msa.exe und ständige PopUp's sowie Antivir Meldungen |
||
---|---|---|
#0
| ||
28.01.2010, 13:54
Member
Beiträge: 60 |
||
|
||
28.01.2010, 16:15
Member
Beiträge: 3716 |
#2
http://board.protecus.de/t23187.htm
bitte noch combofix ausführen, log posten. dann gmer mit rechtsklick als admin starten. |
|
|
||
28.01.2010, 16:18
Member
Themenstarter Beiträge: 60 |
#3
gmer stürzt wenn ich mit rechtsklick - admin ausführe immer ab, sogar im agbesicherten modus
vielleicht nach dem comofix nicht |
|
|
||
28.01.2010, 16:54
Member
Themenstarter Beiträge: 60 |
#4
das combofix hat super geklappt, aber gmer ist mir wieder abgestürzt (siehe anhang)
hier das combofix log: ComboFix 10-01-27.06 - Drago 28.01.2010 16:28:17.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3036.1989 [GMT 1:00] ausgeführt von:: c:\users\Drago\Desktop\test.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ADS - Windows: deleted 96 bytes in 1 streams. (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-4032735365-608106937-2049815217-500 C:\LOG.TXT c:\program files\temp c:\users\Drago\AppData\Roaming\file1.exe c:\windows\system32\lsprst7.dll c:\windows\system32\nsprs.dll c:\windows\system32\prsgrc.dll c:\windows\system32\ssprs.dll . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_NPF ((((((((((((((((((((((( Dateien erstellt von 2009-12-28 bis 2010-01-28 )))))))))))))))))))))))))))))) . 2010-01-28 15:36 . 2010-01-28 15:36 -------- d-----w- c:\users\Mcx1-DRAGO-PC\AppData\Local\temp 2010-01-28 14:05 . 2010-01-28 14:05 -------- d-----w- c:\programdata\WindowsSearch 2010-01-27 22:57 . 2010-01-27 22:57 -------- d-----w- c:\users\Drago\AppData\Roaming\Malwarebytes 2010-01-27 22:57 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-27 22:57 . 2010-01-27 22:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-01-27 22:57 . 2010-01-27 22:57 -------- d-----w- c:\programdata\Malwarebytes 2010-01-27 22:57 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-01-27 22:40 . 2010-01-27 22:40 -------- d-----w- c:\program files\CCleaner 2010-01-27 22:38 . 2010-01-27 22:38 -------- d-----w- c:\program files\Trend Micro 2010-01-27 22:15 . 2010-01-27 22:15 -------- d-----w- c:\users\Drago\AppData\Roaming\MOVAVI 2010-01-27 22:13 . 2010-01-27 22:18 -------- d-----w- c:\program files\Movavi Video Suite 8 2010-01-27 22:12 . 2010-01-27 22:12 -------- d-----w- c:\users\Drago\AppData\Local\Downloaded Installations 2010-01-27 21:56 . 2010-01-27 21:56 -------- d-----w- c:\programdata\AVS4YOU 2010-01-27 21:54 . 2010-01-27 21:58 -------- d-----w- c:\program files\Common Files\AVSMedia 2010-01-27 21:54 . 2007-02-27 18:36 974848 ----a-w- c:\windows\system32\mfc70.dll 2010-01-27 21:54 . 2007-02-27 18:36 487424 ----a-w- c:\windows\system32\msvcp70.dll 2010-01-27 21:54 . 2010-01-27 21:58 -------- d-----w- c:\program files\AVS4YOU 2010-01-27 21:54 . 2007-02-27 18:36 344064 ----a-w- c:\windows\system32\msvcr70.dll 2010-01-27 21:54 . 2007-02-27 18:36 24576 ----a-w- c:\windows\system32\msxml3a.dll 2010-01-27 21:53 . 2010-01-27 21:53 -------- d-----w- C:\Drivers 2010-01-27 21:13 . 2010-01-27 21:27 -------- d-----w- c:\users\Drago\AppData\Roaming\Sytexis Software 2010-01-27 21:13 . 2010-01-27 21:37 -------- d-----w- c:\program files\Sytexis Software 2010-01-27 20:40 . 2010-01-27 20:40 -------- d-----w- c:\users\Drago\AppData\Local\Jaksta_LLC 2010-01-27 20:39 . 2010-01-27 20:40 -------- d-----w- c:\users\Drago\AppData\Roaming\Jaksta 2010-01-27 20:39 . 2010-01-27 20:39 -------- d-----w- c:\program files\Jaksta 2010-01-26 21:03 . 2010-01-26 21:03 -------- d-----w- c:\program files\Logitech Touch Mouse Server 2010-01-23 13:49 . 2010-01-23 13:49 -------- d-----w- c:\users\Drago\trash 2010-01-16 17:17 . 2008-04-07 04:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll 2010-01-15 02:01 . 2010-01-15 02:01 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2 2010-01-14 16:01 . 2010-01-22 17:18 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-13 18:46 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll 2010-01-13 18:46 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll 2010-01-11 19:47 . 2010-01-11 22:57 -------- d-----w- c:\program files\nettvplayer2.0 2010-01-11 16:49 . 2010-01-11 16:49 -------- d-----w- c:\users\Drago\.spss 2010-01-10 13:43 . 2010-01-10 13:43 -------- d-----w- c:\program files\WhereIsIt 2010-01-09 22:50 . 2010-01-09 22:50 -------- d-----w- c:\program files\MediaMonkey 2010-01-09 22:39 . 2010-01-09 22:39 -------- d-----w- c:\users\Birungueta 2010-01-09 22:39 . 2010-01-09 22:39 -------- d-----w- c:\users\Drago\AppData\Local\Thinstall 2010-01-09 22:16 . 2010-01-24 12:17 -------- d-----w- c:\users\Drago\AppData\Local\MediaMonkey 2010-01-07 08:44 . 2010-01-07 08:44 -------- d-----w- c:\users\Drago\AppData\Local\SPSS 15.0 für Windows [Auswertung Version] 2010-01-07 08:42 . 2010-01-07 08:42 1024 ----a-w- c:\windows\system32\clauth2.dll 2010-01-07 08:42 . 2010-01-07 08:42 1024 ----a-w- c:\windows\system32\clauth1.dll 2010-01-07 08:42 . 2006-05-10 10:15 1929216 ----a-w- c:\windows\system32\cdintf250.dll 2010-01-07 08:39 . 2010-01-23 08:26 -------- d-----w- c:\program files\SPSSEV-DE 2010-01-07 00:04 . 2010-01-07 00:04 -------- d-----w- c:\program files\RAR Password Recovery Magic 2010-01-06 18:34 . 2010-01-06 18:34 249856 ------w- c:\windows\Setup1.exe 2010-01-06 18:34 . 2010-01-06 18:34 73216 ----a-w- c:\windows\ST6UNST.EXE 2010-01-06 17:32 . 1999-03-23 08:12 299520 ----a-w- c:\windows\uninst.exe 2010-01-05 22:05 . 2010-01-07 18:49 -------- d-----w- c:\users\Drago\Karaoke 2010-01-05 20:08 . 2001-02-25 00:57 69632 ----a-w- c:\windows\system32\WGDRVR32.DLL 2010-01-05 20:08 . 2010-01-05 20:08 -------- d-----w- c:\program files\WinGroove 2010-01-05 20:06 . 2010-01-05 20:09 -------- d-----w- C:\WG0A4.TMP 2010-01-03 22:49 . 2010-01-27 20:34 -------- d-----w- c:\users\Drago\TV-Browser 2010-01-03 22:45 . 2010-01-03 22:45 -------- d-----w- c:\users\Drago\AppData\Roaming\Regensoft 2010-01-03 18:59 . 2010-01-03 19:11 -------- d-----w- c:\users\Drago\AppData\Roaming\DC++ 2010-01-03 18:59 . 2010-01-03 18:59 -------- d-----w- c:\users\Drago\AppData\Local\DC++ . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-01-28 15:29 . 2008-01-21 07:15 618442 ----a-w- c:\windows\system32\perfh007.dat 2010-01-28 15:29 . 2008-01-21 07:15 122842 ----a-w- c:\windows\system32\perfc007.dat 2010-01-27 23:01 . 2009-10-25 12:37 -------- d-----w- c:\users\Drago\AppData\Roaming\skypePM 2010-01-27 22:34 . 2009-10-25 12:36 -------- d-----w- c:\users\Drago\AppData\Roaming\Skype 2010-01-27 22:15 . 2009-11-04 15:31 -------- d-----w- c:\program files\NetTVPlus Player 2010-01-27 21:53 . 2009-06-05 08:23 -------- d-----w- c:\program files\Common Files\InstallShield 2010-01-25 00:58 . 2009-10-25 14:34 -------- d-----w- c:\users\Drago\AppData\Roaming\vlc 2010-01-24 23:57 . 2009-11-18 01:03 -------- d-----w- c:\users\Drago\AppData\Roaming\dvdcss 2010-01-24 23:47 . 2009-11-09 17:54 -------- d-----w- c:\program files\JDownloader 2010-01-23 13:31 . 2009-12-03 11:14 -------- d-----w- c:\users\Drago\AppData\Roaming\Apple Computer 2010-01-19 06:16 . 2009-10-26 19:25 80616 ----a-w- c:\users\Katarina\AppData\Local\GDIPFONTCACHEV1.DAT 2010-01-17 22:58 . 2009-10-26 18:12 -------- d-----w- c:\program files\Full Tilt Poker 2010-01-16 17:42 . 2009-10-24 21:55 80616 ----a-w- c:\users\Drago\AppData\Local\GDIPFONTCACHEV1.DAT 2010-01-16 00:04 . 2009-06-05 09:07 -------- d-----w- c:\program files\Microsoft Works 2010-01-14 10:12 . 2009-11-18 11:15 181120 ------w- c:\windows\system32\MpSigStub.exe 2010-01-13 22:14 . 2009-11-18 17:28 2516 --sha-w- c:\programdata\KGyGaAvL.sys 2010-01-13 22:14 . 2009-11-18 17:28 2516 --sha-w- c:\programdata\KGyGaAvL.sys 2010-01-09 22:39 . 2009-11-02 20:21 -------- d-----w- c:\users\Drago\AppData\Roaming\Thinstall 2010-01-05 20:23 . 2009-11-01 21:51 -------- d-----w- c:\program files\vanBasco's Karaoke Player 2010-01-03 22:38 . 2009-11-18 18:11 -------- d-----w- c:\program files\TPNet 2010-01-03 21:06 . 2010-01-03 21:06 177024 ----a-w- c:\users\Drago\AppData\Roaming\Mozilla\Firefox\Profiles\ct7w40o0.default\FlashGot.exe 2010-01-02 06:38 . 2010-01-22 17:24 916480 ----a-w- c:\windows\system32\wininet.dll 2010-01-02 06:32 . 2010-01-22 17:24 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-01-02 06:32 . 2010-01-22 17:24 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-01-02 04:57 . 2010-01-22 17:24 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-12-23 17:26 . 2009-12-23 17:26 -------- d-----w- c:\program files\Hugin 2009-12-22 22:16 . 2009-06-05 09:01 -------- d-----w- c:\program files\Google 2009-12-22 17:37 . 2009-11-02 23:39 -------- d-----w- c:\program files\Elaborate Bytes 2009-12-22 17:36 . 2009-12-22 17:33 -------- d-----w- c:\program files\Unlocker 2009-12-22 17:26 . 2009-11-05 22:47 -------- d-----w- c:\program files\SlySoft 2009-12-21 00:20 . 2009-12-21 00:20 -------- d-----w- c:\users\Katarina\AppData\Roaming\HP 2009-12-21 00:18 . 2009-12-21 00:18 -------- d-----w- c:\users\Katarina\AppData\Roaming\Alice Systems 2009-12-15 22:28 . 2009-10-29 22:05 -------- d-----w- c:\programdata\Apple 2009-12-08 02:03 . 2009-10-26 15:01 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-12-03 12:42 . 2009-12-03 10:51 -------- d-----w- c:\programdata\Rosetta Stone 2009-12-03 11:13 . 2009-12-03 11:12 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-12-03 11:13 . 2009-12-03 11:12 -------- d-----w- c:\program files\iTunes 2009-12-03 11:12 . 2009-12-03 11:12 -------- d-----w- c:\program files\iPod 2009-12-03 11:12 . 2009-12-03 11:11 -------- d-----w- c:\programdata\Apple Computer 2009-12-03 11:12 . 2009-12-03 11:07 -------- d-----w- c:\program files\Common Files\Apple 2009-12-03 11:12 . 2009-12-03 11:12 -------- d-----w- c:\program files\Bonjour 2009-12-03 11:11 . 2009-12-03 11:11 -------- d-----w- c:\program files\QuickTime 2009-12-03 11:10 . 2009-12-03 11:10 -------- d-----w- c:\program files\Apple Software Update 2009-12-03 10:51 . 2009-12-03 10:51 -------- d-----w- c:\program files\Rosetta Stone 2009-12-03 10:13 . 2009-12-03 10:13 -------- d-----w- c:\users\Drago\AppData\Roaming\gtk-2.0 2009-12-03 09:34 . 2009-12-03 09:34 48 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-12-03 09:18 . 2009-10-27 11:46 -------- d-----w- c:\program files\Common Files\SPSS 2009-12-03 09:18 . 2009-12-03 09:18 -------- d-----w- c:\programdata\SPSS 2009-12-01 22:06 . 2009-06-05 08:46 -------- d-----w- c:\program files\Java 2009-11-18 17:28 . 