|
Log-Analyse und Auswertung: GVU Trojaner auf Windows 8.1 PCWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
29.12.2013, 15:55 | #1 |
| GVU Trojaner auf Windows 8.1 PC Hi, habe mir auf W8.1 mit 64Bit den GVU Trojaner eingefangen. FRST64 liefert das folgende Log. Wäre schön, wenn Ihr helfen könntet. Gruß Kaloschke FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 Ran by SYSTEM on MININT-APQGS05 on 29-12-2013 15:41:51 Running from I:\gvu Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [ComproRC] - C:\Windows\ComproRC.exe [328328 2011-02-11] (Compro Technology Ltd.) HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [tvncontrol] - "C:\Program Files\TightVNC\tvnserver.exe" -controlservice -slave HKLM\...\Run: [LogMeIn GUI] - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" HKLM-x32\...\Winlogon: [Userinit] [x] HKLM\...\Winlogon: [Shell] C:\Users\MeinName\AppData\Roaming\loadit.exe [595750 2013-12-29] () <=== ATTENTION HKLM-x32\...\Winlogon: [Shell] [0 ] () <=== ATTENTION Winlogon\Notify\ScCertProp: C:\Windows\SysWOW64 () HKLM\...\Policies\Explorer: [NoViewContextMenu] 1 HKLM\...\Policies\Explorer: [NoDesktop] 1 <===== ATTENTION HKU\MeinName\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\MeinName\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [397632 2013-05-02] () HKU\MeinName\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\MeinName\...\Run: [Spotify Web Helper] - C:\Users\MeinName\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-10-25] (Spotify Ltd) HKU\MeinName\...\Run: [Seafile] - C:\Program Files (x86)\Seafile\bin\seafile-applet.exe [1945633 2013-11-09] () HKU\MeinName\...\Run: [OpAgent] - "OpAgent.exe" /agent HKU\MeinName\...\Policies\system: [DisableTaskMgr] 1 HKU\MeinName\...\Policies\system: [DisableRegistryTools] 1 HKU\MeinName\...\Winlogon: [Userinit] C:\Users\MeinName\AppData\Roaming\loadit.exe [595750 2013-12-29] () HKU\MeinName\...\Winlogon: [Shell] C:\Users\MeinName\AppData\Roaming\loadit.exe [595750 2013-12-29] () <==== ATTENTION Startup: C:\Users\MeinName\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ja.lnk ShortcutTarget: ja.lnk -> C:\windows\system32\config\systemprofile\AppData\Roaming\loadit.exe (No File) ==================== Services (Whitelisted) ================= S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [321024 2013-08-22] (Microsoft Corporation) S2 GladFileMonSvc; C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe [29552 2011-05-24] (Gladinet, INC) S2 Mesh Agent; C:\Program Files (x86)\Mesh Agent\MeshAgent.exe [2006080 2013-10-18] () S2 NoIPDUCService4; C:\Program Files (x86)\No-IP\ducservice.exe [11264 2013-01-24] () S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [32568 2013-08-22] (The OpenVPN Project) S2 peservice; C:\Program Files (x86)\photoSync\peservice.exe [41472 2013-04-10] (webEcoz, LLC.) S3 ServiceProviderRegistry; C:\Windows\System32\Essentials\ProviderRegistryService.exe [34816 2013-08-22] (Microsoft Corporation) S2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-06-13] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S2 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [142960 2013-03-19] (Stardock Software, Inc) S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15680000 2012-08-15] () S3 wampapache; D:\wamp\bin\apache\apache2.4.2\bin\httpd.exe [24576 2012-05-13] (Apache Software Foundation) S3 wampmysqld; D:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe [9693696 2012-04-19] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) S3 WseClientMgmtSvc; C:\Windows\System32\Essentials\SharedServiceHost.exe [24576 2013-08-22] (Microsoft Corporation) S3 WseClientMonitorSvc; C:\Windows\System32\Essentials\WseClientMonitorSvc.exe [39936 2013-08-22] (Microsoft Corporation) S3 WseHealthSvc; C:\Windows\System32\Essentials\SharedServiceHost.exe [24576 