s0017mdfl (7258f550419d543bc5c8e80c578a5d54) C:\Windows\system32\DRIVERS\s0017mdfl.sys 2011/04/02 22:30:06.0579 4844 s0017mdm (1de4f6607feb17a15dbd4f1b139e6d2f) C:\Windows\system32\DRIVERS\s0017mdm.sys 2011/04/02 22:30:06.0688 4844 s0017mgmt (9814e6bacc06d2526cd52981c7eeedf0) C:\Windows\system32\DRIVERS\s0017mgmt.sys 2011/04/02 22:30:06.0751 4844 s0017nd5 (2c62cd58225973f26682cd4f783ddede) C:\Windows\system32\DRIVERS\s0017nd5.sys 2011/04/02 22:30:06.0860 4844 s0017obex (f87c3422e84b2fb1b43e0a26247ad5a5) C:\Windows\system32\DRIVERS\s0017obex.sys 2011/04/02 22:30:06.0891 4844 s0017unic (df5e7360a0afa5956bf75da683d0679f) C:\Windows\system32\DRIVERS\s0017unic.sys 2011/04/02 22:30:06.0938 4844 s217bus (0266151de3f36429f6ac3c4b28085061) C:\Windows\system32\DRIVERS\s217bus.sys 2011/04/02 22:30:07.0063 4844 s217mdfl (a43c0af0e46be7ef0c7e8ccf0f058600) C:\Windows\system32\DRIVERS\s217mdfl.sys 2011/04/02 22:30:07.0094 4844 s217mdm (005f5ded1ed8f8a9d2399d765ead20f1) C:\Windows\system32\DRIVERS\s217mdm.sys 2011/04/02 22:30:07.0125 4844 s217mgmt (de9562ad0c91e1857d11f65a91ee1a47) C:\Windows\system32\DRIVERS\s217mgmt.sys 2011/04/02 22:30:07.0250 4844 s217nd5 (11cc5d7f992799e7e75d018e9c018563) C:\Windows\system32\DRIVERS\s217nd5.sys 2011/04/02 22:30:07.0297 4844 s217obex (0f9f4045799afb66b85eef999d0609ec) C:\Windows\system32\DRIVERS\s217obex.sys 2011/04/02 22:30:07.0328 4844 s217unic (1c91e1023f07b6407d84b5a43537d984) C:\Windows\system32\DRIVERS\s217unic.sys 2011/04/02 22:30:07.0453 4844 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 2011/04/02 22:30:07.0500 4844 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 2011/04/02 22:30:07.0578 4844 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/04/02 22:30:07.0687 4844 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys 2011/04/02 22:30:07.0765 4844 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 2011/04/02 22:30:07.0812 4844 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 2011/04/02 22:30:07.0905 4844 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 2011/04/02 22:30:08.0030 4844 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 2011/04/02 22:30:08.0108 4844 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 2011/04/02 22:30:08.0155 4844 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 2011/04/02 22:30:08.0202 4844 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 2011/04/02 22:30:08.0233 4844 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 2011/04/02 22:30:08.0358 4844 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2011/04/02 22:30:08.0389 4844 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 2011/04/02 22:30:08.0420 4844 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 2011/04/02 22:30:08.0560 4844 snapman (bcc773872041aa59bc9a6cf770fb32e2) C:\Windows\system32\DRIVERS\snapman.sys 2011/04/02 22:30:08.0607 4844 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 2011/04/02 22:30:08.0685 4844 srv (112127c3b2e64d7680cc39cd0a39dd7e) C:\Windows\system32\DRIVERS\srv.sys 2011/04/02 22:30:08.0794 4844 srv2 (e5dd784a4ee5ebc72a86c677c988fcdb) C:\Windows\system32\DRIVERS\srv2.sys 2011/04/02 22:30:08.0857 4844 srvnet (cdbe627e16cc9e98f343d73f8e81d258) C:\Windows\system32\DRIVERS\srvnet.sys 2011/04/02 22:30:08.0982 4844 SSPORT (ef3458337d7341a05169cefc73709264) C:\Windows\system32\Drivers\SSPORT.sys 2011/04/02 22:30:09.0060 4844 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\Windows\system32\drivers\StarOpen.sys 2011/04/02 22:30:09.0122 4844 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 2011/04/02 22:30:09.0247 4844 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys 2011/04/02 22:30:09.0340 4844 SynasUSB (e46088b882e6315518630e249ddf958c) C:\Windows\system32\drivers\SynasUSB.sys 2011/04/02 22:30:09.0590 4844 Tcpip (37e8fa3779668837ca9e2c36d2415949) C:\Windows\system32\drivers\tcpip.sys 2011/04/02 22:30:09.0777 4844 TCPIP6 (37e8fa3779668837ca9e2c36d2415949) C:\Windows\system32\DRIVERS\tcpip.sys 2011/04/02 22:30:09.0902 4844 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 2011/04/02 22:30:09.0964 4844 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 2011/04/02 22:30:10.0042 4844 tdrpman (3b7b6779eb231f731bba8f9fe67aadfc) C:\Windows\system32\DRIVERS\tdrpman.sys 2011/04/02 22:30:10.0152 4844 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys 2011/04/02 22:30:10.0198 4844 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 2011/04/02 22:30:10.0245 4844 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys 2011/04/02 22:30:10.0370 4844 tifsfilter (b0b3122bff3910e0ba97014045467778) C:\Windows\system32\DRIVERS\tifsfilt.sys 2011/04/02 22:30:10.0417 4844 timounter (13bfe330880ac0ce8672d00aa5aff738) C:\Windows\system32\DRIVERS\timntr.sys 2011/04/02 22:30:10.0604 4844 