2009-11-18 17:28 8 --sh--r- c:\programdata\AFC2C51FF8.sys 2009-11-18 17:28 . 2009-11-18 17:28 8 --sh--r- c:\programdata\AFC2C51FF8.sys 2009-11-18 00:35 . 2009-11-18 00:35 40960 ----a-r- c:\users\Drago\AppData\Roaming\Microsoft\Installer\{E9E5845E-C2E1-4D8D-A2E1-46E6F7F68C68}\NewShortcut1_E9E5845EC2E14D8DA2E146E6F7F68C68.exe 2009-11-18 00:35 . 2009-11-18 00:35 40960 ----a-r- c:\users\Drago\AppData\Roaming\Microsoft\Installer\{E9E5845E-C2E1-4D8D-A2E1-46E6F7F68C68}\ARPPRODUCTICON.exe 2009-11-16 12:59 . 2009-11-16 12:59 4846 ----a-r- c:\users\Drago\AppData\Roaming\Microsoft\Installer\{37FD2F04-EC91-41AE-B5AB-AFF904BF20EE}\ARPPRODUCTICON.exe 2009-11-16 12:59 . 2009-11-16 12:59 67771 ----a-w- c:\windows\Novatel_V20025InstallerUninstall.exe 2009-11-16 12:56 . 2009-11-16 12:56 67727 ----a-w- c:\windows\OptionPluss_PCCardInstallerUninstall.exe 2009-11-16 12:56 . 2009-11-16 12:56 67719 ----a-w- c:\windows\OptionPCCardInstallerUninstall.exe 2009-11-16 12:27 . 2009-11-16 12:27 8464 ----a-w- c:\windows\system32\SpOrder.dll 2009-11-12 16:07 . 2009-11-12 16:07 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe 2009-11-09 12:31 . 2009-12-10 02:03 24064 ----a-w- c:\windows\system32\nshhttp.dll 2009-11-09 12:30 . 2009-12-10 02:03 30720 ----a-w- c:\windows\system32\httpapi.dll 2009-11-09 10:36 . 2009-12-10 02:03 411648 ----a-w- c:\windows\system32\drivers\http.sys 2009-11-04 22:26 . 2009-11-04 22:26 0 ----a-w- c:\windows\nsreg.dat 2009-11-02 20:21 . 2009-11-02 20:21 7168 ----a-w- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\f000000c100003i\ntvdm.exe 2009-11-02 20:21 . 2009-11-02 20:21 0 --sha-r- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\%drive_C%\MSDOS.SYS 2009-11-02 20:21 . 2009-11-02 20:21 0 --sha-r- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\%drive_C%\IO.SYS 2009-11-02 20:21 . 2009-11-02 20:21 7168 ----a-w- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\40000048600002i\WaveLab-app.exe 2009-11-02 19:46 . 2009-11-02 19:35 147906 ----a-w- c:\windows\hpoins12.dat 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-07-03 135680] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-30 7289376] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304] "ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336] "TUSBSleepChargeSrv"="c:\program files\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe" [2009-03-27 252288] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2007-04-16 421888] "SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2008-11-21 438272] "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2009-01-13 34088] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe" [2009-04-23 1011712] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-04-16 2513472] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-21 61440] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-03-06 468320] "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2009-03-09 55160] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-03-31 503808] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-03-23 729088] "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-04-01 1283384] "HDMICtrlMan"="c:\program files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe" [2009-04-07 811008] "TRCMan"="c:\program files\TOSHIBA\TRCMan\TRCMan.exe" [2008-11-26 701752] "TPCHWMsg"="c:\program files\TOSHIBA\TPHM\TPCHWMsg.exe" [2009-04-15 570736] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2009-09-05 385024] "CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600] "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-03-16 6158240] c:\users\Katarina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2009-2-24 391072] c:\users\Mcx1-DRAGO-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2009-2-24 391072] c:\users\Drago\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech Touch Mouse Server.lnk - c:\program files\Logitech Touch Mouse Server\iTouch-Server-Win.exe [2009-10-23 228352] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Automatic Update-Agent.lnk - c:\program files\T-Mobile\Communication Center\AutoUpdateSrv.exe [2009-11-16 499712] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\acaptuser32.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "MIDI2"=WGDRVR32.DLL "WAVE2"=WGDRVR32.DLL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cfFncEnabler.exe] 2009-03-24 11:53 16384 ----a-w- c:\program files\Toshiba\ConfigFree\cfFncEnabler.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NDSTray.exe] 2009-05-12 20:26 299008 ----a-w- c:\program files\Toshiba\ConfigFree\NDSTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartFaceVWatcher] 2009-03-24 17:33 163840 ----a-w- c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Teco] 2009-04-24 09:40 1323008 ----a-w- c:\program files\Toshiba\TECO\TEco.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2009-10-29 21:25 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration] 2009-03-04 13:53 96144 ----a-w- c:\program files\Toshiba\Registration\ToshibaReminder.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPRO] 2009-03-23 12:30 1045904 ----a-w- c:\program files\Toshiba TEMPRO\TemproTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant] 2009-10-26 07:33 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):7b,9f,7a,54,58,56,ca,01 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4032735365-608106937-2049815217-1000] "EnableNotificationsRef"=dword:00000001 R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\System32\drivers\thpdrv.sys [25.03.2009 16:23 30272] R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\System32\drivers\Thpevm.sys [04.09.2007 09:30 13336] R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [16.09.2008 12:03 169312] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [24.07.2009 10:08 176128] R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [26.10.2009 16:01 108289] R2 camsvc;TOSHIBA Web Camera Service;c:\program files\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe [05.06.2009 09:50 20544] R2 gtdetectsc;GtDetectSc Service;c:\windows\System32\Gtdetectsc.exe [16.11.2009 13:56 118784] R2 GtFlashSwitch;GtFlashSwitch;c:\program files\Common Files\GtFlashSwitch\GtFlashSwitch.exe [09.02.2007 13:48 176128] R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [23.03.2009 13:30 116104] R2 TMachInfo;TMachInfo;c:\program files\Toshiba\TOSHIBA Service Station\TMachInfo.exe [24.07.2009 10:26 62776] R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\Toshiba\TECO\TecoService.exe [24.04.2009 10:40 176128] R2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [17.03.2009 10:49 73728] R2 TPCHSrv;TPCH Service;c:\program files\Toshiba\TPHM\TPCHSrv.exe [15.04.2009 16:03 656752] R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\System32\drivers\TVALZFL.sys [20.03.2009 22:29 12920] R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [30.12.2008 11:18 57856] R3 enecirhid;ENE CIR HID Receiver;c:\windows\System32\drivers\enecirhid.sys [29.04.2008 00:56 11264] R3 enecirhidma;ENE CIR HIDmini Filter;c:\windows\System32\drivers\enecirhidma.sys [25.04.2008 08:16 5632] R3 JakNDisMP;JakNDisMP;c:\windows\System32\drivers\JakNDis.sys [11.05.2009 14:53 21504] R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17.11.2008 06:40 3668480] R3 PGEffect;Pangu effect driver;c:\windows\System32\drivers\PGEffect.sys [05.06.2009 09:50 22272] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10.11.2009 01:10 135664] S3 JakNDis;Jaksta Service;c:\windows\System32\drivers\JakNDis.sys [11.05.2009 14:53 21504] S3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [08.04.2009 15:36 114528] S4 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [10.03.2009 17:51 46448] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Inhalt des "geplante Tasks" Ordners 2010-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-10 00:10] 2010-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-10 00:10] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ uInternet Settings,ProxyOverride = *.local IE: An vorhandene PDF-Datei anfügen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/707-44556-9400-3/4 IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe Trusted Zone: btopenzone.com\www Trusted Zone: t-mobile.net\hotspot FF - ProfilePath - c:\users\Drago\AppData\Roaming\Mozilla\Firefox\Profiles\ct7w40o0.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Picasa2\npPicasa2.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - SafeBoot-mcmscsvc SafeBoot-MCODS ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-01-28 16:38 Windows 6.0.6002 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys thpdrv.sys hal.dll iaStor.sys spui.sys >>UNKNOWN [0x85CAE938]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0x8aa0cd24 \Driver\ACPI -> acpi.sys @ 0x805bbd68 \Driver\atapi -> 0x85cf81f8 \Driver\iaStor -> iaStor.sys @ 0x82af20b0 IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection ! user & kernel MBR OK ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- [HKEY_USERS\S-1-5-21-4032735365-608106937-2049815217-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9A4E3BC2-6451-D004-771F-4AAFA4EA7311}*] "maphhjbkccpmhlhpdefjkcfcin"=hex:6a,61,66,6a,6b,6f,6a,64,67,66,6d,63,65,70,6e, 6a,6c,70,65,66,00,00 "nabinlndebhlpajpeonchfmfiijn"=hex:6a,61,66,6a,6b,6f,6a,64,67,66,6d,63,65,70, 6e,6a,6c,70,65,66,00,fe . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\windows\system32\atieclxx.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\Protexis\License Service\PsiService_2.exe c:\windows\system32\ThpSrv.exe c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe c:\windows\system32\TODDSrv.exe c:\program files\Toshiba\Power Saver\TosCoSrv.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe c:\windows\system32\conime.exe c:\windows\System32\ThpSrv.exe c:\windows\ehome\ehmsas.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files\iPod\bin\iPodService.exe c:\windows\ehome\ehRecvr.exe . ************************************************************************** . Zeit der Fertigstellung: 2010-01-28 16:47:18 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2010-01-28 15:47 Vor Suchlauf: 10 Verzeichnis(se), 77.691.850.752 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 76.273.946.624 Bytes frei - - End Of File - - 54085C5765AF03FB6E5EBE68337A1CF2 Anhang: gmer.jpg
|
|
|
||
28.01.2010, 17:12
Member
Beiträge: 3716 |
#5
ok, brauch n paar minuten.
