Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   multiple Malware: Live Security Platinum, SpyHunter (https://www.trojaner-board.de/119603-multiple-malware-live-security-platinum-spyhunter.html)

petemq 16.07.2012 04:20

multiple Malware: Live Security Platinum, SpyHunter
 
Multiples Virenproblem

Ich habe mir trotz installierter und aktiver avirasoftware einen Virus eingefangen: Live Security Platinum. Nach einem simulierten Virenscan blockierte die Anwendung alles. Ich habe mich auf einem anderen Benutzer angemeldet, auf dem es bisher alles funktioniert, und startete die Virenbekämpfung.
Dabei habe ich mich unter anderem hier informiert und bin auf einen Beitrag (den ich leider nicht mehr kenne) gestoßen, der per SpyHunter Hilfe versprach. Blöd wie ich war bin ich darauf reingefallen, lud mir das Teil runter, startete den Scan (der nach Sekunden auf Live Security Platinum als gefährliche Software stieß und somit mein Vertrauen weckte). Als ich merkte, dass man zum Entfernen eine Vollversion brauchte, habe ich mich nach Alternativen umgeschaut und bin dabei auf Malwarebytes mbam.exe gestoßen. Gescannt, 2 infizierte Dateien gefunden, beseitigt, Neustart. Dann wollte ich sicherheitshalber noch einen anderen Scan (SpyHunter) drüberlaufen lassen. Der stieß (natürlich) auf zig Viren, während mbam.exe nach 5 Stunden immer noch nichts fand.
Dann las ich, dass SpyHunter selbst Fraudware ist. Per OTH alle Tasks abgeschossen, per im mbam mitgelieferten Assasin SpyHunter entfernt (hoffentlich vollständig).
Bevor ich jetzt weitere Schritte unternehme möchte ich erst einmal von jemandem, der sich damit besser auskennt als ich hören, was ich jetzt tun sollte...
Vielen Dank im Voraus!
petemq

t'john 16.07.2012 20:08

:hallo:

Poste alle Logfiles die du schon hast!

petemq 17.07.2012 21:54

Danke, dass du dich der Sache annimmst!
Ich habe mehrere Scans gemacht und (wegen blöd gesetzter Einstellungen) auch schon einiges automatisch entfernt.
Ich sende dir die 3 Suchlogs (1 Quickscan und ein Vollscan gestern, ein Quickscan heute) und 3 Protection - logs.
Ich hoffe, du kannst damit etwas anfangen.
Danke!

petemq 17.07.2012 23:39

Ich habe noch einen vollständigen Test hinterher gemacht, der keine Infizierungen meldet (log anbei).

t'john 18.07.2012 09:39

Sehr gut! :daumenhoc

CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.


Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


petemq 18.07.2012 21:22

Okay, erledigt.
Malwarebytes war heute zufrieden, das vorinstallierte Schutzprogramm Trend Micro Titanium Internet Security wollte aber noch mehrere Dateien löschen (und hat es automatisch getan).
Anbei habe ich das OTL reportfile.
Wenn ansonsten alles behoben ist (was ich hoffe) hätte ich gerne noch einen Tipp, wie ich mich möglichst effektiv gegen zukünftige Attacken schützen kann...
Ansonsten schon mal ein großes :dankeschoen: für deine Hilfe!

PS: Ich musste das OTLfile in zwei Teile splitten, da es die zulässige Größe überschritten hat... OTLreport ist der erste Teil, OTLreport 2 der zweite.

t'john 18.07.2012 21:36

Fixen mit OTL

Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).

  • Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
  • Starte die OTL.exe.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:


Code:

:OTL
PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.12.17 18:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
SRV - [2010.08.21 01:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLSDF8&pc=MDDS&src=IE-SearchBox
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLSDF8&pc=MDDS&src=IE-SearchBox
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1589458562-1367240314-1896126385-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1589458562-1367240314-1896126385-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1589458562-1367240314-1896126385-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1589458562-1367240314-1896126385-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKU\S-1-5-21-1589458562-1367240314-1896126385-1000..\Run: [Dispayed] C:\Users\Pete\AppData\Local\Temp\certsync64.dll (FRISK Software International)
O4 - HKU\S-1-5-21-1589458562-1367240314-1896126385-1000..\Run: [erewmc] rundll32.exe "C:\Users\Pete\AppData\Roaming\erewmc.dll",StrToUintA File not found
O4 - HKU\S-1-5-21-1589458562-1367240314-1896126385-1000..\Run: [Facebook Update] C:\Users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-1589458562-1367240314-1896126385-1000..\Run: [MCAFEE] C:\Users\Pete\AppData\Roaming\52B5C5.exe File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O32 - HKLM CDRom: AutoRun - 1

:Files

C:\Users\Pete\AppData\Local\Temp\certsync64.dll

ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash]

  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Wenn OTL einen Neustart verlangt, bitte zulassen.
  • Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
    Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\

Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

petemq 19.07.2012 03:03

Okay, das wäre erledigt. Beim erforderlichen Neustart ist zwar mein kompletter Desktop unordentlich geworden, aber das soll es wert sein.

Logfile:

Code:

All processes killed
========== OTL ==========
No active process named DivXUpdate.exe was found!
No active process named FF_Protection.exe was found!
Service SftService stopped successfully!
Service SftService deleted successfully!
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}\ not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKEY_USERS\S-1-5-21-1589458562-1367240314-1896126385-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKU\S-1-5-21-1589458562-1367240314-1896126385-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKEY_USERS\S-1-5-21-1589458562-1367240314-1896126385-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKU\S-1-5-21-1589458562-1367240314-1896126385-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IntelTBRunOnce not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully.
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-1589458562-1367240314-1896126385-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Dispayed deleted successfully.
C:\Users\Pete\AppData\Local\Temp\certsync64.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-1589458562-1367240314-1896126385-1000\Software\Microsoft\Windows\CurrentVersion\Run\\erewmc deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1589458562-1367240314-1896126385-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update deleted successfully.
C:\Users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-1589458562-1367240314-1896126385-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MCAFEE deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
========== FILES ==========
File\Folder C:\Users\Pete\AppData\Local\Temp\certsync64.dll not found.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Pete\Desktop\cmd.bat deleted successfully.
C:\Users\Pete\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: admin
->Temp folder emptied: 43202677 bytes
->Temporary Internet Files folder emptied: 2813415 bytes
->FireFox cache emptied: 6046995 bytes
->Flash cache emptied: 456 bytes
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Developdesk
->Temp folder emptied: 29545531 bytes
->Temporary Internet Files folder emptied: 945951 bytes
->FireFox cache emptied: 56557876 bytes
->Flash cache emptied: 763 bytes
 
User: Pete
->Temp folder emptied: 1576677855 bytes
->Temporary Internet Files folder emptied: 134 bytes
->Java cache emptied: 514092 bytes
->FireFox cache emptied: 273970857 bytes
->Flash cache emptied: 12857 bytes
 
User: Public
 
User: Suppenuser
->Temp folder emptied: 37469438 bytes
->Temporary Internet Files folder emptied: 117044922 bytes
->Flash cache emptied: 571 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 190063 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 255868809 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 38989360 bytes
 
Total Files Cleaned = 2.327,00 mb
 
 
[EMPTYFLASH]
 
User: admin
->Flash cache emptied: 0 bytes
 
User: All Users
 
User: Default
 
User: Default User
 
User: Developdesk
->Flash cache emptied: 0 bytes
 
User: Pete
->Flash cache emptied: 0 bytes
 
User: Public
 
User: Suppenuser
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
 
OTL by OldTimer - Version 3.2.54.0 log created on 07192012_033850

Files\Folders moved on Reboot...
File move failed. C:\Users\Pete\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...
[2011.12.13 21:48:32 | 000,000,000 | ---- | M] () C:\Users\Pete\AppData\Local\Temp\FXSAPIDebugLogFile.txt : Unable to obtain MD5

Registry entries deleted on Reboot...


t'john 19.07.2012 09:18

Sehr gut! :daumenhoc

Wie laeuft der Rechner?

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

petemq 19.07.2012 18:37

Der Rechner läuft bis jetzt einwandfrei (das einzig Beunruhigende wäre, dass Trend Micro zwischendurch nochmal Dateien gelöscht hat).

Der Scan ging ja echt schnell, und soweit ih das sehe ist das Ergebnis zufriedenstellend.

t'john 19.07.2012 20:10

Sehr gut! :daumenhoc

Malware mit Combofix beseitigen

Lade Combofix von einem der folgenden Download-Spiegel herunter:

BleepingComputer.com - ForoSpyware.com

und speichere das Programm auf den Desktop, nicht woanders hin, das ist wichtig!
Beachte die ausführliche Original-Anleitung.

Zurzeit ist Combofix auf folgenden Windows-Versionen lauffähig:

  • Windows XP (nur 32-bit)
  • Windows Vista (32-bit/64-bit)
  • Windows 7 (32-bit/64-bit)



Vorbereitung und wichtige Hinweise

  • Bitte während des Scans mit Combofix Antiviren- sowie Antispy-Programme, die Firewall und evtl. vorhandenes Skript-Blocking (Norton) deaktivieren.
  • Liste der zu deaktivierenden Programme.
    Bei Unklarheiten bitte fragen.




  • ComboFix wird Deine Einstellungen in Bezug auf den Bildschirmschoner zurücksetzen.
  • Diese Einstellungen kannst Du nach Beendigung unserer Bereinigung wieder ändern.
  • Mache nichts anderes, wenn es Dir nicht gelungen ist, Combofix laufen zu lassen.
  • Teile uns das mit und warte auf unsere Anweisungen.




  • Starte die Combofix.exe mit Rechtsklick => Als Administrator ausführen und folge den Anweisungen.
  • Während des Laufs von Combofix nichts anderes am Computer machen!
  • Akzeptiere die Bedingungen (Disclaimer) mit "Ja".



  • Sollte Combofix eine aktuellere Version anbieten, Downlaod erlauben.
  • Klicke "Ja", um mit dem Suchlauf nach Malware fortzufahren.
  • Es erscheint eine blaue Eingabeaufforderung, Combofix wird für den Suchlauf vorbereitet.
  • Bitte nicht in dieses Combofix-Fenster klicken.
  • Das könnte Dein System einfrieren oder hängen bleiben lassen.
  • Es wird ein Backup Deiner Registry erstellt.
  • Nun werden die einzelnen Stufen des Programms abgearbeitet, das kann eine Weile dauern.



  • Wenn ComboFix fertig ist, wird es ein Log erstellen (bitte warten, das dauert einen Moment).
  • Unbedingt warten, bis sich das Combofix-Fenster geschlossen hat und das Logfile im Editor erscheint.
  • Bitte poste die Log-Dateien C:\ComboFix.txt und C:\Qoobox\Add-Remove Programs.txt in Code-Tags hier in den Thread.



  • Hinweis: Combofix macht aus verschiedenen Gründen den Internet Explorer zum Standard-Browser und erstellt ein IE-Icon auf dem Desktop.
  • Das IE-Desktop-Icon kannst Du nach der Bereinigung wieder löschen und Deinen bevorzugten Browser wieder als Standard-Browser einstellen.



Combofix nicht auf eigene Faust einsetzen. Wenn keine entsprechende Infektion vorliegt, kann das den Rechner lahmlegen und/oder nachhaltig schädigen!

petemq 21.07.2012 19:13

Okay, soweit erledigt.

