![]() |
AVG hat Trojaner Generic31.BNQF gefunden Hallo! Ich benötige Hilfe. AVG hat mitgeteilt, dass es den Trojaner Generic31.BNQF gefunden hat und in Quarantäne gestellt hat. (allerdings schon im Februar, ich dachte bisher so etwas wird "automatisch" angezeigt. Da hab ich wohl die Einstellungen schlecht gewählt.) Einen anderen Trojaner hat er auch gefunden, aber schon im September 2012! Da muss ich anschließend ein neues Thema melden, oder? Als Pfad zu dieser Datei wurde C:\Windows\Installer\a31.c0.msi angegeben. Ergebnis von OTL.txt: OTL logfile created on: 14.03.2013 09:19:37 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Sandra\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19400) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,96 Gb Total Physical Memory | 1,34 Gb Available Physical Memory | 45,04% Memory free 6,13 Gb Paging File | 4,43 Gb Available in Paging File | 72,27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 433,53 Gb Total Space | 305,64 Gb Free Space | 70,50% Space Free | Partition Type: NTFS Drive D: | 32,22 Gb Total Space | 17,55 Gb Free Space | 54,49% Space Free | Partition Type: FAT32 Computer Name: SANDRA-PC | User Name: Sandra | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - File not found -- C:\Programme\iTunesHelper.exe PRC - [2013.03.14 09:11:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Sandra\Desktop\OTL.exe PRC - [2013.02.13 17:06:34 | 001,124,016 | ---- | M] () -- C:\Programme\AVG Secure Search\vprot.exe PRC - [2013.02.13 17:06:34 | 000,965,296 | ---- | M] () -- C:\Programme\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe PRC - [2012.11.07 19:54:24 | 002,447,440 | ---- | M] (Check Point Software Technologies LTD) -- C:\Programme\CheckPoint\ZoneAlarm\vsmon.exe PRC - [2012.11.07 19:23:46 | 000,073,392 | ---- | M] (Check Point Software Technologies LTD) -- C:\Programme\CheckPoint\ZoneAlarm\zatray.exe PRC - [2012.11.02 19:17:02 | 000,497,320 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe PRC - [2012.11.02 19:16:26 | 000,738,984 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ForceField.exe PRC - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.10.13 16:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft\BingBar\SeaPort.EXE PRC - [2009.12.30 18:52:39 | 000,761,600 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgscanx.exe PRC - [2009.09.05 13:03:37 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgemc.exe PRC - [2009.09.05 13:03:37 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgcsrvx.exe PRC - [2009.09.05 13:03:37 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgnsx.exe PRC - [2009.09.05 13:03:37 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgrsx.exe PRC - [2009.09.05 13:03:36 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgwdsvc.exe PRC - [2009.08.05 15:08:40 | 000,413,696 | ---- | M] (Wistron Corp.) -- C:\Programme\Launch Manager\WButton.exe PRC - [2009.07.29 01:35:56 | 000,450,660 | ---- | M] (IDT, Inc.) -- C:\Programme\IDT\WDM\sttray.exe PRC - [2009.07.29 01:35:56 | 000,217,178 | ---- | M] (IDT, Inc.) -- c:\Programme\IDT\WDM\stacsv.exe PRC - [2009.07.07 09:44:44 | 000,343,552 | ---- | M] (Wistron Corp.) -- C:\Programme\Launch Manager\OSD.exe PRC - [2009.06.19 13:25:02 | 000,765,952 | ---- | M] (Sentelic Corporation) -- C:\Programme\FSP\FspUip.exe PRC - [2009.05.13 16:05:08 | 002,033,544 | ---- | M] (zoneLINK) -- C:\Programme\zoneLINK\SystemUp 2009\Tuning\DefragService.exe PRC - [2009.04.20 09:27:52 | 001,105,288 | ---- | M] (zoneLINK) -- C:\Programme\zoneLINK\SystemUp 2009\Tuning\SUThemeService.exe PRC - [2009.04.10 22:28:04 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.10 22:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.04.10 22:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2009.04.10 15:46:26 | 000,191,488 | ---- | M] (Wistron) -- C:\Programme\Launch Manager\HotkeyApp.exe PRC - [2009.03.05 17:54:50 | 000,311,296 | ---- | M] () -- C:\Windows\System32\Rezip.exe PRC - [2009.03.04 08:27:42 | 000,113,152 | ---- | M] (Wistron Corp.) -- C:\Programme\Launch Manager\WisLMSvc.exe PRC - [2009.02.11 16:38:40 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe PRC - [2009.02.11 16:38:38 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe PRC - [2008.08.28 14:03:22 | 000,233,472 | ---- | M] () -- C:\Windows\tsnp2uvc.exe PRC - [2008.01.21 03:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2008.01.21 03:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe PRC - [2008.01.21 03:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe PRC - [2007.07.24 10:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Programme\Common Files\Protexis\License Service\PsiService_2.exe PRC - [2007.06.05 12:20:32 | 000,177,704 | ---- | M] () -- C:\Windows\System32\PSIService.exe PRC - [2005.09.30 18:22:50 | 000,096,341 | ---- | M] (Canon Inc.) -- C:\Programme\Canon\CAL\CALMAIN.exe PRC - [2001.11.12 13:31:48 | 000,020,480 | ---- | M] (X10) -- C:\Programme\Common Files\X10\Common\X10nets.exe ========== Modules (No Company Name) ========== MOD - [2013.02.13 17:06:34 | 001,124,016 | ---- | M] () -- C:\Programme\AVG Secure Search\vprot.exe MOD - [2013.02.13 17:06:34 | 000,156,848 | ---- | M] () -- C:\Programme\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\SiteSafety.dll MOD - [2009.11.03 15:51:42 | 000,067,872 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2009.11.03 15:51:26 | 000,039,712 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\ASL.dll MOD - [2009.06.18 15:03:34 | 000,053,248 | ---- | M] () -- C:\Programme\FSP\KbdHook.dll MOD - [2009.06.17 16:17:58 | 000,073,728 | ---- | M] () -- C:\Programme\FSP\FspLib.dll MOD - [2008.08.28 14:03:22 | 000,233,472 | ---- | M] () -- C:\Windows\tsnp2uvc.exe Ergebnis von EXTRAS.txt: OTL Extras logfile created on: 14.03.2013 09:19:37 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Sandra\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19400) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,96 Gb Total Physical Memory | 1,34 Gb Available Physical Memory | 45,04% Memory free 6,13 Gb Paging File | 4,43 Gb Available in Paging File | 72,27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 433,53 Gb Total Space | 305,64 Gb Free Space | 70,50% Space Free | Partition Type: NTFS Drive D: | 32,22 Gb Total Space | 17,55 Gb Free Space | 54,49% Space Free | Partition Type: FAT32 Computer Name: SANDRA-PC | User Name: Sandra | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{49697FEC-F53E-4EF1-8DCE-0CC5C732A483}" = lport=2869 | protocol=6 | dir=in | app=system | "{AC55D56C-20F0-4339-A4D6-ADE38D85B02A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3310A557-B625-4445-9057-A1DC37AB12C4}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe | "{419117F4-4C8F-4C81-BB66-BDFC3837606F}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe | "{431F049E-0518-46CB-BB4E-904BFDC37CFB}" = protocol=17 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe | "{4B4BED74-F82D-4D0E-A2E7-2FE2B2B2C083}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{4CCD03F0-3C71-4F29-A0F6-CFD7686D11BA}" = dir=in | app=c:\program files\homecinema\powerdirector\pdr.exe | "{4D563289-8C60-4871-BAF7-D8224274C3AE}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{716C32B2-CA3C-4722-86D3-16ED0557B406}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{746C0871-3E09-4FA6-A2B8-226EB0DB4EB2}" = protocol=17 | dir=in | app=c:\program files\itunes.exe | "{824F3129-2A80-4108-9E29-8628EBE8EF85}" = dir=in | app=c:\program files\homecinema\powerdvd8\powerdvd8.exe | "{90AAD55D-756E-4E48-9799-8A65D408A79E}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{90D25502-E496-41E3-B9A5-4A65C44192D7}" = protocol=6 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe | "{A3F28184-F908-4689-B125-E14DC46D26C6}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe | "{C4161DBD-2732-48E8-8FB9-5F2908A141D6}" = protocol=6 | dir=in | app=c:\program files\itunes.exe | "{D5C885D9-06CE-473B-9335-39A984CC9B9D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{D8A36AD1-6432-4B1E-957B-0C867AAF0A7F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{D9593906-B635-4357-8F4A-7907E19AAB72}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "TCP Query User{8F103E60-71BF-4E5A-8C4B-CFE396C49B95}C:\windows\ehome\ehexthost.exe" = protocol=6 | dir=in | app=c:\windows\ehome\ehexthost.exe | "UDP Query User{E83184A4-E904-42F5-B6D5-25B3A9FCC720}C:\windows\ehome\ehexthost.exe" = protocol=17 | dir=in | app=c:\windows\ehome\ehexthost.