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/04/02 22:30:10.0666 4844 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 2011/04/02 22:30:10.0807 4844 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 2011/04/02 22:30:10.0869 4844 TVicPort (3147063508eae931becc01573c204fac) C:\Windows\system32\DRIVERS\TVICPORT.SYS 2011/04/02 22:30:10.0994 4844 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 2011/04/02 22:30:11.0056 4844 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 2011/04/02 22:30:11.0212 4844 UDST7000BDA (d785cdc0d6e27aa27dc30d3b3aad7819) C:\Windows\system32\DRIVERS\TerraTecUsbBda.sys 2011/04/02 22:30:11.0353 4844 UDST7000HID (527fea6f1669fca060c8fa17174db19b) C:\Windows\system32\DRIVERS\TerraTecUsbHid.sys 2011/04/02 22:30:11.0462 4844 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 2011/04/02 22:30:11.0587 4844 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys 2011/04/02 22:30:11.0634 4844 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 2011/04/02 22:30:11.0758 4844 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys 2011/04/02 22:30:11.0790 4844 usbccgp (7e72e7d7e0757d59481d530fd2b0bfae) C:\Windows\system32\drivers\usbccgp.sys 2011/04/02 22:30:11.0821 4844 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 2011/04/02 22:30:11.0868 4844 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 2011/04/02 22:30:11.0992 4844 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\drivers\usbhub.sys 2011/04/02 22:30:12.0039 4844 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 2011/04/02 22:30:12.0102 4844 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 2011/04/02 22:30:12.0195 4844 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 2011/04/02 22:30:12.0258 4844 USBSTOR (bf63ebfc6979fefb2bc03df7989a0c1a) C:\Windows\system32\drivers\USBSTOR.SYS 2011/04/02 22:30:12.0304 4844 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/04/02 22:30:12.0429 4844 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys 2011/04/02 22:30:12.0507 4844 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 2011/04/02 22:30:12.0570 4844 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/04/02 22:30:12.0648 4844 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 2011/04/02 22:30:12.0710 4844 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 2011/04/02 22:30:12.0772 4844 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 2011/04/02 22:30:12.0866 4844 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 2011/04/02 22:30:12.0928 4844 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 2011/04/02 22:30:12.0944 4844 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 2011/04/02 22:30:13.0038 4844 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 2011/04/02 22:30:13.0116 4844 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 2011/04/02 22:30:13.0225 4844 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 2011/04/02 22:30:13.0287 4844 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys 2011/04/02 22:30:13.0396 4844 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 2011/04/02 22:30:13.0490 4844 wacmoumonitor (f24ee97511fb901189e11cbbd51605ba) C:\Windows\system32\DRIVERS\wacmoumonitor.sys 2011/04/02 22:30:13.0584 4844 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\Windows\system32\DRIVERS\wacommousefilter.sys 2011/04/02 22:30:13.0646 4844 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 2011/04/02 22:30:13.0771 4844 wacomvhid (73e6f16a1f187d71fb26af308551e54a) C:\Windows\system32\DRIVERS\wacomvhid.sys 2011/04/02 22:30:13.0833 4844 WacomVKHid (889459833432b161cb99cfdf84a1a9bb) C:\Windows\system32\DRIVERS\WacomVKHid.sys 2011/04/02 22:30:13.0958 4844 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 2011/04/02 22:30:13.0974 4844 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 2011/04/02 22:30:14.0114 4844 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 2011/04/02 22:30:14.0208 4844 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2011/04/02 22:30:14.0364 4844 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 2011/04/02 22:30:14.0395 4844 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 2011/04/02 22:30:14.0613 4844 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys 2011/04/02 22:30:14.0707 4844 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 2011/04/02 22:30:14.0847 4844 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/04/02 22:30:14.0925 4844 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 2011/04/02 22:30:15.0066 4844 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/04/02 22:30:15.0190 4844 ================================================================================ 2011/04/02 22:30:15.0190 4844 Scan finished 2011/04/02 22:30:15.0190 4844 ================================================================================ Geändert von ronze44 (02.04.2011 um 21:41 Uhr) |
