|
Log-Analyse und Auswertung: Windows Vista-Beim Booten kein Signal an den MonitorWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.12.2013, 18:31 | #1 |
| Windows Vista-Beim Booten kein Signal an den Monitor Hallo Trojaner Board, beim Hochfahren bekommt mein Monitor kein Signal, der Rechner scheint aber hochzufahren. Ein bis mehrere Male mit "reset" abermals hochfahren, dann funktioniert es meistens. Bekomme keine Fehlermeldungen, außer im Bios den Optionenbildschrim auf welche Art hochgefahren werden soll, wegen Zwangs-shut down mit reset Knopf. Außerdem, wenns mal läuft, friert mir der Bildschrim ein. Egal wo und wann. Kann beim Spielen sein, Internet, oder einfach nur beim Arbeiten am PC. USB Ports funktionieren auch nicht alle, oft muss ich mehrmals bereits bekannte Hardware anstecken, damit der Computer es registriert. Habe vor etwa 2 Monaten nvidia Treiber erneuert, bin mir aber nicht sicher, ob die Probleme damit losgingen... Hatte den Computer mal kurz vom ´Stromnetz und bekam beim Hochfahren prompt eine Meldung "cmos checksum error" und Datum und Uhrzeit war total verstellt...habs erst beim Internet surfen gemerkt...! Hier schon mal die logs laut Anleitung: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 17:18 on 16/12/2013 (Norbert) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-12-2013 02 Ran by Norbert (administrator) on NORBERT-PC on 16-12-2013 17:21:01 Running from C:\Users\Norbert\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English(US) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe () C:\Program Files\Belkin\F5D8055\v2\BelkinDetectUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Curse) C:\Users\Norbert\AppData\Local\Apps\2.0\HQJYWCPJ.4ZO\X3MCQ0JK.P1W\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe () C:\Program Files\Opera\18.0.1284.68\opera_crashreporter.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [591696 2008-05-07] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [F5D8055v2] - C:\Program Files\Belkin\F5D8055\v2\BelkinDetectUI.exe [196608 2009-04-15] () HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295512 2013-10-17] (RealNetworks, Inc.) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKCU\...\Run: [TomTomHOME.exe] - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-03-22] (TomTom) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Norbert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://at.msn.com/?st=1 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x766D3BB98C72CA01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKCU - ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 212.186.211.21 ========================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [51168 2009-11-06] (NOS Microsystems Ltd.) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () S3 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [1616048 2013-07-31] (AVG Secure Search) S2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [x] S2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [x] ==================== Drivers (Whitelisted) ==================== R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2009-12-01] () R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209176 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147768 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [56816 2009-12-09] (Avira GmbH) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-07-31] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [96104 2009-03-30] (Avira GmbH) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [7680 2009-12-01] () S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [718336 2010-10-18] (Ralink Technology Corp.) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S1 avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [x] S3 catchme; \??\C:\Users\Norbert\AppData\Local\Temp\catchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 USBMULCD; system32\drivers\CM106.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-16 17:21 - 2013-12-16 17:21 - 00010184 _____ C:\Users\Norbert\Desktop\FRST.txt 2013-12-16 17:20 - 2013-12-16 17:20 - 01060997 _____ (Farbar) C:\Users\Norbert\Desktop\FRST.exe 2013-12-16 17:20 - 2013-12-16 17:20 - 00000000 ____D C:\FRST 2013-12-16 17:16 - 2013-12-16 17:18 - 00000476 _____ C:\Users\Norbert\Desktop\defogger_disable.log 2013-12-16 17:16 - 2013-12-16 17:16 - 00000000 _____ C:\Users\Norbert\defogger_reenable 2013-12-16 17:11 - 2013-12-16 17:11 - 00050477 _____ C:\Users\Norbert\Desktop\Defogger.exe 2013-12-15 17:28 - 2013-12-15 17:28 - 00000000 ____D C:\Users\Norbert\AppData\Local\NVIDIA Corporation 2013-12-15 17:21 - 2013-12-15 17:21 - 199358496 _____ (NVIDIA Corporation) C:\Users\Norbert\Downloads\331.82-desktop-win8-win7-winvista-32bit-international-whql.exe 2013-12-14 12:01 - 2013-12-14 12:01 - 00000971 _____ C:\Users\Norbert\Desktop\Wow - Shortcut.lnk 2013-12-12 10:57 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 10:57 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 10:57 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 10:57 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 10:57 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 10:57 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 10:57 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 10:57 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 10:57 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 10:57 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 10:57 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 10:57 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 10:57 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 07:24 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 07:24 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 07:24 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 07:24 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 07:24 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 07:24 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 07:24 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 18:44 - 2013-12-12 19:32 - 00000000 ____D C:\Users\Norbert\Desktop\WTF1 2013-12-11 18:44 - 2013-12-11 18:46 - 00000000 ____D C:\Users\Norbert\Desktop\Cache1 2013-12-11 18:20 - 2013-12-11 18:20 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\NVIDIA 2013-12-11 11:48 - 2013-12-11 11:48 - 00000000 _____ C:\Windows\setupact.log 2013-12-11 10:07 - 2013-12-11 10:07 - 00000864 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TuneUp Software 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVG2014 2013-12-11 10:06 - 2013-12-11 10:07 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-11 10:06 - 2013-12-11 10:06 - 00000000 ___HD C:\$AVG 2013-12-11 10:05 - 2013-12-11 10:05 - 00000000 ____D C:\Program Files\AVG 2013-12-11 10:03 - 2013-12-16 15:34 - 00000000 ____D C:\ProgramData\MFAData 2013-12-11 10:03 - 2013-12-11 10:42 - 00000000 ____D C:\Users\Norbert\AppData\Local\Avg2014 2013-12-11 10:03 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\MFAData 2013-12-11 10:02 - 2013-12-11 10:02 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet (1).exe 2013-12-11 09:42 - 2013-12-11 09:42 - 00212584 _____ C:\Windows\Minidump\Mini121113-01.dmp 2013-12-11 09:41 - 2013-12-11 09:41 - 06243424 _____ (Systweak Inc ) C:\Users\Norbert\Downloads\rcpsetup1_dcomnew_sec_728_dcomnew_sec_728.exe 2013-12-11 09:41 - 2013-12-11 09:41 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet.exe 2013-12-02 20:59 - 2013-12-02 20:59 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVAST Software 2013-12-02 20:49 - 2013-12-02 20:49 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-02 19:26 - 2013-12-02 19:26 - 00231576 _____ C:\Windows\Minidump\Mini120213-01.dmp 2013-11-29 13:30 - 2013-11-29 13:30 - 00002051 _____ C:\Users\Norbert\Downloads\einkaufskorb.csv 2013-11-26 14:54 - 2013-11-14 12:55 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233182.dll 2013-11-26 14:54 - 2013-11-14 12:55 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233182.