![]() |
Desktop schwarz, kein Zugriff auf Dateien von Festplatte Hallo alle zusammen, ich habe das Problem, wovon viele User bereits berichtet haben. Mein Desktop ist komplett schwarz und ich habe keinen Zugriff mehr auf meine Dateien. Ich habe euren Anweisungen nach einen Vollscan mit Malwarebytes durchführen lassen und hier ist das Ergebnis. Ich hoffe, ihr könnt mir weiterhelfen. Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Datenbank Version: 6967 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 28.06.2011 19:23:30 mbam-log-2011-06-28 (19-23-30).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 340446 Laufzeit: 1 Stunde(n), 47 Minute(n), 15 Sekunde(n) Infizierte Speicherprozesse: 2 Infizierte Speichermodule: 1 Infizierte Registrierungsschlüssel: 4 Infizierte Registrierungswerte: 10 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 1 Infizierte Dateien: 92 Infizierte Speicherprozesse: c:\Windows\Temp\uvltqo\setup.exe (Backdoor.Bot) -> 1700 -> Unloaded process successfully. c:\Windows\System32\jpp3.exe (Trojan.WerTrans) -> 2076 -> Unloaded process successfully. Infizierte Speichermodule: c:\Users\rai\AppData\Local\enajarowijehulal.dll (Trojan.Agent.U) -> Delete on reboot. Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AMService (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{C689C99E-3A8C-4c87-A79C-C80DC9C81632} (Trojan.Banker) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C689C99E-3A8C-4C87-A79C-C80DC9C81632} (Trojan.Banker) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svcmsdebug (Trojan.WerTrans) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AMService (Backdoor.Bot) -> Value: AMService -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{8495736E-46E8-F9EA-196F-B03BD29B6BFE} (Trojan.Dropper) -> Value: {8495736E-46E8-F9EA-196F-B03BD29B6BFE} -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{AA9F9655-A3D3-D7E0-196F-B03BD29B6BFE} (Trojan.Dropper) -> Value: {AA9F9655-A3D3-D7E0-196F-B03BD29B6BFE} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{989A9B0D-2FD6-841C-8CFC-BD2A86913978} (Trojan.FakeAlert) -> Value: {989A9B0D-2FD6-841C-8CFC-BD2A86913978} -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{B6907E36-CAED-AA16-8CFC-BD2A86913978} (Trojan.FakeAlert) -> Value: {B6907E36-CAED-AA16-8CFC-BD2A86913978} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4Y3Y0C3AUZZJ4EYWHTBFXNZQMXODFAB (Trojan.Downloader) -> Value: 4Y3Y0C3AUZZJ4EYWHTBFXNZQMXODFAB -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{CE7FB805-E072-5E4E-02AC-A2990AFD8BC9} (Spyware.Passwords.XGen) -> Value: {CE7FB805-E072-5E4E-02AC-A2990AFD8BC9} -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Osacuka (Trojan.Agent.U) -> Value: Osacuka -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4W1W8B7AWZVCYE3GBRAIU (Trojan.SpyEyes) -> Value: 4W1W8B7AWZVCYE3GBRAIU -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Userinit (Trojan.Agent) -> Value: Userinit -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: c:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully. Infizierte Dateien: c:\Windows\Temp\uvltqo\setup.exe (Backdoor.Bot) -> Delete on reboot. c:\Users\rai\AppData\Roaming\Ysymyp\caxoe.exe (Trojan.Dropper) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Ogtuo\ifab.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\svest\3ed979f3e34.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Vodu\fiad.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Recycle.Bin\recycle.bin.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\OUBVS3YD\contacts[1].exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\OUBVS3YD\windows-update-sp2-kb72170-setup[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\RK1F25QS\windows-update-sp3-kb73364-setup[1].exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\SMUQY3NC\windows-update-sp2-kb72906-setup[1].exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup1008447532.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup1020727048.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup1152744780.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup1237180152.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup1904258508.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup352887232.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup4053500652.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup749304192.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup2240559188.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup2243471788.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup2276230980.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\setup2795684296.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\0.15922482866121335.exe (Trojan.FakeAV) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\0.18517589546822022.exe (Trojan.FakeAV) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\0.2504769801470035.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\0.3368059966747582.exe (Trojan.Agent.SZ) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\0.3522637127378212.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\0.5645673212442865.exe (Trojan.FakeAV) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\AB8C.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\adobe_flash_player.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\ECDF.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\ewacnxrosm.exe (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\F1BE.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\jar_cache4290880000267105886.tmp (Trojan.FakeAV) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\jar_cache630415511970096761.tmp (Trojan.FakeAV) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\jar_cache6357648436762506745.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\jar_cache6517129892316717383.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\Temp\tmpD578.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Guwy\ilhav.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Pylo\nehy.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Reeqe\vuuwk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Xoofka\atipl.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Windows\Temp\0.8980067592258049.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache3238386791498126793.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.052860187623421595.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.07455465554303697.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.09704681782227886.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.1628810541685567.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.1777911629517276.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.19207205017406903.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.24389376577942812.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.2752289388908823.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.29387172081543833.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.39395244160227794.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.4109070587500694.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.4434258496333292.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.4658762270368998.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.5759064824169595.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.6515418031024994.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.7242342735754141.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.7460659086710065.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\0.8469139751466319.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.8549601486715639.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\0.8904307322035636.