![]() |
Problem mit ESET Online scanner bei Fund einer Variante von Win32 SpyZBot ZR Trojaner Hallo liebe Forumsgemeinde, erstmal möcht ich mich vorstellen , ich bin Simon bin das erste mal hier Und vorerstmal hoffe ich, dass dies auch das richtige Unterforum ist, da ich ja sowohl ein Problem mit dem Scanner, als auch mit Befall habe.. Ich habe ein problem mit dem ESET Online Scanner. Mein PC hat im Arbeitsspeicher einen WIn 32 SpyZBot ZR Trojaner gefunden. Nun habe ich den ESET scanner eingesetzt ( in den Feldern ''Automatisches Deinstallieren der Schädlinge'' und ''Archive durchsuchen'' waren bei beiden die Häkchen drin). Jetzt müsste der Bildschirm nach dem Fund, ja theoretisch so aussehn : http://www.trojaner-board.de/attachm...er-nod32-5.png Das Problem ist, dass das unter dem Schriftfeld : '' Wählen sie Deinstallieren , wenn sie alle Dateien von ESET Online Scanner von ihrem Computer entfernen möchten. Wenn sie ESET Online Scanner das nächste mal online ausführen, müssen Sie sie wieder herunterladen '' NICHTS ist... blankes Weiß..nur noch rechts unten '' Fertig stellen'' sodass mir die Reinigung im Prinzip verweigert wird. Ich danke schonmal im Vorraus für die Hilfe Okay ich habe jetzt erstmal folgendes gemacht: Malware Bytes ( nichts gefunden ) Log : Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Datenbank Version: 7988 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 23.10.2011 13:49:31 mbam-log-2011-10-23 (13-49-31).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 293729 Laufzeit: 1 Stunde(n), 7 Minute(n), 25 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) ______________________________________________________________________________________________________________ Antivir: hat 2 Dateien gefunden ( wurden in Quarantäne verschoben) Log : Avira Free Antivirus Erstellungsdatum der Reportdatei: Sonntag, 23. Oktober 2011 13:58 Es wird nach 3421795 Virenstämmen gesucht. Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira AntiVir Personal - Free Antivirus Seriennummer : 0000149996-ADJIE-0000001 Plattform : Windows XP Windowsversion : (Service Pack 3) [5.1.2600] Boot Modus : Normal gebootet Benutzername : SYSTEM Computername : SIMON-14D0750F1 Versionsinformationen: BUILD.DAT : 12.0.0.855 41827 Bytes 12.10.2011 16:36:00 AVSCAN.EXE : 12.1.0.17 490448 Bytes 11.10.2011 12:59:38 AVSCAN.DLL : 12.1.0.17 65744 Bytes 11.10.2011 12:59:58 LUKE.DLL : 12.1.0.17 68304 Bytes 11.10.2011 12:59:47 AVSCPLR.DLL : 12.1.0.19 99536 Bytes 11.10.2011 12:59:38 AVREG.DLL : 12.1.0.20 227024 Bytes 11.10.2011 12:59:38 VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 18:18:34 VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 09:07:39 VBASE002.VDF : 7.11.3.0 1950720 Bytes 09.02.2011 15:08:51 VBASE003.VDF : 7.11.5.225 1980416 Bytes 07.04.2011 10:00:55 VBASE004.VDF : 7.11.8.178 2354176 Bytes 31.05.2011 10:18:22 VBASE005.VDF : 7.11.10.251 1788416 Bytes 07.07.2011 12:12:53 VBASE006.VDF : 7.11.13.60 6411776 Bytes 16.08.2011 07:26:09 VBASE007.VDF : 7.11.15.106 2389504 Bytes 05.10.2011 12:59:54 VBASE008.VDF : 7.11.15.107 2048 Bytes 05.10.2011 12:59:54 VBASE009.VDF : 7.11.15.108 2048 Bytes 05.10.2011 12:59:54 VBASE010.VDF : 7.11.15.109 2048 Bytes 05.10.2011 12:59:54 VBASE011.VDF : 7.11.15.110 2048 Bytes 05.10.2011 12:59:54 VBASE012.VDF : 7.11.15.111 2048 Bytes 05.10.2011 12:59:54 VBASE013.VDF : 7.11.15.144 161792 Bytes 07.10.2011 12:59:54 VBASE014.VDF : 7.11.15.177 130048 Bytes 10.10.2011 12:59:54 VBASE015.VDF : 7.11.15.213 113664 Bytes 11.10.2011 13:35:57 VBASE016.VDF : 7.11.16.1 163328 Bytes 14.10.2011 20:34:20 VBASE017.VDF : 7.11.16.34 187904 Bytes 18.10.2011 21:28:16 VBASE018.VDF : 7.11.16.77 139264 Bytes 20.10.2011 08:52:18 VBASE019.VDF : 7.11.16.78 2048 Bytes 20.10.2011 08:52:18 VBASE020.VDF : 7.11.16.79 2048 Bytes 20.10.2011 08:52:18 VBASE021.VDF : 7.11.16.80 2048 Bytes 20.10.2011 08:52:18 VBASE022.VDF : 7.11.16.81 2048 Bytes 20.10.2011 08:52:18 VBASE023.VDF : 7.11.16.82 2048 Bytes 20.10.2011 08:52:19 VBASE024.VDF : 7.11.16.83 2048 Bytes 20.10.2011 08:52:19 VBASE025.VDF : 7.11.16.84 2048 Bytes 20.10.2011 08:52:19 VBASE026.VDF : 7.11.16.85 2048 Bytes 20.10.2011 08:52:19 VBASE027.VDF : 7.11.16.86 2048 Bytes 20.10.2011 08:52:19 VBASE028.VDF : 7.11.16.87 2048 Bytes 20.10.2011 08:52:19 VBASE029.VDF : 7.11.16.88 2048 Bytes 20.10.2011 08:52:19 VBASE030.VDF : 7.11.16.89 2048 Bytes 20.10.2011 08:52:20 VBASE031.VDF : 7.11.16.106 86016 Bytes 21.10.2011 08:52:01 Engineversion : 8.2.6.84 AEVDF.DLL : 8.1.2.1 106868 Bytes 01.09.2011 21:46:02 AESCRIPT.DLL : 8.1.3.81 467322 Bytes 11.10.2011 12:59:35 AESCN.DLL : 8.1.7.2 127349 Bytes 01.09.2011 21:46:02 AESBX.DLL : 8.2.1.34 323957 Bytes 01.09.2011 21:46:02 AERDL.DLL : 8.1.9.15 639348 Bytes 08.09.2011 21:16:06 AEPACK.DLL : 8.2.10.11 684408 Bytes 22.09.2011 14:18:45 AEOFFICE.DLL : 8.1.2.15 201083 Bytes 15.09.2011 23:17:25 AEHEUR.DLL : 8.1.2.180 3748217 Bytes 12.10.2011 11:41:59 AEHELP.DLL : 8.1.17.7 254327 Bytes 01.09.2011 21:46:01 AEGEN.DLL : 8.1.5.9 401780 Bytes 01.09.2011 21:46:01 AEEMU.DLL : 8.1.3.0 393589 Bytes 01.09.2011 21:46:01 AECORE.DLL : 8.1.23.0 196983 Bytes 01.09.2011 21:46:01 AEBB.DLL : 8.1.1.0 53618 Bytes 01.09.2011 21:46:01 AVWINLL.DLL : 12.1.0.17 27344 Bytes 11.10.2011 12:59:41 AVPREF.DLL : 12.1.0.17 51920 Bytes 11.10.2011 12:59:38 AVREP.DLL : 12.1.0.17 179408 Bytes 11.10.2011 12:59:38 AVARKT.DLL : 12.1.0.17 223184 Bytes 11.10.2011 12:59:36 AVEVTLOG.DLL : 12.1.0.17 169168 Bytes 11.10.2011 12:59:37 SQLITE3.DLL : 3.7.0.0 398288 Bytes 11.10.2011 12:59:51 AVSMTP.DLL : 12.1.0.17 62928 Bytes 11.10.2011 12:59:39 NETNT.DLL : 12.1.0.17 17104 Bytes 11.10.2011 12:59:47 RCIMAGE.DLL : 12.1.0.17 4447952 Bytes 11.10.2011 13:00:00 RCTEXT.DLL : 12.1.0.16 98512 Bytes 11.10.2011 13:00:00 Konfiguration für den aktuellen Suchlauf: Job Name..............................: Vollständige Systemprüfung Konfigurationsdatei...................: c:\programme\avira\antivir desktop\sysscan.avp Protokollierung.......................: standard Primäre Aktion........................: interaktiv Sekundäre Aktion......................: ignorieren Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: ein Bootsektoren..........................: C:, Durchsuche aktive Programme...........: ein Laufende Programme erweitert..........: ein Durchsuche Registrierung..............: ein Suche nach Rootkits...................: ein Integritätsprüfung von Systemdateien..: aus Datei Suchmodus.......................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: erweitert Abweichende Gefahrenkategorien........: +APPL,+JOKE,+PCK,+SPR, Beginn des Suchlaufs: Sonntag, 23. Oktober 2011 13:58 Der Suchlauf über die Masterbootsektoren wird begonnen: Masterbootsektor HD0 [INFO] Es wurde kein Virus gefunden! Der Suchlauf über die Bootsektoren wird begonnen: Bootsektor 'C:\' [INFO] Es wurde kein Virus gefunden! Der Suchlauf nach versteckten Objekten wird begonnen. HKEY_USERS\S-1-5-21-1454471165-2000478354-725345543-1003\Software\SecuROM\License information\datasecu [HINWEIS] Der Registrierungseintrag ist nicht sichtbar. HKEY_USERS\S-1-5-21-1454471165-2000478354-725345543-1003\Software\SecuROM\License information\rkeysecu [HINWEIS] Der Registrierungseintrag ist nicht sichtbar. Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'rsmsink.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'msdtc.exe' - '40' Modul(e) wurden durchsucht Durchsuche Prozess 'dllhost.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'dllhost.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'vssvc.exe' - '48' Modul(e) wurden durchsucht Durchsuche Prozess 'avscan.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'avcenter.exe' - '71' Modul(e) wurden durchsucht Durchsuche Prozess 'alg.exe' - '33' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiapsrv.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'iPodService.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'LVComSer.exe' - '40' Modul(e) wurden durchsucht Durchsuche Prozess 'wscntfy.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'avshadow.exe' - '25' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '42' Modul(e) wurden durchsucht Durchsuche Prozess 'LVPrcSrv.exe' - '17' Modul(e) wurden durchsucht Durchsuche Prozess 'LVComSer.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'jqs.exe' - '85' Modul(e) wurden durchsucht Durchsuche Prozess 'AppleMobileDeviceService.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '63' Modul(e) wurden durchsucht Durchsuche Prozess 'ctfmon.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'iTunesHelper.exe' - '68' Modul(e) wurden durchsucht Durchsuche Prozess 'daemon.exe' - '42' Modul(e) wurden durchsucht Durchsuche Prozess 'hkcmd.exe' - '36' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxtray.exe' - '36' Modul(e) wurden durchsucht Durchsuche Prozess 'Communications_Helper.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'vsnpstd3.