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 22951200 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 10446112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-11-26 14:53 - 2013-11-14 12:55 - 09663656 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 09619872 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 02947872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 02747680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-11-17 12:25 - 2013-11-17 12:25 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-11-17 12:20 - 2013-11-14 12:55 - 15862272 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll 2013-11-17 12:20 - 2013-10-23 11:24 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233165.dll 2013-11-17 12:20 - 2013-10-23 11:24 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233165.dll ==================== One Month Modified Files and Folders ======= 2013-12-16 17:21 - 2013-12-16 17:21 - 00010184 _____ C:\Users\Norbert\Desktop\FRST.txt 2013-12-16 17:20 - 2013-12-16 17:20 - 01060997 _____ (Farbar) C:\Users\Norbert\Desktop\FRST.exe 2013-12-16 17:20 - 2013-12-16 17:20 - 00000000 ____D C:\FRST 2013-12-16 17:18 - 2013-12-16 17:16 - 00000476 _____ C:\Users\Norbert\Desktop\defogger_disable.log 2013-12-16 17:16 - 2013-12-16 17:16 - 00000000 _____ C:\Users\Norbert\defogger_reenable 2013-12-16 17:16 - 2009-12-01 12:59 - 00000000 ____D C:\Users\Norbert 2013-12-16 17:11 - 2013-12-16 17:11 - 00050477 _____ C:\Users\Norbert\Desktop\Defogger.exe 2013-12-16 16:28 - 2008-01-21 02:35 - 01892430 _____ C:\Windows\WindowsUpdate.log 2013-12-16 16:25 - 2010-01-06 12:58 - 00000000 ____D C:\Users\Norbert\AppData\Local\Deployment 2013-12-16 16:24 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-16 16:24 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-16 16:24 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-16 15:41 - 2013-08-16 21:10 - 00000000 ____D C:\Program Files\Opera 2013-12-16 15:34 - 2013-12-11 10:03 - 00000000 ____D C:\ProgramData\MFAData 2013-12-15 19:18 - 2006-11-02 14:01 - 00032644 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-15 18:23 - 2012-10-22 16:12 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-15 17:28 - 2013-12-15 17:28 - 00000000 ____D C:\Users\Norbert\AppData\Local\NVIDIA Corporation 2013-12-15 17:28 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-12-15 17:27 - 2009-12-01 13:09 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-15 17:21 - 2013-12-15 17:21 - 199358496 _____ (NVIDIA Corporation) C:\Users\Norbert\Downloads\331.82-desktop-win8-win7-winvista-32bit-international-whql.exe 2013-12-15 15:32 - 2011-04-18 09:57 - 00000000 ____D C:\Users\Norbert\Norbert neu 2013-12-15 15:30 - 2006-11-02 11:33 - 00765776 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-14 12:01 - 2013-12-14 12:01 - 00000971 _____ C:\Users\Norbert\Desktop\Wow - Shortcut.lnk 2013-12-12 19:32 - 2013-12-11 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\WTF1 2013-12-12 19:03 - 2006-11-02 13:47 - 00248664 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-12 10:59 - 2013-08-05 14:54 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 10:58 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-12 08:10 - 2010-04-03 16:35 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TS3Client 2013-12-11 18:46 - 2013-12-11 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\Cache1 2013-12-11 18:20 - 2013-12-11 18:20 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\NVIDIA 2013-12-11 11:48 - 2013-12-11 11:48 - 00000000 _____ C:\Windows\setupact.log 2013-12-11 11:23 - 2012-06-26 08:13 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 11:23 - 2011-09-13 09:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 10:42 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\Avg2014 2013-12-11 10:17 - 2009-12-12 21:40 - 00000000 ____D C:\Windows\Minidump 2013-12-11 10:07 - 2013-12-11 10:07 - 00000864 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TuneUp Software 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVG2014 2013-12-11 10:07 - 2013-12-11 10:06 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-11 10:06 - 2013-12-11 10:06 - 00000000 ___HD C:\$AVG 2013-12-11 10:05 - 2013-12-11 10:05 - 00000000 ____D C:\Program Files\AVG 2013-12-11 10:03 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\MFAData 2013-12-11 10:02 - 2013-12-11 10:02 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet (1).exe 2013-12-11 09:42 - 2013-12-11 09:42 - 00212584 _____ C:\Windows\Minidump\Mini121113-01.dmp 2013-12-11 09:41 - 2013-12-11 09:41 - 06243424 _____ (Systweak Inc ) C:\Users\Norbert\Downloads\rcpsetup1_dcomnew_sec_728_dcomnew_sec_728.exe 2013-12-11 09:41 - 2013-12-11 09:41 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet.exe 2013-12-10 10:01 - 2010-09-15 01:56 - 00000000 ____D C:\found.000 2013-12-04 15:57 - 2011-11-27 01:33 - 00000000 ____D C:\Program Files\Google 2013-12-04 15:57 - 2010-09-28 13:31 - 00000000 ____D C:\Users\Norbert\AppData\Local\Google 2013-12-02 20:59 - 2013-12-02 20:59 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVAST Software 2013-12-02 20:52 - 2010-09-14 17:10 - 00269216 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-02 20:49 - 2013-12-02 20:49 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-02 20:48 - 2006-11-02 11:23 - 00002577 _____ C:\Windows\system32\config.nt 2013-12-02 19:26 - 2013-12-02 19:26 - 00231576 _____ C:\Windows\Minidump\Mini120213-01.dmp 2013-11-29 13:30 - 2013-11-29 13:30 - 00002051 _____ C:\Users\Norbert\Downloads\einkaufskorb.csv 2013-11-17 12:25 - 2013-11-17 12:25 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-11-17 12:25 - 2009-12-01 13:35 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-11-17 10:07 - 2010-04-03 16:34 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-16 16:30 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-12-2013 02 Ran by Norbert at 2013-12-16 17:21:36 Running from C:\Users\Norbert\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== 7-Zip 9.16 beta Adobe Download Manager (Version: 1.6.2.49) Adobe Flash Player 11 ActiveX (Version: 11.9.900.170) Adobe Flash Player 11 Plugin (Version: 11.9.900.170) Adobe Reader 9.3.2 - Deutsch (Version: 9.3.2) Adobe Reader 9.5.5 - Deutsch (Version: 9.5.5) AVG 2014 (Version: 14.0.3658) AVG 2014 (Version: 14.0.4259) AVG 2014 (Version: 2014.0.4259) Belkin N+ Wireless USB Adapter (Version: 2.00.06) Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000) Cool & Quiet Curse Client (HKCU Version: 5.1.1.792) Epson Easy Photo Print 2 (Version: 2.0.0.0) Epson Event Manager (Version: 2.01.00) Epson Print CD (Version: 2.00.00) EPSON PX800FW Series Printer Uninstall EPSON Scan EPSON Stylus Photo PX700W_PX800FW_TX700W_TX800FW Handbuch Free Driver Scout (Version: 1.0.0.101) GSview 4.9 Java 7 Update 45 (Version: 7.0.450) Java Auto Updater (Version: 2.1.9.8) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938) Microsoft Office XP Professional mit FrontPage (Version: 10.0.6626.0) Microsoft Silverlight (Version: 4.0.50826.0) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) NVIDIA 3D Vision Controller Driver 331.82 (Version: 331.82) NVIDIA Control Panel 331.82 (Version: 331.82) NVIDIA Display Control Panel (Version: 6.14.12.5896) NVIDIA GeForce Experience 1.7.1 (Version: 1.7.1) NVIDIA Graphics Driver 331.82 (Version: 331.82) NVIDIA Install Application (Version: 2.1002.140.952) NVIDIA LED Visualizer 1.0 (Version: 1.0) NVIDIA PhysX (Version: 9.13.0725) NVIDIA PhysX System Software 9.13.0725 (Version: 9.13.0725) NVIDIA Update 9.3.21 (Version: 9.3.21) NVIDIA Update Components (Version: 9.3.21) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0) Opera Stable 18.0.1284.68 (Version: 18.0.1284.68) PVSonyDll (Version: 1.00.0001) RealDownloader (Version: 1.3.3) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0) RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0) RealPlayer (Version: 16.0.3) RealUpgrade 1.1 (Version: 1.1.0) SAMSUNG USB Driver for Mobile Phones (Version: 1.4.103.0) Secunia PSI (3.0.0.7011) (Version: 3.0.0.7011) System Requirements Lab TeamSpeak 3 Client (Version: 3.0.13.1) TomTom HOME (Version: 2.9.5) TomTom HOME Visual Studio Merge Modules (Version: 1.0.2) Visual Studio 2012 x86 Redistributables (Version: 14.0.0.1) World of Warcraft ==================== Restore Points ========================= 12-12-2013 07:09:06 Scheduled Checkpoint 12-12-2013 09:57:14 Windows Update 12-12-2013 19:50:52 Windows Update 13-12-2013 12:30:04 WinZip 17.5 wird entfernt 13-12-2013 12:35:00 Windows Update 13-12-2013 16:45:53 Windows Update 14-12-2013 12:52:44 Windows Update 15-12-2013 11:45:42 Windows Update 15-12-2013 14:26:11 Windows Update 15-12-2013 15:10:30 Windows Update 15-12-2013 16:24:27 Device Driver Package Install: NVIDIA Display adapters 15-12-2013 16:27:36 Device Driver Package Install: NVIDIA Universal Serial Bus controllers 15-12-2013 18:18:05 Windows Update ==================== Hosts content: ========================== 2006-11-02 11:23 - 2013-08-05 15:16 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {183C6459-5B6F-4DA9-AB42-A3777031C292} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe Task: {1C15172B-F8F4-4B44-9881-867CE240BFEC} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1006003231-2697031979-1953750779-1000 => Rundll32.exe portabledeviceapi.dll,#1 Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {1E110028-0926-4147-A05B-32683682C09A} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1006003231-2697031979-1953750779-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {2D720758-712B-455F-B3C7-A18B89417524} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1006003231-2697031979-1953750779-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {2FDBDC47-7148-49DB-9D32-32E6A003C996} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {36A1B5E6-8F9A-41FF-9F57-11F62A8C53CA} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1006003231-2697031979-1953750779-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {5B3A1C4A-EC5A-447D-B7B2-7760BF65C5BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {70E9E92B-F31B-4F59-80AE-5BFE32A91F0F} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1006003231-2697031979-1953750779-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {A1868F64-ED08-49A9-9F86-F62ED855AFFD} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => Rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {B0973208-3DFF-4B32-8373-14BA22DE4807} - \CreateChoiceProcessTask No Task File Task: {B96FFB5F-431B-4E91-B122-ACE0252A4119} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {C6B5ACA0-0F6B-48E6-A21F-6E5BE253C9A5} - System32\Tasks\FreeDriverScout => C:\Program Files\Covus Freemium\Free Driver Scout\1Click.