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Home Office "_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 "_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension "_{E1A63F75-1F72-4450-980D-434496FFC646}" = Corel Painter Essentials 4 "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT "{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE "{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime "{192A107E-C6B9-41B9-BDBF-38E3AA226054}" = OpenOffice.org 3.2 "{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver "{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 33 "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN "{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT "{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Home Office "{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = USB Video Device "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works "{39FE455F-9478-451B-9420-73C15143DF8E}" = Corel Home Office - IPM "{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support "{4737AD9F-13AA-4E4C-B86F-B631D557F6A7}" = e-Wörterbücher "{47948554-90C6-4AAC-8CFA-D23CE11C1031}" = Nero 8 Essentials "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update "{5017D60D-C0A5-4CC8-8D2F-0BDA1ADF39D0}" = Corel Home Office - Templates1 "{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3 "{5A166C0B-9557-4364-A057-F946D674E6AC}" = Windows Live Mail "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6B96DADA-1A27-4A04-8CB2-CC45168D05FA}" = Windows Live Fotogalerie "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "{81821BF8-DA20-4F8C-AA87-F70A274828D4}" = Windows Live Writer "{835686C5-8650-49EB-8CA0-4528B4035495}" = Windows Live Call "{837B6259-6FF5-4E66-87C1-A5A15ED36FF4}" = Windows Live Messenger "{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8C1E2925-14F8-45AA-B999-1E2A74BF5607}" = Windows Live Sync "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes "{9D3D8C60-A55F-4fed-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support "{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch "{AD32654E-90CF-42F2-8CB3-88DA6F1AA11A}" = ZoneAlarm Security "{AE9F7747-0350-4E02-B115-6A2C92F5FA54}" = Corel Home Office "{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw "{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR "{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}" = Microsoft SQL Server 2005 Compact Edition [DEU] "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA "{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension "{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager V1.5.0.4 "{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "{DF5F687F-8018-4542-9F98-7084E9022917}" = Windows Live Essentials "{E1A63F75-1F72-4450-980D-434496FFC646}" = Corel Painter Essentials 4 "{E25ED28D-3F3F-4707-8DFA-66CA75FB9329}" = ZoneAlarm Firewall "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E74EA3B1-7192-489D-9A57-0AE918FEC001}" = Corel Home Office - Launcher "{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}" = Finger-sensing Pad Driver "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters "{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform "Abrosoft FantaMorph_is1" = Abrosoft FantaMorph 2.55 "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11 "AVG Secure Search" = AVG Security Toolbar "AVG8Uninstall" = AVG Free 8.5 "Badaboom" = Badaboom 1.2.1.40 "CAL" = Canon Camera Access Library "CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX "CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX "CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX "CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX "Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX "CSCLIB" = Canon Camera Support Core Library "DPP" = Canon Utilities Digital Photo Professional 2.2 "EOS Utility" = Canon Utilities EOS Utility "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox 15.0 (x86 de)" = Mozilla Firefox 15.0 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIA Drivers" = NVIDIA Drivers "PhotoStitch" = Canon Utilities PhotoStitch "RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX "RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX "WinLiveSuite_Wave3" = Windows Live Essentials "X10Hardware" = X10 Hardware(TM) "ZoneAlarm Free Firewall" = ZoneAlarm Free Firewall "ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar "ZoneAlarm Security Toolbar" = ZoneAlarm Security Toolbar "zonelink_TUNING_is1" = zoneLINK SystemUp 2009 Tuning "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Mozilla Firefox 16.0.1 (x86 de)" = Mozilla Firefox 16.0.1 (x86 de) ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 20.09.2012 00:57:50 | Computer Name = Sandra-PC | Source = Windows Search Service | ID = 3013 Description = Error - 20.09.2012 00:57:50 | Computer Name = Sandra-PC | Source = Windows Search Service | ID = 3013 Description = Error - 20.09.2012 00:57:50 | Computer Name = Sandra-PC | Source = Windows Search Service | ID = 3013 Description = Error - 20.09.2012 00:57:50 | Computer Name = Sandra-PC | Source = Windows Search Service | ID = 3013 Description = Error - 20.09.2012 00:57:50 | Computer Name = Sandra-PC | Source = Windows Search Service | ID = 3013 Description = Error - 20.09.2012 00:57:50 | Computer Name = Sandra-PC | Source = Windows Search Service | ID = 3013 Description = Error - 20.09.2012 00:58:09 | Computer Name = Sandra-PC | Source = Windows Search Service | ID = 3013 Description = Error - 22.09.2012 01:25:11 | Computer Name = Sandra-PC | Source = WinMgmt | ID = 10 Description = Error - 23.09.2012 02:50:55 | Computer Name = Sandra-PC | Source = WinMgmt | ID = 10 Description = Error - 23.09.2012 13:49:05 | Computer Name = Sandra-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 05.03.2013 13:38:06 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7000 Description = Error - 05.03.2013 13:38:06 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7011 Description = Error - 06.03.2013 16:03:40 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7000 Description = Error - 06.03.2013 16:03:40 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7011 Description = Error - 07.03.2013 13:55:13 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7000 Description = Error - 07.03.2013 14:56:57 | Computer Name = Sandra-PC | Source = iaStor | ID = 262153 Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error - 08.03.2013 01:54:05 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7000 Description = Error - 08.03.2013 01:54:05 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7011 Description = Error - 10.03.2013 04:04:42 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7000 Description = Error - 14.03.2013 03:43:10 | Computer Name = Sandra-PC | Source = Service Control Manager | ID = 7000 Description = < End of report > Ergebnis von Gmer.txt: GMER 2.1.19155 - hxxp://www.gmer.net Rootkit scan 2013-03-14 10:42:48 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0003 465,76GB Running: gmer_2.1.19155.exe; Driver: C:\Users\Sandra\AppData\Local\Temp\uwdiqpob.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwAlpcConnectPort [0x918D3E90] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwAlpcCreatePort [0x918D4758] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwConnectPort [0x918D38E6] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreateFile [0x918CD190] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreateKey [0x918EED40] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreatePort [0x918D43F0] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreateProcess [0x918E8B74] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreateProcessEx [0x918E8F9C] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreateSection [0x918F3542] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreateWaitablePort [0x918D454E] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwDeleteFile [0x918CDEC0] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwDeleteKey [0x918F0828] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwDeleteValueKey [0x918F00DE] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwDuplicateObject [0x918E7958] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwLoadDriver [0x918C7C76] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwLoadKey [0x918F12B6] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwLoadKey2 [0x918F14F4] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwLoadKeyEx [0x918F19A6] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwMapViewOfSection [0x918F38FE] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwOpenFile [0x918CDA78] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwOpenProcess [0x918EB082] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwOpenThread [0x918EAC70] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwProtectVirtualMemory [0x918FFC7A] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwRenameKey [0x918F237C] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwReplaceKey [0x918F1C70] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwRequestWaitReplyPort [0x918D348E] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwRestoreKey [0x918F2DDC] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwSecureConnectPort [0x918D3BB2] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwSetInformationFile [0x918CE2CA] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwSetInformationObject [0x918FFB3E] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwSetSecurityObject [0x918F2904] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwSetSystemInformation [0x918C7340] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwSetValueKey [0x918EF802] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwSystemDebugControl [0x918E9C98] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwTerminateProcess [0x918E99C8] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwUnloadDriver [0x918C80C8] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys ZwCreateUserProcess [0x918E9410] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!KeSetEvent + 13D 824F3800 8 Bytes [90, 3E, 8D, 91, 58, 47, 8D, ...] {NOP ; LEA EDX, [ECX-0x6e72b8a8]} .text ntkrnlpa.exe!KeSetEvent + 1C1 824F3884 4 Bytes [E6, 38, 8D, 91] .text ntkrnlpa.exe!KeSetEvent + 1D9 824F389C 4 Bytes [90, D1, 8C, 91] .text ntkrnlpa.exe!KeSetEvent + 1E9 824F38AC 4 Bytes [40, ED, 8E, 91] .text ntkrnlpa.exe!KeSetEvent + 205 824F38C8 12 Bytes [F0, 43, 8D, 91, 74, 8B, 8E, ...] .text ... ---- User code sections - GMER 2.1 ---- .text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[536] USER32.dll!IsWindowUnicode + 37 76E190B5 5 Bytes JMP 20CB9266 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0015affc33fc Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0015affc33fc (not active ControlSet) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler@Heartbeat 0xFD 0x51 0x45 0xFC ... ---- EOF - GMER 2.1 ---- Vielen herzlichen Dank im Voraus! (ich benutze den PC übrigens zum Online-Banking) Sase |
