![]() |
TR/PSW.Sinowal.Y.580 - Antivir hallo, antivir hat meldet mir seit heute dauernd folgenden trojaner: Fund: TR/PSW.Sinowal.Y.580 Objekt: scandiskr65.dll in der datei: C:users/acer/floadu1C.dll könnt ihr mir bitte helfen das ding zu entfernen? Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Datenbank Version: 7408 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 08.08.2011 14:25:19 mbam-log-2011-08-08 (14-25-19).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Durchsuchte Objekte: 439213 Laufzeit: 1 Stunde(n), 11 Minute(n), 27 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 1 Infizierte Registrierungsschlüssel: 1 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 5 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: c:\Users\ACER\floadu1C.dll (Trojan.Agent.WIMP) -> Delete on reboot. Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker (PUP.Casino) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NvCplDaemonTool (Trojan.Agent.WIMP) -> Value: NvCplDaemonTool -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\Poker\titan poker\_setuppoker_cd44d4_de.exe (PUP.Casino) -> Quarantined and deleted successfully. c:\Users\ACER\downloads\setuppoker_cd44d4_de.exe (PUP.Casino) -> Quarantined and deleted successfully. c:\Users\ACER\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\ACER\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\scanidiskr65.dll (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\ACER\floadu1C.dll (Trojan.Agent.WIMP) -> Quarantined and deleted successfully. Code: OTL logfile created on: 8/8/2011 2:32:33 PM - Run 1 Code: OTL Extras logfile created on: 8/8/2011 2:32:33 PM - Run 1 |
Führe auch bitte ESET aus, danach sehen wir weiter. ESET Online Scanner
n. |
ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=12 ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=53955ed3689432458e200c3ae7354adf # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-08-09 06:00:58 # local_time=2011-08-09 08:00:58 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1797 16775165 100 94 203026 49448472 21524 0 # compatibility_mode=5893 16776574 100 94 22946 64537866 0 0 # compatibility_mode=8192 67108863 100 0 504 504 0 0 # scanned=167213 # found=6 # cleaned=0 # scan_time=4843 C:\Users\ACER\floadu1C.dll a variant of Win32/Kryptik.QYV trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\ACER\AppData\Local\Temp\jar_cache4021375851548926749.tmp a variant of Java/TrojanDownloader.OpenStream.NAV trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\9e1402-62bffb19 probably a variant of Win32/Agent.KYOMCBX trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\9e1402-63539567 Java/TrojanDownloader.Agent.NBY trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\b9b001d-337fde30 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Users\ACER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanidiskr65.dll a variant of Win32/Kryptik.QYV trojan (unable to clean) 00000000000000000000000000000000 I |
Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. |
========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Infium deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\NvCplDaemonTool deleted successfully. C:\Users\ACER\floadu1C.dll moved successfully. File C:\Users\ACER\floadu1C.dll not found. C:\ProgramData\FullRemove.exe moved successfully. C:\Windows\KLIF.spi moved successfully. C:\Users\ACER\AppData\Roaming\.# folder moved successfully. C:\Recycle.Bi folder moved successfully. ========== FILES ========== File\Folder C:\Users\ACER\floadu1C.dll not found. C:\Users\ACER\AppData\Local\Temp\jar_cache1038962773578477937.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1055680343641708917.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1059453737898048905.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache107778936925101561.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1080863284840884427.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1092879353734375216.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1132564119172643648.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1182372093085949291.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1186122123286320618.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1207120096163079690.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1233612893074218906.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1238590046490045245.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1299426432348077906.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1371995717162845922.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1375592318716483377.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1385740162539953300.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1425119121431009244.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1435493267392952268.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1593964849978238997.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1635495804079319645.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1661692143874465793.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1696258779499687853.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1715510803830958981.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1744240866846047302.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1790866342662741660.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1887523398232412756.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache1910428943587920435.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache202957610162720364.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache213398181938256483.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2176432867604664501.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2181987950526514142.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2226371736570505783.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache225839720367038574.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2274489793790627593.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2292848304789553784.