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: {F056B862-2DE2-46F4-B124-D1B754B74F21} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe Task: {F8D6E476-24FE-4649-A4D7-985706B29128} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{A972CF4C-A94D-411E-B01B-AB8C488CC158}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-16 22:17 - 2013-08-16 22:17 - 00035840 _____ () C:\Users\Norbert\AppData\Local\Apps\2.0\HQJYWCPJ.4ZO\X3MCQ0JK.P1W\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.Advertising.dll 2013-08-16 22:17 - 2013-08-16 22:17 - 00014848 _____ () C:\Users\Norbert\AppData\Local\Apps\2.0\HQJYWCPJ.4ZO\X3MCQ0JK.P1W\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.WowDb.dll 2013-08-16 22:17 - 2013-08-16 22:17 - 00099840 _____ () C:\Users\Norbert\AppData\Local\Apps\2.0\HQJYWCPJ.4ZO\X3MCQ0JK.P1W\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.CMOD2.dll 2013-12-16 15:41 - 2013-12-12 10:15 - 00879968 _____ () C:\Program Files\Opera\18.0.1284.68\ffmpegsumo.dll 2013-12-16 15:41 - 2013-12-12 10:15 - 00886624 _____ () C:\Program Files\Opera\18.0.1284.68\libglesv2.dll 2013-12-16 15:41 - 2013-12-12 10:15 - 00108896 _____ () C:\Program Files\Opera\18.0.1284.68\libegl.dll 2013-12-11 11:23 - 2013-12-11 11:23 - 16242056 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service" ==================== Faulty Device Manager Devices ============= Name: USB Human Interface Device Description: USB Human Interface Device Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da} Manufacturer: (Standard system devices) Service: HidUsb Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/16/2013 05:14:06 PM) (Source: SideBySide) (User: ) Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (12/16/2013 05:14:06 PM) (Source: SideBySide) (User: ) Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (12/16/2013 05:13:35 PM) (Source: SideBySide) (User: ) Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (12/16/2013 05:13:35 PM) (Source: SideBySide) (User: ) Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (12/16/2013 04:25:56 PM) (Source: Perflib) (User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib) (User: ) Description: PolicyAgent Error: (12/16/2013 04:25:56 PM) (Source: Perflib) (User: ) Description: OpenIPSecPerformanceDataC:\Windows\System32\ipsecsvc.dllPolicyAgent4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib) (User: ) Description: MSDTCC:\Windows\system32\msdtcuiu.DLL4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib) (User: ) Description: LsaC:\Windows\system32\Secur32.dll4 System errors: ============= Error: (12/16/2013 04:25:26 PM) (Source: Service Control Manager) (User: ) Description: avgio Error: (12/16/2013 04:25:26 PM) (Source: Service Control Manager) (User: ) Description: ScRegSetValueExWFailureActions%%5 Error: (12/16/2013 04:25:26 PM) (Source: Service Control Manager) (User: ) Description: Avira AntiVir Guard%%3 Error: (12/16/2013 04:25:26 PM) (Source: Service Control Manager) (User: ) Description: Avira AntiVir Planer%%3 Error: (12/16/2013 04:24:10 PM) (Source: Microsoft-Windows-TaskScheduler) (User: NT AUTHORITY) Description: 2147942402 Error: (12/16/2013 04:24:09 PM) (Source: EventLog) (User: ) Description: The previous system shutdown at 16:22:43 on 16.12.2013 was unexpected. Error: (12/16/2013 04:20:56 PM) (Source: Microsoft-Windows-TaskScheduler) (User: NT AUTHORITY) Description: 2147942402 Error: (12/16/2013 04:20:55 PM) (Source: EventLog) (User: ) Description: The previous system shutdown at 15:38:45 on 16.12.2013 was unexpected. Error: (12/16/2013 03:29:49 PM) (Source: Service Control Manager) (User: ) Description: avgio Error: (12/16/2013 03:29:49 PM) (Source: Service Control Manager) (User: ) Description: ScRegSetValueExWFailureActions%%5 Microsoft Office Sessions: ========================= Error: (12/16/2013 05:14:06 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Epson Software\Easy Photo Print\Microsoft.VC80.MFC\MFC80.DLL Error: (12/16/2013 05:14:06 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Epson Software\Easy Photo Print\Microsoft.VC80.MFC\MFC80.DLL Error: (12/16/2013 05:13:35 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Epson Software\Easy Photo Print\Microsoft.VC80.MFC\MFC80.DLL Error: (12/16/2013 05:13:35 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Epson Software\Easy Photo Print\Microsoft.VC80.MFC\MFC80.DLL Error: (12/16/2013 04:25:56 PM) (Source: Perflib)(User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib)(User: ) Description: PolicyAgent Error: (12/16/2013 04:25:56 PM) (Source: Perflib)(User: ) Description: OpenIPSecPerformanceDataC:\Windows\System32\ipsecsvc.dllPolicyAgent4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib)(User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib)(User: ) Description: MSDTCC:\Windows\system32\msdtcuiu.DLL4 Error: (12/16/2013 04:25:56 PM) (Source: Perflib)(User: ) Description: LsaC:\Windows\system32\Secur32.dll4 CodeIntegrity Errors: =================================== Date: 2013-12-16 17:21:22.512 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-16 17:21:22.352 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-16 17:21:22.189 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-16 17:21:22.017 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-11 12:14:29.163 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-11 12:14:29.009 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-11 12:14:28.838 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-11 12:14:28.667 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-11 11:56:06.621 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. Date: 2013-12-11 11:56:06.450 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3069.63 MB Available physical RAM: 1642.16 MB Total Pagefile: 6354.2 MB Available Pagefile: 4714.98 MB Total Virtual: 2047.88 MB Available Virtual: 1904.84 MB ==================== Drives ================================ Drive c: (SYSTEM) (Fixed) (Total:100.01 GB) (Free:29.73 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (BACKUP) (Fixed) (Total:465.76 GB) (Free:266.02 GB) NTFS Drive j: (DATEN) (Fixed) (Total:365.75 GB) (Free:346.35 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 1BB1E3DB) Partition 1: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=366 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: A69C290E) Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ "There is no disk in the drive. Please insert a disk into drive\Device\Harddisk\DR2." Das Textfenster hieß:gmer_2.1.19163.exe Ich hoffe Ihr könnt damit schon mal etwas angangen, ich kanns leider nicht. Habe im Moment AVG installiert und keine Bedrohungen gefunden, habe auch mit Avast alles scannen lassen und kein Virus gefunden. Bitte um Eure Hilfe. Lg, Plekdemon |
16.12.2013, 18:53 | #2 | |
/// the machine /// TB-Ausbilder | Windows Vista-Beim Booten kein Signal an den Monitor hi,
__________________Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ |
16.12.2013, 19:18 | #3 |
| Windows Vista-Beim Booten kein Signal an den Monitor Hallo Schrauber,
