|
Log-Analyse und Auswertung: Acer Laptop weißer BilschirmWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.04.2013, 18:54 | #1 |
| Acer Laptop weißer Bilschirm Guten Abend zusammen, nun ja ich habe hier einen Acer Laptop mit windows 7 32bit stehen. Das problem ist, dass man nach der Anmeldung nur noch einen weißen Bildschirm vor sich sieht und da ich keine lust habe zu formatieren und win neu draufzumachen dachte ich mir ich versuche mein glück zuerst hier. folgende Log wurde mit Farbar erstellt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-04-2013 Ran by SYSTEM at 14-04-2013 19:42:03 Running from H:\ Windows 7 Ultimate (X86) OS Language: German Standard The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [947152 2013-01-27] (Microsoft Corporation) HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM\...\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [107112 2006-11-22] (Symantec Corporation) HKLM\...\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe [134808 2006-11-28] (Symantec Corporation) HKLM\...\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe [186368 2004-03-11] (SlySoft, Inc.) HKU\acer\...\Winlogon: [Shell] explorer.exe,C:\Users\acer\AppData\Roaming\skype.dat [98304 2011-11-17] (Software ) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 ==================== Services (Whitelisted) =================== 2 ccEvtMgr; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [107624 2006-11-22] (Symantec Corporation) 2 ccSetMgr; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [107624 2006-11-22] (Symantec Corporation) 2 DefWatch; "C:\Program Files\Symantec AntiVirus\DefWatch.exe" [30872 2006-11-28] (Symantec Corporation) 3 LiveUpdate; "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" [2541248 2006-10-31] (Symantec Corporation) 2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [20456 2013-01-27] (Microsoft Corporation) 3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [295232 2013-01-27] (Microsoft Corporation) 3 SavRoam; "C:\Program Files\Symantec AntiVirus\SavRoam.exe" [122008 2006-11-28] (symantec) 2 Symantec AntiVirus; "C:\Program Files\Symantec AntiVirus\Rtvscan.exe" [1962136 2006-11-28] (Symantec Corporation) ==================== Drivers (Whitelisted) ==================== 3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [17024 2004-03-11] (SlySoft, Inc.) 1 eeCtrl; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2012-10-18] (Symantec Corporation) 2 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [9728 2003-11-29] (Elaborate Bytes AG) 3 ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [3840 2003-03-28] (Elaborate Bytes) 3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2012-10-18] (Symantec Corporation) 3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) 0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation) 1 MpKsld5787f8d; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8F07A54-1C2C-4666-BED9-2192E88ED70B}\MpKsld5787f8d.sys [29904 2013-03-21] () 3 NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130324.007\NAVENG.SYS [93296 2013-03-14] (Symantec Corporation) 3 NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130324.007\NAVEX15.SYS [1603824 2013-03-14] (Symantec Corporation) 1 SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [406672 2006-10-06] (Symantec Corporation) 1 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [247144 2006-11-22] (Symantec Corporation) 3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [274328 2006-11-22] (Symantec Corporation) 1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [25448 2006-11-22] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [109744 2012-10-19] (Symantec Corporation) 3 SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [26384 2006-10-26] (Symantec Corporation) 1 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [185744 2006-10-26] (Symantec Corporation) 3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x] 3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x] 3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-03-25 09:27 - 2013-04-14 18:35 - 00000004 ____A C:\Users\acer\AppData\Roaming\skype.ini 2013-03-25 09:19 - 2013-03-25 09:19 - 14317568 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 13761024 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 02877440 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-25 09:19 - 2013-03-25 09:19 - 02046464 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 01766912 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 01441280 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-25 09:19 - 2013-03-25 09:19 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-25 09:19 - 2013-03-25 09:19 - 01129984 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00745472 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00719360 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00690688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00629248 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00493056 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00391680 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00361984 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-25 09:19 - 2013-03-25 09:19 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00242200 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00232960 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00185344 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00138752 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00137216 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00125440 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00117248 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00073728 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-25 09:19 - 2013-03-25 09:19 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00042496 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00038400 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-25 09:17 - 2013-03-25 09:17 - 03419136 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 02284544 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01988096 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01504768 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01247744 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01230336 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01158144 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01080832 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00906240 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00604160 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00417792 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00364544 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00249856 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00207872 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00187392 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-03-25 09:13 - 2013-03-25 09:24 - 00010534 ____A C:\Windows\IE10_main.log 2013-03-25 09:03 - 2013-03-25 09:04 - 00000000 ____D C:\Windows\TempEC6A276D-0B10-6979-48C6-32DF460B7B73-Signatures 2013-03-21 14:26 - 2013-03-21 14:27 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-03-21 09:34 - 2013-02-12 04:32 - 00015872 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys ==================== One Month Modified Files and Folders ======== 2013-04-14 19:41 - 2013-04-14 19:41 - 00000000 ____D C:\FRST 2013-04-14 18:35 - 2013-03-25 09:27 - 00000004 ____A C:\Users\acer\AppData\Roaming\skype.ini 2013-04-14 18:35 - 2012-05-17 21:14 - 01794851 ____A C:\Windows\WindowsUpdate.log 2013-04-14 18:33 - 2009-07-14 05:34 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-14 18:33 - 2009-07-14 05:34 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-14 18:32 - 2010-02-09 20:56 - 01498506 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-14 18:27 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-14 18:27 - 2009-07-14 05:39 - 00048782 ____A C:\Windows\setupact.log 2013-04-13 16:35 - 2012-05-17 21:58 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-04-13 16:35 - 2012-05-17 21:56 - 00001912 ____A C:\Windows\epplauncher.mif 2013-04-08 19:15 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-04-08 18:34 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\DriverStore 2013-04-08 18:33 - 2010-02-09 21:01 - 69796088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-04-07 14:05 - 2012-05-17 21:18 - 00000000 ____D C:\users\acer 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\zh-TW 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\zh-HK 