|
Log-Analyse und Auswertung: Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglichWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
01.12.2013, 18:11 | #1 |
| Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich Hallo an alle! Ich hoffe ihr könnt mir bei meinem Problem helfen! Hatte seit Aktivierung einer neuen Lizenz von Avira antivir das Problem das der PC ständig abgestürzt ist. Daraufhin habe ich heute das Antivirus Programm entfernt um es wieder neu zu installieren. Nun startet mein Pc nicht mehr! Das heißt, ich komme nicht mehr auf den Desktop von Windows! Auch bei den Abgesicherten Modusen startet der Pc auch immer wieder neu! Nun weis ich nicht mehr was ich machen soll! Gibt es eine Möglichkeit die Viruse zu entfernen, ohne meine Daten zu verlieren? Habe im Forum ein ähnliches Problem gefunden und schon einige Schritte erledigt. Hoffentlich war dies nicht falsch. Hab Farbar Recovery Scan Tool heruntergeladen und habe schon eine FRST.txt Bin leider kein Profi auf diesem Gebiet bin. Ich freue mich über jede Hilfe! Danke! FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2013 Ran by SYSTEM on MININT-TB7L294 on 01-12-2013 18:51:37 Running from F:\ Windows 7 Home Premium (X86) OS Language: 0Greek Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [UpdateLBPShortCut] - C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [MDS_Menu] - C:\Program Files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink) HKLM\...\Run: [UpdateP2GoShortCut] - C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [UpdatePDRShortCut] - C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM\...\Run: [PDVD9LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe [50472 2009-04-27] (CyberLink Corp.) HKLM\...\Run: [UpdatePPShortCut] - C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [YouCam Mirror Tray icon] - C:\Program Files\CyberLink\YouCam\YouCamTray.exe [167008 2009-12-23] (CyberLink Corp.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7866912 2009-11-10] (Realtek Semiconductor) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM\...\Run: [avgnt] - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min HKU\Manolis\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [ 2013-09-15] (Apple Inc.) Startup: C:\Users\Manolis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) Startup: C:\Users\Manolis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ========================== Services (Whitelisted) ================= S4 M4-Service; C:\Users\Manolis\AppData\Roaming\Mikogo 4\M4-Service.exe [1007472 2012-01-16] () S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [244904 2009-07-27] () S2 WMI_Hook_Service; C:\Program Files\msi\OSD hot keys\WMI_Hook_Service.exe [100152 2009-12-24] (MICRO-STAR INT'L,.LTD.) S2 AntiVirFirewallService; "C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe" [x] S2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [x] S2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [x] ==================== Drivers (Whitelisted) ==================== S3 hidkmdf; C:\Windows\System32\DRIVERS\hidkmdf.sys [10360 2009-10-29] (Windows (R) Win 7 DDK provider) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-12-01] (Malwarebytes Corporation) S3 MSIDriver_IO_2; C:\Program Files\msi\OSD hot keys\MSI_MAINSYS.sys [26424 2009-12-10] (Your Corporation) S0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation) S3 NW1950; C:\Windows\System32\DRIVERS\NW1950.sys [22392 2009-10-29] () S3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1558368 2009-12-22] (NXP Semiconductors Germany GmbH) S1 avfwot; system32\DRIVERS\avfwot.sys [x] S2 avgntflt; system32\DRIVERS\avgntflt.sys [x] S1 avipbb; system32\DRIVERS\avipbb.sys [x] S1 avkmgr; system32\DRIVERS\avkmgr.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-01 18:44 - 2013-12-01 18:44 - 00000000 ____D C:\FRST 2013-12-01 18:04 - 2013-12-01 18:04 - 00003480 ____N C:\bootsqm.dat 2013-12-01 18:04 - 2013-12-01 18:04 - 00000000 __SHD C:\found.002 2013-11-30 19:32 - 2013-12-01 10:42 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys 2013-11-25 19:15 - 2013-11-25 19:15 - 09721463 _____ C:\Users\Manolis\Documents\Presentation1.pptx 2013-11-20 09:54 - 2013-11-20 09:54 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-11-20 01:34 - 2013-11-20 01:34 - 00000000 __SHD C:\found.001 2013-11-20 01:22 - 2013-11-20 01:23 - 00160704 _____ C:\Windows\Minidump\112013-27253-01.dmp 2013-11-19 19:02 - 2013-11-20 01:22 - 502563072 _____ C:\Windows\MEMORY.DMP 2013-11-19 19:02 - 2013-11-19 19:02 - 00160704 _____ C:\Windows\Minidump\111913-25240-01.dmp 2013-11-19 18:33 - 2013-11-19 18:33 - 17142784 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 11220992 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 04240384 