03.04.2011, 13:55 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
03.04.2011, 17:46 | #23 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL danke Arne. Der Gemer hat mich den ganzen Nachmittag umsonst gekostet. Hat gescannt und nach drei Stunden ungefähr war er fertig, aber als ich drauf klickte ist er abgestürzt mit samt seiner 32 Milliarden Daten. Er hat auf meiner Ramdisk, der ja der Temp Ordner namens T ist einen Windows Ordner mit tausenden Dateien gescannt, den ich gar nicht dort sehe. Na ja, muss ja nicht alles verstehen. Hier der OSAM: OSAM Logfile: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 18:37:17 on 03.04.2011 OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit Default Browser: Mozilla Corporation Firefox 3.6.16 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe "GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe [Control Panel Objects] -----( %SystemRoot%\system32 )----- "ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl "PLWMidiMap.cpl" - "Putzlowitsch" - C:\Windows\system32\PLWMidiMap.cpl "WacomTablet.cpl" - "Wacom Technology, Corp." - C:\Windows\system32\WacomTablet.cpl -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "Bamboo" - "Wacom Technology, Corp." - C:\Program Files\Tablet\Pen\Consumer_CPL.exe "QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl "Wacom Tablett" - "Wacom Technology, Corp." - C:\Windows\system32\WacomTablet.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "a2acc" (a2acc) - "Emsi Software GmbH" - C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys "Acronis Snapshots Manager" (snapman) - "Acronis" - C:\Windows\System32\DRIVERS\snapman.sys "Acronis True Image Backup Archive Explorer" (timounter) - "Acronis" - C:\Windows\System32\DRIVERS\timntr.sys "Acronis True Image FS Filter" (tifsfilter) - "Acronis" - C:\Windows\System32\DRIVERS\tifsfilt.sys "Acronis Try&Decide and Restore Points filter" (tdrpman) - "Acronis" - C:\Windows\System32\DRIVERS\tdrpman.sys "Aspi32" (Aspi32) - "Adaptec" - C:\Windows\System32\drivers\aspi32.sys "catchme" (catchme) - ? - T:\TEMP\catchme.sys (File not found) "cbfs3" (cbfs3) - "EldoS Corporation" - C:\Windows\system32\drivers\cbfs3.sys "DgiVecp" (DgiVecp) - ? - C:\Windows\system32\Drivers\DgiVecp.sys (File not found) "kgldipod" (kgldipod) - ? - T:\TEMP\kgldipod.sys (Hidden registry entry, rootkit activity | File not found) "mbr" (mbr) - ? - C:\Cofi.exe\mbr.sys (Hidden registry entry, rootkit activity | File not found) "MpKsl66cf2e2f" (MpKsl66cf2e2f) - ? - C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys (File not found) "MpKsl892c9348" (MpKsl892c9348) - "Microsoft Corporation" - C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A5ADC00A-7806-463E-9C83-E5C9B3D122FF}\MpKsl892c9348.sys "MpKslda63107b" (MpKslda63107b) - ? - C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{66193AB5-5D42-498E-A3C9-EF5CAC0D8D2D}\MpKslda63107b.sys (File not found) "Pen Class" (PenClass) - "Wacom Technology Corporation" - C:\Windows\System32\Drivers\PenClass.sys "Ramdisk Driver" (RRamdisk) - "gavotte" - C:\Windows\System32\DRIVERS\rramdisk.sys "SSPORT" (SSPORT) - "Samsung Electronics" - C:\Windows\system32\Drivers\SSPORT.sys "StarOpen" (StarOpen) - ? - C:\Windows\system32\drivers\StarOpen.sys (File found, but it contains no detailed information) "SynasUSB" (SynasUSB) - "SIA Syncrosoft" - C:\Windows\System32\drivers\SynasUSB.sys "TVICPORT" (TVicPort) - "EnTech Taiwan" - C:\Windows\system32\DRIVERS\TVICPORT.SYS [Explorer] -----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll -----( HKLM\Software\Classes\Protocols\Handler )----- {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler )----- {1984DD45-52CF-49cd-AB77-18F378FEA264} "FencesShlExt Class" - "Stardock" - C:\Program Files\Stardock\Fences\FencesMenu.dll {1984D045-52CF-49cd-DB77-08F378FEA4DB} "ObjectDockShlExt Class" - "Stardock" - C:\Program Files\Stardock\ObjectDockPlus2\ODMenu.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll {C539A15A-3AF9-4c92-B771-50CB78F5C751} "Acronis True Image Shell Context Menu Extension" - "Acronis" - C:\Program Files\Acronis\TrueImageHome\tishell.dll {C539A15B-3AF9-4c92-B771-50CB78F5C751} "Acronis True Image Shell Extension" - "Acronis" - C:\Program Files\Acronis\TrueImageHome\tishell.dll {09A47860-11B0-4DA5-AFA5-26D86198A780} "EPP" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~4\shellext.dll {693BE9C0-BEC3-11D2-B4C1-C33BBD3AD64B} "Fast Explorer Shell Extension" - "Alex Yakovlev" - C:\ProgramData\AllDup\FEShlExt.dll {1984DD45-52CF-49cd-AB77-18F378FEA264} "FencesShlExt Class" - "Stardock" - C:\Program Files\Stardock\Fences\FencesMenu.dll {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll {1984D045-52CF-49cd-DB77-08F378FEA4DB} "ObjectDockShlExt Class" - "Stardock" - C:\Program Files\Stardock\ObjectDockPlus2\ODMenu.dll {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {4CF20B46-D006-4B90-A64B-DBAA9470EFBE} "PhotoToysClone" - "Brice Lambson" - C:\Program Files\Brice Lambson\PhotoToysClone\PhotoToysClone.dll {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? - (File not found | COM-object registry key not found) {BD88A479-9623-4897-8546-BC62B9628F44} "SPTHandler" - ? - (File not found | COM-object registry key not found) {0420B051-ECD8-4B18-9037-8739B4B6469F} "WebDavContextMenu Class" - "Deutsche Telekom AG" - C:\Windows\system32\WebDAV.ShellExtension.dll {0774B5A9-ADB5-4D3A-915F-72C7EF9CD262} "WebDavOverlayUpload Class" - "Deutsche Telekom AG" - C:\Windows\system32\WebDAV.ShellExtension.dll {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? - (File not found | COM-object registry key not found) {06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe {1984D045-52CF-49cd-DB77-08F378FEA4DB} {000214e8-0000-0000-c000-000000000046} 0x401 "{1984D045-52CF-49cd-DB77-08F378FEA4DB} {000214e8-0000-0000-c000-000000000046} 0x401" - ? - (File not found | COM-object registry key not found) {1984DD45-52CF-49cd-AB77-18F378FEA264} {000214e8-0000-0000-c000-000000000046} 0x401 "{1984DD45-52CF-49cd-AB77-18F378FEA264} {000214e8-0000-0000-c000-000000000046} 0x401" - ? - (File not found | COM-object registry key not found) [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) <binary data> "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll -----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )----- {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_23.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll "Buyertools Reminder" - ? - C:\Program Files\Buyertools Reminder\ReminderIE.exe (File found, but it contains no detailed information) -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- {AD6E6555-FB2C-47D4-8339-3E2965509877} "TerraTec Home Cinema" - "TerraTec Electronic GmbH" - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll {7C7A8947-5935-4430-AC0E-E7D04697414E} "Buyertools" - ? - C:\PROGRA~1\BUYERT~1\IEBUTT~1.DLL (File found, but it contains no detailed information) {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll {9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" - "Conduit Ltd." - C:\Program Files\Winload\tbWinl.dll [LSA Providers] -----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )----- "Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "Dropbox.lnk" - "Dropbox, Inc." - C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Shortcut exists | File exists) "Stardock ObjectDock.lnk" - "Stardock" - C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe (Shortcut exists | File exists) -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "McAfee Security Scan Plus.lnk" - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (Shortcut exists | File exists) -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "Buyertools Reminder" - "Buyertools Ltd." - "C:\Program Files\Buyertools Reminder\Reminder.exe" /autorun "DAEMON Tools Lite" - "DT Soft Ltd" - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun "ISUSPM" - "Macrovision Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler "Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized -----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )----- "StartupPrograms" - ? - rdpclip (File not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "ACFanControl" - "troubadix" - C:\Program Files\ACFanControl\ACFanControl.exe "Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" "Windows7FirewallControl" - "Sphinx Software" - C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe [Network Providers] -----( HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order )----- "Virtual Network Shares CallbackFS v3" - "EldoS Corporation" - C:\Windows\System32\CbFsNetRdr3.dll [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll (File found, but it contains no detailed information) "SSA1M Langmon" - ? - C:\Windows\system32\ssa1ml3.dll [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243" (NisSrv) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe "Acronis Scheduler2 Service" (AcrSch2Svc) - "Acronis" - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe "Acronis Try And Decide Service" (TryAndDecideService) - ? - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe (File found, but it contains no detailed information) "Emsisoft Anti-Malware 5.0 - Service" (a2AntiMalware) - "Emsi Software GmbH" - C:\Program Files\Emsisoft Anti-Malware\a2service.exe "Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe "InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe "McAfee Security Scan Component