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache4237716315418943234.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache4275951188290372044.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache465038264603885305.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache5189369654252030440.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache5498479796581028483.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache5531312842814268344.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache5723188463717295422.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache6126471028174742749.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache663048289573120938.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache6818879000899940757.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache8727919714605495671.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache8949727319327672710.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache913378390925623342.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache9170446646236397553.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\6096.tmp (Trojan.FakeAV) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache1508689122658508332.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache1644977468665193643.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache2196339311734675599.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache2305135084482957881.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache2484313631776547057.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache2569165611358110562.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Windows\Temp\jar_cache3159920195863819109.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Adobe\plugs\mmc195.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Local\enajarowijehulal.dll (Trojan.Agent.U) -> Delete on reboot. c:\Users\rai\AppData\Roaming\appconf32.exe (Trojan.Agent) -> Delete on reboot. c:\Windows\System32\jpp3.exe (Trojan.WerTrans) -> Quarantined and deleted successfully. c:\Recycle.Bin\config.bin (Trojan.Spyeyes) -> Quarantined and deleted successfully. |
Zitat:
Alle Logs posten, auch ältere falls vorhanden. |
So habe erneut einen Vollscan durchgeführt und hier ist das Ergebnis: Malwarebytes' Anti-Malware 1.51.0.1200 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: 7012 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 03.07.2011 20:13:39 mbam-log-2011-07-03 (20-13-39).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 341763 Laufzeit: 1 Stunde(n), 6 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 1 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 1 Infizierte Registrierungswerte: 5 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 1 Infizierte Dateien: 5 Infizierte Speicherprozesse: c:\Windows\System32\config\systemprofile\AppData\Local\nvidia corporation\Update\daemonupd.exe (Trojan.Agent) -> 1908 -> Unloaded process successfully. Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvUpdService (Trojan.Agent) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Osacuka (Trojan.Agent.U) -> Value: Osacuka -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{8495736E-46E8-F9EA-196F-B03BD29B6BFE} (Trojan.ZbotR.Gen) -> Value: {8495736E-46E8-F9EA-196F-B03BD29B6BFE} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{CE7FB805-E072-5E4E-02AC-A2990AFD8BC9} (Trojan.ZbotR.Gen) -> Value: {CE7FB805-E072-5E4E-02AC-A2990AFD8BC9} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{989A9B0D-2FD6-841C-8CFC-BD2A86913978} (Trojan.ZbotR.Gen) -> Value: {989A9B0D-2FD6-841C-8CFC-BD2A86913978} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4E3E0230AEBB4E96 (Trojan.SpyEyes) -> Value: 4E3E0230AEBB4E96 -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: c:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully. Infizierte Dateien: c:\Users\rai\documents\myfuncards(1).exe (Adware.FunWeb) -> Quarantined and deleted successfully. c:\Users\rai\documents\myfuncards.exe (Adware.FunWeb) -> Quarantined and deleted successfully. c:\Windows\System32\config\systemprofile\AppData\Local\nvidia corporation\Update\daemonupd.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\rai\AppData\Roaming\Gaixe\alcu.exe (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully. c:\Recycle.Bin\config.bin (Trojan.Spyeyes) -> Quarantined and deleted successfully. Danke für das schnelle antworten. |
CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: netsvcs
|
So hier ist das Protokoll:OTL Logfile: Code: OTL logfile created on: 7/3/2011 11:06:30 PM - Run 2 |
Zitat:
Zitat:
Deinstalliere bei der Gelegenheit auch alle anderen unnötigen Programme über die Systemsteuerung. |
Ich habe nun die Toolbars alle deinstalliert. Absichtlich habe ich die nicht installiert. Nächstes Mal werde ich die benutzerdefinierte Installationsmethode wählen. Ich habe auch die unnötigen Programme deinstalliert. Ich wusste nichts von der Zusammenarbeit von AntiVir und Ask. Eigentlich dachte ich, dass dieses Antivirenprogramm recht zuverlässig ist. Welches Antivirusprogramm würdet ihr mir empfehlen? |
Zitat:
Mach bitte ein neues CustomLog mit OTL. |
Soll ich das CustomLog mit genau demselben Textinhalt machen wie du bereits beschrieben hast? |
Ja einfach ein neues genau wie vorher machen. |
Das ist das Ergebnis:OTL Logfile: Code: OTL logfile created on: 7/4/2011 1:50:54 PM - Run 3 |
Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. |
Ich habe es wie beschrieben durchgeführt und hier ist das Logfile: ========== OTL ========== Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "Ask.com" removed from browser.search.defaultenginename Prefs.js: "softonic-de3 Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "Ask.com" removed from browser.search.selectedEngine Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: engine@conduit.com:3.2.5.2 removed from extensions.enabledItems Prefs.js: "hxxp://search.babylon.com/?babsrc=toolbar2&q=" removed from keyword.URL C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\searchplugin folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\modules folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\META-INF folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\defaults folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\chrome folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\searchplugin folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\modules folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\META-INF folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\defaults folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\components folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\chrome folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}\searchplugin folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}\modules folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}\META-INF folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}\defaults folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}\components folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}\chrome folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\{f4e6547e-325b-403c-a3bb-ad29ed37a92f} folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com\searchplugin folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com\META-INF folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com\lib folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com\DualPackage folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com\defaults folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com\components folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com\chrome folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\engine@conduit.com folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\vshare@toolbar\META-INF folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\vshare@toolbar\chrome folder moved successfully. C:\Users\rai\AppData\Roaming\mozilla\Firefox\Profiles\8bhp6291.default\extensions\vshare@toolbar folder moved successfully. C:\Users\rai\AppData\Roaming\Mozilla\Firefox\Profiles\8bhp6291.default\searchplugins\askcom.xml moved successfully. C:\Users\rai\AppData\Roaming\Mozilla\Firefox\Profiles\8bhp6291.default\searchplugins\conduit.