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\zh-CN 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\tr-TR 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\sv-SE 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\ru-RU 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\pt-PT 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\pt-BR 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\pl-PL 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\nl-NL 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\nb-NO 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\ko-KR 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\ja-JP 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\it-IT 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\hu-HU 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\fr-FR 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\fi-FI 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\el-GR 2013-03-25 09:31 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\de-DE 2013-03-25 09:24 - 2013-03-25 09:13 - 00010534 ____A C:\Windows\IE10_main.log 2013-03-25 09:19 - 2013-03-25 09:19 - 14317568 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 13761024 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 02877440 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-25 09:19 - 2013-03-25 09:19 - 02046464 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 01766912 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 01441280 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-25 09:19 - 2013-03-25 09:19 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-25 09:19 - 2013-03-25 09:19 - 01129984 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00745472 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00719360 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00690688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00629248 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00493056 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00391680 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00361984 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-25 09:19 - 2013-03-25 09:19 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00242200 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00232960 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00185344 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00138752 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00137216 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00125440 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00117248 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00073728 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-25 09:19 - 2013-03-25 09:19 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00042496 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00038400 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-25 09:19 - 2013-03-25 09:19 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-25 09:19 - 2013-03-25 09:19 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-25 09:17 - 2013-03-25 09:17 - 03419136 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 02284544 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01988096 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01504768 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01247744 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01230336 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01158144 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 01080832 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00906240 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00604160 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00417792 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00364544 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00249856 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00207872 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00187392 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-03-25 09:17 - 2013-03-25 09:17 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-03-25 09:17 - 2012-08-26 19:55 - 00000000 ____D C:\Users\acer\AppData\Roaming\Foxit Software 2013-03-25 09:04 - 2013-03-25 09:03 - 00000000 ____D C:\Windows\TempEC6A276D-0B10-6979-48C6-32DF460B7B73-Signatures 2013-03-21 14:58 - 2012-05-18 12:19 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-03-21 14:27 - 2013-03-21 14:26 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-03-21 10:26 - 2012-10-20 06:05 - 00010370 ____A C:\Windows\PFRO.log ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-04-07 11:04:06 Restore point made on: 2013-04-07 14:08:47 Restore point made on: 2013-04-08 18:32:04 ==================== Memory info =========================== Percentage of memory in use: 20% Total physical RAM: 1976.86 MB Available physical RAM: 1581.27 MB Total Pagefile: 1976.86 MB Available Pagefile: 1578.06 MB Total Virtual: 2047.88 MB Available Virtual: 1962.3 MB ==================== Partitions ============================= 1 Drive c: () (Fixed) (Total:146.39 GB) (Free:118.58 GB) NTFS 2 Drive e: () (Fixed) (Total:151.6 GB) (Free:151.47 GB) NTFS 3 Drive f: (GRTMPVOL_DE) (CDROM) (Total:0.58 GB) (Free:0 GB) CDFS 5 Drive h: (WAAAAAAASSS) (Removable) (Total:7.47 GB) (Free:7.4 GB) NTFS 6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 7 Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Datentr„ger ### Status Gr”áe Frei Dyn GPT --------------- ------------- ------- ------- --- --- Datentr„ger 0 Online 298 GB 0 B Datentr„ger 1 Kein Medium 0 B 0 B Datentr„ger 2 Online 7650 MB 0 B Partitions of Disk 0: =============== Datentr„ger-ID: CE9ED50F Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 100 MB 1024 KB Partition 2 Prim„r 146 GB 101 MB Partition 3 Prim„r 151 GB 146 GB ========================================================= Disk: 0 Partition 1 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 Y System-rese NTFS Partition 100 MB Fehlerfre ========================================================= Disk: 0 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 C NTFS Partition 146 GB Fehlerfre ========================================================= Disk: 0 Partition 3 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 E NTFS Partition 151 GB Fehlerfre ========================================================= Partitions of Disk 2: =============== Datentr„ger-ID: 30E9F6BF Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 7648 MB 1224 KB ========================================================= Disk: 2 Partition 1 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 5 H WAAAAAAASSS NTFS Wechselmed 7648 MB Fehlerfre ========================================================= ============================== MBR Partition Table ================== ============================== Partitions of Disk 0: =============== Disk ID: CE9ED50F Partition 1: ========= Hex: 8020210007DF130C0008000000200300 Active: YES Type: 07 (NTFS) Size: 100 MB Partition 2: ========= Hex: 00DF140C07FEFFFF0028030000604C12 Active: NO Type: 07 (NTFS) Size: 146 GB Partition 3: ========= Hex: 00FEFFFF07FEFFFF00884F120058F312 Active: NO Type: 07 (NTFS) Size: 152 GB ============================== Partitions of Disk 2: =============== Disk ID: 30E9F6BF Partition 1: ========= Hex: 00263700073CEDCF900900007006EF00 Active: NO Type: 07 (NTFS) Size: 7 GB Last Boot: 2013-04-08 19:07 ==================== End Of Log ============================ |
14.04.2013, 18:57 | #2 |
/// TB-Ausbilder | Acer Laptop weißer Bilschirm Hi,
__________________dieses Teil scheint grad irgendwie in Mode zu sein.. Schritt 1 entsperrt den Rechner. Die weiteren Schritte dann wieder im normalen Modus von Windows ausführen. Schritt 1 Drücke auf einem Zweitrechner bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument: Code:
ATTFilter HKU\acer\...\Winlogon: [Shell] explorer.exe,C:\Users\acer\AppData\Roaming\skype.dat [98304 2011-11-17] (Software ) C:\Users\acer\AppData\Roaming\skype.dat 2013-03-25 09:27 - 2013-04-14 18:35 - 00000004 ____A C:\Users\acer\AppData\Roaming\skype.ini
Schritt 2 Downloade dir bitte defogger (von jpshortstuff) auf deinen Desktop.
Schritt 3 Lade dir Gmer herunter (auf den Button Download EXE drücken) und speichere das Programm auf den Desktop.
Schritt 4 Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
Bitte poste in deiner nächsten Antwort:
__________________ |
15.04.2013, 00:46 | #3 |
| Acer Laptop weißer Bilschirm Vorerst vielen dank für die schnelle Antwort. Nun zu den Logs.
