|
Log-Analyse und Auswertung: Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale KontrolleWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.01.2014, 18:36 | #1 |
| Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Hallo! Über euch hört und ließt man ja echt nur Gutes! Habe ich es bisher immer wieder geschafft meinen Freunden/Verwandten ihre Trojaner los zu werden, beiße ich heute auf eine echt harte Nuss, daher bitte ich um finale Hilfe. Ich habe/hatte das gleich Problem, wie der Leidensgenosse im Thread: http://www.trojaner-board.de/137417-...-moeglich.html , aber ich habe es mittlerweile geschafft den Rechner soweit zu bringen, dass er wieder "normal" bootet. Wie war die anfängliche Situation: Das Notebook kam von einem guten Freund mit der Meldung "ich habe den BKA-Trojaner" zu mir. Leider, wie oftmals andere auch, hat auch er viele Stunden selber versucht das Problem zu lösen: wie ihr denken könnt: erfolglos, nona. Was habe ich bisher gemacht: Schritt 1: Festplatte ausbauen, in sauberen PC einbauen: Acronis-Image ziehen..., empfehle ich wirklich jedem, wenn die Möglichkeit besteht das zu tun!! Schritt 2: ebenfalls in diesem sauberen Rechner: mit Avira und AVG Festplatte scannen lassen (es wurden 2 Dateien mit dem TR/Crypt.ZPACK.Gen gefunden und gelöscht) Schritt 3: Platte wieder in NB verbauen: Versuch das NB normal zu starten -> erfolglos, da weiterhin "gesperrt" mit dem BKA-Logo, Taskmanager ließ sich nicht starten. Schritt 4: Versuch das NB im abgesicherten Modus zu starten: erfolglos keiner der 3 Modi konnte gestartet werden, der PC wurde umgehend wieder heruntergefahren. Schritt 5: starten der Kommandozeile über die Computerreparatur.., das hat funktioniert..., leider hatte ich zu diesem Zeitpunkt, eurer Forum noch nicht gegoogelt! Ich habe hier die Registry durchsucht, aber nichts Verdächtiges gefunden. Schlussendlich bin ich über Google in diesem Forum gelandet! Komisch, warum die einfachsten Anweisungen immer missachtet werden (nein, bitte jetzt keine !!)? Nein, ich habe mich nicht an die Anweisungen gehalten und ja, ich habe es auf eigene Faust versucht den Trojaner los zu werden. Bitte NICHT schimpfen, ich weiß das ich einen Fehler gemacht habe! Was habe ich bisher gemacht: - Aus unerfindlichen Gründen, konnte das NB nach mehrmaligem Misserfolg, nun doch im abgesicherten Modus (Eingabeaufforderung) gestartet werden. - regeditor öffnen, unter ///Winlogon habe ich nichts verdächtiges gefunden, unter ///Run habe ich den Baum gesichert und alle Einträge gelöscht. - Neustart: gleiches Bild wie vorher - durch BKA-Logo gesperrt. - erneut abgesicherter Modus (Eingabeaufforderung) und "zufällig" in den Autostart geschaut..., na holla die Waldfee, da hat sichs abgespielt!! -> alle Einträge gelöscht und alles unter ...User/Appdata/lokal/temp in ein anderes Verzeichnis kopiert und in temp gelöscht, msconfig gestartet und alle starts deaktiviert - Neustart: YES! Rechner lässt sich problemlos starten! ABER: und hier weiß ich wirklich nicht weiter: was gilt es jetzt noch zu beachten? - warum hat Avira die anscheinend noch verseuchten Dateien nicht gefunden..., kein Zugriff auf das App Data-Verzeichnis?? Was wäre euer Rat jetzt noch zu tun? Hier das Scan-Ergebnis von FRST und Addition: FRST.TXT: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2014 01 Ran by my (administrator) on my-PC on 15-01-2014 17:13:48 Running from F:\ Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Computer, Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Teruten) C:\Windows\System32\FsUsbExService.Exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (X10) C:\Program Files\Common Files\X10\Common\X10nets.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe (Dropbox, Inc.) C:\Users\my\AppData\Roaming\Dropbox\bin\Dropbox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG) MountPoints2: G - G:\LaunchU3.exe -a MountPoints2: H - H:\LaunchU3.exe -a MountPoints2: {35f1e2fa-e2a8-11df-bbd5-806e6f6e6963} - E:\setup.exe MountPoints2: {d03983a7-88f4-11e2-98a5-00262dc1e8d6} - F:\ICM_ML.exe HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs AppInit_DLLs: C:\Windows\system32\nvinit.dll [100968 2010-07-26] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programme\MSOffice2007\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Programme\MSOffice2007\Office12\GrooveSystemServices.dll (Microsoft Corporation) Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [94208] (Apple Computer, Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt FireFox: ======== FF ProfilePath: C:\Users\my\AppData\Roaming\Mozilla\Firefox\Profiles\sdy3ucuy.default FF DefaultSearchEngine: Google FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Ask.com FF Homepage: hxxp://www.google.at/ FF NewTab: about:blank FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @canon.com/EPPEX - D:\Programme\mx310\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Extension: General Crawler - C:\Users\my\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com [2012-01-26] FF Extension: No Name - C:\Users\my\AppData\Roaming\Mozilla\Firefox\Profiles\sdy3ucuy.default\Extensions\staged [2013-12-02] FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-10-14] ========================== Services (Whitelisted) ================= R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [896056 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-18] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 Microsoft Office Groove Audit Service; D:\Programme\MSOffice2007\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation) R2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [1620584 2010-07-27] (NVIDIA Corporation) R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [244904 2010-02-12] () S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) S3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118560 2009-10-23] (Wistron Corp.) R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10) ==================== Drivers (Whitelisted) ==================== R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26032 2013-06-02] (Wondershare) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-16] (Avira Operations GmbH & Co. KG) R3 dvd43llh; C:\Windows\System32\DRIVERS\dvd43llh.sys [18816 2012-06-10] (RIF) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-02-05] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 mod7700; C:\Windows\System32\DRIVERS\mod7700.sys [786400 2009-08-13] (DiBcom SA) S3 MOSUMAC; C:\Windows\System32\DRIVERS\MOSUMAC.SYS [44032 2009-12-07] (--) R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [64904 2010-04-27] (Renesas Electronics Corporation) R3 nusb3xhc; C:\Windows\system32\DRIVERS\nusb3xhc.sys [146568 2010-04-27] (Renesas Electronics Corporation) R0 nvpciflt; C:\Windows\System32\DRIVERS\nvpciflt.sys [19656 2010-07-26] (NVIDIA Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [16472 2010-08-16] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [11104 2010-08-16] () S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation) S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-10-07] (Avira GmbH) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181344 2013-01-31] (DEVGURU Co., LTD.(www.devguru.co.kr)) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13720 2009-05-13] (X10 Wireless Technology, Inc.) S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27160 2009-05-13] (X10 Wireless Technology, Inc.) S3 Profos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys [x] S3 usbbus; system32\DRIVERS\lgusbbus.sys [x] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-15 17:13 - 2014-01-15 17:13 - 00000000 ____D C:\FRST 2014-01-15 16:18 - 2014-01-15 16:18 - 00004212 _____ C:\Users\my\Documents\run.reg 2014-01-15 16:18 - 2014-01-15 16:18 - 00000734 _____ C:\Users\my\Documents\run-.reg 2014-01-13 22:42 - 2014-01-14 09:08 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2014-01-12 18:59 - 2014-01-15 16:20 - 00000000 _____ C:\ProgramData\id71lfa.odd 2014-01-12 18:59 - 2014-01-14 09:07 - 00000000 _____ C:\ProgramData\78zhlv9.odd 2014-01-08 23:07 - 2014-01-08 23:07 - 00000000 __RHD C:\MSOCache 2014-01-08 23:07 - 2014-01-08 23:07 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2013-12-20 10:11 - 2013-12-20 10:11 - 00000000 ____D C:\Users\my\AppData\Local\{B667BB81-527E-44F2-A9F9-EE09C910F832} 2013-12-18 21:32 - 2013-12-18 21:32 - 00001171 _____ C:\Users\my\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Video Converter.lnk 2013-12-18 21:32 - 2013-12-18 21:32 - 00001103 _____ C:\Users\my\Desktop\Free Video Converter.lnk 2013-12-18 21:32 - 2013-12-18 21:32 - 00000000 ____D C:\Users\my\AppData\Roaming\FreeVideoConverter 2013-12-18 21:31 - 2013-12-18 21:32 - 00000000 ____D C:\Program Files\Free Video Converter 2013-12-18 20:27 - 2013-12-18 20:27 - 00000000 ____D C:\Users\my\AppData\Local\{80BC2BB8-C91E-44AA-877D-30BEEB6F23F4} 2013-12-18 19:23 - 2013-12-18 19:23 - 00000000 ____D C:\Users\my\AppData\Local\{E2048313-E66C-49EB-B520-8D107F1370F8} 2013-12-18 18:58 - 2013-12-18 19:00 - 00000000 ____D C:\Users\my\Documents\Apowersoft Free Screen Recorder 2013-12-18 18:57 - 2013-12-18 18:57 - 00000000 ____D C:\Users\my\AppData\Roaming\Apowersoft 2013-12-18 18:57 - 2013-06-02 04:56 - 00026032 _____ (Wondershare) C:\Windows\system32\Drivers\Apowersoft_AudioDevice.sys 2013-12-18 18:57 - 2013-06-01 20:07 - 00443568 ____H (Bytescout) C:\Windows\system32\ApowersoftScreenCapturing.dll 2013-12-18 18:57 - 2013-06-01 20:07 - 00271536 ____H (Bytescout) C:\Windows\system32\ApowersoftScreenCapturingFilter.dll 2013-12-18 18:57 - 2013-06-01 20:07 - 00181424 ____H (Bytescout) C:\Windows\system32\ApowersoftVideoMixerFilter.dll 2013-12-17 22:36 - 2013-12-17 22:36 - 00001102 _____ C:\Users\Public\Desktop\Prism Videodatei-Konverter.lnk 2013-12-17 