2013-08-22] (Microsoft Corporation) S3 WseNtfSvc; C:\Windows\System32\Essentials\SharedServiceHost.exe [24576 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [131584 2013-08-22] (Microsoft Corporation) S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [32640 2013-08-22] (Microsoft Corporation) S3 CPSBDA; C:\Windows\System32\Drivers\cpsbda.sys [149128 2011-02-11] (Compro Technology Ltd.) S3 DDBaseNg; C:\Windows\system32\DRIVERS\DDBaseNg.sys [80896 2013-10-18] (Digital Devices GmbH) S3 DDCapture; C:\Windows\system32\DRIVERS\DDCapture.sys [21504 2013-10-18] (Digital Devices GmbH) S3 DDTuner; C:\Windows\system32\DRIVERS\DDTuner.sys [212992 2013-10-18] (Digital Devices GmbH) S1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-10-20] (DT Soft Ltd) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) S0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S4 LMIRfsClientNP; No ImagePath S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) S3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [47320 2013-07-29] (Realtek Microelectronics) S3 S332x64; C:\Windows\system32\DRIVERS\S332x64.sys [78080 2012-02-27] (Identive ) S3 SAllBDA; C:\Windows\System32\Drivers\TeViiS2.sys [194128 2013-10-28] (TeVii Technology Ltd.) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S3 sthid; C:\Windows\System32\drivers\sthid.sys [21216 2013-04-01] (Splashtop Inc.) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 tapoas; C:\Windows\system32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) S2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-29 19:10 - 2013-12-29 19:42 - 00143534 _____ C:\OTL.Txt 2013-12-29 15:41 - 2013-12-29 15:41 - 00000000 ____D C:\FRST 2013-12-29 11:59 - 2013-12-29 11:59 - 00595750 _____ C:\Users\MeinName\AppData\Roaming\loadit.exe 2013-12-25 09:29 - 2013-12-25 09:29 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2 2013-12-24 15:50 - 2013-12-29 11:54 - 00000000 ____D C:\Users\MeinName\AppData\Local\gladinet 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ___HD C:\Gladinet 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\Zeon 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\ScanSoft 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\FLEXnet 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Local\ScanSoft 2013-12-24 15:49 - 2013-12-24 15:50 - 00000000 ____D C:\ProgramData\Nuance 2013-12-24 15:49 - 2013-12-24 15:49 - 00002160 _____ C:\Users\Public\Desktop\Nuance Cloud Connector.lnk 2013-12-24 15:49 - 2013-12-24 15:49 - 00000000 ____D C:\ProgramData\zeon 2013-12-24 15:48 - 2013-12-24 15:49 - 00000000 ____D C:\Program Files (x86)\Nuance 2013-12-24 15:48 - 2013-12-24 15:48 - 00000403 _____ C:\Windows\MAXLINK.INI 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\Windows\pixtran 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\Nuance 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\ProgramData\ScanSoft 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\ProgramData\Macrovision 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\ProgramData\FLEXnet 2013-12-22 12:01 - 2013-12-28 18:16 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\UseNeXT 2013-12-22 12:01 - 2013-12-22 12:01 - 00000000 ____D C:\Program Files (x86)\UseNeXT 2013-12-22 11:52 - 2013-12-22 11:56 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\GrabIt 2013-12-21 19:06 - 2013-12-21 19:06 - 00000000 ____D C:\Program Files (x86)\Free M4a to MP3 Converter 2013-12-21 18:35 - 2013-12-29 19:37 - 00000000 ____D C:\z 2013-12-17 15:47 - 2013-12-17 15:47 - 00000000 ____D C:\Program Files (x86)\code4ward.net 2013-12-15 09:49 - 2013-11-12 00:41 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-12-15 09:49 - 2013-11-12 00:40 - 00249856 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-12-15 09:49 - 2013-11-12 00:27 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-12-15 