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2302247886706283980.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2317096157712343998.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2326310540534440293.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2328121114514127631.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2350533428834666424.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache235795628859653454.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2449925836599780796.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2476610317003797757.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2489668364419529822.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2500645528467964752.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2542935303876438488.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2550686864427729288.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2601891231139924431.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2609359409118725749.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2631404343167611776.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2716054113091085909.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache2735957531581256335.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3079440017680587809.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache308907375545121079.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3162235898162785473.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3228877817184866660.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache32637909120554496.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3283571290090178270.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache329106273901846274.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3360411635392650892.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3376473466017498526.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3485946747967494213.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3552830649225944445.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3595516649864305169.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3596246922313913058.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3615134167576661507.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3653725375717554941.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3658955269307217957.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3677356519555436836.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3764278409341990466.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3793832960428215105.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3859204473692251667.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3876843741139679895.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3899672756896985275.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache3936219170984577234.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4008467918634043576.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4021375851548926749.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4058963352693426080.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4145389895584645647.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4190268079025318927.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4430482291837916489.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4504123598356694347.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4516557891232613867.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4538806208627153498.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache456611247507184434.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4657807989189389711.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4692838071361424553.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4895638000495846531.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4948934164706984290.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache4968099375295249184.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5086988306986541600.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5115782556028483070.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5116814763101343251.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5261378613064103121.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5275770682039020593.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5365787892343840825.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5381107582505507320.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5426220702735722797.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5460590203119067527.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5462070691064382285.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5479057744615855996.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5541723442999985385.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5702740303923553460.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5797554230874030792.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5871064922585289291.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5893073048328549073.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache5946444501086118444.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6075557697391516893.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6091647337247958979.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6136268411469059544.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6253474603045893491.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6403623517758452296.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6466407284269839938.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6579063084376400816.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6595115959498898739.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6635920168644943797.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6822283174668286976.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6929242460509346719.