C:\ComboFix.txt
Code:

ComboFix 12-07-21.01 - admin 21.07.2012  19:44:56.1.4 - x64
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.4002.2416 [GMT 2:00]
ausgeführt von:: c:\users\Pete\Desktop\ComboFix.exe
AV: Trend Micro Titanium Internet Security *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902}
FW: Trend Micro Firewall Booster *Disabled* {50C2E989-60CF-0845-AFD3-290B7D301E79}
SP: Trend Micro Titanium Internet Security *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\users\Pete\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum
c:\users\Pete\X17-75062.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-21 bis 2012-07-21  ))))))))))))))))))))))))))))))
.
.
2012-07-19 01:38 . 2012-07-19 01:38        --------        d-----w-        C:\_OTL
2012-07-17 20:23 . 2011-05-21 08:01        339536        ----a-w-        c:\windows\system32\drivers\tmwfp.sys
2012-07-17 20:23 . 2011-05-21 08:01        194640        ----a-w-        c:\windows\system32\drivers\tmlwf.sys
2012-07-17 20:19 . 2012-07-17 20:19        --------        d-----w-        c:\users\Developdesk\AppData\Local\Diagnostics
2012-07-16 21:39 . 2012-07-16 21:39        --------        d-----w-        c:\users\Pete\AppData\Roaming\Malwarebytes
2012-07-16 18:47 . 2012-07-16 18:47        --------        d-----w-        c:\users\admin\AppData\Roaming\Dell
2012-07-16 02:15 . 2012-07-16 02:15        --------        d-----w-        c:\users\admin\AppData\Local\Mozilla
2012-07-15 19:57 . 2012-07-15 19:57        --------        d-----w-        c:\users\Developdesk\AppData\Roaming\Malwarebytes
2012-07-15 19:26 . 2012-07-15 19:26        --------        d-----w-        c:\users\admin\AppData\Roaming\Malwarebytes
2012-07-15 19:26 . 2012-07-15 19:26        --------        d-----w-        c:\programdata\Malwarebytes
2012-07-15 19:26 . 2012-07-15 19:26        --------        d-----w-        c:\program files (x86)\Virenkiller
2012-07-15 19:26 . 2012-07-03 11:46        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-07-15 18:37 . 2012-07-15 18:37        110080        ----a-r-        c:\users\admin\AppData\Roaming\Microsoft\Installer\{F896D026-9016-4122-B9BD-957FF092FFE9}\IconF7A21AF7.exe
2012-07-15 18:37 . 2012-07-15 18:37        110080        ----a-r-        c:\users\admin\AppData\Roaming\Microsoft\Installer\{F896D026-9016-4122-B9BD-957FF092FFE9}\IconD7F16134.exe
2012-07-15 18:37 . 2012-07-15 18:37        110080        ----a-r-        c:\users\admin\AppData\Roaming\Microsoft\Installer\{F896D026-9016-4122-B9BD-957FF092FFE9}\Icon1226A4C5.exe
2012-07-15 18:36 . 2012-07-15 18:36        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard
2012-07-15 18:27 . 2012-07-15 18:27        --------        d-----w-        c:\program files (x86)\Mozilla Maintenance Service
2012-07-15 18:27 . 2012-07-15 18:27        624608        ----a-w-        c:\program files (x86)\Mozilla Firefox\gkmedias.dll
2012-07-15 18:27 . 2012-07-15 18:27        43488        ----a-w-        c:\program files (x86)\Mozilla Firefox\mozglue.dll
2012-07-15 18:27 . 2012-07-15 18:27        421200        ----a-w-        c:\program files (x86)\Mozilla Firefox\msvcp100.dll
2012-07-15 18:27 . 2012-07-15 18:27        157608        ----a-w-        c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-07-15 18:27 . 2012-07-15 18:27        113120        ----a-w-        c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-07-15 18:27 . 2012-07-15 18:27        770384        ----a-w-        c:\program files (x86)\Mozilla Firefox\msvcr100.dll
2012-07-14 00:54 . 2012-07-14 00:56        --------        d-----w-        c:\programdata\7531CCA900094A2E02AFCCC5F875EF60
2012-07-11 22:10 . 2012-06-12 03:08        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-07-11 20:12 . 2012-07-11 20:12        --------        d-----w-        c:\users\Pete\AppData\Local\Windows Live
2012-07-11 16:44 . 2012-06-06 06:05        495616        ----a-w-        c:\program files\Common Files\System\ado\msadox.dll
2012-07-11 16:44 . 2012-06-06 06:05        61440        ----a-w-        c:\program files\Common Files\System\ado\msador15.dll
2012-07-11 16:44 . 2012-06-06 06:05        466944        ----a-w-        c:\program files\Common Files\System\ado\msadomd.dll
2012-07-11 16:44 . 2012-06-06 06:05        1499136        ----a-w-        c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 16:44 . 2012-06-06 06:05        258048        ----a-w-        c:\program files\Common Files\System\msadc\msadco.dll
2012-07-11 16:44 . 2012-06-06 06:02        1133568        ----a-w-        c:\windows\system32\cdosys.dll
2012-07-11 16:44 . 2012-06-06 05:05        143360        ----a-w-        c:\program files (x86)\Common Files\System\ado\msjro.dll
2012-07-11 16:44 . 2012-06-06 05:05        372736        ----a-w-        c:\program files (x86)\Common Files\System\ado\msadox.dll
2012-07-11 16:44 . 2012-06-06 05:05        57344        ----a-w-        c:\program files (x86)\Common Files\System\ado\msador15.dll
2012-07-11 16:44 . 2012-06-06 05:05        352256        ----a-w-        c:\program files (x86)\Common Files\System\ado\msadomd.dll
2012-07-11 16:44 . 2012-06-06 05:05        212992        ----a-w-        c:\program files (x86)\Common Files\System\msadc\msadco.dll
2012-07-11 16:44 . 2012-06-06 05:05        1019904        ----a-w-        c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-07-11 16:44 . 2012-06-06 05:03        805376        ----a-w-        c:\windows\SysWow64\cdosys.dll
2012-07-05 18:53 . 2012-07-11 22:06        59701280        ----a-w-        c:\windows\system32\MRT.exe
2012-07-05 16:45 . 2012-07-05 16:45        5030088        ----a-w-        c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-07-05 15:41 . 2012-01-04 10:44        509952        ----a-w-        c:\windows\system32\ntshrui.dll
2012-07-05 15:41 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\SysWow64\ntshrui.dll
2012-07-05 15:40 . 2012-05-01 05:40        209920        ----a-w-        c:\windows\system32\profsvc.dll
2012-07-05 15:40 . 2011-12-30 06:26        515584        ----a-w-        c:\windows\system32\timedate.cpl
2012-07-05 15:40 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\SysWow64\timedate.cpl
2012-07-05 15:40 . 2011-03-12 12:08        1465344        ----a-w-        c:\windows\system32\XpsPrint.dll
2012-07-05 15:40 . 2011-03-12 11:23        870912        ----a-w-        c:\windows\SysWow64\XpsPrint.dll
2012-07-05 15:40 . 2012-04-24 05:37        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-07-05 15:40 . 2012-04-24 05:37        140288        ----a-w-        c:\windows\system32\cryptnet.dll
2012-07-05 15:40 . 2012-04-24 05:37        1462272        ----a-w-        c:\windows\system32\crypt32.dll
2012-07-05 15:40 . 2012-04-24 04:36        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2012-07-05 15:40 . 2012-04-24 04:36        1158656        ----a-w-        c:\windows\SysWow64\crypt32.dll
2012-07-05 15:40 . 2012-04-24 04:36        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2012-07-05 04:16 . 2012-04-07 12:31        3216384        ----a-w-        c:\windows\system32\msi.dll
2012-07-05 04:16 . 2012-04-07 11:26        2342400        ----a-w-        c:\windows\SysWow64\msi.dll
2012-07-05 02:49 . 2012-07-05 02:49        --------        d-----w-        c:\users\admin\AppData\Local\ElevatedDiagnostics
2012-07-04 19:21 . 2012-07-04 19:21        --------        d-----w-        c:\program files\DivX
2012-07-04 19:20 . 2012-07-04 19:21        --------        d-----w-        c:\program files (x86)\Common Files\DivX Shared
2012-07-04 19:17 . 2012-07-04 19:21        --------        d-----w-        c:\program files (x86)\DivX
2012-07-04 19:07 . 2012-07-04 19:21        --------        d-----w-        c:\programdata\DivX
2012-07-03 22:06 . 2012-07-03 22:06        --------        d-----w-        c:\users\Developdesk\AppData\Local\Macromedia
2012-06-27 13:54 . 2012-06-27 13:54        --------        d-----w-        c:\users\Pete\AppData\Roaming\Lindy
2012-06-27 13:54 . 2012-06-27 13:54        --------        d-----w-        c:\program files (x86)\Lindy
2012-06-27 13:52 . 2012-06-27 13:52        --------        d-----w-        c:\program files (x86)\Ripper
2012-06-24 11:36 . 2012-06-24 11:36        --------        d-----w-        c:\users\Pete\AppData\Local\Macromedia
2012-06-22 13:08 . 2012-06-02 22:19        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-22 13:08 . 2012-06-02 22:19        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-22 13:08 . 2012-06-02 22:19        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-22 13:08 . 2012-06-02 22:15        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-22 13:08 . 2012-06-02 22:19        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-22 13:08 . 2012-06-02 22:19        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-22 13:08 . 2012-06-02 22:15        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-22 13:07 . 2012-06-02 13:19        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-22 13:07 . 2012-06-02 13:15        36864        ----a-w-        c:\windows\system32\wuapp.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 03:51 . 2012-05-08 16:02        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-12 03:51 . 2011-12-09 10:48        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-08 15:45 . 2012-05-01 14:44        8531968        ----a-w-        c:\users\Pete\SteamInstall_German.msi
2012-05-04 11:06 . 2012-06-14 14:55        5559664        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-14 14:55        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 14:55        3913072        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-04-29 15:52 . 2012-04-29 15:52        14804272        ----a-w-        c:\users\Pete\MediaMonkey_4.0.3.1476.exe
2012-04-28 03:55 . 2012-06-14 14:55        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-04-26 05:41 . 2012-06-14 14:55        77312        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-04-26 05:41 . 2012-06-14 14:55        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:34 . 2012-06-14 14:55        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-02-18 283160]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-16 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-16 932288]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-02-22 1073312]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Virenkiller\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2010-08-12 163040]
"DSUpdateLauncher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" [2010-07-21 18240]
"Malwarebytes Anti-Malware"="c:\program files (x86)\Virenkiller\mbamgui.exe" [2012-07-03 462920]
"Malwarebytes Anti-Malware (cleanup)"="c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll" [2012-07-03 1085000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages        REG_MULTI_SZ          DPPassFilter scecli
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-05-19 921664]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-05-19 995392]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-07-05 3048136]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-12 250056]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [x]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-05-19 1335360]
R3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-05-19 51712]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-05-19 53248]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-07-19 282624]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-07-20 59904]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-03-24 34200]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-15 113120]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-02 250984]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 13312]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-09 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616]
S1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\DRIVERS\tmlwf.sys [2011-05-21 194640]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2011-05-12 200320]
S2 CxUtilSvc;Conexant Utility Service;c:\program files\Conexant\SA3\CxUtilSvc.exe [2011-06-24 28288]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-02-18 13336]
S2 MBAMService;MBAMService;c:\program files (x86)\Virenkiller\mbamservice.exe [2012-07-03 655944]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2012-01-13 103440]
S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 6583160]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [2011-05-21 69392]
S2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\DRIVERS\tmwfp.sys [2011-05-21 339536]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 528760]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-23 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2010-12-03 3143472]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-03-24 25496]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-08-03 8604672]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-03-22 452200]
S3 tihub3;TI USB3 Hub Service;c:\windows\system32\DRIVERS\tihub3.sys [2011-07-20 136000]
S3 tixhci;TI XHCI Service;c:\windows\system32\DRIVERS\tixhci.sys [2011-07-20 406336]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-08 03:51]
.
2012-05-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-03-22 17:20]
.
2012-07-21 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2011-03-22 17:20]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-20 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-20 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-20 416024]
"SmartAudio"="c:\program files\CONEXANT\SA3\SACpl.exe" [2011-06-24 1573504]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-03-24 3668336]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-05-19 10365952]
"Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2011-05-21 192520]
"Trend Micro Titanium"="c:\program files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" [2011-05-21 1119392]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-02-01 446392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\2m3fujl9.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-07-21  19:53:11
ComboFix-quarantined-files.txt  2012-07-21 17:53
.
Vor Suchlauf: 16 Verzeichnis(se), 380.146.294.784 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 379.629.219.840 Bytes frei
.
- - End Of File - - AE2C3323F371223976705683E681276C