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. C:\Program Files\ConduitEngine\prxConduitEngine.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Program Files\ConduitEngine\prxConduitEngine.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{76AEEA42-E04A-4B62-83AB-DF4B2BE2541E} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76AEEA42-E04A-4B62-83AB-DF4B2BE2541E}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{989A9B0D-2FD6-841C-8CFC-BD2A86913978} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{989A9B0D-2FD6-841C-8CFC-BD2A86913978}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8f591401-766c-11e0-a156-0024542a71d7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8f591401-766c-11e0-a156-0024542a71d7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8f591401-766c-11e0-a156-0024542a71d7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8f591401-766c-11e0-a156-0024542a71d7}\ not found. File F:\iStudio.exe not found. C:\Program Files\ConduitEngine folder moved successfully. C:\Users\rai\AppData\Local\Conduit folder moved successfully. C:\Users\rai\AppData\Roaming\Tyka folder moved successfully. C:\Users\rai\AppData\Roaming\Gaixe folder moved successfully. C:\Users\rai\AppData\Roaming\Guwy folder moved successfully. C:\Users\rai\AppData\Roaming\Akpoo folder moved successfully. C:\Users\rai\AppData\Roaming\Vodu folder moved successfully. C:\Users\rai\AppData\Roaming\Kofui folder moved successfully. C:\Users\rai\AppData\Roaming\Xafape folder moved successfully. C:\Users\rai\AppData\Roaming\Pylo folder moved successfully. C:\Users\rai\AppData\Roaming\Reeqe folder moved successfully. C:\Users\rai\AppData\Roaming\Futo folder moved successfully. C:\Users\rai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convar\PC Inspector File Recovery folder moved successfully. C:\Users\rai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convar folder moved successfully. C:\Program Files\Convar\PC Inspector File Recovery folder moved successfully. C:\Program Files\Convar folder moved successfully. C:\Users\rai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Restore folder moved successfully. C:\Users\rai\AppData\Roaming\Ynwi folder moved successfully. C:\Users\rai\AppData\Roaming\Xoofka folder moved successfully. C:\Users\rai\AppData\Roaming\Ogtuo folder moved successfully. C:\Users\rai\AppData\Roaming\Duebog folder moved successfully. C:\Users\rai\AppData\Roaming\5015\components folder moved successfully. C:\Users\rai\AppData\Roaming\5015 folder moved successfully. C:\Users\rai\AppData\Roaming\5016\components folder moved successfully. C:\Users\rai\AppData\Roaming\5016 folder moved successfully. C:\Users\rai\AppData\Roaming\5017\components folder moved successfully. C:\Users\rai\AppData\Roaming\5017 folder moved successfully. C:\Users\rai\AppData\Local\Jyiqobituyi.dat moved successfully. C:\Users\rai\AppData\Local\Qkoyocigezori.bin moved successfully. C:\Users\rai\AppData\Local\{9E02C3BE-344B-4FFB-9E09-602CD6B087CD} moved successfully. C:\ProgramData\27057912 moved successfully. C:\ProgramData\~27057912r moved successfully. C:\ProgramData\~27057912 moved successfully. C:\Users\rai\Desktop\Windows 7 Restore.lnk moved successfully. ADS C:\ProgramData\Temp:A42A9F39 deleted successfully. ADS C:\ProgramData\Temp:E1F04E8D deleted successfully. ========== COMMANDS ========== HOSTS file reset successfully OTL by OldTimer - Version 3.2.25.0 log created on 07042011_145415 |
Ok. Zur Kontrolle bitte wieder ein neues CustomLog mit OTL erstellen und posten. |
Ok, ich habe das CustomLog mit OTL erstellt, aber hat erst beim zweiten Versuch geklappt. Der Laptop hatte sich während OTL scannte von allein ausgeschaltet. Beim Einschalten waren alle Dateien wieder sichtbar, aber transparent. Ich habe den Scan dann erneut durchgeführt und hier ist das Protokoll:OTL Logfile: Code: OTL logfile created on: 7/4/2011 3:25:10 PM - Run 4 |
Mach nochmal einen OTL-Fix, ein paar Elemente hab ich bei der Vielzahl übersehen, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. |
Hier ist das Log: ========== OTL ========== C:\Users\rai\AppData\Roaming\kock folder moved successfully. C:\Users\rai\AppData\Roaming\Wuyco folder moved successfully. C:\Users\rai\AppData\Roaming\xmldm folder moved successfully. C:\Users\rai\AppData\Roaming\Ysymyp folder moved successfully. ========== COMMANDS ========== C:\windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.25.0 log created on 07042011_172534 |
Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. http://www.trojaner-board.de/attachm...rnen-start.png Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif |
Ich habe diesen Tool ausgeführt. Hier ist der Report: 2011/07/04 20:49:50.0023 1872 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21 2011/07/04 20:49:50.0275 1872 ================================================================================ 2011/07/04 20:49:50.0275 1872 SystemInfo: 2011/07/04 20:49:50.0275 1872 2011/07/04 20:49:50.0275 1872 OS Version: 6.1.7600 ServicePack: 0.0 2011/07/04 20:49:50.0275 1872 Product type: Workstation 2011/07/04 20:49:50.0275 1872 ComputerName: RAI-PC 2011/07/04 20:49:50.0275 1872 UserName: rai 2011/07/04 20:49:50.0276 1872 Windows directory: C:\windows 2011/07/04 20:49:50.0276 1872 System windows directory: C:\windows 2011/07/04 20:49:50.0276 1872 Processor architecture: Intel x86 2011/07/04 20:49:50.0276 1872 Number of processors: 2 2011/07/04 20:49:50.0276 1872 Page size: 0x1000 2011/07/04 20:49:50.0276 1872 Boot type: Normal boot 2011/07/04 20:49:50.0276 1872 ================================================================================ 2011/07/04 20:49:50.0868 1872 Initialize success 2011/07/04 20:49:53.0244 2912 ================================================================================ 2011/07/04 20:49:53.0245 2912 Scan started 2011/07/04 20:49:53.0245 2912 Mode: Manual; 2011/07/04 20:49:53.0245 2912 ================================================================================ 2011/07/04 20:49:54.0368 2912 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys 2011/07/04 20:49:54.0457 2912 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys 2011/07/04 20:49:54.0520 2912 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys 2011/07/04 20:49:54.0593 2912 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys 2011/07/04 20:49:54.0655 2912 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys 2011/07/04 20:49:54.0686 2912 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys 2011/07/04 20:49:54.0814 2912 AFD (0db7a48388d54d154ebec120461a0fcd) C:\windows\system32\drivers\afd.sys 2011/07/04 20:49:54.0856 2912 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys 2011/07/04 20:49:54.0929 2912 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys 2011/07/04 20:49:54.0978 2912 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys 2011/07/04 20:49:55.0013 2912 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys 2011/07/04 20:49:55.0058 2912 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys 2011/07/04 20:49:55.0129 2912 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys 2011/07/04 20:49:55.0179 2912 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys 2011/07/04 20:49:55.0234 2912 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\windows\system32\drivers\amdsata.sys 