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache6971218408761962223.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7026646499936855342.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7117160661121459201.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7124655346229739994.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7137743108429864186.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7147892636189728984.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache718172969566450987.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7245976959015136387.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7251212604882174523.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7287013332576373868.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7331343680704438194.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7333910115022894577.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7393791006318222650.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7400162759093403200.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7541024572245783744.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache754961579764169477.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7582331570614243527.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7607622205734730221.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7775186124660578446.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7780491332066096724.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7786375460460969878.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7801607998116735399.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7855094754568352112.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7914304898016573454.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache7917705733690523993.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8037560977505391233.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8095713458431281514.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8109047388978124458.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8204862799679329804.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8260577059366084294.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8276109024602370263.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8320509153668098053.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8379366990721019447.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8431316544484128526.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8464764374459968734.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8477991179604363775.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8551399813125789296.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8715033417845473064.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8715213433083811211.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache87242501127254867.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8726289396294140061.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8807465097489187257.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8820209966281277342.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache883133466660085896.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8872099248655345751.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache8915729021171509931.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache9015881979462656485.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache9099722423298326426.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache9105586332460727028.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache9198327292112923104.tmp moved successfully. C:\Users\ACER\AppData\Local\Temp\jar_cache929672455999185764.tmp moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\ACER\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. C:\Users\ACER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanidiskr65.dll moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.26.1 log created on 08092011_212532 |
weiß nicht genau wie das jetzt abläuft, aber nach dem otl fix habe ich gerade antivir wieder eingeschaltet und bekam wieder die virus meldung....! |
Zitat:
|
Guard: Malware gefunden Datum/Uhrzeit: 09.08.2011, 21:29:30 Typ: Fund In der Datei 'C:\Users\ACER\floadu1C.dll' wurde ein Virus oder unerwünschtes Pogramm 'TR/PSW.Sinowal.Y.580' gefunden. |
Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. http://www.trojaner-board.de/attachm...rnen-start.png Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif |
2011/08/10 10:20:29.0550 1880 TDSS rootkit removing tool 2.5.14.0 Aug 5 2011 16:09:29 2011/08/10 10:20:29.0740 1880 ================================================================================ 2011/08/10 10:20:29.0740 1880 SystemInfo: 2011/08/10 10:20:29.0740 1880 2011/08/10 10:20:29.0740 1880 OS Version: 6.1.7600 ServicePack: 0.0 2011/08/10 10:20:29.0740 1880 Product type: Workstation 2011/08/10 10:20:29.0740 1880 ComputerName: ACER-PC 2011/08/10 10:20:29.0740 1880 UserName: ACER 2011/08/10 10:20:29.0740 1880 Windows directory: C:\Windows 2011/08/10 10:20:29.0740 1880 System windows directory: C:\Windows 2011/08/10 10:20:29.0740 1880 Running under WOW64 2011/08/10 10:20:29.0740 1880 Processor architecture: Intel x64 2011/08/10 10:20:29.0740 1880 Number of processors: 2 2011/08/10 10:20:29.0740 1880 Page size: 0x1000 2011/08/10 10:20:29.0740 1880 Boot type: Normal boot 2011/08/10 10:20:29.0740 1880 ================================================================================ 2011/08/10 10:20:32.0913 1880 Initialize success 2011/08/10 10:20:47.0423 3012 ================================================================================ 2011/08/10 10:20:47.0423 3012 Scan started 2011/08/10 10:20:47.0423 3012 Mode: Manual; 2011/08/10 10:20:47.0423 3012 ================================================================================ 2011/08/10 10:20:48.0799 3012 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 2011/08/10 10:20:49.0028 3012 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 