![]() |
| |||||||
Log-Analyse und Auswertung: Bundespolizei Trojaner - auch abgesicherter Modus nicht funktionsfähigWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #13 |
![]() | Bundespolizei Trojaner - auch abgesicherter Modus nicht funktionsfähigCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-10-2013
Ran by user at 2013-10-29 17:53:43 Run:3
Running from F:\
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
C:\ProgramData\4ajhbod.fki
*****************
C:\ProgramData\4ajhbod.fki => Moved successfully.
==== End of Fixlog ====
Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-10-2013 Ran by user at 2013-10-29 17:58:34 Running from F:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== Could not list Security Center items. Check WMI. ==================== Installed Programs ====================== 7-Zip 4.65 (x64 edition) (Version: 4.65.00.0) Adobe AIR (x32 Version: 2.5.1.17730) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Photoshop Elements (x32 Version: 1.0) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8) Agatha Christie - Death on the Nile (x32 Version: 2.2.0.95) Anno 1404 (x32 Version: 1.00.0000) ANNO 1404 (x32 Version: 1.03.0000) ANNO 2070 (x32 Version: 1.0.0.0) AoA Video Joiner (x32) Apple Application Support (x32 Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (x32 Version: 2.1.3.127) ArcSoft Panorama Maker 3.0 (x32) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95) Bing Bar (x32 Version: 7.0.609.0) Bloodline Champions (x32) Bonjour (Version: 3.0.0.10) Calisto DFU Driver (x64) (Version: 2.4.49092.0) Chuzzle Deluxe (x32 Version: 2.2.0.95) Citrix Authentication Manager (x32 Version: 3.0.0.47031) Citrix Receiver (DV) (x32 Version: 13.3.0.55) Citrix Receiver (HDX Flash-Umleitung) (x32 Version: 13.3.0.55) Citrix Receiver (USB) (x32 Version: 13.3.0.55) Citrix Receiver (x32 Version: 13.3.0.55) Citrix Receiver Inside (x32 Version: 3.3.0.17208) Citrix Receiver Updater (x32 Version: 3.3.0.17207) Citrix Receiver(Aero) (x32 Version: 13.3.0.55) CLX.PayMaker (x32 Version: 1.7.1.0) Colin McRae Rally 04 (x32 Version: 1.00.000) comfortlink DIRECT NET Java (TM) (x32) comfortlink MIGROSBANK (x32) comfortlink Yellow Net (x32) CyberLink DVD Suite Deluxe (x32 Version: 7.0.2823) D3DX10 (x32 Version: 15.4.2368.0902) Dashlane (HKCU Version: 2.2.1.46933) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) devolo dLAN Cockpit (x32 Version: 3.0.0.0) Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95) dLAN Cockpit (x32 Version: 3 (23.12.2010)) dLAN Cockpit (x32 Version: 3.23.12) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4030) EAX4 Unified Redist (x32 Version: 4.001) ESET Online Scanner v3 (x32) FATE (x32 Version: 2.2.0.95) FireballFTP Video Cutter Max 1.0.0.6 (x32) FotoStation Easy (x32) Free Video Dub version 2.0.7.423 (x32 Version: 2.0.7.423) Free YouTube Download version 3.0.16.923 (x32) Game Alarm (HKCU) Garmin USB Drivers (x32 Version: 2.3.1.0) Garmin WebUpdater (x32 Version: 2.5.6) Google Chrome (x32 Version: 30.0.1599.101) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4601.54) Google Update Helper (x32 Version: 1.3.21.165) GRID (x32) Half-Life 2 (x32) Half-Life 2: Episode Two (x32) Half-Life: Source (x32) Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000) HP Advisor (x32 Version: 3.4.12850.3526) HP Customer Experience Enhancements (x32 Version: 6.0.1.4) HP Game Console (x32) HP Games (x32 Version: 1.0.1.3) HP MAINSTREAM KEYBOARD (x32 Version: 1.4.3.0) HP MediaSmart DVD (x32 Version: 4.1.4229) HP MediaSmart Music (x32 Version: 4.1.4301) HP MediaSmart Photo (x32 Version: 4.1.4211) HP MediaSmart SmartMenu (Version: 3.1.1.12) HP MediaSmart Video (x32 Version: 4.1.4214) HP Odometer (x32 Version: 2.10.0000) HP Product Detection (x32 Version: 11.14.0001) HP Remote Solution (x32 Version: 1.1.14.0) HP Setup (x32 Version: 8.1.4186.3400) HP Support Assistant (x32 Version: 7.0.39.15) HP Support Information (x32 Version: 10.1.0002) HP Update (x32 Version: 5.002.003.003) HP Vision Hardware Diagnostics (Version: 2.1.2.27173) iCloud (Version: 3.0.2.163) ImTOO Video Splitter (x32 Version: 1.0.34.1231) Insaniquarium Deluxe (x32 Version: 2.2.0.95) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Rapid Storage Technology (x32 Version: 9.6.0.1014) Iron Grip: Marauders (x32) iTunes (Version: 11.1.0.126) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) Java(TM) 6 Update 23 (64-bit) (Version: 6.0.230) Jewel Quest II (x32 Version: 2.2.0.95) Jewel Quest Solitaire (x32 Version: 2.2.0.95) John Deere Drive Green (x32 Version: 