__________________das war rasch, danke vielmals vorerst. Code:
ATTFilter ComboFix 13-12-16.01 - Norbert 16.12.2013 19:02:04.1.4 - x86 ausgeführt von:: c:\users\Norbert\Desktop\ComboFix.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-11-16 bis 2013-12-16 )))))))))))))))))))))))))))))) . . 2013-12-16 16:20 . 2013-12-16 16:20 -------- d-----w- C:\FRST 2013-12-15 16:28 . 2013-12-15 16:28 -------- d-----w- c:\users\Norbert\AppData\Local\NVIDIA Corporation 2013-12-13 07:22 . 2013-11-08 01:15 7772552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76FA336D-7078-481F-8FDF-1F65DAA7594A}\mpengine.dll 2013-12-12 06:24 . 2013-10-30 00:35 2050560 ----a-w- c:\windows\system32\win32k.sys 2013-12-12 06:24 . 2013-10-22 07:19 158208 ----a-w- c:\windows\system32\imagehlp.dll 2013-12-12 06:24 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll 2013-12-12 06:24 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx 2013-12-12 06:24 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll 2013-12-12 06:24 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe 2013-12-12 06:24 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe 2013-12-11 17:20 . 2013-12-11 17:20 -------- d-----w- c:\users\Norbert\AppData\Roaming\NVIDIA 2013-12-11 09:07 . 2013-12-11 09:07 -------- d-----w- c:\users\Norbert\AppData\Roaming\AVG2014 2013-12-11 09:07 . 2013-12-11 09:07 -------- d-----w- c:\users\Norbert\AppData\Roaming\TuneUp Software 2013-12-11 09:06 . 2013-12-11 09:07 -------- d-----w- c:\programdata\AVG2014 2013-12-11 09:06 . 2013-12-11 09:06 -------- d-----w- C:\$AVG 2013-12-11 09:05 . 2013-12-11 09:05 -------- d-----w- c:\program files\AVG 2013-12-11 09:03 . 2013-12-16 16:51 -------- d-----w- c:\programdata\MFAData 2013-12-11 09:03 . 2013-12-11 09:42 -------- d-----w- c:\users\Norbert\AppData\Local\Avg2014 2013-12-11 09:03 . 2013-12-11 09:03 -------- d-----w- c:\users\Norbert\AppData\Local\MFAData 2013-12-06 17:19 . 2013-12-06 17:19 -------- d-----w- c:\windows\Migration 2013-12-02 19:59 . 2013-12-02 19:59 -------- d-----w- c:\users\Norbert\AppData\Roaming\AVAST Software 2013-12-02 19:49 . 2013-12-02 19:49 -------- d-----w- c:\programdata\AVAST Software 2013-11-26 13:54 . 2013-11-14 11:55 893728 ----a-w- c:\windows\system32\nvdispgenco3233182.dll 2013-11-26 13:54 . 2013-11-14 11:55 1049888 ----a-w- c:\windows\system32\nvdispco3233182.dll 2013-11-26 13:53 . 2013-11-14 11:55 10446112 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-11-26 13:53 . 2013-11-14 11:55 9619872 ----a-w- c:\windows\system32\nvopencl.dll 2013-11-26 13:53 . 2013-11-14 11:55 22951200 ----a-w- c:\windows\system32\nvoglv32.dll 2013-11-26 13:53 . 2013-11-14 11:55 9663656 ----a-w- c:\windows\system32\nvcuda.dll 2013-11-26 13:53 . 2013-11-14 11:55 2947872 ----a-w- c:\windows\system32\nvcuvid.dll 2013-11-26 13:53 . 2013-11-14 11:55 2747680 ----a-w- c:\windows\system32\nvcuvenc.dll 2013-11-26 13:53 . 2013-11-14 11:55 17560352 ----a-w- c:\windows\system32\nvcompiler.dll 2013-11-17 11:25 . 2013-11-17 11:25 -------- d-----w- c:\program files\AGEIA Technologies 2013-11-17 11:20 . 2013-10-23 10:24 893728 ----a-w- c:\windows\system32\nvdispgenco3233165.dll 2013-11-17 11:20 . 2013-10-23 10:24 1049888 ----a-w- c:\windows\system32\nvdispco3233165.dll 2013-11-17 11:20 . 2013-11-14 11:55 15862272 ----a-w- c:\windows\system32\nvwgf2um.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-11 10:23 . 2012-06-26 07:13 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-12-11 10:23 . 2011-09-13 08:04 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-12-02 19:52 . 2010-09-14 16:10 269216 ----a-w- c:\windows\system32\aswBoot.exe 2013-11-14 11:55 . 2012-10-10 20:14 15218504 ----a-w- c:\windows\system32\nvd3dum.dll 2013-11-14 11:55 . 2012-10-10 20:14 2697248 ----a-w- c:\windows\system32\nvapi.dll 2013-11-11 14:26 . 2010-07-09 14:37 4321056 ----a-w- c:\windows\system32\nvcpl.dll 2013-11-11 14:26 . 2010-07-09 14:37 3036960 ----a-w- c:\windows\system32\nvsvc.dll 2013-11-11 14:26 . 2011-08-29 11:00 2555168 ----a-w- c:\windows\system32\nvsvcr.dll 2013-11-11 14:26 . 2010-07-09 14:37 664352 ----a-w- c:\windows\system32\nvvsvc.exe 2013-11-11 14:26 . 2010-07-09 14:37 209184 ----a-w- c:\windows\system32\nvmctray.dll 2013-11-11 14:26 . 2009-09-27 16:47 62752 ----a-w- c:\windows\system32\nvshext.dll 2013-11-11 04:50 . 2009-12-01 12:06 230048 ------w- c:\windows\system32\MpSigStub.exe 2013-11-05 20:50 . 2013-11-05 20:50 120600 ----a-w- c:\windows\system32\drivers\avgdiskx.sys 2013-11-04 20:57 . 2013-11-04 20:57 209176 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys 2013-10-31 22:00 . 2013-10-31 22:00 176952 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2013-10-31 21:30 . 2013-10-31 21:30 222520 ----a-w- c:\windows\system32\drivers\avglogx.sys 2013-10-24 21:28 . 2013-10-24 21:28 147768 ----a-w- c:\windows\system32\drivers\avgidshx.sys 2013-10-17 10:26 . 2013-06-23 09:25 499712 ----a-w- c:\windows\system32\msvcp71.dll 2013-10-17 10:26 . 2013-06-23 09:25 348160 ----a-w- c:\windows\system32\msvcr71.dll 2013-10-11 02:08 . 2013-11-13 22:43 444928 ----a-w- c:\windows\system32\IKEEXT.DLL 2013-10-11 02:07 . 2013-11-13 22:43 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2013-10-08 05:50 . 2013-10-17 07:13 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-10-03 12:45 . 2013-11-13 22:43 297984 ----a-w- c:\windows\system32\gdi32.dll 2013-10-03 12:45 . 2013-11-13 22:43 993792 ----a-w- c:\windows\system32\crypt32.dll 2013-09-30 23:49 . 2013-09-30 23:49 102712 ----a-w- c:\windows\system32\drivers\avgmfx86.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2013-03-22 248208] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-05-07 591696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "F5D8055v2"="c:\program files\Belkin\F5D8055\v2\BelkinDetectUI.exe" [2009-04-15 196608] "Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "TkBellExe"="c:\program files\real\realplayer\Update\realsched.exe" [2013-10-17 295512] "AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2013-11-07 4956176] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - UXDIYFOG *Deregistered* - uxdiyfog . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Inhalt des "geplante Tasks" Ordners . 2013-12-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-26 10:23] . 2010-09-14 c:\windows\Tasks\User_Feed_Synchronization-{A972CF4C-A94D-411E-B01B-AB8C488CC158}.job - c:\windows\system32\msfeedssync.exe [2011-08-17 09:54] . . ------- Zusätzlicher Suchlauf ------- . IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 Trusted Zone: asus.de\support TCP: DhcpNameServer = 195.34.133.21 212.186.211.21 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file) ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file) . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2013-12-16 19:09 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Zeit der Fertigstellung: 2013-12-16 19:10:35 ComboFix-quarantined-files.txt 2013-12-16 18:10 . Vor Suchlauf: 32.295.911.424 bytes free Nach Suchlauf: 32.074.592.256 bytes free . - - End Of File - - 7255849E5F9050A1360F7E8268DA990F 5C616939100B85E558DA92B899A0FC36 |
17.12.2013, 10:29 | #4 |
/// the machine /// TB-Ausbilder | Windows Vista-Beim Booten kein Signal an den Monitor Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.12.2013, 18:51 | #5 |
| Windows Vista-Beim Booten kein Signal an den Monitor Guten Abend Schrauber, bitteschön, die logs: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.12.17.06 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Norbert :: NORBERT-PC [administrator] 17.12.2013 18:11:35 mbam-log-2013-12-17 (18-11-35).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 223746 Time elapsed: 5 minute(s), 56 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\Norbert\Downloads\SoftonicDownloader_fuer_curse-client.exe (PUP.Optional.Softonic) -> Quarantined and deleted successfully. (end) Code:
ATTFilter # AdwCleaner v3.015 - Report created 17/12/2013 at 18:34:13 # Updated 10/12/2013 by Xplode # Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Username : Norbert - NORBERT-PC # Running from : C:\Users\Norbert\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Program Files\Common Files\AVG Secure Search File Deleted : C:\Windows\System32\Tasks\FreeDriverScout File Deleted : C:\Windows\System32\Tasks\Software Updater Ui File Deleted : C:\Windows\System32\Tasks\Software Updater ***** [ Shortcuts ] ***** ***** [ Registry ] ***** [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6B5ACA0-0F6B-48E6-A21F-6E5BE253C9A5} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6B5ACA0-0F6B-48E6-A21F-6E5BE253C9A5} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{183C6459-5B6F-4DA9-AB42-A3777031C292} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{183C6459-5B6F-4DA9-AB42-A3777031C292} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F056B862-2DE2-46F4-B124-D1B754B74F21} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F056B862-2DE2-46F4-B124-D1B754B74F21} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE} Key Deleted : HKCU\Software\Softonic ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16526 ************************* AdwCleaner[R0].txt - [1910 octets] - [17/12/2013 18:32:17] AdwCleaner[S0].txt - [1820 octets] - [17/12/2013 18:34:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1880 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by Norbert on 17.12.2013 at 18:40:36,90 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 17.12.2013 at 18:42:57,40 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-12-2013 01 Ran by Norbert (administrator) on NORBERT-PC on 17-12-2013 18:44:57 Running from C:\Users\Norbert\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English(US) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe () C:\Program Files\Belkin\F5D8055\v2\BelkinDetectUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe () C:\Program Files\Opera\18.0.1284.68\opera_crashreporter.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [591696 2008-05-07] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [F5D8055v2] - C:\Program Files\Belkin\F5D8055\v2\BelkinDetectUI.exe [196608 2009-04-15] () HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295512 2013-10-17] (RealNetworks, Inc.) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKCU\...\Run: [TomTomHOME.exe] - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-03-22] (TomTom) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Norbert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://at.msn.com/?st=1 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x766D3BB98C72CA01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKCU - ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 212.186.211.21 ========================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [51168 2009-11-06] (NOS Microsystems Ltd.) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () S3 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [x] S2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [x] S2 vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2009-12-01] () R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209176 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147768 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [56816 2009-12-09] (Avira GmbH) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-07-31] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [96104 2009-03-30] (Avira GmbH) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [7680 2009-12-01] () S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [718336 2010-10-18] (Ralink Technology Corp.) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S1 avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [x] S3 catchme; \??\C:\Users\Norbert\AppData\Local\Temp\catchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 USBMULCD; system32\drivers\CM106.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-17 18:44 - 2013-12-17 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\FRST-OlderVersion 2013-12-17 18:42 - 2013-12-17 18:42 - 00000636 _____ C:\Users\Norbert\Desktop\JRT.txt 2013-12-17 18:39 - 2013-12-17 18:39 - 01034531 _____ (Thisisu) C:\Users\Norbert\Desktop\JRT.exe 2013-12-17 18:37 - 2013-12-17 18:37 - 00001960 _____ C:\Users\Norbert\Desktop\AdwCleaner[S0].txt 2013-12-17 18:32 - 2013-12-17 18:34 - 00000000 ____D C:\AdwCleaner 2013-12-17 18:31 - 2013-12-17 18:31 - 01226750 _____ C:\Users\Norbert\Desktop\adwcleaner.exe 2013-12-17 18:08 - 2013-12-17 18:08 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-17 18:08 - 2013-12-17 18:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-17 18:08 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-12-17 18:05 - 2013-12-17 18:05 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Norbert\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-12-16 19:21 - 2013-12-17 18:27 - 00000944 _____ C:\Windows\PFRO.log 2013-12-16 19:10 - 2013-12-16 19:10 - 00011331 _____ C:\ComboFix.txt 2013-12-16 19:00 - 2013-12-16 19:10 - 00000000 ____D C:\Qoobox 2013-12-16 19:00 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-12-16 19:00 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-12-16 19:00 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-12-16 18:58 - 2013-12-16 18:58 - 05154128 ____R (Swearware) C:\Users\Norbert\Desktop\ComboFix.exe 2013-12-16 17:50 - 2013-12-16 17:50 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe 2013-12-16 17:45 - 2013-12-16 17:45 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe.opdownload 2013-12-16 17:40 - 2013-12-16 17:40 - 00037291 _____ C:\Users\Norbert\Downloads\xkxkv9bf.exe.opdownload 2013-12-16 17:38 - 2013-12-16 17:38 - 00037254 _____ C:\Users\Norbert\Downloads\gmer_2.1.19163.exe.opdownload 2013-12-16 17:21 - 2013-12-17 18:44 - 00010323 _____ C:\Users\Norbert\Desktop\FRST.txt 2013-12-16 17:21 - 2013-12-16 17:22 - 00019180 _____ C:\Users\Norbert\Desktop\Addition.txt 2013-12-16 17:20 - 2013-12-17 18:44 - 01061167 _____ (Farbar) C:\Users\Norbert\Desktop\FRST.exe 2013-12-16 17:20 - 2013-12-17 18:44 - 00000000 ____D C:\FRST 2013-12-16 17:16 - 2013-12-16 17:18 - 00000476 _____ C:\Users\Norbert\Desktop\defogger_disable.log 2013-12-16 17:16 - 2013-12-16 17:16 - 00000000 _____ C:\Users\Norbert\defogger_reenable 2013-12-16 17:11 - 2013-12-16 17:11 - 00050477 _____ C:\Users\Norbert\Desktop\Defogger.exe 2013-12-15 17:28 - 2013-12-15 17:28 - 00000000 ____D C:\Users\Norbert\AppData\Local\NVIDIA Corporation 2013-12-15 17:21 - 2013-12-15 17:21 - 199358496 _____ (NVIDIA Corporation) C:\Users\Norbert\Downloads\331.82-desktop-win8-win7-winvista-32bit-international-whql.exe 2013-12-14 12:01 - 2013-12-14 12:01 - 00000971 _____ C:\Users\Norbert\Desktop\Wow - Shortcut.lnk 2013-12-12 10:57 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 10:57 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 10:57 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 10:57 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 10:57 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 10:57 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 10:57 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 10:57 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 10:57 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 10:57 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 10:57 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 10:57 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 10:57 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 07:24 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 07:24 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 07:24 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 07:24 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 07:24 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 07:24 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 07:24 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 18:44 - 2013-12-12 19:32 - 00000000 ____D C:\Users\Norbert\Desktop\WTF1 2013-12-11 18:44 - 2013-12-11 18:46 - 00000000 ____D C:\Users\Norbert\Desktop\Cache1 2013-12-11 18:20 - 2013-12-11 18:20 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\NVIDIA 2013-12-11 11:48 - 2013-12-11 11:48 - 00000000 _____ C:\Windows\setupact.log 2013-12-11 10:07 - 2013-12-11 10:07 - 00000864 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TuneUp Software 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVG2014 2013-12-11 10:06 - 2013-12-11 10:07 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-11 10:06 - 2013-12-11 10:06 - 00000000 ____D C:\$AVG 2013-12-11 10:05 - 2013-12-11 10:05 - 00000000 ____D C:\Program Files\AVG 2013-12-11 10:03 - 2013-12-17 18:02 - 00000000 ____D C:\ProgramData\MFAData 2013-12-11 10:03 - 2013-12-11 10:42 - 00000000 ____D C:\Users\Norbert\AppData\Local\Avg2014 2013-12-11 10:03 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\MFAData 2013-12-11 10:02 - 2013-12-11 10:02 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet (1).exe 2013-12-11 09:42 - 2013-12-11 09:42 - 00212584 _____ C:\Windows\Minidump\Mini121113-01.dmp 2013-12-11 09:41 - 2013-12-11 09:41 - 06243424 _____ (Systweak Inc ) C:\Users\Norbert\Downloads\rcpsetup1_dcomnew_sec_728_dcomnew_sec_728.exe 2013-12-11 09:41 - 2013-12-11 09:41 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet.exe 2013-12-02 20:59 - 2013-12-02 20:59 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVAST Software 2013-12-02 20:49 - 2013-12-02 20:49 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-02 19:26 - 2013-12-02 19:26 - 00231576 _____ C:\Windows\Minidump\Mini120213-01.dmp 2013-11-29 13:30 - 2013-11-29 13:30 - 00002051 _____ C:\Users\Norbert\Downloads\einkaufskorb.csv 2013-11-26 14:54 - 2013-11-14 12:55 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233182.dll 2013-11-26 14:54 - 2013-11-14 12:55 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233182.