Liste der Anhänge anzeigen (Anzahl: 1) Hallo Kira,
Danke für die schnelle Rückmeldung. So ich habe jetzt mal alles wie oben beschrieben gemacht und hier kommen die Ergebnisse:
LogFile von TDss: Code:
10:59:46.0469 3192 TDSS rootkit removing tool 2.6.9.0 Oct 14 2011 11:33:24
10:59:46.0484 3192 ============================================================
10:59:46.0484 3192 Current date / time: 2011/10/17 10:59:46.0469
10:59:46.0484 3192 SystemInfo:
10:59:46.0484 3192
10:59:46.0484 3192 OS Version: 6.1.7601 ServicePack: 1.0
10:59:46.0484 3192 Product type: Workstation
10:59:46.0484 3192 ComputerName: EUGENIA-PC
10:59:46.0484 3192 UserName: Eugenia
10:59:46.0484 3192 Windows directory: C:\Windows
10:59:46.0484 3192 System windows directory: C:\Windows
10:59:46.0484 3192 Processor architecture: Intel x86
10:59:46.0484 3192 Number of processors: 2
10:59:46.0484 3192 Page size: 0x1000
10:59:46.0484 3192 Boot type: Normal boot
10:59:46.0484 3192 ============================================================
10:59:46.0734 3192 Initialize success
10:59:50.0712 2540 ============================================================
10:59:50.0712 2540 Scan started
10:59:50.0712 2540 Mode: Manual;
10:59:50.0712 2540 ============================================================
10:59:51.0445 2540 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
10:59:51.0445 2540 1394ohci - ok
10:59:51.0586 2540 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
10:59:51.0586 2540 ACPI - ok
10:59:51.0726 2540 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
10:59:51.0726 2540 AcpiPmi - ok
10:59:51.0882 2540 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
10:59:51.0882 2540 adp94xx - ok
10:59:52.0007 2540 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
10:59:52.0007 2540 adpahci - ok
10:59:52.0116 2540 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
10:59:52.0116 2540 adpu320 - ok
10:59:52.0288 2540 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
10:59:52.0303 2540 AFD - ok
10:59:52.0397 2540 AgereSoftModem (7e10e3bb9b258ad8a9300f91214d67b9) C:\Windows\system32\DRIVERS\AGRSM.sys
10:59:52.0412 2540 AgereSoftModem - ok
10:59:52.0522 2540 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
10:59:52.0522 2540 agp440 - ok
10:59:52.0646 2540 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
10:59:52.0646 2540 aic78xx - ok
10:59:52.0802 2540 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
10:59:52.0802 2540 aliide - ok
10:59:52.0912 2540 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
10:59:52.0912 2540 amdagp - ok
10:59:53.0036 2540 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
10:59:53.0036 2540 amdide - ok
10:59:53.0161 2540 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
10:59:53.0161 2540 AmdK8 - ok
10:59:53.0255 2540 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
10:59:53.0255 2540 AmdPPM - ok
10:59:53.0395 2540 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
10:59:53.0395 2540 amdsata - ok
10:59:53.0489 2540 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
10:59:53.0504 2540 amdsbs - ok
10:59:53.0785 2540 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
10:59:53.0785 2540 amdxata - ok
10:59:53.0957 2540 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
10:59:53.0957 2540 AppID - ok
10:59:54.0144 2540 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
10:59:54.0144 2540 arc - ok
10:59:54.0253 2540 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
10:59:54.0253 2540 arcsas - ok
10:59:54.0362 2540 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
10:59:54.0362 2540 AsyncMac - ok
10:59:54.0518 2540 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
10:59:54.0518 2540 atapi - ok
10:59:54.0643 2540 ATSwpWDF (53ff3096d5d9ae2a75c16703a9819965) C:\Windows\system32\Drivers\ATSwpWDF.sys
10:59:54.0659 2540 ATSwpWDF - ok
10:59:54.0830 2540 avgntflt (7713e4eb0276702faa08e52a6e23f2a6) C:\Windows\system32\DRIVERS\avgntflt.sys
10:59:54.0830 2540 avgntflt - ok
10:59:54.0955 2540 avipbb (912d23140cd05980f6cdae790ddafc8d) C:\Windows\system32\DRIVERS\avipbb.sys
10:59:54.0955 2540 avipbb - ok
10:59:55.0080 2540 avkmgr (271cfd1a989209b1964e24d969552bf7) C:\Windows\system32\DRIVERS\avkmgr.sys
10:59:55.0080 2540 avkmgr - ok
10:59:55.0220 2540 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
10:59:55.0236 2540 b06bdrv - ok
10:59:55.0345 2540 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
10:59:55.0345 2540 b57nd60x - ok
10:59:55.0470 2540 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
10:59:55.0470 2540 Beep - ok
10:59:55.0579 2540 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
10:59:55.0579 2540 blbdrive - ok
10:59:55.0673 2540 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
10:59:55.0673 2540 bowser - ok
10:59:55.0751 2540 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:59:55.0751 2540 BrFiltLo - ok
10:59:55.0829 2540 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:59:55.0829 2540 BrFiltUp - ok
10:59:55.0985 2540 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
10:59:56.0000 2540 Brserid - ok
10:59:56.0078 2540 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
10:59:56.0078 2540 BrSerWdm - ok
10:59:56.0125 2540 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
10:59:56.0125 2540 BrUsbMdm - ok
10:59:56.0156 2540 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
10:59:56.0156 2540 BrUsbSer - ok
10:59:56.0234 2540 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
10:59:56.0250 2540 BTHMODEM - ok
10:59:56.0375 2540 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
10:59:56.0375 2540 cdfs - ok
10:59:56.0515 2540 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
10:59:56.0515 2540 cdrom - ok
10:59:56.0640 2540 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
10:59:56.0640 2540 circlass - ok
10:59:56.0702 2540 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
10:59:56.0702 2540 CLFS - ok
10:59:56.0858 2540 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
10:59:56.0858 2540 CmBatt - ok
10:59:56.0968 2540 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
10:59:56.0968 2540 cmdide - ok
10:59:57.0030 2540 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
10:59:57.0030 2540 CNG - ok
10:59:57.0108 2540 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
10:59:57.0108 2540 Compbatt - ok
10:59:57.0233 2540 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
10:59:57.0233 2540 CompositeBus - ok
10:59:57.0342 2540 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
10:59:57.0342 2540 crcdisk - ok
10:59:57.0514 2540 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
10:59:57.0514 2540 DfsC - ok