2.2.0.95) Kane & Lynch 2: Dog Days (x32) LabelPrint (x32 Version: 2.5.2823) LightScribe System Software (x32 Version: 1.18.15.1) Logitech Gaming Software 64 (Version: 4.60) Logitech Gaming Software 64 (x32 Version: ) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) McAfee Internet Security (x32 Version: 12.8.856) McAfee Online Backup (Version: 1.16.4.0) McAfee Online Backup (x32) McAfee Virtual Technician (x32 Version: 7.1.0.2483) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 2.0 SP3 Runtime (x32 Version: 2.0.5050.0) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) MobileMe Control Panel (Version: 3.1.8.0) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030) Mozilla Firefox 16.0.1 (x86 en-US) (x32 Version: 16.0.1) Mozilla Firefox Packages (HKCU) Mozilla Maintenance Service (x32 Version: 16.0.1) MSVCRT (x32 Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MusicStation (x32 Version: 1.0.1.5) Nikon View 5 (x32) NVIDIA Display Control Panel (Version: 6.14.11.9793) NVIDIA Drivers (Version: 1.10.61.39) NVIDIA PhysX (x32 Version: 9.10.0222) Online Plug-in (x32 Version: 13.3.0.55) OpenAL (x32) PAYMAKER 8.0 (x32) PDF24 Creator 5.2.0 (x32) Penguins! (x32 Version: 2.2.0.95) PhotoNow! (x32 Version: 1.1.6904) Picasa 3 (x32 Version: 3.8) PictureMover (x32 Version: 3.5.0.28) Pinnacle VideoSpin (x32 Version: 2.0.0.669) Plantronics Spokes Software (x32 Version: 2.7.14092.0) Plants vs. Zombies (x32 Version: 2.2.0.95) PlayReady PC Runtime amd64 (Version: 1.3.0) Polar Bowler (x32 Version: 2.2.0.95) Power2Go (x32 Version: 6.1.4022) PowerDirector (x32 Version: 8.0.2906) QuickTime (x32 Version: 7.74.80.86) RaceRoom Racing Experience (x32) Ralink 802.11n Wireless LAN Card (x32 Version: 5.0.25.0) RealDownloader (x32 Version: 1.3.0) RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0) RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0) RealPlayer (x32 Version: 16.0.0) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6132) RealUpgrade 1.1 (x32 Version: 1.1.0) Recovery Manager (x32 Version: 5.5.2926) Safari (x32 Version: 5.34.57.2) Self-Service Plug-in (x32 Version: 3.3.0.27839) Shared C Run-time for x64 (Version: 10.0.0) Ski Challenge 13 (CH) (HKCU) Slingo Deluxe (x32 Version: 2.2.0.95) Sniper Elite (x32) Sniper Elite V2 (x32) Sniper Ghost Warrior 2 (x32) SolothurnTax 2010 10.2.17 (x32 Version: 10.2.17) SolothurnTax 2011 11.3.49 (x32 Version: 11.3.49) SolothurnTax 2012 12.3.25 (x32 Version: 12.3.25) Steam (x32 Version: 1.0.0.0) Synology Assistant (x32 Version: 1.0.0.0) Synology Data Replicator 3 (x32 Version: 1.0.0.0) Tom Clancy's Splinter Cell Double Agent (x32 Version: 1.00.0000) TomTom HOME 2.8.1.2218 (x32 Version: 2.8.1.2218) TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2) TwixTel (x32 Version: 35.00.000) Ubisoft Game Launcher (x32 Version: 1.0.0.0) Unity Web Player (HKCU Version: ) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2494150) (x32) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32) Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32) Virtual Villagers - The Secret City (x32 Version: 2.2.0.95) War of the Immortals (x32) Wedding Dash (x32 Version: 2.2.0.95) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (Version: 04/19/2012 2.3.1.0) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3538.0513) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3538.0513) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows-Treiberpaket - Plantronics, Inc. (usbser.ntamd64) Ports (04/21/2009 5.1) (Version: 04/21/2009 5.1) ZBook III (x32 Version: 10.6.366.0) ZBook III (x32) Zuma Deluxe (x32 Version: 2.2.0.95) ==================== Restore Points ========================= Could not list Restore Points. Check WMI. ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {00068534-E501-4B1C-8FC6-BE0D272F48B9} - \DealPly No Task File Task: {0CE26C0D-5421-4C19-A046-B98979829601} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-04-01] (Hewlett-Packard Company) Task: {273EED7B-552B-46EC-830E-9E98F83F0CA8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {2D5ACC9F-F721-471B-8166-8622448EF415} - System32\Tasks\{1774CDD8-B939-4329-B435-A513DECE2384} => C:\Users\user\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe Task: {47DC232F-DCE6-40A6-8952-3F010A2F8DFE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {56071535-BE4F-47AB-BAB5-ED5AFADF26D2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {63AF7300-181B-4221-8577-6C6FDA9BF3EE} - System32\Tasks\GoogleUpdateTaskMachineUA1ce854e6d96fb9c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-03] (Google