C:\Qoobox\Add-Remove Programs.txt
Code:

4Musics MP3 to WAV Converter 4.3
AccelerometerP11
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop CS6
Adobe Reader X MUI
Advanced Audio FX Engine
Advertising Center
Audacity 2.0
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Webcam Central
DivX-Setup
DolbyFiles
Facebook Video Calling 1.2.0.159
Garmin BaseCamp
Garmin MapSource
Garmin Training Center
Garmin USB Drivers
ImagXpress
Intel PROSet Wireless
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Intel(R) WiDi
Java Auto Updater
Java(TM) 6 Update 27
Junk Mail filter update
League of Legends
Malwarebytes Anti-Malware Version 1.62.0.1300
McAfee Security Scan Plus
McAfee SiteAdvisor
MediaMonkey 4.0
Mesh Runtime
Microsoft Office 2010
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010
Microsoft Office Excel MUI (German) 2010
Microsoft Office Home and Business 2010
Microsoft Office OneNote MUI (German) 2010
Microsoft Office Outlook MUI (German) 2010
Microsoft Office PowerPoint MUI (German) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (German) 2010
Microsoft Office Proof (Italian) 2010
Microsoft Office Proofing (German) 2010
Microsoft Office Publisher MUI (German) 2010
Microsoft Office Shared MUI (German) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (German) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft_VC80_CRT_x86
Microsoft_VC90_CRT_x86
Mozilla Firefox 13.0.1 (x86 de)
Mozilla Maintenance Service
Mozilla Thunderbird 10.0.2 (x86 de)
MP3 to WAV Converter 2.85
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 9 Essentials
Nero BurnRights
Nero BurnRights Help
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero Disc Copy Gadget
Nero Disc Copy Gadget Help
Nero DiscSpeed
Nero DiscSpeed Help
Nero DriveSpeed
Nero DriveSpeed Help
Nero Express Help
Nero InfoTool
Nero InfoTool Help
Nero Installer
Nero Online Upgrade
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero StartSmart OEM
Nero Vision
Nero Vision Help
NeroExpress
neroxml
Pando Media Booster
PDF Settings CS6
Realtek Ethernet Controller Driver
Realtek USB 2.0 Card Reader
RippMe
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2553322) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2597981) 32-Bit Edition
Skype Click to Call
Skype™ 5.10
Smart MP3 Converter
Steam
Stronghold 2 Deluxe
Team Fortress 2
TI USB 3.0 Host Controller Driver
TI USB3 Host Driver
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
VC80CRTRedist - 8.0.50727.6195
Visionaire 3.6
WebTablet FB Plugin
WebTablet IE Plugin
WebTablet Netscape Plugin
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalerie
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX control for remote connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources


t'john 21.07.2012 21:03

Sehr gut! :daumenhoc

Malware-Scan mit Emsisoft Anti-Malware

Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm.
Lade über Jetzt Updaten die aktuellen Signaturen herunter.
Wähle den Freeware-Modus aus.

Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers.
Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten.

Anleitung: http://www.trojaner-board.de/103809-...i-malware.html


danach:


ESET Online Scanner

Vorbereitung

  • Schließe evtl. vorhandene externe Festplatten und/oder sonstigen Wechselmedien (z. B. evtl. vorhandene USB-Sticks) an den Rechner an.
  • Bitte während des Online-Scans Anti-Virus-Programm und Firewall deaktivieren.
  • Vista/Win7-User: Bitte den Browser unbedingt als Administrator starten.
Los geht's

  • Lade und starte Eset Smartinstaller
  • Haken setzen bei YES, I accept the Terms of Use.
  • Klick auf Start.
  • Haken setzen bei Remove found threads und Scan archives.
  • Klick auf Start.
  • Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Finish drücken.
  • Browser schließen.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (manchmal auch C:\Programme\Eset\log.txt) suchen und mit Deinem Editor öffnen.
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

petemq 22.07.2012 06:20

:kaffee:
Okay, soweit der Bericht:
Ich habe den Emisoft Scanner runtergeladen etc. . Der Test lief problemlos (abgesehen davon, dass er 3 Stunden dauerte) und fand keine infizierten Dateien. Als ich mir den Bericht jedoch ansehen wollte, öffnete sich ein leeres Explorerfenster im Hintergrund (ich nutze W7) und die Fehlermeldung, dass der angegebene Dateipfad ungültig sei. Als ich die Meldung schloss, verschwand das Fenster. Auch auf manuelle Eingabe im Explorerfenster kam besagte Fehlermeldung.

Ich habe den Test nochmal durchlaufen lassen, das selbe Ergebnis. Also kann ich desbezüglich nur mündlich berichten: Keine Funde.

ESET lief bis jetzt problemlos durch, keine Funde angezeigt. Der Bericht:
Code:

ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internet# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=4c3c655d8066bc4695a0f4844d27df23
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-22 03:42:54
# local_time=2012-07-22 05:42:54 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=512 16777215 100 0 19499201 19499201 0 0
# compatibility_mode=5893 16776574 100 94 19494964 94554850 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=164352
# found=0
# cleaned=0
# scan_time=3575

Ich habe sämtliche Sicherheitsprogramme (Trend Micro Internet Security, Malwarebytes, Windows Firewall) wieder hochgefahren und einen Trend Micro Quickscan gemacht, keine Bedrohungen. Ich werde jetzt also ESET deinstallieren und danach nochmal einen vollständigen Test machen.
MfG

t'john 22.07.2012 09:33

Sehr gut! :daumenhoc

Deinstalliere:
Emsisoft Anti-Malware
ESET


Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 7 Update 5 ) herunter laden.
  • Wenn die Installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Hacken gesetzt ist und klicke OK.
  • Klicke erneut OK.


Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html

petemq 22.07.2012 19:21

Erledigt :)

t'john 22.07.2012 20:36

Sehr gut! :daumenhoc

Combofix deinstallieren

Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking (Norton) und Anti-Malware Programme deaktivieren.

Start => Ausführen

=> dort reinschreiben

ComboFix /Uninstall => Enter drücken

Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch daraus die Schädlinge verschwinden. Es wird ein neuer Systemwiederherstellungspunkt erstellt. Gleichzeitig setzt Combofix die Zeiteinstellungen wieder auf die Ursprungseinstellungen, und setzt die Systemeinstellungen wieder so zurück, dass Dateierweiterungen und Systemdateien versteckt sind, was Du bei Bedarf im Explorer unter Extras => Ordneroptionen aber wieder ändern bzw. Deinen persönlichen Vorlieben entsprechend anpassen kannst.


danach:

TDSSKiller von Kaspersky
- Lade den TDSSKiller und entpacke das Archiv auf Deinen Desktop.
- Vergewissere Dich, dass die TDSSKiller.exe direkt auf dem Desktop liegt (nicht in einem Ordner auf dem Desktop).
- deaktiviere vorübergehend dein AntiVirus-Programm
- Starte die TDSSKiller.exe durch Doppelklick.
- Nach Beendigung der Arbeit schlägt das Tool vor, das System neu zu starten.
- Bestätige das ggfs. mit Y(es).
- Beim Hochfahren des Systems führt der Treiber alle geplanten Operationen aus löscht sich danach.
- Poste den Inhalt von C:\TDSSKiller.txt hier in den Thread.
Hier findest Du eine ausführlichere TDSSKiller Anleitung.

petemq 22.07.2012 21:16

Ich hab alles so gemacht, wei gesagt, jedoch hat der TDSSkiller mir keinen Systemneustart angeboten (und auch keine Threads gefunden).
Ich habe das System manuell neugestartet und den Schutz reaktiviert.

Der Bericht (TDSS):
Code:

22:02:10.0265 3216        TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
22:02:12.0272 3216        ============================================================
22:02:12.0272 3216        Current date / time: 2012/07/22 22:02:12.0272
22:02:12.0272 3216        SystemInfo:
22:02:12.0272 3216       
22:02:12.0273 3216        OS Version: 6.1.7601 ServicePack: 1.0
22:02:12.0273 3216        Product type: Workstation
22:02:12.0273 3216        ComputerName: LESSING
22:02:12.0275 3216        UserName: admin
22:02:12.0275 3216        Windows directory: C:\windows
22:02:12.0275 3216        System windows directory: C:\windows
22:02:12.0275 3216        Running under WOW64
22:02:12.0275 3216        Processor architecture: Intel x64
22:02:12.0275 3216        Number of processors: 4
22:02:12.0275 3216        Page size: 0x1000
22:02:12.0275 3216        Boot type: Normal boot
22:02:12.0275 3216        ============================================================
22:02:12.0802 3216        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:02:12.0810 3216        ============================================================
22:02:12.0810 3216        \Device\Harddisk0\DR0:
22:02:12.0810 3216        MBR partitions:
22:02:12.0810 3216        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1D4C000
22:02:12.0810 3216        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D7E800, BlocksNum 0x38607030
22:02:12.0810 3216        ============================================================
22:02:12.0838 3216        C: <-> \Device\Harddisk0\DR0\Partition1
22:02:12.0838 3216        ============================================================
22:02:12.0838 3216        Initialize success
22:02:12.0838 3216        ============================================================
22:02:35.0852 4832        ============================================================
22:02:35.0852 4832        Scan started
22:02:35.0852 4832        Mode: Manual;
22:02:35.0852 4832        ============================================================
22:02:36.0420 4832        1394ohci        (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
22:02:36.0426 4832        1394ohci - ok
22:02:36.0540 4832        a2acc          (2d6434e957f7cfa0035c20890f77bbc6) C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys
22:02:36.0543 4832        a2acc - ok
22:02:36.0657 4832        a2AntiMalware  (8b75ba256bcada2b73ffa5bd77aa9e6c) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
22:02:36.0680 4832        a2AntiMalware - ok
22:02:36.0700 4832        A2DDA          (3044d0f3feb9ffe8bc953d8f34b5b504) C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys
22:02:36.0701 4832        A2DDA - ok
22:02:36.0802 4832        Acceler        (e0065cbf1a25c015c218457d2cd522b9) C:\windows\system32\DRIVERS\Accelern.sys
22:02:36.0804 4832        Acceler - ok
22:02:36.0851 4832        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
22:02:36.0855 4832        ACPI - ok
22:02:36.0879 4832        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
22:02:36.0881 4832        AcpiPmi - ok
22:02:36.0993 4832        AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:02:36.0999 4832        AdobeFlashPlayerUpdateSvc - ok
22:02:37.0042 4832        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\drivers\adp94xx.sys
22:02:37.0047 4832        adp94xx - ok
22:02:37.0073 4832        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\drivers\adpahci.sys
22:02:37.0080 4832        adpahci - ok
22:02:37.0087 4832        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\drivers\adpu320.sys
22:02:37.0090 4832        adpu320 - ok
22:02:37.0113 4832        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
22:02:37.0114 4832        AeLookupSvc - ok
22:02:37.0177 4832        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
22:02:37.0187 4832        AFD - ok
22:02:37.0238 4832        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
22:02:37.0242 4832        agp440 - ok
22:02:37.0262 4832        ALG            (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
22:02:37.0265 4832        ALG - ok
22:02:37.0272 4832        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
22:02:37.0273 4832        aliide - ok
22:02:37.0288 4832        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
22:02:37.0290 4832        amdide - ok
22:02:37.0303 4832        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\drivers\amdk8.sys
22:02:37.0304 4832        AmdK8 - ok
22:02:37.0309 4832        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\drivers\amdppm.sys
22:02:37.0311 4832        AmdPPM - ok
22:02:37.0326 4832        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
22:02:37.0328 4832        amdsata - ok
22:02:37.0337 4832        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\drivers\amdsbs.sys
22:02:37.0339 4832        amdsbs - ok
22:02:37.0355 4832        amdxata        (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
22:02:37.0356 4832        amdxata - ok
22:02:37.0402 4832        AMPPAL          (7d9e301ab3247765702d0b65e2e47e50) C:\windows\system32\DRIVERS\AMPPAL.sys
22:02:37.0410 4832        AMPPAL - ok
22:02:37.0421 4832        AMPPALP        (7d9e301ab3247765702d0b65e2e47e50) C:\windows\system32\DRIVERS\amppal.sys
22:02:37.0426 4832        AMPPALP - ok
22:02:37.0553 4832        AMPPALR3        (864c632b999be1237a3dc46736e71f27) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
22:02:37.0562 4832        AMPPALR3 - ok
22:02:37.0639 4832        Amsp            (e8494519bcb9e3b1b72e5604993a76e3) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
22:02:37.0645 4832        Amsp - ok
22:02:37.0763 4832        AppID          (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
22:02:37.0766 4832        AppID - ok
22:02:37.0793 4832        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
22:02:37.0796 4832        AppIDSvc - ok
22:02:37.0828 4832        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
22:02:37.0829 4832        Appinfo - ok
22:02:37.0859 4832        AppMgmt        (4aba3e75a76195a3e38ed2766c962899) C:\windows\System32\appmgmts.dll
22:02:37.0865 4832        AppMgmt - ok
22:02:37.0887 4832        arc            (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\drivers\arc.sys
22:02:37.0890 4832        arc - ok
22:02:37.0903 4832        arcsas          (019af6924aefe7839f61c830227fe79c) C:\windows\system32\drivers\arcsas.sys
22:02:37.0907 4832        arcsas - ok
22:02:37.0938 4832        ASPI - ok
22:02:38.0028 4832        aspnet_state    (9217d874131ae6ff8f642f124f00a555) C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:02:38.0031 4832        aspnet_state - ok
22:02:38.0048 4832        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
22:02:38.0050 4832        AsyncMac - ok
22:02:38.0072 4832        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
22:02:38.0074 4832        atapi - ok
22:02:38.0137 4832        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
22:02:38.0148 4832        AudioEndpointBuilder - ok
22:02:38.0160 4832        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
22:02:38.0164 4832        AudioSrv - ok
22:02:38.0209 4832        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
22:02:38.0213 4832        AxInstSV - ok
22:02:38.0263 4832        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\windows\system32\drivers\bxvbda.sys
22:02:38.0270 4832        b06bdrv - ok
22:02:38.0296 4832        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
22:02:38.0301 4832        b57nd60a - ok
22:02:38.0344 4832        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
22:02:38.0346 4832        BDESVC - ok
22:02:38.0360 4832        Beep            (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
22:02:38.0361 4832        Beep - ok
22:02:38.0421 4832        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
22:02:38.0430 4832        BFE - ok
22:02:38.0489 4832        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\windows\system32\qmgr.dll
22:02:38.0502 4832        BITS - ok
22:02:38.0551 4832        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
22:02:38.0553 4832        blbdrive - ok
22:02:38.0696 4832        Bluetooth Device Monitor (5ff7b9916a10e8e69e7c0d16f0b4787a) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
22:02:38.0702 4832        Bluetooth Device Monitor - ok
22:02:38.0767 4832        Bluetooth Media Service (e43d73caf1023976efba1d0f0e69e271) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
22:02:38.0788 4832        Bluetooth Media Service - ok
22:02:38.0829 4832        Bluetooth OBEX Service (20427929646784a482df34ef8c4fed23) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
22:02:38.0835 4832        Bluetooth OBEX Service - ok
22:02:38.0946 4832        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
22:02:38.0949 4832        bowser - ok
22:02:38.0971 4832        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\drivers\BrFiltLo.sys
22:02:38.0973 4832        BrFiltLo - ok
22:02:38.0979 4832        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\drivers\BrFiltUp.sys
22:02:38.0981 4832        BrFiltUp - ok
22:02:38.0997 4832        BridgeMP        (5c2f352a4e961d72518261257aae204b) C:\windows\system32\DRIVERS\bridge.sys
22:02:38.0999 4832        BridgeMP - ok
22:02:39.0058 4832        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
22:02:39.0059 4832        Browser - ok
22:02:39.0094 4832        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
22:02:39.0096 4832        Brserid - ok
22:02:39.0105 4832        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
22:02:39.0106 4832        BrSerWdm - ok
22:02:39.0115 4832        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
22:02:39.0116 4832        BrUsbMdm - ok
22:02:39.0121 4832        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
22:02:39.0122 4832        BrUsbSer - ok
22:02:39.0155 4832        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\windows\system32\drivers\BthEnum.sys
22:02:39.0156 4832        BthEnum - ok
22:02:39.0161 4832        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys
22:02:39.0162 4832        BTHMODEM - ok
22:02:39.0176 4832        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\windows\system32\DRIVERS\bthpan.sys
22:02:39.0177 4832        BthPan - ok
22:02:39.0222 4832        BTHPORT        (64c198198501f7560ee41d8d1efa7952) C:\windows\system32\Drivers\BTHport.sys
22:02:39.0233 4832        BTHPORT - ok
22:02:39.0258 4832        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
22:02:39.0258 4832        bthserv - ok
22:02:39.0334 4832        BTHSSecurityMgr (9e2af97302b9f4bf97e952a865eb31ae) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
22:02:39.0337 4832        BTHSSecurityMgr - ok
22:02:39.0368 4832        BTHUSB          (f188b7394d81010767b6df3178519a37) C:\windows\system32\Drivers\BTHUSB.sys
22:02:39.0369 4832        BTHUSB - ok
22:02:39.0397 4832        btmaudio        (274e47bd9c1367bdbfa9df10c2e6c544) C:\windows\system32\drivers\btmaud.sys
22:02:39.0399 4832        btmaudio - ok
22:02:39.0436 4832        btmaux          (75eab5aaf6e9f83739249ce60b4b9c39) C:\windows\system32\DRIVERS\btmaux.sys
22:02:39.0438 4832        btmaux - ok
22:02:39.0478 4832        btmhsf          (0b1cc2221dc5990e4557a78ce9afad4f) C:\windows\system32\DRIVERS\btmhsf.sys
22:02:39.0484 4832        btmhsf - ok
22:02:39.0490 4832        catchme - ok
22:02:39.0532 4832        cdfs            (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
22:02:39.0534 4832        cdfs - ok
22:02:39.0577 4832        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\DRIVERS\cdrom.sys
22:02:39.0581 4832        cdrom - ok
22:02:39.0616 4832        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
22:02:39.0618 4832        CertPropSvc - ok
22:02:39.0637 4832        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\drivers\circlass.sys
22:02:39.0642 4832        circlass - ok
22:02:39.0677 4832        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
22:02:39.0681 4832        CLFS - ok
22:02:39.0743 4832        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:02:39.0747 4832        clr_optimization_v2.0.50727_32 - ok
22:02:39.0800 4832        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:02:39.0803 4832        clr_optimization_v2.0.50727_64 - ok
22:02:39.0872 4832        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:02:39.0876 4832        clr_optimization_v4.0.30319_32 - ok
22:02:39.0924 4832        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:02:39.0929 4832        clr_optimization_v4.0.30319_64 - ok
22:02:39.0963 4832        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
22:02:39.0964 4832        CmBatt - ok
22:02:39.0977 4832        cmdide          (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
22:02:39.0979 4832        cmdide - ok
22:02:40.0035 4832        CNG            (9ac4f97c2d3e93367e2148ea940cd2cd) C:\windows\system32\Drivers\cng.sys
22:02:40.0045 4832        CNG - ok
22:02:40.0139 4832        CnxtHdAudService (27e50947a5552b2c94b9f22ce8902811) C:\windows\system32\drivers\CHDRT64.sys
22:02:40.0153 4832        CnxtHdAudService - ok
22:02:40.0276 4832        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\windows\system32\drivers\compbatt.sys
22:02:40.0279 4832        Compbatt - ok
22:02:40.0304 4832        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\windows\system32\DRIVERS\CompositeBus.sys
22:02:40.0306 4832        CompositeBus - ok
22:02:40.0322 4832        COMSysApp - ok
22:02:40.0348 4832        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\windows\system32\drivers\crcdisk.sys
22:02:40.0349 4832        crcdisk - ok
22:02:40.0383 4832        CryptSvc        (4f5414602e2544a4554d95517948b705) C:\windows\system32\cryptsvc.dll
22:02:40.0387 4832        CryptSvc - ok
22:02:40.0423 4832        CSC            (54da3dfd29ed9f1619b6f53f3ce55e49) C:\windows\system32\drivers\csc.sys
22:02:40.0428 4832        CSC - ok
22:02:40.0450 4832        CscService      (3ab183ab4d2c79dcf459cd2c1266b043) C:\windows\System32\cscsvc.dll
22:02:40.0454 4832        CscService - ok
22:02:40.0493 4832        CtClsFlt        (bc3d4f90978cd7c8eabd1baf3bf7873a) C:\windows\system32\DRIVERS\CtClsFlt.sys
22:02:40.0496 4832        CtClsFlt - ok
22:02:40.0523 4832        CxAudMsg        (9f76a6e3a793e386f6b93c2632fe1ea8) C:\Windows\system32\CxAudMsg64.exe
22:02:40.0526 4832        CxAudMsg - ok
22:02:40.0584 4832        CxUtilSvc      (bf33586c8ddb9444f58521a68ad8db5c) C:\Program Files\Conexant\SA3\CxUtilSvc.exe
22:02:40.0585 4832        CxUtilSvc - ok
22:02:40.0647 4832        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
22:02:40.0651 4832        DcomLaunch - ok
22:02:40.0682 4832        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
22:02:40.0690 4832        defragsvc - ok
22:02:40.0723 4832        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
22:02:40.0725 4832        DfsC - ok
22:02:40.0755 4832        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
22:02:40.0758 4832        Dhcp - ok
22:02:40.0771 4832        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
22:02:40.0772 4832        discache - ok
22:02:40.0795 4832        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\drivers\disk.sys
22:02:40.0796 4832        Disk - ok
22:02:40.0831 4832        dmvsc          (5db085a8a6600be6401f2b24eecb5415) C:\windows\system32\drivers\dmvsc.sys
22:02:40.0832 4832        dmvsc - ok
22:02:40.0847 4832        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
22:02:40.0848 4832        Dnscache - ok
22:02:40.0865 4832        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
22:02:40.0869 4832        dot3svc - ok
22:02:40.0948 4832        DpHost          (c43618154fc0c8480f53b04ba7a2f371) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
22:02:40.0952 4832        DpHost - ok
22:02:40.0983 4832        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
22:02:40.0985 4832        DPS - ok
22:02:41.0009 4832        drmkaud        (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
22:02:41.0011 4832        drmkaud - ok
22:02:41.0086 4832        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
22:02:41.0100 4832        DXGKrnl - ok