10:59:57.0576 2540 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
10:59:57.0576 2540 discache - ok
10:59:57.0654 2540 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
10:59:57.0654 2540 Disk - ok
10:59:57.0794 2540 DKbFltr (c701324c9e0c25dd9d60311bd87fbc84) C:\Windows\system32\DRIVERS\DKbFltr.sys
10:59:57.0794 2540 DKbFltr - ok
10:59:57.0935 2540 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
10:59:57.0935 2540 drmkaud - ok
10:59:58.0060 2540 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
10:59:58.0060 2540 DXGKrnl - ok
10:59:58.0247 2540 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
10:59:58.0340 2540 ebdrv - ok
10:59:58.0496 2540 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
10:59:58.0496 2540 elxstor - ok
10:59:58.0559 2540 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
10:59:58.0559 2540 ErrDev - ok
10:59:58.0637 2540 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
10:59:58.0637 2540 exfat - ok
10:59:58.0668 2540 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
10:59:58.0668 2540 fastfat - ok
10:59:58.0793 2540 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
10:59:58.0793 2540 fdc - ok
10:59:58.0855 2540 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
10:59:58.0855 2540 FileInfo - ok
10:59:58.0871 2540 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
10:59:58.0871 2540 Filetrace - ok
10:59:58.0902 2540 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
10:59:58.0902 2540 flpydisk - ok
10:59:58.0949 2540 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
10:59:58.0949 2540 FltMgr - ok
10:59:59.0011 2540 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
10:59:59.0011 2540 FsDepends - ok
10:59:59.0027 2540 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
10:59:59.0027 2540 Fs_Rec - ok
10:59:59.0105 2540 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
10:59:59.0105 2540 fvevol - ok
10:59:59.0152 2540 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
10:59:59.0152 2540 gagp30kx - ok
10:59:59.0308 2540 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
10:59:59.0308 2540 hcw85cir - ok
10:59:59.0401 2540 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
10:59:59.0401 2540 HdAudAddService - ok
10:59:59.0432 2540 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
10:59:59.0432 2540 HDAudBus - ok
10:59:59.0464 2540 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
10:59:59.0464 2540 HidBatt - ok
10:59:59.0479 2540 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
10:59:59.0479 2540 HidBth - ok
10:59:59.0542 2540 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
10:59:59.0542 2540 HidIr - ok
10:59:59.0651 2540 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
10:59:59.0651 2540 HidUsb - ok
10:59:59.0698 2540 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
10:59:59.0698 2540 HpSAMD - ok
10:59:59.0822 2540 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
10:59:59.0822 2540 HTTP - ok
10:59:59.0869 2540 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
10:59:59.0885 2540 hwpolicy - ok
10:59:59.0932 2540 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
10:59:59.0932 2540 i8042prt - ok
10:59:59.0978 2540 iaStor (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\DRIVERS\iaStor.sys
10:59:59.0978 2540 iaStor - ok
11:00:00.0103 2540 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
11:00:00.0119 2540 iaStorV - ok
11:00:00.0290 2540 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
11:00:00.0290 2540 iirsp - ok
11:00:00.0415 2540 IntcAzAudAddService (f2baa4ff548f7f0317f7638951c1cd9c) C:\Windows\system32\drivers\RTKVHDA.sys
11:00:00.0478 2540 IntcAzAudAddService - ok
11:00:00.0618 2540 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
11:00:00.0618 2540 intelide - ok
11:00:00.0665 2540 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
11:00:00.0665 2540 intelppm - ok
11:00:00.0696 2540 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:00:00.0696 2540 IpFilterDriver - ok
11:00:00.0774 2540 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
11:00:00.0774 2540 IPMIDRV - ok
11:00:00.0805 2540 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
11:00:00.0805 2540 IPNAT - ok
11:00:00.0821 2540 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
11:00:00.0821 2540 IRENUM - ok
11:00:00.0868 2540 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
11:00:00.0868 2540 isapnp - ok
11:00:00.0914 2540 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
11:00:00.0914 2540 iScsiPrt - ok
11:00:00.0992 2540 k57nd60x (c4c95805b85bce1eb9d20f4a02fc5f9b) C:\Windows\system32\DRIVERS\k57nd60x.sys
11:00:00.0992 2540 k57nd60x - ok
11:00:01.0039 2540 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
11:00:01.0039 2540 kbdclass - ok
11:00:01.0086 2540 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys
11:00:01.0102 2540 kbdhid - ok
11:00:01.0164 2540 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
11:00:01.0164 2540 KSecDD - ok
11:00:01.0195 2540 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
11:00:01.0211 2540 KSecPkg - ok
11:00:01.0382 2540 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
11:00:01.0382 2540 lltdio - ok
11:00:01.0445 2540 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
11:00:01.0445 2540 LSI_FC - ok
11:00:01.0476 2540 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
11:00:01.0476 2540 LSI_SAS - ok
11:00:01.0523 2540 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:00:01.0523 2540 LSI_SAS2 - ok
11:00:01.0554 2540 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:00:01.0554 2540 LSI_SCSI - ok
11:00:01.0585 2540 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
11:00:01.0585 2540 luafv - ok
11:00:01.0632 2540 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
11:00:01.0632 2540 megasas - ok
11:00:01.0663 2540 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
11:00:01.0679 2540 MegaSR - ok
11:00:01.0694 2540 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
11:00:01.0694 2540 Modem - ok
11:00:01.0741 2540 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
11:00:01.0741 2540 monitor - ok
11:00:01.0819 2540 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
11:00:01.0819 2540 mouclass - ok
11:00:01.0897 2540 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
11:00:01.0897 2540 mouhid - ok
11:00:01.0944 2540 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
11:00:01.0944 2540 mountmgr - ok
11:00:01.0991 2540 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
11:00:01.0991 2540 mpio - ok
11:00:02.0022 2540 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
11:00:02.0022 2540 mpsdrv - ok