22:35 - 2013-12-18 20:26 - 00000000 ____D C:\ProgramData\NCH Software 2013-12-17 22:35 - 2013-12-17 22:35 - 00001130 _____ C:\Users\Public\Desktop\VideoPad Video-Editor.lnk 2013-12-17 22:35 - 2013-12-17 22:35 - 00000000 ____D C:\Users\my\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videoverwandte Programme 2013-12-17 22:35 - 2013-12-17 22:35 - 00000000 ____D C:\Users\my\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette 2013-12-17 22:34 - 2013-12-18 20:26 - 00000000 ____D C:\Users\my\AppData\Roaming\NCH Software 2013-12-17 22:34 - 2013-12-18 18:53 - 00001088 _____ C:\Users\Public\Desktop\Debut Videorekorder.lnk 2013-12-17 22:34 - 2013-12-17 22:36 - 00000000 ____D C:\Program Files\NCH Software ==================== One Month Modified Files and Folders ======= 2014-01-15 21:47 - 2009-07-14 03:03 - 81526784 _____ C:\Windows\system32\config\SOFTWARE.alt 2014-01-15 21:29 - 2009-07-14 03:03 - 39321600 _____ C:\Windows\system32\config\SYSTEM.alt 2014-01-15 21:29 - 2009-07-14 03:03 - 00262144 _____ C:\Windows\system32\config\SECURITY.alt 2014-01-15 21:29 - 2009-07-14 03:03 - 00262144 _____ C:\Windows\system32\config\SAM.alt 2014-01-15 17:14 - 2010-10-28 07:36 - 02043319 _____ C:\Windows\WindowsUpdate.log 2014-01-15 17:13 - 2014-01-15 17:13 - 00000000 ____D C:\FRST 2014-01-15 17:13 - 2012-12-10 23:04 - 00000000 ____D C:\Users\my\AppData\Roaming\Dropbox 2014-01-15 17:13 - 2009-07-14 05:39 - 00245038 _____ C:\Windows\setupact.log 2014-01-15 17:10 - 2009-07-14 05:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-15 17:10 - 2009-07-14 05:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-15 17:03 - 2013-02-25 09:57 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-15 17:03 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-15 16:45 - 2010-10-28 07:48 - 00153168 _____ C:\Users\my\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-15 16:20 - 2014-01-12 18:59 - 00000000 _____ C:\ProgramData\id71lfa.odd 2014-01-15 16:18 - 2014-01-15 16:18 - 00004212 _____ C:\Users\my\Documents\run.reg 2014-01-15 16:18 - 2014-01-15 16:18 - 00000734 _____ C:\Users\my\Documents\run-.reg 2014-01-15 12:55 - 2009-07-14 05:33 - 01853688 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-15 12:26 - 2009-07-14 03:03 - 00786432 _____ C:\Windows\system32\config\DEFAULT.alt 2014-01-14 09:08 - 2014-01-13 22:42 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2014-01-14 09:07 - 2014-01-12 18:59 - 00000000 _____ C:\ProgramData\78zhlv9.odd 2014-01-14 00:31 - 2013-02-25 09:57 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-14 00:29 - 2012-11-24 16:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-13 23:11 - 2010-11-28 10:00 - 00000952 ___SH C:\ProgramData\KGyGaAvL.sys 2014-01-13 15:54 - 2009-07-14 05:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-12 19:30 - 2010-07-07 19:31 - 01162222 _____ C:\Windows\PFRO.log 2014-01-09 21:12 - 2010-07-06 21:23 - 01668938 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-09 20:52 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET 2014-01-08 23:11 - 2014-01-08 23:11 - 00000083 _____ C:\Users\my\Downloads\ms project 2010 crack.txt 2014-01-08 23:09 - 2010-11-28 18:12 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-08 23:08 - 2011-07-02 00:40 - 00000000 ____D C:\Program Files\Microsoft Office 2014-01-08 23:08 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2014-01-08 23:07 - 2014-01-08 23:07 - 00000000 __RHD C:\MSOCache 2014-01-08 23:07 - 2014-01-08 23:07 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2014-01-08 23:07 - 2009-07-14 08:48 - 00000000 ____D C:\Windows\ShellNew 2014-01-03 20:02 - 2011-01-12 22:36 - 00000000 ____D C:\ProgramData\Anti-phishing Domain Advisor 2014-01-02 20:03 - 2013-06-16 17:55 - 00006144 _____ C:\Users\my\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-12-20 10:11 - 2013-12-20 10:11 - 00000000 ____D C:\Users\my\AppData\Local\{B667BB81-527E-44F2-A9F9-EE09C910F832} 2013-12-18 22:26 - 2013-05-08 21:35 - 00069240 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-12-18 22:26 - 2012-10-07 19:56 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-18 22:26 - 2012-10-07 19:56 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-18 22:06 - 2013-03-14 21:54 - 00000000 ____D C:\Users\my\AppData\Roaming\Audacity 2013-12-18 21:32 - 2013-12-18 21:32 - 00001171 _____ C:\Users\my\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Video Converter.lnk 2013-12-18 21:32 - 2013-12-18 21:32 - 00001103 _____ C:\Users\my\Desktop\Free Video Converter.lnk 2013-12-18 21:32 - 2013-12-18 21:32 - 00000000 ____D C:\Users\my\AppData\Roaming\FreeVideoConverter 2013-12-18 21:32 - 2013-12-18 21:31 - 00000000 ____D C:\Program Files\Free Video Converter 2013-12-18 20:27 - 2013-12-18 20:27 - 00000000 ____D C:\Users\my\AppData\Local\{80BC2BB8-C91E-44AA-877D-30BEEB6F23F4} 2013-12-18 20:26 - 2013-12-17 22:35 - 00000000 ____D C:\ProgramData\NCH