|
Log-Analyse und Auswertung: Windows 7: Sperrbildschirm nach GVU TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.08.2014, 16:31 | #1 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Windows 7: Sperrbildschirm nach GVU Trojaner Hallo alle Zusammen, mein Computer hat sich jetzt auch einen GVU Trojaner eingefangen. Ich habe die fixlist schon erstellt und würde mich freuen, wenn einer von euch mir sagen kann was ich als nächstes tun muss. Schonmal vielen Dank für die Mühe im Voraus.
|
10.08.2014, 17:03 | #2 |
/// TB-Ausbilder | Windows 7: Sperrbildschirm nach GVU Trojaner Hallo Udol
__________________Mein Name ist Timo und ich werde Dir bei deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist immer der sicherste Weg. Wir "arbeiten" hier alle freiwillig und in unserer Freizeit *hust*. Daher kann es bei Antworten zu Verzögerungen kommen. Solltest du innerhalb 48 Std keine Antwort von mir erhalten, dann schreib mit eine PM Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis ich oder jemand vom Team sagt, dass Du clean bist. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte nochmal in CODE Klammern posten, ich bekomm ja Augenkrebs ^^
__________________ |
10.08.2014, 17:09 | #3 |
| Windows 7: Sperrbildschirm nach GVU Trojaner sorry ich hoffe jetzt klappt es.
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-08-2014 Ran by SYSTEM on MININT-GGP92B3 on 10-08-2014 14:50:00 Running from i:\ Platform: Windows 7 Home Premium (X64) OS Language: Englisch (USA) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [524800 2010-12-01] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2014-06-07] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2010-12-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2014-06-07] (Renesas Electronics Corporation) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-02] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-11-24] (cyberlink) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [976832 2010-06-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-06-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-12-13] (EasyBits Software AS) HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2010-12-13] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2014-03-26] (RealNetworks, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\Mike\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-11-22] (Hewlett-Packard Company) HKU\Mike\...\Run: [Spotify] => C:\Users\Mike\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-24] (Spotify Ltd) HKU\Mike\...\Run: [Spotify Web Helper] => C:\Users\Mike\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-24] (Spotify Ltd) Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk ShortcutTarget: explorer.lnk -> C:\ProgramData\D250639581322285A2C4C66618854AE5\zy4j04.cpp () ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2010-11-24] (CyberLink) S2 Winmgmt; C:\ProgramData\D250639581322285A2C4C66618854AE5\40j4yz.dot [332020 2014-06-14] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-10-17] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO) S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620640 2013-10-17] (Kaspersky Lab ZAO) S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) S1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) S1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-10 14:49 - 2014-08-10 14:50 - 00000000 ____D () C:\FRST 2014-08-10 04:07 - 2014-08-10 04:09 - 00000345 _____ () C:\ProgramData\RUNDLL32.EXE-2772-F.txt 2014-08-10 03:53 - 2014-08-10 03:54 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2752-F.txt 2014-07-15 11:29 - 2014-07-15 11:30 - 00000534 _____ () C:\ProgramData\RUNDLL32.EXE-3332-F.txt 2014-07-15 11:23 - 2014-07-15 11:23 - 00002334 _____ () C:\Users\Mike\Desktop\Sicherer Zahlungsverkehr.lnk 2014-07-15 11:23 - 2014-07-15 11:23 - 00001124 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-07-15 11:23 - 2013-05-05 23:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\System32\klfphc.dll 2014-07-15 11:21 - 2014-08-10 04:21 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-07-15 11:21 - 2014-07-15 11:21 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-07-15 11:21 - 2014-07-15 11:21 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-07-15 11:17 - 2013-10-17 05:47 - 00620640 _____ (Kaspersky Lab ZAO) C:\Windows\System32\Drivers\klif.sys 2014-07-15 11:17 - 2013-06-08 10:18 - 00112224 _____ (Kaspersky Lab ZAO) C:\Windows\System32\Drivers\klflt.sys 2014-07-12 01:11 - 2014-07-12 01:11 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-3328-F.txt 2014-07-12 01:06 - 2014-07-12 01:09 - 00000458 _____ () C:\ProgramData\RUNDLL32.EXE-2800-F.txt 2014-07-12 01:04 - 2014-07-12 01:05 - 00000115 _____ () C:\ProgramData\RUNDLL32.EXE-2812-F.txt 2014-07-12 01:02 - 2014-07-12 01:02 - 00000169 _____ () C:\ProgramData\RUNDLL32.EXE-3044-F.txt 2014-07-12 00:57 - 2014-08-10 03:57 - 00000510 _____ () C:\ProgramData\RUNDLL32.EXE-2844-F.txt 2014-07-12 00:19 - 2014-07-12 00:20 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2832-F.txt 2014-07-12 00:04 - 2014-07-12 00:18 - 00001913 _____ () C:\ProgramData\RUNDLL32.EXE-2492-F.