2011/08/10 10:20:49.0296 3012 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 2011/08/10 10:20:49.0527 3012 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 2011/08/10 10:20:49.0841 3012 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 2011/08/10 10:20:50.0097 3012 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 2011/08/10 10:20:50.0317 3012 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys 2011/08/10 10:20:50.0776 3012 AgereSoftModem (af4748ef93416159459769a24a0053af) C:\Windows\system32\DRIVERS\agrsm64.sys 2011/08/10 10:20:50.0933 3012 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 2011/08/10 10:20:51.0093 3012 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 2011/08/10 10:20:51.0327 3012 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 2011/08/10 10:20:51.0498 3012 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 2011/08/10 10:20:51.0913 3012 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 2011/08/10 10:20:52.0014 3012 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys 2011/08/10 10:20:52.0101 3012 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 2011/08/10 10:20:52.0242 3012 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys 2011/08/10 10:20:52.0426 3012 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 2011/08/10 10:20:52.0657 3012 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 2011/08/10 10:20:53.0009 3012 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 2011/08/10 10:20:53.0315 3012 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/08/10 10:20:53.0546 3012 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 2011/08/10 10:20:53.0932 3012 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 2011/08/10 10:20:54.0127 3012 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 2011/08/10 10:20:54.0289 3012 BCM43XX (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys 2011/08/10 10:20:54.0470 3012 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 2011/08/10 10:20:54.0691 3012 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 2011/08/10 10:20:54.0879 3012 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys 2011/08/10 10:20:55.0027 3012 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2011/08/10 10:20:55.0218 3012 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2011/08/10 10:20:55.0366 3012 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 2011/08/10 10:20:55.0566 3012 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 2011/08/10 10:20:55.0916 3012 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 2011/08/10 10:20:56.0050 3012 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 2011/08/10 10:20:56.0235 3012 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 2011/08/10 10:20:56.0779 3012 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/08/10 10:20:56.0919 3012 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 2011/08/10 10:20:57.0175 3012 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 2011/08/10 10:20:57.0419 3012 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 2011/08/10 10:20:57.0675 3012 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/08/10 10:20:57.0843 3012 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 2011/08/10 10:20:58.0013 3012 cmnsusbser (2b3b8cbea1ba1bce5700607fbdb31034) C:\Windows\system32\DRIVERS\cmnsusbser.sys 2011/08/10 10:20:58.0232 3012 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 2011/08/10 10:20:58.0453 3012 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 2011/08/10 10:20:58.0609 3012 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 2011/08/10 10:20:58.0749 3012 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 2011/08/10 10:20:59.0224 3012 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys 2011/08/10 10:20:59.0374 3012 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 2011/08/10 10:20:59.0683 3012 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 2011/08/10 10:20:59.0925 3012 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 2011/08/10 10:21:00.0191 3012 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys 2011/08/10 10:21:00.0595 3012 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 2011/08/10 10:21:00.0933 3012 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 2011/08/10 10:21:01.0235 3012 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 2011/08/10 10:21:01.0412 3012 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 2011/08/10 10:21:01.0517 3012 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 2011/08/10 10:21:01.0640 3012 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 2011/08/10 10:21:01.0690 3012 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 2011/08/10 10:21:01.0792 3012 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 2011/08/10 10:21:01.0823 3012 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/08/10 10:21:01.0930 3012 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 2011/08/10 10:21:02.0042 3012 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 2011/08/10 10:21:02.0070 3012 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 2011/08/10 10:21:02.0107 3012 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 2011/08/10 10:21:02.0238 3012 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 2011/08/10 10:21:02.0342 3012 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 2011/08/10 10:21:02.0417 3012 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys 2011/08/10 10:21:02.0617 3012 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/08/10 10:21:02.0716 3012 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 2011/08/10 10:21:02.0794 3012 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 2011/08/10 10:21:02.0899 3012 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 2011/08/10 10:21:03.0027 3012 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 2011/08/10 10:21:03.0081 3012 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 2011/08/10 10:21:03.0272 3012 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 2011/08/10 10:21:03.0453 3012 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 