|
|
|
||
28.01.2010, 17:27
Member
Beiträge: 3716 |
||
|
||
28.01.2010, 17:56
Member
Themenstarter Beiträge: 60 |
#7
hier ist der log
17:55:35:166 4192 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25 17:55:35:166 4192 ================================================================================ 17:55:35:166 4192 SystemInfo: 17:55:35:166 4192 OS Version: 6.0.6002 ServicePack: 2.0 17:55:35:166 4192 Product type: Workstation 17:55:35:166 4192 ComputerName: DRAGO-PC 17:55:35:166 4192 UserName: Drago 17:55:35:166 4192 Windows directory: C:\Windows 17:55:35:166 4192 Processor architecture: Intel x86 17:55:35:166 4192 Number of processors: 2 17:55:35:166 4192 Page size: 0x1000 17:55:35:166 4192 Boot type: Normal boot 17:55:35:166 4192 ================================================================================ 17:55:35:166 4192 UnloadDriverW: NtUnloadDriver error 2 17:55:35:166 4192 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2 17:55:35:166 4192 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\drivers\klmd.sys) returned status 00000000 17:55:35:182 4192 UtilityInit: KLMD drop and load success 17:55:35:182 4192 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000) 17:55:35:182 4192 UtilityInit: KLMD open success 17:55:35:182 4192 UtilityInit: Initialize success 17:55:35:182 4192 17:55:35:182 4192 Scanning Services ... 17:55:35:182 4192 CreateRegParser: Registry parser init started 17:55:35:182 4192 CreateRegParser: DisableWow64Redirection error 17:55:35:182 4192 wfopen_ex: Trying to open file C:\Windows\system32\config\system 17:55:35:182 4192 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\config\system) returned status C0000043 17:55:35:182 4192 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 17:55:35:182 4192 wfopen_ex: Trying to KLMD file open 17:55:35:182 4192 KLMD_CreateFileW: Trying to open file C:\Windows\system32\config\system 17:55:35:182 4192 wfopen_ex: File opened ok (Flags 2) 17:55:35:197 4192 CreateRegParser: HIVE_ADAPTER(C:\Windows\system32\config\system) init success: 1B86F88 17:55:35:197 4192 wfopen_ex: Trying to open file C:\Windows\system32\config\software 17:55:35:197 4192 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\config\software) returned status C0000043 17:55:35:197 4192 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 17:55:35:197 4192 wfopen_ex: Trying to KLMD file open 17:55:35:197 4192 KLMD_CreateFileW: Trying to open file C:\Windows\system32\config\software 17:55:35:197 4192 wfopen_ex: File opened ok (Flags 2) 17:55:35:197 4192 CreateRegParser: HIVE_ADAPTER(C:\Windows\system32\config\software) init success: 1B86FB0 17:55:35:197 4192 CreateRegParser: EnableWow64Redirection error 17:55:35:197 4192 CreateRegParser: RegParser init completed 17:55:36:149 4192 GetAdvancedServicesInfo: Raw services enum returned 468 services 17:55:36:149 4192 fclose_ex: Trying to close file C:\Windows\system32\config\system 17:55:36:149 4192 fclose_ex: Trying to close file C:\Windows\system32\config\software 17:55:36:149 4192 17:55:36:149 4192 Scanning Kernel memory ... 17:55:36:149 4192 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk 17:55:36:149 4192 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 86893AC0 17:55:36:149 4192 DetectCureTDL3: KLMD_GetDeviceObjectList returned 1 DevObjects 17:55:36:149 4192 17:55:36:149 4192 DetectCureTDL3: DEVICE_OBJECT: 86F02820 17:55:36:149 4192 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86F02820 17:55:36:149 4192 DetectCureTDL3: DEVICE_OBJECT: 86DFF8E8 17:55:36:149 4192 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86DFF8E8 17:55:36:149 4192 DetectCureTDL3: DEVICE_OBJECT: 85D76028 17:55:36:149 4192 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85D76028 17:55:36:149 4192 KLMD_ReadMem: Trying to ReadMemory 0x85D76028[0x38] 17:55:36:149 4192 DetectCureTDL3: DRIVER_OBJECT: 85D8B830 17:55:36:149 4192 KLMD_ReadMem: Trying to ReadMemory 0x85D8B830[0xA8] 17:55:36:149 4192 KLMD_ReadMem: Trying to ReadMemory 0x85D8C008[0x1C] 17:55:36:149 4192 DetectCureTDL3: DRIVER_OBJECT name: \Driver\iaStor, Driver Name: iaStor 17:55:36:149 4192 DetectCureTDL3: IrpHandler (0) addr: 82AF20B0 17:55:36:149 4192 DetectCureTDL3: IrpHandler (1) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (2) addr: 82AF20B0 17:55:36:149 4192 DetectCureTDL3: IrpHandler (3) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (4) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (5) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (6) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (7) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (8) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (9) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (10) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (11) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (12) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (13) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (14) addr: 82AF20B0 17:55:36:149 4192 DetectCureTDL3: IrpHandler (15) addr: 82AF20B0 17:55:36:149 4192 DetectCureTDL3: IrpHandler (16) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (17) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (18) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (19) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (20) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (21) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (22) addr: 82AF20B0 17:55:36:149 4192 DetectCureTDL3: IrpHandler (23) addr: 82AF20B0 17:55:36:149 4192 DetectCureTDL3: IrpHandler (24) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (25) addr: 8243A9D2 17:55:36:149 4192 DetectCureTDL3: IrpHandler (26) addr: 8243A9D2 17:55:36:149 4192 TDL3_FileDetect: Processing driver: iaStor 17:55:36:149 4192 TDL3_FileDetect: Processing driver file: C:\Windows\system32\DRIVERS\iaStor.sys 17:55:36:149 4192 KLMD_CreateFileW: Trying to open file C:\Windows\system32\DRIVERS\iaStor.sys 17:55:36:180 4192 TDL3_FileDetect: C:\Windows\system32\DRIVERS\iaStor.sys - Verdict: Clean 17:55:36:180 4192 17:55:36:180 4192 Completed 17:55:36:180 4192 17:55:36:180 4192 Results: 17:55:36:180 4192 Memory objects infected / cured / cured on reboot: 0 / 0 / 0 17:55:36:180 4192 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 17:55:36:180 4192 File objects infected / cured / cured on reboot: 0 / 0 / 0 17:55:36:180 4192 17:55:36:180 4192 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\drivers\klmd.sys) returned status 00000000 17:55:36:180 4192 UtilityDeinit: KLMD(ARK) unloaded successfully |
|
|
||
28.01.2010, 18:08
Member
Beiträge: 3716 |
#8
1. öffne avira, verwaltung, leere die Quarantäne
2. lass drweb cureit laufen: http://www.paules-pc-forum.de/forum/4-pc-sicherheit/125060-dr-web-cureit.html#post762096 poste das log. 3. berichte, wie der pc läuft. |
|
|
||
28.01.2010, 19:18
Member
Themenstarter Beiträge: 60 |
#9
also, drweb stürtz bei mir ab, d.h. der laptop geht einfach mittendrin aus.
die frage wie mein rechner läuft kann ich nur mit gut beatworten, sehe keinen unterschied zu dem wie es war bevor ich mich infiziert habe. also eigentlich alles wieder super. Oder irre ich mich da, und da ist irgendwo noch etwas auf meinem rechner?! vielen dank schon mal |
|
|
||
28.01.2010, 19:35
Member
Beiträge: 3716 |
#10
hast du den scan im abgesicherten modus gemacht?
|
|
|
||
28.01.2010, 19:55
Member
Themenstarter Beiträge: 60 |
#11
ja habe ich, aber wie erwähnt, zwei mal absturz
|
|
|
||
28.01.2010, 20:59
Member
Beiträge: 3716 |
#12
kannst du noch mal ein combofix log posten bitte.