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'tsnpstd3.exe' - '31' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '35' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'spoolsv.exe' - '50' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht Durchsuche Prozess 'Explorer.EXE' - '120' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '161' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '51' Modul(e) wurden durchsucht Durchsuche Prozess 'lsass.exe' - '58' Modul(e) wurden durchsucht Durchsuche Prozess 'services.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'winlogon.exe' - '74' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '12' Modul(e) wurden durchsucht Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen: Die Registry wurde durchsucht ( '2750' Dateien ). Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\' C:\System Volume Information\_restore{104CED89-B2A6-4229-BE7C-30F3762A2E14}\RP406\A0099553.exe [FUND] Ist das Trojanische Pferd TR/Crypt.XPACK.Gen5 C:\System Volume Information\_restore{104CED89-B2A6-4229-BE7C-30F3762A2E14}\RP423\A0100941.exe [FUND] Ist das Trojanische Pferd TR/Spy.ZBot.WX Beginne mit der Desinfektion: C:\System Volume Information\_restore{104CED89-B2A6-4229-BE7C-30F3762A2E14}\RP423\A0100941.exe [FUND] Ist das Trojanische Pferd TR/Spy.ZBot.WX [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4c3bbe33.qua' verschoben! C:\System Volume Information\_restore{104CED89-B2A6-4229-BE7C-30F3762A2E14}\RP406\A0099553.exe [FUND] Ist das Trojanische Pferd TR/Crypt.XPACK.Gen5 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '54ad9194.qua' verschoben! Ende des Suchlaufs: Sonntag, 23. Oktober 2011 15:44 Benötigte Zeit: 1:45:40 Stunde(n) Der Suchlauf wurde vollständig durchgeführt. 29979 Verzeichnisse wurden überprüft 409331 Dateien wurden geprüft 2 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 2 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 409329 Dateien ohne Befall 6022 Archive wurden durchsucht 0 Warnungen 4 Hinweise 407833 Objekte wurden beim Rootkitscan durchsucht 2 Versteckte Objekte wurden gefunden ______________________________________________________________________________________________________________ Der Eset Scanner meldet allerdings weiterhin den Befall des Win32 SpyZBot ZR Trojaners. Der Zbot Killer von Kasprsky brachte kein ergebnis : Infected Files : 0 Infected Threads : 0 Unhooked Functions : 164 Deleted Files : 0 Fixed registry Files :0 |
Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind. Zitat:
|
Hi :) komisch, also wenn ich bei google bildersuche eset online scanner eingebe kommt das bild von hier. http://www.trojaner-board.de/80603-e...ner-nod32.html unterstes MWB logs gibt es seit dem problem keine...die, die ich von davor habe sind entweder ebenfalls ohne befund , oder hingen ( falls sie denn was hatten) mit einem ganz anderen problem zusammen..trotzdem posten? und schonmal :dankeschoen: dafür, dass du dich des themas angenommen hast |
Versuch ESET bitte nochmal so: ESET Online Scanner
|
Hier bitte! ;) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=92601776bbb5294bb7852c636cb5c2ab # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-10-22 10:10:00 # local_time=2011-10-23 12:10:00 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777175 100 0 604483 604483 0 0 # compatibility_mode=8192 67108863 100 0 124 124 0 0 # scanned=158426 # found=1 # cleaned=0 # scan_time=6160 ${Memory} a variant of Win32/Spy.Zbot.ZR trojan 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=92601776bbb5294bb7852c636cb5c2ab # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-10-23 12:04:22 # local_time=2011-10-23 02:04:22 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777175 100 0 611008 611008 0 0 # compatibility_mode=8192 67108863 100 0 6649 6649 0 0 # scanned=158432 # found=1 # cleaned=0 # scan_time=6493 ${Memory} Variante von Win32/Spy.Zbot.ZR Trojaner 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=92601776bbb5294bb7852c636cb5c2ab # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-10-23 12:35:57 # local_time=2011-10-23 02:35:57 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777191 100 0 619356 619356 0 0 # compatibility_mode=8192 67108863 100 0 14997 14997 0 0 # scanned=1 # found=1 # cleaned=0 # scan_time=40 ${Memory} Variante von Win32/Spy.Zbot.ZR Trojaner 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=92601776bbb5294bb7852c636cb5c2ab # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-10-23 12:48:09 # local_time=2011-10-23 02:48:09 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777175 100 0 620040 620040 0 0 # compatibility_mode=8192 67108863 100 0 15681 15681 0 0 # scanned=1 # found=1 # cleaned=0 # scan_time=88 ${Memory} Variante von Win32/Spy.Zbot.ZR Trojaner 00000000000000000000000000000000 I # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=92601776bbb5294bb7852c636cb5c2ab # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-10-23 01:51:07 # local_time=2011-10-23 03:51:07 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777191 100 0 667061 667061 0 0 # compatibility_mode=8192 67108863 100 0 62702 62702 0 0 # scanned=1 # found=1 # cleaned=0 # scan_time=45 ${Memory} Variante von Win32/Spy.Zbot.ZR Trojaner 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=92601776bbb5294bb7852c636cb5c2ab # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-10-24 08:00:57 # local_time=2011-10-24 10:00:57 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777175 100 0 775632 775632 0 0 # compatibility_mode=8192 67108863 100 0 171273 171273 0 0 # scanned=1 # found=1 # cleaned=0 # scan_time=65 ${Memory} Variante von Win32/Spy.Zbot.ZR Trojaner 00000000000000000000000000000000 I |
Angeblich ist der im Arbeitsspeicher. CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: netsvcs
|
Hier der Inhalt der OTL.log Textdatei: OTL Logfile: Code: OTL logfile created on: 25.10.2011 11:05:41 - Run 1 |
Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann! |
Hier das Log: All processes killed ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7e111a5c-3d11-4f56-9463-5310c3c69025} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "ICQ Search" removed from browser.search.defaultenginename Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=" removed from browser.search.defaulturl Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q=" removed from keyword.URL Prefs.js: " 84.72.71.238" removed from network.proxy.ftp Prefs.js: 80 removed from network.proxy.ftp_port Prefs.js: " 84.72.71.238" removed from network.proxy.gopher Prefs.js: 80 removed from network.proxy.gopher_port Prefs.js: "184.106.213.192" removed from network.proxy.http Prefs.js: 80 removed from network.proxy.http_port Prefs.js: " 84.72.71.238" removed from network.proxy.socks Prefs.js: 80 removed from network.proxy.socks_port Prefs.js: " 84.72.71.238" removed from network.proxy.ssl Prefs.js: 80 removed from network.proxy.ssl_port C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\search_engine(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\META-INF(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\defaults(2)\preferences(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\defaults(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\components(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\skin(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\tr(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\sk(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\ru(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\it(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\he(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\fr(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\es(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\en-US(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\de(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\cs(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2)\bg(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\locale(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\content(2)\img(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2)\content(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)\chrome(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2) folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}\chrome\mozapps\extensions\in-contentUI folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}\chrome\mozapps\extensions folder moved successfully. Folder C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}\chrome\mozapps\extensions\in-contentUI\ not found. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-1.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-10.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-11.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-12.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-13.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-14.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-15.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-2.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-3.