Host Service" (McComponentHostService) - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe "Mediencenter Service" (MCSWASVR) - "Deutsche Telekom AG" - C:\Program Files\Telekom\Mediencenter\WebDAV.AdminService.exe "Microsoft Antimalware Service" (MsMpSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe "Nalpeiron Licensing Service" (nlsX86cc) - "Nalpeiron Ltd." - C:\Windows\system32\NlsSrv32.exe "NMSAccessU" (NMSAccessU) - ? - C:\Program Files\CDBurnerXP\NMSAccessU.exe (File found, but it contains no detailed information) "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "ShadowExplorer Service" (sesvc) - "www.shadowexplorer.com" - C:\Program Files\ShadowExplorer\sesvc.exe "Sony Ericsson OMSI download service" (OMSI download service) - ? - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe (File found, but it contains no detailed information) "TabletServicePen" (TabletServicePen) - "Wacom Technology, Corp." - C:\Program Files\Tablet\Pen\Pen_Tablet.exe "TabletServiceWacom" (TabletServiceWacom) - "Wacom Technology, Corp." - C:\Windows\system32\Wacom_Tablet.exe "Wacom Consumer Touch Service" (TouchServicePen) - "Wacom Technology, Corp." - C:\Program Files\Tablet\Pen\Pen_TouchService.exe "Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE "Windows7FirewallService" (Windows7FirewallService) - "Sphinx Software" - C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe [Winsock Providers] -----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )----- "WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL "WindowsLive NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Und Hier MBRCheck: MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows 7 Home Premium Edition Windows Information: Service Pack 1 (build 7601), 32-bit Base Board Manufacturer: Acer, Inc. BIOS Manufacturer: Acer System Manufacturer: Acer, inc. System Product Name: Extensa 7630EZ Logical Drives Mask: 0x0008003c Kernel Drivers (total 208): 0x82E03000 \SystemRoot\system32\ntkrnlpa.exe 0x83215000 \SystemRoot\system32\halmacpi.dll 0x80BAD000 \SystemRoot\system32\kdcom.dll 0x83818000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x8389D000 \SystemRoot\system32\PSHED.dll 0x838AE000 \SystemRoot\system32\BOOTVID.dll 0x838B6000 \SystemRoot\system32\CLFS.SYS 0x838F8000 \SystemRoot\system32\CI.dll 0x83A23000 \SystemRoot\system32\drivers\Wdf01000.sys 0x83A94000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x83AA2000 \SystemRoot\system32\drivers\ACPI.sys 0x83AEA000 \SystemRoot\system32\drivers\WMILIB.SYS 0x83AF3000 \SystemRoot\system32\drivers\msisadrv.sys 0x83AFB000 \SystemRoot\system32\drivers\pci.sys 0x83B25000 \SystemRoot\system32\drivers\vdrvroot.sys 0x83B30000 \SystemRoot\System32\drivers\partmgr.sys 0x83B41000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x83B49000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x83B54000 \SystemRoot\system32\drivers\volmgr.sys 0x83B64000 \SystemRoot\System32\drivers\volmgrx.sys 0x83BAF000 \SystemRoot\system32\drivers\pciide.sys 0x83BB6000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x83BC4000 \SystemRoot\system32\DRIVERS\pcmcia.sys 0x83BF2000 \SystemRoot\system32\DRIVERS\rramdisk.sys 0x83A00000 \SystemRoot\System32\drivers\mountmgr.sys 0x83A16000 \SystemRoot\system32\drivers\atapi.sys 0x839A3000 \SystemRoot\system32\drivers\ataport.SYS 0x839C6000 \SystemRoot\system32\drivers\amdxata.sys 0x8B238000 \SystemRoot\system32\drivers\fltmgr.sys 0x8B26C000 \SystemRoot\system32\drivers\fileinfo.sys 0x8B27D000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8B3AC000 \SystemRoot\System32\Drivers\msrpc.sys 0x8B3D7000 \SystemRoot\System32\Drivers\ksecdd.sys 0x8B41B000 \SystemRoot\System32\Drivers\cng.sys 0x8B478000 \SystemRoot\System32\drivers\pcw.sys 0x8B486000 \SystemRoot\system32\Drivers\PenClass.sys 0x8B488000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x8B491000 \SystemRoot\system32\drivers\ndis.sys 0x8B548000 \SystemRoot\system32\drivers\NETIO.SYS 0x8B586000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x8B635000 \SystemRoot\System32\drivers\tcpip.sys 0x8B77F000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8B803000 \SystemRoot\system32\DRIVERS\timntr.sys 0x8B86E000 \SystemRoot\system32\drivers\volsnap.sys 0x8B8AD000 \SystemRoot\system32\DRIVERS\tdrpman.sys 0x8B906000 \SystemRoot\System32\Drivers\spldr.sys 0x8B90E000 \SystemRoot\system32\DRIVERS\snapman.sys 0x8B92C000 \SystemRoot\System32\drivers\rdyboost.sys 0x8B959000 \SystemRoot\System32\Drivers\mup.sys 0x8B969000 \SystemRoot\System32\drivers\hwpolicy.sys 0x8B971000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x8B9A3000 \SystemRoot\system32\DRIVERS\disk.sys 0x8B9B4000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x8B7C1000 \SystemRoot\system32\drivers\cdrom.sys 0x8B600000 \SystemRoot\system32\DRIVERS\MpFilter.sys 0x8B627000 \SystemRoot\System32\Drivers\Null.SYS 0x8B62E000 \SystemRoot\System32\Drivers\Beep.SYS 0x8B7E0000 \SystemRoot\System32\drivers\vga.sys 0x8B5AB000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8B7EC000 \SystemRoot\System32\drivers\watchdog.sys 0x8B5CC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8B5D4000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8B5DC000 \SystemRoot\system32\drivers\rdprefmp.sys 0x8B5E4000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8B5EF000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8B400000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8B3EA000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x90436000 \SystemRoot\system32\drivers\afd.sys 0x90490000 \SystemRoot\System32\DRIVERS\netbt.sys 0x904C2000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x904C9000 \SystemRoot\system32\DRIVERS\pacer.sys 0x904E8000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x904F9000 \SystemRoot\system32\DRIVERS\netbios.sys 0x90507000 \SystemRoot\system32\DRIVERS\dtsoftbus01.sys 0x90542000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x90555000 \SystemRoot\system32\drivers\termdd.sys 0x90566000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x905A7000 \SystemRoot\system32\drivers\nsiproxy.sys 0x905B1000 \SystemRoot\system32\drivers\mssmbios.sys 0x905BB000 \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{37563E15-D2A0-47B6-84A3-03FD8FCAE4B6}\MpKsl66cf2e2f.sys 0x905C1000 \SystemRoot\System32\drivers\discache.sys 0x905CD000 \SystemRoot\System32\Drivers\dfsc.sys 0x93E03000 \??\C:\Windows\system32\drivers\cbfs3.sys 0x93E42000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x93E50000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x93E71000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x93E75000 \SystemRoot\system32\drivers\wmiacpi.sys 0x95037000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 0x93E7E000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x95954000 \SystemRoot\System32\drivers\dxgmms1.sys 0x9598D000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x95998000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x959E3000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x95000000 \SystemRoot\system32\drivers\HDAudBus.sys 0x94217000 \SystemRoot\system32\DRIVERS\athr.sys 0x94327000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x94331000 \SystemRoot\system32\DRIVERS\b57nd60x.sys 0x9436D000 \SystemRoot\system32\drivers\echondgo.sys 0x94390000 \SystemRoot\system32\drivers\portcls.sys 0x943BF000 \SystemRoot\system32\drivers\drmk.sys 0x93F35000 \SystemRoot\system32\drivers\ks.sys 0x943D8000 \SystemRoot\system32\drivers\i8042prt.sys 0x943F0000 \SystemRoot\system32\DRIVERS\DKbFltr.sys 0x94200000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x9501F000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x93F69000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x959F2000 \SystemRoot\system32\drivers\CompositeBus.sys 0x9420D000 \SystemRoot\system32\DRIVERS\WacomVKHid.sys 0x93F7B000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x9420F000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x943FA000 \SystemRoot\system32\DRIVERS\wacomvhid.sys 0x93F8E000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x93FA0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x9502C000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x93FB8000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x93FDA000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x905E5000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x90400000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x93FF2000 \SystemRoot\system32\DRIVERS\seehcri.sys 0x943FC000 \SystemRoot\system32\drivers\swenum.sys 0x90417000 \SystemRoot\system32\drivers\umbus.sys 0x9AE15000 \SystemRoot\system32\drivers\usbhub.sys 0x9AE59000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x9AE65000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x9AE70000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys 0x9AE78000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x9BC04000 \SystemRoot\system32\drivers\RTKVHDA.sys 0x9BE8C000 \SystemRoot\system32\drivers\usbccgp.sys 0x9BEA3000 \SystemRoot\system32\drivers\USBD.SYS 0x9BEA5000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x9BEB0000 \SystemRoot\System32\Drivers\usbvideo.sys 0x9C050000 \SystemRoot\System32\win32k.sys 0x9BED4000 \SystemRoot\System32\drivers\Dxapi.sys 0x9BEDE000 \SystemRoot\System32\Drivers\crashdmp.sys 0x9BEEB000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x9BEF6000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x9BEFF000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x9BF10000 \SystemRoot\system32\DRIVERS\monitor.sys 