Hallo und :hallo: Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
Note: Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread. Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards. Bitte die drei Tools MBAR / aswMBR / TDSSkiller nun ausführen und die Logs in CODE-Tags posten MBAR (Malwarebytes Anti-Rootkit) Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers aswMBR Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). TDSS-Killer Downloade dir bitte ![]()
|
Hallo Cosinus, vielen Dank, dass du mir hilfst. Hier das Ergebnis von mbar: Malwarebytes Anti-Rootkit BETA 1.01.0.1021 www.malwarebytes.org Database version: v2013.03.16.05 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.19401 Sandra :: SANDRA-PC [administrator] 16.03.2013 09:57:19 mbar-log-2013-03-16 (09-57-19).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 29554 Time elapsed: 35 minute(s), 9 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Hier das von aswMBR: aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software Run date: 2013-03-16 17:12:56 ----------------------------- 17:12:56.307 OS Version: Windows 6.0.6002 Service Pack 2 17:12:56.307 Number of processors: 2 586 0x170A 17:12:56.307 ComputerName: SANDRA-PC UserName: Sandra 17:13:02.411 Initialize success 17:15:57.939 AVAST engine defs: 13031600 17:18:54.234 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 17:18:54.250 Disk 0 Vendor: ST950032 0003 Size: 476940MB BusType: 3 17:18:54.266 Disk 0 MBR read successfully 17:18:54.266 Disk 0 MBR scan 17:18:54.281 Disk 0 Windows VISTA default MBR code 17:18:54.297 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 443938 MB offset 2048 17:18:54.328 Disk 0 Partition 2 00 0C FAT32 LBA MSWIN4.1 33000 MB offset 909187072 17:18:54.344 Disk 0 scanning sectors +976771072 17:18:54.484 Disk 0 scanning C:\Windows\system32\drivers 17:19:12.174 Service scanning 17:19:56.042 Modules scanning 17:20:08.210 Disk 0 trace - called modules: 17:20:08.350 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 17:20:08.943 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86af1ac8] 17:20:08.958 3 CLASSPNP.SYS[8aba08b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x858f6028] 17:20:12.515 AVAST engine scan C:\Windows 17:20:28.146 AVAST engine scan C:\Windows\system32 17:29:41.088 AVAST engine scan C:\Windows\system32\drivers 17:30:26.463 AVAST engine scan C:\Users\Sandra 17:45:32.048 AVAST engine scan C:\ProgramData 17:49:40.182 Scan finished successfully 17:51:07.776 Disk 0 MBR has been saved successfully to "C:\Users\Sandra\Desktop\MBR.dat" 17:51:07.776 The log file has been saved successfully to "C:\Users\Sandra\Desktop\aswMBR.txt" Und hier der TDssKiller-log: 17:55:10.0576 5616 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 17:55:11.0466 5616 ============================================================ 17:55:11.0466 5616 Current date / time: 2013/03/16 17:55:11.0466 17:55:11.0466 5616 SystemInfo: 17:55:11.0466 5616 17:55:11.0466 5616 OS Version: 6.0.6002 ServicePack: 2.0 17:55:11.0466 5616 Product type: Workstation 17:55:11.0466 5616 ComputerName: SANDRA-PC 17:55:11.0470 5616 UserName: Sandra 17:55:11.0470 5616 Windows directory: C:\Windows 17:55:11.0470 5616 System windows directory: C:\Windows 17:55:11.0470 5616 Processor architecture: Intel x86 17:55:11.0470 5616 Number of processors: 2 17:55:11.0470 5616 Page size: 0x1000 17:55:11.0470 5616 Boot type: Normal boot 17:55:11.0470 5616 ============================================================ 17:55:12.0827 5616 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 17:55:12.0847 5616 ============================================================ 17:55:12.0847 5616 \Device\Harddisk0\DR0: 17:55:12.0847 5616 MBR partitions: 17:55:12.0847 5616 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x36311000 17:55:12.0847 5616 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xC, StartLBA 0x36311800, BlocksNum 0x4074000 17:55:12.0847 5616 ============================================================ 17:55:12.0877 5616 C: <-> \Device\Harddisk0\DR0\Partition1 17:55:12.0907 5616 D: <-> \Device\Harddisk0\DR0\Partition2 17:55:12.0907 5616 ============================================================ 17:55:12.0907 5616 Initialize success 17:55:12.0907 5616 ============================================================ 17:55:59.0997 4796 ============================================================ 17:55:59.0997 4796 Scan started 17:55:59.0997 4796 Mode: Manual; SigCheck; TDLFS; 17:55:59.0997 4796 ============================================================ 17:56:01.0157 4796 ================ Scan system memory ======================== 17:56:01.0157 4796 System memory - ok 17:56:01.0157 4796 ================ Scan services ============================= 17:56:01.0437 4796 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys 17:56:01.0637 4796 ACPI - ok 17:56:01.0737 4796 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 17:56:01.0767 4796 AdobeARMservice - ok 17:56:01.0817 4796 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 17:56:01.0887 4796 adp94xx - ok 17:56:01.0927 4796 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys 17:56:01.0987 4796 adpahci - ok 17:56:02.0027 4796 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 17:56:02.0077 4796 adpu160m - ok 17:56:02.0097 4796 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 17:56:02.0147 4796 adpu320 - ok 17:56:02.0187 4796 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 17:56:02.0357 4796 AeLookupSvc - ok 17:56:02.0417 4796 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys 17:56:02.0547 4796 AFD - ok 17:56:02.0607 4796 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys 17:56:02.0627 4796 agp440 - ok 17:56:02.0677 4796 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys 17:56:02.0727 4796 aic78xx - ok 17:56:02.0767 4796 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe 17:56:02.0987 4796 ALG - ok 17:56:03.0037 4796 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys 17:56:03.0077 4796 aliide - ok 17:56:03.0107 4796 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys 17:56:03.0147 4796 amdagp - ok 17:56:03.0157 4796 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys 17:56:03.0197 4796 amdide - ok 17:56:03.0207 4796 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys 17:56:03.0327 4796 AmdK7 - ok 17:56:03.0337 4796 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 17:56:03.0437 4796 AmdK8 - ok 17:56:03.0527 4796 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll 17:56:03.0577 4796 Appinfo - ok 17:56:03.0647 4796 [ 557F35D1CA42AEA14A6690E21887A31F ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 17:56:03.0667 4796 Apple Mobile Device - ok 17:56:03.0727 4796 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys 17:56:03.0767 4796 arc - ok 17:56:03.0817 4796 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys 17:56:03.0857 4796 arcsas - ok 17:56:03.0877 4796 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 17:56:03.0967 4796 AsyncMac - ok 17:56:04.0017 4796 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys 17:56:04.0047 4796 atapi - ok 17:56:04.0137 4796 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 17:56:04.0217 4796 AudioEndpointBuilder - ok 17:56:04.0237 4796 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll 17:56:04.0287 4796 Audiosrv - ok 17:56:04.0417 4796 [ D45B7995761253A92AB071D576114F28 ] AVG Security Toolbar Service C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe 17:56:04.0587 4796 AVG Security Toolbar Service - ok 17:56:04.0647 4796 [ B9AE3C63A53396CD669EF8AE9C9CBD85 ] avg8emc C:\PROGRA~1\AVG\AVG8\avgemc.exe 17:56:04.0777 4796 avg8emc - ok 17:56:04.0847 4796 [ DB338A6BD3976904EB0F8343F51E64EB ] avg8wd C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 17:56:04.0887 4796 avg8wd - ok 17:56:04.0917 4796 [ BC12F2404BB6F2B6B2FF3C4C246CB752 ] AvgLdx86 C:\Windows\System32\Drivers\avgldx86.sys 