2011/07/04 20:49:55.0277 2912 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys 2011/07/04 20:49:55.0334 2912 amdxata (869e67d66be326a5a9159fba8746fa70) C:\windows\system32\drivers\amdxata.sys 2011/07/04 20:49:55.0441 2912 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys 2011/07/04 20:49:55.0512 2912 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys 2011/07/04 20:49:55.0544 2912 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys 2011/07/04 20:49:55.0597 2912 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys 2011/07/04 20:49:55.0641 2912 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys 2011/07/04 20:49:55.0718 2912 athr (0f4b6b99d6cdc1d93df1fa690796b2f7) C:\windows\system32\DRIVERS\athr.sys 2011/07/04 20:49:55.0791 2912 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\windows\system32\DRIVERS\avgntflt.sys 2011/07/04 20:49:55.0846 2912 avipbb (5fedef54757b34fb611b9ec8fb399364) C:\windows\system32\DRIVERS\avipbb.sys 2011/07/04 20:49:55.0930 2912 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys 2011/07/04 20:49:55.0992 2912 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys 2011/07/04 20:49:56.0047 2912 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys 2011/07/04 20:49:56.0097 2912 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys 2011/07/04 20:49:56.0152 2912 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\windows\system32\DRIVERS\bowser.sys 2011/07/04 20:49:56.0184 2912 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys 2011/07/04 20:49:56.0234 2912 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys 2011/07/04 20:49:56.0272 2912 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys 2011/07/04 20:49:56.0301 2912 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys 2011/07/04 20:49:56.0329 2912 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys 2011/07/04 20:49:56.0355 2912 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys 2011/07/04 20:49:56.0382 2912 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys 2011/07/04 20:49:56.0433 2912 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys 2011/07/04 20:49:56.0509 2912 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys 2011/07/04 20:49:56.0559 2912 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys 2011/07/04 20:49:56.0602 2912 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys 2011/07/04 20:49:56.0655 2912 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys 2011/07/04 20:49:56.0681 2912 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys 2011/07/04 20:49:56.0727 2912 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys 2011/07/04 20:49:56.0777 2912 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys 2011/07/04 20:49:56.0840 2912 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys 2011/07/04 20:49:56.0887 2912 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys 2011/07/04 20:49:56.0950 2912 CryptOSD (c914d18ab66b132e9c73f19f8f805f1f) C:\windows\system32\DRIVERS\CryptOSD.sys 2011/07/04 20:49:57.0024 2912 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\windows\system32\Drivers\dfsc.sys 2011/07/04 20:49:57.0064 2912 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys 2011/07/04 20:49:57.0103 2912 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys 2011/07/04 20:49:57.0168 2912 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys 2011/07/04 20:49:57.0222 2912 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\windows\System32\drivers\dxgkrnl.sys 2011/07/04 20:49:57.0355 2912 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys 2011/07/04 20:49:57.0538 2912 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys 2011/07/04 20:49:57.0584 2912 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys 2011/07/04 20:49:57.0645 2912 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys 2011/07/04 20:49:57.0688 2912 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys 2011/07/04 20:49:57.0733 2912 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys 2011/07/04 20:49:57.0862 2912 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys 2011/07/04 20:49:57.0891 2912 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys 2011/07/04 20:49:57.0917 2912 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys 2011/07/04 20:49:57.0958 2912 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys 2011/07/04 20:49:58.0030 2912 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys 2011/07/04 20:49:58.0102 2912 fssfltr (b74b0578fd1d3f897e95f2a2b69ea051) C:\windows\system32\DRIVERS\fssfltr.sys 2011/07/04 20:49:58.0158 2912 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\windows\system32\FsUsbExDisk.SYS 2011/07/04 20:49:58.0203 2912 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys 2011/07/04 20:49:58.0265 2912 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\windows\system32\DRIVERS\fvevol.sys 2011/07/04 20:49:58.0328 2912 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys 2011/07/04 20:49:58.0402 2912 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 2011/07/04 20:49:58.0443 2912 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys 2011/07/04 20:49:58.0496 2912 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys 2011/07/04 20:49:58.0550 2912 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys 2011/07/04 20:49:58.0589 2912 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys 2011/07/04 20:49:58.0619 2912 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys 2011/07/04 20:49:58.0684 2912 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys 2011/07/04 20:49:58.0731 2912 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys 2011/07/04 20:49:58.0772 2912 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys 2011/07/04 20:49:58.0825 2912 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\windows\system32\DRIVERS\HPZid412.sys 2011/07/04 20:49:58.0877 2912 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\windows\system32\DRIVERS\HPZipr12.sys 2011/07/04 20:49:58.0916 2912 HPZius12 (ca990306ed4ef732af9695bff24fc96f) C:\windows\system32\DRIVERS\HPZius12.sys 2011/07/04 20:49:58.0972 2912 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys 2011/07/04 20:49:59.0005 2912 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys 2011/07/04 20:49:59.0047 2912 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys 2011/07/04 20:49:59.0119 2912 iaStor (0baa4115dfffd6a6d809a89d65e1281a) C:\windows\system32\DRIVERS\iaStor.sys 2011/07/04 20:49:59.0189 2912 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\windows\system32\drivers\iaStorV.sys 2011/07/04 20:49:59.0426 2912 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\windows\system32\DRIVERS\igdkmd32.sys 2011/07/04 20:49:59.0703 2912 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys 2011/07/04 20:49:59.0847 2912 IntcAzAudAddService (3202e26501e5e18c35dc2cc74709a704) C:\windows\system32\drivers\RTKVHDA.sys 2011/07/04 20:50:00.0007 2912 IntcHdmiAddService (264632ade8127b7baa2190cf6fad435b) C:\windows\system32\drivers\IntcHdmi.sys 2011/07/04 20:50:00.0067 2912 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys 2011/07/04 20:50:00.0119 2912 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys 2011/07/04 20:50:00.0186 2912 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys 2011/07/04 20:50:00.0238 2912 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys 2011/07/04 20:50:00.0289 2912 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys 2011/07/04 20:50:00.0377 2912 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys 2011/07/04 20:50:00.0414 2912 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys 2011/07/04 20:50:00.0451 2912 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys 2011/07/04 20:50:00.0503 2912 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys 2011/07/04 20:50:00.0563 2912 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys 2011/07/04 20:50:00.0603 2912 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys 2011/07/04 20:50:00.0652 2912 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys 2011/07/04 20:50:00.0728 2912 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys 2011/07/04 20:50:00.0799 2912 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys 2011/07/04 20:50:00.0848 2912 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys 2011/07/04 20:50:00.0882 2912 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys 2011/07/04 20:50:00.0917 2912 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys 2011/07/04 20:50:00.0963 2912 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys 2011/07/04 20:50:01.0080 2912 MBAMSwissArmy (b309912717c29fc67e1ba4730a82b6dd) C:\windows\system32\drivers\mbamswissarmy.sys 2011/07/04 20:50:01.0159 2912 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys 2011/07/04 20:50:01.0207 2912 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys 2011/07/04 20:50:01.0250 2912 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys 2011/07/04 20:50:01.0297 2912 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys 2011/07/04 20:50:01.0352 2912 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys 2011/07/04 20:50:01.0398 2912 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys 2011/07/04 20:50:01.0429 2912 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys 2011/07/04 20:50:01.0448 2912 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys 2011/07/04 20:50:01.0499 2912 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys 2011/07/04 20:50:01.0544 2912 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys 2011/07/04 20:50:01.0606 2912 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\windows\system32\DRIVERS\mrxsmb.sys 2011/07/04 20:50:01.0653 2912 mrxsmb10 (c108952d3660375dcb716b222912e868) C:\windows\system32\DRIVERS\mrxsmb10.sys 2011/07/04 20:50:01.0695 2912 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\windows\system32\DRIVERS\mrxsmb20.sys 2011/07/04 20:50:01.0740 2912 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys 2011/07/04 20:50:01.0774 2912 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys 2011/07/04 20:50:01.0831 2912 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys 2011/07/04 20:50:01.0865 2912 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys 2011/07/04 20:50:01.0894 2912 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys 2011/07/04 20:50:01.0954 2912 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys 2011/07/04 20:50:01.0989 2912 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys 2011/07/04 20:50:02.0020 2912 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys 2011/07/04 20:50:02.0061 2912 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys 2011/07/04 20:50:02.0098 2912 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys 2011/07/04 20:50:02.0137 2912 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys 2011/07/04 20:50:02.0164 2912 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys 2011/07/04 20:50:02.0205 2912 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys 2011/07/04 20:50:02.0292 2912 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys 2011/07/04 20:50:02.0394 2912 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys 2011/07/04 20:50:02.0428 2912 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys 2011/07/04 20:50:02.0490 2912 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys 2011/07/04 20:50:02.0534 2912 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys 2011/07/04 20:50:02.0562 2912 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys 2011/07/04 20:50:02.0601 2912 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys 2011/07/04 20:50:02.0630 2912 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys 2011/07/04 20:50:02.0666 2912 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys 2011/07/04 20:50:02.0740 2912 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys 2011/07/04 20:50:02.0784 2912 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys 2011/07/04 20:50:02.0817 2912 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys 2011/07/04 20:50:02.0886 2912 Ntfs (187002ce05693c306f43c873f821381f) C:\windows\system32\drivers\Ntfs.sys 2011/07/04 20:50:02.0950 2912 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys 2011/07/04 20:50:02.0994 2912 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\windows\system32\drivers\nvraid.sys 2011/07/04 20:50:03.0047 2912 nvstor (4520b63899e867f354ee012d34e11536) C:\windows\system32\drivers\nvstor.sys 2011/07/04 20:50:03.0086 2912 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys 2011/07/04 20:50:03.0132 2912 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys 2011/07/04 20:50:03.0192 2912 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys 2011/07/04 20:50:03.0222 2912 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys 2011/07/04 20:50:03.0259 2912 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys 2011/07/04 20:50:03.0348 2912 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys 2011/07/04 20:50:03.0386 2912 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys 2011/07/04 20:50:03.0417 2912 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys 2011/07/04 20:50:03.0458 2912 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys 2011/07/04 20:50:03.0520 2912 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys 2011/07/04 20:50:03.0656 2912 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys 2011/07/04 20:50:03.0677 2912 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys 2011/07/04 20:50:03.0722 2912 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys 2011/07/04 20:50:03.0773 2912 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys 2011/07/04 20:50:03.0817 2912 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys 2011/07/04 20:50:03.0857 2912 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys 2011/07/04 20:50:03.0889 2912 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys 2011/07/04 20:50:03.0952 2912 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys 2011/07/04 20:50:03.0989 2912 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys 2011/07/04 20:50:04.0040 2912 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys 2011/07/04 20:50:04.0092 2912 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys 2011/07/04 20:50:04.0143 2912 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys 2011/07/04 20:50:04.0185 2912 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys 2011/07/04 20:50:04.0218 2912 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys 2011/07/04 20:50:04.0260 2912 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys 2011/07/04 20:50:04.0283 2912 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys 2011/07/04 20:50:04.0324 2912 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys 2011/07/04 20:50:04.0383 2912 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys 2011/07/04 20:50:04.0471 2912 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys 2011/07/04 20:50:04.0507 2912 RTL8167 (7dfd48e24479b68b258d8770121155a0) C:\windows\system32\DRIVERS\Rt86win7.sys 2011/07/04 20:50:04.0565 2912 SABI (6e5fbb7cbaec47038b945d5e9b144a64) C:\windows\system32\Drivers\SABI.sys 2011/07/04 20:50:04.0612 2912 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys 2011/07/04 20:50:04.0654 2912 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys 2011/07/04 20:50:04.0721 2912 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys 2011/07/04 20:50:04.0792 2912 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys 2011/07/04 20:50:04.0844 2912 