Windows 7: "Windows-Verwaltungsinstrumentation"-Dienst startet nicht nach Trojanerbefal

Hallo, ich sitze gerade an einem Laptop von einem Freund, der sich den BKA/GVU-Trojaner mit Sperrbildschirm eingefangen hatte. Diesen konnte ich wieder entfernen. Nun startet jedoch ein Windows-Dienst nicht mehr, was vermutlich mit der Infektion in Verbindung steht. Die Fehlermeldung in den Systemprotokollen lautet: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: Das System kann die angegebene Datei nicht finden. (Ereignis-ID: 7023)
Ich habe bereits einige Schritte durchgeführt: 1. Scan mit Kaspersky RescueDisk10 2. Scan mit Malwarebytes Anti-Malware (Complete-Scan) 3. ADWCleaner 4. ESET-Online-Scanner 5. Temporäre Dateien gelöscht (Windows, Internetexplorer, Java-Cache) 6. Flashplayer, Java (x86+x64) neu installiert + Microsoft Updates installiert 7. Internet Explorer auf Werkseinstellungen zurückgesetzt

zu 1.: Der Log fehlt leider. Gefunden und gelöscht wurden rund 50 Infektionen. Darunter die Trojaner Ransomware und SpyEye.
zu 2.: Einziger Fund: Trojan.FakeMS (Datei: C:\ProgramData\31577CDA788B660569CB7D00D219ACB4\friwq9e.dot)
zu 3.: ADWCleaner fand: Schlüssel: HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS

Ich habe FRST laufen lassen. Hier die Logs:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 08/06/2014 um 11:19:51 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Maag - MAAG-PC # Gestartet von : C:\Users\Maag\Desktop\Scanner\2- adwcleaner_3.212.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [640 octets] - [08/06/2014 11:19:51] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [699 octets] ########## Ich habe FRST laufen lassen. Hier die Logs: FRST: Code:
FRST Scan result (Auszug):
Platform: Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Norman ASA) C:\Program Files\Norman\Npm\Bin\elogsvc.exe (Norman ASA) C:\Program Files\Norman\Ngs\Bin\nnf.exe (AMD) C:\Windows\System32\atiesrxx.exe (Norman ASA) C:\Program Files\Norman\Npm\Bin\zanda.exe (Norman ASA) C:\Program Files\Norman\Npm\Bin\nvoy.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe () C:\Program Files\Norman\Nvc\Bin\nhs.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (AMD) C:\Windows\System32\atieclxx.exe (Norman ASA) C:\Program Files\Norman\Npm\Bin\scheduler.exe () C:\Program Files\Norman\Npm\Bin\njeeves.exe (Norman ASA) C:\Program Files\Norman\Nse\Bin\nsesvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Norman ASA) C:\Program Files\Norman\Npm\Bin\zlh.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-10-14] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\\AsusWSPanel.exe [737104 2011-07-29] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322176 2012-02-16] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-03] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [Norman ZANDA] => C:\Program Files\Norman\Npm\Bin\ZLH.EXE [350560 2013-02-04] (Norman ASA) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4F77BC0F8182CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @java.com/DTPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-03-22] (Advanced Micro Devices, Inc.) R2 eLoggerSvc6; C:\Program Files\Norman\Npm\Bin\elogsvc.exe [76232 2011-10-24] (Norman ASA) R2 NHS; C:\Program Files\Norman\Nvc\bin\nhs.exe [793520 2012-05-10] () R2 NNFSVC; C:\Program Files\Norman\Ngs\Bin\Nnf.exe [231216 2011-11-14] (Norman ASA) R3 Norman NJeeves; C:\Program Files\Norman\Npm\Bin\Njeeves.exe [116056 2012-02-03] () R2 Norman ZANDA; C:\Program Files\Norman\Npm\Bin\Zanda.exe [431320 2012-02-13] (Norman ASA) R3 nsesvc; C:\Program Files\Norman\Nse\Bin\NSESVC.EXE [427288 2013-04-02] (Norman ASA) S3 nvcoas; C:\Program Files\Norman\Nvc\Bin\nvcoas.exe [287312 2012-06-28] (Norman ASA) R2 NVOY; C:\Program Files\Norman\npm\bin\nvoy.exe [100936 2011-10-19] (Norman ASA) R3 Scheduler; C:\Program Files\Norman\Npm\Bin\scheduler.exe [148240 2011-04-11] (Norman ASA) S2 Winmgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R1 NGS; c:\program files\norman\ngs\bin\ngs64.sys [22368 2011-07-12] (Norman ASA) R2 nregsec; C:\Program Files\Norman\Ngs\Bin\nregsec64.sys [63032 2011-11-11] (Norman ASA) S3 NvcMFlt; C:\Windows\System32\DRIVERS\nvcv64mf.sys [57952 2012-08-16] (Norman ASA) S0 flgloqgy; System32\drivers\gvwxbhl.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-08 21:29 - 2014-06-08 22:32 - 00000000 ____D () C:\FRST 2014-06-08 19:44 - 2014-06-08 19:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-08 19:32 - 2014-06-08 19:31 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-06-08 19:32 - 2014-06-08 19:31 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-06-08 19:32 - 2014-06-08 19:31 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-06-08 19:32 - 2014-06-08 19:31 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Sun 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Oracle 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\Program Files\Java 2014-06-08 19:28 - 2014-06-08 19:27 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\Program Files (x86)\Java 2014-06-08 19:26 - 2014-06-08 22:00 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-08 19:26 - 2014-06-08 19:26 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-08 19:26 - 2014-06-08 19:26 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-08 19:26 - 2014-06-08 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-08 13:22 - 2014-06-08 13:22 - 00000000 ____D () C:\Users\Maag\AppData\Roaming\WinRAR 2014-06-08 12:07 - 2014-06-08 12:07 - 00000000 ____D () C:\Windows\ERUNT 2014-06-08 10:45 - 2014-06-08 10:45 - 00006760 ____N () C:\bootsqm.dat 2014-06-08 09:44 - 2014-06-08 22:18 - 00000000 ____D () C:\Users\Maag\Desktop\Installs 2014-06-07 21:34 - 2014-06-07 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2014-06-07 21:12 - 2014-06-07 21:20 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-07 21:12 - 2014-05-04 17:12 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-07 20:58 - 2014-06-07 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-07 19:53 - 2014-06-07 19:53 - 00000000 ____D () C:\Users\Maag\AppData\Local\WindowsUpdate 2014-06-07 19:42 - 2014-06-07 19:42 - 00000000 ____D () C:\Users\Maag\AppData\Local\Google 2014-06-07 19:34 - 2014-06-08 22:32 - 00000000 ____D () C:\Users\Maag\Desktop\Scanner 2014-06-07 15:14 - 2014-06-08 18:56 - 00000000 ____D () C:\Windows\pss 2014-05-27 17:37 - 2014-05-27 17:38 - 00000109 _____ () C:\ProgramData\RUNDLL32.EXE-2176-F.txt 2014-05-27 17:08 - 2014-05-27 17:08 - 00000170 _____ () C:\ProgramData\RUNDLL32.EXE-2428-F.txt 2014-05-27 17:06 - 2014-05-27 17:06 - 00000054 _____ () C:\ProgramData\RUNDLL32.EXE-2304-F.txt 2014-05-27 16:57 - 2014-05-27 17:02 - 00000741 _____ () C:\ProgramData\RUNDLL32.EXE-2124-F.txt 2014-05-27 16:49 - 2014-05-27 16:55 - 00003500 _____ () C:\ProgramData\RUNDLL32.EXE-2388-F.txt 2014-05-27 16:46 - 2014-05-27 16:47 - 00001176 _____ () C:\ProgramData\RUNDLL32.EXE-2404-F.txt 2014-05-25 08:53 - 2014-05-25 09:41 - 00001948 _____ () C:\ProgramData\RUNDLL32.EXE-2072-F.txt 2014-05-25 08:41 - 2014-06-08 10:29 - 00000000 ____D () C:\ProgramData\31577CDA788B660569CB7D00D219ACB4 2014-05-25 08:41 - 2014-05-25 08:51 - 00001407 _____ () C:\ProgramData\RUNDLL32.EXE-5864-F.txt 2014-05-16 16:49 - 2014-05-16 16:49 - 17352880 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-05-15 16:40 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 16:40 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 16:40 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 16:40 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 16:40 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 16:40 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-15 16:21 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-15 16:21 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-15 16:21 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-15 16:21 