__________________Fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-04-2013 Ran by SYSTEM at 2013-04-14 23:48:18 Run:1 Running from H:\ ============================================== HKEY_USERS\acer\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell Value deleted successfully. C:\Users\acer\AppData\Roaming\skype.dat moved successfully. C:\Users\acer\AppData\Roaming\skype.ini moved successfully. ==== End of Fixlog ==== Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-04-15 00:54:49 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS543232L9A300 rev.FB4OC40C 298,09GB Running: gm416uyw.exe; Driver: C:\Users\acer\AppData\Local\Temp\kxldrpob.sys ---- System - GMER 2.1 ---- SSDT 859F72F8 ZwAlertResumeThread SSDT 85B29530 ZwAlertThread SSDT 858A6B78 ZwAllocateVirtualMemory SSDT 85A24610 ZwConnectPort SSDT 85B29F90 ZwCreateMutant SSDT 85B41528 ZwCreateThread SSDT 859A70B0 ZwFreeVirtualMemory SSDT 85BCB4A0 ZwImpersonateAnonymousToken SSDT 859F7238 ZwImpersonateThread SSDT 858E0950 ZwMapViewOfSection SSDT 85B29ED0 ZwOpenEvent SSDT 859A70E8 ZwOpenProcessToken SSDT 85BB06D0 ZwOpenThreadToken SSDT 85B056F8 ZwResumeThread SSDT 85B1BCC8 ZwSetContextThread SSDT 85B8E780 ZwSetInformationProcess SSDT 85B5BFD0 ZwSetInformationThread SSDT 85AA2BC8 ZwSuspendProcess SSDT 85A9C5F0 ZwSuspendThread SSDT 85B8E2A8 ZwTerminateProcess SSDT 85BCC788 ZwTerminateThread SSDT 85B8DAC8 ZwUnmapViewOfSection SSDT 85AD01B0 ZwWriteVirtualMemory ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82A8E9E9 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AC81C2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 10DB 82ACF1F0 8 Bytes [F8, 72, 9F, 85, 30, 95, B2, ...] {CLC ; JB 0xffffffa2; TEST [EAX], ESI; XCHG EBP, EAX; MOV DL, 0x85} .text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82ACF208 4 Bytes [78, 6B, 8A, 85] .text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82ACF2A8 4 Bytes [10, 46, A2, 85] .text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82ACF2E4 4 Bytes [90, 9F, B2, 85] {NOP ; LAHF ; MOV DL, 0x85} .text ntkrnlpa.exe!KeRemoveQueueEx + 1203 82ACF318 4 Bytes [28, 15, B4, 85] .text ... ---- Devices - GMER 2.1 ---- Device Ntfs.sys AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS Device cdfs.sys ---- EOF - GMER 2.1 ---- OTL Code:
ATTFilter OTL logfile created on: 15.04.2013 01:00:26 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\acer\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16521) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,93 Gb Total Physical Memory | 1,07 Gb Available Physical Memory | 55,17% Memory free 3,86 Gb Paging File | 2,78 Gb Available in Paging File | 71,87% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 146,39 Gb Total Space | 118,34 Gb Free Space | 80,84% Space Free | Partition Type: NTFS Drive D: | 151,60 Gb Total Space | 151,47 Gb Free Space | 99,91% Space Free | Partition Type: NTFS Drive E: | 591,06 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive G: | 7,47 Gb Total Space | 7,40 Gb Free Space | 99,12% Space Free | Partition Type: NTFS Computer Name: ACER-PC | User Name: acer | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.04.15 00:58:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\acer\Desktop\OTL.exe PRC - [2013.04.14 14:12:52 | 005,892,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SoftwareDistribution\Download\Install\AM_Delta.exe PRC - [2013.04.02 12:33:22 | 000,237,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe PRC - [2013.03.21 15:27:58 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\NisSrv.exe PRC - [2013.01.27 11:11:46 | 000,284,304 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MpCmdRun.exe PRC - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe PRC - [2013.01.27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe PRC - [2012.11.30 04:55:25 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2006.11.28 06:34:38 | 000,134,808 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\VPTray.exe PRC - [2006.11.28 06:34:18 | 001,962,136 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\Rtvscan.exe PRC - [2006.11.28 06:34:00 | 000,030,872 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\DefWatch.exe PRC - [2006.11.22 17:12:36 | 000,107,112 | ---- | M] (Symantec Corporation) -- C:\Programme\Common Files\Symantec Shared\ccApp.exe PRC - [2006.11.22 17:12:16 | 000,107,624 | ---- | M] (Symantec Corporation) -- C:\Programme\Common Files\Symantec Shared\ccSvcHst.exe PRC - [2006.11.10 11:00:00 | 000,389,120 | ---- | M] (WinZip Computing LP) -- C:\Programme\WinZip\WZQKPICK.EXE PRC - [2004.03.11 20:40:16 | 000,186,368 | ---- | M] (SlySoft, Inc.) -- C:\Programme\SlySoft\AnyDVD\AnyDVD.exe PRC - [2003.05.15 01:19:50 | 000,217,193 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe ========== Modules (No Company Name) ========== MOD - [2013.03.21 15:27:24 | 003,069,848 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2006.12.03 14:53:06 | 000,126,976 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll ========== Services (SafeList) ========== SRV - [2013.03.21 15:27:57 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2006.11.28 06:34:26 | 000,122,008 | ---- | M] (symantec) [On_Demand | Stopped] -- C:\Programme\Symantec AntiVirus\SavRoam.exe -- (SavRoam) SRV - [2006.11.28 06:34:18 | 001,962,136 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus) SRV - [2006.11.28 06:34:00 | 000,030,872 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Symantec AntiVirus\DefWatch.exe -- (DefWatch) SRV - [2006.11.22 17:12:16 | 000,107,624 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr) SRV - [2006.11.22 17:12:16 | 000,107,624 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr) SRV - [2006.10.31 10:32:09 | 002,541,248 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8F07A54-1C2C-4666-BED9-2192E88ED70B}\MpKsld5787f8d.sys -- (MpKsld5787f8d) DRV - [2013.03.14 10:00:00 | 001,603,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20130324.007\NAVEX15.SYS -- (NAVEX15) DRV - [2013.03.14 10:00:00 | 000,093,296 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20130324.007\NAVENG.SYS -- (NAVENG) DRV - [2013.01.20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv) DRV - [2012.10.19 23:03:35 | 000,109,744 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent) DRV - [2012.10.18 08:36:58 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programme\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl) DRV - [2012.10.18 08:36:58 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Programme\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.07.14 00:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2009.07.14 00:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7) DRV - [2009.07.14 00:02:46 | 001,096,704 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009.03.18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2006.11.22 16:17:06 | 000,274,328 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtspl.sys -- (SRTSPL) DRV - [2006.11.22 16:17:06 | 000,247,144 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\srtsp.sys -- (SRTSP) DRV - [2006.11.22 16:17:06 | 000,025,448 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\srtspx.sys -- (SRTSPX) DRV - [2006.10.26 12:01:34 | 000,185,744 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\symtdi.sys -- (SYMTDI) DRV - [2006.10.26 12:01:34 | 000,026,384 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\symredrv.sys -- (SYMREDRV) DRV - [2006.10.06 14:26:16 | 000,406,672 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programme\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv) DRV - [2004.03.11 19:03:22 | 000,017,024 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD) DRV - [2003.03.28 17:25:52 | 000,003,840 | ---- | M] (Elaborate Bytes) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ElbyDelay.sys -- (ElbyDelay) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startzentrale.de IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A8 E5 4C 3C 5C 57 CD 01 [binary data] IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb164/?search={searchTerms}&loc=IB_DS&a=6R8AfAyjhU&i=26 IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\acer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.21 15:27:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.21 15:27:58 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.18 13:19:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\acer\AppData\Roaming\mozilla\Extensions [2013.03.21 15:26:58 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.03.21 15:27:58 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.04.21 03:54:08 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.13 11:21:49 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.04.21 03:54:08 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.04.21 03:54:08 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.04.21 03:54:08 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.04.21 03:54:08 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Browser Companion Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Programme\BrowserCompanion\jsloader.dll ( ) O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Programme\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll (Montera Technologeis LTD) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Browser Companion Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Programme\BrowserCompanion\updatebhoWin32.dll ( ) O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Programme\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll (Montera Technologeis LTD) O4 - HKLM..