09:49 - 2013-11-12 00:24 - 00840704 _____ (Microsoft Corporation) C:\Windows\System32\WSShared.dll 2013-12-15 09:49 - 2013-11-11 03:48 - 00039768 ____C (Microsoft Corporation) C:\Windows\System32\Drivers\intelpep.sys 2013-12-15 09:49 - 2013-11-09 12:55 - 00325464 ____C (Microsoft Corporation) C:\Windows\System32\Drivers\USBXHCI.SYS 2013-12-15 09:49 - 2013-11-09 07:37 - 01756160 _____ (Microsoft Corporation) C:\Windows\System32\WMPDMC.exe 2013-12-15 09:49 - 2013-11-09 06:56 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe 2013-12-15 09:49 - 2013-11-08 11:26 - 00358896 _____ (Microsoft Corporation) C:\Windows\System32\dcomp.dll 2013-12-15 09:49 - 2013-11-08 06:23 - 00449024 _____ (Microsoft Corporation) C:\Windows\System32\appmgr.dll 2013-12-15 09:49 - 2013-11-08 05:43 - 00254464 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentClient.dll 2013-12-15 09:49 - 2013-11-08 05:42 - 00366080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgr.dll 2013-12-15 09:49 - 2013-11-08 05:28 - 13177344 _____ (Microsoft Corporation) C:\Windows\System32\twinui.dll 2013-12-15 09:49 - 2013-11-08 05:26 - 11674624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2013-12-15 09:49 - 2013-11-08 05:16 - 00225792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll 2013-12-15 09:49 - 2013-11-08 05:15 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2013-12-15 09:49 - 2013-11-08 05:07 - 00115712 _____ (Microsoft Corporation) C:\Windows\System32\winbici.dll 2013-12-15 09:49 - 2013-11-08 04:41 - 01302528 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentServer.dll 2013-12-15 09:49 - 2013-11-08 04:14 - 00922624 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentExtensions.dll 2013-12-15 09:49 - 2013-11-05 15:19 - 00566784 _____ (Microsoft Corporation) C:\Windows\System32\wpncore.dll 2013-12-15 09:49 - 2013-11-05 15:03 - 00637952 _____ (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe 2013-12-15 09:49 - 2013-11-05 14:57 - 00479744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2013-12-15 09:49 - 2013-11-05 14:33 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2013-12-15 09:49 - 2013-11-05 14:32 - 00744448 _____ (Microsoft Corporation) C:\Windows\System32\SettingSyncCore.dll 2013-12-15 09:49 - 2013-11-04 18:13 - 01530200 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-12-15 09:49 - 2013-11-04 18:13 - 00382808 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-12-15 09:49 - 2013-11-04 14:07 - 01843712 _____ (Microsoft Corporation) C:\Windows\System32\Display.dll 2013-12-15 09:49 - 2013-11-04 12:50 - 02143744 _____ (Microsoft Corporation) C:\Windows\System32\dwmcore.dll 2013-12-15 09:49 - 2013-11-04 11:32 - 02570240 _____ (Microsoft Corporation) C:\Windows\System32\SettingsHandlers.dll 2013-12-15 09:49 - 2013-11-04 03:28 - 01816576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll 2013-12-15 09:49 - 2013-11-04 02:30 - 01765376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-12-15 09:49 - 2013-11-01 12:39 - 00086872 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\pdc.sys 2013-12-15 09:49 - 2013-11-01 07:08 - 00747008 _____ (Microsoft Corporation) C:\Windows\System32\wlidcli.dll 2013-12-15 09:49 - 2013-11-01 06:57 - 00544768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll 2013-12-15 09:49 - 2013-10-31 01:58 - 00372568 ____C (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys 2013-12-15 09:49 - 2013-10-31 01:42 - 07399256 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-12-15 09:49 - 2013-10-31 01:33 - 01642016 _____ (Microsoft Corporation) C:\Windows\System32\winload.efi 2013-12-15 09:49 - 2013-10-31 01:33 - 01506680 _____ (Microsoft Corporation) C:\Windows\System32\winload.exe 2013-12-15 09:49 - 2013-10-31 01:33 - 01476184 _____ (Microsoft Corporation) C:\Windows\System32\winresume.efi 2013-12-15 09:49 - 