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-4.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-5.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-6.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-7.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-8.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin-9.xml moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Mozilla\Firefox\Profiles\mezz9njm.default\searchplugins\icqplugin.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7e111a5c-3d11-4f56-9463-5310c3c69025} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7e111a5c-3d11-4f56-9463-5310c3c69025} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CameraFixer deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\giva.exe deleted successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Ycigy\giva.exe moved successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\AUTOEXEC.BAT moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Ycigy folder moved successfully. C:\Dokumente und Einstellungen\Simon\Anwendungsdaten\Zenay folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 49554 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 194364 bytes User: Simon ->Temp folder emptied: 1109614999 bytes ->Temporary Internet Files folder emptied: 14635328 bytes ->Java cache emptied: 59692065 bytes ->FireFox cache emptied: 1172803213 bytes ->Flash cache emptied: 190612 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2134333 bytes %systemroot%\System32 .tmp files removed: 2951 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1923205 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 2.252,00 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.31.0 log created on 10252011_134030 Files\Folders moved on Reboot... File move failed. C:\WINDOWS\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot. Registry entries deleted on Reboot... Tante Edith sagt: ESET findet nichts mehr und es wird mir das erste mal nach dem Scan '' Anwendung nach dem Schließen deinstallieren'' angezeigt! :Boogie: |
Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten! http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif |
Hier das Log: 16:32:37.0500 1932 TDSS rootkit removing tool 2.6.13.0 Oct 25 2011 13:56:21 16:32:37.0609 1932 ============================================================ 16:32:37.0609 1932 Current date / time: 2011/10/25 16:32:37.0609 16:32:37.0609 1932 SystemInfo: 16:32:37.0609 1932 16:32:37.0609 1932 OS Version: 5.1.2600 ServicePack: 3.0 16:32:37.0609 1932 Product type: Workstation 16:32:37.0609 1932 ComputerName: SIMON-14D0750F1 16:32:37.0609 1932 UserName: Simon 16:32:37.0609 1932 Windows directory: C:\WINDOWS 16:32:37.0609 1932 System windows directory: C:\WINDOWS 16:32:37.0609 1932 Processor architecture: Intel x86 16:32:37.0609 1932 Number of processors: 1 16:32:37.0609 1932 Page size: 0x1000 16:32:37.0609 1932 Boot type: Normal boot 16:32:37.0609 1932 ============================================================ 16:32:38.0750 1932 Initialize success 16:33:21.0062 1232 ============================================================ 16:33:21.0062 1232 Scan started 16:33:21.0062 1232 Mode: Manual; SigCheck; TDLFS; 16:33:21.0062 1232 ============================================================ 16:33:21.0296 1232 Abiosdsk - ok 16:33:21.0312 1232 abp480n5 - ok 16:33:21.0375 1232 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys 16:33:22.0046 1232 ACPI ( UnsignedFile.Multi.Generic ) - warning 16:33:22.0046 1232 ACPI - detected UnsignedFile.Multi.Generic (1) 16:33:22.0140 1232 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\drivers\ACPIEC.sys 16:33:22.0156 1232 ACPIEC ( UnsignedFile.Multi.Generic ) - warning 16:33:22.0156 1232 ACPIEC - detected UnsignedFile.Multi.Generic (1) 16:33:22.0187 1232 adpu160m - ok 16:33:22.0281 1232 aeaudio (3cb6ae5435987b1f8c83fd2730479878) C:\WINDOWS\system32\drivers\aeaudio.sys 16:33:22.0296 1232 aeaudio ( UnsignedFile.Multi.Generic ) - warning 16:33:22.0296 1232 aeaudio - detected UnsignedFile.Multi.Generic (1) 16:33:22.0328 1232 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 16:33:22.0343 1232 aec ( UnsignedFile.Multi.Generic ) - warning 16:33:22.0343 1232 aec - detected UnsignedFile.Multi.Generic (1) 16:33:22.0437 1232 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 16:33:22.0468 1232 AFD ( UnsignedFile.Multi.Generic ) - warning 16:33:22.0468 1232 AFD - detected UnsignedFile.Multi.Generic (1) 16:33:22.0515 1232 Aha154x - ok 16:33:22.0562 1232 aic78u2 - ok 16:33:22.0609 1232 aic78xx - ok 16:33:22.0656 1232 AliIde - ok 16:33:22.0687 1232 amsint - ok 16:33:22.0718 1232 asc - ok 16:33:22.0734 1232 asc3350p - ok 16:33:22.0750 1232 asc3550 - ok 16:33:22.0796 1232 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16:33:22.0812 1232 AsyncMac ( UnsignedFile.Multi.Generic ) - warning 16:33:22.0812 1232 AsyncMac - detected UnsignedFile.Multi.Generic (1) 16:33:22.0890 1232 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 16:33:22.0906 1232 atapi ( UnsignedFile.Multi.Generic ) - warning 16:33:22.0906 1232 atapi - detected UnsignedFile.Multi.Generic (1) 16:33:22.0968 1232 Atdisk - ok 16:33:23.0031 1232 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 16:33:23.0046 1232 Atmarpc ( UnsignedFile.Multi.Generic ) - warning 16:33:23.0046 1232 Atmarpc - detected UnsignedFile.Multi.Generic (1) 16:33:23.0156 1232 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 16:33:23.0156 1232 audstub ( UnsignedFile.Multi.Generic ) - warning 16:33:23.0156 1232 audstub - detected UnsignedFile.Multi.Generic (1) 16:33:23.0234 1232 avgntflt (7713e4eb0276702faa08e52a6e23f2a6) C:\WINDOWS\system32\DRIVERS\avgntflt.sys 16:33:23.0328 1232 avgntflt - ok 16:33:23.0421 1232 avipbb (912d23140cd05980f6cdae790ddafc8d) C:\WINDOWS\system32\DRIVERS\avipbb.sys 16:33:23.0437 1232 avipbb - ok 16:33:23.0515 1232 avkmgr (271cfd1a989209b1964e24d969552bf7) C:\WINDOWS\system32\DRIVERS\avkmgr.sys 16:33:23.0531 1232 avkmgr - ok 16:33:23.0593 1232 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 16:33:23.0609 1232 Beep ( UnsignedFile.Multi.Generic ) - warning 16:33:23.0609 1232 Beep - detected UnsignedFile.Multi.Generic (1) 16:33:23.0703 1232 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 16:33:23.0734 1232 cbidf2k ( UnsignedFile.Multi.Generic ) - warning 16:33:23.0734 1232 cbidf2k - detected UnsignedFile.Multi.Generic (1) 16:33:23.0812 1232 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 16:33:23.0812 1232 CCDECODE ( UnsignedFile.Multi.Generic ) - warning 16:33:23.0812 1232 CCDECODE - detected UnsignedFile.Multi.Generic (1) 16:33:23.0859 1232 cd20xrnt - ok 16:33:23.0937 1232 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 16:33:23.0953 1232 Cdaudio ( UnsignedFile.Multi.Generic ) - warning 16:33:23.0953 1232 Cdaudio - detected UnsignedFile.Multi.Generic (1) 16:33:24.0046 1232 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 16:33:24.0046 1232 Cdfs ( UnsignedFile.Multi.Generic ) - warning 16:33:24.0046 1232 Cdfs - detected UnsignedFile.Multi.Generic (1) 16:33:24.0140 1232 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 16:33:24.0156 1232 Cdrom ( UnsignedFile.Multi.Generic ) - warning 16:33:24.0156 1232 Cdrom - detected UnsignedFile.Multi.Generic (1) 16:33:24.0187 1232 Changer - ok 16:33:24.0250 1232 CmdIde - ok 16:33:24.0296 1232 Cpqarray - ok 16:33:24.0312 1232 dac2w2k - ok 16:33:24.0328 1232 dac960nt - ok 16:33:24.0390 1232 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 16:33:24.0421 1232 Disk ( UnsignedFile.Multi.Generic ) - warning 16:33:24.0421 1232 Disk - detected UnsignedFile.Multi.Generic (1) 16:33:24.0515 1232 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys 16:33:24.0593 1232 dmboot ( UnsignedFile.Multi.Generic ) - warning 16:33:24.0593 1232 dmboot - detected UnsignedFile.Multi.Generic (1) 16:33:24.0687 1232 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys 16:33:24.0718 1232 dmio ( UnsignedFile.Multi.Generic ) - warning 16:33:24.0718 1232 dmio - detected UnsignedFile.Multi.Generic (1) 16:33:24.0765 1232 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 16:33:24.0781 1232 dmload ( UnsignedFile.Multi.Generic ) - warning 16:33:24.0781 1232 dmload - detected UnsignedFile.Multi.Generic (1) 16:33:24.0875 1232 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 16:33:24.0890 1232 DMusic ( UnsignedFile.Multi.Generic ) - warning 16:33:24.0890 1232 DMusic - detected UnsignedFile.Multi.Generic (1) 16:33:24.0953 1232 dpti2o - ok 16:33:25.0000 1232 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 16:33:25.0015 1232 drmkaud ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0015 1232 drmkaud - detected UnsignedFile.Multi.Generic (1) 16:33:25.0093 1232 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys 16:33:25.0109 1232 E100B ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0109 1232 E100B - detected UnsignedFile.Multi.Generic (1) 16:33:25.0234 1232 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 16:33:25.0250 1232 Fastfat ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0250 1232 Fastfat - detected UnsignedFile.Multi.Generic (1) 16:33:25.0343 1232 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 16:33:25.0359 1232 Fdc ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0359 1232 Fdc - detected UnsignedFile.Multi.Generic (1) 16:33:25.0421 1232 FilterService (c9993169e75e75e8f2f450b172ddf814) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys 16:33:25.0421 1232 FilterService - ok 16:33:25.0500 1232 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys 16:33:25.0515 1232 Fips ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0515 1232 Fips - detected UnsignedFile.Multi.Generic (1) 16:33:25.0546 1232 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 16:33:25.0562 1232 Flpydisk ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0562 1232 Flpydisk - detected UnsignedFile.Multi.Generic (1) 16:33:25.0640 1232 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 16:33:25.0703 1232 FltMgr ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0703 1232 FltMgr - detected UnsignedFile.Multi.Generic (1) 16:33:25.0781 1232 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 16:33:25.0796 1232 Fs_Rec ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0796 1232 Fs_Rec - detected UnsignedFile.Multi.Generic (1) 16:33:25.0906 1232 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 16:33:25.0921 1232 Ftdisk ( UnsignedFile.Multi.Generic ) - warning 16:33:25.0921 1232 Ftdisk - detected UnsignedFile.Multi.Generic (1) 16:33:26.0015 1232 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 16:33:26.0015 1232 GEARAspiWDM - ok 16:33:26.0078 1232 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 16:33:26.0109 1232 Gpc ( UnsignedFile.Multi.Generic ) - warning 16:33:26.0109 1232 Gpc - detected UnsignedFile.Multi.Generic (1) 16:33:26.0203 1232 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 16:33:26.0203 1232 hidusb ( UnsignedFile.Multi.Generic ) - warning 16:33:26.0203 1232 hidusb - detected UnsignedFile.Multi.Generic (1) 16:33:26.0250 1232 hpn - ok 16:33:26.0343 1232 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys 16:33:26.0359 1232 HTTP ( UnsignedFile.Multi.Generic ) - warning 16:33:26.0359 1232 HTTP - detected UnsignedFile.Multi.Generic (1) 16:33:26.0421 1232 i2omgmt - ok 16:33:26.0453 1232 i2omp - ok 16:33:26.0500 1232 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 16:33:26.0515 1232 i8042prt ( UnsignedFile.Multi.Generic ) - warning 16:33:26.0515 1232 i8042prt - detected UnsignedFile.Multi.Generic (1) 16:33:26.0625 1232 ialm (16f8de7a7f9023aac04dec6a8a264441) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 16:33:26.0687 1232 ialm ( UnsignedFile.Multi.Generic ) - warning 16:33:26.0687 1232 ialm - detected UnsignedFile.Multi.Generic (1) 16:33:26.0781 1232 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 16:33:26.0796 1232 Imapi ( UnsignedFile.Multi.Generic ) - warning 16:33:26.0796 1232 Imapi - detected UnsignedFile.Multi.Generic (1) 16:33:26.0859 1232 ini910u - ok 16:33:26.0937 1232 IntelIde (69c4e3c9e67a1f103b94e14fdd5f3213) C:\WINDOWS\system32\DRIVERS\intelide.sys 16:33:26.0953 1232 IntelIde ( UnsignedFile.Multi.Generic ) - warning 16:33:26.0953 1232 IntelIde - detected UnsignedFile.Multi.Generic (1) 16:33:27.0046 1232 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys 16:33:27.0062 1232 intelppm ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0062 1232 intelppm - detected UnsignedFile.Multi.Generic (1) 16:33:27.0156 1232 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 16:33:27.0171 1232 Ip6Fw ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0171 1232 Ip6Fw - detected UnsignedFile.Multi.Generic (1) 16:33:27.0234 1232 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 16:33:27.0234 1232 IpFilterDriver ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0234 1232 IpFilterDriver - detected UnsignedFile.Multi.Generic (1) 16:33:27.0328 1232 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 16:33:27.0343 1232 IpInIp ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0343 1232 IpInIp - detected UnsignedFile.Multi.Generic (1) 16:33:27.0437 1232 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 16:33:27.0453 1232 IpNat ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0453 1232 IpNat - detected UnsignedFile.Multi.Generic (1) 16:33:27.0546 1232 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 16:33:27.0546 1232 IPSec ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0546 1232 IPSec - detected UnsignedFile.Multi.Generic (1) 16:33:27.0593 1232 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 16:33:27.0609 1232 IRENUM ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0609 1232 IRENUM - detected UnsignedFile.Multi.Generic (1) 16:33:27.0718 1232 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys 16:33:27.0718 1232 isapnp ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0718 1232 isapnp - detected UnsignedFile.Multi.Generic (1) 16:33:27.0796 1232 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 16:33:27.0812 1232 Kbdclass ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0812 1232 Kbdclass - detected UnsignedFile.Multi.Generic (1) 16:33:27.0875 1232 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 16:33:27.0890 1232 kmixer ( UnsignedFile.Multi.Generic ) - warning 16:33:27.0890 1232 kmixer - detected UnsignedFile.Multi.Generic (1) 16:33:27.0984 1232 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 16:33:28.0000 1232 KSecDD ( UnsignedFile.Multi.Generic ) - warning 16:33:28.0000 1232 KSecDD - detected UnsignedFile.Multi.Generic (1) 16:33:28.0062 1232 lbrtfdc - ok 16:33:28.0156 1232 LVPr2Mon (9af4d60b777832834e6fe424ede60fcd) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys 16:33:28.0156 1232 LVPr2Mon - ok 16:33:28.0265 1232 LVRS (c0bb2a314dbf04cfde45868ddeee204d) C:\WINDOWS\system32\DRIVERS\lvrs.sys 16:33:28.0328 1232 LVRS - ok 16:33:28.0421 1232 LVUSBSta (c77adb4c1c0767e2e7b2c54375cd7a09) C:\WINDOWS\system32\drivers\LVUSBSta.sys 16:33:28.0421 1232 LVUSBSta - ok 16:33:28.0609 1232 LVUVC (cb971e3cba88339e43625f16d1cb9f1b) C:\WINDOWS\system32\DRIVERS\lvuvc.sys 16:33:28.0859 1232 LVUVC - ok 16:33:28.0968 1232 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 16:33:28.0984 1232 mnmdd ( UnsignedFile.Multi.Generic ) - warning 16:33:28.0984 1232 mnmdd - detected UnsignedFile.Multi.Generic (1) 16:33:29.0062 1232 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys 16:33:29.0062 1232 Modem ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0062 1232 Modem - detected UnsignedFile.Multi.Generic (1) 16:33:29.0125 1232 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys 16:33:29.0140 1232 Mouclass ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0140 1232 Mouclass - detected UnsignedFile.Multi.Generic (1) 16:33:29.0234 1232 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys 16:33:29.0234 1232 mouhid ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0234 1232 mouhid - detected UnsignedFile.Multi.Generic (1) 16:33:29.0312 1232 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 16:33:29.0343 1232 MountMgr ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0343 1232 MountMgr - detected UnsignedFile.Multi.Generic (1) 16:33:29.0359 1232 mraid35x - ok 16:33:29.0437 1232 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 16:33:29.0453 1232 MRxDAV ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0453 1232 MRxDAV - detected UnsignedFile.Multi.Generic (1) 16:33:29.0546 1232 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 16:33:29.0625 1232 MRxSmb ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0625 1232 MRxSmb - detected UnsignedFile.Multi.Generic (1) 16:33:29.0718 1232 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 16:33:29.0734 1232 Msfs ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0734 1232 Msfs - detected UnsignedFile.Multi.Generic (1) 16:33:29.0828 1232 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 16:33:29.0859 1232 MSKSSRV ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0859 1232 MSKSSRV - detected UnsignedFile.Multi.Generic (1) 16:33:29.0953 1232 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 16:33:29.0953 1232 MSPCLOCK ( UnsignedFile.Multi.Generic ) - warning 16:33:29.0953 1232 MSPCLOCK - detected UnsignedFile.Multi.Generic (1) 16:33:30.0046 1232 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 16:33:30.0062 1232 MSPQM ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0062 1232 MSPQM - detected UnsignedFile.Multi.Generic (1) 16:33:30.0187 1232 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16:33:30.0203 1232 mssmbios ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0203 1232 mssmbios - detected UnsignedFile.Multi.Generic (1) 16:33:30.0296 1232 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 16:33:30.0328 1232 MSTEE ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0328 1232 MSTEE - detected UnsignedFile.Multi.Generic (1) 16:33:30.0406 1232 