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-15 16:21 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-15 16:21 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-15 16:21 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-15 16:21 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-15 16:21 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-15 16:21 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-15 16:21 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-15 16:21 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-15 16:21 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-15 16:21 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-15 16:21 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-15 16:21 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-15 16:21 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-15 16:21 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-15 16:21 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-15 16:21 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll ==================== One Month Modified Files and Folders ======= 2014-06-08 22:32 - 2014-06-08 21:29 - 00000000 ____D () C:\FRST 2014-06-08 22:32 - 2014-06-07 19:34 - 00000000 ____D () C:\Users\Maag\Desktop\Scanner 2014-06-08 22:32 - 2012-09-28 00:00 - 00000000 ____D () C:\Users\Maag\AppData\Local\Temp 2014-06-08 22:18 - 2014-06-08 09:44 - 00000000 ____D () C:\Users\Maag\Desktop\Installs 2014-06-08 22:10 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-08 22:10 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-08 22:00 - 2014-06-08 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-08 21:36 - 2012-05-15 12:58 - 01547613 ____N () C:\Windows\WindowsUpdate.log 2014-06-08 21:08 - 2012-09-28 00:00 - 00000380 _____ () C:\Users\Maag\AppData\Roaming\sp_data.sys 2014-06-08 21:08 - 2012-05-15 13:13 - 00001832 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-06-08 21:08 - 2012-05-15 13:13 - 00001509 _____ () C:\Windows\system32\ServiceFilter.ini 2014-06-08 21:07 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-08 21:05 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-08 20:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-06-08 20:06 - 2012-09-28 17:29 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-08 19:59 - 2012-02-24 04:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-06-08 19:50 - 2009-07-14 04:34 - 00000510 _____ () C:\Windows\win.ini 2014-06-08 19:44 - 2014-06-08 19:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-08 19:31 - 2014-06-08 19:32 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-06-08 19:31 - 2014-06-08 19:32 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-06-08 19:31 - 2014-06-08 19:32 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-06-08 19:31 - 2014-06-08 19:32 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Sun 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Oracle 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\Program Files\Java 2014-06-08 19:27 - 2014-06-08 19:28 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\Program Files (x86)\Java 2014-06-08 19:26 - 2014-06-08 19:26 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-08 19:26 - 2014-06-08 19:26 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-08 19:26 - 2014-06-08 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-08 18:56 - 2014-06-07 15:14 - 00000000 ____D () C:\Windows\pss 2014-06-08 18:52 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther 2014-06-08 18:49 - 2012-02-24 04:28 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-06-08 13:22 - 2014-06-08 13:22 - 00000000 ____D () C:\Users\Maag\AppData\Roaming\WinRAR 2014-06-08 12:07 - 2014-06-08 12:07 - 00000000 ____D () C:\Windows\ERUNT 2014-06-08 12:03 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-08 11:49 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-08 11:15 - 2013-03-24 14:34 - 00000000 ____D () C:\Users\Maag\Desktop\Bilder Manni 2014-06-08 10:47 - 2009-07-14 06:45 - 00413624 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-08 10:45 - 2014-06-08 10:45 - 00006760 ____N () C:\bootsqm.dat 2014-06-08 10:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-06-08 10:29 - 2014-05-25 08:41 - 00000000 ____D () C:\ProgramData\31577CDA788B660569CB7D00D219ACB4 2014-06-08 08:48 - 2012-09-28 00:01 - 00109296 _____ () C:\Users\Maag\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-07 21:34 - 2014-06-07 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2014-06-07 21:26 - 2012-02-24 04:28 - 01594892 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-06-07 21:26 - 2011-02-19 06:24 - 00699666 _____ () C:\Windows\system32\perfh007.dat 2014-06-07 21:26 - 2011-02-19 06:24 - 00149774 _____ () C:\Windows\system32\perfc007.dat 2014-06-07 21:25 - 2009-07-14 07:13 - 01594892 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-07 21:20 - 2014-06-07 21:12 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-07 21:06 - 2012-09-28 17:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2014-06-07 20:58 - 2014-06-07 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-07 19:53 - 2014-06-07 19:53 - 00000000 ____D () C:\Users\Maag\AppData\Local\WindowsUpdate 2014-06-07 19:42 - 2014-06-07 19:42 - 00000000 ____D () C:\Users\Maag\AppData\Local\Google 2014-06-07 15:14 - 2012-09-28 00:03 - 00000000 ___RD () C:\Users\Maag\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-05 16:05 - 2014-04-17 17:32 - 00000000 ____D () C:\ProgramData\2992199F9A 2014-05-27 17:38 - 2014-05-27 17:37 - 00000109 _____ () C:\ProgramData\RUNDLL32.EXE-2176-F.txt 2014-05-27 17:08 - 2014-05-27 17:08 - 00000170 _____ () C:\ProgramData\RUNDLL32.EXE-2428-F.txt 2014-05-27 17:06 - 2014-05-27 17:06 - 00000054 _____ () C:\ProgramData\RUNDLL32.EXE-2304-F.txt 2014-05-27 17:02 - 2014-05-27 16:57 - 00000741 _____ () C:\ProgramData\RUNDLL32.EXE-2124-F.txt 2014-05-27 16:55 - 2014-05-27 16:49 - 00003500 _____ () C:\ProgramData\RUNDLL32.EXE-2388-F.txt 2014-05-27 16:47 - 2014-05-27 16:46 - 00001176 _____ () C:\ProgramData\RUNDLL32.EXE-2404-F.txt 2014-05-25 09:41 - 2014-05-25 08:53 - 00001948 _____ () C:\ProgramData\RUNDLL32.EXE-2072-F.txt 2014-05-25 08:51 - 2014-05-25 08:41 - 00001407 _____ () C:\ProgramData\RUNDLL32.EXE-5864-F.txt 2014-05-16 16:49 - 2014-05-16 16:49 - 17352880 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-05-16 16:45 - 2013-05-14 16:52 - 00000000 ____D () C:\Users\Maag\AppData\Local\PokerStars.EU 2014-05-16 15:55 - 2012-09-28 00:03 - 00000000 ___RD () C:\Users\Maag\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-16 15:51 - 2014-05-07 16:45 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-09 16:40 - 2013-05-14 16:52 - 00000000 ____D () C:\Program Files (x86)\PokerStars.EU 2014-05-09 08:14 - 2014-05-15 16:21 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-15 16:21 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll Files to move or delete: ==================== C:\ProgramData\bn0j4lf9.bxx C:\ProgramData\bn0j4lf9.fvv C:\ProgramData\bn0j4lf9.reg Some content of TEMP: ==================== C:\Users\Maag\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-06-08 13:04 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-06-2014 Ran by Maag at 2014-06-08 22:33:00 Running from C:\Users\Maag\Desktop\Scanner Boot Mode: Normal ========================================================== ==================== Security Center ======================== ==================== Installed Programs ====================== Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated) Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) AMD APP SDK Runtime (Version: 10.0.851.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{4572399F-5B78-3C50-7281-4AB6248FC1F0}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.) AMD Fuel (Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.70321.2226 - Advanced Micro Devices, Inc.) Hidden AMD VISION Engine Control Center (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS) ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.29 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.7 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS) ASUS Sonic Focus (HKLM-x32\...