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 22951200 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 10446112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-11-26 14:53 - 2013-11-14 12:55 - 09663656 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 09619872 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 02947872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 02747680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-11-17 12:25 - 2013-11-17 12:25 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-11-17 12:20 - 2013-11-14 12:55 - 15862272 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll 2013-11-17 12:20 - 2013-10-23 11:24 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233165.dll 2013-11-17 12:20 - 2013-10-23 11:24 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233165.dll ==================== One Month Modified Files and Folders ======= 2013-12-17 18:45 - 2013-12-16 17:21 - 00010323 _____ C:\Users\Norbert\Desktop\FRST.txt 2013-12-17 18:44 - 2013-12-17 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\FRST-OlderVersion 2013-12-17 18:44 - 2013-12-16 17:20 - 01061167 _____ (Farbar) C:\Users\Norbert\Desktop\FRST.exe 2013-12-17 18:44 - 2013-12-16 17:20 - 00000000 ____D C:\FRST 2013-12-17 18:42 - 2013-12-17 18:42 - 00000636 _____ C:\Users\Norbert\Desktop\JRT.txt 2013-12-17 18:40 - 2008-01-21 02:35 - 01983932 _____ C:\Windows\WindowsUpdate.log 2013-12-17 18:39 - 2013-12-17 18:39 - 01034531 _____ (Thisisu) C:\Users\Norbert\Desktop\JRT.exe 2013-12-17 18:37 - 2013-12-17 18:37 - 00001960 _____ C:\Users\Norbert\Desktop\AdwCleaner[S0].txt 2013-12-17 18:36 - 2006-11-02 14:01 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-17 18:36 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-17 18:36 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-17 18:36 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-17 18:34 - 2013-12-17 18:32 - 00000000 ____D C:\AdwCleaner 2013-12-17 18:31 - 2013-12-17 18:31 - 01226750 _____ C:\Users\Norbert\Desktop\adwcleaner.exe 2013-12-17 18:27 - 2013-12-16 19:21 - 00000944 _____ C:\Windows\PFRO.log 2013-12-17 18:23 - 2012-10-22 16:12 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-17 18:08 - 2013-12-17 18:08 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-17 18:08 - 2013-12-17 18:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-17 18:05 - 2013-12-17 18:05 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Norbert\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-12-17 18:02 - 2013-12-11 10:03 - 00000000 ____D C:\ProgramData\MFAData 2013-12-16 19:10 - 2013-12-16 19:10 - 00011331 _____ C:\ComboFix.txt 2013-12-16 19:10 - 2013-12-16 19:00 - 00000000 ____D C:\Qoobox 2013-12-16 19:10 - 2010-01-06 12:58 - 00000000 ____D C:\Users\Norbert\AppData\Local\Apps\2.0 2013-12-16 19:09 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini 2013-12-16 18:58 - 2013-12-16 18:58 - 05154128 ____R (Swearware) C:\Users\Norbert\Desktop\ComboFix.exe 2013-12-16 18:49 - 2010-01-06 12:58 - 00000000 ____D C:\Users\Norbert\AppData\Local\Deployment 2013-12-16 17:50 - 2013-12-16 17:50 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe 2013-12-16 17:45 - 2013-12-16 17:45 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe.opdownload 2013-12-16 17:40 - 2013-12-16 17:40 - 00037291 _____ C:\Users\Norbert\Downloads\xkxkv9bf.exe.opdownload 2013-12-16 17:38 - 2013-12-16 17:38 - 00037254 _____ C:\Users\Norbert\Downloads\gmer_2.1.19163.exe.opdownload 2013-12-16 17:22 - 2013-12-16 17:21 - 00019180 _____ C:\Users\Norbert\Desktop\Addition.txt 2013-12-16 17:18 - 2013-12-16 17:16 - 00000476 _____ C:\Users\Norbert\Desktop\defogger_disable.log 2013-12-16 17:16 - 2013-12-16 17:16 - 00000000 _____ C:\Users\Norbert\defogger_reenable 2013-12-16 17:16 - 2009-12-01 12:59 - 00000000 ____D C:\Users\Norbert 2013-12-16 17:11 - 2013-12-16 17:11 - 00050477 _____ C:\Users\Norbert\Desktop\Defogger.exe 2013-12-16 15:41 - 2013-08-16 21:10 - 00000000 ____D C:\Program Files\Opera 2013-12-15 17:28 - 2013-12-15 17:28 - 00000000 ____D C:\Users\Norbert\AppData\Local\NVIDIA Corporation 2013-12-15 17:28 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-12-15 17:27 - 2009-12-01 13:09 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-15 17:21 - 2013-12-15 17:21 - 199358496 _____ (NVIDIA Corporation) C:\Users\Norbert\Downloads\331.82-desktop-win8-win7-winvista-32bit-international-whql.exe 2013-12-15 15:32 - 2011-04-18 09:57 - 00000000 ____D C:\Users\Norbert\Norbert neu 2013-12-15 15:30 - 2006-11-02 11:33 - 00765776 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-14 12:01 - 2013-12-14 12:01 - 00000971 _____ C:\Users\Norbert\Desktop\Wow - Shortcut.lnk 2013-12-12 19:32 - 2013-12-11 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\WTF1 2013-12-12 19:03 - 2006-11-02 13:47 - 00248664 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-12 10:59 - 2013-08-05 14:54 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 10:58 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-12 08:10 - 2010-04-03 16:35 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TS3Client 2013-12-11 18:46 - 2013-12-11 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\Cache1 2013-12-11 18:20 - 2013-12-11 18:20 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\NVIDIA 2013-12-11 11:48 - 2013-12-11 11:48 - 00000000 _____ C:\Windows\setupact.log 2013-12-11 11:23 - 2012-06-26 08:13 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 11:23 - 2011-09-13 09:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 10:42 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\Avg2014 2013-12-11 10:17 - 2009-12-12 21:40 - 00000000 ____D C:\Windows\Minidump 2013-12-11 10:07 - 2013-12-11 10:07 - 00000864 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TuneUp Software 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVG2014 2013-12-11 10:07 - 2013-12-11 10:06 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-11 10:06 - 2013-12-11 10:06 - 00000000 ____D C:\$AVG 2013-12-11 10:05 - 2013-12-11 10:05 - 00000000 ____D C:\Program Files\AVG 2013-12-11 10:03 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\MFAData 2013-12-11 10:02 - 2013-12-11 10:02 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet (1).exe 2013-12-11 09:42 - 2013-12-11 09:42 - 00212584 _____ C:\Windows\Minidump\Mini121113-01.dmp 2013-12-11 09:41 - 2013-12-11 09:41 - 06243424 _____ (Systweak Inc ) C:\Users\Norbert\Downloads\rcpsetup1_dcomnew_sec_728_dcomnew_sec_728.exe 2013-12-11 09:41 - 2013-12-11 09:41 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet.exe 2013-12-10 10:01 - 2010-09-15 01:56 - 00000000 ____D C:\found.000 2013-12-04 15:57 - 2011-11-27 01:33 - 00000000 ____D C:\Program Files\Google 2013-12-04 15:57 - 2010-09-28 13:31 - 00000000 ____D C:\Users\Norbert\AppData\Local\Google 2013-12-02 20:59 - 2013-12-02 20:59 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVAST Software 2013-12-02 20:52 - 2010-09-14 17:10 - 00269216 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-02 20:49 - 2013-12-02 20:49 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-02 20:48 - 2006-11-02 11:23 - 00002577 _____ C:\Windows\system32\config.nt 2013-12-02 19:26 - 2013-12-02 19:26 - 00231576 _____ C:\Windows\Minidump\Mini120213-01.dmp 2013-11-29 13:30 - 2013-11-29 13:30 - 00002051 _____ C:\Users\Norbert\Downloads\einkaufskorb.csv 2013-11-19 03:33 - 2009-12-01 13:06 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-17 12:25 - 2013-11-17 12:25 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-11-17 12:25 - 2009-12-01 13:35 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-11-17 10:07 - 2010-04-03 16:34 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client Some content of TEMP: ==================== C:\Users\Norbert\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-17 18:43 ==================== End Of Log ============================ --- --- --- Mit freundlichen Grüßen. |
18.12.2013, 10:33 | #6 |
/// the machine /// TB-Ausbilder | Windows Vista-Beim Booten kein Signal an den MonitorESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows Vista-Beim Booten kein Signal an den Monitor |
18.12.2013, 15:16 | #7 |
| Windows Vista-Beim Booten kein Signal an den Monitor Mahlzeit Schrauber, vielen Dank für die einfach nachvollziehbaren Anweisungen, bitteschön: Hier die Logs: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=7ae336bad0e56a4e91d5613b76bc8019 # engine=16310 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-12-18 12:19:30 # local_time=2013-12-18 01:19:30 (+0100, W. Europe Standard Time) # country="Austria" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=5892 16776574 100 100 72606 224901898 0 0 # scanned=211881 # found=0 # cleaned=0 # scan_time=8811 Code:
ATTFilter Results of screen317's Security Check version 0.99.77 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! Windows Firewall Disabled! WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Secunia PSI (3.0.0.7011) Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 45 Adobe Flash Player 11.9.900.170 Adobe Reader 9 Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe AVG avgwdsvc.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 3 % Defragment your hard drive soon! (Do NOT defrag if SSD!) ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-12-2013 01 Ran by Norbert (administrator) on NORBERT-PC on 18-12-2013 13:37:50 Running from C:\Users\Norbert\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English(US) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe () C:\Program Files\Belkin\F5D8055\v2\BelkinDetectUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe () C:\Program Files\Opera\18.0.1284.68\opera_crashreporter.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [591696 2008-05-07] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [F5D8055v2] - C:\Program Files\Belkin\F5D8055\v2\BelkinDetectUI.exe [196608 2009-04-15] () HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295512 2013-10-17] (RealNetworks, Inc.) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [NvBackend] - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKCU\...