2011/08/10 10:21:03.0583 3012 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/08/10 10:21:03.0781 3012 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 2011/08/10 10:21:04.0048 3012 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys 2011/08/10 10:21:04.0344 3012 igfx (a87261ef1546325b559374f5689cf5bc) C:\Windows\system32\DRIVERS\igdkmd64.sys 2011/08/10 10:21:04.0633 3012 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 2011/08/10 10:21:04.0762 3012 IntcAzAudAddService (9aa6a93852e36fe76c3f7fc2904f3b01) C:\Windows\system32\drivers\RTKVHD64.sys 2011/08/10 10:21:04.0934 3012 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 2011/08/10 10:21:05.0085 3012 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 2011/08/10 10:21:05.0207 3012 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/08/10 10:21:05.0237 3012 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2011/08/10 10:21:05.0344 3012 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 2011/08/10 10:21:05.0374 3012 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 2011/08/10 10:21:05.0468 3012 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 2011/08/10 10:21:05.0518 3012 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/08/10 10:21:05.0644 3012 k57nd60a (249ee2d26cb1530f3bede0ac8b9e3099) C:\Windows\system32\DRIVERS\k57nd60a.sys 2011/08/10 10:21:05.0767 3012 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/08/10 10:21:05.0802 3012 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/08/10 10:21:05.0892 3012 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 2011/08/10 10:21:05.0943 3012 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 2011/08/10 10:21:06.0120 3012 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 2011/08/10 10:21:06.0254 3012 L1E (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys 2011/08/10 10:21:06.0486 3012 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 2011/08/10 10:21:06.0631 3012 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 2011/08/10 10:21:06.0677 3012 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 2011/08/10 10:21:06.0812 3012 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2011/08/10 10:21:06.0934 3012 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2011/08/10 10:21:06.0971 3012 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 2011/08/10 10:21:07.0140 3012 MBAMProtector (9c4fb231b6e02f84580de2f00f3c5293) C:\Windows\system32\drivers\mbam.sys 2011/08/10 10:21:07.0291 3012 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 2011/08/10 10:21:07.0465 3012 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 2011/08/10 10:21:07.0644 3012 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 2011/08/10 10:21:07.0935 3012 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 2011/08/10 10:21:08.0046 3012 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 2011/08/10 10:21:08.0185 3012 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 2011/08/10 10:21:08.0225 3012 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 2011/08/10 10:21:08.0471 3012 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 2011/08/10 10:21:08.0647 3012 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 2011/08/10 10:21:08.0694 3012 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 2011/08/10 10:21:08.0867 3012 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/08/10 10:21:09.0103 3012 mrxsmb10 (a8c2d7673c8a010569390c826a0efaf4) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/08/10 10:21:09.0311 3012 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/08/10 10:21:09.0530 3012 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 2011/08/10 10:21:09.0710 3012 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 2011/08/10 10:21:09.0839 3012 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 2011/08/10 10:21:09.0870 3012 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 2011/08/10 10:21:09.0899 3012 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 2011/08/10 10:21:10.0063 3012 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 2011/08/10 10:21:10.0188 3012 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/08/10 10:21:10.0230 3012 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 2011/08/10 10:21:10.0255 3012 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 2011/08/10 10:21:10.0504 3012 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/08/10 10:21:10.0700 3012 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 2011/08/10 10:21:10.0934 3012 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 2011/08/10 10:21:11.0036 3012 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 2011/08/10 10:21:11.0283 3012 mwlPSDFilter (6ffecc25b39dc7652a0cec0ada9db589) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys 2011/08/10 10:21:11.0473 3012 mwlPSDNServ (0befe32ca56d6ee89d58175725596a85) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys 2011/08/10 10:21:11.0624 3012 mwlPSDVDisk (d43bc633b8660463e446e28e14a51262) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys 2011/08/10 10:21:11.0705 3012 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 2011/08/10 10:21:11.0907 3012 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 2011/08/10 10:21:12.0147 3012 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 2011/08/10 10:21:12.0312 3012 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/08/10 10:21:12.0384 3012 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/08/10 10:21:12.0622 3012 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/08/10 10:21:12.0754 3012 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 2011/08/10 10:21:12.0907 3012 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 2011/08/10 10:21:13.0020 3012 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 2011/08/10 10:21:13.0650 3012 NETw5s64 (4d85a450edef10c38882182753a49aae) C:\Windows\system32\DRIVERS\NETw5s64.sys 2011/08/10 10:21:14.0034 3012 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 2011/08/10 10:21:14.0238 3012 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 