\{B0002707-4F7E-4745-88A7-852DA8A88635}) (Version: - Synopsys ) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0041 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: - eCareme Technologies, Inc.) ASUS_Screensaver (HKLM-x32\...\ASUS_Screensaver) (Version: - ) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0016 - ASUS) Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) Hidden CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.) CyberLink Media Suite (x32 Version: 8.0.2926 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: - CyberLink Corp.) CyberLink Power2Go (x32 Version: - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media) Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media) Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media) ETDWare PS/2-X64 (HKLM\...\Elantech) (Version: - ELAN Microelectronic Corp.) Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.9 - ASUS) Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM-x32\...\Game Park Console) (Version: - Oberon Media Inc.) Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media) Java 7 Update 60 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417060FF}) (Version: 7.0.600 - Oracle) Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle) Java Auto Updater (x32 Version: - Oracle, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden Norman Security Suite (HKLM\...\{79214B92-A439-4841-B160-0896E977A383}) (Version: 8.00.1500 - Norman ASA) Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media) PokerStars.eu (HKLM-x32\...\PokerStars.eu) (Version: - PokerStars.eu) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.42.304.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.) Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2880505) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{2720451F-5D04-43EC-AB1F-26D948FD971B}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_PROPLUS_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_PROPLUS_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_PROPLUS_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS) Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.27 - ASUS) World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {016A077C-48F7-423C-91BE-CC862DEE5232} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-02-16] (ASUSTek Computer Inc.) Task: {23870B20-347D-4946-8106-CE5EDC162C7E} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.) Task: {4B5B400D-CDBC-4F80-8CB7-4F026CE713DB} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS) Task: {DB649E30-42CC-4BA9-8030-898C16FD2316} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-08] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-03-22 07:30 - 2012-03-22 07:30 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2012-10-01 22:31 - 2012-05-10 10:17 - 00793520 _____ () C:\Program Files\Norman\Nvc\bin\nhs.exe 2012-09-28 20:42 - 2012-02-03 10:13 - 00116056 _____ () C:\Program Files\Norman\Npm\Bin\Njeeves.exe 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll 2009-03-02 04:08 - 2009-03-02 04:08 - 00003584 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\\LogicNP.PropSheetExtensionHelper_x64.dll 2012-09-28 20:42 - 2011-02-14 09:35 - 01069048 _____ () C:\Program Files\Norman\Npm\Bin\libxml2.dll 2012-09-28 20:42 - 2009-09-03 12:10 - 00210432 _____ () C:\Program Files\Norman\Npm\Bin\lua.dll 2012-02-21 23:49 - 2012-02-21 23:49 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll 2012-09-28 20:42 - 2010-10-18 11:05 - 10896384 _____ () C:\Program Files\Norman\Npm\Bin\NQtCore4.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AsusVibeLauncher.lnk => C:\Windows\pss\AsusVibeLauncher.lnk.CommonStartup MSCONFIG\startupreg: ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s ==================== Faulty Device Manager Devices ============= Could not list Devices. Check "winmgmt" service or repair WMI. ==================== Event log errors: ========================= Application errors: ================== Error: (06/08/2014 08:02:42 PM) (Source: MsiInstaller) (EventID: 11935) (User: Maag-PC) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C} Error: (06/08/2014 05:40:30 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (06/08/2014 00:39:13 PM) (Source: MsiInstaller) (EventID: 11935) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C} Error: (06/08/2014 11:34:41 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C} Error: (06/08/2014 08:49:55 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C} Error: (06/07/2014 09:31:30 PM) (Source: MsiInstaller) (EventID: 11935) (User: Maag-PC) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C} Error: (05/25/2014 09:42:16 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm rundll32.exe, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 818 Startzeit: 01cf77e5f9d560d9 Endzeit: 16 Anwendungspfad: C:\Windows\SysWOW64\rundll32.exe Berichts-ID: 1184d810-e3e0-11e3-a18e-10bf4856cdf0 Error: (05/24/2014 05:06:30 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80004005 Error: (05/13/2014 04:17:56 PM) (Source: Nvcoas) (EventID: 1) (User: ) Description: Norman Virus Control error: Error creating pipe: 130007 Error: (05/10/2014 04:22:07 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm PokerStars.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2574 Startzeit: 01cf6c5b007293e3 Endzeit: 16 Anwendungspfad: C:\Program Files (x86)\PokerStars.EU\PokerStars.exe Berichts-ID: 716d3cc3-d84e-11e3-aa92-10bf4856cdf0 System errors: ============= Error: (06/08/2014 10:35:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:34:32 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:34:00 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:33:30 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:33:00 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:10:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:06:20 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:04:55 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:04:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/08/2014 10:03:18 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 43% Total physical RAM: 4075.7 MB Available physical RAM: 2285.17 MB Total Pagefile: 8149.59 MB Available Pagefile: 6374.09 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:200.28 GB) (Free:146.48 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:240.48 GB) (Free:239.37 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 125FC5E1) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=200 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=240 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Soweit läuft der Laptop wieder ... nur dieser Dienst ist momentan offensichtlich noch problematisch. Zumindest soweit ich das überblicken kann. Würde mich freuen, wenn sich das einer von euch ansehen könnte, da ich alleine hier nicht mehr weiterkomme. Wünsche euch ein schönes Wochenende! Viele Grüße Jonas |
Mein Name ist Sandra und ich werde Dir bei Deinem Problem behilflich sein.

Schritt 1: Bitte lade dir FRST herunter und führe einen Scan durch.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und bei einem Befall durch Malware immer der sicherste Weg. Adware lässt sich in den allermeisten Fällen problemlos entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Dir jemand vom Team sagt, dass Du clean bist. Posten in Code Tags Bitte füge die Logs immer in Code-Tags ein. Wenn Du das nicht machst, erschwert es mir sehr das Auswerten. Danke. Dazu:
Schritt 1 Downloade dir bitte ![]()
Poste bitte den Inhalt hier.
Guten Morgen Sandra, vielen Dank, dass du mir helfen möchtest! Ich habe den Scan laufen lassen.