\Run: [TomTomHOME.exe] - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-03-22] (TomTom) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Norbert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://at.msn.com/?st=1 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x766D3BB98C72CA01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKCU - ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 212.186.211.21 ========================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [51168 2009-11-06] (NOS Microsystems Ltd.) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () S3 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [x] S2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [x] S2 vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2009-12-01] () R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209176 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147768 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [56816 2009-12-09] (Avira GmbH) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-07-31] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [96104 2009-03-30] (Avira GmbH) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [7680 2009-12-01] () S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [718336 2010-10-18] (Ralink Technology Corp.) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S1 avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [x] S3 catchme; \??\C:\Users\Norbert\AppData\Local\Temp\catchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 USBMULCD; system32\drivers\CM106.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-18 13:35 - 2013-12-18 13:35 - 00001144 _____ C:\Users\Norbert\Desktop\checkup.txt 2013-12-18 13:31 - 2013-12-18 13:31 - 00891200 _____ C:\Users\Norbert\Desktop\SecurityCheck.exe 2013-12-18 10:46 - 2013-12-18 10:46 - 02347384 _____ (ESET) C:\Users\Norbert\Desktop\esetsmartinstaller_enu.exe 2013-12-17 18:44 - 2013-12-18 13:37 - 00000000 ____D C:\Users\Norbert\Desktop\FRST-OlderVersion 2013-12-17 18:42 - 2013-12-17 18:42 - 00000636 _____ C:\Users\Norbert\Desktop\JRT.txt 2013-12-17 18:39 - 2013-12-17 18:39 - 01034531 _____ (Thisisu) C:\Users\Norbert\Desktop\JRT.exe 2013-12-17 18:37 - 2013-12-17 18:37 - 00001960 _____ C:\Users\Norbert\Desktop\AdwCleaner[S0].txt 2013-12-17 18:32 - 2013-12-17 18:34 - 00000000 ____D C:\AdwCleaner 2013-12-17 18:31 - 2013-12-17 18:31 - 01226750 _____ C:\Users\Norbert\Desktop\adwcleaner.exe 2013-12-17 18:08 - 2013-12-17 18:08 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-17 18:08 - 2013-12-17 18:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-17 18:08 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-12-17 18:05 - 2013-12-17 18:05 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Norbert\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-12-16 19:21 - 2013-12-17 18:27 - 00000944 _____ C:\Windows\PFRO.log 2013-12-16 19:10 - 2013-12-16 19:10 - 00011331 _____ C:\ComboFix.txt 2013-12-16 19:00 - 2013-12-16 19:10 - 00000000 ____D C:\Qoobox 2013-12-16 19:00 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-12-16 19:00 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-12-16 19:00 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-12-16 19:00 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-12-16 18:58 - 2013-12-16 18:58 - 05154128 ____R (Swearware) C:\Users\Norbert\Desktop\ComboFix.exe 2013-12-16 17:50 - 2013-12-16 17:50 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe 2013-12-16 17:45 - 2013-12-16 17:45 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe.opdownload 2013-12-16 17:40 - 2013-12-16 17:40 - 00037291 _____ C:\Users\Norbert\Downloads\xkxkv9bf.exe.opdownload 2013-12-16 17:38 - 2013-12-16 17:38 - 00037254 _____ C:\Users\Norbert\Downloads\gmer_2.1.19163.exe.opdownload 2013-12-16 17:21 - 2013-12-18 13:37 - 00010529 _____ C:\Users\Norbert\Desktop\FRST.txt 2013-12-16 17:21 - 2013-12-16 17:22 - 00019180 _____ C:\Users\Norbert\Desktop\Addition.txt 2013-12-16 17:20 - 2013-12-18 13:37 - 01062145 _____ (Farbar) C:\Users\Norbert\Desktop\FRST.exe 2013-12-16 17:20 - 2013-12-18 13:37 - 00000000 ____D C:\FRST 2013-12-16 17:16 - 2013-12-16 17:18 - 00000476 _____ C:\Users\Norbert\Desktop\defogger_disable.log 2013-12-16 17:16 - 2013-12-16 17:16 - 00000000 _____ C:\Users\Norbert\defogger_reenable 2013-12-16 17:11 - 2013-12-16 17:11 - 00050477 _____ C:\Users\Norbert\Desktop\Defogger.exe 2013-12-15 17:28 - 2013-12-15 17:28 - 00000000 ____D C:\Users\Norbert\AppData\Local\NVIDIA Corporation 2013-12-15 17:21 - 2013-12-15 17:21 - 199358496 _____ (NVIDIA Corporation) C:\Users\Norbert\Downloads\331.82-desktop-win8-win7-winvista-32bit-international-whql.exe 2013-12-14 12:01 - 2013-12-14 12:01 - 00000971 _____ C:\Users\Norbert\Desktop\Wow - Shortcut.lnk 2013-12-12 10:57 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 10:57 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 10:57 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 10:57 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 10:57 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 10:57 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 10:57 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 10:57 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-12 10:57 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 10:57 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 10:57 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 10:57 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 10:57 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 10:57 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 07:24 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 07:24 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 07:24 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 07:24 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 07:24 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 07:24 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 07:24 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 18:44 - 2013-12-12 19:32 - 00000000 ____D C:\Users\Norbert\Desktop\WTF1 2013-12-11 18:44 - 2013-12-11 18:46 - 00000000 ____D C:\Users\Norbert\Desktop\Cache1 2013-12-11 18:20 - 2013-12-11 18:20 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\NVIDIA 2013-12-11 11:48 - 2013-12-11 11:48 - 00000000 _____ C:\Windows\setupact.log 2013-12-11 10:07 - 2013-12-11 10:07 - 00000864 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TuneUp Software 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVG2014 2013-12-11 10:06 - 2013-12-11 10:07 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-11 10:06 - 2013-12-11 10:06 - 00000000 ____D C:\$AVG 2013-12-11 10:05 - 2013-12-11 10:05 - 00000000 ____D C:\Program Files\AVG 2013-12-11 10:03 - 2013-12-18 10:44 - 00000000 ____D C:\ProgramData\MFAData 2013-12-11 10:03 - 2013-12-11 10:42 - 00000000 ____D C:\Users\Norbert\AppData\Local\Avg2014 2013-12-11 10:03 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\MFAData 2013-12-11 10:02 - 2013-12-11 10:02 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet (1).exe 2013-12-11 09:42 - 2013-12-11 09:42 - 00212584 _____ C:\Windows\Minidump\Mini121113-01.dmp 2013-12-11 09:41 - 2013-12-11 09:41 - 06243424 _____ (Systweak Inc ) C:\Users\Norbert\Downloads\rcpsetup1_dcomnew_sec_728_dcomnew_sec_728.exe 2013-12-11 09:41 - 2013-12-11 09:41 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet.exe 2013-12-02 20:59 - 2013-12-02 20:59 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVAST Software 2013-12-02 20:49 - 2013-12-02 20:49 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-02 19:26 - 2013-12-02 19:26 - 00231576 _____ C:\Windows\Minidump\Mini120213-01.dmp 2013-11-29 13:30 - 2013-11-29 13:30 - 00002051 _____ C:\Users\Norbert\Downloads\einkaufskorb.csv 2013-11-26 14:54 - 2013-11-14 12:55 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233182.dll 2013-11-26 14:54 - 2013-11-14 12:55 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233182.