Software 2013-12-18 20:26 - 2013-12-17 22:34 - 00000000 ____D C:\Users\my\AppData\Roaming\NCH Software 2013-12-18 19:23 - 2013-12-18 19:23 - 00000000 ____D C:\Users\my\AppData\Local\{E2048313-E66C-49EB-B520-8D107F1370F8} 2013-12-18 19:00 - 2013-12-18 18:58 - 00000000 ____D C:\Users\my\Documents\Apowersoft Free Screen Recorder 2013-12-18 18:57 - 2013-12-18 18:57 - 00000000 ____D C:\Users\my\AppData\Roaming\Apowersoft 2013-12-18 18:53 - 2013-12-17 22:34 - 00001088 _____ C:\Users\Public\Desktop\Debut Videorekorder.lnk 2013-12-17 22:37 - 2012-09-11 14:02 - 00001413 _____ C:\Users\my\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-17 22:37 - 2011-07-22 22:18 - 00000000 ____D C:\Users\my\AppData\Local\Google 2013-12-17 22:37 - 2011-07-22 22:18 - 00000000 ____D C:\Program Files\Google 2013-12-17 22:36 - 2013-12-17 22:36 - 00001102 _____ C:\Users\Public\Desktop\Prism Videodatei-Konverter.lnk 2013-12-17 22:36 - 2013-12-17 22:34 - 00000000 ____D C:\Program Files\NCH Software 2013-12-17 22:35 - 2013-12-17 22:35 - 00001130 _____ C:\Users\Public\Desktop\VideoPad Video-Editor.lnk 2013-12-17 22:35 - 2013-12-17 22:35 - 00000000 ____D C:\Users\my\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videoverwandte Programme 2013-12-17 22:35 - 2013-12-17 22:35 - 00000000 ____D C:\Users\my\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette 2013-12-16 13:29 - 2012-10-07 19:56 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys Files to move or delete: ==================== C:\Users\my\AppData\Roaming\settings.ini C:\Users\my\AppData\Roaming\skype.ini C:\ProgramData\78zhlv9.odd C:\ProgramData\id71lfa.odd ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-07 17:00 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-01-2014 01 Ran by my at 2014-01-15 17:14:31 Running from F:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Out of date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Out of date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (Version: - Microsoft) 32 Bit HP CIO Components Installer (Version: 8.1.1 - Hewlett-Packard) Hidden Acrobat.com (Version: 1.6.65 - Adobe Systems Incorporated) Adobe Acrobat 9 Pro - English, Français, Deutsch (Version: 9.3.0 - Adobe Systems) Hidden Adobe Acrobat 9.3.0 - CPSID_52073 (Version: - Adobe Systems Incorporated) Adobe AIR (Version: 3.9.0.1030 - Adobe Systems Incorporated) Adobe AIR (Version: 3.9.0.1030 - Adobe Systems Incorporated) Hidden Adobe Anchor Service CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Asset Services CS3 (Version: 3 - Adobe Systems Incorporated) Hidden Adobe Bridge 1.0 (Version: 001.000.001 - Adobe Systems) Hidden Adobe Bridge CS3 (Version: 2 - Adobe Systems Incorporated) Hidden Adobe Bridge Start Meeting (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe BridgeTalk Plugin CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Camera Raw 4.0 (Version: 4.0 - Adobe Systems Incorporated) Hidden Adobe CMaps (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Color - Photoshop Specific (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Color Common Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Color EU Recommended Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Color JA Extra Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Color NA Extra Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Common File Installer (Version: 1.00.001 - Adobe System Incorporated) Hidden Adobe Creative Suite 3 Design Premium (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Creative Suite 3 Design Premium hinzufügen oder entfernen (Version: 1.0 - Adobe Systems Incorporated) Adobe Default Language CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Device Central CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (Version: 1.2.3 - Adobe Systems Incorporated) Adobe Download Assistant (Version: 1.2.3 - Adobe Systems Incorporated) Hidden Adobe ExtendScript Toolkit 2 (Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Extension Manager CS3 (Version: 1.8 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Fonts All (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Help Center 1.0 (Version: 1.0.1 - Adobe Systems) Hidden Adobe Help Viewer CS3 (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Illustrator CS3 (Version: 13.0 - Adobe Systems Incorporated) Hidden Adobe InDesign CS3 (Version: 5.0 - Adobe Systems Incorporated) Hidden Adobe InDesign CS3 Icon Handler (Version: 5.0 - Adobe Systems Incorporated) Hidden Adobe Linguistics CS3 (Version: 3.0.0 - Adobe Systems Incorporated) Hidden Adobe MotionPicture Color Files (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe PDF Library Files (Version: 8.0 - Adobe Systems Incorporated) Hidden Adobe Photoshop CS3 (Version: 10 - Adobe Systems Incorporated) Hidden Adobe Setup (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe SING CS3 (Version: 0.1 - Adobe Systems Incorporated) Hidden