![]() |
|
Log-Analyse und Auswertung: Windows 7 64Bit - weisser Bildschirm - abgesicherter Modus funktioniert nichtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
|
![]() | #1 |
| ![]() Windows 7 64Bit - weisser Bildschirm - abgesicherter Modus funktioniert nicht Betriebssystem Windows 7 - 64Bit Problem: Erst "Interpol-Trojaner" nun weisser Bildschirm, booten im abgesicherten Modus klappt nicht, Rechner fährt sofort wieder runter - nur Abgesicherter Modus m. Eingabeaufforderung geht. So, da wären wir wieder - ich und der "Bundestrojaner" a.k.a. "Interpol-Trojaner"........ ![]() Hab mich an die Anleitung hier im Board gehalten und haben den Kampf nun aufgenommen und werde meine "Erfolge" und Fortschritte hier posten. Also dann, auf ein neues...... Nun die FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by SYSTEM on MININT-96VLKF8 on 05-10-2013 13:43:24 Running from H:\REPARATUR Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ISW] - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [1127592 2012-11-22] (Check Point Software Technologies) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-02-12] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM\...\Run: [FG_Monitor] - C:\PROGRAMS\FGUARD\FGKey64.exe [129864 2008-01-04] (WinAbility® Software Corporation) HKLM-x32\...\Run: [ZoneAlarm] - C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-01-29] (Check Point Software Technologies LTD) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310640 2013-03-28] (Samsung Electronics Co., Ltd.) HKU\RK\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1511792 2013-03-28] (Samsung) HKU\RK\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup HKU\RK\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-03-28] (Samsung) HKU\RK\...\Winlogon: [Shell] explorer.exe,C:\Users\RK\AppData\Roaming\data.dat [85504 2013-08-02] () <==== ATTENTION Startup: C:\Users\RK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Services (Whitelisted) ================= S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) S2 IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [828072 2012-11-22] (Check Point Software Technologies) S2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) S2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-03] () S2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-02-12] (Crawler.com) S2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2447888 2013-01-29] (Check Point Software Technologies LTD) ==================== Drivers (Whitelisted) ==================== S2 AODDriver4.2; C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\FUEL\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S2 FGUARD64; C:\PROGRAMS\FGUARD\FGUARD64.SYS [69752 2008-01-04] (WinAbility® Software Corporation) S2 ISWKL; C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [33712 2012-11-22] (Check Point Software Technologies) S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [611160 2012-11-15] (Kaspersky Lab) S2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2013-03-15] (Windows (R) Win 7 DDK provider) S0 viamrx64; C:\Windows\System32\DRIVERS\viamrx64.sys [162928 2011-03-15] (VIA Technologies Inc.,Ltd) S1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [450136 2012-12-13] (Check Point Software Technologies LTD) S0 KL1; S5 klflt; C:\Windows\System32\Drivers\klflt.sys [89432 2012-11-15] (Kaspersky Lab) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-05 13:43 - 2013-10-05 13:43 - 00000000 ____D C:\FRST 2013-10-05 01:26 - 2013-10-05 12:38 - 00000004 _____ C:\Users\RK\AppData\Roaming\settings.ini 2013-10-04 17:45 - 2013-10-04 17:51 - 00000000 ____D C:\Users\RK\Desktop\Heike 2013-10-04 01:36 - 2013-10-04 01:36 - 00000000 ____D C:\Windows\System32\MRT 2013-10-04 01:35 - 2013-09-01 16:08 - 79143768 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-10-04 01:34 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\rdpudd.dll 2013-10-04 01:34 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys 2013-10-04 01:34 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys 2013-10-04 01:34 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-10-04 01:34 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-10-04 01:34 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2013-10-04 01:34 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll 2013-10-04 01:34 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll 2013-10-04 01:34 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll 2013-10-04 01:34 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-10-04 01:34 