22:02:41.0134 4832        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
22:02:41.0137 4832        EapHost - ok
22:02:41.0275 4832        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\drivers\evbda.sys
22:02:41.0306 4832        ebdrv - ok
22:02:41.0393 4832        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
22:02:41.0396 4832        EFS - ok
22:02:41.0465 4832        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
22:02:41.0481 4832        ehRecvr - ok
22:02:41.0510 4832        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
22:02:41.0510 4832        ehSched - ok
22:02:41.0574 4832        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\drivers\elxstor.sys
22:02:41.0587 4832        elxstor - ok
22:02:41.0594 4832        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
22:02:41.0596 4832        ErrDev - ok
22:02:41.0651 4832        esgiguard - ok
22:02:41.0736 4832        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
22:02:41.0743 4832        EventSystem - ok
22:02:41.0857 4832        EvtEng          (e3a96d5ae6e5c7b5472011ba77353368) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
22:02:41.0879 4832        EvtEng - ok
22:02:41.0979 4832        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
22:02:41.0984 4832        exfat - ok
22:02:42.0009 4832        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
22:02:42.0012 4832        fastfat - ok
22:02:42.0109 4832        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
22:02:42.0122 4832        Fax - ok
22:02:42.0159 4832        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\drivers\fdc.sys
22:02:42.0161 4832        fdc - ok
22:02:42.0177 4832        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
22:02:42.0178 4832        fdPHost - ok
22:02:42.0189 4832        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
22:02:42.0191 4832        FDResPub - ok
22:02:42.0208 4832        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
22:02:42.0210 4832        FileInfo - ok
22:02:42.0226 4832        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
22:02:42.0228 4832        Filetrace - ok
22:02:42.0240 4832        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\drivers\flpydisk.sys
22:02:42.0243 4832        flpydisk - ok
22:02:42.0258 4832        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
22:02:42.0263 4832        FltMgr - ok
22:02:42.0342 4832        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\windows\system32\FntCache.dll
22:02:42.0359 4832        FontCache - ok
22:02:42.0426 4832        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:02:42.0428 4832        FontCache3.0.0.0 - ok
22:02:42.0467 4832        FsDepends      (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
22:02:42.0470 4832        FsDepends - ok
22:02:42.0496 4832        Fs_Rec          (6bd9295cc032dd3077c671fccf579a7b) C:\windows\system32\drivers\Fs_Rec.sys
22:02:42.0498 4832        Fs_Rec - ok
22:02:42.0532 4832        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
22:02:42.0538 4832        fvevol - ok
22:02:42.0562 4832        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\drivers\gagp30kx.sys
22:02:42.0563 4832        gagp30kx - ok
22:02:42.0647 4832        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
22:02:42.0659 4832        gpsvc - ok
22:02:42.0690 4832        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
22:02:42.0692 4832        hcw85cir - ok
22:02:42.0729 4832        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
22:02:42.0733 4832        HdAudAddService - ok
22:02:42.0740 4832        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\DRIVERS\HDAudBus.sys
22:02:42.0742 4832        HDAudBus - ok
22:02:42.0746 4832        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\drivers\HidBatt.sys
22:02:42.0747 4832        HidBatt - ok
22:02:42.0765 4832        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys
22:02:42.0767 4832        HidBth - ok
22:02:42.0771 4832        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\drivers\hidir.sys
22:02:42.0772 4832        HidIr - ok
22:02:42.0795 4832        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\windows\System32\hidserv.dll
22:02:42.0796 4832        hidserv - ok
22:02:42.0813 4832        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\DRIVERS\hidusb.sys
22:02:42.0815 4832        HidUsb - ok
22:02:42.0868 4832        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
22:02:42.0872 4832        hkmsvc - ok
22:02:42.0899 4832        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
22:02:42.0901 4832        HomeGroupListener - ok
22:02:42.0927 4832        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
22:02:42.0929 4832        HomeGroupProvider - ok
22:02:42.0946 4832        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
22:02:42.0949 4832        HpSAMD - ok
22:02:42.0999 4832        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
22:02:43.0015 4832        HTTP - ok
22:02:43.0042 4832        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
22:02:43.0043 4832        hwpolicy - ok
22:02:43.0051 4832        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys
22:02:43.0054 4832        i8042prt - ok
22:02:43.0157 4832        iaStor          (53cc5bf8b5a219119953c7abb19a7705) C:\windows\system32\DRIVERS\iaStor.sys
22:02:43.0164 4832        iaStor - ok
22:02:43.0269 4832        IAStorDataMgrSvc (f5c0317af600f8c0d7e4202eb04232b1) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
22:02:43.0270 4832        IAStorDataMgrSvc - ok
22:02:43.0302 4832        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
22:02:43.0306 4832        iaStorV - ok
22:02:43.0347 4832        iBtFltCoex      (8a4ec1c3f10385181b1066120c610ae5) C:\windows\system32\DRIVERS\iBtFltCoex.sys
22:02:43.0349 4832        iBtFltCoex - ok
22:02:43.0451 4832        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:02:43.0469 4832        idsvc - ok
22:02:43.0865 4832        igfx            (9937600a1584ff00565d5379eb4c9edb) C:\windows\system32\DRIVERS\igdkmd64.sys
22:02:44.0077 4832        igfx - ok
22:02:44.0190 4832        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\drivers\iirsp.sys
22:02:44.0192 4832        iirsp - ok
22:02:44.0252 4832        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
22:02:44.0266 4832        IKEEXT - ok
22:02:44.0310 4832        intaud_WaveExtensible (caddf0927dac63edae48f5c35a61d87d) C:\windows\system32\drivers\intelaud.sys
22:02:44.0313 4832        intaud_WaveExtensible - ok
22:02:44.0374 4832        IntcDAud        (fc727061c0f47c8059e88e05d5c8e381) C:\windows\system32\DRIVERS\IntcDAud.sys
22:02:44.0382 4832        IntcDAud - ok
22:02:44.0393 4832        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
22:02:44.0395 4832        intelide - ok
22:02:44.0416 4832        intelppm        (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
22:02:44.0417 4832        intelppm - ok
22:02:44.0449 4832        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
22:02:44.0453 4832        IPBusEnum - ok
22:02:44.0462 4832        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
22:02:44.0465 4832        IpFilterDriver - ok
22:02:44.0496 4832        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
22:02:44.0504 4832        iphlpsvc - ok
22:02:44.0528 4832        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
22:02:44.0529 4832        IPMIDRV - ok
22:02:44.0535 4832        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
22:02:44.0537 4832        IPNAT - ok
22:02:44.0555 4832        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
22:02:44.0558 4832        IRENUM - ok
22:02:44.0566 4832        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
22:02:44.0568 4832        isapnp - ok
22:02:44.0639 4832        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
22:02:44.0646 4832        iScsiPrt - ok
22:02:44.0682 4832        iwdbus          (716f66336f10885d935b08174dc54242) C:\windows\system32\DRIVERS\iwdbus.sys
22:02:44.0684 4832        iwdbus - ok
22:02:44.0727 4832        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys
22:02:44.0729 4832        kbdclass - ok
22:02:44.0741 4832        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\DRIVERS\kbdhid.sys
22:02:44.0742 4832        kbdhid - ok
22:02:44.0782 4832        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:02:44.0783 4832        KeyIso - ok
22:02:44.0808 4832        KSecDD          (97a7070aea4c058b6418519e869a63b4) C:\windows\system32\Drivers\ksecdd.sys
22:02:44.0812 4832        KSecDD - ok
22:02:44.0838 4832        KSecPkg        (26c43a7c2862447ec59deda188d1da07) C:\windows\system32\Drivers\ksecpkg.sys
22:02:44.0839 4832        KSecPkg - ok
22:02:44.0849 4832        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
22:02:44.0850 4832        ksthunk - ok
22:02:44.0883 4832        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
22:02:44.0894 4832        KtmRm - ok
22:02:44.0933 4832        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\System32\srvsvc.dll
22:02:44.0935 4832        LanmanServer - ok
22:02:44.0977 4832        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
22:02:44.0983 4832        LanmanWorkstation - ok
22:02:45.0009 4832        lltdio          (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
22:02:45.0010 4832        lltdio - ok
22:02:45.0039 4832        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
22:02:45.0048 4832        lltdsvc - ok
22:02:45.0063 4832        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
22:02:45.0064 4832        lmhosts - ok
22:02:45.0173 4832        LMS            (1584deeae5aa0e3fb045f3d0eac585ea) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:02:45.0178 4832        LMS - ok
22:02:45.0203 4832        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\drivers\lsi_fc.sys
22:02:45.0205 4832        LSI_FC - ok
22:02:45.0219 4832        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\drivers\lsi_sas.sys
22:02:45.0220 4832        LSI_SAS - ok
22:02:45.0225 4832        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\drivers\lsi_sas2.sys
22:02:45.0226 4832        LSI_SAS2 - ok
22:02:45.0233 4832        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\drivers\lsi_scsi.sys
22:02:45.0234 4832        LSI_SCSI - ok
22:02:45.0259 4832        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
22:02:45.0261 4832        luafv - ok
22:02:45.0301 4832        MBAMProtector  (dc8490812a3b72811ae534f423b4c206) C:\windows\system32\drivers\mbam.sys
22:02:45.0304 4832        MBAMProtector - ok
22:02:45.0367 4832        MBAMService    (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Virenkiller\mbamservice.exe
22:02:45.0378 4832        MBAMService - ok
22:02:45.0490 4832        McAfee SiteAdvisor Service (be8c524313db75fa26fb2b0c0aaff88e) c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
22:02:45.0493 4832        McAfee SiteAdvisor Service - ok
22:02:45.0612 4832        McComponentHostService (22a7776c5d8eb5930edf9c8dd0884259) C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe
22:02:45.0618 4832        McComponentHostService - ok
22:02:45.0671 4832        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
22:02:45.0676 4832        Mcx2Svc - ok
22:02:45.0700 4832        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\drivers\megasas.sys
22:02:45.0702 4832        megasas - ok
22:02:45.0720 4832        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\drivers\MegaSR.sys
22:02:45.0723 4832        MegaSR - ok
22:02:45.0759 4832        MEIx64          (a6518dcc42f7a6e999bb3bea8fd87567) C:\windows\system32\DRIVERS\HECIx64.sys
22:02:45.0762 4832        MEIx64 - ok
22:02:45.0787 4832        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
22:02:45.0790 4832        MMCSS - ok
22:02:45.0804 4832        Modem          (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
22:02:45.0806 4832        Modem - ok
22:02:45.0824 4832        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
22:02:45.0825 4832        monitor - ok
22:02:45.0838 4832        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
22:02:45.0839 4832        mouclass - ok
22:02:45.0861 4832        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
22:02:45.0862 4832        mouhid - ok
22:02:45.0884 4832        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
22:02:45.0888 4832        mountmgr - ok
22:02:45.0952 4832        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:02:45.0956 4832        MozillaMaintenance - ok
22:02:45.0978 4832        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
22:02:45.0981 4832        mpio - ok
22:02:46.0003 4832        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
22:02:46.0006 4832        mpsdrv - ok
22:02:46.0081 4832        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\windows\system32\mpssvc.dll
22:02:46.0094 4832        MpsSvc - ok
22:02:46.0104 4832        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
22:02:46.0108 4832        MRxDAV - ok
22:02:46.0146 4832        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
22:02:46.0150 4832        mrxsmb - ok
22:02:46.0188 4832        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
22:02:46.0195 4832        mrxsmb10 - ok
22:02:46.0232 4832        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
22:02:46.0236 4832        mrxsmb20 - ok
22:02:46.0253 4832        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
22:02:46.0255 4832        msahci - ok
22:02:46.0274 4832        msdsm          (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
22:02:46.0276 4832        msdsm - ok
22:02:46.0295 4832        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
22:02:46.0301 4832        MSDTC - ok
22:02:46.0348 4832        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
22:02:46.0350 4832        Msfs - ok
22:02:46.0369 4832        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
22:02:46.0371 4832        mshidkmdf - ok
22:02:46.0385 4832        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
22:02:46.0386 4832        msisadrv - ok
22:02:46.0406 4832        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
22:02:46.0410 4832        MSiSCSI - ok
22:02:46.0417 4832        msiserver - ok
22:02:46.0438 4832        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
22:02:46.0439 4832        MSKSSRV - ok
22:02:46.0444 4832        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
22:02:46.0445 4832        MSPCLOCK - ok
22:02:46.0459 4832        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
22:02:46.0460 4832        MSPQM - ok
22:02:46.0483 4832        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
22:02:46.0487 4832        MsRPC - ok
22:02:46.0507 4832        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys
22:02:46.0508 4832        mssmbios - ok
22:02:46.0523 4832        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
22:02:46.0524 4832        MSTEE - ok
22:02:46.0528 4832        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\drivers\MTConfig.sys
22:02:46.0529 4832        MTConfig - ok
22:02:46.0545 4832        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
22:02:46.0548 4832        Mup - ok
22:02:46.0668 4832        MyWiFiDHCPDNS  (8f57db74bf5407a4cda6c8b005dc8dd0) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
22:02:46.0676 4832        MyWiFiDHCPDNS - ok
22:02:46.0722 4832        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
22:02:46.0735 4832        napagent - ok
22:02:46.0778 4832        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
22:02:46.0786 4832        NativeWifiP - ok
22:02:46.0829 4832        NDIS            (c38b8ae57f78915905064a9a24dc1586) C:\windows\system32\drivers\ndis.sys
22:02:46.0839 4832        NDIS - ok
22:02:46.0858 4832        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
22:02:46.0859 4832        NdisCap - ok
22:02:46.0878 4832        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
22:02:46.0879 4832        NdisTapi - ok
22:02:46.0896 4832        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
22:02:46.0899 4832        Ndisuio - ok