__________________vielen Dank, dass du mir helfen möchtest! Ich habe den Scan laufen lassen. Hier das Ergebnis: Code:
ATTFilter Farbar Service Scanner Version: 21-05-2014 Ran by Maag (administrator) on 09-06-2014 at 09:28:16 Running from "C:\Users\Maag\Desktop\Scanner" Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. winmgmt Service is not running. Checking service configuration: The start type of winmgmt service is OK. The ImagePath of winmgmt: "%systemroot%\system32\svchost.exe -k netsvcs". Unable to retrieve ServiceDll of winmgmt. The value does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** Ich habe ja gestern Updates installieren lassen durch Windows. Nun kam beim Starten die Meldung, dass ein Fehler dabei passiert ist und die Updates wieder deinstalliert werden. Hat ca. eine halbe Stunde gedauert, bis der Laptop hochgefahren war. Diese Fehlermeldungen gibt das Systemprotokoll aus: - Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0826 fehlgeschlagen: Update für Windows 7 für x64-Systeme (KB2592687) - Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80080005 fehlgeschlagen: Update für Windows 7 für x64-basierte Systeme (KB2830477) - Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0826 fehlgeschlagen: Update für Windows 7 für x64-Systeme (KB2709981) Ich weiß nicht, ob das damit zu tun hat, aber ich wollte es dir nicht vorenthalten. ![]() Wünsche dir noch einen schönen Tag! LG Jonas |
Hallo jonnywalker

Schritt 1: Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere folgenden Text in das Textdokument und speichere als Fixlist.txt. Starte FRST und drücke Fix.
ATTFilter C:\ProgramData\31577CDA788B660569CB7D00D219ACB4 C:\ProgramData\bn0j4lf9.bxx C:\ProgramData\bn0j4lf9.fvv C:\ProgramData\bn0j4lf9.reg C:\Windows\win.ini cmd: type C:\ProgramData\RUNDLL32.EXE-2428-F.txt cmd: type C:\ProgramData\RUNDLL32.EXE-2404-F.txt Reg: reg add "hklm\System\CurrentControlSet\services\winmgmt\parameters\" /v Servicedll /t REG_EXPAND_SZ /d ^%Systemroot^%\system32\wbem\WMIsvc.dll /f reboot: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Mache nochmal einen neuen Scan mit Farbars Service Scanner, du brauchst ihn dir nicht nochmals downloaden. Downloade dir bitte ![]()
![]() | #5 |
![]() | ![]() Windows 7: "Windows-Verwaltungsinstrumentation"-Dienst startet nicht nach Trojanerbefall Hallo, ich habe beides gemacht. Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-06-2014 Ran by Maag at 2014-06-09 22:49:09 Run:1 Running from C:\Users\Maag\Desktop\Scanner\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\ProgramData\31577CDA788B660569CB7D00D219ACB4 C:\ProgramData\bn0j4lf9.bxx C:\ProgramData\bn0j4lf9.fvv C:\ProgramData\bn0j4lf9.reg C:\Windows\win.ini cmd: type C:\ProgramData\RUNDLL32.EXE-2428-F.txt cmd: type C:\ProgramData\RUNDLL32.EXE-2404-F.txt Reg: reg add "hklm\System\CurrentControlSet\services\winmgmt\parameters\" /v Servicedll t/ REG_EXPAND_SZ / d ^%Systemroot^%\system32\wbem\WMIsvc.dll reboot: ***************** C:\ProgramData\31577CDA788B660569CB7D00D219ACB4 => Moved successfully. C:\ProgramData\bn0j4lf9.bxx => Moved successfully. C:\ProgramData\bn0j4lf9.fvv => Moved successfully. C:\ProgramData\bn0j4lf9.reg => Moved successfully. C:\Windows\win.ini => Moved successfully. ========= type C:\ProgramData\RUNDLL32.EXE-2428-F.txt ========= 27.05.2014 17:08:01 | THread Start IP: 27.05.2014 17:08:27 | THread Start IP: 27.05.2014 17:08:53 | THread Start IP: ========= End of CMD: ========= ========= type C:\ProgramData\RUNDLL32.EXE-2404-F.txt ========= 27.05.2014 16:46:06 | THread Start IP: 27.05.2014 16:46:10 | Revice His OK 27.05.2014 16:46:10 | Connect OK - 6D6C93A1F8A69C29F9AC02B8FB4B9788 Germany Nortel Networks 27.05.2014 16:46:14 | Write OK - 27.05.2014 16:46:32 | THread Start IP: 27.05.2014 16:46:38 | Revice His OK 27.05.2014 16:46:38 | Connect OK - 6D6C93A1F8A69C29F9AC02B8FB4B9788 Germany Nortel Networks 27.05.2014 16:46:41 | Write OK - 27.05.2014 16:46:57 | THread Start IP: 27.05.2014 16:47:01 | Revice His OK 27.05.2014 16:47:01 | Connect OK - 6D6C93A1F8A69C29F9AC02B8FB4B9788 Germany Nortel Networks 27.05.2014 16:47:06 | Write OK - 27.05.2014 16:47:23 | THread Start IP: 27.05.2014 16:47:27 | Revice His OK 27.05.2014 16:47:27 | Connect OK - 6D6C93A1F8A69C29F9AC02B8FB4B9788 Germany Nortel Networks 27.05.2014 16:47:31 | Write OK - 27.05.2014 16:47:49 | THread Start IP: 27.05.2014 16:47:53 | Revice His OK 27.05.2014 16:47:53 | Connect OK - 6D6C93A1F8A69C29F9AC02B8FB4B9788 Germany Nortel Networks 27.05.2014 16:47:57 | Write OK - ========= End of CMD: ========= ========= reg add "hklm\System\CurrentControlSet\services\winmgmt\parameters\" /v Servicedll t/ REG_EXPAND_SZ / d ^%Systemroot^%\system32\wbem\WMIsvc.dll ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ==== Und hier der FSS-Log Code:
ATTFilter Farbar Service Scanner Version: 21-05-2014 Ran by Maag (administrator) on 09-06-2014 at 22:56:54 Running from "C:\Users\Maag\Desktop\Scanner" Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. winmgmt Service is not running. Checking service configuration: The start type of winmgmt service is OK. The ImagePath of winmgmt: "%systemroot%\system32\svchost.exe -k netsvcs". Unable to retrieve ServiceDll of winmgmt. The value does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** |
Hallo Jonas, da haben sich unsere Tätigkeiten überschnitten. Müssen wir nochmal wiederholen.

Schritt 1: Erstelle eine neue Fixlist.txt mit folgendem Inhalt und führe den Fix durch.
Schritt 2: Mache nochmals einen neuen Scan mit Farbars Service Scanner.