\Run: [AnyDVD] C:\Programme\SlySoft\AnyDVD\AnyDVD.exe (SlySoft, Inc.) O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [vptray] C:\Programme\Symantec AntiVirus\VPTray.exe (Symantec Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{04276A1A-23F4-45DF-B5D0-65C16DAEDAEA}: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{056D11EC-4B78-4C4A-9D66-85CB4041E12F}: DhcpNameServer = 10.0.1.1 O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Programme\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Programme\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Programme\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2008.04.14 14:00:00 | 000,000,112 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.04.15 00:58:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\acer\Desktop\OTL.exe [2013.04.14 20:41:45 | 000,000,000 | ---D | C] -- C:\FRST [2013.03.25 10:19:54 | 000,745,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe [2013.03.25 10:19:54 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll [2013.03.25 10:19:53 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2013.03.25 10:19:52 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2013.03.25 10:19:51 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2013.03.25 10:19:51 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2013.03.25 10:19:51 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2013.03.25 10:19:51 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2013.03.25 10:19:51 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2013.03.25 10:19:51 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2013.03.25 10:19:51 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2013.03.25 10:19:51 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2013.03.25 10:19:50 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2013.03.25 10:19:50 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2013.03.25 10:19:50 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2013.03.25 10:19:50 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2013.03.25 10:19:50 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2013.03.25 10:19:50 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2013.03.25 10:19:49 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2013.03.25 10:19:49 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2013.03.25 10:19:49 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2013.03.25 10:19:49 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2013.03.25 10:19:49 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2013.03.25 10:19:49 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2013.03.25 10:19:49 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2013.03.25 10:19:49 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2013.03.25 10:19:48 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2013.03.25 10:19:48 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2013.03.25 10:19:48 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll [2013.03.25 10:19:48 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2013.03.25 10:19:48 | 000,242,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2013.03.25 10:19:48 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2013.03.25 10:19:48 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2013.03.25 10:19:48 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2013.03.25 10:19:48 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2013.03.25 10:19:48 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2013.03.25 10:17:06 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmpeg2vdec.dll [2013.03.25 10:17:06 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2013.03.25 10:17:06 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll [2013.03.25 10:17:06 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll [2013.03.25 10:17:06 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll [2013.03.25 10:17:06 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2013.03.25 10:17:06 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2013.03.25 10:17:06 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll [2013.03.25 10:17:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll [2013.03.25 10:17:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll [2013.03.25 10:17:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll [2013.03.25 10:17:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll [2013.03.25 10:17:06 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll [2013.03.25 10:17:05 | 003,419,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2013.03.25 10:17:05 | 001,988,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll [2013.03.25 10:17:05 | 001,504,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll [2013.03.25 10:17:05 | 001,247,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2013.03.25 10:17:05 | 001,080,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll [2013.03.25 10:17:05 | 000,604,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll [2013.03.25 10:17:05 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll [2013.03.25 10:17:05 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll [2013.03.25 10:17:05 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll [2013.03.25 10:17:05 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll [2013.03.25 10:17:05 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll [2013.03.25 10:17:05 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll [2013.03.25 10:03:58 | 000,000,000 | ---D | C] -- C:\Windows\TempEC6A276D-0B10-6979-48C6-32DF460B7B73-Signatures [2013.03.21 15:26:57 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.03.21 10:34:31 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys ========== Files - Modified Within 30 Days ========== [2013.04.15 01:04:16 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.04.15 01:04:16 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.04.15 01:04:16 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.04.15 01:04:16 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.04.15 01:01:53 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.15 01:01:53 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.15 00:58:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\acer\Desktop\OTL.exe [2013.04.15 00:56:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.15 00:56:20 | 1554,665,472 | -HS- | M] () -- C:\hiberfil.sys [2013.04.14 23:55:54 | 000,377,856 | ---- | M] () -- C:\Users\acer\Desktop\gm416uyw.exe [2013.04.14 23:53:38 | 000,000,000 | ---- | M] () -- C:\Users\acer\defogger_reenable [2013.04.14 23:52:47 | 000,050,477 | ---- | M] () -- C:\Users\acer\Desktop\Defogger.exe [2013.04.13 17:35:34 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif [2013.04.02 12:33:22 | 000,237,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2013.03.25 10:19:54 | 000,745,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe [2013.03.25 10:19:54 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll [2013.03.25 10:19:53 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2013.03.25 10:19:52 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2013.03.25 10:19:52 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2013.03.25 10:19:51 | 002,706,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2013.03.25 10:19:51 | 000,493,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2013.03.25 10:19:51 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2013.03.25 10:19:51 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2013.03.25 10:19:51 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2013.03.25 