22:02:46.0912 4832        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
22:02:46.0916 4832        NdisWan - ok
22:02:46.0940 4832        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
22:02:46.0942 4832        NDProxy - ok
22:02:47.0105 4832        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:02:47.0120 4832        Nero BackItUp Scheduler 4.0 - ok
22:02:47.0144 4832        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
22:02:47.0145 4832        NetBIOS - ok
22:02:47.0167 4832        NetBT          (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
22:02:47.0169 4832        NetBT - ok
22:02:47.0196 4832        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:02:47.0199 4832        Netlogon - ok
22:02:47.0241 4832        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
22:02:47.0249 4832        Netman - ok
22:02:47.0358 4832        NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:02:47.0363 4832        NetMsmqActivator - ok
22:02:47.0370 4832        NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:02:47.0373 4832        NetPipeActivator - ok
22:02:47.0400 4832        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
22:02:47.0402 4832        netprofm - ok
22:02:47.0405 4832        NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:02:47.0406 4832        NetTcpActivator - ok
22:02:47.0410 4832        NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:02:47.0411 4832        NetTcpPortSharing - ok
22:02:47.0724 4832        NETwNs64        (50ad7f7040c22bb7caa59a0880875a21) C:\windows\system32\DRIVERS\NETwNs64.sys
22:02:47.0818 4832        NETwNs64 - ok
22:02:47.0922 4832        nfrd960        (77889813be4d166cdab78ddba990da92) C:\windows\system32\drivers\nfrd960.sys
22:02:47.0924 4832        nfrd960 - ok
22:02:47.0963 4832        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
22:02:47.0965 4832        NlaSvc - ok
22:02:48.0152 4832        NOBU            (b9b72faaaa41d59b73b88fe3dd737ed1) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
22:02:48.0166 4832        NOBU - ok
22:02:48.0202 4832        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
22:02:48.0203 4832        Npfs - ok
22:02:48.0221 4832        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
22:02:48.0225 4832        nsi - ok
22:02:48.0253 4832        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
22:02:48.0254 4832        nsiproxy - ok
22:02:48.0325 4832        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
22:02:48.0341 4832        Ntfs - ok
22:02:48.0374 4832        Null            (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
22:02:48.0375 4832        Null - ok
22:02:48.0400 4832        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
22:02:48.0403 4832        nvraid - ok
22:02:48.0411 4832        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
22:02:48.0414 4832        nvstor - ok
22:02:48.0422 4832        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
22:02:48.0424 4832        nv_agp - ok
22:02:48.0430 4832        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
22:02:48.0432 4832        ohci1394 - ok
22:02:48.0530 4832        ose            (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:02:48.0535 4832        ose - ok
22:02:48.0785 4832        osppsvc        (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
22:02:48.0849 4832        osppsvc - ok
22:02:48.0945 4832        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
22:02:48.0953 4832        p2pimsvc - ok
22:02:48.0985 4832        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
22:02:48.0988 4832        p2psvc - ok
22:02:49.0028 4832        Parport        (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\drivers\parport.sys
22:02:49.0032 4832        Parport - ok
22:02:49.0056 4832        partmgr        (e9766131eeade40a27dc27d2d68fba9c) C:\windows\system32\drivers\partmgr.sys
22:02:49.0058 4832        partmgr - ok
22:02:49.0072 4832        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
22:02:49.0074 4832        PcaSvc - ok
22:02:49.0091 4832        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
22:02:49.0093 4832        pci - ok
22:02:49.0096 4832        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
22:02:49.0097 4832        pciide - ok
22:02:49.0109 4832        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\drivers\pcmcia.sys
22:02:49.0112 4832        pcmcia - ok
22:02:49.0135 4832        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
22:02:49.0137 4832        pcw - ok
22:02:49.0167 4832        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
22:02:49.0174 4832        PEAUTH - ok
22:02:49.0248 4832        PeerDistSvc    (b9b0a4299dd2d76a4243f75fd54dc680) C:\windows\system32\peerdistsvc.dll
22:02:49.0264 4832        PeerDistSvc - ok
22:02:49.0330 4832        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
22:02:49.0333 4832        PerfHost - ok
22:02:49.0463 4832        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
22:02:49.0478 4832        pla - ok
22:02:49.0522 4832        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
22:02:49.0532 4832        PlugPlay - ok
22:02:49.0549 4832        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
22:02:49.0554 4832        PNRPAutoReg - ok
22:02:49.0580 4832        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
22:02:49.0583 4832        PNRPsvc - ok
22:02:49.0623 4832        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
22:02:49.0632 4832        PolicyAgent - ok
22:02:49.0664 4832        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
22:02:49.0666 4832        Power - ok
22:02:49.0725 4832        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
22:02:49.0729 4832        PptpMiniport - ok
22:02:49.0743 4832        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\drivers\processr.sys
22:02:49.0745 4832        Processor - ok
22:02:49.0784 4832        ProfSvc        (53e83f1f6cf9d62f32801cf66d8352a8) C:\windows\system32\profsvc.dll
22:02:49.0790 4832        ProfSvc - ok
22:02:49.0818 4832        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:02:49.0821 4832        ProtectedStorage - ok
22:02:49.0841 4832        Psched          (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
22:02:49.0843 4832        Psched - ok
22:02:49.0919 4832        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\drivers\ql2300.sys
22:02:49.0932 4832        ql2300 - ok
22:02:50.0009 4832        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\drivers\ql40xx.sys
22:02:50.0013 4832        ql40xx - ok
22:02:50.0038 4832        QWAVE          (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
22:02:50.0042 4832        QWAVE - ok
22:02:50.0060 4832        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
22:02:50.0061 4832        QWAVEdrv - ok
22:02:50.0065 4832        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
22:02:50.0066 4832        RasAcd - ok
22:02:50.0101 4832        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
22:02:50.0104 4832        RasAgileVpn - ok
22:02:50.0121 4832        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
22:02:50.0127 4832        RasAuto - ok
22:02:50.0143 4832        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
22:02:50.0145 4832        Rasl2tp - ok
22:02:50.0164 4832        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
22:02:50.0166 4832        RasMan - ok
22:02:50.0180 4832        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
22:02:50.0182 4832        RasPppoe - ok
22:02:50.0186 4832        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
22:02:50.0188 4832        RasSstp - ok
22:02:50.0202 4832        rdbss          (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
22:02:50.0205 4832        rdbss - ok
22:02:50.0232 4832        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys
22:02:50.0235 4832        rdpbus - ok
22:02:50.0249 4832        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
22:02:50.0250 4832        RDPCDD - ok
22:02:50.0278 4832        RDPDR          (1b6163c503398b23ff8b939c67747683) C:\windows\system32\drivers\rdpdr.sys
22:02:50.0280 4832        RDPDR - ok
22:02:50.0303 4832        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
22:02:50.0303 4832        RDPENCDD - ok
22:02:50.0308 4832        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
22:02:50.0309 4832        RDPREFMP - ok
22:02:50.0342 4832        RDPWD          (e61608aa35e98999af9aaeeea6114b0a) C:\windows\system32\drivers\RDPWD.sys
22:02:50.0347 4832        RDPWD - ok
22:02:50.0369 4832        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
22:02:50.0371 4832        rdyboost - ok
22:02:50.0491 4832        RegSrvc        (fd11c1287d38a46fb72353e14d50089c) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
22:02:50.0504 4832        RegSrvc - ok
22:02:50.0536 4832        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
22:02:50.0537 4832        RemoteAccess - ok
22:02:50.0564 4832        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
22:02:50.0571 4832        RemoteRegistry - ok
22:02:50.0657 4832        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\windows\system32\DRIVERS\rfcomm.sys
22:02:50.0661 4832        RFCOMM - ok
22:02:50.0684 4832        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
22:02:50.0685 4832        RpcEptMapper - ok
22:02:50.0694 4832        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
22:02:50.0695 4832        RpcLocator - ok
22:02:50.0719 4832        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
22:02:50.0722 4832        RpcSs - ok
22:02:50.0729 4832        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
22:02:50.0730 4832        rspndr - ok
22:02:50.0775 4832        RSUSBSTOR      (135a64530d7699ad48f29d73a658dd11) C:\windows\system32\Drivers\RtsUStor.sys
22:02:50.0782 4832        RSUSBSTOR - ok
22:02:50.0810 4832        RTL8167        (16d4e350420baa7e63e16e3fc033e1f5) C:\windows\system32\DRIVERS\Rt64win7.sys
22:02:50.0815 4832        RTL8167 - ok
22:02:50.0839 4832        s3cap          (e60c0a09f997826c7627b244195ab581) C:\windows\system32\drivers\vms3cap.sys
22:02:50.0840 4832        s3cap - ok
22:02:50.0863 4832        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:02:50.0866 4832        SamSs - ok
22:02:50.0891 4832        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
22:02:50.0893 4832        sbp2port - ok
22:02:50.0922 4832        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
22:02:50.0930 4832        SCardSvr - ok
22:02:50.0974 4832        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
22:02:50.0976 4832        scfilter - ok
22:02:51.0027 4832        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
22:02:51.0043 4832        Schedule - ok
22:02:51.0084 4832        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
22:02:51.0085 4832        SCPolicySvc - ok
22:02:51.0106 4832        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
22:02:51.0113 4832        SDRSVC - ok
22:02:51.0194 4832        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
22:02:51.0197 4832        secdrv - ok
22:02:51.0252 4832        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
22:02:51.0256 4832        seclogon - ok
22:02:51.0271 4832        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\windows\system32\sens.dll
22:02:51.0273 4832        SENS - ok
22:02:51.0279 4832        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
22:02:51.0280 4832        SensrSvc - ok
22:02:51.0302 4832        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\drivers\serenum.sys
22:02:51.0303 4832        Serenum - ok
22:02:51.0315 4832        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\drivers\serial.sys
22:02:51.0316 4832        Serial - ok
22:02:51.0328 4832        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\drivers\sermouse.sys
22:02:51.0329 4832        sermouse - ok
22:02:51.0375 4832        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
22:02:51.0381 4832        SessionEnv - ok
22:02:51.0391 4832        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
22:02:51.0392 4832        sffdisk - ok
22:02:51.0396 4832        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
22:02:51.0397 4832        sffp_mmc - ok
22:02:51.0402 4832        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
22:02:51.0403 4832        sffp_sd - ok
22:02:51.0437 4832        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\drivers\sfloppy.sys
22:02:51.0438 4832        sfloppy - ok
22:02:51.0494 4832        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
22:02:51.0504 4832        SharedAccess - ok
22:02:51.0533 4832        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
22:02:51.0535 4832        ShellHWDetection - ok
22:02:51.0559 4832        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\drivers\SiSRaid2.sys
22:02:51.0561 4832        SiSRaid2 - ok
22:02:51.0571 4832        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\drivers\sisraid4.sys
22:02:51.0572 4832        SiSRaid4 - ok
22:02:51.0767 4832        Skype C2C Service (0f97e7a47a52f4a36969f0fc319654c2) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:02:51.0794 4832        Skype C2C Service - ok
22:02:51.0885 4832        SkypeUpdate    (ea396139541706b4b433641d62ea53ce) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:02:51.0890 4832        SkypeUpdate - ok
22:02:51.0983 4832        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
22:02:51.0986 4832        Smb - ok
22:02:52.0040 4832        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
22:02:52.0045 4832        SNMPTRAP - ok
22:02:52.0066 4832        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
22:02:52.0068 4832        spldr - ok
22:02:52.0116 4832        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
22:02:52.0128 4832        Spooler - ok
22:02:52.0266 4832        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
22:02:52.0296 4832        sppsvc - ok
22:02:52.0369 4832        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
22:02:52.0375 4832        sppuinotify - ok
22:02:52.0415 4832        SpyHunter 4 Service - ok
22:02:52.0468 4832        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
22:02:52.0479 4832        srv - ok
22:02:52.0509 4832        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
22:02:52.0513 4832        srv2 - ok
22:02:52.0532 4832        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
22:02:52.0538 4832        srvnet - ok
22:02:52.0573 4832        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
22:02:52.0581 4832        SSDPSRV - ok
22:02:52.0603 4832        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
22:02:52.0604 4832        SstpSvc - ok
22:02:52.0622 4832        stdcfltn        (92e7f6666633d2dd91d527503daa7be0) C:\windows\system32\DRIVERS\stdcfltn.sys
22:02:52.0624 4832        stdcfltn - ok
22:02:52.0705 4832        Steam Client Service - ok
22:02:52.0737 4832        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\drivers\stexstor.sys
22:02:52.0739 4832        stexstor - ok
22:02:52.0791 4832        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
22:02:52.0801 4832        stisvc - ok
22:02:52.0833 4832        storflt        (7785dc213270d2fc066538daf94087e7) C:\windows\system32\drivers\vmstorfl.sys
22:02:52.0834 4832        storflt - ok
22:02:52.0853 4832        StorSvc        (c40841817ef57d491f22eb103da587cc) C:\windows\system32\storsvc.dll
22:02:52.0855 4832        StorSvc - ok
22:02:52.0871 4832        storvsc        (d34e4943d5ac096c8edeebfd80d76e23) C:\windows\system32\drivers\storvsc.sys
22:02:52.0873 4832        storvsc - ok
22:02:52.0888 4832        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys
22:02:52.0890 4832        swenum - ok
22:02:52.0974 4832        SwitchBoard    (f577910a133a592234ebaad3f3afa258) C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
22:02:52.0986 4832        SwitchBoard - ok
22:02:53.0038 4832        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
22:02:53.0051 4832        swprv - ok
22:02:53.0167 4832        SynTP          (b9dd56f953abdf85777e113ffe18fd5c) C:\windows\system32\DRIVERS\SynTP.sys
22:02:53.0188 4832        SynTP - ok