2011/08/10 10:21:14.0423 3012 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 2011/08/10 10:21:14.0686 3012 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys 2011/08/10 10:21:14.0812 3012 NTIDrvr (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys 2011/08/10 10:21:14.0882 3012 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 2011/08/10 10:21:15.0130 3012 NVHDA (ad37248bd442d41c9a896e53eb8a85ee) C:\Windows\system32\drivers\nvhda64v.sys 2011/08/10 10:21:16.0079 3012 nvlddmkm (fd39b98ff1bb8ed3848781497e9d02e0) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2011/08/10 10:21:16.0351 3012 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys 2011/08/10 10:21:16.0405 3012 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys 2011/08/10 10:21:16.0533 3012 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 2011/08/10 10:21:16.0712 3012 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/08/10 10:21:16.0995 3012 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 2011/08/10 10:21:17.0173 3012 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 2011/08/10 10:21:17.0541 3012 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 2011/08/10 10:21:17.0825 3012 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 2011/08/10 10:21:17.0878 3012 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 2011/08/10 10:21:18.0021 3012 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 2011/08/10 10:21:18.0206 3012 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 2011/08/10 10:21:18.0489 3012 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 2011/08/10 10:21:18.0606 3012 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 2011/08/10 10:21:18.0703 3012 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 2011/08/10 10:21:18.0886 3012 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 2011/08/10 10:21:19.0149 3012 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 2011/08/10 10:21:19.0307 3012 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 2011/08/10 10:21:19.0476 3012 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 2011/08/10 10:21:19.0596 3012 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 2011/08/10 10:21:19.0723 3012 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/08/10 10:21:19.0774 3012 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/08/10 10:21:19.0845 3012 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 2011/08/10 10:21:19.0995 3012 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 2011/08/10 10:21:20.0117 3012 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 2011/08/10 10:21:20.0232 3012 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/08/10 10:21:20.0325 3012 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 2011/08/10 10:21:20.0460 3012 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 2011/08/10 10:21:20.0777 3012 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 2011/08/10 10:21:20.0967 3012 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 2011/08/10 10:21:21.0234 3012 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 2011/08/10 10:21:21.0434 3012 RSUSBSTOR (2db8116d52b19216812c4e6d5d837810) C:\Windows\System32\Drivers\RtsUStor.sys 2011/08/10 10:21:21.0859 3012 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 2011/08/10 10:21:21.0997 3012 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 2011/08/10 10:21:22.0211 3012 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 2011/08/10 10:21:22.0412 3012 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 2011/08/10 10:21:22.0637 3012 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 2011/08/10 10:21:22.0907 3012 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 2011/08/10 10:21:23.0314 3012 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 2011/08/10 10:21:23.0525 3012 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2011/08/10 10:21:23.0705 3012 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 2011/08/10 10:21:23.0783 3012 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 2011/08/10 10:21:24.0003 3012 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2011/08/10 10:21:24.0272 3012 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 2011/08/10 10:21:24.0523 3012 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 2011/08/10 10:21:24.0760 3012 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 2011/08/10 10:21:25.0163 3012 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys 2011/08/10 10:21:25.0442 3012 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys 2011/08/10 10:21:25.0673 3012 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys 2011/08/10 10:21:25.0869 3012 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 2011/08/10 10:21:26.0032 3012 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 2011/08/10 10:21:26.0310 3012 Tcpip (61dc720bb065d607d5823f13d2a64321) C:\Windows\system32\drivers\tcpip.sys 2011/08/10 10:21:26.0636 3012 TCPIP6 (61dc720bb065d607d5823f13d2a64321) C:\Windows\system32\DRIVERS\tcpip.sys 2011/08/10 10:21:26.0972 3012 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 2011/08/10 10:21:27.0082 3012 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 2011/08/10 10:21:27.0102 3012 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 2011/08/10 10:21:27.0136 3012 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 2011/08/10 10:21:27.0371 3012 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 2011/08/10 10:21:27.0566 3012 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/08/10 10:21:27.0813 3012 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 2011/08/10 10:21:28.0113 3012 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 2011/08/10 10:21:28.0215 3012 UBHelper (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys 2011/08/10 10:21:28.0291 3012 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 2011/08/10 10:21:28.0492 3012 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 2011/08/10 10:21:28.0630 3012 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 2011/08/10 10:21:28.0668 3012 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 