|
|
|
||
28.01.2010, 21:27
Member
Themenstarter Beiträge: 60 |
#13
gerne, hier nochmal combofix-log
ComboFix 10-01-27.06 - Drago 28.01.2010 21:13:21.2.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3036.1861 [GMT 1:00] ausgeführt von:: c:\users\Drago\Desktop\Virus\test.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((( Dateien erstellt von 2009-12-28 bis 2010-01-28 )))))))))))))))))))))))))))))) . 2010-01-28 20:22 . 2010-01-28 20:22 -------- d-----w- c:\users\Drago\AppData\Local\temp 2010-01-28 20:22 . 2010-01-28 20:22 -------- d-----w- c:\users\Public\AppData\Local\temp 2010-01-28 20:22 . 2010-01-28 20:22 -------- d-----w- c:\users\Mcx1-DRAGO-PC\AppData\Local\temp 2010-01-28 20:22 . 2010-01-28 20:22 -------- d-----w- c:\users\Katarina\AppData\Local\temp 2010-01-28 20:22 . 2010-01-28 20:22 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-01-28 20:22 . 2010-01-28 20:22 -------- d-----w- c:\users\Birungueta\AppData\Local\temp 2010-01-28 17:53 . 2010-01-28 17:53 -------- d-----w- c:\users\Drago\DoctorWeb 2010-01-28 14:05 . 2010-01-28 14:05 -------- d-----w- c:\programdata\WindowsSearch 2010-01-27 22:57 . 2010-01-27 22:57 -------- d-----w- c:\users\Drago\AppData\Roaming\Malwarebytes 2010-01-27 22:57 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-27 22:57 . 2010-01-27 22:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-01-27 22:57 . 2010-01-27 22:57 -------- d-----w- c:\programdata\Malwarebytes 2010-01-27 22:57 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-01-27 22:40 . 2010-01-27 22:40 -------- d-----w- c:\program files\CCleaner 2010-01-27 22:38 . 2010-01-27 22:38 -------- d-----w- c:\program files\Trend Micro 2010-01-27 22:15 . 2010-01-27 22:15 -------- d-----w- c:\users\Drago\AppData\Roaming\MOVAVI 2010-01-27 22:13 . 2010-01-27 22:18 -------- d-----w- c:\program files\Movavi Video Suite 8 2010-01-27 22:12 . 2010-01-27 22:12 -------- d-----w- c:\users\Drago\AppData\Local\Downloaded Installations 2010-01-27 21:56 . 2010-01-27 21:56 -------- d-----w- c:\programdata\AVS4YOU 2010-01-27 21:54 . 2010-01-27 21:58 -------- d-----w- c:\program files\Common Files\AVSMedia 2010-01-27 21:54 . 2007-02-27 18:36 974848 ----a-w- c:\windows\system32\mfc70.dll 2010-01-27 21:54 . 2007-02-27 18:36 487424 ----a-w- c:\windows\system32\msvcp70.dll 2010-01-27 21:54 . 2010-01-27 21:58 -------- d-----w- c:\program files\AVS4YOU 2010-01-27 21:54 . 2007-02-27 18:36 344064 ----a-w- c:\windows\system32\msvcr70.dll 2010-01-27 21:54 . 2007-02-27 18:36 24576 ----a-w- c:\windows\system32\msxml3a.dll 2010-01-27 21:53 . 2010-01-27 21:53 -------- d-----w- C:\Drivers 2010-01-27 21:13 . 2010-01-27 21:27 -------- d-----w- c:\users\Drago\AppData\Roaming\Sytexis Software 2010-01-27 21:13 . 2010-01-27 21:37 -------- d-----w- c:\program files\Sytexis Software 2010-01-27 20:40 . 2010-01-27 20:40 -------- d-----w- c:\users\Drago\AppData\Local\Jaksta_LLC 2010-01-27 20:39 . 2010-01-27 20:40 -------- d-----w- c:\users\Drago\AppData\Roaming\Jaksta 2010-01-27 20:39 . 2010-01-27 20:39 -------- d-----w- c:\program files\Jaksta 2010-01-26 21:03 . 2010-01-26 21:03 -------- d-----w- c:\program files\Logitech Touch Mouse Server 2010-01-23 13:49 . 2010-01-23 13:49 -------- d-----w- c:\users\Drago\trash 2010-01-16 17:17 . 2008-04-07 04:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll 2010-01-15 02:01 . 2010-01-15 02:01 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2 2010-01-14 16:01 . 2010-01-22 17:18 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-13 18:46 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll 2010-01-13 18:46 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll 2010-01-11 19:47 . 2010-01-11 22:57 -------- d-----w- c:\program files\nettvplayer2.0 2010-01-11 16:49 . 2010-01-11 16:49 -------- d-----w- c:\users\Drago\.spss 2010-01-10 13:43 . 2010-01-10 13:43 -------- d-----w- c:\program files\WhereIsIt 2010-01-09 22:50 . 2010-01-09 22:50 -------- d-----w- c:\program files\MediaMonkey 2010-01-09 22:39 . 2010-01-28 15:47 -------- d-----w- c:\users\Birungueta 2010-01-09 22:39 . 2010-01-09 22:39 -------- d-----w- c:\users\Drago\AppData\Local\Thinstall 2010-01-09 22:16 . 2010-01-24 12:17 -------- d-----w- c:\users\Drago\AppData\Local\MediaMonkey 2010-01-07 08:44 . 2010-01-07 08:44 -------- d-----w- c:\users\Drago\AppData\Local\SPSS 15.0 für Windows [Auswertung Version] 2010-01-07 08:42 . 2010-01-07 08:42 1024 ----a-w- c:\windows\system32\clauth2.dll 2010-01-07 08:42 . 2010-01-07 08:42 1024 ----a-w- c:\windows\system32\clauth1.dll 2010-01-07 08:42 . 2006-05-10 10:15 1929216 ----a-w- c:\windows\system32\cdintf250.dll 2010-01-07 08:39 . 2010-01-23 08:26 -------- d-----w- c:\program files\SPSSEV-DE 2010-01-07 00:04 . 2010-01-07 00:04 -------- d-----w- c:\program files\RAR Password Recovery Magic 2010-01-06 18:34 . 2010-01-06 18:34 249856 ------w- c:\windows\Setup1.exe 2010-01-06 18:34 . 2010-01-06 18:34 73216 ----a-w- c:\windows\ST6UNST.EXE 2010-01-06 17:32 . 1999-03-23 08:12 299520 ----a-w- c:\windows\uninst.exe 2010-01-05 22:05 . 2010-01-07 18:49 -------- d-----w- c:\users\Drago\Karaoke 2010-01-05 20:08 . 2001-02-25 00:57 69632 ----a-w- c:\windows\system32\WGDRVR32.DLL 2010-01-05 20:08 . 2010-01-05 20:08 -------- d-----w- c:\program files\WinGroove 2010-01-05 20:06 . 2010-01-05 20:09 -------- d-----w- C:\WG0A4.TMP 2010-01-03 22:49 . 2010-01-28 18:32 -------- d-----w- c:\users\Drago\TV-Browser 2010-01-03 22:45 . 2010-01-03 22:45 -------- d-----w- c:\users\Drago\AppData\Roaming\Regensoft 2010-01-03 21:06 . 2010-01-03 21:06 177024 ----a-w- c:\users\Drago\AppData\Roaming\Mozilla\Firefox\Profiles\ct7w40o0.default\FlashGot.exe 2010-01-03 18:59 . 2010-01-03 19:11 -------- d-----w- c:\users\Drago\AppData\Roaming\DC++ 2010-01-03 18:59 . 2010-01-03 18:59 -------- d-----w- c:\users\Drago\AppData\Local\DC++ . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-01-28 20:17 . 2008-01-21 07:15 618442 ----a-w- c:\windows\system32\perfh007.dat 2010-01-28 20:17 . 2008-01-21 07:15 122842 ----a-w- c:\windows\system32\perfc007.dat 2010-01-28 19:38 . 2009-11-04 15:31 -------- d-----w- c:\program files\NetTVPlus Player 2010-01-27 23:01 . 2009-10-25 12:37 -------- d-----w- c:\users\Drago\AppData\Roaming\skypePM 2010-01-27 22:34 . 2009-10-25 12:36 -------- d-----w- c:\users\Drago\AppData\Roaming\Skype 2010-01-27 21:53 . 2009-06-05 08:23 -------- d-----w- c:\program files\Common Files\InstallShield 2010-01-25 00:58 . 2009-10-25 14:34 -------- d-----w- c:\users\Drago\AppData\Roaming\vlc 2010-01-24 23:57 . 2009-11-18 01:03 -------- d-----w- c:\users\Drago\AppData\Roaming\dvdcss 2010-01-24 23:47 . 2009-11-09 17:54 -------- d-----w- c:\program files\JDownloader 2010-01-23 13:31 . 2009-12-03 11:14 -------- d-----w- c:\users\Drago\AppData\Roaming\Apple Computer 2010-01-19 06:16 . 2009-10-26 19:25 80616 ----a-w- c:\users\Katarina\AppData\Local\GDIPFONTCACHEV1.DAT 2010-01-17 22:58 . 2009-10-26 18:12 -------- d-----w- c:\program files\Full Tilt Poker 2010-01-16 17:42 . 2009-10-24 21:55 80616 ----a-w- c:\users\Drago\AppData\Local\GDIPFONTCACHEV1.DAT 2010-01-16 00:04 . 2009-06-05 09:07 -------- d-----w- c:\program files\Microsoft Works 2010-01-14 10:12 . 2009-11-18 11:15 181120 ------w- c:\windows\system32\MpSigStub.exe 2010-01-13 22:14 . 2009-11-18 17:28 2516 --sha-w- c:\programdata\KGyGaAvL.sys 2010-01-13 22:14 . 2009-11-18 17:28 2516 --sha-w- c:\programdata\KGyGaAvL.sys 2010-01-09 22:39 . 2009-11-02 20:21 -------- d-----w- c:\users\Drago\AppData\Roaming\Thinstall 2010-01-05 20:23 . 2009-11-01 21:51 -------- d-----w- c:\program files\vanBasco's Karaoke Player 2010-01-03 22:38 . 2009-11-18 18:11 -------- d-----w- c:\program files\TPNet 2010-01-02 06:38 . 2010-01-22 17:24 916480 ----a-w- c:\windows\system32\wininet.dll 2010-01-02 06:32 . 2010-01-22 17:24 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-01-02 06:32 . 2010-01-22 17:24 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-01-02 04:57 . 2010-01-22 17:24 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-12-23 17:26 . 2009-12-23 17:26 -------- d-----w- c:\program files\Hugin 2009-12-22 22:16 . 2009-06-05 09:01 -------- d-----w- c:\program files\Google 2009-12-22 17:37 . 2009-11-02 23:39 -------- d-----w- c:\program files\Elaborate Bytes 2009-12-22 17:36 . 2009-12-22 17:33 -------- d-----w- c:\program files\Unlocker 2009-12-22 17:26 . 2009-11-05 22:47 -------- d-----w- c:\program files\SlySoft 2009-12-21 00:20 . 2009-12-21 00:20 -------- d-----w- c:\users\Katarina\AppData\Roaming\HP 2009-12-21 00:18 . 2009-12-21 00:18 -------- d-----w- c:\users\Katarina\AppData\Roaming\Alice Systems 2009-12-15 22:28 . 2009-10-29 22:05 -------- d-----w- c:\programdata\Apple 2009-12-08 02:03 . 2009-10-26 15:01 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-12-03 12:42 . 2009-12-03 10:51 -------- d-----w- c:\programdata\Rosetta Stone 2009-12-03 11:13 . 2009-12-03 11:12 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-12-03 11:13 . 2009-12-03 11:12 -------- d-----w- c:\program files\iTunes 2009-12-03 11:12 . 2009-12-03 11:12 -------- d-----w- c:\program files\iPod 2009-12-03 11:12 . 2009-12-03 11:11 -------- d-----w- c:\programdata\Apple Computer 2009-12-03 11:12 . 2009-12-03 11:07 -------- d-----w- c:\program files\Common Files\Apple 2009-12-03 11:12 . 2009-12-03 11:12 -------- d-----w- c:\program files\Bonjour 2009-12-03 11:11 . 2009-12-03 11:11 -------- d-----w- c:\program files\QuickTime 2009-12-03 11:10 . 2009-12-03 11:10 -------- d-----w- c:\program files\Apple Software Update 2009-12-03 10:51 . 2009-12-03 10:51 -------- d-----w- c:\program files\Rosetta Stone 2009-12-03 10:13 . 2009-12-03 10:13 -------- d-----w- c:\users\Drago\AppData\Roaming\gtk-2.0 2009-12-03 09:34 . 