22:02:53.0325 4832        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
22:02:53.0343 4832        SysMain - ok
22:02:53.0392 4832        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
22:02:53.0394 4832        TabletInputService - ok
22:02:53.0714 4832        TabletServicePen (c4c20cfa4f42e9b7454e895c5c47bcd3) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
22:02:53.0745 4832        TabletServicePen - ok
22:02:53.0798 4832        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
22:02:53.0807 4832        TapiSrv - ok
22:02:53.0830 4832        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
22:02:53.0832 4832        TBS - ok
22:02:53.0942 4832        Tcpip          (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\drivers\tcpip.sys
22:02:53.0958 4832        Tcpip - ok
22:02:54.0060 4832        TCPIP6          (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\DRIVERS\tcpip.sys
22:02:54.0069 4832        TCPIP6 - ok
22:02:54.0114 4832        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
22:02:54.0116 4832        tcpipreg - ok
22:02:54.0134 4832        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
22:02:54.0148 4832        TDPIPE - ok
22:02:54.0175 4832        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
22:02:54.0176 4832        TDTCP - ok
22:02:54.0232 4832        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
22:02:54.0236 4832        tdx - ok
22:02:54.0266 4832        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\DRIVERS\termdd.sys
22:02:54.0268 4832        TermDD - ok
22:02:54.0406 4832        TermService    (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
22:02:54.0420 4832        TermService - ok
22:02:54.0504 4832        Themes          (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
22:02:54.0509 4832        Themes - ok
22:02:54.0551 4832        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
22:02:54.0554 4832        THREADORDER - ok
22:02:54.0649 4832        tihub3          (68fe3d89829e27d4fd5eea7bd2c41985) C:\windows\system32\DRIVERS\tihub3.sys
22:02:54.0653 4832        tihub3 - ok
22:02:54.0877 4832        tixhci          (0102c9633ce1f18a6ac021f28b734db5) C:\windows\system32\DRIVERS\tixhci.sys
22:02:54.0887 4832        tixhci - ok
22:02:54.0978 4832        tmactmon        (89dc033f4ee8f171826b1845c2136033) C:\windows\system32\DRIVERS\tmactmon.sys
22:02:55.0000 4832        tmactmon - ok
22:02:55.0040 4832        tmcomm          (6af3002be88c56382cd87aa0884d7d30) C:\windows\system32\DRIVERS\tmcomm.sys
22:02:55.0044 4832        tmcomm - ok
22:02:55.0072 4832        tmevtmgr        (063b2c13f62f873e14c29a223c409ad8) C:\windows\system32\DRIVERS\tmevtmgr.sys
22:02:55.0074 4832        tmevtmgr - ok
22:02:55.0175 4832        tmlwf          (5922b1f5741bbdbaf7f7b4cbd2b7c4a5) C:\windows\system32\DRIVERS\tmlwf.sys
22:02:55.0191 4832        tmlwf - ok
22:02:55.0273 4832        tmtdi          (e5021a4a72204c15c52c546f9301baef) C:\windows\system32\DRIVERS\tmtdi.sys
22:02:55.0280 4832        tmtdi - ok
22:02:55.0339 4832        tmwfp          (0a2e3899cc72ad4cc85ea3d50a5331cc) C:\windows\system32\DRIVERS\tmwfp.sys
22:02:55.0347 4832        tmwfp - ok
22:02:55.0468 4832        TouchServicePen (7625dcf246e488e523dc1f64c38abda2) C:\Program Files\Tablet\Pen\Pen_TouchService.exe
22:02:55.0477 4832        TouchServicePen - ok
22:02:55.0507 4832        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
22:02:55.0508 4832        TrkWks - ok
22:02:55.0565 4832        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\windows\servicing\TrustedInstaller.exe
22:02:55.0570 4832        TrustedInstaller - ok
22:02:55.0607 4832        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
22:02:55.0608 4832        tssecsrv - ok
22:02:55.0629 4832        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
22:02:55.0632 4832        TsUsbFlt - ok
22:02:55.0642 4832        TsUsbGD        (9cc2ccae8a84820eaecb886d477cbcb8) C:\windows\system32\drivers\TsUsbGD.sys
22:02:55.0644 4832        TsUsbGD - ok
22:02:55.0675 4832        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
22:02:55.0677 4832        tunnel - ok
22:02:55.0730 4832        TurboB          (fd24f98d2898be093fe926604be7db99) C:\windows\system32\DRIVERS\TurboB.sys
22:02:55.0732 4832        TurboB - ok
22:02:55.0761 4832        TurboBoost      (600b406a04d90f577fea8a88d7379f08) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
22:02:55.0766 4832        TurboBoost - ok
22:02:55.0776 4832        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\drivers\uagp35.sys
22:02:55.0780 4832        uagp35 - ok
22:02:55.0799 4832        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
22:02:55.0803 4832        udfs - ok
22:02:55.0836 4832        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\windows\system32\UI0Detect.exe
22:02:55.0838 4832        UI0Detect - ok
22:02:55.0844 4832        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
22:02:55.0845 4832        uliagpkx - ok
22:02:55.0859 4832        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\DRIVERS\umbus.sys
22:02:55.0861 4832        umbus - ok
22:02:55.0878 4832        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys
22:02:55.0879 4832        UmPass - ok
22:02:55.0920 4832        UmRdpService    (a293dcd756d04d8492a750d03b9a297c) C:\windows\System32\umrdp.dll
22:02:55.0925 4832        UmRdpService - ok
22:02:56.0129 4832        UNS            (fc43877b4625f6eb773c98233eb625c5) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:02:56.0141 4832        UNS - ok
22:02:56.0250 4832        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\windows\System32\upnphost.dll
22:02:56.0259 4832        upnphost - ok
22:02:56.0330 4832        usbaudio        (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\windows\system32\drivers\usbaudio.sys
22:02:56.0334 4832        usbaudio - ok
22:02:56.0372 4832        usbccgp        (19ad7990c0b67e48dac5b26f99628223) C:\windows\system32\DRIVERS\usbccgp.sys
22:02:56.0376 4832        usbccgp - ok
22:02:56.0411 4832        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
22:02:56.0414 4832        usbcir - ok
22:02:56.0438 4832        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\DRIVERS\usbehci.sys
22:02:56.0439 4832        usbehci - ok
22:02:56.0489 4832        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\DRIVERS\usbhub.sys
22:02:56.0495 4832        usbhub - ok
22:02:56.0502 4832        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
22:02:56.0504 4832        usbohci - ok
22:02:56.0523 4832        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\drivers\usbprint.sys
22:02:56.0524 4832        usbprint - ok
22:02:56.0538 4832        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
22:02:56.0539 4832        USBSTOR - ok
22:02:56.0545 4832        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
22:02:56.0546 4832        usbuhci - ok
22:02:56.0566 4832        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\windows\system32\Drivers\usbvideo.sys
22:02:56.0569 4832        usbvideo - ok
22:02:56.0607 4832        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\windows\System32\uxsms.dll
22:02:56.0610 4832        UxSms - ok
22:02:56.0648 4832        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:02:56.0651 4832        VaultSvc - ok
22:02:56.0795 4832        vcsFPService    (8c51e58d59cbf2639832484ec9ed8dda) C:\Windows\system32\vcsFPService.exe
22:02:56.0810 4832        vcsFPService - ok
22:02:56.0911 4832        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
22:02:56.0914 4832        vdrvroot - ok
22:02:56.0957 4832        vds            (8d6b481601d01a456e75c3210f1830be) C:\windows\System32\vds.exe
22:02:56.0964 4832        vds - ok
22:02:56.0989 4832        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
22:02:56.0991 4832        vga - ok
22:02:57.0015 4832        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
22:02:57.0017 4832        VgaSave - ok
22:02:57.0025 4832        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
22:02:57.0028 4832        vhdmp - ok
22:02:57.0041 4832        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
22:02:57.0043 4832        viaide - ok
22:02:57.0079 4832        vmbus          (86ea3e79ae350fea5331a1303054005f) C:\windows\system32\drivers\vmbus.sys
22:02:57.0082 4832        vmbus - ok
22:02:57.0091 4832        VMBusHID        (7de90b48f210d29649380545db45a187) C:\windows\system32\drivers\VMBusHID.sys
22:02:57.0094 4832        VMBusHID - ok
22:02:57.0122 4832        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
22:02:57.0124 4832        volmgr - ok
22:02:57.0138 4832        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
22:02:57.0142 4832        volmgrx - ok
22:02:57.0162 4832        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\windows\system32\drivers\volsnap.sys
22:02:57.0166 4832        volsnap - ok
22:02:57.0187 4832        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\drivers\vsmraid.sys
22:02:57.0189 4832        vsmraid - ok
22:02:57.0268 4832        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\windows\system32\vssvc.exe
22:02:57.0277 4832        VSS - ok
22:02:57.0377 4832        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
22:02:57.0379 4832        vwifibus - ok
22:02:57.0427 4832        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
22:02:57.0430 4832        vwififlt - ok
22:02:57.0449 4832        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\windows\system32\DRIVERS\vwifimp.sys
22:02:57.0451 4832        vwifimp - ok
22:02:57.0476 4832        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\windows\system32\w32time.dll
22:02:57.0483 4832        W32Time - ok
22:02:57.0513 4832        wacmoumonitor  (fe75777289278a4941fe6139e82b3bd9) C:\windows\system32\DRIVERS\wacmoumonitor.sys
22:02:57.0514 4832        wacmoumonitor - ok
22:02:57.0540 4832        wacommousefilter (e04d43c7d1641e95d35cae6086c7e350) C:\windows\system32\DRIVERS\wacommousefilter.sys
22:02:57.0542 4832        wacommousefilter - ok
22:02:57.0561 4832        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\drivers\wacompen.sys
22:02:57.0564 4832        WacomPen - ok
22:02:57.0582 4832        wacomvhid      (ec1ceb237e365330c1fcfc4876aa0ac0) C:\windows\system32\DRIVERS\wacomvhid.sys
22:02:57.0584 4832        wacomvhid - ok
22:02:57.0607 4832        WANARP          (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
22:02:57.0611 4832        WANARP - ok
22:02:57.0619 4832        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
22:02:57.0621 4832        Wanarpv6 - ok
22:02:57.0714 4832        WatAdminSvc    (3cec96de223e49eaae3651fcf8faea6c) C:\windows\system32\Wat\WatAdminSvc.exe
22:02:57.0726 4832        WatAdminSvc - ok
22:02:57.0800 4832        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\windows\system32\wbengine.exe
22:02:57.0818 4832        wbengine - ok
22:02:57.0897 4832        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\windows\System32\wbiosrvc.dll
22:02:57.0906 4832        WbioSrvc - ok
22:02:57.0928 4832        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\windows\System32\wcncsvc.dll
22:02:57.0931 4832        wcncsvc - ok
22:02:57.0957 4832        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\windows\System32\WcsPlugInService.dll
22:02:57.0961 4832        WcsPlugInService - ok
22:02:57.0998 4832        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\drivers\wd.sys
22:02:58.0000 4832        Wd - ok
22:02:58.0038 4832        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
22:02:58.0049 4832        Wdf01000 - ok
22:02:58.0061 4832        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
22:02:58.0062 4832        WdiServiceHost - ok
22:02:58.0065 4832        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
22:02:58.0067 4832        WdiSystemHost - ok
22:02:58.0080 4832        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\windows\System32\webclnt.dll
22:02:58.0084 4832        WebClient - ok
22:02:58.0096 4832        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\windows\system32\wecsvc.dll
22:02:58.0100 4832        Wecsvc - ok
22:02:58.0110 4832        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\windows\System32\wercplsupport.dll
22:02:58.0111 4832        wercplsupport - ok
22:02:58.0132 4832        WerSvc          (6d137963730144698cbd10f202e9f251) C:\windows\System32\WerSvc.dll
22:02:58.0134 4832        WerSvc - ok
22:02:58.0149 4832        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
22:02:58.0149 4832        WfpLwf - ok
22:02:58.0179 4832        WimFltr        (b14ef15bd757fa488f9c970eee9c0d35) C:\windows\system32\DRIVERS\wimfltr.sys
22:02:58.0183 4832        WimFltr - ok
22:02:58.0196 4832        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
22:02:58.0198 4832        WIMMount - ok
22:02:58.0256 4832        WinDefend - ok
22:02:58.0275 4832        WinHttpAutoProxySvc - ok
22:02:58.0329 4832        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\windows\system32\wbem\WMIsvc.dll
22:02:58.0333 4832        Winmgmt - ok
22:02:58.0438 4832        WinRM          (bcb1310604aa415c4508708975b3931e) C:\windows\system32\WsmSvc.dll
22:02:58.0457 4832        WinRM - ok
22:02:58.0572 4832        WinUSB          (fe88b288356e7b47b74b13372add906d) C:\windows\system32\DRIVERS\WinUSB.sys
22:02:58.0575 4832        WinUSB - ok
22:02:58.0688 4832        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\windows\System32\wlansvc.dll
22:02:58.0705 4832        Wlansvc - ok
22:02:58.0773 4832        wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
22:02:58.0776 4832        wlcrasvc - ok
22:02:58.0918 4832        wlidsvc        (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:02:58.0929 4832        wlidsvc - ok
22:02:59.0037 4832        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys
22:02:59.0039 4832        WmiAcpi - ok
22:02:59.0095 4832        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\windows\system32\wbem\WmiApSrv.exe
22:02:59.0101 4832        wmiApSrv - ok
22:02:59.0167 4832        WMPNetworkSvc - ok
22:02:59.0206 4832        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\windows\System32\wpcsvc.dll
22:02:59.0212 4832        WPCSvc - ok
22:02:59.0234 4832        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\windows\system32\wpdbusenum.dll
22:02:59.0237 4832        WPDBusEnum - ok
22:02:59.0253 4832        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
22:02:59.0255 4832        ws2ifsl - ok
22:02:59.0269 4832        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\windows\system32\wscsvc.dll
22:02:59.0270 4832        wscsvc - ok
22:02:59.0273 4832        WSearch - ok
22:02:59.0393 4832        wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\windows\system32\wuaueng.dll
22:02:59.0430 4832        wuauserv - ok
22:02:59.0523 4832        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
22:02:59.0527 4832        WudfPf - ok
22:02:59.0569 4832        WUDFRd          (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
22:02:59.0574 4832        WUDFRd - ok
22:02:59.0606 4832        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\windows\System32\WUDFSvc.dll
22:02:59.0612 4832        wudfsvc - ok
22:02:59.0630 4832        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\windows\System32\wwansvc.dll
22:02:59.0638 4832        WwanSvc - ok
22:02:59.0678 4832        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:02:59.0849 4832        \Device\Harddisk0\DR0 - ok
22:02:59.0855 4832        Boot (0x1200)  (b4a651ea79a9998884da67ecffb5e2e7) \Device\Harddisk0\DR0\Partition0
22:02:59.0858 4832        \Device\Harddisk0\DR0\Partition0 - ok
22:02:59.0875 4832        Boot (0x1200)  (9353cf31a6ec515e78353d1600509a2f) \Device\Harddisk0\DR0\Partition1
22:02:59.0878 4832        \Device\Harddisk0\DR0\Partition1 - ok
22:02:59.0879 4832        ============================================================
22:02:59.0879 4832        Scan finished
22:02:59.0879 4832        ============================================================
22:02:59.0888 5480        Detected object count: 0
22:02:59.0888 5480        Actual detected object count: 0