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-10 14:50 - 2014-08-10 14:49 - 00000000 ____D () C:\FRST 2014-08-10 04:24 - 2009-07-13 20:45 - 00023024 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-10 04:24 - 2009-07-13 20:45 - 00023024 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-10 04:23 - 2014-06-16 23:03 - 00000505 _____ () C:\ProgramData\RUNDLL32.EXE-2756-F.txt 2014-08-10 04:21 - 2014-07-15 11:21 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-08-10 04:21 - 2014-05-24 08:28 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\Spotify 2014-08-10 04:20 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-10 04:19 - 2009-07-13 20:51 - 00062931 _____ () C:\Windows\setupact.log 2014-08-10 04:09 - 2014-08-10 04:07 - 00000345 _____ () C:\ProgramData\RUNDLL32.EXE-2772-F.txt 2014-08-10 03:57 - 2014-07-12 00:57 - 00000510 _____ () C:\ProgramData\RUNDLL32.EXE-2844-F.txt 2014-08-10 03:54 - 2014-08-10 03:53 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2752-F.txt 2014-08-10 03:52 - 2011-05-07 08:03 - 00247958 _____ () C:\Windows\PFRO.log 2014-07-15 11:30 - 2014-07-15 11:29 - 00000534 _____ () C:\ProgramData\RUNDLL32.EXE-3332-F.txt 2014-07-15 11:30 - 2014-05-24 08:28 - 00000000 ____D () C:\Users\Mike\AppData\Local\Spotify 2014-07-15 11:29 - 2011-05-07 07:38 - 01061204 _____ () C:\Windows\WindowsUpdate.log 2014-07-15 11:23 - 2014-07-15 11:23 - 00002334 _____ () C:\Users\Mike\Desktop\Sicherer Zahlungsverkehr.lnk 2014-07-15 11:23 - 2014-07-15 11:23 - 00001124 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-07-15 11:21 - 2014-07-15 11:21 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-07-15 11:21 - 2014-07-15 11:21 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-07-15 11:12 - 2011-05-07 08:09 - 00000000 ____D () C:\ProgramData\Norton 2014-07-12 01:11 - 2014-07-12 01:11 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-3328-F.txt 2014-07-12 01:09 - 2014-07-12 01:06 - 00000458 _____ () C:\ProgramData\RUNDLL32.EXE-2800-F.txt 2014-07-12 01:05 - 2014-07-12 01:04 - 00000115 _____ () C:\ProgramData\RUNDLL32.EXE-2812-F.txt 2014-07-12 01:02 - 2014-07-12 01:02 - 00000169 _____ () C:\ProgramData\RUNDLL32.EXE-3044-F.txt 2014-07-12 00:20 - 2014-07-12 00:19 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2832-F.txt 2014-07-12 00:18 - 2014-07-12 00:04 - 00001913 _____ () C:\ProgramData\RUNDLL32.EXE-2492-F.txt Some content of TEMP: ==================== C:\Users\Mike\AppData\Local\Temp\autorun.dll C:\Users\Mike\AppData\Local\Temp\Execute2App.exe C:\Users\Mike\AppData\Local\Temp\Extract.exe C:\Users\Mike\AppData\Local\Temp\lowproc.exe C:\Users\Mike\AppData\Local\Temp\msvcp90.dll C:\Users\Mike\AppData\Local\Temp\msvcr90.dll C:\Users\Mike\AppData\Local\Temp\SP52503.exe C:\Users\Mike\AppData\Local\Temp\SP52509.exe C:\Users\Mike\AppData\Local\Temp\SP52898.exe C:\Users\Mike\AppData\Local\Temp\SP53998.exe C:\Users\Mike\AppData\Local\Temp\SP54714.exe C:\Users\Mike\AppData\Local\Temp\SP55068.exe C:\Users\Mike\AppData\Local\Temp\SP55094.exe C:\Users\Mike\AppData\Local\Temp\SP55101.exe C:\Users\Mike\AppData\Local\Temp\SP55102.exe C:\Users\Mike\AppData\Local\Temp\SP55107.exe C:\Users\Mike\AppData\Local\Temp\SP55109.exe C:\Users\Mike\AppData\Local\Temp\SP55150.exe C:\Users\Mike\AppData\Local\Temp\SP55152.exe C:\Users\Mike\AppData\Local\Temp\sp58915.exe C:\Users\Mike\AppData\Local\Temp\stubhelper.dll C:\Users\Mike\AppData\Local\Temp\UninstallHPSA.exe C:\Users\Mike\AppData\Local\Temp\UninstallHPTCA.