2013-10-31 01:33 - 01345536 _____ (Microsoft Corporation) C:\Windows\System32\winresume.exe 2013-12-15 09:49 - 2013-10-26 02:54 - 00146776 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\SerCx2.sys 2013-12-15 09:49 - 2013-10-24 10:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\System32\CredentialMigrationHandler.dll 2013-12-15 09:49 - 2013-10-24 10:12 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredentialMigrationHandler.dll 2013-12-15 09:49 - 2013-10-17 12:21 - 02896896 _____ (Microsoft Corporation) C:\Windows\System32\msftedit.dll 2013-12-15 09:49 - 2013-10-17 11:36 - 02266624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2013-12-15 09:49 - 2013-10-05 15:21 - 02140888 _____ (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-12-15 09:49 - 2013-10-05 15:21 - 00516496 _____ (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-12-15 09:49 - 2013-10-05 13:05 - 01765384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-12-15 09:49 - 2013-10-05 13:05 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-12-13 13:34 - 2013-12-15 09:44 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\TeamViewer 2013-12-13 12:51 - 2013-12-13 12:52 - 00000000 ____D C:\Users\MeinName\ccnet 2013-12-13 12:51 - 2013-12-13 12:51 - 00001064 _____ C:\Users\Public\Desktop\Seafile.lnk 2013-12-13 12:51 - 2013-12-13 12:51 - 00000000 ____D C:\Program Files (x86)\Seafile 2013-12-12 19:19 - 2013-12-12 19:19 - 00002232 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-12-11 16:47 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-12-11 16:47 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 16:47 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-12-11 16:47 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-12-11 16:47 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 16:47 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-12-11 16:47 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 16:47 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-12-11 16:47 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-12-11 16:47 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 16:47 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 16:47 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-12-11 16:47 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-12-11 16:47 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-12-11 16:47 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 16:47 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 16:47 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 16:47 - 2013-11-23 05:34 - 00393216 _____ (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-12-11 16:47 - 2013-11-23 05:13 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 16:47 - 2013-11-23 04:32 - 04105728 _____ (Microsoft Corporation) C:\Windows\System32\SyncEngine.dll 2013-12-11 16:47 - 2013-11-23 04:10 - 00568832 _____ (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe 2013-12-11 16:47 - 2013-11-09 07:34 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\MDMAgent.exe 2013-12-11 16:47 - 2013-11-09 07:34 - 00287744 _____ (Microsoft Corporation) C:\Windows\System32\mdmregistration.dll 2013-12-11 16:47 - 2013-11-09 06:52 - 00240128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll 2013-12-11 16:47 - 2013-11-08 08:21 - 04191744 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-12-11 16:47 - 2013-10-19 09:53 - 00075360 _____ (Microsoft Corporation) C:\Windows\System32\imagehlp.dll 2013-12-11 16:47 - 2013-10-19 08:14 - 00070680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 16:47 - 2013-10-15 09:54 - 00197120 _____ (Microsoft Corporation) C:\Windows\System32\scrrun.dll 2013-12-11 16:47 - 2013-10-15 09:03 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 09:38 - 2013-12-11 09:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-05 