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys 2011/07/04 20:50:04.0888 2912 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys 2011/07/04 20:50:04.0953 2912 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys 2011/07/04 20:50:04.0990 2912 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys 2011/07/04 20:50:05.0009 2912 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys 2011/07/04 20:50:05.0042 2912 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys 2011/07/04 20:50:05.0084 2912 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys 2011/07/04 20:50:05.0141 2912 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys 2011/07/04 20:50:05.0174 2912 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys 2011/07/04 20:50:05.0209 2912 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys 2011/07/04 20:50:05.0266 2912 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys 2011/07/04 20:50:05.0353 2912 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\windows\system32\DRIVERS\srv.sys 2011/07/04 20:50:05.0409 2912 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\windows\system32\DRIVERS\srv2.sys 2011/07/04 20:50:05.0449 2912 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\windows\system32\DRIVERS\srvnet.sys 2011/07/04 20:50:05.0499 2912 sscdbus (d6870895fe46a464a19141440eb6cc1e) C:\windows\system32\DRIVERS\sscdbus.sys 2011/07/04 20:50:05.0550 2912 sscdmdfl (0fe167362e4689b716cdc8d93adedda8) C:\windows\system32\DRIVERS\sscdmdfl.sys 2011/07/04 20:50:05.0574 2912 sscdmdm (55a15707e32b6709242ad127e62ca55a) C:\windows\system32\DRIVERS\sscdmdm.sys 2011/07/04 20:50:05.0634 2912 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\windows\system32\DRIVERS\ssmdrv.sys 2011/07/04 20:50:05.0678 2912 ss_bbus (eaa66218cd39f5bb1b4853a78c67c787) C:\windows\system32\DRIVERS\ss_bbus.sys 2011/07/04 20:50:05.0713 2912 ss_bmdfl (91765f99914ed8693d8bc76524f21581) C:\windows\system32\DRIVERS\ss_bmdfl.sys 2011/07/04 20:50:05.0752 2912 ss_bmdm (840e7b738b03c10ee91d9b7d3d6eff15) C:\windows\system32\DRIVERS\ss_bmdm.sys 2011/07/04 20:50:05.0811 2912 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys 2011/07/04 20:50:05.0862 2912 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys 2011/07/04 20:50:05.0935 2912 SynTP (215a45246c6e2d0a9c263ce1786c8d8a) C:\windows\system32\DRIVERS\SynTP.sys 2011/07/04 20:50:06.0038 2912 Tcpip (0158d5e9982e9d6a90dfc802f618e130) C:\windows\system32\drivers\tcpip.sys 2011/07/04 20:50:06.0109 2912 TCPIP6 (0158d5e9982e9d6a90dfc802f618e130) C:\windows\system32\DRIVERS\tcpip.sys 2011/07/04 20:50:06.0172 2912 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys 2011/07/04 20:50:06.0217 2912 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys 2011/07/04 20:50:06.0252 2912 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys 2011/07/04 20:50:06.0280 2912 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys 2011/07/04 20:50:06.0308 2912 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys 2011/07/04 20:50:06.0386 2912 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys 2011/07/04 20:50:06.0515 2912 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys 2011/07/04 20:50:06.0564 2912 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys 2011/07/04 20:50:06.0604 2912 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys 2011/07/04 20:50:06.0662 2912 udfs (eb0a7bd4d471ac3ce55564a4c55b9d8e) C:\windows\system32\DRIVERS\udfs.sys 2011/07/04 20:50:06.0721 2912 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys 2011/07/04 20:50:06.0764 2912 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys 2011/07/04 20:50:06.0802 2912 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys 2011/07/04 20:50:06.0876 2912 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\windows\system32\Drivers\usbaapl.sys 2011/07/04 20:50:06.0936 2912 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys 2011/07/04 20:50:06.0984 2912 usbccgp (c31ae588e403042632dc796cf09e30b0) C:\windows\system32\DRIVERS\usbccgp.sys 2011/07/04 20:50:07.0027 2912 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys 2011/07/04 20:50:07.0071 2912 usbehci (e4c436d914768ce965d5e659ba7eebd8) C:\windows\system32\DRIVERS\usbehci.sys 2011/07/04 20:50:07.0137 2912 usbhub (bdcd7156ec37448f08633fd899823620) C:\windows\system32\DRIVERS\usbhub.sys 2011/07/04 20:50:07.0190 2912 usbohci (eb2d819a639015253c871cda09d91d58) C:\windows\system32\drivers\usbohci.sys 2011/07/04 20:50:07.0240 2912 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys 2011/07/04 20:50:07.0290 2912 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\windows\system32\DRIVERS\usbscan.sys 2011/07/04 20:50:07.0324 2912 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS 2011/07/04 20:50:07.0373 2912 usbuhci (22480bf4e5a09192e5e30ba4dde79fa4) C:\windows\system32\DRIVERS\usbuhci.sys 2011/07/04 20:50:07.0452 2912 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\windows\System32\Drivers\usbvideo.sys 2011/07/04 20:50:07.0572 2912 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys 2011/07/04 20:50:07.0611 2912 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys 2011/07/04 20:50:07.0646 2912 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys 2011/07/04 20:50:07.0680 2912 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys 2011/07/04 20:50:07.0714 2912 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys 2011/07/04 20:50:07.0739 2912 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys 2011/07/04 20:50:07.0762 2912 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys 2011/07/04 20:50:07.0802 2912 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys 2011/07/04 20:50:07.0836 2912 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys 2011/07/04 20:50:07.0864 2912 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys 2011/07/04 20:50:07.0916 2912 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys 2011/07/04 20:50:07.0962 2912 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys 2011/07/04 20:50:08.0006 2912 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys 2011/07/04 20:50:08.0051 2912 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys 2011/07/04 20:50:08.0098 2912 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys 2011/07/04 20:50:08.0119 2912 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys 2011/07/04 20:50:08.0199 2912 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys 2011/07/04 20:50:08.0240 2912 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys 2011/07/04 20:50:08.0330 2912 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys 2011/07/04 20:50:08.0382 2912 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys 2011/07/04 20:50:08.0481 2912 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys 2011/07/04 20:50:08.0538 2912 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys 2011/07/04 20:50:08.0608 2912 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys 2011/07/04 20:50:08.0673 2912 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys 2011/07/04 20:50:08.0717 2912 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys 2011/07/04 20:50:08.0808 2912 yukonw7 (30b73eb97218a16cbc6de535782a1b35) C:\windows\system32\DRIVERS\yk62x86.sys 2011/07/04 20:50:08.0870 2912 MBR (0x1B8) (2e5debb2116b3417023e0d6562d7ed07) \Device\Harddisk0\DR0 2011/07/04 20:50:09.0100 2912 Boot (0x1200) (637be9c1deaf06a8e9c2e5089d1fc835) \Device\Harddisk0\DR0\Partition0 2011/07/04 20:50:09.0129 2912 Boot (0x1200) (63f2e75680beb7f9a897a49a82b0b510) \Device\Harddisk0\DR0\Partition1 2011/07/04 20:50:09.0163 2912 Boot (0x1200) (1fe05ceacc35091abb6084baefc9ed97) \Device\Harddisk0\DR0\Partition2 2011/07/04 20:50:09.0170 2912 ================================================================================ 2011/07/04 20:50:09.0170 2912 Scan finished 2011/07/04 20:50:09.0170 2912 ================================================================================ 2011/07/04 20:50:09.0187 2100 Detected object count: 0 2011/07/04 20:50:09.0187 2100 Actual detected object count: 0 Ich kann zwar auf meine Dokumente zugreifen, allerdings sind sie transparent (also versteckt). Sollte ich dann das Programm unhide anwenden? |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! |