11:00:02.0100 2540 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
11:00:02.0100 2540 MRxDAV - ok
11:00:02.0178 2540 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
11:00:02.0178 2540 mrxsmb - ok
11:00:02.0240 2540 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:00:02.0240 2540 mrxsmb10 - ok
11:00:02.0256 2540 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:00:02.0256 2540 mrxsmb20 - ok
11:00:02.0303 2540 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
11:00:02.0303 2540 msahci - ok
11:00:02.0365 2540 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
11:00:02.0381 2540 msdsm - ok
11:00:02.0443 2540 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
11:00:02.0443 2540 Msfs - ok
11:00:02.0459 2540 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
11:00:02.0459 2540 mshidkmdf - ok
11:00:02.0506 2540 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
11:00:02.0506 2540 msisadrv - ok
11:00:02.0552 2540 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
11:00:02.0552 2540 MSKSSRV - ok
11:00:02.0584 2540 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
11:00:02.0584 2540 MSPCLOCK - ok
11:00:02.0615 2540 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
11:00:02.0615 2540 MSPQM - ok
11:00:02.0646 2540 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
11:00:02.0646 2540 MsRPC - ok
11:00:02.0708 2540 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
11:00:02.0708 2540 mssmbios - ok
11:00:02.0771 2540 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
11:00:02.0771 2540 MSTEE - ok
11:00:02.0786 2540 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
11:00:02.0786 2540 MTConfig - ok
11:00:02.0833 2540 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
11:00:02.0833 2540 Mup - ok
11:00:02.0864 2540 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
11:00:02.0864 2540 NativeWifiP - ok
11:00:02.0927 2540 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
11:00:02.0927 2540 NDIS - ok
11:00:02.0958 2540 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
11:00:02.0958 2540 NdisCap - ok
11:00:02.0989 2540 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
11:00:02.0989 2540 NdisTapi - ok
11:00:03.0036 2540 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
11:00:03.0036 2540 Ndisuio - ok
11:00:03.0083 2540 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
11:00:03.0083 2540 NdisWan - ok
11:00:03.0130 2540 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
11:00:03.0130 2540 NDProxy - ok
11:00:03.0176 2540 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
11:00:03.0176 2540 NetBIOS - ok
11:00:03.0223 2540 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
11:00:03.0223 2540 NetBT - ok
11:00:03.0488 2540 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\Windows\system32\DRIVERS\netw5v32.sys
11:00:03.0613 2540 netw5v32 - ok
11:00:03.0738 2540 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
11:00:03.0738 2540 nfrd960 - ok
11:00:03.0800 2540 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
11:00:03.0800 2540 Npfs - ok
11:00:03.0847 2540 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
11:00:03.0847 2540 nsiproxy - ok
11:00:03.0941 2540 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
11:00:03.0972 2540 Ntfs - ok
11:00:04.0034 2540 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
11:00:04.0034 2540 Null - ok
11:00:04.0066 2540 NVHDA (603b0c9bb86f7b3efb88a482c6663ec4) C:\Windows\system32\drivers\nvhda32v.sys
11:00:04.0066 2540 NVHDA - ok
11:00:04.0284 2540 nvlddmkm (9a55250a7edc9ea12dc3495f5e9f8703) C:\Windows\system32\DRIVERS\nvlddmkm.sys
11:00:04.0471 2540 nvlddmkm - ok
11:00:04.0534 2540 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
11:00:04.0534 2540 nvraid - ok
11:00:04.0596 2540 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
11:00:04.0596 2540 nvstor - ok
11:00:04.0658 2540 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
11:00:04.0658 2540 nv_agp - ok
11:00:04.0721 2540 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
11:00:04.0721 2540 ohci1394 - ok
11:00:04.0768 2540 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
11:00:04.0768 2540 Parport - ok
11:00:04.0814 2540 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
11:00:04.0814 2540 partmgr - ok
11:00:04.0846 2540 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
11:00:04.0846 2540 Parvdm - ok
11:00:04.0892 2540 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
11:00:04.0892 2540 pci - ok
11:00:04.0939 2540 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
11:00:04.0939 2540 pciide - ok
11:00:04.0955 2540 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
11:00:04.0955 2540 pcmcia - ok
11:00:04.0986 2540 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
11:00:04.0986 2540 pcw - ok
11:00:05.0017 2540 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
11:00:05.0017 2540 PEAUTH - ok
11:00:05.0080 2540 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
11:00:05.0080 2540 PptpMiniport - ok
11:00:05.0095 2540 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
11:00:05.0095 2540 Processor - ok
11:00:05.0158 2540 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
11:00:05.0158 2540 Psched - ok
11:00:05.0189 2540 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
11:00:05.0251 2540 ql2300 - ok
11:00:05.0267 2540 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
11:00:05.0282 2540 ql40xx - ok
11:00:05.0298 2540 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
11:00:05.0298 2540 QWAVEdrv - ok
11:00:05.0314 2540 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
11:00:05.0314 2540 RasAcd - ok
11:00:05.0360 2540 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
11:00:05.0360 2540 RasAgileVpn - ok
11:00:05.0376 2540 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
11:00:05.0376 2540 Rasl2tp - ok
11:00:05.0407 2540 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
11:00:05.0407 2540 RasPppoe - ok
11:00:05.0438 2540 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
11:00:05.0438 2540 RasSstp - ok
11:00:05.0485 2540 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
11:00:05.0501 2540 rdbss - ok
11:00:05.0516 2540 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
11:00:05.0516 2540 rdpbus - ok
11:00:05.0579 2540 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
11:00:05.0579 2540 RDPCDD - ok
11:00:05.0594 2540 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
11:00:05.0610 2540 RDPENCDD - ok
11:00:05.0641 2540 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
11:00:05.0641 2540 RDPREFMP - ok
11:00:05.0688 2540 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
