|
Plagegeister aller Art und deren Bekämpfung: weisser Bildschrim beim notebookWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
13.12.2013, 20:00 | #1 |
| weisser Bildschrim beim notebook Hallo ich habe einen ASUS U36J notebook mit windows 7.Beim aufstarten kommt ein weisser Bildschirm. Ich hab der notebook Gescanned mit Farbar's Recovery Scan Tool. Was soll ich machen? Anbei die Posting Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2013 01 Ran by SYSTEM on MININT-OJV4HAJ on 13-12-2013 19:06:05 Running from E:\ Windows 7 Home Premium (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-10] (Alcor Micro Corp.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2283816 2010-08-12] (Synaptics Incorporated) HKLM\...\Run: [SynAsusAcpi] - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [92456 2010-08-12] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4156 2010-04-16] () HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [6806144 2010-06-24] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] () HKLM-x32\...\Run: [VAWinAgent] - C:\ExpressGateUtil\VAWinAgent.exe [21504 2010-08-12] () HKLM-x32\...\Run: [ccApp] - C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe [115560 2011-02-10] (Symantec Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-11] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKU\ASUS\...\Run: [] - [x] HKU\ASUS\...\Run: [NokiaSuite.exe] - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-04-18] (Nokia) HKU\ASUS\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\ASUS\...\Winlogon: [Shell] explorer.exe,C:\Users\ASUS\AppData\Roaming\Other.res [107008 2011-11-16] () <==== ATTENTION AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation) Startup: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\thunderbird.exe (Mozilla Corporation) ==================== Services (Whitelisted) ================= S2 ccEvtMgr; C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [108392 2011-02-10] (Symantec Corporation) S2 ccSetMgr; C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [108392 2011-02-10] (Symantec Corporation) S3 LiveUpdate; C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_3.EXE [3093880 2010-09-07] (Symantec Corporation) S2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-29] (Microsoft Corporation) S2 SmcService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe [3249768 2011-02-10] (Symantec Corporation) S4 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SNAC64.EXE [428912 2011-02-10] (Symantec Corporation) S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-29] (Microsoft Corporation) S2 Symantec AntiVirus; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [1839776 2011-02-10] (Symantec Corporation) S2 TGCM_ImportWiFiSvc; C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe [201080 2011-06-14] (Telefónica) S2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [77312 2010-08-20] () ==================== Drivers (Whitelisted) ==================== S1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation) S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.) S3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [81984 2010-10-28] (Fresco Logic) S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 NAVENG; C:\ProgramData\Symantec\Definitions\VirusDefs\20131211.032\eng64.sys [126040 2013-08-30] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Symantec\Definitions\VirusDefs\20131211.032\ex64.sys [2099288 2013-08-30] (Symantec Corporation) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1806400 2009-06-05] () S1 SRTSP; C:\Windows\System32\Drivers\SRTSP64.SYS [449072 2011-02-10] (Symantec Corporation) S1 SRTSP; C:\Windows\SysWow64\Drivers\SRTSP64.SYS [449072 2011-02-10] (Symantec Corporation) S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL64.SYS [482352 2011-02-10] (Symantec Corporation) S3 SRTSPL; C:\Windows\SysWow64\Drivers\SRTSPL64.SYS [482352 2011-02-10] (Symantec Corporation) S1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX64.SYS [32304 2011-02-10] (Symantec Corporation) S1 SRTSPX; C:\Windows\SysWow64\Drivers\SRTSPX64.SYS [32304 2011-02-10] (Symantec Corporation) S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [173616 2012-08-18] (Symantec Corporation) S3 Teefer2; C:\Windows\System32\DRIVERS\teefer2.sys [64048 2011-02-10] (Symantec Corporation) S2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-16] () S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [117080 2012-09-07] (Oracle Corporation) S1 WPS; C:\Windows\system32\drivers\wpsdrvnt.sys [53808 2011-02-10] (Symantec Corporation) S3 WpsHelper; C:\Windows\system32\drivers\WpsHelper.sys [233120 2012-10-04] (Symantec Corporation) S3 cpuz133; \??\C:\Users\ASUS\AppData\Local\Temp\cpuz133\cpuz133_x64.sys [x] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys 1C7857B62DE5994A75B054A9FD4C3825 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\System32\Drivers\AiCharger.sys FCEF78A26EBD74E971F2AB8236CD29D6 C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49 C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys 4C016FD76ED5C05E84CA8CAB77993961 C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\athrx.sys A5E770426D18F8EF332A593F3289DA91 C:\Windows\system32\DRIVERS\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\BrSerIb.sys E5E9B1625A767CEB6F319C12D33EAB78 C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\BrUsbSIb.sys D9F6B30AD93CBD165EC71FADF51DF25E C:\Windows\system32\drivers\BthEnum.sys CF98190A94F62E405C8CB255018B2315 C:\Windows\system32\DRIVERS\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bthpan.sys 02DD601B708DD0667E1331FA8518E9FF C:\Windows\System32\Drivers\BTHport.sys 738D0E9272F59EB7A1449C3EC118E6C4 C:\Windows\System32\Drivers\BTHUSB.sys F188B7394D81010767B6DF3178519A37 C:\Windows\System32\drivers\btusbflt.sys D3466F77C2C49C6E393BA5FBA963A33E C:\Windows\System32\drivers\btwaudio.sys A72A9101F9730DB7332714E566614E4D C:\Windows\System32\DRIVERS\btwavdt.sys 5CEEC634B617525F2B6AD29F871033F7 C:\Windows\System32\DRIVERS\btwl2cap.sys 6149301DC3F81D6F9667A3FBAC410975 C:\Windows\System32\DRIVERS\btwrchid.sys 2AF5604D28BEF77B7CF4B9D232FE7CD3 C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys 9AC4F97C2D3E93367E2148EA940CD2CD C:\Windows\System32\DRIVERS\compbatt.sys ==> MD5 is legit C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys AF2E16242AA723F68F461B6EAE2EAD3D C:\Windows\system32\DRIVERS\evbda.sys ==> MD5 is legit C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 1B7AA375F711F66D5FF2B855F9EC987F C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 7230C8B80DDE1F0524C353240B78CC0E C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ewusbnet.sys D83EB7ADE99D99A4CD6568AC1261D35E C:\Windows\System32\DRIVERS\ew_hwusbdev.sys 86F7951BBCEE4A86E79A97306BD14318 C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\FLxHCIc.sys 1E7D0CBE3C0A4DE771C9E7EAB2A08DDE C:\Windows\System32\DRIVERS\FLxHCIh.sys 75DB3989C799B9721FA828DA76621933 C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\system32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\HECIx64.sys B6AC71AAA2B10848F57FC49D55A651AF C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidir.sys ==> MD5 is legit C:\Windows\system32\drivers\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ew_jubusenum.sys C2212C930D7A6CC21972B9882683D271 C:\Windows\System32\DRIVERS\ewusbmdm.sys 6E05228393CD614B983568EC40C262C3 C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\iaStor.sys 2064090C9FAAD92C090D77E50E735B2E C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\Windows\System32\DRIVERS\igdkmd64.sys F4F91789C7C7A159CE8215C1F69F2A85 C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Impcd.sys DD587A55390ED2295BCE6D36AD567DA9 C:\Windows\System32\drivers\RTKVHD64.sys CDB772F707AC24B43A20C821852CA61F C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit C:\Windows\system32\drivers\kbdclass.sys ==> MD5 is legit C:\Windows\system32\drivers\kbdhid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbfiltr.sys E63EF8C3271D014F14E2469CE75FECB4 C:\Windows\System32\Drivers\ksecdd.sys 97A7070AEA4C058B6418519E869A63B4 C:\Windows\System32\Drivers\ksecpkg.sys 26C43A7C2862447EC59DEDA188D1DA07 C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\system32\drivers\mouclass.