19:06 - 2013-12-05 19:06 - 00000000 ____D C:\Program Files (x86)\GeoGebra 4.4 2013-12-02 19:30 - 2013-12-02 19:30 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS 2013-12-02 19:30 - 2013-12-02 19:30 - 00001087 _____ C:\Users\Public\Desktop\Find Drivers with BIOSAgentPlus.lnk 2013-12-02 19:30 - 2013-12-02 19:30 - 00000000 ____D C:\Users\MeinName\AppData\Local\eSupport.com 2013-12-02 19:30 - 2013-12-02 19:30 - 00000000 ____D C:\Program Files (x86)\BiosAgentPlus 2013-12-01 18:35 - 2013-12-24 14:48 - 00001106 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2013-12-01 18:35 - 2013-12-01 18:35 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-12-01 13:50 - 2013-12-01 13:50 - 00000020 ___SH C:\Users\LogMeInRemoteUser\ntuser.ini 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Vorlagen 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Startmenü 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Netzwerkumgebung 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Lokale Einstellungen 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Eigene Dateien 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Druckumgebung 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Documents\Eigene Musik 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Documents\Eigene Bilder 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\AppData\Local\Verlauf 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\AppData\Local\Anwendungsdaten 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Anwendungsdaten 2013-12-01 13:50 - 2013-10-22 20:44 - 00000000 ____D C:\Users\LogMeInRemoteUser\Documents\Visual Studio 2010 2013-12-01 13:50 - 2013-10-22 20:44 - 00000000 ____D C:\Users\LogMeInRemoteUser\AppData\Roaming\Macromedia 2013-12-01 13:50 - 2013-10-22 20:44 - 00000000 ____D C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft Help 2013-12-01 13:48 - 2013-12-15 09:50 - 00000000 ____D C:\ProgramData\LogMeIn 2013-12-01 13:48 - 2013-12-15 09:50 - 00000000 ____D C:\Program Files (x86)\LogMeIn 2013-12-01 13:48 - 2013-12-12 21:52 - 00107368 _____ (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll 2013-12-01 13:48 - 2013-12-12 21:52 - 00092488 _____ (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll 2013-12-01 13:48 - 2013-12-12 21:52 - 00035656 _____ (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll 2013-12-01 13:48 - 2013-12-01 13:48 - 00000000 ____D C:\Users\MeinName\AppData\Local\LogMeIn 2013-12-01 13:48 - 2013-10-24 12:41 - 00107368 _____ (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll.000.bak 2013-12-01 13:48 - 2013-04-30 10:57 - 00072216 _____ (LogMeIn, Inc.) C:\Windows\System32\Drivers\LMIRfsDriver.sys 2013-11-30 12:19 - 2013-11-30 12:19 - 00000000 ____D C:\Users\MeinName\AppData\Local\Apps\CAcert Root Certificates 2013-11-29 19:29 - 2013-11-29 19:29 - 00000000 ____D C:\Users\MeinName\AppData\Local\e-academy Inc ==================== One Month Modified Files and Folders ======= 2013-12-29 19:42 - 2013-12-29 19:10 - 00143534 _____ C:\OTL.Txt 2013-12-29 19:37 - 2013-12-21 18:35 - 00000000 ____D C:\z 2013-12-29 19:05 - 2013-10-22 20:40 - 00000000 ____D C:\users\MeinName 2013-12-29 15:41 - 2013-12-29 15:41 - 00000000 ____D C:\FRST 2013-12-29 15:22 - 2013-09-30 05:14 - 01785100 _____ C:\Windows\System32\PerfStringBackup.INI 2013-12-29 15:22 - 2013-09-30 04:56 - 00767024 _____ C:\Windows\System32\perfh007.dat 2013-12-29 15:22 - 2013-09-30 04:56 - 00160370 _____ C:\Windows\System32\perfc007.dat 2013-12-29 12:11 - 2013-10-22 20:47 - 01366941 _____ C:\Windows\WindowsUpdate.log 2013-12-29 12:11 - 2013-09-21 16:38 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-29 12:11 - 2013-08-22 15:46 - 01963432 _____ C:\Windows\setupact.log 2013-12-29 12:11 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-29 12:11 - 2013-03-31 18:45 - 00000000 ____D