2011/08/10 10:21:29.0005 3012 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/08/10 10:21:29.0216 3012 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 2011/08/10 10:21:29.0436 3012 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys 2011/08/10 10:21:29.0865 3012 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys 2011/08/10 10:21:30.0068 3012 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys 2011/08/10 10:21:30.0299 3012 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 2011/08/10 10:21:30.0453 3012 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 2011/08/10 10:21:30.0564 3012 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/08/10 10:21:30.0887 3012 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/08/10 10:21:31.0197 3012 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys 2011/08/10 10:21:31.0347 3012 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 2011/08/10 10:21:31.0431 3012 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/08/10 10:21:31.0730 3012 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 2011/08/10 10:21:31.0905 3012 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 2011/08/10 10:21:31.0945 3012 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 2011/08/10 10:21:31.0965 3012 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 2011/08/10 10:21:31.0990 3012 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 2011/08/10 10:21:32.0093 3012 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 2011/08/10 10:21:32.0209 3012 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 2011/08/10 10:21:32.0243 3012 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 2011/08/10 10:21:32.0420 3012 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 2011/08/10 10:21:32.0615 3012 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 2011/08/10 10:21:32.0839 3012 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2011/08/10 10:21:32.0873 3012 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2011/08/10 10:21:33.0125 3012 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 2011/08/10 10:21:33.0290 3012 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 2011/08/10 10:21:33.0465 3012 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 2011/08/10 10:21:33.0623 3012 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 2011/08/10 10:21:33.0847 3012 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys 2011/08/10 10:21:34.0069 3012 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/08/10 10:21:34.0227 3012 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 2011/08/10 10:21:34.0440 3012 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 2011/08/10 10:21:34.0637 3012 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/08/10 10:21:34.0715 3012 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 2011/08/10 10:21:34.0734 3012 Boot (0x1200) (52b904b75ab5897cf6dff165d8a4c238) \Device\Harddisk0\DR0\Partition0 2011/08/10 10:21:34.0767 3012 Boot (0x1200) (3f4a3012079f6bd55237f902e64a9d20) \Device\Harddisk0\DR0\Partition1 2011/08/10 10:21:34.0818 3012 Boot (0x1200) (c37f0ea150c1d7bb96572d6f4e0cfd46) \Device\Harddisk0\DR0\Partition2 2011/08/10 10:21:34.0848 3012 ================================================================================ 2011/08/10 10:21:34.0848 3012 Scan finished 2011/08/10 10:21:34.0848 3012 ================================================================================ 2011/08/10 10:21:34.0860 4356 Detected object count: 0 2011/08/10 10:21:34.0860 4356 Actual detected object count: 0 hab heute seit tagen mal den computer neu gestartet: es kam folegende meldung : Problem beim starten von C:\users\ACER\floadu1C.dll |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! |
nachdem combofix meinen pc neugestartet hat, kamen 2 fehlermeldungungen: "Zugriff verweigert: C:\Users\ACER\floadu1C.dll" und "Problem beim Starten von C:\users\ACER\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SCANID~1.dll" da sich durch das hochfahren auch antivir wieder aktiviert hat kam dann auch die meldung, dass 'TR/PSW.Sinowal.Y.580' in obigenen Pfaden gefunden wurde. soll ich wenn antivir die fehler meldet immer auf "remove klicken"? hier der log von combofix Combofix Logfile: Code: ComboFix 11-08-10.01 - ACER 10.08.2011 12:06:41.1.2 - x64 |
hab grad nen quickscan mit malwarebytes gemacht hat 3 dateien gefunden und diese gelöscht (siehe log) nach dem neustart hab ich nochmal quickscan durchgeführt und er hat nichts mehr gefunden. es kam auch keine fehlermeldung beim neustart... Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Datenbank Version: 7415 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 10.08.2011 13:42:21 mbam-log-2011-08-10 (13-42-21).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 212535 Laufzeit: 2 Minute(n), 40 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 3 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NvCplDaemonTool (Trojan.FakeAlert) -> Value: NvCplDaemonTool -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\Users\ACER\floadu1C.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\ACER\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\scanidiskr65.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\ACER\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully. |
Combofix - Scripten 1. Starte das Notepad (Start / Ausführen / notepad[Enter]) 2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein. Code: Folder:: 4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall. (Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !) 5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet. http://users.pandora.be/bluepatchy/m...s/CFScript.gif 6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien: Combofix.txt Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann! |
keine auffälligkeiten bisher beim neustart und keine meldung von antivir... Combofix Logfile: Code: ComboFix 11-08-10.01 - ACER 10.08.2011 15:01:26.2.2 - x64 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 00:22 Uhr. |
Copyright ©2000-2025, Trojaner-Board