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163 C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ATK64AMD.sys 032D35C996F21D19A205A7C8F0B76F3C C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\ProgramData\Symantec\Definitions\VirusDefs\20131211.032\eng64.sys 702E07EC32F96ACDB873E9A5465D4401 C:\ProgramData\Symantec\Definitions\VirusDefs\20131211.032\ex64.sys 302EA314A1AF0D7CEF0A3D0195F79561 C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit C:\Windows\System32\drivers\ccdcmbx64.sys 1381E95D4E0F94F22DD484B5F8C1D61D C:\Windows\System32\drivers\ccdcmbox64.sys 205510CDB7B6084BF31760B5D06F9242 C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\drivers\nvhda64v.sys 1F07B814C0BB5AABA703ABFF1F31F2E8 C:\Windows\System32\DRIVERS\nvlddmkm.sys 5104BAC2DA2A5BDD86AC6B0708B00F06 C:\Windows\System32\DRIVERS\nvpciflt.sys 918841B2454F4F2BD94479692079490B C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\DRIVERS\pccsmcfdx64.sys 3FDE033DFB0D07F8B7D5C9A3044AA121 C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\System32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rfcomm.sys 3DD798846E2C28102B922C56E71B7932 C:\Windows\System32\DRIVERS\RsFx0103.sys CD553B8633466A6D1C115812F2619F1F C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Rt64win7.sys 20A466B9EA2BD828C0EC723F99B8CFE7 C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\serenum.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\serial.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sfloppy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\SiSG664.sys 1BC348CF6BAA90EC8E533EF6E6A69933 C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\snp2uvc.sys 1D8474722CDFFBB8FCA5FA12C50A05A2 C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\Drivers\SRTSP64.SYS 83834EBC0786CCF5EE64FBBB6A89CF3A C:\Windows\SysWow64\Drivers\SRTSP64.SYS 83834EBC0786CCF5EE64FBBB6A89CF3A C:\Windows\System32\Drivers\SRTSPL64.SYS E47D5D68917E0D70E3730263D41CEFA3 C:\Windows\SysWow64\Drivers\SRTSPL64.SYS E47D5D68917E0D70E3730263D41CEFA3 C:\Windows\System32\Drivers\SRTSPX64.SYS EA2051FF6A40C89EAA98C1769AD68597 C:\Windows\SysWow64\Drivers\SRTSPX64.SYS EA2051FF6A40C89EAA98C1769AD68597 C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28 C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit C:\Windows\system32\Drivers\SYMEVENT64x86.SYS D1F1A5E72E33D6BE449F5F1F4A513DD1 C:\Windows\System32\DRIVERS\SynTP.sys 420BFFA74350020E0AD6F22E73CB63B6 C:\Windows\System32\drivers\tcpip.sys 9849EA3843A2ADBDD1497E97A85D8CAE C:\Windows\System32\DRIVERS\tcpip.sys 9849EA3843A2ADBDD1497E97A85D8CAE C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\teefer2.sys 9416ED539BB8771EEF44D454555A97DB C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tssecsrv.sys ==> MD5 is legit C:\Windows\System32\drivers\tsusbflt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\TurboB.sys B355581A9DA34C92E2DBAFA410D2F829 C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\system32\drivers\umbus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\umpass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys 311C90F0767A63000AC35DD0A7078A30 C:\Windows\System32\DRIVERS\usbccgp.sys 6F1A3157A1C89435352CEB543CDB359C C:\Windows\system32\drivers\usbcir.sys ==> MD5 is legit C:\Windows\system32\drivers\usbehci.sys C025055FE7B87701EB042095DF1A2D7B C:\Windows\System32\DRIVERS\usbhub.sys 287C6C9410B111B68B52CA298F7B8C24 C:\Windows\system32\drivers\usbohci.sys 9840FC418B4CBD632D3D0A667A725C31 C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbscan.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbser.sys 4ACEE387FA8FD39F83564FCD2FC234F2 C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys C03DA998E412D69D18DD11D835229AF0 C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6 C:\Windows\system32\drivers\usbuhci.sys 62069A34518BCF9C1FD9E74B3F6DB7CD C:\Windows\System32\Drivers\usbvideo.sys 454800C2BC7F3927CE030141EE4F4C50 C:\Windows\System32\DRIVERS\VBoxDrv.sys F4AA0C0516C29056BE842819D6A64A5A C:\Windows\System32\DRIVERS\VBoxNetAdp.sys 57A6B43FB25B965869837350A6F1DA9E C:\Windows\System32\DRIVERS\VBoxNetFlt.sys 0E84C7FFA51D0396CB747BA93CBC596C C:\Windows\System32\Drivers\VBoxUSB.sys D37D507175C413D967D71DA155BAA3D4 C:\Windows\System32\DRIVERS\VBoxUSBMon.sys 066A0F2741E49DEF9C9E70B5298ED243 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys 442783E2CB0DA19873B7A63833FF4CB4 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wimfltr.sys 52DED146E4797E6CCF94799E8E22BB2A C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWow64\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\wpsdrvnt.sys 5C123D0266A85DC828B4DD638CBD6968 C:\Windows\system32\drivers\WpsHelper.sys 49B9FA407586503D27D17DBDEAEAC970 C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-13 19:04 - 2013-12-13 19:04 - 00000000 ____D C:\FRST 2013-12-13 05:07 - 2013-12-13 05:07 - 00107008 _____ C:\Users\ASUS\Downloads\adobeflashplayerv10.2.152.32.exe 2013-12-13 01:50 - 2013-12-13 01:50 - 00044544 _____ C:\Users\ASUS\Desktop\2013-14 GE 2.xls 2013-12-13 01:48 - 2013-12-13 01:48 - 00044544 _____ C:\Users\ASUS\Desktop\Kopie von 2_ge_answers_deo31_2008-09.xls 2013-12-08 06:53 - 2013-12-08 06:57 - 00000000 ____D C:\Users\ASUS\Desktop\1 2013-12-08 06:53 - 2013-12-08 06:55 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-12-08 06:53 - 2013-12-08 06:53 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2013-12-08 06:53 - 2013-12-08 06:53 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\TuneUp Software 2013-12-08 06:52 - 2013-12-08 06:52 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Philipp Winterberg 2013-12-08 06:52 - 2013-12-08 06:52 - 00000000 ____D C:\Program Files (x86)\RarZilla Free Unrar 2013-12-08 06:51 - 2013-12-08 06:51 - 01718088 _____ (Philipp Winterberg) C:\Users\ASUS\Downloads\InstallRarZilla.exe 2013-12-07 21:41 - 2013-12-07 21:41 - 17625561 ____N C:\Users\ASUS\Desktop\1.rar 2013-12-04 01:12 - 2013-12-04 01:12 - 00614784 _____ C:\Users\ASUS\Downloads\Free PDF to Word Doc Converter - CHIP-Downloader.exe 2013-12-03 14:16 - 2013-12-03 14:16 - 05139456 _____ C:\Users\ASUS\Downloads\Διαφάνειες Τόμου Β.ppt 2013-11-21 14:59 - 2013-11-21 14:59 - 13332116 _____ C:\Users\ASUS\Desktop\Desktop.7z 2013-11-20 14:17 - 2013-12-02 02:26 - 00000000 ____D C:\Users\ASUS\Desktop\DEO 45 2013-11-17 05:20 - 2013-11-17 05:20 - 00000833 _____ C:\Users\ASUS\Downloads\Outlook.zip 2013-11-17 05:19 - 2013-11-17 05:19 - 00000659 _____ C:\Users\ASUS\Downloads\B-9,B-10 Steriou 844644 blatt3 (1).tar.gz 2013-11-17 05:16 - 2013-11-17 05:16 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-11-17 05:15 - 2013-11-17 05:15 - 01110476 _____ C:\Users\ASUS\Downloads\7z920.exe 2013-11-17 05:11 - 2013-11-17 05:14 - 00000000 ____D C:\Program Files\7-Zip 2013-11-17 05:10 - 2013-11-17 05:10 - 01376768 _____ C:\Users\ASUS\Downloads\7z920-x64.msi 2013-11-17 05:07 - 2013-11-17 05:07 - 00000659 _____ C:\Users\ASUS\Downloads\B-9,B-10 Steriou 844644 blatt3 .tar.gz 2013-11-17 04:18 - 2013-12-02 02:11 - 00000000 ____D C:\Users\ASUS\Desktop\MEDION STICK 2013-11-16 07:27 - 2013-11-16 07:30 - 00000000 ____D C:\Users\ASUS\Desktop\Neuer Ordner 2013-11-16 07:04 - 2013-11-16 07:04 - 19583525 _____ C:\Users\ASUS\Downloads\Finanzmathe-Teil 2.zip 2013-11-16 06:55 - 2013-11-16 06:55 - 22087078 _____ C:\Users\ASUS\Downloads\Finanzmathe.zip 2013-11-16 