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll 2013-10-04 01:34 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll 2013-10-04 01:34 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\System32\tsgqec.dll 2013-10-04 01:34 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe 2013-10-04 01:34 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-10-04 01:34 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\System32\wksprt.exe 2013-10-04 01:34 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-10-04 01:34 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\System32\aaclient.dll 2013-10-04 01:34 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll 2013-10-04 01:34 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-10-04 01:34 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\System32\mstsc.exe 2013-10-04 01:34 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll 2013-10-04 01:34 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-10-04 01:34 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2013-10-04 01:33 - 2012-05-04 12:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2013-10-04 01:33 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-10-04 01:32 - 2012-08-24 19:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2013-10-04 01:32 - 2012-08-24 19:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2013-10-04 01:32 - 2012-08-24 19:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll 2013-10-04 01:32 - 2012-08-24 19:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2013-10-04 01:32 - 2012-08-24 17:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-10-04 01:32 - 2012-08-24 17:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-10-04 01:32 - 2012-08-24 17:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-10-04 01:26 - 2013-10-04 01:31 - 00000000 ____D C:\Users\RK\Documents\Battlefield 4 2013-10-03 22:57 - 2013-10-03 22:57 - 00000000 ____D C:\Users\RK\AppData\Roaming\Wargaming.net 2013-10-03 20:07 - 2013-10-03 20:07 - 00000778 _____ C:\Users\Public\Desktop\World of Tanks.lnk 2013-10-03 20:07 - 2013-10-03 20:07 - 00000000 ___HD C:\Windows\msdownld.tmp 2013-10-03 20:07 - 2013-10-03 20:07 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-10-03 17:41 - 2013-10-03 17:41 - 00000760 _____ C:\Users\Public\Desktop\Battlefield 4™ Beta.lnk 2013-10-03 17:40 - 2013-10-03 17:40 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-29 14:48 - 2013-09-29 14:48 - 00000000 _____ C:\END 2013-09-29 10:22 - 2013-09-29 10:22 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-09-22 19:21 - 2013-09-22 19:21 - 03723656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-09-21 17:46 - 2013-09-21 17:46 - 00000000 ____D C:\Users\RK\Desktop\Digital-Receiver 2013-09-15 00:04 - 2013-08-10 06:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-09-15 00:04 - 2013-08-10 06:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-09-15 00:04 - 2013-08-10 06:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-09-15 00:04 - 2013-08-10 06:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-09-15 00:04 - 2013-08-10 06:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-09-15 00:04 - 2013-08-10 06:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-09-15 00:04 - 2013-08-10 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-09-15 00:04 - 2013-08-10 04:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-15 00:04 - 2013-08-10 04:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-15 00:04 - 2013-08-10 04:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-15 00:04 - 2013-08-10 04:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-09-15 00:04 - 2013-08-10 04:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-15 00:04 - 2013-08-10 03:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-09-15 00:04 - 2013-08-10 03:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-14 14:24 - 2013-08-08 02:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-09-14 14:24 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ataport.sys 2013-09-14 14:24 - 2013-08-02 03:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-09-14 14:24 - 2013-08-02 03:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2013-09-14 14:24 - 2013-08-02 03:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll 2013-09-14 14:24 - 2013-08-02 03:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll 2013-09-14 14:24 - 2013-08-02 03:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll 2013-09-14 14:24 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2013-09-14 14:24 - 2013-08-02 03:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll 2013-09-14 14:24 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2013-09-14 14:24 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-14 14:24 - 2013-08-02 02:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-14 14:24 - 2013-08-02 02:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-14 14:24 - 2013-08-02 02:51 - 00085504 _____ C:\Users\RK\AppData\Roaming\data.dat 2013-09-14 14:24 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-14 14:24 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-14 14:24 - 2013-08-02 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe 2013-09-14 14:24 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe 2013-09-14 14:24 - 2013-08-02 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-14 14:24 - 2013-08-02 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-14 14:24 - 2013-08-02 01:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-14 14:24 - 2013-08-02 01:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-14 14:24 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-14 14:24 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-14 14:24 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-09-14 14:24 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-09-14 14:24 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-14 14:24 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-07 16:38 - 2013-09-22 19:21 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater ==================== One Month Modified Files and Folders ======= 2013-10-05 13:43 - 2013-10-05 13:43 - 00000000 ____D C:\FRST 2013-10-05 12:38 - 2013-10-05 01:26 - 00000004 _____ C:\Users\RK\AppData\Roaming\settings.ini 2013-10-05 12:34 - 2009-07-14 05:45 - 00015632 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-05 12:34 - 2009-07-14 05:45 - 00015632 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-05 12:27 - 2013-03-24 11:00 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-05 12:26 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-05 12:26 - 2009-07-14 05:51 - 00029615 _____ C:\Windows\setupact.log 2013-10-05 01:31 - 2013-03-15 22:23 - 01886115 _____ C:\Windows\WindowsUpdate.log 2013-10-05 01:26 - 2013-03-24 11:00 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-05 01:21 - 2013-03-24 11:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-05 01:15 - 2013-05-01 15:32 - 00000000 ____D C:\Auto 2013-10-04 20:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-04 17:51 - 2013-10-04 17:45 - 00000000 ____D C:\Users\RK\Desktop\Heike 2013-10-04 13:03 - 2013-03-15 22:50 - 00000000 ____D C:\ProgramData\Spyware Terminator 2013-10-04 02:15 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-10-04 01:39 - 2013-10-04 01:36 - 00000000 ____D C:\Windows\System32\MRT 2013-10-04 01:31 - 2013-10-04 01:26 - 00000000 ____D C:\Users\RK\Documents\Battlefield 4 2013-10-04 01:31 - 2013-03-25 19:26 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-04 01:27 - 2013-03-17 18:36 - 00000000 ____D C:\Users\RK\AppData\Local\PunkBuster 2013-10-04 01:27 - 2013-03-16 00:59 - 00215416 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-03 22:57 - 2013-10-03 22:57 - 00000000 ____D C:\Users\RK\AppData\Roaming\Wargaming.net 2013-10-03 20:12 - 2013-03-17 18:36 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-10-03 20:07 - 2013-10-03 20:07 - 00000778 _____ C:\Users\Public\Desktop\World of Tanks.lnk 2013-10-03 20:07 - 2013-10-03 20:07 - 00000000 ___HD C:\Windows\msdownld.tmp 2013-10-03 20:07 - 2013-10-03 20:07 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-10-03 20:06 - 2013-03-15 23:26 - 00000000 ____D C:\Spiele 2013-10-03 19:56 - 2013-03-15 23:20 - 00000000 ____D C:\ProgramData\Origin 2013-10-03 17:41 - 2013-10-03 17:41 - 00000760 _____ C:\Users\Public\Desktop\Battlefield 4™ Beta.lnk 2013-10-03 17:40 - 2013-10-03 17:40 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-03 17:40 - 2013-03-25 19:26 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-03 17:39 - 2013-03-16 00:56 - 00360038 _____ C:\Windows\DirectX.log 2013-10-03 16:50 - 2013-03-17 18:24 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-09-29 16:28 - 2013-06-23 22:56 - 00004114 _____ C:\Users\RK\Documents\Untitled.fga 2013-09-29 14:49 - 2013-09-29 14:49 - 00000000 ____D C:\Users\RK\.swt 2013-09-29 14:49 - 2013-03-15 22:23 - 00000000 ____D C:\users\RK 2013-09-29 14:48 - 2013-09-29 14:48 - 00000000 _____ C:\END 2013-09-29 10:52 - 2013-06-23 10:34 - 00000000 ____D C:\Users\RK\AppData\Roaming\vlc 2013-09-29 10:22 - 2013-09-29 10:22 