Adobe Stock Photos 1.0 (Version: 1.0.1 - Adobe Systems) Hidden Adobe Stock Photos CS3 (Version: 1.5 - Adobe Systems Incorporated) Hidden Adobe Support Advisor (Version: 1.6.1 - Adobe Systems Incorporated) Hidden Adobe Support Advisor (Version: 1.6.1.20120504 - Adobe Systems Incorporated) Adobe Type Support (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Update Manager CS3 (Version: 5.1.0 - Adobe Systems Incorporated) Hidden Adobe Version Cue CS3 Client (Version: 3 - Adobe Systems Incorporated) Hidden Adobe WAS CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe WinSoft Linguistics Plugin (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe XMP Panels CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden AHV content for Acrobat and Flash (Version: 1 - Adobe Systems Incorporated) Hidden Allway Sync version 12.16.1 (Version: - Botkind Inc) Anti-phishing Domain Advisor (Version: 1.0.0.1 - Visicom Media Inc. (Powered by Panda Security)) Apowersoft kostenloser Bildschirmrekorder V1.2.4 (Version: 1.2.4 - Apowersoft) Apple Application Support (Version: 2.1.5 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio (Version: 9.23.0 - ashampoo GmbH & Co. KG) Ashampoo Photo Commander (Version: 8.1.0 - ashampoo GmbH & Co. KG) Ashampoo Snap (Version: 3.4.0 - ashampoo GmbH & Co. KG) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (Version: 1.0.0.27 - Atheros Communications Inc.) Audacity 2.0.3 (Version: 2.0.3 - Audacity Team) Audiograbber 1.83 SE (Version: 1.83 SE - Audiograbber) Audiograbber MP3-Plugin (Version: 1.0 - AG) AutoCAD 2010 - Deutsch (Version: 18.0.309.0 - Autodesk) AutoCAD 2010 - Deutsch (Version: 18.0.309.0 - Autodesk) Hidden AutoCAD 2010 - Deutsch Version 3 (Version: 1 - Autodesk) AutoCAD 2010 Language Pack - Deutsch (Version: 18.0.55.0 - Autodesk) Hidden AutoCAD Architecture 2010 - Deutsch (Version: 6.0.82.0 - Autodesk) Hidden AutoCAD Architecture 2010 - Deutsch Version 3 (Version: 1 - Autodesk) AutoCAD Architecture 2010 Language Pack - Deutsch (Version: 18.0.55.0 - Autodesk) Hidden Avira Antivirus Premium (Version: 14.0.2.286 - Avira) Canon MX320 series Benutzerregistrierung (Version: - ) Canon MX320 series MP Drivers (Version: - ) Canon Utilities Easy-PhotoPrint EX (Version: - ) Canon Utilities My Printer (Version: - ) Cisco EAP-FAST Module (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (Version: 1.1.6 - Cisco Systems, Inc.) CorelDRAW Essentials 4 - Content (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Draw (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Filters (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - ICA (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - IPM - No VBA (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang BR (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang DE (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang EN (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang ES (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang FR (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang IT (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang NL (Version: 4.0 - Uw bedrijfsnaam) Hidden CorelDRAW Essentials 4 - PHOTO-PAINT (Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Windows Shell Extension (Version: - Corel Corporation) CorelDRAW Essentials 4 - Windows Shell Extension (Version: 1.1 - Corel Corporation) Hidden CorelDRAW Essentials 4 (Version: - Corel Corporation) CorelDRAW Essentials 4 (Version: 4.0 - Corel Corporation) Hidden CrissCross 8.40 (Version: 8.4.0.0 - ) Crossword Compiler Deutsch 9 Testversion (Version: - WordWeb Software) CyberLink LabelPrint (Version: 2.5.2602 - CyberLink Corp.) CyberLink LabelPrint (Version: 2.5.2602 - CyberLink Corp.) Hidden CyberLink MediaShow (Version: 5.0.1410a - CyberLink Corp.) CyberLink MediaShow (Version: 5.0.1410a - CyberLink Corp.) Hidden CyberLink MediaShow Espresso (Version: 5.5.1412_24021 - CyberLink Corp.) CyberLink MediaShow Espresso (Version: 5.5.1412_24021 - CyberLink Corp.) Hidden CyberLink PhotoNow (Version: 1.1.6904 - CyberLink Corp.) CyberLink PhotoNow (Version: 1.1.6904 - CyberLink Corp.) Hidden CyberLink Power2Go (Version: 6.1.3602c - CyberLink Corp.) CyberLink Power2Go (Version: 6.1.3602c - CyberLink Corp.) Hidden CyberLink PowerDirector (Version: 8.0.2718 - CyberLink Corp.) CyberLink PowerDirector (Version: 8.0.2718 - CyberLink Corp.) Hidden CyberLink PowerDVD 9 (Version: 9.0.2925.52 - CyberLink Corp.) CyberLink PowerDVD 9 (Version: 9.0.2925.52 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy (Version: 1.5.1306 - CyberLink Corp.) CyberLink PowerDVD Copy (Version: 1.5.1306 - CyberLink Corp.) Hidden CyberLink PowerProducer (Version: 5.0.2.2326 - CyberLink Corp.) CyberLink PowerProducer (Version: 5.0.2.2326 - CyberLink Corp.) Hidden CyberLink YouCam (Version: 3.0.2626 - CyberLink Corp.) CyberLink YouCam (Version: 3.0.2626 - CyberLink