11:00:05.0688 2540 RDPWD - ok
11:00:05.0750 2540 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
11:00:05.0750 2540 rdyboost - ok
11:00:05.0875 2540 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
11:00:05.0875 2540 rspndr - ok
11:00:05.0938 2540 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
11:00:05.0938 2540 sbp2port - ok
11:00:05.0984 2540 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
11:00:05.0984 2540 scfilter - ok
11:00:06.0047 2540 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
11:00:06.0047 2540 secdrv - ok
11:00:06.0094 2540 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
11:00:06.0094 2540 Serenum - ok
11:00:06.0125 2540 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
11:00:06.0125 2540 Serial - ok
11:00:06.0187 2540 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
11:00:06.0187 2540 sermouse - ok
11:00:06.0234 2540 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
11:00:06.0250 2540 sffdisk - ok
11:00:06.0250 2540 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
11:00:06.0250 2540 sffp_mmc - ok
11:00:06.0281 2540 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
11:00:06.0281 2540 sffp_sd - ok
11:00:06.0312 2540 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
11:00:06.0312 2540 sfloppy - ok
11:00:06.0359 2540 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
11:00:06.0359 2540 sisagp - ok
11:00:06.0406 2540 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:00:06.0406 2540 SiSRaid2 - ok
11:00:06.0421 2540 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
11:00:06.0421 2540 SiSRaid4 - ok
11:00:06.0452 2540 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
11:00:06.0452 2540 Smb - ok
11:00:06.0484 2540 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
11:00:06.0484 2540 spldr - ok
11:00:06.0562 2540 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
11:00:06.0562 2540 srv - ok
11:00:06.0593 2540 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
11:00:06.0593 2540 srv2 - ok
11:00:06.0608 2540 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
11:00:06.0624 2540 srvnet - ok
11:00:06.0671 2540 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
11:00:06.0671 2540 ssmdrv - ok
11:00:06.0718 2540 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
11:00:06.0718 2540 stexstor - ok
11:00:06.0796 2540 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
11:00:06.0796 2540 swenum - ok
11:00:06.0905 2540 Tcpip (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\drivers\tcpip.sys
11:00:06.0952 2540 Tcpip - ok
11:00:06.0998 2540 TCPIP6 (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\DRIVERS\tcpip.sys
11:00:07.0014 2540 TCPIP6 - ok
11:00:07.0076 2540 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
11:00:07.0076 2540 tcpipreg - ok
11:00:07.0123 2540 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
11:00:07.0123 2540 TDPIPE - ok
11:00:07.0154 2540 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
11:00:07.0154 2540 TDTCP - ok
11:00:07.0201 2540 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
11:00:07.0201 2540 tdx - ok
11:00:07.0248 2540 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
11:00:07.0248 2540 TermDD - ok
11:00:07.0342 2540 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
11:00:07.0342 2540 tssecsrv - ok
11:00:07.0404 2540 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
11:00:07.0404 2540 TsUsbFlt - ok
11:00:07.0466 2540 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
11:00:07.0482 2540 tunnel - ok
11:00:07.0513 2540 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
11:00:07.0529 2540 uagp35 - ok
11:00:07.0560 2540 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
11:00:07.0576 2540 udfs - ok
11:00:07.0654 2540 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
11:00:07.0654 2540 uliagpkx - ok
11:00:07.0732 2540 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
11:00:07.0732 2540 umbus - ok
11:00:07.0778 2540 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
11:00:07.0778 2540 UmPass - ok
11:00:07.0810 2540 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
11:00:07.0810 2540 usbccgp - ok
11:00:07.0857 2540 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
11:00:07.0857 2540 usbcir - ok
11:00:07.0903 2540 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
11:00:07.0903 2540 usbehci - ok
11:00:07.0950 2540 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
11:00:07.0950 2540 usbhub - ok
11:00:07.0981 2540 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys
11:00:07.0981 2540 usbohci - ok
11:00:08.0028 2540 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
11:00:08.0028 2540 usbprint - ok
11:00:08.0059 2540 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:00:08.0059 2540 USBSTOR - ok
11:00:08.0075 2540 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys
11:00:08.0075 2540 usbuhci - ok
11:00:08.0137 2540 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
11:00:08.0153 2540 usbvideo - ok
11:00:08.0215 2540 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
11:00:08.0215 2540 vdrvroot - ok
11:00:08.0262 2540 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
11:00:08.0262 2540 vga - ok
11:00:08.0278 2540 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
11:00:08.0278 2540 VgaSave - ok
11:00:08.0325 2540 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
11:00:08.0325 2540 vhdmp - ok
11:00:08.0387 2540 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
11:00:08.0387 2540 viaagp - ok
11:00:08.0418 2540 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
11:00:08.0434 2540 ViaC7 - ok
11:00:08.0465 2540 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
11:00:08.0465 2540 viaide - ok
11:00:08.0496 2540 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
11:00:08.0496 2540 volmgr - ok
11:00:08.0527 2540 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
11:00:08.0527 2540 volmgrx - ok
11:00:08.0559 2540 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
11:00:08.0559 2540 volsnap - ok
11:00:08.0590 2540 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
11:00:08.0590 2540 vsmraid - ok
11:00:08.0637 2540 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
11:00:08.0637 2540 vwifibus - ok
11:00:08.0683 2540 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
11:00:08.0683 2540 WacomPen - ok
11:00:08.0746 2540 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
11:00:08.0746 2540 WANARP - ok
11:00:08.0746 2540 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
11:00:08.0746 2540 Wanarpv6 - ok
11:00:08.0824 2540 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