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-11-19 18:33 - 2013-11-19 18:33 - 02166272 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 01926656 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-11-19 18:33 - 2013-11-19 18:33 - 01818112 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 01156608 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 01051136 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00703488 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00646144 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00645120 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-11-19 18:33 - 2013-11-19 18:33 - 00610304 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00523776 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00454656 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00440832 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00367104 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\System32\html.iec 2013-11-19 18:33 - 2013-11-19 18:33 - 00244736 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00238288 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00233472 _____ (Microsoft Corporation) C:\Windows\System32\url.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00208896 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00194048 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00182272 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00164864 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00151552 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00127488 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00116736 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00108032 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00083456 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00074240 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00071680 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00036352 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2013-11-19 18:32 - 2013-11-19 18:36 - 00009298 _____ C:\Windows\IE11_main.log 2013-11-19 18:16 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\System32\SmartcardCredentialProvider.dll 2013-11-19 18:16 - 2013-10-04 03:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-11-19 18:16 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\credui.dll 2013-11-19 18:16 - 2013-10-03 03:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll 2013-11-19 18:16 - 2013-09-25 04:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2013-11-19 18:16 - 2013-09-25 04:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2013-11-19 18:16 - 2013-09-25 03:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll 2013-11-19 18:16 - 2013-09-25 03:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll 2013-11-19 18:16 - 2013-09-25 03:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll 2013-11-19 18:16 - 2013-09-25 03:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2013-11-19 18:16 - 2013-09-25 03:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2013-11-19 18:16 - 2013-09-25 02:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe 2013-11-19 18:16 - 2013-09-25 02:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll 2013-11-19 18:16 - 2013-07-04 14:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2013-11-19 18:14 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\System32\nshwfp.dll 2013-11-19 18:14 - 2013-10-12 04:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL 2013-11-19 18:14 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\System32\FWPUCLNT.DLL 2013-11-19 18:14 - 2013-10-05 21:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-11-19 17:44 - 2013-11-19 17:44 - 00000000 __SHD C:\found.000 2013-11-13 14:57 - 2013-11-13 15:31 - 00012038 _____ C:\Users\Manolis\Documents\Book1.xlsx 2013-11-10 11:55 - 2013-11-10 11:55 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-10 11:52 - 2013-11-10 11:54 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-11-10 11:52 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files\iTunes 2013-11-10 11:52 - 2013-11-10 11:52 - 00000000 ____D C:\Program Files\iPod 2013-11-08 10:36 - 2013-11-08 10:36 - 00000000 ___SD C:\Users\Manolis\Documents\My Data Sources ==================== One Month Modified Files and Folders ======= 2013-12-01 18:44 - 2013-12-01 18:44 - 00000000 ____D C:\FRST 2013-12-01 18:07 - 2012-03-27 16:11 - 01089833 _____ C:\Windows\WindowsUpdate.log 2013-12-01 18:05 - 2013-03-12 13:54 - 00007782 _____ C:\Windows\PFRO.log 2013-12-01 18:05 - 2012-03-27 18:04 - 00000000 ____D C:\Program Files\Avira 2013-12-01 18:04 - 2013-12-01 18:04 - 00003480 ____N C:\bootsqm.dat 2013-12-01 18:04 - 2013-12-01 18:04 - 00000000 __SHD C:\found.002 2013-12-01 18:00 - 2012-04-23 19:16 - 00000000 ____D