10:19:51 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2013.03.25 10:19:51 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2013.03.25 10:19:50 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2013.03.25 10:19:50 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2013.03.25 10:19:50 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2013.03.25 10:19:50 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2013.03.25 10:19:50 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2013.03.25 10:19:50 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2013.03.25 10:19:49 | 002,877,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2013.03.25 10:19:49 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2013.03.25 10:19:49 | 000,391,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2013.03.25 10:19:49 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2013.03.25 10:19:49 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2013.03.25 10:19:49 | 000,226,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2013.03.25 10:19:49 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2013.03.25 10:19:49 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2013.03.25 10:19:49 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2013.03.25 10:19:48 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2013.03.25 10:19:48 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll [2013.03.25 10:19:48 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2013.03.25 10:19:48 | 000,242,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2013.03.25 10:19:48 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2013.03.25 10:19:48 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2013.03.25 10:19:48 | 000,042,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2013.03.25 10:19:48 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2013.03.25 10:19:48 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2013.03.25 10:19:48 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2013.03.25 10:17:06 | 002,284,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msmpeg2vdec.dll [2013.03.25 10:17:06 | 001,158,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2013.03.25 10:17:06 | 000,417,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll [2013.03.25 10:17:06 | 000,364,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll [2013.03.25 10:17:06 | 000,010,752 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll [2013.03.25 10:17:06 | 000,009,728 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2013.03.25 10:17:06 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2013.03.25 10:17:06 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll [2013.03.25 10:17:06 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll [2013.03.25 10:17:06 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll [2013.03.25 10:17:06 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll [2013.03.25 10:17:06 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll [2013.03.25 10:17:06 | 000,002,560 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll [2013.03.25 10:17:05 | 003,419,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2013.03.25 10:17:05 | 001,988,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll [2013.03.25 10:17:05 | 001,504,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll [2013.03.25 10:17:05 | 001,247,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2013.03.25 10:17:05 | 001,080,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll [2013.03.25 10:17:05 | 000,604,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll [2013.03.25 10:17:05 | 000,293,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll [2013.03.25 10:17:05 | 000,249,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll [2013.03.25 10:17:05 | 000,220,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll [2013.03.25 10:17:05 | 000,207,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll [2013.03.25 10:17:05 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll [2013.03.25 10:17:05 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll ========== Files Created - No Company Name ========== [2013.04.14 23:55:48 | 000,377,856 | ---- | C] () -- C:\Users\acer\Desktop\gm416uyw.exe [2013.04.14 23:53:38 | 000,000,000 | ---- | C] () -- C:\Users\acer\defogger_reenable [2013.04.14 23:52:45 | 000,050,477 | ---- | C] () -- C:\Users\acer\Desktop\Defogger.exe [2013.03.25 10:19:48 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2012.05.20 13:04:01 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2012.05.20 13:01:53 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both < End of report > Code:
ATTFilter OTL Extras logfile created on: 15.04.2013 01:00:26 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\acer\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16521) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,93 Gb Total Physical Memory | 1,07 Gb Available Physical Memory | 55,17% Memory free 3,86 Gb Paging File | 2,78 Gb Available in Paging File | 71,87% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 146,39 Gb Total Space | 118,34 Gb Free Space | 80,84% Space Free | Partition Type: NTFS Drive D: | 151,60 Gb Total Space | 151,47 Gb Free Space | 99,91% Space Free | Partition Type: NTFS Drive E: | 591,06 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive G: | 7,47 Gb Total Space | 7,40 Gb Free Space | 99,12% Space Free | Partition Type: NTFS Computer Name: ACER-PC | User Name: acer | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{15672921-2C1D-4B5B-A88D-FDEBF5A78A8A}" = rport=139 | protocol=6 | dir=out | app=system | "{282B6416-FCE3-4AFD-9F6B-466E44F1EC46}" = rport=10243 | protocol=6 | dir=out | app=system | "{2B9E2A57-4C90-4652-8853-A88A79B0AD54}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3F1A7604-C67E-4468-9202-8B393B42729B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{466B47B0-FF90-42D9-8F98-57DC0129137D}" = rport=138 | protocol=17 | dir=out | app=system | "{48B47643-0B5A-4B28-B746-22692DE57C6F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{650AAFAC-CDC3-48BD-90FF-CF61491EBCB2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{68794BE1-25E5-4B4A-A63E-F46B02009548}" = lport=10243 | protocol=6 | dir=in | app=system | "{71D52C66-AD58-4EAD-B322-5C356EB911CF}" = rport=137 | protocol=17 | dir=out | app=system | "{7312CB6C-65D6-4AC2-80F7-B220E5957D84}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{87F55CA8-8DB8-418E-9E3C-6C26F1508F22}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{881B5321-E492-4FFE-9B68-CDABA272AF1E}" = lport=138 | protocol=17 | dir=in | app=system | "{8FE9F67F-93D7-4165-BC32-09600E807EB3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{92907190-983B-489E-B99E-26DC9E6753CE}" = rport=445 | protocol=6 | dir=out | app=system | "{9505EEAE-9F98-4D14-A563-070AFB64C2E3}" = lport=2869 | protocol=6 | dir=in | app=system | "{9E215095-8E3A-451C-B066-232B65CAEF4D}" = lport=25565 | protocol=6 | dir=in | name=server1 | "{B1B427B8-42D8-4070-A209-394788EC3793}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C865A1AB-EEE6-4AE0-8369-952A1FF9B57D}" = lport=139 | protocol=6 | dir=in | app=system | "{CDF85654-D8E6-4805-A7CE-3EC08F750C99}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D96496DB-F541-49D5-A916-49054A887830}" = lport=137 | protocol=17 | dir=in | app=system | "{DAE6730A-674D-4FD9-891C-3F1FAD8DACAA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{FFA40CDD-8B41-42F0-9E1E-5E8DCFE54967}" = lport=445 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0B67E09B-D43B-40F1-AFA8-1BB457C20151}" = protocol=17 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe | "{0D7E61B0-103E-4CBB-81B7-EFD6B4BCCBDD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{10059921-21A2-4760-81F4-F0A7BD3CACF7}" = protocol=6 | dir=out | app=system | "{12824286-1CDE-4FFE-A1DE-382B72A3D596}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{1CCBD72E-6002-48E7-A61C-4B72A658E6B5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{2991DBBB-F42C-4F89-9C1A-66749B10BE48}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{38486903-E121-4B08-9486-FFDA31D1DE52}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{46B89C83-DEC8-4CAA-A6FD-2F6FE922FA2F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{505CAF4F-7516-432E-95E3-8A4523E455FB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5398E842-1DBB-41C7-8036-3A9BB9822B79}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{68884E1F-63EE-4B09-9E9D-1F03BE384B60}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{70D75B9F-4A55-4828-A314-47216100D2B4}" = protocol=6 | dir=in | app=c:\program files\symantec antivirus\rtvscan.exe | "{77A78752-941F-4F45-9FF9-1A0C8327CC5D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{843588A7-FC2A-441D-BFF5-2B5F5272EA32}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{8CBC6C7A-7C09-4FDE-968D-5508A1C03C1B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A860525F-536F-44C6-AC5A-47787AF44053}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C267833F-DE72-42D2-8856-884A1C7F5007}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C7A6419C-5BA7-47DC-B5E9-7F69F99CCF78}" = protocol=6 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe | "{D17D03EE-6D67-4059-9C94-74DDB8358012}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{FE768C31-F889-43A1-BDE8-B53D380FBAE3}" = protocol=17 | dir=in | app=c:\program files\symantec antivirus\rtvscan.exe | "TCP Query User{20EA0F87-65D1-41D0-9C7C-55256DD44D48}C:\users\acer\documents\xtrememt2client2012\xtrememt2-2012\metin2client.exe" = protocol=6 | dir=in | app=c:\users\acer\documents\xtrememt2client2012\xtrememt2-2012\metin2client.exe | "TCP Query User{2406447F-A3AF-40B5-8682-371ABBB4E593}C:\users\acer\desktop\client\metin2client.bin" = protocol=6 | dir=in | app=c:\users\acer\desktop\client\metin2client.bin | "TCP Query User{6CC53CD0-3910-43D0-91D3-5FB24D92AB7D}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "TCP Query User{9D7FFAE9-66F1-4422-96EB-396930A4FA4C}C:\users\acer\desktop\xtrememt2client2012\xtrememt2-2012\metin2client.exe" = protocol=6 | dir=in | app=c:\users\acer\desktop\xtrememt2client2012\xtrememt2-2012\metin2client.exe | "TCP Query User{D14FC5CD-716C-4158-829D-4E6366DF42A3}C:\users\acer\documents\xtrememt2-2012\metin2client.bin" = protocol=6 | dir=in | app=c:\users\acer\documents\xtrememt2-2012\metin2client.bin | "TCP Query User{D859FC3C-228C-41A6-A056-C1376033A479}C:\users\acer\desktop\tsuyoshi2\metin2client.bin" = protocol=6 | dir=in | app=c:\users\acer\desktop\tsuyoshi2\metin2client.bin | "TCP Query User{E2952065-232E-452C-A55B-927C21E720EF}C:\users\acer\documents\xtrememt2-2012\metin2client.exe" = protocol=6 | dir=in | app=c:\users\acer\documents\xtrememt2-2012\metin2client.exe | "TCP Query User{E6A0B575-BE35-4DFD-8834-F0FD5EFCC2BC}C:\users\acer\desktop\xtrememt2-2012\metin2client.bin" = protocol=6 | dir=in | app=c:\users\acer\desktop\xtrememt2-2012\metin2client.bin | "UDP Query User{3DD2B18B-F5D9-4CF9-A9A9-660B1D13D0AB}C:\users\acer\documents\xtrememt2-2012\metin2client.exe" = protocol=17 | dir=in | app=c:\users\acer\documents\xtrememt2-2012\metin2client.exe | "UDP Query User{4A62C3EC-4F35-42AF-AE0C-87F22C3B73AE}C:\users\acer\desktop\tsuyoshi2\metin2client.bin" = protocol=17 | dir=in | app=c:\users\acer\desktop\tsuyoshi2\metin2client.bin | "UDP Query User{4EA19B9F-F331-4788-9F4D-9A0E6F2A37F6}C:\users\acer\documents\xtrememt2-2012\metin2client.bin" = protocol=17 | dir=in | app=c:\users\acer\documents\xtrememt2-2012\metin2client.bin | "UDP Query User{9B15A545-57F2-4AE4-A0F4-FA59441F6F61}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "UDP Query User{9C31E11A-CA4A-4421-9541-EC29D6F98764}C:\users\acer\desktop\xtrememt2client2012\xtrememt2-2012\metin2client.exe" = protocol=17 | dir=in | app=c:\users\acer\desktop\xtrememt2client2012\xtrememt2-2012\metin2client.exe | "UDP Query User{9CC7AFC6-DE40-47D3-A4A0-50169BC97399}C:\users\acer\desktop\xtrememt2-2012\metin2client.bin" = protocol=17 | dir=in | app=c:\users\acer\desktop\xtrememt2-2012\metin2client.bin | "UDP Query User{BE0012BC-71B9-4DB8-9548-BFD7FB1CB92B}C:\users\acer\documents\xtrememt2client2012\xtrememt2-2012\metin2client.exe" = protocol=17 | dir=in | app=c:\users\acer\documents\xtrememt2client2012\xtrememt2-2012\metin2client.exe | "UDP Query User{D79A7BE9-712C-4AC8-9B6C-078F7AF0E86B}C:\users\acer\desktop\client\metin2client.bin" = protocol=17 | dir=in | app=c:\users\acer\desktop\client\metin2client.bin | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5 "{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{7C9E6E52-EB11-44DB-A761-82D5D873A8D9}" = Symantec AntiVirus "{A14C40E7-F7E5-498D-B8BD-A3EAE942EED0}" = LEGO® Indiana Jones™ "{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0 Professional - English, Français, Deutsch "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AnyDVD" = AnyDVD "BrowserCompanion" = BrowserCompanion "CloneDVD2" = CloneDVD2 "Foxit Reader_is1" = Foxit Reader "incredibar" = Incredibar Toolbar on IE "InstallShield_{A14C40E7-F7E5-498D-B8BD-A3EAE942EED0}" = LEGO® Indiana Jones™ "LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation) "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft Security Client" = Microsoft Security Essentials "Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Nero - Burning Rom!UninstallKey" = Nero 6 Demo "VLC media player" = VLC media player 2.0.4 "WinRAR archiver" = WinRAR Archivierer "WinZip" = WinZip ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "UnityWebPlayer" = Unity Web Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 07.04.2013 15:15:14 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQDF66.tmp by: Auto-Protect scan. Action: Clean succeeded : Access allowed. Action Description: The file was repaired successfully. Error - 07.04.2013 15:15:15 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ7628.tmp by: Auto-Protect scan. Action: Clean succeeded : Access allowed. Action Description: The file was repaired successfully. Error - 07.04.2013 15:15:16 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQBD36.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully. Error - 07.04.2013 15:15:17 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ32D2.tmp by: Auto-Protect scan. Action: Clean succeeded : Access allowed. Action Description: The file was repaired successfully. Error - 08.04.2013 13:30:52 | Computer Name = acer-PC | Source = Microsoft Security Client Setup | ID = 100 Description = HRESULT:0x8004FF80 Description:Cannot complete the Security Essentials Upgrade. An error has prevented the Security Essentials Upgrade Wizard from continuing. The previous version of Security Essentials was restored. Error code:0x8004FF80. Error - 08.04.2013 13:34:00 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711726 Description = Security Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ12B5.tmp by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description: The file was left unchanged. Error - 08.04.2013 13:34:00 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ12B5.tmp by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied. Action Description: The file was left unchanged. Error - 08.04.2013 13:34:01 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711731 Description = Security Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ12B5.tmp by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied. Action Description: Risk was partially removed. Error - 08.04.2013 13:34:01 | Computer Name = acer-PC | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: W32.Traxg@mm in File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ12B5.tmp by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied. Action Description: The file was left unchanged. Error - 13.04.2013 11:34:05 | Computer Name = acer-PC | Source = System Restore | ID = 8193 Description = [ System Events ] Error - 31.01.2013 10:22:17 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%838 Error - 31.01.2013 10:24:33 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%838 Error - 31.01.2013 10:56:23 | Computer Name = acer-PC | Source = WMPNetworkSvc | ID = 866300 Description = Error - 31.01.2013 11:22:19 | Computer Name = acer-PC | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows-Fehlerberichterstattungsdienst erreicht. Error - 31.01.2013 11:24:37 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%838 Error - 31.01.2013 11:37:25 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%838 Error - 31.01.2013 11:41:22 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%838 Error - 31.01.2013 11:47:35 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%840 Error - 31.01.2013 12:20:08 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%838 Error - 31.01.2013 16:23:30 | Computer Name = acer-PC | Source = Microsoft Antimalware | ID = 3002 Description = Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt Feature: %%834 Fehlercode: 0x80004005 Fehlerbeschreibung: Unbekannter Fehler Grund: %%838 < End of report > |
15.04.2013, 00:55 | #4 |
/// TB-Ausbilder | Acer Laptop weißer Bilschirm Hi, hier die nächsten Schritte: Schritt 1
Schritt 2 Downloade dir bitte AdwCleaner und speichere es auf deinen Desktop.