0x9C2B0000 \SystemRoot\System32\TSDDD.dll 0x9C2E0000 \SystemRoot\System32\cdd.dll 0x9BF1B000 \SystemRoot\system32\drivers\luafv.sys 0x9BF36000 \SystemRoot\system32\DRIVERS\tifsfilt.sys 0x9BF40000 \SystemRoot\system32\drivers\WudfPf.sys 0x9BF5A000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x9BF6A000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x9BFB0000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x9BFC0000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x9AE89000 \SystemRoot\system32\drivers\HTTP.sys 0x9BFD3000 \SystemRoot\system32\DRIVERS\bowser.sys 0x9BFEC000 \SystemRoot\System32\drivers\mpsdrv.sys 0x9AF0E000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x9AF31000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x9AF6C000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x9BC00000 \SystemRoot\System32\drivers\aspi32.sys 0xAF607000 \SystemRoot\system32\drivers\peauth.sys 0xAF69E000 \SystemRoot\System32\Drivers\secdrv.SYS 0xAF6A8000 \SystemRoot\System32\DRIVERS\srvnet.sys 0xAF6C9000 \??\C:\Windows\system32\Drivers\SSPORT.sys 0xAF6D0000 \SystemRoot\System32\drivers\tcpipreg.sys 0xAF6DD000 \SystemRoot\System32\DRIVERS\srv2.sys 0xAF72C000 \SystemRoot\System32\DRIVERS\srv.sys 0xAF7E7000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0xAF7F0000 \??\C:\Windows\system32\Drivers\PROCEXP113.SYS 0xAF7F2000 \SystemRoot\system32\DRIVERS\MpNWMon.sys 0xAF79B000 \??\T:\TEMP\catchme.sys 0xAF785000 \SystemRoot\system32\DRIVERS\cdfs.sys 0xAF7A3000 \??\T:\TEMP\kgldipod.sys 0xAF7CA000 \SystemRoot\system32\DRIVERS\NisDrvWFP.sys 0xAF7D6000 \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A5ADC00A-7806-463E-9C83-E5C9B3D122FF}\MpKsl892c9348.sys 0x76E40000 \Windows\System32\ntdll.dll 0x475D0000 \Windows\System32\smss.exe 0x77080000 \Windows\System32\apisetschema.dll 0x00840000 \Windows\System32\autochk.exe 0x77020000 \Windows\System32\gdi32.dll 0x76FE0000 \Windows\System32\ws2_32.dll 0x76D60000 \Windows\System32\kernel32.dll 0x76CD0000 \Windows\System32\clbcatq.dll 0x76B30000 \Windows\System32\setupapi.dll 0x76A60000 \Windows\System32\msctf.dll 0x76FC0000 \Windows\System32\imm32.dll 0x76900000 \Windows\System32\ole32.dll 0x76850000 \Windows\System32\rpcrt4.dll 0x76FB0000 \Windows\System32\normaliz.dll 0x76F80000 \Windows\System32\imagehlp.dll 0x76840000 \Windows\System32\nsi.dll 0x767F0000 \Windows\System32\Wldap32.dll 0x75BA0000 \Windows\System32\shell32.dll 0x75B80000 \Windows\System32\sechost.dll 0x75AE0000 \Windows\System32\usp10.dll 0x75A80000 \Windows\System32\shlwapi.dll 0x759F0000 \Windows\System32\oleaut32.dll 0x758F0000 \Windows\System32\wininet.dll 0x758E0000 \Windows\System32\psapi.dll 0x75830000 \Windows\System32\msvcrt.dll 0x757B0000 \Windows\System32\comdlg32.dll 0x756E0000 \Windows\System32\user32.dll 0x754E0000 \Windows\System32\iertutil.dll 0x75440000 \Windows\System32\advapi32.dll 0x753E0000 \Windows\System32\difxapi.dll 0x753D0000 \Windows\System32\lpk.dll 0x75290000 \Windows\System32\urlmon.dll 0x75240000 \Windows\System32\KernelBase.dll 0x75120000 \Windows\System32\crypt32.dll 0x750F0000 \Windows\System32\wintrust.dll 0x750D0000 \Windows\System32\devobj.dll 0x750A0000 \Windows\System32\cfgmgr32.dll 0x75010000 \Windows\System32\comctl32.dll 0x75000000 \Windows\System32\msasn1.dll Processes (total 70): 0 System Idle Process 4 System 392 C:\Windows\System32\smss.exe 536 csrss.exe 580 C:\Windows\System32\wininit.exe 596 csrss.exe 636 C:\Windows\System32\services.exe 660 C:\Windows\System32\lsass.exe 668 C:\Windows\System32\lsm.exe 724 C:\Windows\System32\winlogon.exe 812 C:\Windows\System32\svchost.exe 876 C:\Program Files\Emsisoft Anti-Malware\a2service.exe 960 C:\Windows\System32\svchost.exe 1008 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe 1120 C:\Windows\System32\svchost.exe 1176 C:\Windows\System32\svchost.exe 1208 C:\Windows\System32\svchost.exe 1348 C:\Windows\System32\svchost.exe 1408 C:\Program Files\Tablet\Pen\Pen_TouchService.exe 1500 C:\Windows\System32\wisptis.exe 1536 C:\Windows\System32\svchost.exe 1708 C:\Windows\System32\spoolsv.exe 1736 C:\Windows\System32\svchost.exe 1820 C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe 1864 C:\Program Files\Telekom\Mediencenter\WebDAV.AdminService.exe 112 C:\Windows\System32\wisptis.exe 420 C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe 548 C:\Program Files\Tablet\Pen\Pen_TouchUser.exe 664 C:\Windows\System32\taskhost.exe 936 C:\Windows\System32\dwm.exe 2400 C:\Windows\System32\NlsSrv32.exe 2432 C:\Program Files\CDBurnerXP\NMSAccessU.exe 2496 C:\Program Files\ShadowExplorer\sesvc.exe 2544 C:\Windows\System32\svchost.exe 2568 C:\Program Files\Tablet\Pen\Pen_Tablet.exe 2604 C:\Windows\System32\Wacom_Tablet.exe 2656 C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe 2720 