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2014-06-07 04:30:52 Restore point made on: 2014-06-07 04:31:46 Restore point made on: 2014-06-07 04:40:26 Restore point made on: 2014-06-07 04:45:15 Restore point made on: 2014-06-11 07:57:16 Restore point made on: 2014-06-11 23:22:37 Restore point made on: 2014-06-20 15:24:38 Restore point made on: 2014-07-04 07:06:21 ==================== Memory info =========================== Percentage of memory in use: 11% Total physical RAM: 8139.86 MB Available physical RAM: 7208.55 MB Total Pagefile: 8138.01 MB Available Pagefile: 7201.69 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:914.56 GB) (Free:832.88 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: () (Fixed) (Total:931.51 GB) (Free:923.61 GB) NTFS Drive f: (RECOVERY) (Fixed) (Total:16.65 GB) (Free:2.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive g: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.08 GB) FAT32 Drive h: (KIS 2014) (CDROM) (Total:0.53 GB) (Free:0 GB) CDFS Drive i: (USB DISK) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 067D8327) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=915 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=17 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 2CD2F13C) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 2 GB) (Disk ID: 00000000) Partition: GPT Partition Type. LastRegBack: 2014-07-08 00:18 ==================== End Of Log ============================ --- --- --- |
10.08.2014, 17:22 | #4 |
/// TB-Ausbilder | Windows 7: Sperrbildschirm nach GVU Trojaner Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk ShortcutTarget: explorer.lnk -> C:\ProgramData\D250639581322285A2C4C66618854AE5\zy4j04.cpp () S2 Winmgmt; C:\ProgramData\D250639581322285A2C4C66618854AE5\40j4yz.dot [332020 2014-06-14] (Microsoft Corporation) C:\ProgramData\D250639581322285A2C4C66618854AE5\
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Danach Neustart ins normale Windows. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
10.08.2014, 17:34 | #5 |
| Windows 7: Sperrbildschirm nach GVU TrojanerCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-08-2014 Ran by SYSTEM at 2014-08-10 18:33:12 Run:1 Running from i:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk ShortcutTarget: explorer.lnk -> C:\ProgramData\D250639581322285A2C4C66618854AE5\zy4j04.cpp () S2 Winmgmt; C:\ProgramData\D250639581322285A2C4C66618854AE5\40j4yz.dot [332020 2014-06-14] (Microsoft Corporation) C:\ProgramData\D250639581322285A2C4C66618854AE5\ ***************** C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk => Moved successfully. C:\ProgramData\D250639581322285A2C4C66618854AE5\zy4j04.cpp => Moved successfully. Winmgmt => Service restored successfully. C:\ProgramData\D250639581322285A2C4C66618854AE5 => Moved successfully. ==== End of Fixlog ==== |
10.08.2014, 18:12 | #6 |
/// TB-Ausbilder | Windows 7: Sperrbildschirm nach GVU Trojaner Jo, der Rechner sollte jetzt wieder normal ohne Sperrbildschirm starten. Mach dort nochmal ein FRST Log. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Windows 7: Sperrbildschirm nach GVU Trojaner |
10.08.2014, 18:34 | #7 |
| Windows 7: Sperrbildschirm nach GVU TrojanerFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-08-2014 Ran by Mike (administrator) on MIKE-HP on 10-08-2014 19:30:02 Running from H:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Spotify Ltd) C:\Users\Mike\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Hewlett-Packard Company) C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [524800 2010-12-02] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2014-06-07] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2010-12-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2014-06-07] (Renesas Electronics Corporation) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-11-25] (cyberlink) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [976832 2010-06-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-06-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-12-13] (EasyBits Software AS) HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2010-12-13] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2014-03-26] (RealNetworks, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-05-27] (Microsoft Corporation) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-11-22] (Hewlett-Packard Company) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\Run: [Spotify] => C:\Users\Mike\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-24] (Spotify Ltd) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\Run: [Spotify Web Helper] => C:\Users\Mike\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-24] (Spotify Ltd) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\MountPoints2: {a149c82e-b38b-11e3-b45a-806e6f6e6963} - F:\autorun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish PictureMover.lnk ShortcutTarget: Snapfish PictureMover.lnk -> C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company) ShellIconOverlayIdentifiers: 00Zecter -> {D25B32FE-CB96-491A-98FF-AD59DA382D69} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 01Zecter -> {EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 02Zecter -> {B3C78E40-6B64-47C3-AE34-60B770881EB8} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 03Zecter -> {622AFE52-33F6-4D9F-9966-E0BC52D7D69D} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 04Zecter -> {855156F0-2A0F-11DE-8C30-0800200C9A66} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-01-27] (EasyBits Software Corp.) FireFox: ======== FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-05-07] FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-05-07] FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-05-07] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-07-15] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [nhfpefkeidlhbjljfdojcnngjbddgein] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2010-11-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2010-11-24] (CyberLink) R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed] R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-11-22] (Hewlett-Packard Company) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-10-17] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620640 2013-10-17] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-11 00:49 - 2014-08-10 19:30 - 00000000 ____D () C:\FRST 2014-08-10 14:07 - 2014-08-10 14:09 - 00000345 _____ () C:\ProgramData\RUNDLL32.EXE-2772-F.txt 2014-08-10 13:53 - 2014-08-10 13:54 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2752-F.txt 2014-07-15 21:29 - 2014-07-15 21:30 - 00000534 _____ () C:\ProgramData\RUNDLL32.EXE-3332-F.txt 2014-07-15 21:23 - 2014-07-15 21:23 - 00002334 _____ () C:\Users\Mike\Desktop\Sicherer Zahlungsverkehr.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00001124 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-07-15 21:23 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2014-07-15 21:21 - 2014-08-10 18:36 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-07-15 21:17 - 2013-10-17 15:47 - 00620640 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-07-15 21:17 - 2013-06-08 20:18 - 00112224 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-07-12 11:11 - 2014-07-12 11:11 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-3328-F.txt 2014-07-12 11:06 - 2014-07-12 11:09 - 00000458 _____ () C:\ProgramData\RUNDLL32.EXE-2800-F.txt 2014-07-12 11:04 - 2014-07-12 11:05 - 00000115 _____ () C:\ProgramData\RUNDLL32.EXE-2812-F.txt 2014-07-12 11:02 - 2014-07-12 11:02 - 00000169 _____ () C:\ProgramData\RUNDLL32.EXE-3044-F.txt 2014-07-12 10:57 - 2014-08-10 13:57 - 00000510 _____ () C:\ProgramData\RUNDLL32.EXE-2844-F.txt 2014-07-12 10:19 - 2014-07-12 10:20 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2832-F.txt 2014-07-12 10:04 - 2014-07-12 10:18 - 00001913 _____ () C:\ProgramData\RUNDLL32.EXE-2492-F.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-10 19:30 - 2014-08-11 00:49 - 00000000 ____D () C:\FRST 2014-08-10 19:29 - 2009-07-14 06:51 - 00063782 _____ () C:\Windows\setupact.log 2014-08-10 19:27 - 2011-05-07 17:38 - 01068045 _____ () C:\Windows\WindowsUpdate.log 2014-08-10 18:43 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-10 18:43 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-10 18:41 - 2011-01-28 01:28 - 00698926 _____ () C:\Windows\system32\perfh007.dat 2014-08-10 18:41 - 2011-01-28 01:28 - 00149034 _____ () C:\Windows\system32\perfc007.dat 2014-08-10 18:41 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-10 18:36 - 2014-07-15 21:21 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-08-10 18:36 - 2014-05-24 18:28 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\Spotify 2014-08-10 18:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-10 14:23 - 2014-06-17 09:03 - 00000505 _____ () C:\ProgramData\RUNDLL32.EXE-2756-F.txt 2014-08-10 14:09 - 2014-08-10 14:07 - 00000345 _____ () C:\ProgramData\RUNDLL32.EXE-2772-F.txt 2014-08-10 13:57 - 2014-07-12 10:57 - 00000510 _____ () C:\ProgramData\RUNDLL32.EXE-2844-F.txt 2014-08-10 13:54 - 2014-08-10 13:53 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2752-F.txt 2014-08-10 13:52 - 2011-05-07 18:03 - 00247958 _____ () C:\Windows\PFRO.log 2014-07-15 21:30 - 2014-07-15 21:29 - 00000534 _____ () C:\ProgramData\RUNDLL32.EXE-3332-F.txt 2014-07-15 21:30 - 2014-05-24 18:28 - 00000000 ____D () C:\Users\Mike\AppData\Local\Spotify 2014-07-15 21:23 - 2014-07-15 21:23 - 00002334 _____ () C:\Users\Mike\Desktop\Sicherer Zahlungsverkehr.