Corp.) Hidden D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden Debut Videorekorder (Version: - NCH Software) Dropbox (Version: 2.0.22 - Dropbox, Inc.) DVD43 v4.6.0 (Version: - ) DxO Optics Pro 5.3.2 (Version: 5.3.2 - DXO Labs) EGR-ShellExtension (Version: 1.0.0.100 - EasternGraphics) ExpressFiles (Version: 1.2.5 - hxxp://www.express-files.com/) <==== ATTENTION FFmpeg v0.6.2 for Audacity (Version: - ) FileZilla Client 3.6.0.2 (Version: 3.6.0.2 - FileZilla Project) Free DVD Video Converter version 2.0.7.608 (Version: 2.0.7.608 - DVDVideoSoft Ltd.) Free PDF to Word Doc Converter v1.1 (Version: 1.1 - www.hellopdf.com) Free Video Converter V 3.2 (Version: 3.2.0.0 - Koyote Soft) Free YouTube Download version 3.1.26.504 (Version: 3.1.26.504 - DVDVideoSoft Ltd.) Gigaflat (Version: - Bitrockers Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.2182 - Intel Corporation) Intel(R) Management Engine Components (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 9.6.0.1014 - Intel Corporation) Java 7 Update 7 (Version: 7.0.70 - Oracle) Java Auto Updater (Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden Joe (Version: 3.05.0100 - Wirth New Media Sarl) Lame ACM MP3 Codec (Version: - ) LAME v3.99.3 (for Windows) (Version: - ) Launch Manager (Version: 1.5.1.2 - Wistron Corp.) Licensing Service Install (Version: 2.0.1.181 - Protexis Inc.) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation) Maxwell for SketchUp 8 (Standalone) (Version: 2.6.10 - Next Limit Technologies) Medion Home Cinema (Version: 8.0.1505 - CyberLink Corp.) Medion Home Cinema (Version: 8.0.1505 - CyberLink Corp.) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Silverlight (Version: 4.1.10329.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) MiniTool Partition Wizard Home Edition 5.2 (Version: - MiniTool Solution Ltd.) MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) MyFreeCodec (Version: - ) NVIDIA Display Control Panel (Version: 6.14.12.5912 - NVIDIA Corporation) NVIDIA Drivers (Version: 1.10.62.40 - NVIDIA Corporation) NVIDIA Updatus (Version: 1.0.3 - NVIDIA Corporation) Hidden PDF Architect (Version: 1.1.83.9982 - pdfforge GmbH) PDF Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden PDFCreator (Version: 1.7.1 - pdfforge) PeaZip 3.6.2 (Version: - Giorgio Tani) PlayReady PC Runtime x86 (Version: 1.3.0 - Microsoft Corporation) Prism Videodatei-Konverter (Version: 2.02 - NCH Software) QuickTime (Version: 7.71.80.42 - Apple Inc.) Realtek High Definition Audio Driver (Version: 6.0.1.6128 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (Version: 6.1.7600.30121 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (Version: 1.00.0148 - REALTEK Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.4.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden Samsung Kies (Version: 2.3.2.12064_10 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.3.2.12064_10 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: 1.5.18.0 - SAMSUNG Electronics Co., Ltd.) Schachermayer Warenkorb 2.6 (Version: - ) Shaderlight For SketchUp (Version: 0.1.0.0 - ArtVPS) SketchUp Pro 8 (Version: 3.0.16944 - Trimble Navigation Limited) Sony Ericsson Update Engine (Version: 2.13.2.40 - Sony Ericsson Communications AB) Sony Ericsson Update Service (Version: 2.11.12.5 - Sony Ericsson Mobile Communications AB) Sony PC Companion 2.10.136 (Version: 2.10.136 - Sony) SUPER © +Recorder.2013.55 (Mar 7, 2013) Version +Recorder.2013. (Version: +Recorder.2013.55 - eRightSoft) Synaptics Pointing Device Driver (Version: 14.0.19.0 - Synaptics Incorporated) Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760586) 32-Bit Edition (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (Version: - Microsoft) VideoPad Video-Editor (Version: 3.23 - NCH Software) VLC media player 1.1.11 (Version: 1.1.11 - VideoLAN) WIA and Minimal TWAIN for hp Scanjet 4500-5550 (Version: 1.00.0000 - Hewlett-Packard) WIA and Minimal TWAIN for hp Scanjet 4500-5550 (Version: 1.00.0000 - Hewlett-Packard) Hidden Win7codecs (Version: 3.2.2 - Shark007) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Sync (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Media Encoder 9 Series (Version: - ) Windows Media Encoder 9 Series (Version: 9.00.2980 - Microsoft Corporation) Hidden Windows-Treiberpaket - Hewlett-Packard Image (12/27/2006 8.0.0.0) (Version: 12/27/2006 8.0.0.0 - Hewlett-Packard) X10 Hardware(TM) (Version: - ) XnView 1.99 (Version: 1.99 - Gougelet Pierre-e) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:04 - 2011-04-14 13:01 - 00001383 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate.adobe.com:443 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 192.150.18.108 127.0.0.1 adobeereg.