C:\Program Files\Tablet\Pen\Pen_TabletUser.exe 2744 C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe 2772 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 2896 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE 3024 C:\Windows\System32\WTablet\Wacom_TabletUser.exe 3080 C:\Windows\System32\Wacom_Tablet.exe 3120 C:\Program Files\Tablet\Pen\Pen_Tablet.exe 3368 C:\Windows\System32\svchost.exe 3736 C:\Windows\System32\svchost.exe 2348 C:\Windows\System32\SearchIndexer.exe 2372 C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe 3632 C:\Program Files\Windows Media Player\wmpnetwk.exe 2756 C:\Program Files\Microsoft Security Client\msseces.exe 4448 C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe 4616 C:\Windows\explorer.exe 5164 C:\Windows\explorer.exe 2600 C:\Windows\explorer.exe 5332 C:\Windows\System32\svchost.exe 4184 C:\Windows\System32\taskhost.exe 4120 C:\Windows\explorer.exe 6016 C:\Windows\explorer.exe 5608 C:\Windows\explorer.exe 5988 C:\Windows\explorer.exe 4700 C:\Windows\explorer.exe 2292 C:\Windows\explorer.exe 2408 C:\Windows\explorer.exe 2208 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe 1248 C:\Program Files\Mozilla Firefox\firefox.exe 4760 C:\Windows\System32\audiodg.exe 3232 C:\Windows\System32\notepad.exe 1844 C:\Users\***\Desktop\MBRCheck.exe 5396 C:\Windows\System32\conhost.exe 3488 C:\Windows\System32\dllhost.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`c0100000 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x0000001e`7c500000 (NTFS) \\.\T: --> error 1 PhysicalDrive0 Model Number: HitachiHTS543225L9A300, Rev: FBEOC40C Size Device Name MBR Status -------------------------------------------- 232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 Done! |
03.04.2011, 17:55 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!!
__________________ Logfiles bitte immer in CODE-Tags posten |
03.04.2011, 20:45 | #25 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL MalWBites: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6256 Windows 6.1.7601 Service Pack 1 Internet Explorer 8.0.7601.17514 03.04.2011 20:56:37 mbam-log-2011-04-03 (20-56-37).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|T:\|) Durchsuchte Objekte: 289107 Laufzeit: 1 Stunde(n), 57 Minute(n), 8 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 04/03/2011 at 09:23 PM Application Version : 4.50.1002 Core Rules Database Version : 6743 Trace Rules Database Version: 4555 Scan type : Complete Scan Total Scan Time : 01:56:00 Memory items scanned : 758 Memory threats detected : 0 Registry items scanned : 9286 Registry threats detected : 0 File items scanned : 139290 File threats detected : 4 Trojan.Agent/Gen-Cryptor[Egun] C:\JWPACK\JWOSETUP.EXE C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\JUSTWRITE OFFICE\WERKZEUGLEISTE KONFIGURIEREN.LNK Trojan.Agent/Gen-Bancos C:\PROGRAM FILES\BUYERTOOLS REMINDER\IEBUTTONEBAYINTERFACE.DLL Adware.Tracking Cookie www.mjmedia.de [ C:\Users\***\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LTK5LV7K ] |
04.04.2011, 09:10 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Nur Fehlalarme und ein Cookie. Harmlos. Rechner wieder ok oder noch Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
04.04.2011, 11:09 | #27 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Rechner geht. Der komische RtkBtMnt.exe war ja schon länger verschwunden gewesen, nach Neustart ist er nun wieder da... muss wohl ein Falschalarm sein, den ich da bei Google fand. Die Soundkarte funktioniert allerdings auch ohne das Ding. ...werde es einfach ignorieren Jedenfalls bin ich erleichtert - Neuaufsetzen verhindert TOLL Zudem hast du einen Wochenend-Bonus verdient, danke nochmal für alles : |
04.04.2011, 11:47 | #28 |
/// Winkelfunktion /// TB-Süch-Tiger™ | RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL Dann wären wir durch! Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Anleitung Windows-Update PDF-Reader aktualisieren Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink: Mozilla und andere Browser => http://filepony.de/?q=Flash+Player Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe Java-Update Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________ Logfiles bitte immer in CODE-Tags posten |
05.04.2011, 11:40 | #29 |
| RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL - nochmal tausend Milliarden Dank Arne für die Unterstützung! - |
Themen zu RtkBtMnt.exe im Temp Ordner - Windows 7 - BEFALL |
administrator, anfang, anfänger, befall, datei, dateien, fix, gelöscht, löschen, malwarebytes, microsoft, microsoft security, microsoft security essentials, neustart, nicht mehr, ordner, prozess, rar datei, rechner, registry, scan, security, sophos, sophos anti-rootkit, system, system32, tablet, temp, voll, windows, write |