06:34 - 2009-07-20 16:42 - 00078872 _____ (Microsoft Corporation) C:\Windows\System32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll 2013-11-16 06:34 - 2009-07-20 16:42 - 00050200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll 2013-11-16 06:33 - 2009-07-20 16:42 - 00111640 _____ (Microsoft Corporation) C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll 2013-11-16 06:33 - 2009-07-20 16:42 - 00079896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll 2013-11-16 06:32 - 2013-11-16 06:32 - 00000000 ____D C:\Windows\System32\RsFx 2013-11-16 06:32 - 2013-11-16 06:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\SysWOW64\1033 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\SysWOW64\1031 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\System32\1033 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\System32\1031 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 9.0 2013-11-16 06:29 - 2013-11-16 06:31 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2013-11-16 06:28 - 2013-11-16 06:33 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2013-11-16 06:24 - 2013-12-10 12:31 - 00000000 ____D C:\Users\ASUS\Documents\Visual Studio 2010 2013-11-16 06:23 - 2013-11-16 06:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Windows\symbols 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Program Files\Microsoft Help Viewer 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-11-16 06:20 - 2013-11-16 06:20 - 00000000 ____D C:\Windows\PCHEALTH 2013-11-16 06:06 - 2013-11-16 06:06 - 03349320 _____ (Microsoft Corporation) C:\Users\ASUS\Downloads\vc_web.exe 2013-11-16 06:02 - 2013-11-16 06:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-14 12:25 - 2013-11-14 12:36 - 00000000 ____D C:\Users\ASUS\Desktop\finanzmathematik vorlesung 2013-11-14 02:04 - 2013-12-13 08:53 - 00065536 _____ C:\Windows\System32\Ikeext.etl ==================== One Month Modified Files and Folders ======= 2013-12-13 19:04 - 2013-12-13 19:04 - 00000000 ____D C:\FRST 2013-12-13 08:53 - 2013-11-14 02:04 - 00065536 _____ C:\Windows\System32\Ikeext.etl 2013-12-13 08:53 - 2013-04-21 11:49 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-13 08:52 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-13 08:51 - 2013-07-11 22:28 - 00036440 _____ C:\Windows\setupact.log 2013-12-13 08:51 - 2010-12-01 02:11 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-13 07:58 - 2010-12-01 01:38 - 01753806 _____ C:\Windows\WindowsUpdate.log 2013-12-13 07:57 - 2012-04-07 13:08 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Skype 2013-12-13 07:57 - 2012-03-27 04:36 - 00045056 _____ C:\Windows\System32\acovcnt.exe 2013-12-13 07:54 - 2013-07-13 13:57 - 00000000 ____D C:\Users\ASUS\AppData\Local\CrashDumps 2013-12-13 06:30 - 2009-07-13 20:45 - 00012288 _____ C:\Windows\System32\umstartup.etl 2013-12-13 06:09 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\tracing 2013-12-13 05:07 - 2013-12-13 05:07 - 00107008 _____ C:\Users\ASUS\Downloads\adobeflashplayerv10.2.152.32.exe 2013-12-13 05:01 - 2013-04-21 11:49 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-13 04:40 - 2012-04-12 10:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-13 04:24 - 2013-10-30 14:16 - 00000284 _____ C:\Windows\Tasks\FoxTab.job 2013-12-13 01:50 - 2013-12-13 01:50 - 00044544 _____ C:\Users\ASUS\Desktop\2013-14 GE 2.xls 2013-12-13 01:48 - 2013-12-13 01:48 - 00044544 _____ C:\Users\ASUS\Desktop\Kopie von 2_ge_answers_deo31_2008-09.xls 2013-12-13 01:28 - 2009-08-04 01:51 - 00774682 _____ C:\Windows\System32\perfh007.dat 2013-12-13 01:28 - 2009-08-04 01:51 - 00177376 _____ C:\Windows\System32\perfc007.dat 2013-12-13 01:28 - 2009-07-13 21:13 - 01830898 _____ C:\Windows\System32\PerfStringBackup.INI 2013-12-13 00:46 - 2012-07-10 11:38 - 00000432 _____ C:\Windows\BRWMARK.INI 2013-12-13 00:34 - 2013-08-01 02:21 - 00000000 ____D C:\Users\ASUS\AppData\Local\CUSTPDF