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {546A6CE3-49FF-4FA4-9964-F44B5CFB6F31} - System32\Tasks\Express FilesUpdate => C:\Program Files\ExpressFiles\EFUpdater.exe [2012-11-02] (hxxp://www.express-files.com/) <==== ATTENTION Task: {55909ECE-149C-4AEB-BCC1-A3531C49D99B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-02-25] (Google Inc.) Task: {772E6681-B4AD-4893-A3A4-7AA033E400EA} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {8C2D6EDE-A93A-4195-8A4B-BD896646247E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-02-25] (Google Inc.) Task: {9FAD91E0-C0CB-43A5-91D9-1782B54AB325} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: {A7E27166-2B87-420D-AA7A-CC430ABEC870} - System32\Tasks\Your File Updater => C:\Program Files\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {B731CF09-318A-47F2-B36A-1D1FA0BE1453} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C6EDF829-7834-4E53-AFF4-66955516CFD5} - System32\Tasks\{3807FC5F-4575-4AE4-ABCC-5EDDA02FC4C9} => D:\Programme\MSOffice2007\Office14\WINPROJ.EXE Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\my\AppData\Roaming\Dropbox\bin\libcef.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:vQpTqFAs8pZJXC2q4P AlternateDataStreams: C:\ProgramData\Microsoft:xaenFFay703yDwi7xEujWFvp1Mj AlternateDataStreams: C:\ProgramData\Microsoft:yQMWkaos8xgxPGBr78qoVE7 AlternateDataStreams: C:\ProgramData\Temp:661DFA1C AlternateDataStreams: C:\Users\my\Cookies:6CESOffMMfhcBK4PBKnfCt2Q ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/12/2014 07:02:45 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: RtHDVCpl.exe, Version: 1.0.0.526, Zeitstempel: 0x4c04b49e Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b60 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00052cc7 ID des fehlerhaften Prozesses: 0xaa0 Startzeit der fehlerhaften Anwendung: 0xRtHDVCpl.exe0 Pfad der fehlerhaften Anwendung: RtHDVCpl.exe1 Pfad des fehlerhaften Moduls: RtHDVCpl.exe2 Berichtskennung: RtHDVCpl.exe3 Error: (01/09/2014 09:59:26 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16457, Zeitstempel: 0x50a2f9e3 Name des fehlerhaften Moduls: MSHTML.dll, Version: 9.0.8112.16457, Zeitstempel: 0x50a30507 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00262690 ID des fehlerhaften Prozesses: 0x1524 Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0 Pfad der fehlerhaften Anwendung: iexplore.exe1 Pfad des fehlerhaften Moduls: iexplore.exe2 Berichtskennung: iexplore.exe3 Error: (01/08/2014 11:12:41 PM) (Source: Office Software Protection Platform Service) (User: ) Description: hr=0xC004C00347a5840c-8124-4a1f-a447-50168cd6833d Error: (01/08/2014 11:12:41 PM) (Source: Office Software Protection Platform Service) (User: ) Description: hr=0xC004C00300010001(0x00000000, 23:12:41:356 - hxxp://go.microsoft.com/fwlink/?LinkID=120751) 00020001(0x00000000, 23:12:41:356) 00030001(0x00000000, 23:12:41:356 - hxxp://go.microsoft.com) 00030002(0x00000000, 23:12:41:356 - 1) 00020005(0x00000000, 23:12:41:356 - 0) 0002000C(0x00000000, 23:12:41:528 - 302) 0002000E(0x00000000, 23:12:41:528 - https://activation.sls.microsoft.com/slpkc/SLCertifyProduct.asmx?configextension=o14) 00020001(0x00000000, 23:12:41:528) 00030001(0x00000000, 23:12:41:528 - https://activation.sls.microsoft.com) 00030002(0x00000000, 23:12:41:528 - 1) 00020005(0x00000000, 23:12:41:528 - 0) 0002000C(0x00000000, 23:12:41:731 - 500) 00010002(0x8004FC01, 23:12:41:731 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="hxxp://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C003</HRESULT><Messages><Message>103 (Activation) - [PA Product key blocked. ---> Product key blocked]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>) 00010003(0x8004FC01, 23:12:41:731) Error: (01/08/2014 11:07:00 PM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Users\HRBIE~1\AppData\Local\Temp\OWP53BB.tmp\setup.exe; Beschreibung = Installed Microsoft Project Professional 2010; Fehler = 0x80070422). Error: (01/08/2014 00:02:25 PM) (Source: Software Protection Platform Service) (User: ) Description: Fehler bei der Erfassung des authentischen Tickets (hr=0x8004FE30) für die Vorlagen-ID 66c92734-d682-4d71-983e-d6ec3f16059f. Error: (01/08/2014 00:02:25 PM) (Source: Software Protection Platform Service) (User: ) Description: Lizenzerwerb-Fehlerdetails. hr=0x8004FE30 Error: (01/03/2014 08:31:34 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Die Daten sind unzulässig. . Error: (01/03/2014 08:31:33 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Die Daten sind unzulässig. . Error: (01/03/2014 08:31:28 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Die Daten sind unzulässig. . System errors: ============= Error: (01/15/2014 04:44:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:35 PM) (Source: DCOM) (User: ) Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (01/15/2014 04:44:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:34 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (01/15/2014 04:44:35 PM) (Source: DCOM) (User: ) Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Microsoft