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 16:33:30.0406 1232 Mup ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0406 1232 Mup - detected UnsignedFile.Multi.Generic (1) 16:33:30.0515 1232 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 16:33:30.0531 1232 NABTSFEC ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0531 1232 NABTSFEC - detected UnsignedFile.Multi.Generic (1) 16:33:30.0640 1232 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 16:33:30.0671 1232 NDIS ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0671 1232 NDIS - detected UnsignedFile.Multi.Generic (1) 16:33:30.0750 1232 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 16:33:30.0781 1232 NdisIP ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0781 1232 NdisIP - detected UnsignedFile.Multi.Generic (1) 16:33:30.0828 1232 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 16:33:30.0843 1232 NdisTapi ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0843 1232 NdisTapi - detected UnsignedFile.Multi.Generic (1) 16:33:30.0890 1232 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16:33:30.0906 1232 Ndisuio ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0906 1232 Ndisuio - detected UnsignedFile.Multi.Generic (1) 16:33:30.0968 1232 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 16:33:30.0984 1232 NdisWan ( UnsignedFile.Multi.Generic ) - warning 16:33:30.0984 1232 NdisWan - detected UnsignedFile.Multi.Generic (1) 16:33:31.0046 1232 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 16:33:31.0062 1232 NDProxy ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0062 1232 NDProxy - detected UnsignedFile.Multi.Generic (1) 16:33:31.0125 1232 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 16:33:31.0140 1232 NetBIOS ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0140 1232 NetBIOS - detected UnsignedFile.Multi.Generic (1) 16:33:31.0218 1232 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 16:33:31.0234 1232 NetBT ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0234 1232 NetBT - detected UnsignedFile.Multi.Generic (1) 16:33:31.0343 1232 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\WINDOWS\system32\drivers\ccdcmb.sys 16:33:31.0359 1232 nmwcd ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0359 1232 nmwcd - detected UnsignedFile.Multi.Generic (1) 16:33:31.0406 1232 nmwcdc (3859c69a77793180548802dac9f34a38) C:\WINDOWS\system32\drivers\ccdcmbo.sys 16:33:31.0421 1232 nmwcdc ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0421 1232 nmwcdc - detected UnsignedFile.Multi.Generic (1) 16:33:31.0515 1232 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 16:33:31.0546 1232 Npfs ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0546 1232 Npfs - detected UnsignedFile.Multi.Generic (1) 16:33:31.0609 1232 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 16:33:31.0687 1232 Ntfs ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0687 1232 Ntfs - detected UnsignedFile.Multi.Generic (1) 16:33:31.0781 1232 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 16:33:31.0812 1232 Null ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0812 1232 Null - detected UnsignedFile.Multi.Generic (1) 16:33:31.0890 1232 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 16:33:31.0921 1232 NwlnkFlt ( UnsignedFile.Multi.Generic ) - warning 16:33:31.0921 1232 NwlnkFlt - detected UnsignedFile.Multi.Generic (1) 16:33:32.0015 1232 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 16:33:32.0031 1232 NwlnkFwd ( UnsignedFile.Multi.Generic ) - warning 16:33:32.0031 1232 NwlnkFwd - detected UnsignedFile.Multi.Generic (1) 16:33:32.0125 1232 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys 16:33:32.0140 1232 Parport ( UnsignedFile.Multi.Generic ) - warning 16:33:32.0140 1232 Parport - detected UnsignedFile.Multi.Generic (1) 16:33:32.0234 1232 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 16:33:32.0250 1232 PartMgr ( UnsignedFile.Multi.Generic ) - warning 16:33:32.0250 1232 PartMgr - detected UnsignedFile.Multi.Generic (1) 16:33:32.0343 1232 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys 16:33:32.0359 1232 ParVdm ( UnsignedFile.Multi.Generic ) - warning 16:33:32.0359 1232 ParVdm - detected UnsignedFile.Multi.Generic (1) 16:33:32.0437 1232 pccsmcfd - ok 16:33:32.0500 1232 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys 16:33:32.0515 1232 PCI ( UnsignedFile.Multi.Generic ) - warning 16:33:32.0515 1232 PCI - detected UnsignedFile.Multi.Generic (1) 16:33:32.0609 1232 PCIDump - ok 16:33:32.0671 1232 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\drivers\PCIIde.sys 16:33:32.0687 1232 PCIIde ( UnsignedFile.Multi.Generic ) - warning 16:33:32.0687 1232 PCIIde - detected UnsignedFile.Multi.Generic (1) 16:33:32.0781 1232 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys 16:33:32.0796 1232 Pcmcia ( UnsignedFile.Multi.Generic ) - warning 16:33:32.0796 1232 Pcmcia - detected UnsignedFile.Multi.Generic (1) 16:33:32.0843 1232 PDCOMP - ok 16:33:32.0890 1232 PDFRAME - ok 16:33:32.0906 1232 PDRELI - ok 16:33:32.0921 1232 PDRFRAME - ok 16:33:32.0937 1232 perc2 - ok 16:33:32.0953 1232 perc2hib - ok 16:33:33.0031 1232 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 16:33:33.0046 1232 PptpMiniport ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0046 1232 PptpMiniport - detected UnsignedFile.Multi.Generic (1) 16:33:33.0156 1232 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 16:33:33.0171 1232 PSched ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0171 1232 PSched - detected UnsignedFile.Multi.Generic (1) 16:33:33.0265 1232 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 16:33:33.0265 1232 Ptilink ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0265 1232 Ptilink - detected UnsignedFile.Multi.Generic (1) 16:33:33.0312 1232 ql1080 - ok 16:33:33.0375 1232 Ql10wnt - ok 16:33:33.0390 1232 ql12160 - ok 16:33:33.0406 1232 ql1240 - ok 16:33:33.0421 1232 ql1280 - ok 16:33:33.0468 1232 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 16:33:33.0500 1232 RasAcd ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0500 1232 RasAcd - detected UnsignedFile.Multi.Generic (1) 16:33:33.0593 1232 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 16:33:33.0609 1232 Rasl2tp ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0609 1232 Rasl2tp - detected UnsignedFile.Multi.Generic (1) 16:33:33.0703 1232 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 16:33:33.0718 1232 RasPppoe ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0718 1232 RasPppoe - detected UnsignedFile.Multi.Generic (1) 16:33:33.0812 1232 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 16:33:33.0828 1232 Raspti ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0828 1232 Raspti - detected UnsignedFile.Multi.Generic (1) 16:33:33.0890 1232 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 16:33:33.0906 1232 Rdbss ( UnsignedFile.Multi.Generic ) - warning 16:33:33.0906 1232 Rdbss - detected UnsignedFile.Multi.Generic (1) 16:33:34.0000 1232 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 16:33:34.0000 1232 RDPCDD ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0000 1232 RDPCDD - detected UnsignedFile.Multi.Generic (1) 16:33:34.0078 1232 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 16:33:34.0093 1232 rdpdr ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0093 1232 rdpdr - detected UnsignedFile.Multi.Generic (1) 16:33:34.0156 1232 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 16:33:34.0171 1232 RDPWD ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0171 1232 RDPWD - detected UnsignedFile.Multi.Generic (1) 16:33:34.0234 1232 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys 16:33:34.0250 1232 redbook ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0250 1232 redbook - detected UnsignedFile.Multi.Generic (1) 16:33:34.0375 1232 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 16:33:34.0390 1232 Secdrv ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0390 1232 Secdrv - detected UnsignedFile.Multi.Generic (1) 16:33:34.0453 1232 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 16:33:34.0468 1232 serenum ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0468 1232 serenum - detected UnsignedFile.Multi.Generic (1) 16:33:34.0531 1232 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys 16:33:34.0546 1232 Serial ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0546 1232 Serial - detected UnsignedFile.Multi.Generic (1) 16:33:34.0640 1232 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys 16:33:34.0640 1232 sfdrv01 ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0656 1232 sfdrv01 - detected UnsignedFile.Multi.Generic (1) 16:33:34.0703 1232 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys 16:33:34.0718 1232 sfhlp02 ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0718 1232 sfhlp02 - detected UnsignedFile.Multi.Generic (1) 16:33:34.0828 1232 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 16:33:34.0843 1232 Sfloppy ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0843 1232 Sfloppy - detected UnsignedFile.Multi.Generic (1) 16:33:34.0953 1232 sfsync03 (344b5af83cca5377752b8855d4324e69) C:\WINDOWS\system32\drivers\sfsync03.sys 16:33:34.0968 1232 sfsync03 ( UnsignedFile.Multi.Generic ) - warning 16:33:34.0968 1232 sfsync03 - detected UnsignedFile.Multi.Generic (1) 16:33:35.0046 1232 Simbad - ok 16:33:35.0093 1232 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 16:33:35.0125 1232 SLIP ( UnsignedFile.Multi.Generic ) - warning 16:33:35.0125 1232 SLIP - detected UnsignedFile.Multi.Generic (1) 16:33:35.0218 1232 smwdm (4aa922332433cdeb8b82c072c212e32e) C:\WINDOWS\system32\drivers\smwdm.sys 16:33:35.0359 1232 smwdm ( UnsignedFile.Multi.Generic ) - warning 16:33:35.0359 1232 smwdm - detected UnsignedFile.Multi.Generic (1) 16:33:37.0093 1232 SNPSTD3 (de2dc31ed0b921c223691462059f7183) C:\WINDOWS\system32\DRIVERS\snpstd3.sys 16:33:39.0234 1232 SNPSTD3 ( UnsignedFile.Multi.Generic ) - warning 16:33:39.0234 1232 SNPSTD3 - detected UnsignedFile.Multi.Generic (1) 16:33:39.0281 1232 Sparrow - ok 16:33:39.0343 1232 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 16:33:39.0359 1232 splitter ( UnsignedFile.Multi.Generic ) - warning 16:33:39.0359 1232 splitter - detected UnsignedFile.Multi.Generic (1) 16:33:39.0500 1232 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys 16:33:39.0500 1232 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 16:33:39.0500 1232 sptd ( LockedFile.Multi.Generic ) - warning 16:33:39.0500 1232 sptd - detected LockedFile.Multi.Generic (1) 16:33:39.0546 1232 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys 16:33:39.0578 1232 sr ( UnsignedFile.Multi.Generic ) - warning 16:33:39.0578 1232 sr - detected UnsignedFile.Multi.Generic (1) 16:33:39.0656 1232 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys 16:33:39.0687 1232 Srv ( UnsignedFile.Multi.Generic ) - warning 16:33:39.0687 1232 Srv - detected UnsignedFile.Multi.Generic (1) 16:33:39.0781 1232 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 16:33:39.0781 1232 ssmdrv - ok 16:33:39.0906 1232 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 16:33:39.0921 1232 streamip ( UnsignedFile.Multi.Generic ) - warning 16:33:39.0921 1232 streamip - detected UnsignedFile.Multi.Generic (1) 16:33:39.0984 1232 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 16:33:39.0984 1232 swenum ( UnsignedFile.Multi.Generic ) - warning 16:33:39.0984 1232 swenum - detected UnsignedFile.Multi.Generic (1) 16:33:40.0078 1232 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 16:33:40.0093 1232 swmidi ( UnsignedFile.Multi.Generic ) - warning 16:33:40.0093 1232 swmidi - detected UnsignedFile.Multi.Generic (1) 16:33:40.0125 1232 symc810 - ok 16:33:40.0171 1232 symc8xx - ok 16:33:40.0203 1232 sym_hi - ok 16:33:40.0265 1232 sym_u3 - ok 16:33:40.0296 1232 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 16:33:40.0312 1232 sysaudio ( UnsignedFile.Multi.Generic ) - warning 16:33:40.0312 1232 sysaudio - detected UnsignedFile.Multi.Generic (1) 16:33:40.0421 1232 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 16:33:40.0500 1232 Tcpip ( UnsignedFile.Multi.Generic ) - warning 16:33:40.0500 1232 Tcpip - detected UnsignedFile.Multi.Generic (1) 16:33:40.0609 1232 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 16:33:40.0640 1232 TDPIPE ( UnsignedFile.Multi.Generic ) - warning 16:33:40.0640 1232 TDPIPE - detected UnsignedFile.Multi.Generic (1) 16:33:40.0671 1232 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 16:33:40.0671 1232 TDTCP ( UnsignedFile.Multi.Generic ) - warning 16:33:40.0671 1232 TDTCP - detected UnsignedFile.Multi.Generic (1) 16:33:40.0765 1232 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 16:33:40.0796 1232 TermDD ( UnsignedFile.Multi.Generic ) - warning 16:33:40.0796 1232 TermDD - detected UnsignedFile.Multi.Generic (1) 16:33:40.0843 1232 TosIde - ok 16:33:40.0937 1232 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 16:33:40.0953 1232 Udfs ( UnsignedFile.Multi.Generic ) - warning 16:33:40.0953 1232 Udfs - detected UnsignedFile.Multi.Generic (1) 16:33:40.0968 1232 ultra - ok 16:33:41.0062 1232 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 16:33:41.0125 1232 Update ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0125 1232 Update - detected UnsignedFile.Multi.Generic (1) 16:33:41.0203 1232 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys 16:33:41.0218 1232 upperdev ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0218 1232 upperdev - detected UnsignedFile.Multi.Generic (1) 16:33:41.0296 1232 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys 16:33:41.0328 1232 USBAAPL ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0328 1232 USBAAPL - detected UnsignedFile.Multi.Generic (1) 16:33:41.0406 1232 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 16:33:41.0421 1232 usbaudio ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0421 1232 usbaudio - detected UnsignedFile.Multi.Generic (1) 16:33:41.0500 1232 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 16:33:41.0515 1232 usbccgp ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0515 1232 usbccgp - detected UnsignedFile.Multi.Generic (1) 16:33:41.0609 1232 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 16:33:41.0625 1232 usbehci ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0625 1232 usbehci - detected UnsignedFile.Multi.Generic (1) 16:33:41.0703 1232 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 16:33:41.0718 1232 usbhub ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0718 1232 usbhub - detected UnsignedFile.Multi.Generic (1) 16:33:41.0796 1232 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 16:33:41.0828 1232 usbscan ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0828 1232 usbscan - detected UnsignedFile.Multi.Generic (1) 16:33:41.0921 1232 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys 16:33:41.0937 1232 usbser ( UnsignedFile.Multi.Generic ) - warning 16:33:41.0937 1232 usbser - detected UnsignedFile.Multi.Generic (1) 16:33:42.0015 1232 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys 16:33:42.0031 1232 UsbserFilt ( UnsignedFile.Multi.Generic ) - warning 16:33:42.0031 1232 UsbserFilt - detected UnsignedFile.Multi.Generic (1) 16:33:42.0140 1232 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 16:33:42.0156 1232 USBSTOR ( UnsignedFile.Multi.Generic ) - warning 16:33:42.0156 1232 USBSTOR - detected UnsignedFile.Multi.Generic (1) 16:33:42.0250 1232 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 16:33:42.0265 1232 usbuhci ( UnsignedFile.Multi.Generic ) - warning 16:33:42.0265 1232 usbuhci - detected UnsignedFile.Multi.Generic (1) 16:33:42.0359 1232 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 16:33:42.0406 1232 usbvideo ( UnsignedFile.Multi.Generic ) - warning 16:33:42.0406 1232 usbvideo - detected UnsignedFile.Multi.Generic (1) 16:33:42.0515 1232 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 16:33:42.0531 1232 VgaSave ( UnsignedFile.Multi.Generic ) - warning 16:33:42.0531 1232 VgaSave - detected UnsignedFile.Multi.Generic (1) 16:33:42.0593 1232 ViaIde - ok 16:33:42.0656 1232 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys 16:33:42.0671 1232 VolSnap ( UnsignedFile.Multi.Generic ) - warning 16:33:42.0671 1232 VolSnap - detected UnsignedFile.Multi.Generic (1) 16:33:42.0781 1232 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 16:33:42.0781 1232 Wanarp ( UnsignedFile.Multi.Generic ) - warning 16:33:42.0781 1232 Wanarp - detected UnsignedFile.Multi.Generic (1) 16:33:42.0890 1232 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys 16:33:42.0937 1232 Wdf01000 - ok 16:33:43.0031 1232 WDICA - ok 16:33:43.0093 1232 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 16:33:43.0109 1232 wdmaud ( UnsignedFile.Multi.Generic ) - warning 16:33:43.0109 1232 wdmaud - detected UnsignedFile.Multi.Generic (1) 16:33:43.0234 1232 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 16:33:43.0265 1232 WpdUsb ( UnsignedFile.Multi.Generic ) - warning 16:33:43.0265 1232 WpdUsb - detected UnsignedFile.Multi.Generic (1) 16:33:43.0375 1232 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 16:33:43.0406 1232 WSTCODEC ( UnsignedFile.Multi.Generic ) - warning 16:33:43.0406 1232 WSTCODEC - detected UnsignedFile.Multi.Generic (1) 16:33:43.0468 1232 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 16:33:43.0484 1232 WudfPf ( UnsignedFile.Multi.Generic ) - warning 16:33:43.0484 1232 WudfPf - detected UnsignedFile.Multi.Generic (1) 16:33:43.0562 1232 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 16:33:43.0578 1232 WudfRd ( UnsignedFile.Multi.Generic ) - warning 16:33:43.0578 1232 WudfRd - detected UnsignedFile.Multi.Generic (1) 16:33:43.0640 1232 MBR (0x1B8) (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0 16:33:43.0890 1232 \Device\Harddisk0\DR0 - ok 16:33:43.0921 1232 Boot (0x1200) (b4acdcb8fb3fa8fa9756c11a20aff5e7) \Device\Harddisk0\DR0\Partition0 16:33:43.0921 1232 \Device\Harddisk0\DR0\Partition0 - ok 16:33:43.0921 1232 ============================================================ 16:33:43.0921 1232 Scan finished 16:33:43.0921 1232 ============================================================ 16:33:44.0046 1200 Detected object count: 139 16:33:44.0046 1200 Actual detected object count: 139 16:34:04.0421 1200 ACPI ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 ACPI ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 ACPIEC ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 ACPIEC ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 aeaudio ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 aeaudio ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 aec ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 aec ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 AFD ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 AFD ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 AsyncMac ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 AsyncMac ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 atapi ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 atapi ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 Atmarpc ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 Atmarpc ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 audstub ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 audstub ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 Beep ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 Beep ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 cbidf2k ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 cbidf2k ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 CCDECODE ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 CCDECODE ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 Cdaudio ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 Cdaudio ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0437 1200 Cdfs ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0437 1200 Cdfs ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 Cdrom ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 Cdrom ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 Disk ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 Disk ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 dmboot ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 dmboot ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 dmio ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 dmio ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 dmload ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 dmload ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 DMusic ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 DMusic ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 drmkaud ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 drmkaud ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 E100B ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 E100B ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 Fastfat ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 Fastfat ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0453 1200 Fdc ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0453 1200 Fdc ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 Fips ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 Fips ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 Flpydisk ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 Flpydisk ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 FltMgr ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 FltMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 Fs_Rec ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 Fs_Rec ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 Ftdisk ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 Ftdisk ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 Gpc ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 Gpc ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 hidusb ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 hidusb ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 HTTP ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 HTTP ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 i8042prt ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 i8042prt ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 ialm ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 ialm ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0468 1200 Imapi ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0468 1200 Imapi ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 IntelIde ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 IntelIde ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 intelppm ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 intelppm ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 Ip6Fw ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 Ip6Fw ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 IpFilterDriver ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 IpFilterDriver ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 IpInIp ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 IpInIp ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 IpNat ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 IpNat ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 IPSec ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 IPSec ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 IRENUM ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 IRENUM ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 isapnp ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 isapnp ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 Kbdclass ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 Kbdclass ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 kmixer ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 kmixer ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 KSecDD ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 KSecDD ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 mnmdd ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 mnmdd ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 Modem ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 Modem ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0484 1200 Mouclass ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0484 1200 Mouclass ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 mouhid ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 mouhid ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 MountMgr ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 MountMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 MRxDAV ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 MRxDAV ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 MRxSmb ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 MRxSmb ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 Msfs ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 Msfs ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 MSKSSRV ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 MSKSSRV ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 MSPCLOCK ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 MSPCLOCK ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 MSPQM ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 MSPQM ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 mssmbios ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 mssmbios ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0500 1200 MSTEE ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0500 1200 MSTEE ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 Mup ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 Mup ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NABTSFEC ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NABTSFEC ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NDIS ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NDIS ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NdisIP ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NdisIP ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NdisTapi ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NdisTapi ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 Ndisuio ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 Ndisuio ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NdisWan ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NdisWan ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NDProxy ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NDProxy ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NetBIOS ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NetBIOS ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0515 1200 NetBT ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0515 1200 NetBT ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 nmwcd ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 