Schritt 3 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
15.04.2013, 01:19 | #5 |
| Acer Laptop weißer Bilschirm Schritt 1 bis 3 check. Hier die Logs: AdwCleaner Code:
ATTFilter # AdwCleaner v2.200 - Datei am 15/04/2013 um 02:01:57 erstellt # Aktualisiert am 02/04/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits) # Benutzer : acer - ACER-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\acer\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : \user.js Ordner Gelöscht : C:\Program Files\BrowserCompanion Ordner Gelöscht : C:\Users\acer\AppData\Local\Ilivid Player Ordner Gelöscht : C:\Users\acer\AppData\Roaming\BrowserCompanion ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Blabbers Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Schlüssel Gelöscht : HKLM\Software\Web Assistant Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16537 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v19.0.2 (de) Datei : C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\swd19u5r.default-1363268367390\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [2913 octets] - [15/04/2013 02:01:57] ########## EOF - \AdwCleaner[S1].txt - [2973 octets] ########## Code:
ATTFilter OTL logfile created on: 15.04.2013 02:07:14 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\acer\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16540) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,93 Gb Total Physical Memory | 0,70 Gb Available Physical Memory | 36,46% Memory free 3,86 Gb Paging File | 2,98 Gb Available in Paging File | 77,14% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 146,39 Gb Total Space | 117,63 Gb Free Space | 80,36% Space Free | Partition Type: NTFS Drive D: | 151,60 Gb Total Space | 151,47 Gb Free Space | 99,91% Space Free | Partition Type: NTFS Computer Name: ACER-PC | User Name: acer | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.04.15 00:58:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\acer\Desktop\OTL.exe PRC - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\NisSrv.exe PRC - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe PRC - [2013.01.27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2006.11.28 06:34:38 | 000,134,808 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\VPTray.exe PRC - [2006.11.28 06:34:28 | 000,075,416 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\SavUI.exe PRC - [2006.11.28 06:34:18 | 001,962,136 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\Rtvscan.exe PRC - [2006.11.28 06:34:02 | 000,024,728 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\DoScan.exe PRC - [2006.11.28 06:34:00 | 000,030,872 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec AntiVirus\DefWatch.exe PRC - [2006.11.22 17:12:36 | 000,107,112 | ---- | M] (Symantec Corporation) -- C:\Programme\Common Files\Symantec Shared\ccApp.exe PRC - [2006.11.22 17:12:16 | 000,107,624 | ---- | M] (Symantec Corporation) -- C:\Programme\Common Files\Symantec Shared\ccSvcHst.exe PRC - [2006.11.10 11:00:00 | 000,389,120 | ---- | M] (WinZip Computing LP) -- C:\Programme\WinZip\WZQKPICK.EXE PRC - [2004.03.11 20:40:16 | 000,186,368 | ---- | M] (SlySoft, Inc.) -- C:\Programme\SlySoft\AnyDVD\AnyDVD.exe PRC - [2003.05.15 01:19:50 | 000,217,193 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe ========== Modules (No Company Name) ========== MOD - [2006.12.03 14:53:06 | 000,126,976 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll ========== Services (SafeList) ========== SRV - [2013.03.21 15:27:57 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2006.11.28 06:34:26 | 000,122,008 | ---- | M] (symantec) [On_Demand | Stopped] -- C:\Programme\Symantec AntiVirus\SavRoam.exe -- (SavRoam) SRV - [2006.11.28 06:34:18 | 001,962,136 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus) SRV - [2006.11.28 06:34:00 | 000,030,872 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Symantec AntiVirus\DefWatch.exe -- (DefWatch) SRV - [2006.11.22 17:12:16 | 000,107,624 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr) SRV - [2006.11.22 17:12:16 | 000,107,624 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr) SRV - [2006.10.31 10:32:09 | 002,541,248 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - [2013.03.14 10:00:00 | 001,603,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20130324.007\NAVEX15.SYS -- (NAVEX15) DRV - [2013.03.14 10:00:00 | 000,093,296 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20130324.007\NAVENG.SYS -- (NAVENG) DRV - [2013.01.20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv) DRV - [2012.10.19 23:03:35 | 000,109,744 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent) DRV - [2012.10.18 08:36:58 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programme\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl) DRV - [2012.10.18 08:36:58 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Programme\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.10.05 16:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009.09.28 09:22:00 | 000,315,392 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7) DRV - [2009.07.14 00:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2009.03.18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2006.11.22 16:17:06 | 000,274,328 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtspl.sys -- (SRTSPL) DRV - [2006.11.22 16:17:06 | 000,247,144 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\srtsp.sys -- (SRTSP) DRV - [2006.11.22 16:17:06 | 000,025,448 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\srtspx.sys -- (SRTSPX) DRV - [2006.10.26 12:01:34 | 000,185,744 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\symtdi.sys -- (SYMTDI) DRV - [2006.10.26 12:01:34 | 000,026,384 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\symredrv.sys -- (SYMREDRV) DRV - [2006.10.06 14:26:16 | 000,406,672 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programme\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv) DRV - [2004.03.11 19:03:22 | 000,017,024 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD) DRV - [2003.03.28 17:25:52 | 000,003,840 | ---- | M] (Elaborate Bytes) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ElbyDelay.sys -- (ElbyDelay) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startzentrale.de IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A8 E5 4C 3C 5C 57 CD 01 [binary data] IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-4224770134-3112264526-3228493458-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\acer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.21 15:27:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.21 15:27:58 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.18 13:19:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\acer\AppData\Roaming\mozilla\Extensions [2013.03.21 15:26:58 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.03.21 15:27:58 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.04.21 03:54:08 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.13 11:21:49 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.04.21 03:54:08 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.04.21 03:54:08 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.04.21 03:54:08 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.04.21 03:54:08 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O4 - HKLM..