C:\Users\Manolis\AppData\Local\TSVNCache 2013-12-01 16:50 - 2013-03-11 10:17 - 00000000 ___RD C:\Users\Manolis\Dropbox 2013-12-01 16:50 - 2013-03-11 10:09 - 00000000 ____D C:\Users\Manolis\AppData\Roaming\Dropbox 2013-12-01 12:18 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-01 12:18 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-01 12:10 - 2013-03-05 12:45 - 00018928 _____ C:\Windows\setupact.log 2013-12-01 11:47 - 2012-03-28 15:29 - 00000000 ____D C:\OutLook 2013-12-01 11:47 - 2012-03-28 15:28 - 00000000 ____D C:\Outlook - Group Use 2013-12-01 10:42 - 2013-11-30 19:32 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys 2013-11-30 13:06 - 2012-03-29 15:30 - 00000000 ___RD C:\Users\Manolis\Spielhalle 2013-11-25 19:15 - 2013-11-25 19:15 - 09721463 _____ C:\Users\Manolis\Documents\Presentation1.pptx 2013-11-24 10:26 - 2013-09-25 11:49 - 00000000 ____D C:\Users\Manolis\CIP 2013-11-21 18:45 - 2012-11-28 14:25 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-11-21 14:47 - 2012-03-27 16:14 - 01490422 _____ C:\Windows\System32\PerfStringBackup.INI 2013-11-20 13:36 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-11-20 11:29 - 2012-10-19 17:23 - 00018288 _____ C:\Users\Manolis\Documents\Monthly Budget.xlsx 2013-11-20 09:54 - 2013-11-20 09:54 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-11-20 01:34 - 2013-11-20 01:34 - 00000000 __SHD C:\found.001 2013-11-20 01:23 - 2013-11-20 01:22 - 00160704 _____ C:\Windows\Minidump\112013-27253-01.dmp 2013-11-20 01:22 - 2013-11-19 19:02 - 502563072 _____ C:\Windows\MEMORY.DMP 2013-11-20 01:22 - 2012-03-28 20:14 - 00000000 ____D C:\Windows\Minidump 2013-11-19 19:02 - 2013-11-19 19:02 - 00160704 _____ C:\Windows\Minidump\111913-25240-01.dmp 2013-11-19 18:37 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\el-GR 2013-11-19 18:36 - 2013-11-19 18:32 - 00009298 _____ C:\Windows\IE11_main.log 2013-11-19 18:33 - 2013-11-19 18:33 - 17142784 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 11220992 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 04240384 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-11-19 18:33 - 2013-11-19 18:33 - 02166272 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 01926656 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-11-19 18:33 - 2013-11-19 18:33 - 01818112 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 01156608 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 01051136 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00703488 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00646144 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00645120 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-11-19 18:33 - 2013-11-19 18:33 - 00610304 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00523776 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00454656 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00440832 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00367104 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\System32\html.iec 2013-11-19 18:33 - 2013-11-19 18:33 - 00244736 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00238288 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00233472 _____ (Microsoft Corporation) C:\Windows\System32\url.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00208896 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00194048 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00182272 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00164864 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00151552 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00127488 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00116736 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00108032 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00083456 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00074240 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00071680 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00036352 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-11-19 18:33 - 2013-11-19 18:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-11-19 18:33 - 2013-11-19 18:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2013-11-19 18:22 - 2012-03-28 11:35 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-19 18:19 - 2013-07-20 23:05 - 00000000 ____D C:\Windows\System32\MRT 2013-11-19 18:17 - 2012-03-27 21:41 - 80340640 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-11-19 17:54 - 2012-03-27 16:11 - 00000000 ____D C:\users\Manolis 2013-11-19 17:54 - 2009-07-14 10:42 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\wfp 2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat 2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-11-19 17:44 - 2013-11-19 