ATTFilter 2014-05-27 17:37 - 2014-05-27 17:38 - 00000109 _____ () C:\ProgramData\RUNDLL32.EXE-2176-F.txt 2014-05-27 17:08 - 2014-05-27 17:08 - 00000170 _____ () C:\ProgramData\RUNDLL32.EXE-2428-F.txt 2014-05-27 17:06 - 2014-05-27 17:06 - 00000054 _____ () C:\ProgramData\RUNDLL32.EXE-2304-F.txt 2014-05-27 16:57 - 2014-05-27 17:02 - 00000741 _____ () C:\ProgramData\RUNDLL32.EXE-2124-F.txt 2014-05-27 16:49 - 2014-05-27 16:55 - 00003500 _____ () C:\ProgramData\RUNDLL32.EXE-2388-F.txt 2014-05-27 16:46 - 2014-05-27 16:47 - 00001176 _____ () C:\ProgramData\RUNDLL32.EXE-2404-F.txt 2014-05-25 08:53 - 2014-05-25 09:41 - 00001948 _____ () C:\ProgramData\RUNDLL32.EXE-2072-F.txt 2014-05-25 08:41 - 2014-06-08 10:29 - 00000000 ____D () C:\ProgramData\31577CDA788B660569CB7D00D219ACB4 2014-05-25 08:41 - 2014-05-25 08:51 - 00001407 _____ () C:\ProgramData\RUNDLL32.EXE-5864-F.txt 2014-05-27 17:38 - 2014-05-27 17:37 - 00000109 _____ () C:\ProgramData\RUNDLL32.EXE-2176-F.txt 2014-05-27 17:08 - 2014-05-27 17:08 - 00000170 _____ () C:\ProgramData\RUNDLL32.EXE-2428-F.txt 2014-05-27 17:06 - 2014-05-27 17:06 - 00000054 _____ () C:\ProgramData\RUNDLL32.EXE-2304-F.txt 2014-05-27 17:02 - 2014-05-27 16:57 - 00000741 _____ () C:\ProgramData\RUNDLL32.EXE-2124-F.txt 2014-05-27 16:55 - 2014-05-27 16:49 - 00003500 _____ () C:\ProgramData\RUNDLL32.EXE-2388-F.txt 2014-05-27 16:47 - 2014-05-27 16:46 - 00001176 _____ () C:\ProgramData\RUNDLL32.EXE-2404-F.txt 2014-05-25 09:41 - 2014-05-25 08:53 - 00001948 _____ () C:\ProgramData\RUNDLL32.EXE-2072-F.txt 2014-05-25 08:51 - 2014-05-25 08:41 - 00001407 _____ () C:\ProgramData\RUNDLL32.EXE-5864-F.txt Reg: reg add "hklm\System\CurrentControlSet\services\winmgmt\parameters" /v Servicedll /t REG_EXPAND_SZ /d ^%Systemroot^%\system32\wbem\WMIsvc.dll /f Reg: reg query "hklm\System\CurrentControlSet\services\winmgmt\parameters" reboot: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Bitte nochmals einen Scan mit Farbas Service Scanner ![]()
__________________ --> Windows 7: "Windows-Verwaltungsinstrumentation"-Dienst startet nicht nach Trojanerbefall |
![]() | ![]() Windows 7: "Windows-Verwaltungsinstrumentation"-Dienst startet nicht nach Trojanerbefall So ... ein zweites Mal ![]() Zunächst der Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-06-2014 Ran by Maag at 2014-06-09 23:16:42 Run:2 Running from C:\Users\Maag\Desktop\Scanner\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** 2014-05-27 17:37 - 2014-05-27 17:38 - 00000109 _____ () C:\ProgramData\RUNDLL32.EXE-2176-F.txt 2014-05-27 17:08 - 2014-05-27 17:08 - 00000170 _____ () C:\ProgramData\RUNDLL32.EXE-2428-F.txt 2014-05-27 17:06 - 2014-05-27 17:06 - 00000054 _____ () C:\ProgramData\RUNDLL32.EXE-2304-F.txt 2014-05-27 16:57 - 2014-05-27 17:02 - 00000741 _____ () C:\ProgramData\RUNDLL32.EXE-2124-F.txt 2014-05-27 16:49 - 2014-05-27 16:55 - 00003500 _____ () C:\ProgramData\RUNDLL32.EXE-2388-F.txt 2014-05-27 16:46 - 2014-05-27 16:47 - 00001176 _____ () C:\ProgramData\RUNDLL32.EXE-2404-F.txt 2014-05-25 08:53 - 2014-05-25 09:41 - 00001948 _____ () C:\ProgramData\RUNDLL32.EXE-2072-F.txt 2014-05-25 08:41 - 2014-06-08 10:29 - 00000000 ____D () C:\ProgramData\31577CDA788B660569CB7D00D219ACB4 2014-05-25 08:41 - 2014-05-25 08:51 - 00001407 _____ () C:\ProgramData\RUNDLL32.EXE-5864-F.txt 2014-05-27 17:38 - 2014-05-27 17:37 - 00000109 _____ () C:\ProgramData\RUNDLL32.EXE-2176-F.txt 2014-05-27 17:08 - 2014-05-27 17:08 - 00000170 _____ () C:\ProgramData\RUNDLL32.EXE-2428-F.txt 2014-05-27 17:06 - 2014-05-27 17:06 - 00000054 _____ () C:\ProgramData\RUNDLL32.EXE-2304-F.txt 2014-05-27 17:02 - 2014-05-27 16:57 - 00000741 _____ () C:\ProgramData\RUNDLL32.EXE-2124-F.txt 2014-05-27 16:55 - 2014-05-27 16:49 - 00003500 _____ () C:\ProgramData\RUNDLL32.EXE-2388-F.txt 2014-05-27 16:47 - 2014-05-27 16:46 - 00001176 _____ () C:\ProgramData\RUNDLL32.EXE-2404-F.txt 2014-05-25 09:41 - 2014-05-25 08:53 - 00001948 _____ () C:\ProgramData\RUNDLL32.EXE-2072-F.txt 2014-05-25 08:51 - 2014-05-25 08:41 - 00001407 _____ () C:\ProgramData\RUNDLL32.EXE-5864-F.txt Reg: reg add "hklm\System\CurrentControlSet\services\winmgmt\parameters" /v Servicedll /t REG_EXPAND_SZ /d ^%Systemroot^%\system32\wbem\WMIsvc.dll /f Reg: reg query "hklm\System\CurrentControlSet\services\winmgmt\parameters" reboot: ***************** C:\ProgramData\RUNDLL32.EXE-2176-F.txt => Moved successfully. C:\ProgramData\RUNDLL32.EXE-2428-F.txt => Moved successfully. C:\ProgramData\RUNDLL32.EXE-2304-F.txt => Moved successfully. C:\ProgramData\RUNDLL32.EXE-2124-F.txt => Moved successfully. C:\ProgramData\RUNDLL32.EXE-2388-F.txt => Moved successfully. C:\ProgramData\RUNDLL32.EXE-2404-F.txt => Moved successfully. C:\ProgramData\RUNDLL32.EXE-2072-F.txt => Moved successfully. "C:\ProgramData\31577CDA788B660569CB7D00D219ACB4" => File/Directory not found. C:\ProgramData\RUNDLL32.EXE-5864-F.txt => Moved successfully. "C:\ProgramData\RUNDLL32.EXE-2176-F.txt" => File/Directory not found. "C:\ProgramData\RUNDLL32.EXE-2428-F.txt" => File/Directory not found. "C:\ProgramData\RUNDLL32.EXE-2304-F.txt" => File/Directory not found. "C:\ProgramData\RUNDLL32.EXE-2124-F.txt" => File/Directory not found. "C:\ProgramData\RUNDLL32.EXE-2388-F.txt" => File/Directory not found. "C:\ProgramData\RUNDLL32.EXE-2404-F.txt" => File/Directory not found. "C:\ProgramData\RUNDLL32.EXE-2072-F.txt" => File/Directory not found. "C:\ProgramData\RUNDLL32.EXE-5864-F.txt" => File/Directory not found. ========= reg add "hklm\System\CurrentControlSet\services\winmgmt\parameters" /v Servicedll /t REG_EXPAND_SZ /d ^%Systemroot^%\system32\wbem\WMIsvc.dll /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg query "hklm\System\CurrentControlSet\services\winmgmt\parameters" ========= HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\winmgmt\parameters ServiceDllUnloadOnStop REG_DWORD 0x0 ServiceMain REG_SZ ServiceMain Servicedll REG_EXPAND_SZ %Systemroot%\system32\wbem\WMIsvc.dll ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ==== Und hier der FSS-Log: Code:
ATTFilter Farbar Service Scanner Version: 21-05-2014 Ran by Maag (administrator) on 09-06-2014 at 23:20:45 Running from "C:\Users\Maag\Desktop\Scanner" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Attempt to access Google.com returned error: Google.com is unreachable Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** ![]() |
Hallo Jonas, Ok, das sieht sehr viel besser aus. Funktioniert nun das Windows Sicherheitscenter auch wieder?