nmwcd ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 nmwcdc ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 nmwcdc ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 Npfs ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 Npfs ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 Ntfs ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 Ntfs ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 Null ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 Null ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 NwlnkFlt ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 NwlnkFlt ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 NwlnkFwd ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 NwlnkFwd ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 Parport ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 Parport ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 PartMgr ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 PartMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 ParVdm ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 ParVdm ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 PCI ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 PCI ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0531 1200 PCIIde ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0531 1200 PCIIde ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 Pcmcia ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 Pcmcia ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 PptpMiniport ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 PptpMiniport ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 PSched ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 PSched ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 Ptilink ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 Ptilink ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 RasAcd ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 RasAcd ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 Rasl2tp ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 Rasl2tp ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 RasPppoe ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 RasPppoe ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 Raspti ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 Raspti ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 Rdbss ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 Rdbss ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0546 1200 RDPCDD ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0546 1200 RDPCDD ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 rdpdr ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 rdpdr ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 RDPWD ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 RDPWD ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 redbook ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 redbook ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 Secdrv ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 Secdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 serenum ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 serenum ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 Serial ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 Serial ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 Sfloppy ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 Sfloppy ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0562 1200 sfsync03 ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0562 1200 sfsync03 ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 SLIP ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 SLIP ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 smwdm ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 smwdm ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 SNPSTD3 ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 SNPSTD3 ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 splitter ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 splitter ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 sptd ( LockedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 sr ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 sr ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 Srv ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 Srv ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 streamip ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 streamip ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 swenum ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 swenum ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0578 1200 swmidi ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0578 1200 swmidi ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 sysaudio ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 sysaudio ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 Tcpip ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 Tcpip ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 TDPIPE ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 TDPIPE ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 TDTCP ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 TDTCP ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 TermDD ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 TermDD ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 Udfs ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 Udfs ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 Update ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 Update ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 upperdev ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 upperdev ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 USBAAPL ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 USBAAPL ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0593 1200 usbaudio ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0593 1200 usbaudio ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 usbccgp ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 usbccgp ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 usbehci ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 usbehci ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 usbhub ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 usbhub ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 usbscan ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 usbscan ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 usbser ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 usbser ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 UsbserFilt ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 UsbserFilt ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 USBSTOR ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 USBSTOR ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 usbuhci ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 usbuhci ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 usbvideo ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 usbvideo ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0609 1200 VgaSave ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0609 1200 VgaSave ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0625 1200 VolSnap ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0625 1200 VolSnap ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0625 1200 Wanarp ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0625 1200 Wanarp ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0625 1200 wdmaud ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0625 1200 wdmaud ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0625 1200 WpdUsb ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0625 1200 WpdUsb ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0625 1200 WSTCODEC ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0625 1200 WSTCODEC ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0625 1200 WudfPf ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0625 1200 WudfPf ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:34:04.0625 1200 WudfRd ( UnsignedFile.Multi.Generic ) - skipped by user 16:34:04.0625 1200 WudfRd ( UnsignedFile.Multi.Generic ) - User select action: Skip |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
|
Hier das Combo Fix Log: Combofix Logfile: Code: ComboFix 11-10-25.03 - Simon 25.10.2011 16:56:48.1.1 - x86 Edit: Für alles ( bis hierhin und weiter ) danke ich dir , Cosinus/Arne schonmal sehr herzlich !! :dankeschoen::party: |
Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM! Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). |
Hier schonmal das Log von GMER: GMER Logfile: Code: GMER 1.0.15.15641 - hxxp://www.gmer.net Der alarm von Antivir beim entpacken von OSAM als TR/ Gendal ist also Fehlalarm? |
Alle Zeitangaben in WEZ +1. Es ist jetzt 01:27 Uhr. |
Copyright ©2000-2025, Trojaner-Board