Ich habe nach Anweisung combofix benutzt und hier ist das Log: Combofix Logfile: Code: ComboFix 11-07-03.04 - rai 04.07.2011 21:23:28.1.2 - x86 |
Combofix - Scripten 1. Starte das Notepad (Start / Ausführen / notepad[Enter]) 2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein. Code: File:: 4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall. (Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !) 5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet. http://users.pandora.be/bluepatchy/m...s/CFScript.gif 6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien: Combofix.txt Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann! |
Ich habe versucht das so durchzuführen, wie oben beschrieben. Allerdings ist der Laptop dabei abgestürzt. Bevor ich es nochmals durchführe, wollte ich sichergehen, ob ich es nochmal machen sollte oder nicht. |
Ja bitte nochmal probieren. Genau die Anleitung umsetzen. |
Dieses Mal hats geklappt. Hier ist die Log-Datei: Combofix Logfile: Code: ComboFix 11-07-06.01 - rai 06.07.2011 11:56:31.3.2 - x86 |
Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM! Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
|
Hier ist zunächst das Log von GMER, die anderen werde ich noch durchführen und anschließend hier posten. GMER Logfile: Code: GMER 1.0.15.15640 - GMER - Rootkit Detector and Remover |
Log von OSAM: OSAM Logfile: Code: Report of OSAM: Autorun Manager v5.0.11926.0 If You have questions or want to get some help, You can visit Online Solutions :: Index |
MBRCheck: MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows 7 Home Premium Edition Windows Information: (build 7600), 32-bit Base Board Manufacturer: SAMSUNG ELECTRONICS CO., LTD. BIOS Manufacturer: Phoenix Technologies Ltd. System Manufacturer: SAMSUNG ELECTRONICS CO., LTD. System Product Name: R530/R730 Logical Drives Mask: 0x0000001c Kernel Drivers (total 185): 0x8303B000 \SystemRoot\system32\ntoskrnl.exe 0x83004000 \SystemRoot\system32\halmacpi.dll 0x80BB3000 \SystemRoot\system32\kdcom.dll 0x89403000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x8947B000 \SystemRoot\system32\PSHED.dll 0x8948C000 \SystemRoot\system32\BOOTVID.dll 0x89494000 \SystemRoot\system32\CLFS.SYS 0x894D6000 \SystemRoot\system32\CI.dll 0x89581000 \SystemRoot\system32\drivers\Wdf01000.sys 0x895F2000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x89600000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x89648000 \SystemRoot\system32\DRIVERS\WMILIB.SYS 0x89651000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x89659000 \SystemRoot\system32\DRIVERS\pci.sys 0x89683000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x8968E000 \SystemRoot\System32\drivers\partmgr.sys 0x8969F000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x896A7000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x896B2000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x896C2000 \SystemRoot\System32\drivers\volmgrx.sys 0x8970D000 \SystemRoot\System32\drivers\mountmgr.sys 0x89723000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x8980A000 \SystemRoot\system32\DRIVERS\atapi.sys 0x89813000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x89836000 \SystemRoot\system32\DRIVERS\msahci.sys 0x89840000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x8984E000 \SystemRoot\system32\drivers\amdxata.sys 0x89857000 \SystemRoot\system32\drivers\fltmgr.sys 0x8988B000 \SystemRoot\system32\drivers\fileinfo.sys 0x8989C000 \SystemRoot\System32\Drivers\Ntfs.sys 0x899CB000 \SystemRoot\System32\Drivers\msrpc.sys 0x899F6000 \SystemRoot\System32\Drivers\ksecdd.sys 0x89A09000 \SystemRoot\System32\Drivers\cng.sys 0x89A66000 \SystemRoot\System32\drivers\pcw.sys 0x89A74000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x89A7D000 \SystemRoot\system32\drivers\ndis.sys 0x89B34000 \SystemRoot\system32\drivers\NETIO.SYS 0x89B72000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x89B97000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x89BD6000 \SystemRoot\System32\Drivers\spldr.sys 0x89C29000 \SystemRoot\System32\drivers\rdyboost.sys 0x89C56000 \SystemRoot\System32\Drivers\mup.sys 0x89C66000 \SystemRoot\System32\drivers\hwpolicy.sys 0x89C6E000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x89CA0000 \SystemRoot\system32\DRIVERS\disk.sys 0x89CB1000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x89DCE000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x89DED000 \SystemRoot\System32\Drivers\Null.SYS 0x89DF4000 \SystemRoot\System32\Drivers\Beep.SYS 0x89DFB000 \SystemRoot\System32\drivers\vga.sys 0x89E07000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x89E28000 \SystemRoot\System32\drivers\watchdog.sys 0x89E35000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x89E3D000 \SystemRoot\system32\drivers\rdpencdd.sys 0x89E45000 \SystemRoot\system32\drivers\rdprefmp.sys 0x89E4D000 \SystemRoot\System32\Drivers\Msfs.SYS 0x89E58000 \SystemRoot\System32\Drivers\Npfs.SYS 0x89E66000 \SystemRoot\System32\drivers\tcpip.sys 0x89FAF000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x89FE0000 \SystemRoot\system32\DRIVERS\tdx.sys 0x89C00000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x9380C000 \SystemRoot\system32\drivers\afd.sys 0x93866000 \SystemRoot\System32\DRIVERS\netbt.sys 0x93898000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x9389F000 \SystemRoot\system32\DRIVERS\pacer.sys 0x938BE000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x938CF000 \SystemRoot\system32\DRIVERS\netbios.sys 0x938DD000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x938F0000 \SystemRoot\system32\DRIVERS\termdd.sys 0x93900000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0x93906000 \??\C:\windows\system32\Drivers\SABI.sys 0x9390E000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x9394F000 \SystemRoot\system32\drivers\nsiproxy.sys 0x93959000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x93963000 \SystemRoot\System32\drivers\discache.sys 0x9396F000 \SystemRoot\System32\Drivers\dfsc.sys 0x93987000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x93995000 \SystemRoot\system32\DRIVERS\avipbb.sys 0x939BB000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x93C2E000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 0x9454B000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x94602000 \SystemRoot\System32\drivers\dxgmms1.sys 0x9463B000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x94646000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x94691000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x946A0000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x946BF000 \SystemRoot\system32\DRIVERS\athr.sys 0x947EE000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x939DC000 \SystemRoot\system32\DRIVERS\yk62x86.sys 0x947F8000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x93C00000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x93C18000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x93A2D000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x93C25000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x93A64000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x93C27000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x93A71000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x93A83000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x93A90000 \SystemRoot\system32\DRIVERS\CryptOSD.sys 