Schritt 1: Erstelle Fixlist.txt und führe Fix durch
Schritt 2: Downloade Malwarebytes Anti-Malware und führe einen vollständigen Scan durch
Schritt 3: Führe ESET Online Scanner durch (kann mehrere Stunden dauern)
Schritt 4: Starte FRST erneut
ATTFilter C:\ProgramData\2992199F9A Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Da der Scan mit Eset sehr gründlich ist, kann er unter Umständen mehrere Stunden dauern ![]() ESET Online Scanner
Schritt 4 Starte noch einmal FRST.
Hallo Sandra, die Schritte werde ich morgen durchführen. Zum Virenprogramm: Derzeit ist nur eine abgelaufene Version von Norman installiert. Wann soll ich GData Internet Security aufspielen? Nach den Schritten oder schon jetzt?
![]() | #10 |
Hallo Jonas, mach da bitte nach dem ESET-Scan ein Antivirenprogramm drauf und surf damit nicht rum.
Guten Morgen, hier schonmal der Fixlog. Jetzt läuft der Rechner die Scans durch.
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-06-2014 Ran by Maag at 2014-06-10 08:34:40 Run:3 Running from C:\Users\Maag\Desktop\Scanner\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\ProgramData\2992199F9A ***************** C:\ProgramData\2992199F9A => Moved successfully. ==== End of Fixlog ==== Jetzt läuft der Rechner die Scans durch. Melde mich später dann. LG Jonas Hier nun der Log von MBAM Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 10.06.2014 Suchlauf-Zeit: 08:41:35 Logdatei: Administrator: Ja Version: Malware Datenbank: v2014.06.09.01 Rootkit Datenbank: v2014.06.02.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Maag Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 265754 Verstrichene Zeit: 15 Min, 19 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK ![]() Und dann hier noch die beiden FRST-Logs FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 Ran by Maag (administrator) on MAAG-PC on 10-06-2014 11:29:32 Running from C:\Users\Maag\Desktop\Scanner\FRST Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AMD) C:\Windows\System32\atieclxx.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-10-14] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\\AsusWSPanel.exe [737104 2011-07-29] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322176 2012-02-16] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-03] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4F77BC0F8182CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @java.com/DTPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-03-22] (Advanced Micro Devices, Inc.) [File not signed] S2 NNFSVC; "C:\Program Files\Norman\Ngs\Bin\Nnf.exe" [X] ==================== Drivers (Whitelisted) ==================== S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S0 flgloqgy; System32\drivers\gvwxbhl.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-10 08:39 - 2014-06-10 08:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-10 08:39 - 2014-06-10 08:39 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-10 08:39 - 2014-06-10 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-10 08:39 - 2014-06-10 08:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-10 08:39 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-10 08:39 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-10 08:39 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-09 08:23 - 2014-06-10 11:24 - 00004826 _____ () C:\Windows\PFRO.log 2014-06-09 08:23 - 2014-06-10 11:24 - 00000616 _____ () C:\Windows\setupact.log 2014-06-09 08:23 - 2014-06-09 08:23 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-08 21:29 - 2014-06-10 11:29 - 00000000 ____D () C:\FRST 2014-06-08 19:44 - 2014-06-08 19:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-08 19:32 - 2014-06-08 19:31 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-06-08 19:32 - 2014-06-08 19:31 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-06-08 19:32 - 2014-06-08 19:31 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-06-08 19:32 - 2014-06-08 19:31 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Sun 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Oracle 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\Program Files\Java 2014-06-08 19:28 - 2014-06-08 19:27 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\Program Files (x86)\Java 2014-06-08 19:26 - 2014-06-10 11:00 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-08 19:26 - 2014-06-08 19:26 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-08 19:26 - 2014-06-08 19:26 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-08 19:26 - 2014-06-08 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-08 13:22 - 2014-06-08 13:22 - 00000000 ____D () C:\Users\Maag\AppData\Roaming\WinRAR 2014-06-08 12:07 - 2014-06-08 12:07 - 00000000 ____D () C:\Windows\ERUNT 2014-06-08 10:45 - 2014-06-08 10:45 - 00006760 ____N () C:\bootsqm.dat 2014-06-08 09:44 - 2014-06-08 22:18 - 00000000 ____D () C:\Users\Maag\Desktop\Installs 2014-06-07 21:34 - 2014-06-07 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2014-06-07 21:12 - 2014-06-07 21:20 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-07 21:12 - 2014-05-04 17:12 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-07 20:58 - 2014-06-07 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-07 19:53 - 2014-06-07 19:53 - 00000000 ____D () C:\Users\Maag\AppData\Local\WindowsUpdate 2014-06-07 19:42 - 2014-06-07 19:42 - 00000000 ____D () C:\Users\Maag\AppData\Local\Google 2014-06-07 19:34 - 2014-06-10 11:26 - 00000000 ____D () C:\Users\Maag\Desktop\Scanner 2014-06-07 15:14 - 2014-06-08 18:56 - 00000000 ____D () C:\Windows\pss 2014-05-16 16:49 - 2014-05-16 16:49 - 17352880 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-05-15 16:40 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 16:40 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 16:40 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 16:40 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 16:40 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 16:40 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-15 16:21 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-15 16:21 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-15 16:21 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-15 16:21 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-15 16:21 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-15 16:21 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-15 16:21 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-15 16:21 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-15 16:21 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-15 16:21 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-15 16:21 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-15 16:21 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-15 16:21 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-15 16:21 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-15 16:21 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-15 16:21 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-15 16:21 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-15 16:21 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-15 16:21 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-15 16:21 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-15 16:21 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-15 16:21 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-15 16:21 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll ==================== One Month Modified Files and Folders ======= 2014-06-10 11:30 - 2012-09-28 00:00 - 00000000 ____D () C:\Users\Maag\AppData\Local\Temp 2014-06-10 11:29 - 2014-06-08 21:29 - 00000000 ____D () C:\FRST 2014-06-10 11:29 - 2012-05-15 12:58 - 01672773 _____ () C:\Windows\WindowsUpdate.log 2014-06-10 11:26 - 2014-06-07 19:34 - 00000000 ____D () C:\Users\Maag\Desktop\Scanner 2014-06-10 11:25 - 2012-09-28 00:00 - 00000380 _____ () C:\Users\Maag\AppData\Roaming\sp_data.sys 2014-06-10 11:24 - 2014-06-09 08:23 - 00004826 _____ () C:\Windows\PFRO.log 2014-06-10 11:24 - 2014-06-09 08:23 - 00000616 _____ () C:\Windows\setupact.log 2014-06-10 11:24 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-10 11:22 - 2012-09-28 17:40 - 00000000 ____D () C:\Program Files\Norman 2014-06-10 11:00 - 2014-06-08 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-10 09:09 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-10 09:09 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-10 09:06 - 2011-02-19 06:24 - 00699666 _____ () C:\Windows\system32\perfh007.dat 2014-06-10 09:06 - 2011-02-19 06:24 - 00149774 _____ () C:\Windows\system32\perfc007.dat 2014-06-10 09:06 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-10 08:39 - 2014-06-10 08:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-10 08:39 - 2014-06-10 08:39 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-10 08:39 - 2014-06-10 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-10 08:39 - 2014-06-10 08:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-09 08:45 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-09 08:23 - 2014-06-09 08:23 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-08 23:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-06-08 22:18 - 2014-06-08 09:44 - 00000000 ____D () C:\Users\Maag\Desktop\Installs 2014-06-08 21:08 - 2012-05-15 13:13 - 00001832 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-06-08 21:08 - 2012-05-15 13:13 - 00001509 _____ () C:\Windows\system32\ServiceFilter.ini 2014-06-08 20:06 - 2012-09-28 17:29 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-08 19:59 - 2012-02-24 04:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-06-08 19:44 - 2014-06-08 19:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-08 19:31 - 2014-06-08 19:32 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-06-08 19:31 - 2014-06-08 19:32 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-06-08 19:31 - 2014-06-08 19:32 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-06-08 19:31 - 2014-06-08 19:32 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Sun 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\ProgramData\Oracle 2014-06-08 19:31 - 2014-06-08 19:31 - 00000000 ____D () C:\Program Files\Java 2014-06-08 19:27 - 2014-06-08 19:28 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-06-08 19:27 - 2014-06-08 19:27 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-06-08 19:27 - 2014-06-08 19:27 - 00000000 ____D () C:\Program Files (x86)\Java 2014-06-08 19:26 - 2014-06-08 19:26 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-08 