Inc.) Task: {6D498D3F-F1D5-463B-9217-9CFFD3DB11A8} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1538151765-1259356480-861008499-1001 => C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {6F863807-C36D-4321-A97D-6C19A14C4290} - System32\Tasks\HPOSIAPP64 => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe [2009-02-28] () Task: {76C19BD4-00B3-4639-9963-6C2055CC7400} - System32\Tasks\Synology Data Replicator 3-CHEF-PC-user => C:\Program Files (x86)\Synology Data Replicator 3\Backup.exe [2008-06-13] (Synology Inc.) Task: {9B7F861A-0695-413B-800C-950FEA6F3594} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1538151765-1259356480-861008499-1001 => C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {A612FBE4-0D44-417D-8806-62CB57E2F70E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {C6812AFE-C92E-4B88-A11A-AB58E57BE4C1} - System32\Tasks\{91F99346-C29B-47A1-A26E-1C37347D23FC} => C:\Program Files (x86)\iTunes\iTunes.exe [2013-09-17] (Apple Inc.) Task: {C7644BDC-42CD-4167-B197-521BACB769B7} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1538151765-1259356480-861008499-1001 => C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {CF151822-58F1-44D7-98BF-78E795B53D26} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1538151765-1259356480-861008499-1001 => C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {DD031958-7CD7-4D4E-A32F-098040E5CB9D} - \DealPlyUpdate No Task File Task: {E3446223-9D83-4D1E-937F-EAAE129F9772} - System32\Tasks\HPCeeScheduleForuser => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {E4087ED5-41D1-49B1-B62E-FC49EDF44AFB} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {EAF050F8-6F36-4F2C-BC4B-9AA377CF5133} - System32\Tasks\{6CAB7BE8-0C98-4E0D-9B40-F684416155F0} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.1.0.179.161/de/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;notincluded Task: {F725B19B-D963-407F-B4DE-38569BD0AB3B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-03] (Google Inc.) Task: {FD2D6392-ECA9-4867-A769-97BC116A1494} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-13] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1ce854e6d96fb9c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForuser.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\Synology Data Replicator 3-CHEF-PC-user.job => C:\Program Files (x86)\Synology Data Replicator 3\Backup.exe ==================== Loaded Modules (whitelisted) ============= ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:3B71D0B4 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== Faulty Device Manager Devices ============= Could not list Devices. Check WMI. ==================== Event log errors: ========================= Application errors: ================== Error: (10/29/2013 05:53:07 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 10.0.9200.16720 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1844 Startzeit: 01ced4c73ffc960f Endzeit: 124 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (10/29/2013 05:51:55 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: mcshield.exe, Version: 1.1.2.123, Zeitstempel: 0x521df4ef Name des fehlerhaften Moduls: netprofm.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x4a5bdfd0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000007fef3ce75f4 ID des fehlerhaften Prozesses: 0x8c0 Startzeit der fehlerhaften Anwendung: 0xmcshield.exe0 Pfad der fehlerhaften Anwendung: mcshield.exe1 Pfad des fehlerhaften Moduls: mcshield.exe2 Berichtskennung: mcshield.exe3 Error: (10/29/2013 05:31:51 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {7dd5be93-dac9-4c2d-a7a8-a513b7cfbf8d} Error: (10/28/2013 09:04:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/24/2013 07:35:41 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/24/2013 07:35:34 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/24/2013 07:35:34 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/24/2013 07:35:04 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/24/2013 07:35:04 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/22/2013 09:29:23 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (10/29/2013 06:07:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:07:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:06:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:06:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:05:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:05:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:04:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:04:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:03:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Error: (10/29/2013 06:03:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%126 Microsoft Office Sessions: ========================= Error: (10/29/2013 05:53:07 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE10.0.9200.16720184401ced4c73ffc960f124C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (10/29/2013 05:51:55 PM) (Source: Application Error)(User: ) Description: mcshield.exe1.1.2.123521df4efnetprofm.dll_unloaded0.0.0.04a5bdfd0c0000005000007fef3ce75f48c001ced4c40fa67432C:\Program Files\Common Files\McAfee\AMCore\mcshield.exenetprofm.dll6a433929-40ba-11e3-9a82-6c626d5dcdf2 Error: (10/29/2013 05:31:51 PM) (Source: VSS)(User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {7dd5be93-dac9-4c2d-a7a8-a513b7cfbf8d} Error: (10/28/2013 09:04:03 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (10/24/2013 07:35:41 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_enu.exe Error: (10/24/2013 07:35:34 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_enu.exe Error: (10/24/2013 07:35:34 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_enu.exe Error: (10/24/2013 07:35:04 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_enu.exe Error: (10/24/2013 07:35:04 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_enu.exe Error: (10/22/2013 09:29:23 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_enu.exe CodeIntegrity Errors: =================================== Date: 2013-01-06 15:19:21.970 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\McAfee\Temp\qxz3E68\vscore\mfeelamk.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-06 15:19:21.961 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\McAfee\Temp\qxz3E68\vscore\mfeelamk.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-06 15:19:21.940 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\McAfee\Temp\qxz3E68\vscore\mfeelamk.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 8151.08 MB Available physical RAM: 5719.48 MB Total Pagefile: 16300.34 MB Available Pagefile: 13557.72 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:916.45 GB) (Free:626.32 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:14.96 GB) (Free:1.85 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (STICK ALEX) (Removable) (Total:29.8 GB) (Free:29.6 GB) FAT32 Drive k: (FLASH AT) (Removable) (Total:7.2 GB) (Free:7.19 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: FD87B6C0) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=916 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS) ======================================================== Disk: 5 (MBR Code: Windows XP) (Size: 30 GB) (Disk ID: C3072E18) Partition 1: (Not Active) - (Size=30 GB) - (Type=0C) ======================================================== Disk: 6 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18) Partition 1: (Not Active) - (Size=7 GB) - (Type=0B) ==================== End Of Log ============================ Besten Dank für deine wertvolle Unterstützung Schrauber. Habe noch das Problem beim Starten. Fehlermeldung: Problem beim Starten von C:\PROGRA~3\dobhja4.plz Das angegebene Modul wurde nicht gefunden. Gruss Alex Code:
ATTFilter Farbar Service Scanner Version: 24-10-2013
Ran by user (administrator) on 29-10-2013 at 18:14:15
Running from "C:\Users\user\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.
winmgmt Service is not running. Checking service configuration:
The start type of winmgmt service is OK.
The ImagePath of winmgmt: "%systemroot%\system32\svchost.exe -k netsvcs".
The ServiceDll of winmgmt: "C:\PROGRA~3\4ajhbod.pzz".
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2013-10-17 20:24] - [2013-09-14 02:10] - 0497152 ____A (Microsoft Corporation) 314C17917AC8523EC77A710215012A65
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-10-17 20:24] - [2013-09-08 03:30] - 1903552 ____A (Microsoft Corporation) 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
|
| Themen zu Bundespolizei Trojaner - auch abgesicherter Modus nicht funktionsfähig |
| abgesicherten, adware.installbrain, adware.yontoo, anweisung, appdata, explorer.exe, fixlist.txt, pup.dealply, pup.optional.dealply, pup.optional.dealply.a, pup.optional.installbrain.a, pup.optional.installcore.a, pup.optional.sweetim, pup.optional.sweetim.a, pup.optional.sweetpacks, pup.optional.tarma.a, rechner, roaming, runter, thema, trojan.fakems, trojan.ransom.ed, trojaner, windows, winlogon, zugriff |