2009-12-03 09:34 48 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-12-03 09:18 . 2009-10-27 11:46 -------- d-----w- c:\program files\Common Files\SPSS 2009-12-03 09:18 . 2009-12-03 09:18 -------- d-----w- c:\programdata\SPSS 2009-12-01 22:06 . 2009-06-05 08:46 -------- d-----w- c:\program files\Java 2009-11-18 17:28 . 2009-11-18 17:28 8 --sh--r- c:\programdata\AFC2C51FF8.sys 2009-11-18 17:28 . 2009-11-18 17:28 8 --sh--r- c:\programdata\AFC2C51FF8.sys 2009-11-18 00:35 . 2009-11-18 00:35 40960 ----a-r- c:\users\Drago\AppData\Roaming\Microsoft\Installer\{E9E5845E-C2E1-4D8D-A2E1-46E6F7F68C68}\NewShortcut1_E9E5845EC2E14D8DA2E146E6F7F68C68.exe 2009-11-18 00:35 . 2009-11-18 00:35 40960 ----a-r- c:\users\Drago\AppData\Roaming\Microsoft\Installer\{E9E5845E-C2E1-4D8D-A2E1-46E6F7F68C68}\ARPPRODUCTICON.exe 2009-11-16 12:59 . 2009-11-16 12:59 4846 ----a-r- c:\users\Drago\AppData\Roaming\Microsoft\Installer\{37FD2F04-EC91-41AE-B5AB-AFF904BF20EE}\ARPPRODUCTICON.exe 2009-11-16 12:59 . 2009-11-16 12:59 67771 ----a-w- c:\windows\Novatel_V20025InstallerUninstall.exe 2009-11-16 12:56 . 2009-11-16 12:56 67727 ----a-w- c:\windows\OptionPluss_PCCardInstallerUninstall.exe 2009-11-16 12:56 . 2009-11-16 12:56 67719 ----a-w- c:\windows\OptionPCCardInstallerUninstall.exe 2009-11-16 12:27 . 2009-11-16 12:27 8464 ----a-w- c:\windows\system32\SpOrder.dll 2009-11-12 16:07 . 2009-11-12 16:07 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe 2009-11-09 12:31 . 2009-12-10 02:03 24064 ----a-w- c:\windows\system32\nshhttp.dll 2009-11-09 12:30 . 2009-12-10 02:03 30720 ----a-w- c:\windows\system32\httpapi.dll 2009-11-09 10:36 . 2009-12-10 02:03 411648 ----a-w- c:\windows\system32\drivers\http.sys 2009-11-04 22:26 . 2009-11-04 22:26 0 ----a-w- c:\windows\nsreg.dat 2009-11-02 20:21 . 2009-11-02 20:21 7168 ----a-w- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\f000000c100003i\ntvdm.exe 2009-11-02 20:21 . 2009-11-02 20:21 0 --sha-r- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\%drive_C%\MSDOS.SYS 2009-11-02 20:21 . 2009-11-02 20:21 0 --sha-r- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\%drive_C%\IO.SYS 2009-11-02 20:21 . 2009-11-02 20:21 7168 ----a-w- c:\users\Drago\AppData\Roaming\Thinstall\Steinberg WaveLab 5.01b\40000048600002i\WaveLab-app.exe 2009-11-02 19:46 . 2009-11-02 19:35 147906 ----a-w- c:\windows\hpoins12.dat 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-07-03 135680] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-30 7289376] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304] "ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336] "TUSBSleepChargeSrv"="c:\program files\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe" [2009-03-27 252288] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2007-04-16 421888] "SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2008-11-21 438272] "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2009-01-13 34088] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe" [2009-04-23 1011712] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-04-16 2513472] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-21 61440] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-03-06 468320] "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2009-03-09 55160] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-03-31 503808] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-03-23 729088] "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-04-01 1283384] "HDMICtrlMan"="c:\program files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe" [2009-04-07 811008] "TRCMan"="c:\program files\TOSHIBA\TRCMan\TRCMan.exe" [2008-11-26 701752] "TPCHWMsg"="c:\program files\TOSHIBA\TPHM\TPCHWMsg.exe" [2009-04-15 570736] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2009-09-05 385024] "CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600] "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-03-16 6158240] c:\users\Katarina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2009-2-24 391072] c:\users\Mcx1-DRAGO-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2009-2-24 391072] c:\users\Drago\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech Touch Mouse Server.lnk - c:\program files\Logitech Touch Mouse Server\iTouch-Server-Win.exe [2009-10-23 228352] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Automatic Update-Agent.lnk - c:\program files\T-Mobile\Communication Center\AutoUpdateSrv.exe [2009-11-16 499712] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\acaptuser32.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "MIDI2"=WGDRVR32.DLL "WAVE2"=WGDRVR32.DLL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cfFncEnabler.exe] 2009-03-24 11:53 16384 ----a-w- c:\program files\Toshiba\ConfigFree\cfFncEnabler.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NDSTray.exe] 2009-05-12 20:26 299008 ----a-w- c:\program files\Toshiba\ConfigFree\NDSTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartFaceVWatcher] 2009-03-24 17:33 163840 ----a-w- c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Teco] 2009-04-24 09:40 1323008 ----a-w- c:\program files\Toshiba\TECO\TEco.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2009-10-29 21:25 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration] 2009-03-04 13:53 96144 ----a-w- c:\program files\Toshiba\Registration\ToshibaReminder.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPRO] 2009-03-23 12:30 1045904 ----a-w- c:\program files\Toshiba TEMPRO\TemproTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant] 2009-10-26 07:33 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):7b,9f,7a,54,58,56,ca,01 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4032735365-608106937-2049815217-1000] "EnableNotificationsRef"=dword:00000001 R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\System32\drivers\thpdrv.sys [25.03.2009 16:23 30272] R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\System32\drivers\Thpevm.sys [04.09.2007 09:30 13336] R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [16.09.2008 12:03 169312] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [24.07.2009 10:08 176128] R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [26.10.2009 16:01 108289] R2 camsvc;TOSHIBA Web Camera Service;c:\program files\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe [05.06.2009 09:50 20544] R2 gtdetectsc;GtDetectSc Service;c:\windows\System32\Gtdetectsc.exe [16.11.2009 13:56 118784] R2 GtFlashSwitch;GtFlashSwitch;c:\program files\Common Files\GtFlashSwitch\GtFlashSwitch.exe [09.02.2007 13:48 176128] R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [23.03.2009 13:30 116104] R2 TMachInfo;TMachInfo;c:\program files\Toshiba\TOSHIBA Service Station\TMachInfo.exe [24.07.2009 10:26 62776] R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\Toshiba\TECO\TecoService.exe [24.04.2009 10:40 176128] R2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [17.03.2009 10:49 73728] R2 TPCHSrv;TPCH Service;c:\program files\Toshiba\TPHM\TPCHSrv.exe [15.04.2009 16:03 656752] R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\System32\drivers\TVALZFL.sys [20.03.2009 22:29 12920] R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [30.12.2008 11:18 57856] R3 enecirhid;ENE CIR HID Receiver;c:\windows\System32\drivers\enecirhid.sys [29.04.2008 00:56 11264] R3 enecirhidma;ENE CIR HIDmini Filter;c:\windows\System32\drivers\enecirhidma.sys [25.04.2008 08:16 5632] R3 JakNDisMP;JakNDisMP;c:\windows\System32\drivers\JakNDis.sys [11.05.2009 14:53 21504] R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17.11.2008 06:40 3668480] R3 PGEffect;Pangu effect driver;c:\windows\System32\drivers\PGEffect.sys [05.06.2009 09:50 22272] S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [27.10.2009 12:33 722416] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10.11.2009 01:10 135664] S3 JakNDis;Jaksta Service;c:\windows\System32\drivers\JakNDis.sys [11.05.2009 14:53 21504] S3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [08.04.2009 15:36 114528] S4 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [10.03.2009 17:51 46448] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Inhalt des "geplante Tasks" Ordners 2010-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-10 00:10] 2010-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-10 00:10] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ uInternet Settings,ProxyOverride = *.local IE: An vorhandene PDF-Datei anfügen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/707-44556-9400-3/4 IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe Trusted Zone: btopenzone.com\www Trusted Zone: t-mobile.net\hotspot FF - ProfilePath - c:\users\Drago\AppData\Roaming\Mozilla\Firefox\Profiles\ct7w40o0.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Picasa2\npPicasa2.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-01-28 21:22 Windows 6.0.6002 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- [HKEY_USERS\S-1-5-21-4032735365-608106937-2049815217-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9A4E3BC2-6451-D004-771F-4AAFA4EA7311}*] "maphhjbkccpmhlhpdefjkcfcin"=hex:6a,61,66,6a,6b,6f,6a,64,67,66,6d,63,65,70,6e, 6a,6c,70,65,66,00,00 "nabinlndebhlpajpeonchfmfiijn"=hex:6a,61,66,6a,6b,6f,6a,64,67,66,6d,63,65,70, 6e,6a,6c,70,65,66,00,fe . Zeit der Fertigstellung: 2010-01-28 21:26:00 ComboFix-quarantined-files.txt 2010-01-28 20:25 ComboFix2.txt 2010-01-28 15:47 Vor Suchlauf: 14 Verzeichnis(se), 78.173.892.608 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 76.066.193.408 Bytes frei - - End Of File - - C1F85DF23B68D6E58C0E94FA8561467F |
|
|
||
29.01.2010, 23:14
Moderator
Beiträge: 5694 |
#14
Ich werde hier übernehmen, das Virenfinder Weg ist einige Tage.