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00001124 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-07-15 21:12 - 2011-05-07 18:09 - 00000000 ____D () C:\ProgramData\Norton 2014-07-12 11:11 - 2014-07-12 11:11 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-3328-F.txt 2014-07-12 11:09 - 2014-07-12 11:06 - 00000458 _____ () C:\ProgramData\RUNDLL32.EXE-2800-F.txt 2014-07-12 11:05 - 2014-07-12 11:04 - 00000115 _____ () C:\ProgramData\RUNDLL32.EXE-2812-F.txt 2014-07-12 11:02 - 2014-07-12 11:02 - 00000169 _____ () C:\ProgramData\RUNDLL32.EXE-3044-F.txt 2014-07-12 10:20 - 2014-07-12 10:19 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2832-F.txt 2014-07-12 10:18 - 2014-07-12 10:04 - 00001913 _____ () C:\ProgramData\RUNDLL32.EXE-2492-F.txt Some content of TEMP: ==================== C:\Users\Mike\AppData\Local\Temp\autorun.dll C:\Users\Mike\AppData\Local\Temp\Execute2App.exe C:\Users\Mike\AppData\Local\Temp\Extract.exe C:\Users\Mike\AppData\Local\Temp\lowproc.exe C:\Users\Mike\AppData\Local\Temp\msvcp90.dll C:\Users\Mike\AppData\Local\Temp\msvcr90.dll C:\Users\Mike\AppData\Local\Temp\SP52503.exe C:\Users\Mike\AppData\Local\Temp\SP52509.exe C:\Users\Mike\AppData\Local\Temp\SP52898.exe C:\Users\Mike\AppData\Local\Temp\SP53998.exe C:\Users\Mike\AppData\Local\Temp\SP54714.exe C:\Users\Mike\AppData\Local\Temp\SP55068.exe C:\Users\Mike\AppData\Local\Temp\SP55094.exe C:\Users\Mike\AppData\Local\Temp\SP55101.exe C:\Users\Mike\AppData\Local\Temp\SP55102.exe C:\Users\Mike\AppData\Local\Temp\SP55107.exe C:\Users\Mike\AppData\Local\Temp\SP55109.exe C:\Users\Mike\AppData\Local\Temp\SP55150.exe C:\Users\Mike\AppData\Local\Temp\SP55152.exe C:\Users\Mike\AppData\Local\Temp\sp58915.exe C:\Users\Mike\AppData\Local\Temp\stubhelper.dll C:\Users\Mike\AppData\Local\Temp\UninstallHPSA.exe C:\Users\Mike\AppData\Local\Temp\UninstallHPTCA.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-10 18:54 ==================== End Of Log ============================ und die Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-08-2014 Ran by Mike at 2014-08-10 19:30:35 Running from H:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Kaspersky Internet Security (Enabled - Out of date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.1.102.64 - Adobe Systems Incorporated) Adobe Reader 9.3.3 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.3.3 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM-x32\...\{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}) (Version: 11.5.8.612 - Adobe Systems, Inc) Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden ATI Catalyst Install Manager (HKLM\...\{2E794F67-DAC1-C4A3-9128-0C841DF8A1BE}) (Version: 3.0.808.0 - ATI Technologies, Inc.) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Bing Bar (HKLM-x32\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 6.0.2282.0 - Microsoft Corporation) Bing Bar Platform (x32 Version: 6.0.2282.0 - Microsoft Corporation) Hidden Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden Broadcom 2070 Bluetooth 3.0 (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.6300 - Broadcom Corporation) Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.48.61 - Broadcom Corporation) Build-a-Lot - The Elizabethan Era (x32 Version: 2.2.0.95 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.1230.1709.30713 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.1230.1709.30713 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.1230.1709.30713 - ATI) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2010.1230.1709.30713 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Czech (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Danish (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help English (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help French (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help German (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Greek (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Italian (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Korean (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Polish (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Russian (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.1230.1708.30713 - ATI) Hidden CCC Help Thai (x32 Version: 2010.1230.1708.30713 - ATI) Hidden ccc-core-static (x32 Version: 2010.1230.1709.30713 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2010.1230.1709.30713 - ATI) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3525 - CyberLink Corp.) CyberLink DVD Suite (x32 Version: 7.0.3525 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.1.2430 - CyberLink Corp.) CyberLink PowerDVD 10 (x32 Version: 10.0.1.2430 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.2.1.3609 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.2.1.3609 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP 3D DriveGuard (HKLM\...