11:00:08.0824 2540 Wd - ok
11:00:08.0855 2540 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
11:00:08.0871 2540 Wdf01000 - ok
11:00:08.0933 2540 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
11:00:08.0933 2540 WfpLwf - ok
11:00:08.0949 2540 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
11:00:08.0949 2540 WIMMount - ok
11:00:09.0027 2540 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
11:00:09.0027 2540 WmiAcpi - ok
11:00:09.0089 2540 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
11:00:09.0089 2540 ws2ifsl - ok
11:00:09.0136 2540 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
11:00:09.0151 2540 WudfPf - ok
11:00:09.0183 2540 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
11:00:09.0183 2540 WUDFRd - ok
11:00:09.0214 2540 MBR (0x1B8) (de1996b5390bac8242e23168f828c750) \Device\Harddisk0\DR0
11:00:09.0214 2540 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - infected
11:00:09.0214 2540 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
11:00:09.0229 2540 Boot (0x1200) (fee8532a7e4fb61d280e8fa3ca1b98f1) \Device\Harddisk0\DR0\Partition0
11:00:09.0245 2540 \Device\Harddisk0\DR0\Partition0 - ok
11:00:09.0245 2540 ============================================================
11:00:09.0245 2540 Scan finished
11:00:09.0245 2540 ============================================================
11:00:09.0261 3728 Detected object count: 1
11:00:09.0261 3728 Actual detected object count: 1
11:00:32.0754 3728 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - will be cured on reboot
11:00:32.0754 3728 \Device\Harddisk0\DR0 - ok
11:00:32.0754 3728 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - User select action: Cure
11:00:42.0769 2592 Deinitialize success Textdatei vom CCleaner: Code:
7-Zip 9.20 15.10.2011
Acer Bio Protection Egis Technology Inc. 30.12.2010 109,3MB 6.2.56
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 31.12.2010 6,00MB 10.1.102.64
Adobe Flash Player 10 Plugin Adobe Systems Incorporated 14.06.2011 6,00MB 10.3.181.26
Adobe Reader X (10.1.0) - Deutsch Adobe Systems Incorporated 15.06.2011 165,3MB 10.1.0
AuthenTec Fingerprint Software AuthenTec, Inc. 30.12.2010 9,04MB 8.5.2.3
Avira Free Antivirus Avira 14.10.2011 104,4MB 12.0.0.855
CCleaner Piriform 16.10.2011 3.11
Click to Call with Skype Skype Technologies S.A. 21.08.2011 13,7MB 5.5.8013
CorelDRAW Essential Edition 3 Corel Corporation 30.12.2010
Google Chrome Google Inc. 02.02.2011 14.0.835.202
Google Earth Plug-in Google 25.05.2011 39,9MB 6.0.3.2197
ICQ Toolbar ICQ 30.12.2010 3.0.0
Java(TM) 6 Update 26 Oracle 17.03.2011 94,8MB 6.0.260
Launch Manager Acer Inc. 30.12.2010 3.0.03
Malwarebytes' Anti-Malware Version 1.51.2.1300 Malwarebytes Corporation 12.10.2011 13,8MB 1.51.2.1300
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 31.12.2010 38,8MB 4.0.30319
Microsoft Office File Validation Add-In Microsoft Corporation 16.09.2011 7,95MB 14.0.5130.5003
Microsoft Office Home and Student 2007 Microsoft Corporation 31.12.2010 12.0.6425.1000
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Corporation 11.05.2011 0,58MB 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 14.10.2011 0,23MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 30.12.2010 0,58MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 15.06.2011 0,59MB 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 15.10.2011 12,3MB 10.0.40219
Mozilla Firefox 6.0.2 (x86 de) Mozilla 08.09.2011 37,8MB 6.0.2
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 31.12.2010 1,28MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 01.01.2011 1,33MB 4.20.9876.0
Nero 8 Essentials Nero AG 30.12.2010 1.930MB 8.3.124
NVIDIA Drivers NVIDIA Corporation 30.12.2010 1.5
PDFCreator Frank Heindörfer, Philip Chinery 22.05.2011 1.2.1
pdfforge Toolbar v4.7 Spigot, Inc. 03.10.2011 6,61MB 4.7
Phase 5 HTML-Editor Systemberatung Schommer 19.05.2011 3,72MB 5.6.2.3
PhotoScape 02.02.2011
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 30.12.2010 6.0.1.5888
Skype™ 5.5 Skype Technologies S.A. 21.08.2011 17,0MB 5.5.113
Upgrade Kit Acer Inc. 30.12.2010 1.00.3002 LogFile Gmer
[code]
GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2011-10-17 12:35:27
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0
Running: q6kd39nk.exe; Driver: C:\Users\Eugenia\AppData\Local\Temp\pwdiyfow.sys
---- System - GMER 1.0.15 ----
SSDT 90C17AAE ZwCreateSection
SSDT 90C17AB8 ZwRequestWaitReplyPort
SSDT 90C17AB3 ZwSetContextThread
SSDT 90C17ABD ZwSetSecurityObject
SSDT 90C17AC2 ZwSystemDebugControl
SSDT 90C17A4F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 83293349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 832CCD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 832D3EAC 4 Bytes [AE, 7A, C1, 90] {SCASB ; JP 0xffffffffffffffc4; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1553 832D4208 4 Bytes [B8, 7A, C1, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1597 832D424C 4 Bytes [B3, 7A, C1, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1613 832D42C8 4 Bytes [BD, 7A, C1, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1667 832D431C 4 Bytes [C2, 7A, C1, 90] {RET 0xc17a; NOP }
.text ...
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000046 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ---- --- --- ---
LogFile Mbr: Code:
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, hxxp://www.gmer.net
Windows 6.1.7601 Disk: WDC_WD50 rev.01.0 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
1 ntkrnlpa!IofCallDriver[0x8328C52A] -> \Device\Harddisk0\DR0[0x86EDF848]
3 CLASSPNP[0x8B3D959E] -> ntkrnlpa!IofCallDriver[0x8328C52A] -> \Device\Ide\IAAStorageDevice-1[0x8608B028]
kernel: MBR read successfully
user & kernel MBR OK und Logfile von OTL:
OTL
OTL Logfile: Code:
OTL logfile created on: 17.10.2011 13:26:51 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Eugenia\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 66,75% Memory free
5,99 Gb Paging File | 4,84 Gb Available in Paging File | 80,87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 374,82 Gb Free Space | 82,20% Space Free | Partition Type: NTFS
Computer Name: EUGENIA-PC | User Name: Eugenia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.10.16 19:51:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Eugenia\Desktop\OTL.exe
PRC - [2011.10.11 15:00:02 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.10.11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 14:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.09.27 21:34:02 | 000,894,304 | ---- | M] (Spigot, Inc.) -- C:\Programme\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2011.09.27 20:08:40 | 000,745,880 | ---- | M] (Spigot, Inc.) -- C:\Programme\Application Updater\ApplicationUpdater.exe