17:56:05.0047 4796 AvgLdx86 - ok 17:56:05.0087 4796 [ 5903D729D4F0C5BCA74123C96A1B29E0 ] AvgMfx86 C:\Windows\System32\Drivers\avgmfx86.sys 17:56:05.0127 4796 AvgMfx86 - ok 17:56:05.0177 4796 [ 92D8E1E8502E649B60E70074EB29C380 ] AvgTdiX C:\Windows\System32\Drivers\avgtdix.sys 17:56:05.0217 4796 AvgTdiX - ok 17:56:05.0257 4796 [ F3D2D8D48E3B0CA83D70A420240E509B ] avgtp C:\Windows\system32\drivers\avgtpx86.sys 17:56:05.0297 4796 avgtp - ok 17:56:05.0467 4796 [ 01A24B415926BB5F772DBE12459D97DE ] BBSvc C:\Program Files\Microsoft\BingBar\BBSvc.EXE 17:56:05.0567 4796 BBSvc - ok 17:56:05.0647 4796 [ 785DE7ABDA13309D6065305542829E76 ] BBUpdate C:\Program Files\Microsoft\BingBar\SeaPort.EXE 17:56:05.0697 4796 BBUpdate - ok 17:56:05.0757 4796 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys 17:56:05.0847 4796 Beep - ok 17:56:05.0907 4796 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll 17:56:05.0967 4796 BFE - ok 17:56:06.0047 4796 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll 17:56:06.0197 4796 BITS - ok 17:56:06.0227 4796 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 17:56:06.0327 4796 blbdrive - ok 17:56:06.0377 4796 [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 17:56:06.0407 4796 Bonjour Service - ok 17:56:06.0447 4796 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys 17:56:06.0527 4796 bowser - ok 17:56:06.0597 4796 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 17:56:06.0667 4796 BrFiltLo - ok 17:56:06.0677 4796 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 17:56:06.0737 4796 BrFiltUp - ok 17:56:06.0767 4796 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll 17:56:06.0827 4796 Browser - ok 17:56:06.0907 4796 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys 17:56:07.0217 4796 Brserid - ok 17:56:07.0297 4796 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 17:56:07.0417 4796 BrSerWdm - ok 17:56:07.0427 4796 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 17:56:07.0577 4796 BrUsbMdm - ok 17:56:07.0587 4796 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 17:56:07.0707 4796 BrUsbSer - ok 17:56:07.0777 4796 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys 17:56:07.0817 4796 BthEnum - ok 17:56:07.0867 4796 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 17:56:07.0977 4796 BTHMODEM - ok 17:56:08.0047 4796 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 17:56:08.0117 4796 BthPan - ok 17:56:08.0187 4796 [ 5A3ABAA2F8EECE7AEFB942773766E3DB ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys 17:56:08.0337 4796 BTHPORT - ok 17:56:08.0387 4796 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll 17:56:08.0457 4796 BthServ - ok 17:56:08.0497 4796 [ 94E2941280E3756A5E0BCB467865C43A ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys 17:56:08.0567 4796 BTHUSB - ok 17:56:08.0627 4796 [ 5753532C476B83119D85AA43B1B10AB3 ] CCALib8 C:\Program Files\Canon\CAL\CALMAIN.exe 17:56:08.0637 4796 CCALib8 ( UnsignedFile.Multi.Generic ) - warning 17:56:08.0647 4796 CCALib8 - detected UnsignedFile.Multi.Generic (1) 17:56:08.0697 4796 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 17:56:08.0777 4796 cdfs - ok 17:56:08.0827 4796 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 17:56:08.0887 4796 cdrom - ok 17:56:09.0007 4796 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll 17:56:09.0097 4796 CertPropSvc - ok 17:56:09.0157 4796 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys 17:56:09.0317 4796 circlass - ok 17:56:09.0357 4796 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys 17:56:09.0417 4796 CLFS - ok 17:56:09.0487 4796 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 17:56:09.0547 4796 clr_optimization_v2.0.50727_32 - ok 17:56:09.0597 4796 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 17:56:09.0677 4796 CmBatt - ok 17:56:09.0707 4796 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys 17:56:09.0747 4796 cmdide - ok 17:56:09.0777 4796 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 17:56:09.0807 4796 Compbatt - ok 17:56:09.0827 4796 COMSysApp - ok 17:56:09.0837 4796 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 17:56:09.0877 4796 crcdisk - ok 17:56:09.0907 4796 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys 17:56:10.0007 4796 Crusoe - ok 17:56:10.0087 4796 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll 17:56:10.0147 4796 CryptSvc - ok 17:56:10.0227 4796 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll 17:56:10.0307 4796 DcomLaunch - ok 17:56:10.0387 4796 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys 17:56:10.0477 4796 DfsC - ok 17:56:10.0627 4796 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe 17:56:10.0877 4796 DFSR - ok 17:56:10.0977 4796 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll 17:56:11.0087 4796 Dhcp - ok 17:56:11.0147 4796 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys 17:56:11.0197 4796 disk - ok 17:56:11.0257 4796 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll 17:56:11.0367 4796 Dnscache - ok 17:56:11.0427 4796 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll 17:56:11.0507 4796 dot3svc - ok 17:56:11.0547 4796 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll 17:56:11.0617 4796 DPS - ok 17:56:11.0667 4796 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 17:56:11.0737 4796 drmkaud - ok 17:56:11.0787 4796 [ FB85F7F69E9B109820409243F578CC4D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 17:56:11.0937 4796 DXGKrnl - ok 17:56:11.0977 4796 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys 17:56:12.0087 4796 E1G60 - ok 17:56:12.0127 4796 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll 17:56:12.0187 4796 EapHost - ok 17:56:12.0247 4796 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys 17:56:12.0297 4796 Ecache - ok 17:56:12.0377 4796 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 17:56:12.0437 4796 ehRecvr - ok 17:56:12.0487 4796 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe 17:56:12.0547 4796 ehSched - ok 17:56:12.0577 4796 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll 17:56:12.0637 4796 ehstart - ok 17:56:12.0677 4796 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys 17:56:12.0737 4796 elxstor - ok 17:56:12.0797 4796 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll 17:56:12.0907 4796 EMDMgmt - ok 17:56:12.0977 4796 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys 17:56:13.0047 4796 ErrDev - ok 17:56:13.0107 4796 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll 17:56:13.0257 4796 EventSystem - ok 17:56:13.0327 4796 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys 17:56:13.0427 4796 exfat - ok 17:56:13.0497 4796 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys 17:56:13.0607 4796 fastfat - ok 17:56:13.0687 4796 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys 17:56:13.0807 4796 fdc - ok 17:56:13.0847 4796 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll 17:56:13.0897 4796 fdPHost - ok 17:56:13.0917 4796 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll 17:56:14.0047 4796 FDResPub - ok 17:56:14.0147 4796 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 17:56:14.0177 4796 FileInfo - ok 17:56:14.0217 4796 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys 17:56:14.0327 4796 Filetrace - ok 17:56:14.0337 4796 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 17:56:14.0417 4796 flpydisk - ok 17:56:14.0467 4796 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 17:56:14.0557 4796 FltMgr - ok 17:56:14.0637 4796 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 17:56:14.0677 4796 FontCache3.0.0.0 - ok 17:56:14.0727 4796 [ 4875E6384310E3AAFB9847312EDB0CFF ] fspad_wlh32 C:\Windows\system32\DRIVERS\fspad_wlh32.sys 17:56:14.0817 4796 fspad_wlh32 - ok 17:56:14.0857 4796 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 17:56:14.0947 4796 Fs_Rec - ok 17:56:14.0997 4796 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 17:56:15.0037 4796 gagp30kx - ok 17:56:15.0117 4796 [ F2F431D1573EE632975C524418655B84 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 17:56:15.0217 4796 GEARAspiWDM - ok 17:56:15.0257 4796 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll 17:56:15.0377 4796 gpsvc - ok 17:56:15.0467 4796 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 17:56:15.0537 4796 HdAudAddService - ok 17:56:15.0597 4796 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 17:56:15.0727 4796 HDAudBus - ok 17:56:15.0757 4796 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys 17:56:15.0857 4796 HidBth - ok 17:56:15.0887 4796 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys 17:56:16.0047 4796 HidIr - ok 17:56:16.0077 4796 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll 17:56:16.0137 4796 hidserv - ok 17:56:16.0167 4796 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 17:56:16.0227 4796 HidUsb - ok 17:56:16.0257 4796 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll 17:56:16.0337 4796 hkmsvc - ok 17:56:16.0367 4796 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 17:56:16.0417 4796 HpCISSs - ok 17:56:16.0477 4796 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys 17:56:16.0697 4796 