Grüsse Dich Sieht doch gut aus, aber denoch will ich mir noch einiges anschauen: Schritt 1 Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop >Doppelklick auf die OTL.exe -->Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen >Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output >Unter Extra Registry, wähle bitte Use SafeList >Klicke nun auf Run Scan links oben >Wenn der Scan beendet wurde werden 2 Logfiles erstellt >Poste die Logfiles in Code-Tags hier in den Thread. Schritt 2 Rootkitscan mit RootRepeal • Gehe hierhin, scrolle runter und downloade RootRepeal.zip. • Entpacke die Datei auf Deinen Desktop. • Doppelklicke die RootRepeal.exe, um den Scanner zu starten. • Klicke auf den Reiter Report und dann auf den Button Scan. • Mache einen Haken bei den folgenden Elementen und klicke Ok. . Drivers Files Processes SSDT Stealth Objects Hidden Services Shadow SSDT . • Im Anschluss wirst Du gefragt, welche Laufwerke gescannt werden sollen. • Wähle C:\ und klicke wieder Ok. • Der Suchlauf beginnt automatisch, es wird eine Weile dauern, bitte Geduld. • Wenn der Suchlauf beendet ist, klicke auf Save Report. • Speichere das Logfile als RootRepeal.txt auf dem Desktop. • Kopiere den Inhalt hier in den Thread. |
|
|
||
30.01.2010, 14:44
Member
Themenstarter Beiträge: 60 |
#15
Danke, dass du dich meines Problems annimmst.
Hier sind die logs: Code OTL logfile created on: 30.01.2010 14:07:29 - Run 1 Code OTL Extras logfile created on: 30.01.2010 14:07:29 - Run 1 ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2010/01/30 14:16 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP2 ================================================== Drivers ------------------- Name: dump_iaStor.sys Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys Address: 0x8FE6A000 Size: 897024 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0x9E7A6000 Size: 49152 File Visible: No Signed: - Status: - Name: splj.sys Image Path: C:\Windows\System32\Drivers\splj.sys Address: 0x80695000 Size: 1052672 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: C:\System Volume Information\{074f6941-0b6f-11df-aee8-afb0ef0d9a46}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{074f69a0-0b6f-11df-aee8-995e83a6a71b}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{074f69ed-0b6f-11df-aee8-a656b8d6bae2}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{12b59b34-077a-11df-b162-9a78d547bb47}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{26e269b4-04e8-11df-bcd2-a999b691af14}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{30fb236b-0433-11df-bf3e-a34201956ca8}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{31cadc85-08de-11df-b04a-9c3b5910717e}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{37dd905f-0c9a-11df-aa16-a80a13ce3295}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{72b058be-06db-11df-8ab2-8341b0ea0775}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{75108b3e-0b99-11df-87fd-c878b069f46f}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{85ab1ade-09ac-11df-8ce8-cbd6a095dd1d}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{d2d9f76b-0c0d-11df-96be-f4b725dfa9e5}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{f3f74b89-07f5-11df-b248-e12eecc8a26f}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\Windows\System32\XPSViewer\XPSVIE~1.XML Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f0efb442f8a0f46c.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_ecdf8c290e547f39.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_818f59bf601aa775.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_7ab8cc63a6e4c2a3.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc0ea08098.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.91_none_0e9c342f74fd2e58.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.91_none_5c400d5e63e93b68.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.91_none_58b1a5ca663317c4.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9876.0_none_b7e610287b2b4ea5.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_4ddfc6cd11929a02.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_81c25f21d3d46d84.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.1.0.0_none_6c030d6fdc86522c.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b5d18a9128.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.91_none_db5f5c9d98cb161f.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_516e2e610f48bda6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.91_none_dc9917e997f80c63.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cda6db.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.91_none_d6c3f1519bae0514.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_7658964504b9f3b6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0ebd6590e0b.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.91_none_588445e3d272feb1.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe76806.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9876.0_none_a6e4a7980e9b18a2.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.91_none_54c1279468b7b84b.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\d14225a52543aa5a9605b00dd7574812bf89c605ebc73a9730e1e386bfc965f8.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\d5ecf2ab9387e082648bbcccd6eceb9d67b096939150833d0ae3066b3a1a676e.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\91ca50cec42075fff02b366323bf3b45d2053b24544bd12b622b65621bd0edd5.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\b3beb16c28db357e654a6b132f59cd48cb95cee949d7b97587f8f02f233f3ce1.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\935df4549e21123a2efb986a707f54475380a037519679510e4b4dfc4bdb5767.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\88b03fe13d2710ad787d5d96cd0e5cbeda3a61c2a0a2bdc0c0984a48365242e2.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\b080e112e69d2e9c8e71acd39a81f0d469d837625ceb8ed73b5b87da1fd1424c.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\23b92a7e8d7a21cc76b46dc3885c05ac29036240854e18dfce39b283b8cfdf52.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\f8209ee440679adcdab198fe5262dd5ff95c1d654f488816d0f33c8a45d5e8d8.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\26340819d2ef86080d9001c6f2737d70fd6602ddf4b86b6c26b326ef81cc3342.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\ef483ae0673e2975dd4224fe26749623c1c702b8b3fded10161417459e1771a7.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\2d3cb7907b1336ea5889a2b731d5e97ad40903a4efd2287c1c117bc30f208f46.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\a2492fa83366394b7c17fa6c9650ce5688b887d0ad0ad79743a3422debf4d997.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\a951d53950c367acc37622f0dd619a954df5de2c4ec40296e6636605aa33714a.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\5effcbd6bfe308cd94c31922a126a132ef26282a495f9fc0963000a8e158d866.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\71503c1b988fb27a41668f3ba35468d268daf07e8e79cf7b82a1ef64a8d213a1.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\f7bf65ca621d8ad32ead1500a08827be239d0f49d83dc20dabf57d2eb17adbd7.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\989e628160e12c984a435d2bb2a335ad043e006646150c7b1f3bb52dccd842cc.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\bd83dce340498e7c363093c2fc74dfb58e1ec17770453905172c7471fadd9333.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\dd72f7ab2def5f75f58d01b24643b308750c38685daaed50bcddf61c18460dee.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Manifests\8b414e757cb8b153bff77dd00a36556aea3adab25ce15f3e8b184ffbf41ba7a2.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\msil_system.speech_31bf3856ad364e35_6.0.6000.16708_none_080e70cf835a2dc3\SYSTEM~1.DLL Status: Locked to the Windows API! Path: C:\Windows\winsxs\msil_system.speech_31bf3856ad364e35_6.0.6000.20864_none_08532cea9cac0fd7\SYSTEM~1.DLL Status: Locked to the Windows API! Path: C:\Windows\winsxs\msil_system.speech_31bf3856ad364e35_6.0.6001.18096_none_09915daf80cb8a58\SYSTEM~1.DLL Status: Locked to the Windows API! Path: C:\Windows\winsxs\msil_system.speech_31bf3856ad364e35_6.0.6001.22208_none_0a7e4c40999e5e7e\SYSTEM~1.DLL Status: Locked to the Windows API! Path: C:\Windows\winsxs\msil_system.speech_31bf3856ad364e35_6.0.6002.18005_none_0bd8244b7da9c221\SYSTEM~1.DLL Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_fdproxy_31bf3856ad364e35_6.0.6000.16386_none_792f8ff471a64e3b\$$DeleteMe.fdProxy.dll.01ca5657512ca4c6.0026 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_fdssdp_31bf3856ad364e35_6.0.6001.18000_none_3addf297743e6161\$$DeleteMe.fdSSDP.dll.01ca56575755f1d6.0055 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_fdwsd_31bf3856ad364e35_6.0.6001.18000_none_7da88373c225d895\$$DeleteMe.fdWSD.dll.01ca565761e57f36.00a8 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_fundisc_31bf3856ad364e35_6.0.6001.18000_none_7be46ed83ae29055\$$DeleteMe.fundisc.dll.01ca565754c582f6.0041 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.18000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCredentialProvider.dll.01ca56575dd28f06.0080 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_none_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01ca56576216c866.00ab Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..o-mmecore-wdm-audio_31bf3856ad364e35_6.0.6001.18000_none_4a4e4c26e5b22007\$$DeleteMe.wdmaud.drv.01ca565757fa2116.0059 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f327439667d597c\$$DeleteMe.adsldpc.dll.01ca565754abb966.003f Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18293_none_aac1f52459f8aeb3\$$DeleteMe.atl.dll.01ca56575e025196.0082 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiodg.exe.01ca56574fbdf996.0021 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.AudioSes.dll.01ca56575d364f06.007a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiosrv.dll.01ca5657613234c6.00a0 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-dsound_31bf3856ad364e35_6.0.6001.18000_none_589bbe5841e2df00\$$DeleteMe.dsound.dll.01ca56575af44e46.0069 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a51b01b87\$$DeleteMe.winmm.dll.01ca56575fac7f26.0092 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6001.18000_none_8cfdc804108fe1a6\$$DeleteMe.midimap.dll.01ca56575d24c2d6.0079 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6001.18000_none_8cfdc804108fe1a6\$$DeleteMe.msacm32.drv.01ca565765ce5226.00c8 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6001.18000_none_e34851aa8681b8b0\$$DeleteMe.advapi32.dll.01ca56574fa0fbb6.0020 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18000_none_ab203fc659b26ce7\$$DeleteMe.atl.dll.01ca55016b7023c0.001a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.22364_none_0c403f4e0eb28911\$$DeleteMe.authui.dll.01ca56575c101e86.0071 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-azman_31bf3856ad364e35_6.0.6001.18000_none_56571935b2b95c99\$$DeleteMe.azroles.dll.01ca56574f65c776.001c Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\$$DeleteMe.bcrypt.dll.01ca56575072f1b6.0024 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\$$DeleteMe.qmgr.dll.01ca565759a05706.0063 