Writer 2013-12-12 23:36 - 2009-07-13 20:45 - 00010016 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-12 23:36 - 2009-07-13 20:45 - 00010016 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-11 05:25 - 2013-08-11 05:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-10 12:33 - 2012-05-05 04:04 - 00000000 ____D C:\Users\ASUS\.VirtualBox 2013-12-10 12:31 - 2013-11-16 06:24 - 00000000 ____D C:\Users\ASUS\Documents\Visual Studio 2010 2013-12-09 01:05 - 2010-12-01 02:23 - 00001618 _____ C:\Windows\System32\ServiceFilter.ini 2013-12-09 01:03 - 2013-07-11 22:27 - 00020790 _____ C:\Windows\PFRO.log 2013-12-08 06:57 - 2013-12-08 06:53 - 00000000 ____D C:\Users\ASUS\Desktop\1 2013-12-08 06:55 - 2013-12-08 06:53 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-12-08 06:53 - 2013-12-08 06:53 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2013-12-08 06:53 - 2013-12-08 06:53 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\TuneUp Software 2013-12-08 06:52 - 2013-12-08 06:52 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Philipp Winterberg 2013-12-08 06:52 - 2013-12-08 06:52 - 00000000 ____D C:\Program Files (x86)\RarZilla Free Unrar 2013-12-08 06:52 - 2013-07-15 13:54 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\OpenCandy 2013-12-08 06:51 - 2013-12-08 06:51 - 01718088 _____ (Philipp Winterberg) C:\Users\ASUS\Downloads\InstallRarZilla.exe 2013-12-08 04:36 - 2013-06-03 01:54 - 00000000 ____D C:\Users\ASUS\Documents\Fax 2013-12-08 04:12 - 2013-07-10 12:27 - 00000000 ____D C:\Users\ASUS\Desktop\MORAKI 2013-12-07 21:41 - 2013-12-07 21:41 - 17625561 ____N C:\Users\ASUS\Desktop\1.rar 2013-12-05 10:09 - 2013-04-21 11:49 - 00002177 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-12-05 09:56 - 2013-04-21 11:49 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-05 09:56 - 2013-04-21 11:49 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-04 01:15 - 2013-06-16 15:39 - 00000000 ____D C:\Program Files (x86)\Free PDF to Word Doc Converter 2013-12-04 01:12 - 2013-12-04 01:12 - 00614784 _____ C:\Users\ASUS\Downloads\Free PDF to Word Doc Converter - CHIP-Downloader.exe 2013-12-04 01:07 - 2013-10-16 06:09 - 00000000 ____D C:\Users\ASUS\Desktop\SPITIA 2013-12-04 01:05 - 2013-04-03 12:33 - 00000000 ____D C:\Users\ASUS\Desktop\GEO 2013-12-04 01:03 - 2013-09-17 23:41 - 00000000 ____D C:\Users\ASUS\Desktop\DOULIES 2013-12-03 14:16 - 2013-12-03 14:16 - 05139456 _____ C:\Users\ASUS\Downloads\Διαφάνειες Τόμου Β.ppt 2013-12-02 02:26 - 2013-11-20 14:17 - 00000000 ____D C:\Users\ASUS\Desktop\DEO 45 2013-12-02 02:11 - 2013-11-17 04:18 - 00000000 ____D C:\Users\ASUS\Desktop\MEDION STICK 2013-12-01 09:11 - 2013-10-15 10:40 - 00000000 ____D C:\Users\ASUS\Desktop\FRONTISTHRIO 2013-12-01 06:18 - 2013-01-30 12:00 - 00000000 ____D C:\Users\ASUS\Desktop\ΕΦΟΡΙΑ 2013-11-29 07:23 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF 2013-11-27 01:49 - 2012-04-07 13:08 - 00000000 ____D C:\ProgramData\Skype 2013-11-27 01:49 - 2012-04-07 12:42 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-26 05:11 - 2013-06-14 13:00 - 00000000 ____D C:\Users\ASUS\Desktop\CSI_Einladungen 2013-11-25 09:43 - 2009-07-13 21:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-11-21 14:59 - 2013-11-21 14:59 - 13332116 _____ C:\Users\ASUS\Desktop\Desktop.7z 2013-11-21 02:32 - 2013-09-17 06:12 - 00000000 ____D C:\Users\ASUS\Desktop\XAVR 2013-11-17 05:20 - 2013-11-17 05:20 - 00000833 _____ C:\Users\ASUS\Downloads\Outlook.zip 2013-11-17 05:19 - 2013-11-17 05:19 - 00000659 _____ C:\Users\ASUS\Downloads\B-9,B-10 Steriou 844644 blatt3 (1).tar.gz 2013-11-17 05:16 - 2013-11-17 05:16 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-11-17 05:15 - 2013-11-17 05:15 - 01110476 _____ C:\Users\ASUS\Downloads\7z920.exe 2013-11-17 05:14 - 2013-11-17 05:11 - 00000000 ____D C:\Program Files\7-Zip 2013-11-17 05:10 - 2013-11-17 05:10 - 01376768 _____ C:\Users\ASUS\Downloads\7z920-x64.msi 2013-11-17 05:07 - 2013-11-17 05:07 - 00000659 _____ C:\Users\ASUS\Downloads\B-9,B-10 Steriou 844644 blatt3 .tar.gz 2013-11-17 03:32 - 2013-11-02 05:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-16 07:30 - 2013-11-16 07:27 - 00000000 ____D C:\Users\ASUS\Desktop\Neuer Ordner 2013-11-16 07:04 - 2013-11-16 07:04 - 19583525 _____ C:\Users\ASUS\Downloads\Finanzmathe-Teil 2.zip 2013-11-16 06:55 - 2013-11-16 06:55 - 22087078 _____ C:\Users\ASUS\Downloads\Finanzmathe.zip 2013-11-16 06:37 - 2013-11-16 06:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 06:33 - 2013-11-16 06:28 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2013-11-16 06:32 - 2013-11-16 06:32 - 00000000 ____D C:\Windows\System32\RsFx 2013-11-16 06:32 - 2013-11-16 06:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\SysWOW64\1033 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\SysWOW64\1031 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\System32\1033 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Windows\System32\1031 2013-11-16 06:31 - 2013-11-16 06:31 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 9.0 2013-11-16 06:31 - 2013-11-16 06:29 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2013-11-16 06:31 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2013-11-16 06:25 - 2013-11-16 06:25 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2013-11-16 06:23 - 2013-11-16 06:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0 2013-11-16 06:23 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Windows\symbols 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Program Files\Microsoft Help Viewer 2013-11-16 06:22 - 2013-11-16 06:22 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-11-16 06:22 - 2013-07-28 03:52 - 01622066 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-16 06:20 - 2013-11-16 06:20 - 00000000 ____D C:\Windows\PCHEALTH 2013-11-16 06:06 - 2013-11-16 06:06 - 03349320 _____ (Microsoft Corporation) C:\Users\ASUS\Downloads\vc_web.exe 2013-11-14 12:36 - 2013-11-14 12:25 - 00000000 ____D C:\Users\ASUS\Desktop\finanzmathematik vorlesung 2013-11-13 13:12 - 2013-11-12 05:03 - 00000000 ____D C:\Program Files (x86)\IminentToolbar 2013-11-13 13:11 - 2013-11-12 05:03 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog ZeroAccess: C:\Windows\Installer\{42677c4b-104a-0abf-8ffb-67ca7c9f429f} C:\Windows\Installer\{42677c4b-104a-0abf-8ffb-67ca7c9f429f}\@ ZeroAccess: C:\Users\ASUS\AppData\Local\{42677c4b-104a-0abf-8ffb-67ca7c9f429f} Some content of TEMP: ==================== C:\Users\ASUS\AppData\Local\Temp\NEventMessages.dll C:\Users\ASUS\AppData\Local\Temp\NOSEventMessages.dll ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== BCD ================================ Windows Boot Manager -------------------- identifier {bootmgr} device boot description Windows Boot Manager locale de-DE inherit {globalsettings} default {default} resumeobject {8cb2d9b0-7c05-11de-842e-b4611d44fefa} displayorder {default} toolsdisplayorder {memdiag} timeout 30 Windows Boot Loader ------------------- identifier {572bcd56-ffa7-11d9-aae0-0007e994107d} Windows Boot Loader ------------------- identifier {default} device boot path \Windows\system32\winload.exe description Windows 7 locale de-DE inherit {bootloadersettings} recoverysequence {current} recoveryenabled Yes osdevice boot systemroot \Windows resumeobject {8cb2d9b0-7c05-11de-842e-b4611d44fefa} nx OptIn bootlog No Windows Boot Loader ------------------- identifier {current} device ramdisk=[C:]\Recovery\8cb2d9b4-7c05-11de-842e-b4611d44fefa\Winre.wim,{8cb2d9b5-7c05-11de-842e-b4611d44fefa} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\8cb2d9b4-7c05-11de-842e-b4611d44fefa\Winre.wim,{8cb2d9b5-7c05-11de-842e-b4611d44fefa} systemroot \windows nx OptIn winpe Yes Resume from Hibernate --------------------- identifier {8cb2d9b0-7c05-11de-842e-b4611d44fefa} device