0x93AEE000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x93B00000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x93B18000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x93B23000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x93B45000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x93B5D000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x93B74000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x947FC000 \SystemRoot\system32\DRIVERS\swenum.sys 0x93B8B000 \SystemRoot\system32\DRIVERS\ks.sys 0x93BBF000 \SystemRoot\system32\DRIVERS\umbus.sys 0x9902F000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x99073000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x99084000 \SystemRoot\system32\drivers\RTKVHDA.sys 0x99331000 \SystemRoot\system32\drivers\portcls.sys 0x99360000 \SystemRoot\system32\drivers\drmk.sys 0x99379000 \SystemRoot\system32\drivers\IntcHdmi.sys 0x96C20000 \SystemRoot\System32\win32k.sys 0x9939C000 \SystemRoot\System32\drivers\Dxapi.sys 0x993A6000 \SystemRoot\System32\Drivers\crashdmp.sys 0x89CD6000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x993B3000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x993C4000 \SystemRoot\system32\DRIVERS\monitor.sys 0x993CF000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x99000000 \SystemRoot\System32\Drivers\usbvideo.sys 0x96E80000 \SystemRoot\System32\TSDDD.dll 0x96EB0000 \SystemRoot\System32\cdd.dll 0x93BCD000 \SystemRoot\system32\drivers\luafv.sys 0x993E6000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0x89DB0000 \SystemRoot\system32\drivers\WudfPf.sys 0x93BE8000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x97037000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x9707D000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x9708D000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x970A0000 \SystemRoot\system32\drivers\HTTP.sys 0x97125000 \SystemRoot\system32\DRIVERS\bowser.sys 0x9713E000 \SystemRoot\System32\drivers\mpsdrv.sys 0x97150000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x97173000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x971AE000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x971E1000 \SystemRoot\system32\drivers\peauth.sys 0x97278000 \SystemRoot\System32\Drivers\secdrv.SYS 0x97282000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x972A3000 \SystemRoot\System32\drivers\tcpipreg.sys 0x972B0000 \SystemRoot\System32\DRIVERS\srv2.sys 0x972FF000 \SystemRoot\System32\DRIVERS\srv.sys 0x97351000 \??\C:\windows\system32\FsUsbExDisk.SYS 0x9735A000 \??\C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys 0x76F60000 \Windows\System32\ntdll.dll 0x47940000 \Windows\System32\smss.exe 0x771A0000 \Windows\System32\apisetschema.dll 0x00970000 \Windows\System32\autochk.exe 0x770E0000 \Windows\System32\rpcrt4.dll 0x76EB0000 \Windows\System32\msvcrt.dll 0x76E20000 \Windows\System32\oleaut32.dll 0x770C0000 \Windows\System32\sechost.dll 0x76DC0000 \Windows\System32\difxapi.dll 0x76C20000 \Windows\System32\setupapi.dll 0x76BA0000 \Windows\System32\comdlg32.dll 0x76B00000 \Windows\System32\advapi32.dll 0x76A30000 \Windows\System32\user32.dll 0x769E0000 \Windows\System32\Wldap32.dll 0x769A0000 \Windows\System32\ws2_32.dll 0x76860000 \Windows\System32\urlmon.dll 0x770B0000 \Windows\System32\psapi.dll 0x75C10000 \Windows\System32\shell32.dll 0x75B40000 \Windows\System32\msctf.dll 0x770A0000 \Windows\System32\lpk.dll 0x75B20000 \Windows\System32\imm32.dll 0x75B10000 \Windows\System32\normaliz.dll 0x75AE0000 \Windows\System32\imagehlp.dll 0x75A40000 \Windows\System32\usp10.dll 0x759F0000 \Windows\System32\gdi32.dll 0x759E0000 \Windows\System32\nsi.dll 0x75980000 \Windows\System32\shlwapi.dll 0x758F0000 \Windows\System32\clbcatq.dll 0x757F0000 \Windows\System32\wininet.dll 0x75710000 \Windows\System32\kernel32.dll 0x75510000 \Windows\System32\iertutil.dll 0x753B0000 \Windows\System32\ole32.dll 0x75320000 \Windows\System32\comctl32.dll 0x752F0000 \Windows\System32\wintrust.dll 0x752D0000 \Windows\System32\devobj.dll 0x751B0000 \Windows\System32\crypt32.dll 0x75180000 \Windows\System32\cfgmgr32.dll 0x75130000 \Windows\System32\KernelBase.dll 0x75120000 \Windows\System32\msasn1.dll Processes (total 65): 0 System Idle Process 4 SYSTEM 300 C:\Windows\System32\smss.exe 428 csrss.exe 484 C:\Windows\System32\wininit.exe 492 csrss.exe 540 C:\Windows\System32\services.exe 556 C:\Windows\System32\lsass.exe 564 C:\Windows\System32\lsm.exe 592 C:\Windows\System32\winlogon.exe 712 C:\Windows\System32\svchost.exe 808 C:\Windows\System32\svchost.exe 872 C:\Windows\System32\svchost.exe 936 C:\Windows\System32\svchost.exe 984 C:\Windows\System32\svchost.exe 1048 C:\Windows\System32\audiodg.exe 1112 C:\Windows\System32\svchost.exe 1328 C:\Windows\System32\svchost.exe 1516 C:\Windows\System32\spoolsv.exe 1560 C:\Program Files\Avira\AntiVir Desktop\sched.exe 1580 C:\Windows\System32\svchost.exe 1748 C:\Program Files\Avira\AntiVir Desktop\avguard.exe 1776 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1828 C:\Windows\System32\FsUsbExService.Exe 1872 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe 1896 C:\Windows\System32\conhost.exe 1948 C:\Program Files\CyberLink\Shared files\RichVideo.exe 1988 C:\Windows\System32\svchost.exe 2028 C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe 456 C:\Windows\System32\svchost.exe 824 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 2168 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE 2320 C:\Windows\System32\SearchIndexer.exe 2752 C:\Windows\System32\taskhost.exe 2804 C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe 2812 C:\Windows\System32\taskeng.exe 2864 C:\Windows\System32\dwm.exe 2960 C:\Windows\explorer.exe 2980 C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe 3036 C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe 3044 C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe 3140 C:\Windows\System32\igfxext.exe 3168 C:\Windows\System32\igfxsrvc.exe 3328 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe 3344 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 3424 C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe 3504 C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe 3596 C:\Program Files\AnyPC Client\APLangApp.exe 3680 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 3688 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 3796 C:\Windows\System32\hkcmd.exe 3912 C:\Windows\System32\igfxpers.exe 2564 C:\Windows\System32\svchost.exe 2888 C:\Windows\System32\svchost.exe 3484 C:\Program Files\Windows Media Player\wmpnetwk.exe 3160 C:\Program Files\Nero\Update\NASvc.exe 1908 C:\Windows\System32\wuauclt.exe 1716 C:\Windows\System32\svchost.exe 4180 C:\PROGRA~1\Samsung\SAMSUN~2\SUPNOT~1.EXE 4160 C:\Windows\System32\SearchProtocolHost.exe 3316 C:\Windows\System32\SearchFilterHost.exe 932 dllhost.exe 2108 dllhost.exe 4380 C:\Users\rai\Desktop\MBRCheck.exe 2832 C:\Windows\System32\conhost.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000003`c6500000 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000016`d4a00000 (NTFS) PhysicalDrive0 Model Number: SAMSUNGHM250HI, Rev: 2AC101C4 Size Device Name MBR Status -------------------------------------------- 232 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: F5C09ACABD4A5370BDD907E8EDFE0C1DA0F9D3F5 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: |
Zitat:
Hast Du noch andere Betriebssysteme außer Win7 (32-Bit) installiert? Wenn nicht: Schau mal hier => RescueDisc-Win7-32-Bit Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten) Falls Du eine normale Win7-Installations-DVD (32-Bit) hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der dieser DVD booten. Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:34 Uhr. |
Copyright ©2000-2025, Trojaner-Board