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b16c3d098f004f58\$$DeleteMe.bitsigd.dll.01ca56575847cbe6.005a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18057_none_0cbe918751dfdd3f\$$DeleteMe.es.dll.01ca56576108b3c6.009f Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6001.18000_none_06b40dcad71051f6\$$DeleteMe.Query.dll.01ca5657594c6aa6.005f Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.0.6001.18000_none_72c2652d9fddfafd\$$DeleteMe.comsvcs.dll.01ca56575db3bc66.007f Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71173946e986845\$$DeleteMe.diagperf.dll.01ca565764d52516.00c1 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.0.6001.18000_none_d77db57c3ca78826\$$DeleteMe.certcli.dll.01ca565755180fc6.0043 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485a8ade99\$$DeleteMe.cmiv2.dll.01ca56576a32bdb6.00d7 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18000_none_ac1da75bf2516084\$$DeleteMe.ole32.dll.01ca565756813cb6.004e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18226_none_69bb41ac3deac876\$$DeleteMe.rpcss.dll.01ca565760daed06.009d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-com-dtc-client_31bf3856ad364e35_6.0.6001.18085_none_4ca16fc8b98a26e2\$$DeleteMe.xolehlp.dll.01ca5657641641e6.00bd Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-comdlg32_31bf3856ad364e35_6.0.6001.18000_none_b5b111a1a5a793a5\$$DeleteMe.comdlg32.dll.01ca565755257d46.0044 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_none_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01ca565763087b66.00b5 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374cc18eed7408\$$DeleteMe.credui.dll.01ca56574c800ca6.000a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbddd3c6da\$$DeleteMe.crypt32.dll.01ca56575e8208e6.0088 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\$$DeleteMe.cryptsvc.dll.01ca5657563b3306.004a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cryptui-dll_31bf3856ad364e35_6.0.6001.18000_none_85ee5b5e98235317\$$DeleteMe.cryptui.dll.01ca56575b2e9826.006b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cpfilters_31bf3856ad364e35_6.1.1000.18299_none_f24aebf2486034b3\$$DeleteMe.CPFilters.dll.01ca56535442bd64.0000 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6001.18000_none_8da39414bd31fb37\$$DeleteMe.uxsms.dll.01ca565762840926.00af Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc.dll.01ca565762a043b6.00b1 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc6.dll.01ca56574ce3fe96.000d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dfsr-core-clientonly_31bf3856ad364e35_6.0.6001.18000_none_b6798caa9a04157b\$$DeleteMe.dfsr.exe.01ca565758653ef6.005b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directx-direct3d9_31bf3856ad364e35_6.0.6001.18000_none_c24d6ca560c635f9\$$DeleteMe.d3d9.dll.01ca56575b4b47e6.006c Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsapi.dll.01ca56574e4e15e6.0015 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsrslvr.dll.01ca5657539e19f6.0039 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directshow-core_31bf3856ad364e35_6.0.6001.22167_none_a6bff72a072e245d\$$DeleteMe.quartz.dll.01ca56575b7df0a6.006d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790f3532b2696\$$DeleteMe.winrnr.dll.01ca5657658d7896.00c6 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eappcfg.dll.01ca56574cf0f6e6.000e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eapphost.dll.01ca565764a2ca76.00bf Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samlib.dll.01ca565759264506.005d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samsrv.dll.01ca56574efe7a26.0019 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\$$DeleteMe.emdmgmt.dll.01ca56575ebbb686.008a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e12c0bbf09\$$DeleteMe.esent.dll.01ca56575c4ba0e6.0074 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-enhancedvideorenderer_31bf3856ad364e35_6.0.6001.22164_none_8fef3c16e5d12be0\$$DeleteMe.evr.dll.01ca565761c65e76.00a7 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_6.0.6001.18000_none_2076b21605e43be9\$$DeleteMe.wer.dll.01ca565756a53f76.0050 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6001.18000_none_ac31021c654a3267\$$DeleteMe.wevtapi.dll.01ca56574d03bb96.000f Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc45c1a12d92f84\$$DeleteMe.wevtsvc.dll.01ca56574f77c8d6.001d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6001.18000_none_beda112b5794d4e0\$$DeleteMe.feclient.dll.01ca5657634695d6.00b7 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.18000_none_79cbf36190e59fa9\$$DeleteMe.wersvc.dll.01ca565356688394.0002 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.18145_none_79a5b70991018b47\$$DeleteMe.wersvc.dll.01ca56575defdb06.0081 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpapi.dll.01ca5657598a5e06.0062 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpsvc.dll.01ca56575f636836.0090 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-hid-user_31bf3856ad364e35_6.0.6000.16386_none_d47586718a839763\$$DeleteMe.hidserv.dll.01ca56575fb69146.0093 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.18828_none_97be9dffeca028c3\$$DeleteMe.urlmon.dll.01ca793f6c40c8b0.0002 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.18865_none_97905d71ecc34c82\$$DeleteMe.urlmon.dll.01ca9b8b9d003217.0000 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..mentation.resources_31bf3856ad364e35_6.0.6000.16386_de-de_6d2913106de015bc\$$DeleteMe.wininet.dll.mui.01ca5501742b4ee0.0023 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..nal-core-locale-nls_31bf3856ad364e35_6.0.6001.18000_none_6ab830d9a945c1d1\$$DeleteMe.locale.nls.01ca5657656927b6.00c4 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18226_none_01d9592da1dddc20\$$DeleteMe.wininet.dll.01ca55016cce0de0.001e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18828_none_e4c479a1b7a94f56\$$DeleteMe.wininet.dll.01ca793f6c5fba90.0004 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18865_none_e4963913b7cc7315\$$DeleteMe.wininet.dll.01ca9b8b9d0c18f7.0002 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.0.6001.18000_none_22c7ea5489633945\$$DeleteMe.mscms.dll.01ca5657597fafa6.0061 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6001.18000_none_11e312d27c5a6ba6\$$DeleteMe.iphlpsvc.dll.01ca5657471b4816.0004 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18226_none_479410098c8efa7d\$$DeleteMe.iertutil.dll.01ca55016c54a7c0.001d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6001.18359_none_10bc6b74b4f2be85\ASPNET~1.XML Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6001.18359_none_10bc6b74b4f2be85\REDIRE~1.CON Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6001.22559_none_11460a25ce105b76\ASPNET~1.XML Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6001.22559_none_11460a25ce105b76\REDIRE~1.CON Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6002.18005_none_12d4ebd0b1f42298\ASPNET~1.XML Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6002.18005_none_12d4ebd0b1f42298\REDIRE~1.CON Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6002.18139_none_12b87f1ab208d8ee\ASPNET~1.XML Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6002.18139_none_12b87f1ab208d8ee\REDIRE~1.CON Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6002.22261_none_1319a9d1cb4601d3\ASPNET~1.XML Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-iis-sharedlibraries_31bf3856ad364e35_6.0.6002.22261_none_1319a9d1cb4601d3\REDIRE~1.CON Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\$$DeleteMe.imm32.dll.01ca5657521bbfb6.002e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-installer-engine_31bf3856ad364e35_6.0.6001.18000_none_037a7e2bb384bf01\$$DeleteMe.msi.dll.01ca56574ea69626.0017 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18215_none_93b81a93564f1da0\$$DeleteMe.kernel32.dll.01ca565752104e06.002d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-k..eo-capture-plug-ins_31bf3856ad364e35_6.0.6000.16386_none_f333da7d43ad950a\$$DeleteMe.Kswdmcap.ax.01ca56575724cfb6.0054 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-ldap-client_31bf3856ad364e35_6.0.6001.18000_none_f33c4797566bb3db\$$DeleteMe.Wldap32.dll.01ca5657596067d6.0060 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\$$DeleteMe.lsass.exe.01ca55016a67eb20.0011 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\$$DeleteMe.lsasrv.dll.01ca55016a7170a0.0012 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\$$DProcesses ------------------- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1348 Status: Locked to the Windows API! SSDT ------------------- #: 078 Function Name: NtCreateThread Status: Hooked by "<unknown>" at address 0x8b9d7a3c #: 194 Function Name: NtOpenProcess Status: Hooked by "<unknown>" at address 0x8b9d7a28 #: 201 Function Name: NtOpenThread Status: Hooked by "<unknown>" at address 0x8b9d7a2d #: 334 Function Name: NtTerminateProcess Status: Hooked by "<unknown>" at address 0x8b9d7a37 Stealth Objects ------------------- Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x85cfa1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_CREATE] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_CLOSE] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_READ] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_WRITE] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_SHUTDOWN] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_POWER] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: cdromĬ, IRP_MJ_PNP] Process: System Address: 0x877ba1f8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE] Process: System Address: 0x85cf81f8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE] Process: System Address: 0x85cf81f8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x85cf81f8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x85cf81f8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_POWER] Process: System Address: 0x85cf81f8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x85cf81f8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_PNP] Process: System Address: 0x85cf81f8 Size: 121 Datei Anhang: Datei wird hocObject: Hidden Code [Driver: usbuhci藗Џ浍摌챨藗ࡠ蝥????, IRP_MJ_CREATE] Process: System Address: 0x876881f8 Size: 121 hgeladen... - bitte Geduld! (je nach Größe)Object: Hidden Code [Driver: usbuhci藗Џ浍摌챨藗ࡠ蝥????, IRP_MJ_CLOSE] Process: System Address: 0x876881f8 Size: 121 E-Mail Benachrichtigung: Object: Hidden Code [Driver: usbuhci藗Џ浍摌챨藗ࡠ蝥????, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x876881f8 Size: 121 FolgendObject: Hidden Code [Driver: usbuhci藗Џ浍摌챨藗ࡠ蝥????, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x876881f8 Size: 121 e Themen könnten dich auch interessieren:Object: Hidden Code [Driver: usbuhci藗Џ浍摌챨藗ࡠ蝥????, IRP_MJ_POWER] Process: System Address: 0x876881f8 Size: 121 » ständige AntiVir Meldung ----> TR/VundoObject: Hidden Code [Driver: usbuhci藗Џ浍摌챨藗ࡠ蝥????, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x876881f8 Size: 121 .Gen» WORM/Alcra.B sowie TR/Drop.Agent.sObject: Hidden Code [Driver: usbuhci藗Џ浍摌챨藗ࡠ蝥????, IRP_MJ_PNP] Process: System Address: 0x876881f8 Size: 121 Object: Hidden Code [Driver: Smb, IRP_MJ_CREATE] Process: System Address: 0x897c51f8 Size: 121 Object: Hidden Code [Driver: Smb, IRP_MJ_CLOSE] Process: System Address: 0x897c51f8 Size: 121 Object: Hidden Code [Driver: Smb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x897c51f8 Size: 121 Object: Hidden Code [Driver: Smb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x897c51f8 