19:26 - 2014-06-08 19:26 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-08 19:26 - 2014-06-08 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-08 18:56 - 2014-06-07 15:14 - 00000000 ____D () C:\Windows\pss 2014-06-08 18:52 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther 2014-06-08 18:49 - 2012-02-24 04:28 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-06-08 13:22 - 2014-06-08 13:22 - 00000000 ____D () C:\Users\Maag\AppData\Roaming\WinRAR 2014-06-08 12:07 - 2014-06-08 12:07 - 00000000 ____D () C:\Windows\ERUNT 2014-06-08 12:03 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-08 11:49 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-08 11:15 - 2013-03-24 14:34 - 00000000 ____D () C:\Users\Maag\Desktop\Bilder Manni 2014-06-08 10:47 - 2009-07-14 06:45 - 00413624 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-08 10:45 - 2014-06-08 10:45 - 00006760 ____N () C:\bootsqm.dat 2014-06-08 10:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-06-08 08:48 - 2012-09-28 00:01 - 00109296 _____ () C:\Users\Maag\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-07 21:34 - 2014-06-07 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2014-06-07 21:26 - 2012-02-24 04:28 - 01594892 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-06-07 21:20 - 2014-06-07 21:12 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-07 21:06 - 2012-09-28 17:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2014-06-07 20:58 - 2014-06-07 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-07 20:54 - 2014-06-07 20:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-06-07 19:53 - 2014-06-07 19:53 - 00000000 ____D () C:\Users\Maag\AppData\Local\WindowsUpdate 2014-06-07 19:42 - 2014-06-07 19:42 - 00000000 ____D () C:\Users\Maag\AppData\Local\Google 2014-06-07 15:14 - 2012-09-28 00:03 - 00000000 ___RD () C:\Users\Maag\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-16 16:49 - 2014-05-16 16:49 - 17352880 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-05-16 16:45 - 2013-05-14 16:52 - 00000000 ____D () C:\Users\Maag\AppData\Local\PokerStars.EU 2014-05-16 15:55 - 2012-09-28 00:03 - 00000000 ___RD () C:\Users\Maag\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-16 15:51 - 2014-05-07 16:45 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-12 07:26 - 2014-06-10 08:39 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-10 08:39 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-10 08:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys Some content of TEMP: ==================== C:\Users\Maag\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-08 13:04 ==================== End Of Log ============================ --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-06-2014 Ran by Maag at 2014-06-10 11:31:55 Running from C:\Users\Maag\Desktop\Scanner\FRST Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated) Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) AMD APP SDK Runtime (Version: 10.0.851.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{4572399F-5B78-3C50-7281-4AB6248FC1F0}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.) AMD Fuel (Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.70321.2226 - Advanced Micro Devices, Inc.) Hidden AMD VISION Engine Control Center (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS) ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.29 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.7 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS) ASUS Sonic Focus (HKLM-x32\...\{B0002707-4F7E-4745-88A7-852DA8A88635}) (Version: - Synopsys ) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0041 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: - eCareme Technologies, Inc.) ASUS_Screensaver (HKLM-x32\...\ASUS_Screensaver) (Version: - ) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0016 - ASUS) Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0321.2214.37961 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0321.2215.37961 - Advanced Micro Devices, Inc.) Hidden Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) Hidden CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.) CyberLink Media Suite (x32 Version: 8.0.2926 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: - CyberLink Corp.) CyberLink Power2Go (x32 Version: - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media) Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media) Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media) ETDWare PS/2-X64 (HKLM\...\Elantech) (Version: - ELAN Microelectronic Corp.) Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.9 - ASUS) Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM-x32\...\Game Park Console) (Version: - Oberon Media Inc.) Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media) Java 7 Update 60 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417060FF}) (Version: 7.0.600 - Oracle) Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle) Java Auto Updater (x32 Version: - Oracle, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media) Malwarebytes Anti-Malware Version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media) PokerStars.eu (HKLM-x32\...\PokerStars.eu) (Version: - PokerStars.eu) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.42.304.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.) Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2880505) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{2720451F-5D04-43EC-AB1F-26D948FD971B}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_PROPLUS_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_PROPLUS_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_PROPLUS_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS) Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.27 - ASUS) World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 08-06-2014 10:36:25 Windows Update 08-06-2014 17:27:06 Installed Java 7 Update 60 08-06-2014 17:31:28 Installed Java 7 Update 60 (64-bit) 08-06-2014 17:45:13 Windows Update 08-06-2014 19:21:56 Windows Update 08-06-2014 21:03:42 Windows Update 09-06-2014 07:45:47 Windows Update 09-06-2014 21:28:03 Windows Update 10-06-2014 08:37:31 Removed Norman Security Suite. ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {016A077C-48F7-423C-91BE-CC862DEE5232} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-02-16] (ASUSTek Computer Inc.) Task: {23870B20-347D-4946-8106-CE5EDC162C7E} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.) Task: {4B5B400D-CDBC-4F80-8CB7-4F026CE713DB} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS) Task: {DB649E30-42CC-4BA9-8030-898C16FD2316} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-08] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-03-22 07:30 - 2012-03-22 07:30 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll 2012-02-21 23:49 - 2012-02-21 23:49 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AsusVibeLauncher.lnk => C:\Windows\pss\AsusVibeLauncher.lnk.CommonStartup MSCONFIG\startupreg: ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/10/2014 11:18:01 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\AR-SA\MSFEEDS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\RU-RU\MSFEEDSBS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\HE-IL\MSFEEDSBS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\EL-GR\MSFEEDSBS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\EL-GR\MSFEEDS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\ZH-TW\MSFEEDS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\ZH-TW\MSFEEDSBS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\PT-PT\MSFEEDSBS.MFL Error: (06/09/2014 11:20:18 PM) (Source: WinMgmt) (EventID: 4) (User: ) Description: 0x80041002C:\WINDOWS\SYSTEM32\WBEM\PT-PT\MSFEEDS.MFL System errors: ============= Error: (06/10/2014 11:25:16 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: flgloqgy Error: (06/10/2014 11:24:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Norman Network Filtering service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/10/2014 09:02:23 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: flgloqgy Error: (06/10/2014 08:15:59 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: flgloqgy Error: (06/09/2014 11:18:02 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: flgloqgy Error: (06/09/2014 11:16:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/09/2014 11:16:12 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/09/2014 11:15:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/09/2014 11:15:12 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Error: (06/09/2014 11:14:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%2 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 4075.7 MB Available physical RAM: 2257.81 MB Total Pagefile: 8149.59 MB Available Pagefile: 6263.39 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:200.28 GB) (Free:145.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:240.48 GB) (Free:239.37 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 125FC5E1) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=200 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=240 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Beim Durchsehen ist mir aufgefallen, dass der gemeldete Systemfehler (Boot und Systemstarttreiber) auch heute wieder gemeldet wurde in den Systemprotokollen. Der wurde in dem Log aber für heute nicht mehr aufgeführt. Ich installiere dann jetzt GData Internet Security und warte auf Antwort von dir. LG Jonas |
Ruhe in Frieden † 2019 ![]() ![]() ![]() ![]() ![]() | ![]() Windows 7: "Windows-Verwaltungsinstrumentation"-Dienst startet nicht nach Trojanerbefall Hallo Jonas, ja da sitzt auch noch ein Überbleibsel Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter S0 flgloqgy; System32\drivers\gvwxbhl.sys C:\System32\drivers\gvwxbhl.sys C:\Users\Maag\AppData\Local\Temp\Quarantine.exe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Ist es hiernach weg? Ansonsten sieht das soweit gut aus. OK So wie ich es sehe, haben wir damit alles Schadhafte entfernt. Deine Logs sind sauber. Abschließend räumen wir noch etwas auf, führen Updates durch und dann bekommst du noch etwas Lesestoff von mir. Schritt 1 Falls Du Malwarebytes-Antimalware und den ESET-Onlinescan nicht mehr benötigst, kannst Du beide Programme einfach über die Programmdeinstallation deinstallieren. Ich empfehle Dir aber zumindest Malwarebytes zu behalten, und damit einmal die Woche einen Kontrollscan zu machen. Schritt 2 Downloade dir bitte delfix auf deinen Desktop.