\Run: [AnyDVD] C:\Programme\SlySoft\AnyDVD\AnyDVD.exe (SlySoft, Inc.) O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [vptray] C:\Programme\Symantec AntiVirus\VPTray.exe (Symantec Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{04276A1A-23F4-45DF-B5D0-65C16DAEDAEA}: DhcpNameServer = 192.168.178.1 O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.04.15 02:00:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013.04.15 01:59:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013.04.15 00:58:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\acer\Desktop\OTL.exe [2013.04.14 20:41:45 | 000,000,000 | ---D | C] -- C:\FRST [2013.03.25 10:03:58 | 000,000,000 | ---D | C] -- C:\Windows\TempEC6A276D-0B10-6979-48C6-32DF460B7B73-Signatures [2013.03.21 15:26:57 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox ========== Files - Modified Within 30 Days ========== [2013.04.15 02:11:07 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.15 02:11:07 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.15 02:04:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.15 02:03:56 | 1554,665,472 | -HS- | M] () -- C:\hiberfil.sys [2013.04.15 02:01:25 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.04.15 02:01:25 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.04.15 02:01:25 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.04.15 02:01:25 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.04.15 01:47:05 | 000,269,680 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.15 00:58:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\acer\Desktop\OTL.exe [2013.04.14 23:55:54 | 000,377,856 | ---- | M] () -- C:\Users\acer\Desktop\gm416uyw.exe [2013.04.14 23:53:38 | 000,000,000 | ---- | M] () -- C:\Users\acer\defogger_reenable [2013.04.14 23:52:47 | 000,050,477 | ---- | M] () -- C:\Users\acer\Desktop\Defogger.exe [2013.04.13 17:35:34 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif [2013.03.25 10:19:48 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf ========== Files Created - No Company Name ========== [2013.04.14 23:55:48 | 000,377,856 | ---- | C] () -- C:\Users\acer\Desktop\gm416uyw.exe [2013.04.14 23:53:38 | 000,000,000 | ---- | C] () -- C:\Users\acer\defogger_reenable [2013.04.14 23:52:45 | 000,050,477 | ---- | C] () -- C:\Users\acer\Desktop\Defogger.exe [2013.03.25 10:19:48 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2012.05.20 13:04:01 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2012.05.20 13:01:53 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012.07.27 14:50:26 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\.minecraft [2013.03.25 10:17:30 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Foxit Software [2012.09.16 04:17:14 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\hellomoto [2012.08.05 16:23:44 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Unity ========== Purity Check ========== < End of report > |
15.04.2013, 01:22 | #6 |
/// TB-Ausbilder | Acer Laptop weißer Bilschirm Prima, wie läuft der Rechner jetzt? Noch eine Kontrolle: Schritt 1
Code:
ATTFilter :OTL [2012.09.16 04:17:14 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\hellomoto :commands [emptytemp]
Schritt 2 Downloade dir bitte Malwarebytes Anti-Malware .
Schritt 3 Lade das Setup des ESET Online Scanners herunter und speichere es auf den Desktop.
Schritt 4 Downloade dir bitte SecurityCheck (Link 2).
Bitte poste in deiner nächsten Antwort:
__________________ --> Acer Laptop weißer Bilschirm |
15.04.2013, 23:41 | #7 |
| Acer Laptop weißer Bilschirm Der PC Läuft eigentlich seit dem aller ersten schritt schon hervorragend. OTL Code:
ATTFilter All processes killed ========== OTL ========== C:\Users\acer\AppData\Roaming\hellomoto folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: acer ->Temp folder emptied: 399734080 bytes ->Temporary Internet Files folder emptied: 33962711 bytes ->Java cache emptied: 1470 bytes ->FireFox cache emptied: 13708394 bytes ->Flash cache emptied: 118199 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 688065182 bytes RecycleBin emptied: 49081 bytes Total Files Cleaned = 1.083,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 04152013_195942 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.04.15.08 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16540 acer :: ACER-PC [Administrator] Schutz: Aktiviert 15.04.2013 20:09:44 mbam-log-2013-04-15 (20-09-44).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 192503 Laufzeit: 7 Minute(n), 38 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ESET: NO THREATS FOUND Security Check Code:
ATTFilter Results of screen317's Security Check version 0.99.62 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 JavaFX 2.1.1 Java(TM) 7 Update 5 Java version out of Date! Adobe Flash Player 11.2.202.235 Mozilla Firefox 19.0.2 Firefox out of Date! ````````Process Check: objlist.exe by Laurent```````` Norton ccSvcHst.exe Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Symantec AntiVirus DefWatch.exe Symantec AntiVirus Rtvscan.exe Symantec AntiVirus VPTray.exe ESET ESET Online Scanner OnlineScannerApp.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
15.04.2013, 23:46 | #8 |
/// TB-Ausbilder | Acer Laptop weißer Bilschirm Hallo, das sieht gut aus. Bleiben nur noch Updates und aufräumen. Schritt 1 Downloade und installiere den Internet Explorer 10. Der Internet Explorer sollte auch dann aktuell gehalten werden, wenn er nicht zum Surfen verwendet wird. Schritt 2 Dein Firefox ist nicht mehr aktuell. Starte deinen Firefox als Administrator, klicke Hilfe --> Über Firefox und führe das angebotene Update durch. Wiederhole diesen Schritt, bis Firefox als aktuell angezeigt wird. Schritt 3 Dein Java ist nicht mehr aktuell. Ältere Versionen enthalten Sicherheitslücken, die von Malware zur Infizierung per Drive-by Download missbraucht werden können. Die aktuelle Version ist Java 7 Update 17.
Überleg dir also, ob du eine Java-Installation wirklich brauchst. Falls du Java weiterhin verwenden möchtest, dann:
Schritt 4 Dein Flashplayer ist veraltet. Installiere folgendermassen die aktuelle Version:
Überprüfe dann mit diesem Plugin-Check, ob nun alle deine verwendeten Versionen aktuell sind und update sie anderenfalls. Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen.
__________________ cheers, Leo |
16.04.2013, 00:02 | #9 |
| Acer Laptop weißer Bilschirm von mir auch vielen dank für die sehr schnellen antworten. thema kann geschlossen werden. |
16.04.2013, 00:07 | #10 |
/// TB-Ausbilder | Acer Laptop weißer Bilschirm Danke für die Rückmeldung. Freut mich, dass wir helfen konnten. Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu Acer Laptop weißer Bilschirm |
acer, antivirus, applaus, association, bildschirm, cdrom, explorer.exe, farbar, farbar recovery scan tool, formatieren, free, laptop, log, microsoft, mozilla, neu, problem, registry, scan, security, services.exe, software, svchost.exe, symantec, system, system32, windows, winlogon, winlogon.exe |