Size: 121 Object: Hidden Code [Driver: Smb, IRP_MJ_CLEANUP] Process: System Address: 0x897c51f8 Size: 121 Object: Hidden Code [Driver: Smb, IRP_MJ_PNP] Process: System Address: 0x897c51f8 Size: 121 Object: Hidden Code [Driver: netbt裒, IRP_MJ_CREATE] Process: System Address: 0x897c11f8 Size: 121 Object: Hidden Code [Driver: netbt裒, IRP_MJ_CLOSE] Process: System Address: 0x897c11f8 Size: 121 Object: Hidden Code [Driver: netbt裒, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x897c11f8 Size: 121 Object: Hidden Code [Driver: netbt裒, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x897c11f8 Size: 121 Object: Hidden Code [Driver: netbt裒, IRP_MJ_CLEANUP] Process: System Address: 0x897c11f8 Size: 121 Object: Hidden Code [Driver: netbt裒, IRP_MJ_PNP] Process: System Address: 0x897c11f8 Size: 121 Object: Hidden Code [Driver: iScsiPrtЅ晖呉큤輨툴良, IRP_MJ_CREATE] Process: System Address: 0x8781c1f8 Size: 121 Object: Hidden Code [Driver: iScsiPrtЅ晖呉큤輨툴良, IRP_MJ_CLOSE] Process: System Address: 0x8781c1f8 Size: 121 Object: Hidden Code [Driver: iScsiPrtЅ晖呉큤輨툴良, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8781c1f8 Size: 121 Object: Hidden Code [Driver: iScsiPrtЅ晖呉큤輨툴良, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8781c1f8 Size: 121 Object: Hidden Code [Driver: iScsiPrtЅ晖呉큤輨툴良, IRP_MJ_POWER] Process: System Address: 0x8781c1f8 Size: 121 Object: Hidden Code [Driver: iScsiPrtЅ晖呉큤輨툴良, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8781c1f8 Size: 121 Object: Hidden Code [Driver: iScsiPrtЅ晖呉큤輨툴良, IRP_MJ_PNP] Process: System Address: 0x8781c1f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_READ] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP] Process: System Address: 0x85cf51f8 Size: 121 Object: Hidden Code [Driver: a36tqd67Ѕ灓摴껠聯蝺绰誼, IRP_MJ_CREATE] Process: System Address: 0x878191f8 Size: 121 Object: Hidden Code [Driver: a36tqd67Ѕ灓摴껠聯蝺绰誼, IRP_MJ_CLOSE] Process: System Address: 0x878191f8 Size: 121 Object: Hidden Code [Driver: a36tqd67Ѕ灓摴껠聯蝺绰誼, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x878191f8 Size: 121 Object: Hidden Code [Driver: a36tqd67Ѕ灓摴껠聯蝺绰誼, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x878191f8 Size: 121 Object: Hidden Code [Driver: a36tqd67Ѕ灓摴껠聯蝺绰誼, IRP_MJ_POWER] Process: System Address: 0x878191f8 Size: 121 Object: Hidden Code [Driver: a36tqd67Ѕ灓摴껠聯蝺绰誼, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x878191f8 Size: 121 Object: Hidden Code [Driver: a36tqd67Ѕ灓摴껠聯蝺绰誼, IRP_MJ_PNP] Process: System Address: 0x878191f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE] Process: System Address: 0x876fb1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE] Process: System Address: 0x876fb1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x876fb1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x876fb1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER] Process: System Address: 0x876fb1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x876fb1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP] Process: System Address: 0x876fb1f8 Size: 121 Object: Hidden Code [Driver: msahci, IRP_MJ_POWER] Process: System Address: 0x85cf91f8 Size: 121 Object: Hidden Code [Driver: msahci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x85cf91f8 Size: 121 Object: Hidden Code [Driver: msahci, IRP_MJ_PNP] Process: System Address: 0x85cf91f8 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLOSE] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_READ] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_WRITE] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_EA] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_EA] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLEANUP] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_POWER] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: mrxsmb, IRP_MJ_PNP] Process: System Address: 0x89b69500 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_CREATE] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_CLOSE] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_READ] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_WRITE] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_SET_INFORMATION] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_SHUTDOWN] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_CLEANUP] Process: System Address: 0x877841f8 Size: 121 Object: Hidden Code [Driver: cdfsЋ瑅퉷堸ꘆ, IRP_MJ_PNP] Process: System Address: 0x877841f8 Size: 121 ==EOF== |
|
|
||
ich habe seit gestern Abend folgendes Problem: habe mich mit msa.exe infiziert, es öffnen sich ständig popups im IE obwohl mein Standardbrowser Firefox ist.
Könntet ihr mir vielleicht Helfen den Fehler zu bereinigen?
Hab folgendes schon unternommen:
1. HijackThis-Log erstellt
2. mit mbam gescant und log erstellt
3. neues Hijackthis-log erstellt
4. wollte noch gmer durchführen, aber während des scanens kam ein bluescreen und der laptop stürtzte ab.
(Edit: selbst im abgesicherten modus bricht er mir gmer mitten im scan ab)
danke schon einmal im voraus.
hier nun die einzelnen log auswertungen in obiger Reihenfolge:
1.hijackthis-log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:48:58, on 27.01.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\Toshiba\TECO\TEco.exe
C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
C:\Program Files\Toshiba\TRCMan\TRCMan.exe
C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\FreePDF_XP\fpassist.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\T-Mobile\Communication Center\AutoUpdateSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\rundll32.exe
C:\Windows\msa.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [TUSBSleepChargeSrv] %ProgramFiles%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
O4 - HKLM\..\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
O4 - HKLM\..\Run: [HWSetup] "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
O4 - HKLM\..\Run: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [ThpSrv] C:\Windows\system32\thpsrv /logon
O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
O4 - HKLM\..\Run: [TRCMan] C:\Program Files\TOSHIBA\TRCMan\TRCMan.exe
O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [cfFncEnabler.exe] "C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe"
O4 - HKLM\..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaReminder.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [LosAlamos] rundll32.exe C:\Windows\system32\sshnas21.dll,AttachConsoleA
O4 - HKCU\..\Run: [BMIMZMHMFM] C:\Users\Drago\AppData\Local\Temp\Thi.exe
O4 - HKCU\..\Run: [ROUA3O12PW] C:\Users\Drago\AppData\Local\Temp\Thj.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: Logitech Touch Mouse Server.lnk = C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe
O4 - Global Startup: Automatic Update-Agent.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/707-44556-9400-3/4 (file missing)
O9 - Extra button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home (file missing)
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/ZwinkyInitialSetup1.0.1.1.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: acaptuser32.dll
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: GtDetectSc Service (gtdetectsc) - OptionNV - C:\Windows\system32\gtdetectsc.exe
O23 - Service: GtFlashSwitch - OptionNV - C:\Program Files\Common Files\GtFlashSwitch\GtFlashSwitch.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TOSHIBA Festplattenschutz (Thpsrv) - TOSHIBA Corporation - C:\Windows\system32\ThpSrv.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
--
End of file - 14576 bytes
2. mbam-logfile
Malwarebytes' Anti-Malware 1.44
Datenbank Version: 3647
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882
28.01.2010 13:30:51
mbam-log-2010-01-28 (13-30-51).txt
Scan-Methode: Vollständiger Scan (C:\|E:\|)
Durchsuchte Objekte: 412324
Laufzeit: 2 hour(s), 45 minute(s), 53 second(s)
Infizierte Speicherprozesse: 1
Infizierte Speichermodule: 1
Infizierte Registrierungsschlüssel: 23
Infizierte Registrierungswerte: 3
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 11
Infizierte Speicherprozesse:
C:\Windows\msb.exe (Trojan.Agent) -> Unloaded process successfully.
Infizierte Speichermodule:
C:\Windows\System32\sshnas21.dll (Trojan.FakeAlert) -> Delete on reboot.
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\BMIMZMHMFM (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmimzmhmfm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\losalamos (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\roua3o12pw (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
C:\Program Files\Rosetta Stone\Rosetta Stone V3\Rosetta Stone v3.2 - Patch.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Drago\AppData\Local\Temp\Thf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Drago\AppData\Local\Temp\Thg.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_6.0.6002.18005_lt-lt_bf12ba06fdc0c65b_msimsg.dll.mui_72e8994f (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\serauth1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\serauth2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\msb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\sshnas21.dll (Trojan.FakeAlert) -> Delete on reboot.
und nun noch
3. neues hijackthis-log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:45:33, on 28.01.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\Toshiba\TECO\TEco.exe
C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
C:\Program Files\Toshiba\TRCMan\TRCMan.exe
C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\FreePDF_XP\fpassist.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\T-Mobile\Communication Center\AutoUpdateSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [TUSBSleepChargeSrv] %ProgramFiles%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
O4 - HKLM\..\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
O4 - HKLM\..\Run: [HWSetup] "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
O4 - HKLM\..\Run: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [ThpSrv] C:\Windows\system32\thpsrv /logon
O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
O4 - HKLM\..\Run: [TRCMan] C:\Program Files\TOSHIBA\TRCMan\TRCMan.exe
O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [cfFncEnabler.exe] "C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe"
O4 - HKLM\..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaReminder.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: Logitech Touch Mouse Server.lnk = C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe
O4 - Global Startup: Automatic Update-Agent.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/707-44556-9400-3/4 (file missing)
O9 - Extra button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home (file missing)
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: acaptuser32.dll
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: GtDetectSc Service (gtdetectsc) - OptionNV - C:\Windows\system32\gtdetectsc.exe
O23 - Service: GtFlashSwitch - OptionNV - C:\Program Files\Common Files\GtFlashSwitch\GtFlashSwitch.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TOSHIBA Festplattenschutz (Thpsrv) - TOSHIBA Corporation - C:\Windows\system32\ThpSrv.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
--
End of file - 14026 bytes