C:\ProgramData\VMware 2013-12-29 12:01 - 2013-03-29 11:55 - 00005136 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Nirwana5-MeinName NIRWANA5 2013-12-29 11:59 - 2013-12-29 11:59 - 00595750 _____ C:\Users\MeinName\AppData\Roaming\loadit.exe 2013-12-29 11:59 - 2013-08-22 14:25 - 00524288 ___SH C:\Windows\System32\config\BBI 2013-12-29 11:58 - 2013-03-28 14:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-29 11:54 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Local\gladinet 2013-12-29 11:54 - 2013-04-05 18:18 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\XBMC 2013-12-29 01:18 - 2013-09-21 16:38 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-29 01:00 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\System32\sru 2013-12-28 22:16 - 2013-03-31 18:46 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\VMware 2013-12-28 21:10 - 2013-03-31 18:46 - 00000000 ____D C:\Users\MeinName\AppData\Local\VMware 2013-12-28 19:16 - 2013-06-23 19:35 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\vlc 2013-12-28 18:16 - 2013-12-22 12:01 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\UseNeXT 2013-12-28 09:50 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\AppReadiness 2013-12-26 11:48 - 2013-04-04 18:52 - 00000072 _____ C:\Users\Public\LMDebug.log 2013-12-25 09:29 - 2013-12-25 09:29 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2 2013-12-24 21:13 - 2013-08-22 15:44 - 05034648 _____ C:\Windows\System32\FNTCACHE.DAT 2013-12-24 16:13 - 2013-03-28 13:35 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-862617867-1843000802-1688245454-1001 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ___HD C:\Gladinet 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\Zeon 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\ScanSoft 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\FLEXnet 2013-12-24 15:50 - 2013-12-24 15:50 - 00000000 ____D C:\Users\MeinName\AppData\Local\ScanSoft 2013-12-24 15:50 - 2013-12-24 15:49 - 00000000 ____D C:\ProgramData\Nuance 2013-12-24 15:49 - 2013-12-24 15:49 - 00002160 _____ C:\Users\Public\Desktop\Nuance Cloud Connector.lnk 2013-12-24 15:49 - 2013-12-24 15:49 - 00000000 ____D C:\ProgramData\zeon 2013-12-24 15:49 - 2013-12-24 15:48 - 00000000 ____D C:\Program Files (x86)\Nuance 2013-12-24 15:48 - 2013-12-24 15:48 - 00000403 _____ C:\Windows\MAXLINK.INI 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\Windows\pixtran 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\Nuance 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\ProgramData\ScanSoft 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\ProgramData\Macrovision 2013-12-24 15:48 - 2013-12-24 15:48 - 00000000 ____D C:\ProgramData\FLEXnet 2013-12-24 14:48 - 2013-12-01 18:35 - 00001106 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2013-12-22 12:01 - 2013-12-22 12:01 - 00000000 ____D C:\Program Files (x86)\UseNeXT 2013-12-22 11:56 - 2013-12-22 11:52 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\GrabIt 2013-12-22 11:03 - 2013-04-01 20:22 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2013-12-22 02:07 - 2013-04-05 16:39 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\Winamp 2013-12-21 19:06 - 2013-12-21 19:06 - 00000000 ____D C:\Program Files (x86)\Free M4a to MP3 Converter 2013-12-21 18:36 - 2013-03-28 14:35 - 00000000 ____D C:\Program Files (x86)\DVBViewer 2013-12-17 17:21 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\System32\NDF 2013-12-17 15:47 - 2013-12-17 15:47 - 00000000 ____D C:\Program Files (x86)\code4ward.net 2013-12-16 06:33 - 2013-08-15 16:00 - 00000000 ____D C:\Windows\System32\MRT 2013-12-16 06:33 - 2013-03-28 13:49 - 90708896 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-12-16 06:20 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache 2013-12-15 23:07 - 2013-08-22 16:36 - 00000000 ___RD C:\Windows\ToastData 2013-12-15 23:07 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\WinStore 2013-12-15 23:07 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\MediaViewer 2013-12-15 23:07 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\FileManager 2013-12-15 23:07 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\Camera 2013-12-15 11:06 - 2013-03-29 10:59 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-15 09:50 - 2013-12-01 13:48 - 00000000 ____D C:\ProgramData\LogMeIn 2013-12-15 09:50 - 2013-12-01 13:48 - 00000000 ____D C:\Program Files (x86)\LogMeIn 2013-12-15 09:44 - 2013-12-13 13:34 - 00000000 ____D C:\Users\MeinName\AppData\Roaming\TeamViewer 2013-12-13 12:52 - 2013-12-13 12:51 - 00000000 ____D C:\Users\MeinName\ccnet 2013-12-13 12:51 - 2013-12-13 12:51 - 00001064 _____ C:\Users\Public\Desktop\Seafile.lnk 2013-12-13 12:51 - 2013-12-13 12:51 - 00000000 ____D C:\Program Files (x86)\Seafile 2013-12-13 07:02 - 2013-09-29 20:04 - 00028568 _____ C:\Windows\PFRO.log 2013-12-12 21:52 - 2013-12-01 13:48 - 00107368 _____ (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll 2013-12-12 21:52 - 2013-12-01 13:48 - 00092488 _____ (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll 2013-12-12 21:52 - 2013-12-01 13:48 - 00035656 _____ (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll 2013-12-12 19:19 - 2013-12-12 19:19 - 00002232 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-12-12 19:19 - 2013-09-21 16:38 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-12 06:38 - 2013-03-28 14:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-11 17:24 - 2013-09-30 04:59 - 00000000 ____D C:\Windows\ShellNew 2013-12-11 09:38 - 2013-12-11 09:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-10 19:58 - 2013-03-28 14:05 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-09 19:59 - 2013-03-29 18:01 - 00000000 ____D C:\Users\MeinName\AppData\Local\Adobe 2013-12-05 19:06 - 2013-12-05 19:06 - 00000000 ____D C:\Program Files (x86)\GeoGebra 4.4 2013-12-04 01:05 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-04 01:05 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-03 08:13 - 2013-09-21 16:38 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-03 08:13 - 2013-09-21 16:38 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-02 19:41 - 2013-03-28 13:29 - 00000000 ____D C:\Users\MeinName\AppData\Local\Packages 2013-12-02 19:30 - 2013-12-02 19:30 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS 2013-12-02 19:30 - 2013-12-02 19:30 - 00001087 _____ C:\Users\Public\Desktop\Find Drivers with BIOSAgentPlus.lnk 2013-12-02 19:30 - 2013-12-02 19:30 - 00000000 ____D C:\Users\MeinName\AppData\Local\eSupport.com 2013-12-02 19:30 - 2013-12-02 19:30 - 00000000 ____D C:\Program Files (x86)\BiosAgentPlus 2013-12-02 18:58 - 2013-03-29 10:25 - 00000000 ____D C:\ProgramData\Stardock 2013-12-01 18:35 - 2013-12-01 18:35 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-12-01 13:50 - 2013-12-01 13:50 - 00000020 ___SH C:\Users\LogMeInRemoteUser\ntuser.ini 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Vorlagen 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Startmenü 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Netzwerkumgebung 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Lokale Einstellungen 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Eigene Dateien 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Druckumgebung 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Documents\Eigene Musik 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Documents\Eigene Bilder 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\AppData\Local\Verlauf 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\AppData\Local\Anwendungsdaten 2013-12-01 13:50 - 2013-12-01 13:50 - 00000000 _SHDL C:\Users\LogMeInRemoteUser\Anwendungsdaten 2013-12-01 13:48 - 2013-12-01 13:48 - 00000000 ____D C:\Users\MeinName\AppData\Local\LogMeIn 2013-12-01 13:48 - 2013-03-31 18:45 - 00001024 _____ C:\.rnd 2013-11-30 12:19 - 2013-11-30 12:19 - 00000000 ____D C:\Users\MeinName\AppData\Local\Apps\CAcert Root Certificates 2013-11-29 19:29 - 2013-11-29 19:29 - 00000000 ____D C:\Users\MeinName\AppData\Local\e-academy Inc Some content of TEMP: ==================== C:\Users\MeinName\AppData\Local\Temp\MouseKeyboardCenterx64_1031.