17:44 - 00000000 __SHD C:\found.000 2013-11-19 17:43 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\LogFiles 2013-11-13 17:46 - 2013-08-20 15:17 - 00000000 ____D C:\Users\Manolis\Documents\Takis Bekas - Latino Hair Lauf 2013-11-13 15:31 - 2013-11-13 14:57 - 00012038 _____ C:\Users\Manolis\Documents\Book1.xlsx 2013-11-10 12:40 - 2013-06-01 09:57 - 00000000 ____D C:\Users\Manolis\Eurobank 2013-11-10 11:55 - 2013-11-10 11:55 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-10 11:54 - 2013-11-10 11:52 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-11-10 11:54 - 2013-11-10 11:52 - 00000000 ____D C:\Program Files\iTunes 2013-11-10 11:52 - 2013-11-10 11:52 - 00000000 ____D C:\Program Files\iPod 2013-11-10 11:52 - 2012-03-28 13:23 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-11-08 10:36 - 2013-11-08 10:36 - 00000000 ___SD C:\Users\Manolis\Documents\My Data Sources 2013-11-03 19:19 - 2012-03-29 18:55 - 00000000 ____D C:\Users\Manolis\AppData\Roaming\Skype 2013-11-03 18:26 - 2012-03-29 18:55 - 00000000 ___RD C:\Program Files\Skype 2013-11-03 18:26 - 2012-03-29 18:55 - 00000000 ____D C:\ProgramData\Skype 2013-11-01 11:15 - 2013-04-08 13:33 - 00000000 ___RD C:\Users\Manolis\HypoVereinsbank Some content of TEMP: ==================== C:\Users\Manolis\AppData\Local\Temp\avgnt.exe C:\Users\Manolis\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Manolis\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Manolis\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Manolis\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Manolis\AppData\Local\Temp\SkypeSetup.exe ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 13% Total physical RAM: 3839.24 MB Available physical RAM: 3312.44 MB Total Pagefile: 3837.52 MB Available Pagefile: 3335.63 MB Total Virtual: 2047.88 MB Available Virtual: 1935.04 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:826.42 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (MEDHPELL32) (CDROM) (Total:2.26 GB) (Free:0 GB) CDFS Drive f: () (Removable) (Total:1.86 GB) (Free:1.44 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (Δεσμευμένο από το σύστημα) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 2 GB) (Disk ID: 496B48DD) Partition 1: (Not Active) - (Size=2 GB) - (Type=0C) LastRegBack: 2013-11-30 13:35 ==================== End Of Log ============================ --- --- --- --- --- --- |
01.12.2013, 18:13 | #2 |
/// the machine /// TB-Ausbilder | Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich Hi,
__________________hast Du Antivir auch wieder neu installiert oder ist das Problem seit der Deinstallation? Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter LastRegBack: 2013-11-30 13:35
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ |
01.12.2013, 18:25 | #3 |
| Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich Hallo,
__________________das Problem habe ich seit der Deinstallierung. Anbei die Fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-12-2013 Ran by SYSTEM at 2013-12-01 19:23:05 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** LastRegBack: 2013-11-30 13:35 ***************** DEFAULT hive was successfully copied to System32\config\HiveBackup DEFAULT hive was successfully restored from registry back up. SAM hive was successfully copied to System32\config\HiveBackup SAM hive was successfully restored from registry back up. SECURITY hive was successfully copied to System32\config\HiveBackup SECURITY hive was successfully restored from registry back up. SOFTWARE hive was successfully copied to System32\config\HiveBackup SOFTWARE hive was successfully restored from registry back up. SYSTEM hive was successfully copied to System32\config\HiveBackup SYSTEM hive was successfully restored from registry back up. ==== End of Fixlog ==== |
02.12.2013, 11:26 | #4 |
/// the machine /// TB-Ausbilder | Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich Geht es jetzt wieder?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.12.2013, 20:09 | #5 |
| Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich Nein geht leider immer noch nicht. Immer noch das selbe Problem. |
04.12.2013, 11:48 | #6 |
/// the machine /// TB-Ausbilder | Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich Als aller erstes würd ich jetzt mal Daten sichern von Aussen, mit Linux oder so. ich glaub das Ding ist hin.
__________________ --> Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich |
Themen zu Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich |
abgesicherten, aktivierung, antivir, antivirus, association, avira, avira antivir, desktop, entfernen, forum, lizenz, minidump, modus, neue, neuen, nicht mehr, problem, profi, programm, recovery, scan, startet, systemwiederherstellung, tool, verlieren, virus, windows |