PRC - [2011.09.09 17:00:35 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.01.05 10:18:50 | 000,133,432 | ---- | M] (ICQ, LLC.) -- C:\Programme\ICQ7.2\ICQ.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () -- C:\Programme\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.09.05 10:29:06 | 003,449,856 | ---- | M] (Egis Technology Inc.) -- C:\Programme\Acer Bio Protection\BASVC.exe
PRC - [2009.09.05 10:28:52 | 003,360,768 | ---- | M] (Egis Technology Inc.) -- C:\Programme\Acer Bio Protection\CompPtcVUI.exe
PRC - [2009.08.27 06:48:32 | 001,194,504 | ---- | M] (Dritek System Inc.) -- C:\Programme\Launch Manager\LManager.exe
PRC - [2009.08.05 05:40:10 | 001,807,608 | ---- | M] (AuthenTec, Inc.) -- C:\Programme\Fingerprint Sensor\AtService.exe
========== Modules (No Company Name) ==========
MOD - [2011.09.09 17:00:35 | 001,846,232 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2011.06.15 11:38:26 | 006,271,136 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011.01.05 10:18:56 | 000,733,184 | ---- | M] () -- C:\Programme\ICQ7.2\MDb.dll
========== Win32 Services (SafeList) ==========
SRV - [2011.10.11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.09.27 20:08:40 | 000,745,880 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.01.13 23:13:46 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () [Auto | Running] -- C:\Programme\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.09.05 10:29:06 | 003,449,856 | ---- | M] (Egis Technology Inc.) [Auto | Running] -- C:\Programme\Acer Bio Protection\BASVC.exe -- (IGBASVC)
SRV - [2009.08.05 05:40:10 | 001,807,608 | ---- | M] (AuthenTec, Inc.) [Auto | Running] -- C:\Programme\Fingerprint Sensor\AtService.exe -- (ATService)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2011.10.11 15:00:01 | 000,134,344 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.10.11 15:00:01 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.10.11 15:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.08.05 06:14:40 | 000,659,328 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATSwpWDF.sys -- (ATSwpWDF)
DRV - [2009.07.28 00:26:00 | 009,791,552 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.07.14 00:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2009.07.14 00:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x) Broadcom NetLink (TM)
DRV - [2009.04.30 15:43:34 | 000,064,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DB 05 8D 96 FA A8 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.7\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.web.de"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.09.09 17:00:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.16 10:20:56 | 000,000,000 | ---D | M]
[2010.12.31 17:07:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eugenia\AppData\Roaming\mozilla\Extensions
[2011.05.23 19:47:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eugenia\AppData\Roaming\mozilla\Firefox\Profiles\omwy9vkt.default\extensions
[2011.05.23 19:47:47 | 000,000,000 | ---D | M] (Gutscheinrausch.de) -- C:\Users\Eugenia\AppData\Roaming\mozilla\Firefox\Profiles\omwy9vkt.default\extensions\mail@gutscheinrausch.de
[2011.10.10 14:04:06 | 000,000,950 | ---- | M] () -- C:\Users\Eugenia\AppData\Roaming\Mozilla\Firefox\Profiles\omwy9vkt.default\searchplugins\icqplugin-1.xml
[2011.04.29 23:03:08 | 000,001,056 | ---- | M] () -- C:\Users\Eugenia\AppData\Roaming\Mozilla\Firefox\Profiles\omwy9vkt.default\searchplugins\icqplugin.xml
[2011.10.04 12:09:06 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.08.22 17:17:39 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.03.18 13:57:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.07.15 19:49:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011.07.01 20:47:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\distribution\extensions
[2011.07.01 20:47:32 | 000,000,000 | ---D | M] (WEB.DE Toolbar) -- C:\Programme\Mozilla Firefox\distribution\extensions\toolbar@web.de
[2011.09.09 17:00:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - Extension: Click to call with Skype = C:\Users\Eugenia\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\
Hosts file not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.7\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.7\pdfforgeToolbarIE.dll (Spigot, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Programme\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.)
O9 - Extra 'Tools' menuitem : Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Programme\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C3CBFE35-9BE8-11D1-B31B-006008948294} hxxp://www.aquire.com/codebase81/OrgPubX.cab (OrgPublisher PluginX)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.196.13.241
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1ADD4CCA-84F6-421A-828B-F206D322F822}: DhcpNameServer = 141.72.3.12 141.72.3.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7187A8D5-2AA9-410A-8E49-0A3B7E2B5935}: DhcpNameServer = 193.196.13.241
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.10.16 19:51:44 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Eugenia\Desktop\OTL.exe
[2011.10.16 18:52:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011.10.16 18:52:48 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011.10.15 17:23:57 | 000,000,000 | ---D | C] -- C:\Users\Eugenia\AppData\Roaming\Avira
[2011.10.15 17:23:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011.10.15 17:23:26 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011.10.15 17:23:25 | 000,134,344 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.10.15 17:23:25 | 000,074,640 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011.10.15 17:23:25 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
[2011.10.15 17:23:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011.10.15 17:23:21 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011.10.15 16:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2011.10.14 12:04:02 | 001,559,344 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Eugenia\Desktop\TDSSKiller.exe
[2011.10.13 11:50:46 | 000,000,000 | ---D | C] -- C:\Users\Eugenia\AppData\Roaming\Malwarebytes