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-09-29 09:53 - 2013-03-16 03:16 - 00027272 _____ C:\Windows\PFRO.log 2013-09-28 16:04 - 2013-03-24 11:00 - 00000000 ____D C:\Program Files\Google 2013-09-28 16:04 - 2013-03-24 11:00 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-22 19:21 - 2013-09-22 19:21 - 03723656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-09-22 19:21 - 2013-09-07 16:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-22 19:21 - 2013-03-24 11:00 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-22 19:21 - 2013-03-24 11:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-22 18:46 - 2013-04-07 20:25 - 00000000 ____D C:\Users\RK\AppData\Roaming\BabSolution 2013-09-22 18:46 - 2013-03-24 11:00 - 00000000 ____D C:\Users\RK\AppData\Local\Google 2013-09-21 17:46 - 2013-09-21 17:46 - 00000000 ____D C:\Users\RK\Desktop\Digital-Receiver 2013-09-17 23:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF 2013-09-15 18:15 - 2013-03-15 23:07 - 00000000 ____D C:\Program Files (x86)\Steam 2013-09-15 18:14 - 2009-07-14 05:45 - 00294168 _____ C:\Windows\System32\FNTCACHE.DAT 2013-09-07 16:38 - 2013-04-06 13:16 - 00000000 ____D C:\Users\RK\AppData\Local\Adobe Files to move or delete: ==================== C:\Users\RK\AppData\Roaming\data.dat C:\Users\RK\AppData\Roaming\settings.ini C:\Users\RK\desinst.bat C:\Users\RK\desinstart.bat C:\Users\RK\save_uninst.bat C:\Users\RK\AppData\Roaming\i.ini Some content of TEMP: ==================== C:\Users\RK\AppData\Local\Temp\AskSLib.dll C:\Users\RK\AppData\Local\Temp\catiqpeqnionhmgylqo.bfg C:\Users\RK\AppData\Local\Temp\CUninst.exe C:\Users\RK\AppData\Local\Temp\devcon.exe C:\Users\RK\AppData\Local\Temp\i4jdel0.exe C:\Users\RK\AppData\Local\Temp\nsb9D33.exe C:\Users\RK\AppData\Local\Temp\nsd4F34.exe C:\Users\RK\AppData\Local\Temp\nsd9CE7.exe C:\Users\RK\AppData\Local\Temp\nsi47B3.exe C:\Users\RK\AppData\Local\Temp\nsoA42A.exe C:\Users\RK\AppData\Local\Temp\nst4B4D.exe C:\Users\RK\AppData\Local\Temp\nsyA071.exe C:\Users\RK\AppData\Local\Temp\setup_fsu_cid.exe C:\Users\RK\AppData\Local\Temp\sonarinst.exe C:\Users\RK\AppData\Local\Temp\tmp310E.exe C:\Users\RK\AppData\Local\Temp\tmp8CD3.exe C:\Users\RK\AppData\Local\Temp\ubi31FC.tmp.exe C:\Users\RK\AppData\Local\Temp\uninst1.exe C:\Users\RK\AppData\Local\Temp\utt1CE9.tmp.exe C:\Users\RK\AppData\Local\Temp\utt63F7.tmp.exe C:\Users\RK\AppData\Local\Temp\vlc-2.0.6-win64.exe C:\Users\RK\AppData\Local\Temp\vlc-2.0.7-win64.exe C:\Users\RK\AppData\Local\Temp\vlc-2.0.8-win64.exe C:\Users\RK\AppData\Local\Temp\_isF833.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= 8 Restore point made on: 2013-09-14 14:18:33 Restore point made on: 2013-09-15 00:02:45 Restore point made on: 2013-09-21 17:46:30 Restore point made on: 2013-09-28 16:08:57 Restore point made on: 2013-10-03 15:26:44 Restore point made on: 2013-10-03 17:38:53 Restore point made on: 2013-10-03 17:40:32 Restore point made on: 2013-10-04 01:33:59 ==================== Memory info =========================== Percentage of memory in use: 7% Total physical RAM: 16354.13 MB Available physical RAM: 15166.66 MB Total Pagefile: 16352.27 MB Available Pagefile: 15168.61 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:686.61 GB) NTFS Drive e: (CDROM) (CDROM) (Total:3.17 GB) (Free:0 GB) CDFS Drive f: (Res) (CDROM) (Total:0.25 GB) (Free:0 GB) CDFS Drive g: (VERBATIM) (Fixed) (Total:465.65 GB) (Free:427.08 GB) FAT32 Drive h: () (Removable) (Total:29.7 GB) (Free:1.33 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 28DC2E54) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 466 GB) (Disk ID: E8CD189D) Partition 1: (Not Active) - (Size=466 GB) - (Type=0C) ======================================================== Disk: 2 (Size: 30 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=30 GB) - (Type=0C) LastRegBack: 2013-10-03 17:14 ==================== End Of Log ============================ --- --- --- --- --- --- Geändert von roka05 (05.10.2013 um 13:09 Uhr) |
Themen zu Windows 7 64Bit - weisser Bildschirm - abgesicherter Modus funktioniert nicht |
64bit, abgesicherten, association, betriebssystem, betriebssystem windows 7, bundestrojaner, eingabeaufforderung, farbar, farbar recovery scan tool, funktionier, funktioniert nicht, java/exploit.agent.pfi, java/exploit.cve-2013-1493.fy, nur abgesicherter modus, pup.optional.babsolution.a, pup.optional.babylon.a, pup.optional.conduit.a, pup.optional.crx.a, pup.optional.delta, pup.optional.installcore.a, pup.optional.installex, trojan.fakealert, trojan.fakescanner.dt1, win32/kryptik.blwe |