HTTP - ok 17:56:16.0787 4796 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys 17:56:16.0837 4796 i2omp - ok 17:56:16.0887 4796 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 17:56:17.0007 4796 i8042prt - ok 17:56:17.0107 4796 [ 52E8A3CC8269ADB27D25182284C5E650 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 17:56:17.0147 4796 IAANTMON - ok 17:56:17.0197 4796 [ 71ECC07BC7C5E24C3DD01D8A29A24054 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 17:56:17.0247 4796 iaStor - ok 17:56:17.0287 4796 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 17:56:17.0347 4796 iaStorV - ok 17:56:17.0427 4796 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 17:56:17.0597 4796 idsvc - ok 17:56:17.0697 4796 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys 17:56:17.0737 4796 iirsp - ok 17:56:17.0777 4796 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll 17:56:17.0907 4796 IKEEXT - ok 17:56:17.0957 4796 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys 17:56:17.0987 4796 intelide - ok 17:56:18.0037 4796 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 17:56:18.0107 4796 intelppm - ok 17:56:18.0137 4796 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 17:56:18.0217 4796 IPBusEnum - ok 17:56:18.0247 4796 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:56:18.0367 4796 IpFilterDriver - ok 17:56:18.0427 4796 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 17:56:18.0547 4796 iphlpsvc - ok 17:56:18.0557 4796 IpInIp - ok 17:56:18.0617 4796 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 17:56:18.0717 4796 IPMIDRV - ok 17:56:18.0727 4796 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 17:56:18.0797 4796 IPNAT - ok 17:56:18.0877 4796 [ E8E568EA584973DFD99AAC7D00A16287 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 17:56:18.0937 4796 iPod Service - ok 17:56:18.0957 4796 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 17:56:19.0027 4796 IRENUM - ok 17:56:19.0067 4796 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys 17:56:19.0107 4796 isapnp - ok 17:56:19.0157 4796 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 17:56:19.0227 4796 iScsiPrt - ok 17:56:19.0337 4796 [ 33112D12B95BD1DE18AF409D865DF10C ] ISWKL C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys 17:56:19.0377 4796 ISWKL - ok 17:56:19.0437 4796 [ CFF1CD2C1CC8F5271967AA268982E878 ] IswSvc C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe 17:56:19.0477 4796 IswSvc - ok 17:56:19.0537 4796 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 17:56:19.0577 4796 iteatapi - ok 17:56:19.0607 4796 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys 17:56:19.0637 4796 iteraid - ok 17:56:19.0677 4796 [ 9EFE54794B3A94E93DA50703692E011E ] JMCR C:\Windows\system32\DRIVERS\jmcr.sys 17:56:19.0777 4796 JMCR - ok 17:56:19.0797 4796 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 17:56:19.0847 4796 kbdclass - ok 17:56:19.0877 4796 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 17:56:19.0937 4796 kbdhid - ok 17:56:19.0987 4796 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe 17:56:20.0047 4796 KeyIso - ok 17:56:20.0097 4796 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 17:56:20.0242 4796 KSecDD - ok 17:56:20.0292 4796 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll 17:56:20.0377 4796 KtmRm - ok 17:56:20.0437 4796 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll 17:56:20.0517 4796 LanmanServer - ok 17:56:20.0552 4796 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 17:56:20.0632 4796 LanmanWorkstation - ok 17:56:20.0697 4796 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 17:56:20.0782 4796 lltdio - ok 17:56:20.0842 4796 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll 17:56:20.0957 4796 lltdsvc - ok 17:56:20.0987 4796 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll 17:56:21.0107 4796 lmhosts - ok 17:56:21.0197 4796 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 17:56:21.0272 4796 LSI_FC - ok 17:56:21.0287 4796 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 17:56:21.0332 4796 LSI_SAS - ok 17:56:21.0347 4796 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 17:56:21.0377 4796 LSI_SCSI - ok 17:56:21.0402 4796 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys 17:56:21.0477 4796 luafv - ok 17:56:21.0532 4796 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 17:56:21.0612 4796 Mcx2Svc - ok 17:56:21.0667 4796 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys 17:56:21.0722 4796 megasas - ok 17:56:21.0787 4796 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys 17:56:21.0837 4796 MegaSR - ok 17:56:21.0912 4796 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll 17:56:21.0987 4796 MMCSS - ok 17:56:22.0032 4796 [ 47DA077CB3735AE65D83BF2AD22E5C01 ] mod7700 C:\Windows\system32\DRIVERS\mod7700.sys 17:56:22.0187 4796 mod7700 - ok 17:56:22.0222 4796 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys 17:56:22.0302 4796 Modem - ok 17:56:22.0337 4796 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 17:56:22.0432 4796 monitor - ok 17:56:22.0477 4796 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 17:56:22.0537 4796 mouclass - ok 17:56:22.0587 4796 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 17:56:22.0667 4796 mouhid - ok 17:56:22.0707 4796 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 17:56:22.0742 4796 MountMgr - ok 17:56:22.0837 4796 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 17:56:22.0867 4796 MozillaMaintenance - ok 17:56:22.0967 4796 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys 17:56:23.0007 4796 mpio - ok 17:56:23.0027 4796 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 17:56:23.0087 4796 mpsdrv - ok 17:56:23.0157 4796 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll 17:56:23.0312 4796 MpsSvc - ok 17:56:23.0342 4796 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 17:56:23.0437 4796 Mraid35x - ok 17:56:23.0477 4796 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 17:56:23.0552 4796 MRxDAV - ok 17:56:23.0587 4796 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 17:56:23.0667 4796 mrxsmb - ok 17:56:23.0727 4796 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:56:23.0797 4796 mrxsmb10 - ok 17:56:23.0847 4796 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:56:23.0942 4796 mrxsmb20 - ok 17:56:24.0002 4796 [ F70590424EEFBF5C27A40C67AFDB8383 ] msahci C:\Windows\system32\drivers\msahci.sys 17:56:24.0042 4796 msahci - ok 17:56:24.0127 4796 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys 17:56:24.0197 4796 msdsm - ok 17:56:24.0237 4796 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe 17:56:24.0352 4796 MSDTC - ok 17:56:24.0387 4796 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys 17:56:24.0467 4796 Msfs - ok 17:56:24.0527 4796 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 17:56:24.0557 4796 msisadrv - ok 17:56:24.0592 4796 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 17:56:24.0697 4796 MSiSCSI - ok 17:56:24.0712 4796 msiserver - ok 17:56:24.0752 4796 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 17:56:24.0872 4796 MSKSSRV - ok 17:56:24.0882 4796 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 17:56:24.0957 4796 MSPCLOCK - ok 17:56:24.0977 4796 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 17:56:25.0072 4796 MSPQM - ok 17:56:25.0117 4796 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 17:56:25.0187 4796 MsRPC - ok 17:56:25.0207 4796 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 17:56:25.0232 4796 mssmbios - ok 17:56:25.0272 4796 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 17:56:25.0382 4796 MSTEE - ok 17:56:25.0437 4796 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys 17:56:25.0507 4796 Mup - ok 17:56:25.0557 4796 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll 17:56:25.0632 4796 napagent - ok 17:56:25.0712 4796 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 17:56:25.0847 4796 NativeWifiP - ok 17:56:25.0912 4796 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys 17:56:25.0997 4796 NDIS - ok 17:56:26.0047 4796 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 17:56:26.0112 4796 NdisTapi - ok 17:56:26.0167 4796 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 17:56:26.0247 4796 Ndisuio - ok 17:56:26.0292 4796 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 17:56:26.0377 4796 NdisWan - ok 17:56:26.0397 4796 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 17:56:26.0452 4796 NDProxy - ok 17:56:26.0612 4796 [ 40D7D0A208EE863BCA8D89E299216F15 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 17:56:26.0682 4796 Nero BackItUp Scheduler 3 - ok 17:56:26.0727 4796 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 17:56:26.0837 4796 NetBIOS - ok 17:56:26.0882 4796 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys 17:56:26.0957 4796 netbt - ok 17:56:27.0002 4796 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe 17:56:27.0037 4796 Netlogon - ok 17:56:27.0097 4796 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll 17:56:27.0187 4796 Netman - ok 17:56:27.0257 4796 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll 17:56:27.0362 4796 netprofm - ok 