|
Log-Analyse und Auswertung: Monitor Schwarz, Mauszeiger sichtbar, Windows 7 32bitWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.10.2013, 12:21 | #1 |
| Monitor Schwarz, Mauszeiger sichtbar, Windows 7 32bit Hallo zusammen, war 2 Wochen im Urlaub und meine Schwägerin hat auf unser Haus aufgepasst. Vermutlich auch den PC genutzt, war ja nicht verboten, was sie genau gemacht hat, ist wie immer unbekannt Nachdem ich nun meinen Rechner angeschalten habe, bliebt der Bildschirm schwarz, lediglich die Maus war zu sehen. Abgesicherter Modus oder ähnliches war nicht erfolgreich. Hab schon so einiges an Malware in der Vergangenheit selber bereinigen können, aber das ding bzw Problem ist mir neu. Google half und brachte mich hier her. Habe mit FRST.EXE (Windows 7 32bit) bereits gescannt. Das Protokoll sieht folgendermaßen aus: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by SYSTEM on MININT-8O8EPSC on 04-10-2013 13:02:43 Running from J:\ Windows 7 Home Premium (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [281768 2012-10-12] (Avira GmbH) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7625248 2009-07-20] (Realtek Semiconductor) HKLM\...\Run: [Launch LgDeviceAgent] - C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe [358472 2010-08-03] (Logitech Inc.) HKLM\...\Run: [Launch LCDMon] - C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [1809992 2010-08-03] (Logitech Inc.) HKLM\...\Run: [Launch LGDCore] - C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [3649096 2010-08-03] (Logitech Inc.) HKLM\...\Run: [AdobeCS4ServiceManager] - C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated) HKLM\...\Run: [TrayServer] - C:\Program Files\MAGIX\Video_deluxe_MX_Premium_Download-Version\TrayServer_de.exe [90112 2008-08-07] (MAGIX AG) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.) HKLM\...\Run: [] - [x] HKLM\...\Run: [RUSB3MON] - C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [106344 2011-05-17] (Renesas Electronics Corporation) HKLM\...\Run: [AllShareAgent] - C:\Program Files\Samsung\AllShare\AllShareAgent.exe [285072 2012-03-01] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [383424 2012-02-05] (Autodesk, Inc.) HKLM\...\Run: [CloneCDTray] - C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.) HKLM\...\Run: [Acrobat Assistant 8.0] - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840768 2013-05-10] (Adobe Systems Inc.) HKU\housedevil\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [ 2013-04-22] (Microsoft Corporation) HKU\housedevil\...\Run: [Akamai NetSession Interface] - C:\Users\housedevil\AppData\Local\Akamai\netsession_win.exe [ 2011-12-12] (Akamai Technologies, Inc) HKU\housedevil\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2013-06-21] (Skype Technologies S.A.) ========================== Services (Whitelisted) ================= S2 ACPService; C:\Program Files\Philips\CamSuite\2.0.15.0\ACPService.exe [687104 2010-08-26] () S2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.) S2 AntiVirFirewallService; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [567464 2012-10-12] (Avira GmbH) S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [340136 2012-10-12] (Avira GmbH) S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [136360 2012-10-12] (Avira GmbH) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [269480 2012-10-12] (Avira GmbH) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [428200 2012-10-12] (Avira GmbH) S2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2013-04-23] (Flexera Software, Inc.) S2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] () S2 KMService; C:\Windows\system32\srvany.exe [8192 2003-04-18] () S2 mitsijm2013; C:\Program Files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe [257344 2012-01-31] ( ) S2 SamsungAllShareV2.0; C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [25504 2012-03-02] (Samsung Electronics Co., Ltd.) S3 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [323584 2013-03-22] () S3 SimpleSlideShowServer; C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe [27584 2012-03-02] (Samsung Electronics Co., Ltd.) S2 StarMoney 7.0 OnlineUpdate; C:\Program Files\StarMoney 7.0\ouservice\StarMoneyOnlineUpdate.exe [554160 2011-11-08] (Star Finanz - Software Entwicklung und Vertriebs GmbH) S2 StarMoney 9.0 OnlineUpdate; C:\Program Files\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-06-13] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 PS3 Media Server; "C:\Program Files\PS3 Media Server\win32\service\wrapper.exe" -s "C:\Program Files\PS3 Media Server\win32\service\wrapper.conf" S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x] ==================== Drivers (Whitelisted) ==================== S3 adatadrv; C:\Windows\System32\DRIVERS\adatadrv.sys [762112 2009-07-01] (none) S3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [82952 2012-10-12] (Avira GmbH) S1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [106904 2012-10-12] (Avira GmbH) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2012-10-12] (Avira GmbH) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2012-10-12] (Avira GmbH) S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) S3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) S1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [24232 2009-02-17] (Elaborate Bytes AG) S3 IwUSB; C:\Windows\System32\Drivers\IwUSB.sys [20645 2010-10-01] (Thesycon GmbH, Germany) S3 KOBCCEX; C:\Windows\System32\drivers\KOBCCEX.sys [23424 2010-06-05] (KOBIL Systems GmbH) S3 KOBCCID; C:\Windows\System32\drivers\KOBCCID.sys [94720 2013-02-25] (KOBIL Systems GmbH) S3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [19720 2009-11-23] (Logitech Inc.) S3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [14856 2009-11-23] (Logitech Inc.) S2 NPF; C:\Windows\System32\drivers\npf.sys [35088 2010-06-25] (CACE Technologies, Inc.) S2 NPF_devolo; C:\Windows\system32\drivers\npf_devolo.sys [35840 2009-07-13] (CACE Technologies) S3 phaudlwr; C:\Windows\System32\DRIVERS\phaudlwr.sys [89648 2009-10-21] (Philips Applied Technologies) S3 PSSDK42; C:\Windows\system32\Drivers\pssdk42.sys [38976 2010-09-13] (microOLAP Technologies LTD) S3 PSSDKLBF; C:\Windows\system32\Drivers\pssdklbf.sys [53312 2010-09-13] (microOLAP Technologies LTD) S3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [91016 2012-08-27] (Renesas Electronics Corporation) S3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [181128 2012-08-27] (Renesas Electronics Corporation) S3 SNTNLUSB; C:\Windows\System32\DRIVERS\SNTNLUSB.SYS [37088 2008-07-11] (SafeNet, Inc.) S3 SPC1030; C:\Windows\System32\DRIVERS\spc1030.sys [3035776 2008-06-11] () S0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-05-30] (Duplex Secure Ltd.) S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH) S3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10064 2010-11-29] (TuneUp Software) S3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [186592 2007-06-17] (Jungo) S3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.) S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.) S3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.) S1 archlp; system32\drivers\archlp.sys [x] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [x] S3 BlueletSCOAudio; system32\DRIVERS\BlueletSCOAudio.sys [x] S3 BT; system32\DRIVERS\btnetdrv.sys [x] S3 Btcsrusb; System32\Drivers\btcusb.sys [x] S0 BTHidEnum; System32\Drivers\vbtenum.sys [x] S0 BTHidMgr; System32\Drivers\BTHidMgr.sys [x] S3 ManyCam; system32\DRIVERS\ManyCam.sys [x] S3 VComm; system32\DRIVERS\VComm.sys [x] S3 VcommMgr; System32\Drivers\VcommMgr.sys [x] S3 XDva375; \??\C:\Windows\system32\XDva375.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-04 13:02 - 2013-10-04 13:02 - 00000000 ____D C:\FRST 2013-09-16 08:01 - 2013-08-10 04:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-09-16 08:01 - 2013-08-10 04:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-09-16 08:01 - 2013-08-10 04:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-09-16 08:01 - 2013-08-10 04:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-09-16 08:01 - 2013-08-10 04:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-09-16 08:01 - 2013-08-10 04:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-09-16 08:01 - 2013-08-10 03:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-09-11 00:08 - 2013-08-08 02:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-09-11 00:08 - 2013-08-05 02:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ataport.sys 2013-09-11 00:08 - 2013-08-02 02:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2013-09-11 00:08 - 2013-08-02 02:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2013-09-11 00:08 - 2013-08-02 02:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 01:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe 2013-09-11 00:08 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 00:08 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 00:08 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-09-11 00:08 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\System32\shdocvw.dll ==================== One Month Modified Files and Folders ======= 2013-10-04 13:02 - 2013-10-04 13:02 - 00000000 ____D C:\FRST 2013-10-04 11:40 - 2010-05-30 14:11 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-03 14:57 - 2010-05-30 13:55 - 01747364 _____ C:\Windows\WindowsUpdate.log 2013-10-03 14:54 - 2010-05-30 15:39 - 00000000 ____D C:\Users\housedevil\AppData\Roaming\Skype 2013-09-28 00:50 - 2010-06-04 06:38 - 00114337 _____ C:\Windows\setupact.log 2013-09-28 00:42 - 2011-01-16 15:28 - 00000000 ____D C:\Users\housedevil\AppData\Roaming\vlc 2013-09-28 00:42 - 2010-05-30 14:00 - 01649892 _____ C:\Windows\System32\PerfStringBackup.INI 2013-09-27 20:10 - 2009-07-14 05:34 - 00018736 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-27 20:10 - 2009-07-14 05:34 - 00018736 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-27 20:03 - 2011-08-19 19:11 - 00000000 ____D C:\Program Files\Common Files\Akamai 2013-09-24 12:47 - 2013-08-18 23:24 - 00000000 ____D C:\Program Files\StarMoney 9.0 2013-09-19 18:44 - 2012-04-11 16:57 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-09-19 18:44 - 2011-06-14 05:54 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-09-17 17:18 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-09-17 16:39 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-17 16:30 - 2009-07-14 05:33 - 02564992 _____ C:\Windows\System32\FNTCACHE.DAT 2013-09-16 19:42 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\de-DE 2013-09-16 08:04 - 2010-05-30 15:11 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-16 07:59 - 2013-08-14 23:26 - 00000000 ____D C:\Windows\System32\MRT 2013-09-16 07:56 - 2010-05-30 14:16 - 76725432 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-09-15 20:03 - 2010-12-30 20:02 - 00000000 ____D C:\ProgramData\CanonIJPLM 2013-09-15 16:39 - 2013-08-04 21:43 - 00000000 ____D C:\Users\housedevil\AppData\Local\JDownloader v2.0 2013-09-14 10:35 - 2010-05-30 15:47 - 00053760 _____ C:\Users\housedevil\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 6135.11 MB Available physical RAM: 5523.31 MB Total Pagefile: 6133.39 MB Available Pagefile: 5535.11 MB Total Virtual: 2047.88 MB Available Virtual: 1931.8 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:253.81 GB) (Free:96.2 GB) NTFS Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (Eigene) (Fixed) (Total:651.6 GB) (Free:160.69 GB) NTFS Drive g: (Recover) (Fixed) (Total:25 GB) (Free:24.67 GB) NTFS Drive h: (MEDHPDEU32) (CDROM) (Total:2.31 GB) (Free:0 GB) CDFS Drive j: (Pierre64) (Fixed) (Total:59.62 GB) (Free:50.18 GB) NTFS Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (Film & Serien) (Fixed) (Total:1863.01 GB) (Free:129.54 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 2B3DE93F) Partition 1: (Not Active) - (Size=-198626754560) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: D139CE73) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=254 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=652 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=25 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 60 GB) (Disk ID: 8C625B04) Partition 1: (Not Active) - (Size=60 GB) - (Type=07 NTFS) LastRegBack: 2013-09-20 23:54 ==================== End Of Log ============================ |
04.10.2013, 12:45 | #2 |
/// the machine /// TB-Ausbilder | Monitor Schwarz, Mauszeiger sichtbar, Windows 7 32bit hi,
__________________hast Du alle 3 Safe Modes versucht?
__________________ |
04.10.2013, 12:53 | #3 |
| Monitor Schwarz, Mauszeiger sichtbar, Windows 7 32bit Hallo schrauber,
__________________habe die folgenden Modi versucht: Computer reparieren Abgesicherter Modus Abgesicherter Modus mit Netzwerktreibern Abgesicherter Modus mit Eingabeaufforderung Windows normal Starten Alles versucht, nichts hat mich bisher weitergebracht, immer Schwarzer Bildschirm mit Mauszeiger. Mit der Recoverydisk kam ich auch nicht weiter, da angeblich keine Wiederherstellungspunkte vorhanden sind, die ich aber immer anlege sobald ich was installiere. |
05.10.2013, 09:53 | #4 |
/// the machine /// TB-Ausbilder | Monitor Schwarz, Mauszeiger sichtbar, Windows 7 32bit Gibt es noch andere Benutzerprofile? Geh bitte nochmal in das Menü wo man auch Safe Mode auswählt, wähle Startprotokollierung aktivieren. Versuche dann normal zu booten. Dann bitte wieder in die Recovery und ein neues FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Monitor Schwarz, Mauszeiger sichtbar, Windows 7 32bit |
.dll, akamai, antivir, association, avg, avira, bildschirm, canon, desktop, explorer, explorer.exe, farbar, farbar recovery scan tool, google, home, launch, malware, maus, microsoft, monitor, monitor schwarz, problem, realtek, registry, secure, services.exe, software, starmoney, svchost.exe, system, windows, winlogon.exe |