Office Sessions: ========================= Error: (06/17/2013 10:21:09 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2721 seconds with 2640 seconds of active time. This session ended with a crash. Error: (05/11/2013 07:32:31 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 56 seconds with 0 seconds of active time. This session ended with a crash. Error: (05/11/2013 07:29:36 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 30 seconds with 0 seconds of active time. This session ended with a crash. Error: (05/11/2013 07:27:36 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 595 seconds with 60 seconds of active time. This session ended with a crash. Error: (05/11/2013 07:17:16 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 85 seconds with 0 seconds of active time. This session ended with a crash. Error: (05/11/2013 07:10:49 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 96 seconds with 60 seconds of active time. This session ended with a crash. Error: (04/04/2013 04:26:27 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 92 seconds with 0 seconds of active time. This session ended with a crash. Error: (03/18/2013 09:46:26 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1973 seconds with 1380 seconds of active time. This session ended with a crash. Error: (02/19/2013 09:30:22 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1030 seconds with 1020 seconds of active time. This session ended with a crash. Error: (01/21/2013 04:15:08 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1516 seconds with 1140 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 35% Total physical RAM: 3253.42 MB Available physical RAM: 2114.7 MB Total Pagefile: 6505.13 MB Available Pagefile: 4972.74 MB Total Virtual: 2047.88 MB Available Virtual: 1896.29 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:78.12 GB) (Free:16.69 GB) NTFS Drive d: (Programme-Daten) (Fixed) (Total:516.95 GB) (Free:421.22 GB) NTFS Drive f: () (Removable) (Total:29.84 GB) (Free:29.05 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=78 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=517 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=1 GB) - (Type=02) ======================================================== Disk: 1 (Size: 30 GB) (Disk ID: 0D0C0B0A) Partition 1: (Active) - (Size=30 GB) - (Type=0C) ==================== End Of Log ============================ LG 2bs |
16.01.2014, 07:42 | #2 |
/// the machine /// TB-Ausbilder | Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Hi,
__________________kannste die Änderungen wieder einrichten mit msconfig und Co? Scan mit Combofix
__________________ |
16.01.2014, 08:24 | #3 |
| Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Hallo Schrauber!
__________________Danke für die rasche Rückmeldung! Ganz schön was los hier!! Ja, ich habe bis auf zwei meines Erachtens nicht relevanten Einträge in ///run zurückkopiert und auch in der msconfig wieder alles reaktiviert. Hier das Ergebnis von Combofix: Code:
ATTFilter Combofix Logfile: |
16.01.2014, 17:22 | #4 |
/// the machine /// TB-Ausbilder | Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.01.2014, 17:35 | #5 |
| Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Danke Schrauber! Werde ich alles machen, bekomme das Gerät aber frühestens Montag wieder in die Hände..., wenn ihr so nett wärt und den Threat so lang offen lasst?! ..., Spende ist bereits unterwegs!! Zusätzlich 6 von 5 Sternen für euer professionelles Engagement! Weiter so! LG |
17.01.2014, 12:52 | #6 |
/// the machine /// TB-Ausbilder | Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Klar bleibt der Thread offen
__________________ --> Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle |
26.01.2014, 22:13 | #7 |
| Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Danke für eure Geduld! Mein lieber Kollege hat sich dazu entschieden nichts weiter zu unternehmen, er braucht sein Notebook "ganz dringend"! Klar! :-( Na wie auch immer, ich habe ihn jedenfalls darauf hingewiesen, dass er damit rechnen muss, dass das Gerät nicht vollständig sauber ist..., er meint das sei ihm jetzt egal! ICH jedenfalls danke euch nochmals sehr herzlich für eure schnell und kompetente Hilfe, und werde euch auf jeden Fall weiterempfehlen!! Somit kann der Thread jetzt geschlossen werden! LG 2bs |
27.01.2014, 16:12 | #8 |
/// the machine /// TB-Ausbilder | Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Polizei Trojaner (Österreich). Kein abgesicherter Modus möglich - Finale Kontrolle |
0x8007042, antivir, applaus, avira, browser, converter, desktop, device driver, dvdvideosoft ltd., email, entfernen, error, excel, festplatte, flash player, google, home, homepage, iexplore.exe, koyote, newtab, ntdll.dll, nvpciflt.sys, problem, scan, server, shark, sketchup, software, starten, system, taskmanager, trojaner, warum, windows, wsearch |