t'john 22.07.2012 21:20

Sehr gut! :daumenhoc


Java aktualisieren

Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 7 Update 5 ) herunter laden.
  • Wenn die Installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Hacken gesetzt ist und klicke OK.
  • Klicke erneut OK.


Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html

petemq 22.07.2012 22:47

Auch erledigt :)

t'john 22.07.2012 23:13

Sehr gut! :daumenhoc

damit bist Du sauber und entlassen! :)


Aufräumern mit CCleaner

Lasse mit CCleaner (Download) (Anleitung) Fehler in der
  • Registry beheben (mehrmals, solange bis keine Fehler mehr gefunden werden) und
  • temporäre Dateien löschen.


Tool-Bereinigung mit OTL


Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
  • Bitte lade Dir (falls noch nicht vorhanden) OTL von OldTimer herunter.
  • Speichere es auf Deinem Desktop.
  • Doppelklick auf OTL.exe um das Programm auszuführen.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Klicke auf den Button "Bereinigung"
  • OTL fragt eventuell nach einem Neustart.
    Sollte es dies tun, so lasse dies bitte zu.
Anmerkung: Nach dem Neustart werden OTL und andere Helferprogramme, die Du im Laufe der Bereinigung heruntergeladen hast, nicht mehr vorhanden sein. Sie wurden entfernt. Es ist daher Ok, wenn diese Programme nicht mehr vorhanden sind. Sollten noch welche übrig geblieben sein, lösche sie manuell.


Lektuere zum abarbeiten:
http://www.trojaner-board.de/90880-d...tallation.html
http://www.trojaner-board.de/105213-...tellungen.html
PluginCheck
http://www.trojaner-board.de/96344-a...-rechners.html
Secunia Online Software Inspector
http://www.trojaner-board.de/71715-k...iendungen.html
http://www.trojaner-board.de/83238-a...sschalten.html

petemq 22.07.2012 23:59

Juhu! :Boogie:

Soweit ausgeführt, nur das Beseitigen der Registry-Fehler habe ich gelassen (nachdem ich mir die Anleitungen der Software durchgelesen habe, die betonte dass ein Systemausfall entstehen könne, der Nutzen jedoch quasi null sei).

Meinst du, mein derzeitiges Antivirensystem (Trend Micro Titanium Internet Security, Windows Defender, Windows Firewall, McAfee Site Advisor) reicht aus, um mich ausreichend zu schützen?

Ansonsten ein ganz dickes :dankeschoen: für deine Hilfe!

t'john 23.07.2012 00:04

Zitat:

Soweit ausgeführt, nur das Beseitigen der Registry-Fehler habe ich gelassen (nachdem ich mir die Anleitungen der Software durchgelesen habe, die betonte dass ein Systemausfall entstehen könne, der Nutzen jedoch quasi null sei).
Ich kenne die Anleitung, man soll es nicht zum Spass machen.
Ich empfehle es dennoch jetzt zu machen.

Zitat:

Meinst du, mein derzeitiges Antivirensystem (Trend Micro Titanium Internet Security, Windows Defender, Windows Firewall, McAfee Site Advisor) reicht aus, um mich ausreichend zu schützen?
Alles Bloedsinn.
Du brauchst: Alle Updates, Windows Firewall, Microsoft Security Essentials - Kostenloser Virenschutz für Windows
Den Rest schmeisst du weg.


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:07 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131