[2011.10.13 11:50:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.10.13 11:50:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.10.13 11:50:32 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.10.13 11:50:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.10.12 13:42:45 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2011.10.12 13:42:45 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2011.10.12 13:42:44 | 002,334,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.10.12 13:42:39 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.10.12 13:42:39 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.10.12 13:42:38 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.10.12 13:42:38 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.10.12 13:42:38 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.10.11 18:34:17 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011.10.11 17:32:13 | 000,000,000 | RHSD | C] -- C:\Users\Eugenia\M-1-52-5782-8752-5245
[2011.10.04 12:09:06 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2011.10.04 12:09:05 | 000,000,000 | ---D | C] -- C:\Program Files\pdfforge Toolbar
========== Files - Modified Within 30 Days ==========
[2011.10.17 13:24:26 | 000,010,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.10.17 13:24:26 | 000,010,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.10.17 13:17:05 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.10.17 13:16:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.10.17 13:16:50 | 2411,855,872 | -HS- | M] () -- C:\hiberfil.sys
[2011.10.17 12:42:01 | 000,089,088 | ---- | M] () -- C:\Windows\System32\mbr.exe
[2011.10.17 11:52:00 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.10.17 11:46:07 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.10.16 22:18:54 | 000,014,260 | ---- | M] () -- C:\Users\Eugenia\Desktop\Desktop.zip
[2011.10.16 21:16:48 | 000,302,592 | ---- | M] () -- C:\Users\Eugenia\Desktop\q6kd39nk.exe
[2011.10.16 19:51:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Eugenia\Desktop\OTL.exe
[2011.10.16 18:55:33 | 000,000,000 | ---- | M] () -- C:\Users\Eugenia\defogger_reenable
[2011.10.16 18:45:14 | 000,050,477 | ---- | M] () -- C:\Users\Eugenia\Desktop\Defogger.exe
[2011.10.15 17:23:42 | 000,001,944 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2011.10.15 16:06:23 | 001,394,358 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB
[2011.10.14 12:04:02 | 001,559,344 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Eugenia\Desktop\TDSSKiller.exe
[2011.10.13 11:50:37 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.10.12 14:24:39 | 000,309,224 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.10.12 14:18:34 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.10.12 14:18:34 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.10.12 14:18:34 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.10.12 14:18:34 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.10.11 15:00:01 | 000,134,344 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.10.11 15:00:01 | 000,074,640 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011.10.11 15:00:01 | 000,036,000 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
[2011.10.09 12:43:17 | 000,002,821 | ---- | M] () -- C:\Users\Eugenia\Desktop\5. Semester - Verknüpfung.lnk
[2011.10.05 11:53:39 | 000,002,290 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011.10.01 04:42:56 | 001,638,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.09.18 10:12:53 | 000,051,712 | ---- | M] () -- C:\Users\Eugenia\Desktop\studienbescheinigung eugenia schwagerus.pdf
========== Files Created - No Company Name ==========
[2011.10.17 12:41:48 | 000,089,088 | ---- | C] () -- C:\Windows\System32\mbr.exe
[2011.10.16 22:18:54 | 000,014,260 | ---- | C] () -- C:\Users\Eugenia\Desktop\Desktop.zip
[2011.10.16 21:16:43 | 000,302,592 | ---- | C] () -- C:\Users\Eugenia\Desktop\q6kd39nk.exe
[2011.10.16 18:55:33 | 000,000,000 | ---- | C] () -- C:\Users\Eugenia\defogger_reenable
[2011.10.16 18:45:13 | 000,050,477 | ---- | C] () -- C:\Users\Eugenia\Desktop\Defogger.exe
[2011.10.15 17:23:42 | 000,001,944 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2011.10.15 16:05:47 | 001,394,358 | ---- | C] () -- C:\Windows\System32\drivers\Cat.DB
[2011.10.13 11:50:37 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.10.09 12:43:17 | 000,002,821 | ---- | C] () -- C:\Users\Eugenia\Desktop\5. Semester - Verknüpfung.lnk
[2011.09.18 10:12:53 | 000,051,712 | ---- | C] () -- C:\Users\Eugenia\Desktop\studienbescheinigung eugenia schwagerus.pdf
[2011.05.23 19:47:42 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010.12.31 16:47:06 | 000,123,780 | R--- | C] () -- C:\Windows\System32\drivers\RtConvEQ.DAT
[2010.12.31 16:47:06 | 000,001,496 | R--- | C] () -- C:\Windows\System32\drivers\RtkAcerM.dat
[2010.12.31 16:47:06 | 000,000,728 | R--- | C] () -- C:\Windows\System32\drivers\RtHdatEx.dat
[2010.12.31 16:47:06 | 000,000,520 | R--- | C] () -- C:\Windows\System32\drivers\RTEQEX2.dat
[2010.12.31 16:47:06 | 000,000,520 | R--- | C] () -- C:\Windows\System32\drivers\RTEQEX1.dat
[2010.12.31 16:47:06 | 000,000,520 | R--- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat
[2010.12.31 16:47:06 | 000,000,008 | R--- | C] () -- C:\Windows\System32\drivers\rtkhdaud.dat
[2009.07.14 10:47:43 | 000,654,166 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,130,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,309,224 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,616,008 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2011.10.15 17:23:29 | 000,000,000 | ---D | M] -- C:\Users\Eugenia\AppData\Roaming\ICQ
[2011.03.19 16:55:23 | 000,000,000 | ---D | M] -- C:\Users\Eugenia\AppData\Roaming\Juniper Networks
[2011.05.23 19:47:40 | 000,000,000 | ---D | M] -- C:\Users\Eugenia\AppData\Roaming\OpenCandy
[2011.07.27 20:32:49 | 000,000,000 | ---D | M] -- C:\Users\Eugenia\AppData\Roaming\PhotoScape
[2011.10.17 11:03:07 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report > --- --- ---
Extras:
OTL Logfile: Code:
OTL Extras logfile created on: 17.10.2011 13:26:51 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Eugenia\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 66,75% Memory free
5,99 Gb Paging File | 4,84 Gb Available in Paging File | 80,87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 374,82 Gb Free Space | 82,20% Space Free | Partition Type: NTFS
Computer Name: EUGENIA-PC | User Name: Eugenia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}" = CorelDRAW Essential Edition 3
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{1D0FDD6D-3C5E-4588-8ED0-02DC88014BF2}" = Upgrade Kit
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20B1B020-DEAE-48D1-9960-D4C3185D758B}" = Phase 5 HTML-Editor
"{22CFB202-3D2D-44E2-BB7C-6F703B99919B}" = pdfforge Toolbar v4.7
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 26