boot path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows Memory Tester --------------------- identifier {memdiag} device unknown path \boot\memtest.exe description Windows Memory Diagnostic locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS Settings ------------ identifier {emssettings} bootems Yes Debugger Settings ----------------- identifier {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM Defects ----------- identifier {badmemory} Global Settings --------------- identifier {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Boot Loader Settings -------------------- identifier {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisor Settings ------------------- identifier {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Resume Loader Settings ---------------------- identifier {resumeloadersettings} inherit {globalsettings} Device options -------------- identifier {8cb2d9b5-7c05-11de-842e-b4611d44fefa} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\8cb2d9b4-7c05-11de-842e-b4611d44fefa\boot.sdi Device options -------------- identifier {ad6c7bc8-fa0f-11da-8ddf-0013200354d8} description Ramdisk Device Options ramdisksdidevice unknown ramdisksdipath \boot.sdi ==================== Memory info =========================== Percentage of memory in use: 14% Total physical RAM: 3884.29 MB Available physical RAM: 3305.57 MB Total Pagefile: 3882.43 MB Available Pagefile: 3301.49 MB Total Virtual: 8192 MB Available Virtual: 8191.87 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:74.52 GB) (Free:18.31 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:211.85 GB) (Free:207.58 GB) NTFS Drive e: () (Removable) (Total:0.97 GB) (Free:0.96 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 6897E73A) Partition 1: (Not Active) - (Size=12 GB) - (Type=1C) Partition 2: (Active) - (Size=75 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=212 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 993 MB) (Disk ID: 31E9F8F5) Partition 1: (Active) - (Size=993 MB) - (Type=0B) LastRegBack: 2013-11-30 04:44 ==================== End Of Log ============================ |
13.12.2013, 20:36 | #2 | |
/// the machine /// TB-Ausbilder | weisser Bildschrim beim notebook hi,
__________________Zitat:
Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\ASUS\...\Winlogon: [Shell] explorer.exe,C:\Users\ASUS\AppData\Roaming\Other.res [107008 2011-11-16] () <==== ATTENTION C:\Users\ASUS\AppData\Roaming\Other.res
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. rechner normal starten.
__________________ |
13.12.2013, 21:14 | #3 |
| weisser Bildschrim beim notebook Hallo Schrauber
__________________vielen Dank für die schnelle Unterstützung! Code:
ATTFilter Hallo Schrauber vielen Dank für die schnelle Unterstützung! Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-12-2013 01 Ran by SYSTEM at 2013-12-13 20:57:25 Run:1 Running from E:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** HKU\ASUS\...\Winlogon: [Shell] explorer.exe,C:\Users\ASUS\AppData\Roaming\Other.res [107008 2011-11-16] () <==== ATTENTION C:\Users\ASUS\AppData\Roaming\Other.res ***************** HKU\ASUS\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully. C:\Users\ASUS\AppData\Roaming\Other.res => Moved successfully. ==== End of Fixlog ==== alles hat gut geklappt. danke vielmals alles hat gut geklappt. danke vielmals |
14.12.2013, 07:50 | #4 |
/// the machine /// TB-Ausbilder | weisser Bildschrim beim notebook Kontrollscans im normalen Modus Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu weisser Bildschrim beim notebook |
adobe, adobe flash player, antivirus, association, asus, bootmgr, converter, desktop, explorer, explorer.exe, flash player, hdaudio.sys, home, i8042prt.sys, micro, microsoft, mozilla, notebook, nvidia, nvpciflt.sys, pdf, registry, services.exe, svchost.exe, symantec, system, temp, usbvideo.sys, windows, winlogon.exe |