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 22951200 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 10446112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-11-26 14:53 - 2013-11-14 12:55 - 09663656 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 09619872 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 02947872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-11-26 14:53 - 2013-11-14 12:55 - 02747680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll ==================== One Month Modified Files and Folders ======= 2013-12-18 13:38 - 2013-12-16 17:21 - 00010529 _____ C:\Users\Norbert\Desktop\FRST.txt 2013-12-18 13:37 - 2013-12-17 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\FRST-OlderVersion 2013-12-18 13:37 - 2013-12-16 17:20 - 01062145 _____ (Farbar) C:\Users\Norbert\Desktop\FRST.exe 2013-12-18 13:37 - 2013-12-16 17:20 - 00000000 ____D C:\FRST 2013-12-18 13:35 - 2013-12-18 13:35 - 00001144 _____ C:\Users\Norbert\Desktop\checkup.txt 2013-12-18 13:31 - 2013-12-18 13:31 - 00891200 _____ C:\Users\Norbert\Desktop\SecurityCheck.exe 2013-12-18 13:23 - 2012-10-22 16:12 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-18 12:55 - 2008-01-21 02:35 - 02075664 _____ C:\Windows\WindowsUpdate.log 2013-12-18 12:38 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-18 12:38 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-18 10:46 - 2013-12-18 10:46 - 02347384 _____ (ESET) C:\Users\Norbert\Desktop\esetsmartinstaller_enu.exe 2013-12-18 10:44 - 2013-12-11 10:03 - 00000000 ____D C:\ProgramData\MFAData 2013-12-18 10:38 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-18 07:58 - 2006-11-02 14:01 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-17 23:06 - 2013-06-23 16:09 - 00000000 ____D C:\Users\Norbert\AppData\Local\NVIDIA 2013-12-17 23:06 - 2010-09-27 20:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-12-17 23:06 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-12-17 23:05 - 2009-12-01 13:35 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-12-17 18:42 - 2013-12-17 18:42 - 00000636 _____ C:\Users\Norbert\Desktop\JRT.txt 2013-12-17 18:39 - 2013-12-17 18:39 - 01034531 _____ (Thisisu) C:\Users\Norbert\Desktop\JRT.exe 2013-12-17 18:37 - 2013-12-17 18:37 - 00001960 _____ C:\Users\Norbert\Desktop\AdwCleaner[S0].txt 2013-12-17 18:34 - 2013-12-17 18:32 - 00000000 ____D C:\AdwCleaner 2013-12-17 18:31 - 2013-12-17 18:31 - 01226750 _____ C:\Users\Norbert\Desktop\adwcleaner.exe 2013-12-17 18:27 - 2013-12-16 19:21 - 00000944 _____ C:\Windows\PFRO.log 2013-12-17 18:08 - 2013-12-17 18:08 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-17 18:08 - 2013-12-17 18:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-17 18:05 - 2013-12-17 18:05 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Norbert\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-12-16 19:10 - 2013-12-16 19:10 - 00011331 _____ C:\ComboFix.txt 2013-12-16 19:10 - 2013-12-16 19:00 - 00000000 ____D C:\Qoobox 2013-12-16 19:10 - 2010-01-06 12:58 - 00000000 ____D C:\Users\Norbert\AppData\Local\Apps\2.0 2013-12-16 19:09 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini 2013-12-16 18:58 - 2013-12-16 18:58 - 05154128 ____R (Swearware) C:\Users\Norbert\Desktop\ComboFix.exe 2013-12-16 18:49 - 2010-01-06 12:58 - 00000000 ____D C:\Users\Norbert\AppData\Local\Deployment 2013-12-16 17:50 - 2013-12-16 17:50 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe 2013-12-16 17:45 - 2013-12-16 17:45 - 00377856 _____ C:\Users\Norbert\Desktop\gmer_2.1.19163.exe.opdownload 2013-12-16 17:40 - 2013-12-16 17:40 - 00037291 _____ C:\Users\Norbert\Downloads\xkxkv9bf.exe.opdownload 2013-12-16 17:38 - 2013-12-16 17:38 - 00037254 _____ C:\Users\Norbert\Downloads\gmer_2.1.19163.exe.opdownload 2013-12-16 17:22 - 2013-12-16 17:21 - 00019180 _____ C:\Users\Norbert\Desktop\Addition.txt 2013-12-16 17:18 - 2013-12-16 17:16 - 00000476 _____ C:\Users\Norbert\Desktop\defogger_disable.log 2013-12-16 17:16 - 2013-12-16 17:16 - 00000000 _____ C:\Users\Norbert\defogger_reenable 2013-12-16 17:16 - 2009-12-01 12:59 - 00000000 ____D C:\Users\Norbert 2013-12-16 17:11 - 2013-12-16 17:11 - 00050477 _____ C:\Users\Norbert\Desktop\Defogger.exe 2013-12-16 15:41 - 2013-08-16 21:10 - 00000000 ____D C:\Program Files\Opera 2013-12-15 17:28 - 2013-12-15 17:28 - 00000000 ____D C:\Users\Norbert\AppData\Local\NVIDIA Corporation 2013-12-15 17:27 - 2009-12-01 13:09 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-15 17:21 - 2013-12-15 17:21 - 199358496 _____ (NVIDIA Corporation) C:\Users\Norbert\Downloads\331.82-desktop-win8-win7-winvista-32bit-international-whql.exe 2013-12-15 15:32 - 2011-04-18 09:57 - 00000000 ____D C:\Users\Norbert\Norbert neu 2013-12-15 15:30 - 2006-11-02 11:33 - 00765776 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-14 12:01 - 2013-12-14 12:01 - 00000971 _____ C:\Users\Norbert\Desktop\Wow - Shortcut.lnk 2013-12-12 19:32 - 2013-12-11 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\WTF1 2013-12-12 19:03 - 2006-11-02 13:47 - 00248664 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-12 10:59 - 2013-08-05 14:54 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 10:58 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-12 08:10 - 2010-04-03 16:35 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TS3Client 2013-12-11 18:46 - 2013-12-11 18:44 - 00000000 ____D C:\Users\Norbert\Desktop\Cache1 2013-12-11 18:20 - 2013-12-11 18:20 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\NVIDIA 2013-12-11 11:48 - 2013-12-11 11:48 - 00000000 _____ C:\Windows\setupact.log 2013-12-11 11:23 - 2012-06-26 08:13 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 11:23 - 2011-09-13 09:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 10:42 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\Avg2014 2013-12-11 10:17 - 2009-12-12 21:40 - 00000000 ____D C:\Windows\Minidump 2013-12-11 10:07 - 2013-12-11 10:07 - 00000864 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\TuneUp Software 2013-12-11 10:07 - 2013-12-11 10:07 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVG2014 2013-12-11 10:07 - 2013-12-11 10:06 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-11 10:06 - 2013-12-11 10:06 - 00000000 ____D C:\$AVG 2013-12-11 10:05 - 2013-12-11 10:05 - 00000000 ____D C:\Program Files\AVG 2013-12-11 10:03 - 2013-12-11 10:03 - 00000000 ____D C:\Users\Norbert\AppData\Local\MFAData 2013-12-11 10:02 - 2013-12-11 10:02 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet (1).exe 2013-12-11 09:42 - 2013-12-11 09:42 - 00212584 _____ C:\Windows\Minidump\Mini121113-01.dmp 2013-12-11 09:41 - 2013-12-11 09:41 - 06243424 _____ (Systweak Inc ) C:\Users\Norbert\Downloads\rcpsetup1_dcomnew_sec_728_dcomnew_sec_728.exe 2013-12-11 09:41 - 2013-12-11 09:41 - 04436944 _____ (AVG Technologies) C:\Users\Norbert\Downloads\avg_free_stb_all_2014_4259_cnet.exe 2013-12-10 10:01 - 2010-09-15 01:56 - 00000000 ____D C:\found.000 2013-12-04 15:57 - 2011-11-27 01:33 - 00000000 ____D C:\Program Files\Google 2013-12-04 15:57 - 2010-09-28 13:31 - 00000000 ____D C:\Users\Norbert\AppData\Local\Google 2013-12-02 20:59 - 2013-12-02 20:59 - 00000000 ____D C:\Users\Norbert\AppData\Roaming\AVAST Software 2013-12-02 20:52 - 2010-09-14 17:10 - 00269216 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-02 20:49 - 2013-12-02 20:49 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-02 20:48 - 2006-11-02 11:23 - 00002577 _____ C:\Windows\system32\config.nt 2013-12-02 19:26 - 2013-12-02 19:26 - 00231576 _____ C:\Windows\Minidump\Mini120213-01.dmp 2013-11-29 13:30 - 2013-11-29 13:30 - 00002051 _____ C:\Users\Norbert\Downloads\einkaufskorb.csv 2013-11-19 03:33 - 2009-12-01 13:06 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Norbert\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-18 10:46 ==================== End Of Log ============================ --- --- --- --- --- --- Ich habe im Moment ein gut rennendes System hier! War das die eine "Curse" File? Ich bitte ich Dich um Deine Meinung zu Folgendem: Mein Schwager hat mir gestern die zweite Graphikkarte abgesteckt, weil ich die Karten nicht im SLI Modus verwenden kann. (alle heutigen scans also ohne 2. Karte) Hat iwie noch nie funktioniert-bekomme beim spielen nach wenigen MInuten immer so einen flashing screen, und dann geht nichts mehr....verwende also in den Einstellungen kein SLI. (seine Begründung: zieht nur unnötig am schwachen Netzteil..) Soll ich das so beibehalten? (mir wärs ja lieber, wenn der Mist (SLI) funktionieren würde). Und ich habe mir eine passende Batterie geholt (wegen checksum error). Soll ich die auswechseln? (er hat mir gezeigt, wo das Teil ist, falls Du das auch so siehst...) Vorerst riesigen Dank an Dich und Trojaner Board....ich freu mich einfach, daß die Kiste nun rennt. Einzig gezockt habe ich noch nichts, editiere ich aber sobald dies geschehen ist. Danke, danke. Zusatz: zockt sich sehr angenehm mit gar hohen Einstellungen! (wie gesagt mit eben nur einer Karte im MOment) |
19.12.2013, 10:16 | #8 |
/// the machine /// TB-Ausbilder | Windows Vista-Beim Booten kein Signal an den Monitor für SLI brauchste nen besseres Netzteil. CMOS Batterie würde ich auf jeden Fall mal neu machen Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.12.2013, 15:38 | #9 |
| Windows Vista-Beim Booten kein Signal an den Monitor Vielen Dank lieber Schrauber, scheint alles zu funktionieren. Keine weiteren Fragen. Danke, danke. |
23.12.2013, 08:57 | #10 |
/// the machine /// TB-Ausbilder | Windows Vista-Beim Booten kein Signal an den Monitor Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows Vista-Beim Booten kein Signal an den Monitor |
antivir guard, antivirus, avg antivirus, avira, booten, computer, curse, device driver, down, error, failed, flash player, freemium, helper, home, internet, minidump, monitor, plug-in, registry, rundll, scan, secunia psi, secure search, security, services.exe, software, spielen, svchost.exe, system, teamspeak, trojaner, trojaner board, vtoolbarupdater, windows |