17:56:27.0407 4796 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 17:56:27.0467 4796 NetTcpPortSharing - ok 17:56:27.0512 4796 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 17:56:27.0547 4796 nfrd960 - ok 17:56:27.0597 4796 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll 17:56:27.0662 4796 NlaSvc - ok 17:56:27.0737 4796 [ EBA1B4BF2E2375ABDADEDB649F283541 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 17:56:28.0472 4796 NMIndexingService - ok 17:56:28.0507 4796 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys 17:56:28.0592 4796 Npfs - ok 17:56:28.0672 4796 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll 17:56:28.0762 4796 nsi - ok 17:56:28.0812 4796 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 17:56:28.0882 4796 nsiproxy - ok 17:56:28.0977 4796 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 17:56:29.0072 4796 Ntfs - ok 17:56:29.0127 4796 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys 17:56:29.0262 4796 ntrigdigi - ok 17:56:29.0312 4796 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys 17:56:29.0392 4796 Null - ok 17:56:29.0447 4796 [ D2F4C4B22969236382CA853B8DAA2D4E ] NVHDA C:\Windows\system32\drivers\nvhda32v.sys 17:56:29.0487 4796 NVHDA - ok 17:56:30.0022 4796 [ 5CE5B23855262ACABAECCE156F48DD88 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 17:56:33.0662 4796 nvlddmkm - ok 17:56:33.0872 4796 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys 17:56:33.0917 4796 nvraid - ok 17:56:33.0977 4796 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys 17:56:34.0017 4796 nvstor - ok 17:56:34.0087 4796 [ 6DF4CC671CD9704840C5522627F3ED43 ] nvsvc C:\Windows\system32\nvvsvc.exe 17:56:34.0122 4796 nvsvc - ok 17:56:34.0167 4796 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 17:56:34.0227 4796 nv_agp - ok 17:56:34.0242 4796 NwlnkFlt - ok 17:56:34.0262 4796 NwlnkFwd - ok 17:56:34.0357 4796 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 17:56:34.0462 4796 odserv - ok 17:56:34.0497 4796 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 17:56:34.0622 4796 ohci1394 - ok 17:56:34.0742 4796 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 17:56:34.0872 4796 ose - ok 17:56:34.0932 4796 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll 17:56:35.0097 4796 p2pimsvc - ok 17:56:35.0117 4796 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll 17:56:35.0162 4796 p2psvc - ok 17:56:35.0197 4796 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys 17:56:35.0337 4796 Parport - ok 17:56:35.0372 4796 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys 17:56:35.0412 4796 partmgr - ok 17:56:35.0437 4796 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys 17:56:35.0612 4796 Parvdm - ok 17:56:35.0642 4796 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll 17:56:35.0742 4796 PcaSvc - ok 17:56:35.0832 4796 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys 17:56:35.0882 4796 pci - ok 17:56:35.0917 4796 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys 17:56:35.0972 4796 pciide - ok 17:56:35.0992 4796 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 17:56:36.0047 4796 pcmcia - ok 17:56:36.0097 4796 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 17:56:36.0267 4796 PEAUTH - ok 17:56:36.0342 4796 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll 17:56:36.0552 4796 pla - ok 17:56:36.0617 4796 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\Windows\system32\IoctlSvc.exe 17:56:36.0637 4796 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - warning 17:56:36.0637 4796 PLFlash DeviceIoControl Service - detected UnsignedFile.Multi.Generic (1) 17:56:36.0672 4796 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll 17:56:36.0757 4796 PlugPlay - ok 17:56:36.0807 4796 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 17:56:36.0897 4796 PNRPAutoReg - ok 17:56:36.0947 4796 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll 17:56:36.0992 4796 PNRPsvc - ok 17:56:37.0042 4796 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 17:56:37.0107 4796 PolicyAgent - ok 17:56:37.0177 4796 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 17:56:37.0257 4796 PptpMiniport - ok 17:56:37.0272 4796 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys 17:56:37.0337 4796 Processor - ok 17:56:37.0352 4796 Profos - ok 17:56:37.0387 4796 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll 17:56:37.0427 4796 ProfSvc - ok 17:56:37.0447 4796 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe 17:56:37.0472 4796 ProtectedStorage - ok 17:56:37.0522 4796 [ F115AF58ABE5605D7D709CBFBD83F418 ] ProtexisLicensing C:\Windows\system32\PSIService.exe 17:56:37.0557 4796 ProtexisLicensing - ok 17:56:37.0592 4796 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys 17:56:37.0677 4796 PSched - ok 17:56:37.0762 4796 [ A6A7AD767BF5141665F5C675F671B3E1 ] PSI_SVC_2 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe 17:56:37.0787 4796 PSI_SVC_2 - ok 17:56:37.0862 4796 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 17:56:37.0952 4796 ql2300 - ok 17:56:37.0992 4796 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 17:56:38.0052 4796 ql40xx - ok 17:56:38.0087 4796 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll 17:56:38.0132 4796 QWAVE - ok 17:56:38.0177 4796 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 17:56:38.0227 4796 QWAVEdrv - ok 17:56:38.0252 4796 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 17:56:38.0337 4796 RasAcd - ok 17:56:38.0387 4796 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll 17:56:38.0472 4796 RasAuto - ok 17:56:38.0497 4796 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 17:56:38.0572 4796 Rasl2tp - ok 17:56:38.0617 4796 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll 17:56:38.0677 4796 RasMan - ok 17:56:38.0722 4796 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 17:56:38.0802 4796 RasPppoe - ok 17:56:38.0827 4796 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 17:56:38.0877 4796 RasSstp - ok 17:56:38.0902 4796 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 17:56:38.0957 4796 rdbss - ok 17:56:38.0982 4796 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 17:56:39.0087 4796 RDPCDD - ok 17:56:39.0127 4796 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 17:56:39.0212 4796 rdpdr - ok 17:56:39.0282 4796 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 17:56:39.0392 4796 RDPENCDD - ok 17:56:39.0447 4796 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 17:56:39.0532 4796 RDPWD - ok 17:56:39.0582 4796 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll 17:56:39.0637 4796 RemoteAccess - ok 17:56:39.0677 4796 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll 17:56:39.0807 4796 RemoteRegistry - ok 17:56:39.0952 4796 [ F85AE59A52885F4B09AADAFB23001A3B ] Rezip C:\Windows\SYSTEM32\Rezip.exe 17:56:39.0992 4796 Rezip ( UnsignedFile.Multi.Generic ) - warning 17:56:39.0992 4796 Rezip - detected UnsignedFile.Multi.Generic (1) 17:56:40.0022 4796 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 17:56:40.0102 4796 RFCOMM - ok 17:56:40.0177 4796 [ 7CCAEBCAB6FC1ED0206C07E083E79207 ] RichVideo C:\Program Files\Cyberlink\Shared files\RichVideo.exe 17:56:40.0212 4796 RichVideo - ok 17:56:40.0242 4796 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe 17:56:40.0307 4796 RpcLocator - ok 17:56:40.0362 4796 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll 17:56:40.0462 4796 RpcSs - ok 17:56:40.0527 4796 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 17:56:40.0587 4796 rspndr - ok 17:56:40.0642 4796 [ 9FF72982F8C3945FB1BC10A6246B9B97 ] rtl8192se C:\Windows\system32\DRIVERS\rtl8192se.sys 17:56:40.0737 4796 rtl8192se - ok 17:56:40.0797 4796 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe 17:56:40.0822 4796 SamSs - ok 17:56:40.0847 4796 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 17:56:40.0912 4796 sbp2port - ok 17:56:40.0962 4796 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll 17:56:41.0027 4796 SCardSvr - ok 17:56:41.0117 4796 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll 17:56:41.0252 4796 Schedule - ok 17:56:41.0267 4796 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll 17:56:41.0317 4796 SCPolicySvc - ok 17:56:41.0347 4796 [ 126EA89BCC413EE45E3004FB0764888F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 17:56:41.0452 4796 sdbus - ok 17:56:41.0472 4796 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll 17:56:41.0597 4796 SDRSVC - ok 17:56:41.0682 4796 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 17:56:41.0827 4796 secdrv - ok 17:56:41.0892 4796 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll 17:56:41.0972 4796 seclogon - ok 17:56:42.0012 4796 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll 17:56:42.0092 4796 SENS - ok 17:56:42.0147 4796 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys 17:56:42.0267 4796 Serenum - ok 17:56:42.0282 4796 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys 17:56:42.0557 4796 Serial - ok 17:56:42.0787 4796 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys 17:56:42.0897 4796 sermouse - ok 17:56:42.0982 4796 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll 17:56:43.0032 4796 SessionEnv - ok 17:56:43.0047 4796 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 17:56:43.0137 4796 sffdisk - ok 17:56:43.0147 4796 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 17:56:43.0227 4796 sffp_mmc - ok 17:56:43.0242 4796 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 17:56:43.0312 4796 sffp_sd - ok 17:56:43.0332 4796 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 17:56:43.0522 4796 sfloppy - ok 17:56:43.0592 4796 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll 17:56:43.0707 4796 SharedAccess - ok 17:56:43.0737 4796 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 17:56:43.0807 4796 ShellHWDetection - ok 17:56:43.0862 4796 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys 17:56:43.0902 4796 sisagp - ok 17:56:43.0952 4796 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 17:56:44.0002 4796 SiSRaid2 - ok 17:56:44.0017 4796 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 17:56:44.0102 4796 SiSRaid4 - ok 17:56:44.0292 4796 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe 17:56:44.0622 4796 slsvc - ok 17:56:44.0682 4796 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll 17:56:44.0767 4796 SLUINotify - ok 17:56:44.0807 4796 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys 17:56:44.0917 4796 Smb - ok 17:56:44.0947 4796 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 17:56:44.0982 4796 SNMPTRAP - ok 17:56:45.0062 4796 [ 82E3315B1B3E76B9A9643F987ED3AE5C ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys 17:56:45.0327 4796 SNP2UVC - ok 17:56:45.0387 4796 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys 17:56:45.0417 4796 spldr - ok 17:56:45.0467 4796 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe 17:56:45.0577 4796 Spooler - ok 17:56:45.0617 4796 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys 17:56:45.0692 4796 srv - ok 17:56:45.0762 4796 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 17:56:45.0842 4796 srv2 - ok 17:56:45.0907 4796 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 17:56:45.0982 4796 srvnet - ok 17:56:46.0087 4796 [ 06A13FCF558BF181C6EF1A3DFD6D3172 ] srvSUThemeService C:\Program Files\zoneLINK\SystemUp 2009\Tuning\SUThemeService.exe 17:56:46.0222 4796 srvSUThemeService - ok 17:56:46.0287 4796 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 17:56:46.0372 4796 SSDPSRV - ok 17:56:46.0452 4796 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll 17:56:46.0547 4796 SstpSvc - ok 17:56:46.0632 4796 [ 2EF99F5129D4A89480DFDF24332A0CA9 ] STacSV c:\program files\idt\wdm\STacSV.exe 17:56:46.0692 4796 STacSV - ok 17:56:46.0737 4796 [ 1475633F01CB13102B55C059287CBAC8 ] STHDA C:\Windows\system32\DRIVERS\stwrt.sys 17:56:46.0862 4796 STHDA - ok 17:56:46.0947 4796 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll 17:56:47.0047 4796 stisvc - ok 17:56:47.0087 4796 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 17:56:47.0152 4796 swenum - ok 17:56:47.0187 4796 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll 17:56:47.0312 4796 swprv - ok 17:56:47.0342 4796 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 17:56:47.0387 4796 Symc8xx - ok 17:56:47.0412 4796 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 17:56:47.0452 4796 Sym_hi - ok 17:56:47.0462 4796 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 17:56:47.0512 4796 Sym_u3 - ok 17:56:47.0557 4796 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll 17:56:47.0672 4796 SysMain - ok 17:56:47.0697 4796 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll 17:56:47.0792 4796 TabletInputService - ok 17:56:47.0812 4796 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll 17:56:47.0877 4796 TapiSrv - ok 17:56:47.0917 4796 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll 17:56:48.0007 4796 TBS - ok 17:56:48.0087 4796 [ 3535CD93F944C00F098E73E12EE7FEB6 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 17:56:48.0507 4796 Tcpip - ok 17:56:48.0637 4796 [ 3535CD93F944C00F098E73E12EE7FEB6 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 17:56:48.0717 4796 Tcpip6 - ok 17:56:48.0782 4796 [ CD21572F83F7EC6E2C20C465967BEDD9 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 17:56:48.0922 4796 tcpipreg - ok 17:56:48.0977 4796 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 17:56:49.0117 4796 TDPIPE - ok 17:56:49.0132 4796 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 17:56:49.0227 4796 TDTCP - ok 17:56:49.0272 4796 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 17:56:49.0447 4796 tdx - ok 17:56:49.0517 4796 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 17:56:49.0582 4796 TermDD - ok 17:56:49.0662 4796 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll 17:56:49.0842 4796 TermService - ok 17:56:49.0892 4796 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll 17:56:50.0067 4796 Themes - ok 17:56:50.0112 4796 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll 17:56:50.0167 4796 THREADORDER - ok 17:56:50.0232 4796 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll 17:56:50.0327 4796 TrkWks - ok 17:56:50.0337 4796 Trufos - ok 17:56:50.0422 4796 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 17:56:50.0502 4796 TrustedInstaller - ok 17:56:50.0557 4796 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 17:56:50.0712 4796 tssecsrv - ok 17:56:50.0777 4796 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 17:56:50.0852 4796 tunmp - ok 17:56:50.0902 4796 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 17:56:50.0947 4796 tunnel - ok 17:56:51.0002 4796 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys 17:56:51.0047 4796 uagp35 - ok 17:56:51.0117 4796 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 17:56:51.0227 4796 udfs - ok 17:56:51.0307 4796 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 17:56:51.0417 4796 UI0Detect - ok 17:56:51.0447 4796 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 17:56:51.0532 4796 uliagpkx - ok 17:56:51.0612 4796 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys 17:56:51.0682 4796 uliahci - ok 17:56:51.0707 4796 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys 17:56:51.0757 4796 UlSata - ok 17:56:51.0762 4796 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 17:56:51.0842 4796 ulsata2 - ok 17:56:51.0877 4796 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 17:56:51.0977 4796 umbus - ok 17:56:52.0032 4796 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll 17:56:52.0157 4796 upnphost - ok 17:56:52.0212 4796 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 17:56:52.0307 4796 usbccgp - ok 17:56:52.0352 4796 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys 17:56:52.0547 4796 usbcir - ok 17:56:52.0622 4796 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 17:56:52.0737 4796 usbehci - ok 17:56:52.0777 4796 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 17:56:52.0902 4796 usbhub - ok 17:56:52.0937 4796 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys 17:56:53.0042 4796 usbohci - ok 17:56:53.0122 4796 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 17:56:53.0212 4796 usbprint - ok 17:56:53.0247 4796 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:56:53.0322 4796 USBSTOR - ok 17:56:53.0347 4796 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 17:56:53.0432 4796 usbuhci - ok 17:56:53.0477 4796 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 17:56:53.0562 4796 usbvideo - ok 17:56:53.0632 4796 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll 17:56:53.0697 4796 UxSms - ok 17:56:53.0762 4796 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe 17:56:53.0907 4796 vds - ok 17:56:53.0942 4796 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 17:56:54.0032 4796 vga - ok 17:56:54.0062 4796 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys 17:56:54.0137 4796 VgaSave - ok 17:56:54.0157 4796 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys 17:56:54.0202 4796 viaagp - ok 17:56:54.0267 4796 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys 17:56:54.0342 4796 ViaC7 - ok 17:56:54.0382 4796 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys 17:56:54.0422 4796 viaide - ok 17:56:54.0447 4796 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys 17:56:54.0502 4796 volmgr - ok 17:56:54.0607 4796 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 17:56:54.0727 4796 volmgrx - ok 17:56:54.0792 4796 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys 17:56:54.0887 4796 volsnap - ok 17:56:54.0952 4796 [ DD476FCEE9A7E3D110F445373CC63B7B ] Vsdatant C:\Windows\system32\DRIVERS\vsdatant.sys 17:56:55.0027 4796 Vsdatant - ok 17:56:55.0047 4796 vsdatant7 - ok 17:56:55.0087 4796 vsmon - ok 17:56:55.0132 4796 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 17:56:55.0192 4796 vsmraid - ok 17:56:55.0262 4796 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe 17:56:55.0457 4796 VSS - ok 17:56:55.0562 4796 [ 87C57CBE385E00726A2113614F6C6BD2 ] vToolbarUpdater14.1.7 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe 17:56:55.0667 4796 vToolbarUpdater14.1.7 - ok 17:56:55.0702 4796 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll 17:56:55.0757 4796 W32Time - ok 17:56:55.0777 4796 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 17:56:55.0882 4796 WacomPen - ok 17:56:55.0927 4796 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 17:56:55.0987 4796 Wanarp - ok 17:56:56.0002 4796 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 17:56:56.0052 4796 Wanarpv6 - ok 17:56:56.0072 4796 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll 17:56:56.0187 4796 wcncsvc - ok 17:56:56.0237 4796 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 17:56:56.0302 4796 WcsPlugInService - ok 17:56:56.0347 4796 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys 17:56:56.0412 4796 Wd - ok 17:56:56.0437 4796 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 17:56:56.0532 4796 Wdf01000 - ok 17:56:56.0557 4796 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll 17:56:56.0622 4796 WdiServiceHost - ok 17:56:56.0637 4796 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll 17:56:56.0697 4796 WdiSystemHost - ok 17:56:56.0747 4796 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll 17:56:56.0807 4796 WebClient - ok 17:56:56.0872 4796 [ 905214925A88311FCE52F66153DE7610 ] Wecsvc C:\Windows\system32\wecsvc.dll 17:56:56.0947 4796 Wecsvc - ok 17:56:56.0967 4796 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll 17:56:57.0027 4796 wercplsupport - ok 17:56:57.0062 4796 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll 17:56:57.0127 4796 WerSvc - ok 17:56:57.0187 4796 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 17:56:57.0222 4796 WinDefend - ok 17:56:57.0227 4796 WinHttpAutoProxySvc - ok 17:56:57.0307 4796 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 17:56:57.0387 4796 Winmgmt - ok 17:56:57.0427 4796 [ 01874D4689C212460FBABF0ECD7CB7F7 ] WinRM C:\Windows\system32\WsmSvc.dll 17:56:57.0607 4796 WinRM - ok 17:56:57.0722 4796 [ 20A97B632A76CC977FCFB98F28CAAAB3 ] WisLMSvc C:\Program Files\Launch Manager\WisLMSvc.exe 17:56:57.0747 4796 WisLMSvc ( UnsignedFile.Multi.Generic ) - warning 17:56:57.0747 4796 WisLMSvc - detected UnsignedFile.Multi.Generic (1) 17:56:57.0787 4796 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll 17:56:57.0917 4796 Wlansvc - ok 17:56:57.0972 4796 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 17:56:58.0052 4796 WmiAcpi - ok 17:56:58.0117 4796 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 17:56:58.0197 4796 wmiApSrv - ok 17:56:58.0307 4796 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 17:56:58.0412 4796 WMPNetworkSvc - ok 17:56:58.0442 4796 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll 17:56:58.0572 4796 WPCSvc - ok 17:56:58.0642 4796 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 17:56:58.0762 4796 WPDBusEnum - ok 17:56:58.0807 4796 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 17:56:58.0897 4796 WpdUsb - ok 17:56:58.0932 4796 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 17:56:59.0052 4796 ws2ifsl - ok 17:56:59.0092 4796 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll 17:56:59.0147 4796 wscsvc - ok 17:56:59.0157 4796 WSearch - ok 17:56:59.0282 4796 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll 17:56:59.0467 4796 wuauserv - ok 17:56:59.0547 4796 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 17:56:59.0622 4796 WUDFRd - ok 17:56:59.0687 4796 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll 17:56:59.0777 4796 wudfsvc - ok 17:56:59.0822 4796 [ AB2D77BF7222B007717ABB61B15F9AE2 ] X10Hid C:\Windows\system32\Drivers\x10hid.sys 17:56:59.0877 4796 X10Hid - ok 17:56:59.0967 4796 [ 5A0C788C5BC5F2C993CB60940ADCF95E ] x10nets C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe 17:56:59.0987 4796 x10nets ( UnsignedFile.Multi.Generic ) - warning 17:56:59.0987 4796 x10nets - detected UnsignedFile.Multi.Generic (1) 17:57:00.0057 4796 [ 0625DB94911790F20A866A564D22612B ] XUIF C:\Windows\system32\Drivers\x10ufx2.sys 17:57:00.0092 4796 XUIF - ok 17:57:00.0147 4796 [ C6CA0CC2F7FCDCFE5B551335BFE6D696 ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys 17:57:00.0252 4796 yukonwlh - ok 17:57:00.0332 4796 [ 82FA1A47C2BB762203BFAFFCFE2ECF47 ] zoneLINKDefrag C:\Program Files\zoneLINK\SystemUp 2009\Tuning\DefragService.exe 17:57:00.0527 4796 zoneLINKDefrag - ok 17:57:00.0552 4796 ================ Scan global =============================== 17:57:00.0612 4796 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll 17:57:00.0662 4796 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 17:57:00.0687 4796 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 17:57:00.0762 4796 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe 17:57:00.0782 4796 [Global] - ok 17:57:00.0792 4796 ================ Scan MBR ================================== 17:57:00.0807 4796 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 17:57:02.0287 4796 \Device\Harddisk0\DR0 - ok 17:57:02.0292 4796 ================ Scan VBR ================================== 17:57:02.0337 4796 [ 75D51756C3E908998B6E5571374286C2 ] \Device\Harddisk0\DR0\Partition1 17:57:02.0342 4796 \Device\Harddisk0\DR0\Partition1 - ok 17:57:02.0387 4796 [ 6E35418AA34E95B942D583A9244F566A ] \Device\Harddisk0\DR0\Partition2 17:57:02.0387 4796 \Device\Harddisk0\DR0\Partition2 - ok 17:57:02.0392 4796 ============================================================ 17:57:02.0392 4796 Scan finished 17:57:02.0392 4796 ============================================================ 17:57:02.0412 3792 Detected object count: 5 17:57:02.0412 3792 Actual detected object count: 5 17:57:30.0667 3792 CCALib8 ( UnsignedFile.Multi.Generic ) - skipped by user 17:57:30.0667 3792 CCALib8 ( UnsignedFile.Multi.Generic ) - User select action: Skip 17:57:30.0672 3792 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - skipped by user 17:57:30.0672 3792 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 17:57:30.0672 3792 Rezip ( UnsignedFile.Multi.Generic ) - skipped by user 17:57:30.0672 3792 Rezip ( UnsignedFile.Multi.Generic ) - User select action: Skip 17:57:30.0672 3792 WisLMSvc ( UnsignedFile.Multi.Generic ) - skipped by user 17:57:30.0677 3792 WisLMSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 17:57:30.0677 3792 x10nets ( UnsignedFile.Multi.Generic ) - skipped by user 17:57:30.0677 3792 x10nets ( UnsignedFile.Multi.Generic ) - User select action: Skip ÄHM, ich kann mit "code-tags" nichts anfangen, hoffe, das passt so? Grüße Sase |
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
ah, OK, danke. Also: das Ergebnis von mbar: Code: Malwarebytes Anti-Rootkit BETA 1.01.0.1021 Hier das von aswMBR: Code: aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software Und hier das TDssKiller-Ergebnis: Code: 17:55:10.0576 5616 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 Sase |
Dann bitte jetzt Combofix ausführen: Scan mit Combofix
|
Hallo Cosinus, hier das log file von Combo fix: Code: ComboFix 13-03-17.01 - Sandra 17.03.2013 17:30:39.1.2 - x86 Sase |
Zitat:
|
hallo cosinus, ich hab die firewallfunktion von zonealarm ausgeschaltet. Aber noch nicht deinstalliert, da von dem Programm auch der "webidentitätsschutz" angeboten wird, der ist noch an. Kann das das windowssicherheitscenter auch oder welches "gute" Programm gibt es dafür? Sase |
So eine Funktion ist völlig überflüssig und du solltest dich daran gewöhnen dass derartigenSoftware dich nicht 100 %ig vor allem beschützen kann, will damit sagen ich sehe da druchaus die Gefahr, dass du meinst du kannst dich zu sehr auf die Software verlassen und du selbst dadruch nachlässig wirst Wie gesagt ich würde ZoneAlarm komplett streichen, nur noch einen reinen Virenscanner rauf mit Windows-Firewall |
Hallo, ok, verstanden. Ähm, trotzdem noch eine Frage, ist der Trojaner nach der Combo fix - Anwendung nun entfernt und mein PC "sauber" oder muss noch etwas gemacht werden? Gruß Sase |
JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Im Anschluss: adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen Downloade Dir bitte ![]()
Danach eine Kontrolle mit OTL bitte:
|
Hallo Cosinus, ich war leider nicht bei der Sache. Ich hatte letzte Woche alles erledigt und geantwortet, aber wohl nur auf die Vorschau geklickt und dann nicht mehr abschließend auf "antworten". ... Ich habe Zonenalarm noch nicht deinstalliert, aber ausgeschaltet. Ich habe aber trotzdem von dem Programm eine Warnung bekommen, dass ein "Hotkey-irgendwas" Zugriff verlangt. Das habe ich bisher aber immer abgelehnt. Soll ich das ggf. zulassen und die drei scans noch mal laufen lassen? (da tauchen errors in den scan-ergebnissen auf, falls es daran liegt). Hier von JRT: Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Hier von adwcleaner: Code: # AdwCleaner v2.115 - Datei am 21/03/2013 um 20:20:31 erstellt Code: OTL logfile created on: 21.03.2013 20:30:53 - Run 2 Code: OTL Extras logfile created on: 21.03.2013 20:30:53 - Run 2 Sase |
ZoneAlarm bitte deinstallieren! Anschließend ein neues OTL-Log machen |
Hallo. Zonenalarm ist deinstalliert. Hier das erst OTL-Ergebnis: Code: OTL logfile created on: 31.03.2013 10:55:57 - Run 3 Code: OTL Extras logfile created on: 31.03.2013 10:55:57 - Run 3 Sase |
Alle Zeitangaben in WEZ +1. Es ist jetzt 00:18 Uhr. |
Copyright ©2000-2025, Trojaner-Board