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit safeboot: ==> The system is configured to boot to Safe Mode <===== ATTENTION! ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-12-17 15:47:21 Restore point made on: 2013-12-22 16:20:37 Restore point made on: 2013-12-24 15:47:13 Restore point made on: 2013-12-24 15:47:26 ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 7935.18 MB Available physical RAM: 6952.24 MB Total Pagefile: 7935.18 MB Available Pagefile: 7011.66 MB Total Virtual: 131072 MB Available Virtual: 131071.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:118.9 GB) (Free:36.39 GB) NTFS Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:301.94 GB) NTFS Drive i: (Windows 8 Install) (Removable) (Total:14.75 GB) (Free:6.67 GB) NTFS Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.49 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.34 GB) (Free:0.04 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 98400FA3) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=119 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 932 GB) (Disk ID: 2BC12786) Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 4 (MBR Code: Windows 7 or 8) (Size: 15 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=15 GB) - (Type=07 NTFS) LastRegBack: 2013-12-28 10:04 ==================== End Of Log ============================ |
29.12.2013, 18:17 | #2 |
/// the machine /// TB-Ausbilder | GVU Trojaner auf Windows 8.1 PC hi,
__________________Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM-x32\...\Winlogon: [Userinit] [x] HKLM\...\Winlogon: [Shell] C:\Users\MeinName\AppData\Roaming\loadit.exe [595750 2013-12-29] () <=== ATTENTION HKLM-x32\...\Winlogon: [Shell] [0 ] () <=== ATTENTION Winlogon\Notify\ScCertProp: C:\Windows\SysWOW64 () HKLM\...\Policies\Explorer: [NoViewContextMenu] 1 HKLM\...\Policies\Explorer: [NoDesktop] 1 <===== ATTENTION HKU\MeinName\...\Policies\system: [DisableTaskMgr] 1 HKU\MeinName\...\Policies\system: [DisableRegistryTools] 1 HKU\MeinName\...\Winlogon: [Userinit] C:\Users\MeinName\AppData\Roaming\loadit.exe [595750 2013-12-29] () HKU\MeinName\...\Winlogon: [Shell] C:\Users\MeinName\AppData\Roaming\loadit.exe [595750 2013-12-29] () <==== ATTENTION Startup: C:\Users\MeinName\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ja.lnk ShortcutTarget: ja.lnk -> C:\windows\system32\config\systemprofile\AppData\Roaming\loadit.exe (No File) safeboot: ==> The system is configured to boot to Safe Mode <===== ATTENTION! C:\windows\system32\config\systemprofile\AppData\Roaming\loadit.exe C:\Users\MeinName\AppData\Roaming\loadit.exe
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Rechner normal starten.
__________________ |
01.01.2014, 19:02 | #3 |
| GVU Trojaner auf Windows 8.1 PC Danke für die Hilfe.
__________________ |
02.01.2014, 16:56 | #4 |
/// the machine /// TB-Ausbilder | GVU Trojaner auf Windows 8.1 PC Wir sind noch nit fertig Ab jetzt alles im normalen Modus: Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu GVU Trojaner auf Windows 8.1 PC |
adobe flash player, association, check, defender, explorer, explorer.exe, flash player, free, google, icon, ics, loadit.exe, microsoft, mozilla, no-ip, realtek, registry, server.exe, services.exe, spotify web helper, starmoney, svchost.exe, system, system32, trojaner, userinit, windows, winlogon, winlogon.exe |