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{47948554-90C6-4AAC-8CFA-D23CE11C1031}" = Nero 8 Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6E810309-4B18-4DC4-A383-F0FB830B02B1}" = AuthenTec Fingerprint Software
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A334F1BA-0A1D-4ED6-B4F9-4066157CA15D}" = DE
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Deutsch
"{ADDBE07D-95B8-4789-9C76-187FFF9624B4}" = CorelDRAW Essential Edition 3
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{E09664BB-BB08-45FA-87D1-33EAB0E017F5}" = Fingerprint Solution
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ICQToolbar" = ICQ Toolbar
"InstallShield_{E09664BB-BB08-45FA-87D1-33EAB0E017F5}" = Acer Bio Protection
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 6.0.2 (x86 de)" = Mozilla Firefox 6.0.2 (x86 de)
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoScape" = PhotoScape
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 16.10.2011 06:02:18 | Computer Name = Eugenia-PC | Source = VSS | ID = 8194
Description =
Error - 16.10.2011 14:34:43 | Computer Name = Eugenia-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 110c Startzeit:
01cc8c30628e75ee Endzeit: 16 Anwendungspfad: C:\Users\Eugenia\Desktop\OTL.exe Berichts-ID:
Error - 16.10.2011 14:38:10 | Computer Name = Eugenia-PC | Source = Application Hang | ID = 1002
Description = Programm ICQ.exe, Version 7.2.0.3525 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c84 Startzeit:
01cc8c25b29c8114 Endzeit: 16 Anwendungspfad: C:\Program Files\ICQ7.2\ICQ.exe Berichts-ID:
Error - 16.10.2011 14:46:40 | Computer Name = Eugenia-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 96c Startzeit:
01cc8c331906507b Endzeit: 16 Anwendungspfad: C:\Users\Eugenia\Desktop\OTL.exe Berichts-ID:
Error - 16.10.2011 15:03:26 | Computer Name = Eugenia-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: f14 Startzeit:
01cc8c33f4b83442 Endzeit: 31 Anwendungspfad: C:\Users\Eugenia\Desktop\OTL.exe Berichts-ID:
Error - 16.10.2011 15:21:53 | Computer Name = Eugenia-PC | Source = Application Hang | ID = 1002
Description = Programm ICQ.exe, Version 7.2.0.3525 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c1c Startzeit:
01cc8c38b6aa07c1 Endzeit: 0 Anwendungspfad: C:\Program Files\ICQ7.2\ICQ.exe Berichts-ID:
Error - 16.10.2011 15:28:52 | Computer Name = Eugenia-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: q6kd39nk.exe, Version: 1.0.15.15641,
Zeitstempel: 0x4e21f2b1 Name des fehlerhaften Moduls: q6kd39nk.exe, Version: 1.0.15.15641,
Zeitstempel: 0x4e21f2b1 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000c676 ID des fehlerhaften
Prozesses: 0xa28 Startzeit der fehlerhaften Anwendung: 0x01cc8c398be925a6 Pfad der
fehlerhaften Anwendung: C:\Users\Eugenia\Desktop\q6kd39nk.exe Pfad des fehlerhaften
Moduls: C:\Users\Eugenia\Desktop\q6kd39nk.exe Berichtskennung: 140a4519-f82d-11e0-bf94-001f1693f381
Error - 17.10.2011 04:59:24 | Computer Name = Eugenia-PC | Source = Application Hang | ID = 1002
Description = Programm ICQ.exe, Version 7.2.0.3525 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: d68 Startzeit:
01cc8ca54457cad8 Endzeit: 4 Anwendungspfad: C:\Program Files\ICQ7.2\ICQ.exe Berichts-ID:
Error - 17.10.2011 05:19:00 | Computer Name = Eugenia-PC | Source = Application Hang | ID = 1002
Description = Programm ICQ.exe, Version 7.2.0.3525 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c94 Startzeit:
01cc8cabbb6dfb19 Endzeit: 0 Anwendungspfad: C:\Program Files\ICQ7.2\ICQ.exe Berichts-ID:
Error - 17.10.2011 06:07:58 | Computer Name = Eugenia-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: q6kd39nk.exe, Version: 1.0.15.15641,
Zeitstempel: 0x4e21f2b1 Name des fehlerhaften Moduls: q6kd39nk.exe, Version: 1.0.15.15641,
Zeitstempel: 0x4e21f2b1 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000c676 ID des fehlerhaften
Prozesses: 0x7b8 Startzeit der fehlerhaften Anwendung: 0x01cc8cb47a6e7f00 Pfad der
fehlerhaften Anwendung: C:\Users\Eugenia\Desktop\q6kd39nk.exe Pfad des fehlerhaften
Moduls: C:\Users\Eugenia\Desktop\q6kd39nk.exe Berichtskennung: e306d9d1-f8a7-11e0-b3d5-001f1693f381
[ Media Center Events ]
Error - 03.02.2011 16:40:03 | Computer Name = Eugenia-PC | Source = MCUpdate | ID = 0
Description = 21:40:03 - Directory konnte nicht abgerufen werden (Fehler: Die zugrunde
liegende Verbindung wurde geschlossen: Für den geschützten SSL/TLS-Kanal konnte
keine Vertrauensstellung hergestellt werden..)
Error - 12.03.2011 12:45:21 | Computer Name = Eugenia-PC | Source = MCUpdate | ID = 0
Description = 17:45:21 - Directory konnte nicht abgerufen werden (Fehler: Die zugrunde
liegende Verbindung wurde geschlossen: Für den geschützten SSL/TLS-Kanal konnte
keine Vertrauensstellung hergestellt werden..)
Error - 12.03.2011 12:45:23 | Computer Name = Eugenia-PC | Source = MCUpdate | ID = 0
Description = 17:45:22 - MCEClientUX konnte nicht abgerufen werden (Fehler: Die
zugrunde liegende Verbindung wurde geschlossen: Für den geschützten SSL/TLS-Kanal
konnte keine Vertrauensstellung hergestellt werden..)
Error - 12.03.2011 12:45:25 | Computer Name = Eugenia-PC | Source = MCUpdate | ID = 0
Description = 17:45:23 - Broadband konnte nicht abgerufen werden (Fehler: Die zugrunde
liegende Verbindung wurde geschlossen: Für den geschützten SSL/TLS-Kanal konnte
keine Vertrauensstellung hergestellt werden..)
[ System Events ]
Error - 17.10.2011 06:36:46 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 06:36:46 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 06:48:21 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 06:48:21 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 07:17:04 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 07:17:06 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 07:17:22 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 07:17:24 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 07:22:02 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
Error - 17.10.2011 07:27:03 | Computer Name = Eugenia-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
< End of report > --- --- ---
Heute ist mir außerdem aufgefallen, dass bei meinen Dokumenten einige Ordner sich verdoppelt, sowie sich zu Verknüpfungen umgewandelt haben oder verschlüsselt sind. (siehe Bild im Anhang)
Bei meinem USB-Stick war das auch der Fall, so dass ich auf einige Dateien einfach nicht mehr zugreifen konnte. Ich habe den USB-Stick formatiert, kann ich ihn weiter benutzen oder sollte ich weitere Maßnahmen ergreifen/ihn einfach nicht mehr verwenden?
Fragen über Fragen, sorry.
Danke schon mal für die Hilfe und Unterstützung! ;)
Grüße |