Updates / Programme aktualisieren
Deinstalliere Deinen Reader und lade Dir die neueste Version von hier herunter. Schaue, ob sich noch etwas mit installieren möchte und entferne den Haken gegebenenfalls. Nun zum Schluss noch ein paar Tipps zur Absicherung deines Systems. Aktualität des Systems Es ist extrem wichtig, dass sowohl dein System als auch die darauf installierte sicherheitsrelevante Software (Flash Player, PDF-Reader und besonders Java, sofern vorhanden) aktuell sind.
Sofern du Java nicht zwingend benötigst, solltest du es komplett deinstallieren. Windows XP Gehe auf: Start --> Systemsteuerung --> Software --> Javaversionen auswählen --> entfernen Windows Vista Gehe auf: Start --> Systemsteuerung -- > Programme --> Programme deinstallieren --> Javaversionen suchen --> entfernen Windows 7 Dazu gehe auf: den Windowsbutton in der Taskleiste --> Systemsteuerung --> Programme (Unterpunkt Programme deinstallieren) --> Programm auswählen --> entfernen Windows 8 Dazu drücke auf: Windowstaste und X dann: Programme und Funktionen -->Javaversionen auswählen --> entfernen Falls du Java doch unbedingt benötigst, dann
Hier findest du eine Anleitung dazu. Antivirensoftware
Zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der Internet Explorer, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Systemleistung Lösche regelmäßig deine temporären Dateien. Ich empfehle hierzu die Datenträgerbereinigung von Windows. Windows Vista
Windows 7
Windows 8
Halte dich fern von jeglichen Registry Cleanern. Diese schaden deinem System mehr als dass sie es schneller machen. Verhaltensregeln zum sichereren Surfen
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen. Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind. Falls Du Lob oder Kritik abgeben möchtest, kannst Du das sehr gerne hier tun. Wenn Du etwas für das Forum und unsere Arbeit spenden möchtest, so kannst Du das hier tun. |
Hallo Sandra, vielen Dank für deine Hilfe. Ich habe die Fixes durchführen lassen.

Mir ist noch eine Sache aufgefallen: Im Taskmanager ist ein Prozess "TrustedInstaller", der immer mal wieder für hohe CPU-Auslastung sorgt.
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-06-2014 01 Ran by Maag at 2014-06-12 19:17:17 Run:4 Running from C:\Users\Maag\Desktop\Scanner\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** S0 flgloqgy; System32\drivers\gvwxbhl.sys C:\System32\drivers\gvwxbhl.sys C:\Users\Maag\AppData\Local\Temp\Quarantine.exe ***************** flgloqgy => Service deleted successfully. "C:\System32\drivers\gvwxbhl.sys" => File/Directory not found. C:\Users\Maag\AppData\Local\Temp\Quarantine.exe => Moved successfully. ==== End of Fixlog ==== Mir ist noch eine Sache aufgefallen, zu der ich gerne noch deine Meinung/Einschätzung hätte. 1. Im Taskmanager ist ein Prozess "TrustedInstaller", der immer mal wieder für hohe CPU-Auslastung sorgt und das System ziemlich verlangsamt. Zeitweise wird er dort aber auch nicht aufgeführt. Im Anwendungsprotokoll findet sich zwei Meldungen zu diesem Prozess mit folgendem Inhalt: Code:
ATTFilter Protokollname: Application Quelle: Microsoft-Windows-Winlogon Datum: 12.06.2014 21:15:22 Ereignis-ID: 6006 Aufgabenkategorie:Keine Ebene: Warnung Schlüsselwörter:Klassisch Benutzer: Nicht zutreffend Computer: Maag-PC Beschreibung: Der Anmeldebenachrichtigungsabonnent <TrustedInstaller> hat 347 Sekunden benötigt, um dieses Benachrichtigungsereignis (CreateSession) zu bearbeiten. Ereignis-XML: <Event xmlns="hxxp://schemas.microsoft.com/win/2004/08/events/event"> <System> <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" /> <EventID Qualifiers="32768">6006</EventID> <Version>0</Version> <Level>3</Level> <Task>0</Task> <Opcode>0</Opcode> <Keywords>0x80000000000000</Keywords> <TimeCreated SystemTime="2014-06-12T19:15:22.000000000Z" /> <EventRecordID>53998</EventRecordID> <Correlation /> <Execution ProcessID="0" ThreadID="0" /> <Channel>Application</Channel> <Computer>Maag-PC</Computer> <Security /> </System> <EventData> <Data>TrustedInstaller</Data> <Data>347</Data> <Data>CreateSession</Data> <Binary>04000000</Binary> </EventData> </Event> Ansonsten sind alle anderen Symptome wieder verschwunden und der Laptop arbeitet wieder ordnungsgemäß. LG Jonas |
Hallo Jonas, das sieht sehr nach dem Windowsdienst Trusted Installer aus. Dieser prüft in regelmäßigen Abständen Windows auf Updates. Der ist notwendig, da hilft nur abwarten.
![]() | #15 |
Hallo Sandra, vielen Dank für deine Hilfe! Der Laptop läuft wieder stabil und es gibt nun auch keine Fehlermeldungen mehr. Das war wirklich eine gute und klar strukturierte Arbeit von dir! Von mir aus kannst du das Thema nun schließen!
Themen zu Windows 7: "Windows-Verwaltungsinstrumentation"-Dienst startet nicht nach Trojanerbefall |
association, bingbar, browser, dateien gelöscht, desktop, dienste starten nicht, email, error, excel, flash player, focus, google, home, installation, internet explorer, kaspersky, norman, programm, ransomware, realtek, registrierungsdatenbank, registry, rundll, scan, secur, security, software, svchost.exe, updates, usb, verwaltungsinstrumentation, virus, werkseinstellungen, windows |