\{CA6EDFBB-B76A-4785-A606-B1B64685869E}) (Version: 4.1.1.6 - Hewlett-Packard Company) HP Auto (Version: 1.0.12494.3472 - Hewlett-Packard Company) Hidden HP Client Services (Version: 1.0.12656.3472 - Hewlett-Packard) Hidden HP CloudDrive (HKLM-x32\...\ZumoDrive) (Version: - Zecter Inc.) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{A71D76FD-DF5A-4380-9D0C-7B3FEB80DE4C}) (Version: 1.1.0.0 - Hewlett-Packard) HP Game Console (x32 Version: - WildTangent) Hidden HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent) HP On Screen Display (HKLM-x32\...\{124DB96E-CBF5-44FB-AB59-7D2444DEC777}) (Version: 1.0.7 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{AF306BD8-F9D1-4627-89B9-246E59074A05}) (Version: 1.1.2 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{EB58480C-0721-483C-B354-9D35A147999F}) (Version: 2.3.6 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{802C068E-0576-4F25-8137-D54B7DB0FC5E}) (Version: 8.4.4487.3576 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.0.12845.3522 - Hewlett-Packard Company) HP SimplePass 2011 (HKLM-x32\...\{F1DD6CD2-6734-4089-9EF5-441F51E083B6}) (Version: 5.0.1.448 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{2483ABA1-192F-40A1-97EE-CEC79638C65D}) (Version: 4.0.80.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company) HP Wireless Assistant (HKLM\...\{9EA86AD9-FB32-4B9E-BD56-3068F9B8031F}) (Version: 4.0.10.0 - Hewlett-Packard) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6315.0 - IDT) Insaniquarium Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation) Java Auto Updater (x32 Version: 2.0.2.4 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 22 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416022FF}) (Version: 6.0.220 - Oracle) Java(TM) 6 Update 22 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.220 - Oracle) Jewel Quest II (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3429 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.3429 - CyberLink Corp.) Hidden LightScribe System Software (HKLM-x32\...\{FD7F0DB8-0E96-4D64-AD4D-9B5A936AF2A8}) (Version: 1.18.20.1 - LightScribe) Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Default Manager (x32 Version: 2.2.114.0 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Search Enhancement Pack (x32 Version: 3.0.131.0 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden PictureMover (HKLM-x32\...\{264FE20A-757B-492a-B0C3-4009E2997D8A}) (Version: 3.5.0.35 - Hewlett-Packard Company) Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4725 - CyberLink Corp.) Power2Go (x32 Version: 6.1.4725 - CyberLink Corp.) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.30.1019.2010 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.69 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Recovery Manager (x32 Version: 1.0.22 - Hewlett-Packard) Hidden Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.19.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.19.0 - Renesas Electronics Corporation) Hidden Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14024.11 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.14024.11 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.34.0 - SAMSUNG Electronics Co., Ltd.) Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Spotify (HKCU\...\Spotify) (Version: 0.9.10.14.g578d350b - Spotify AB) Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.11.0 - Synaptics Incorporated) Validity WBF DDK (HKLM\...\{79174AF2-6CB1-42F5-981E-66DCA49391D0}) (Version: 4.3.205.0 - Validity Sensors, Inc.) Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 07-06-2014 12:30:37 HPSF Applying updates 07-06-2014 12:30:37 HPSF Applying updates 07-06-2014 12:40:22 Konfiguriert Renesas Electronics USB 3.0 Host Controller Driver 07-06-2014 12:45:11 Installiert Realtek Ethernet Controller Driver 11-06-2014 15:57:04 Windows Update 12-06-2014 07:22:26 Windows Update 20-06-2014 23:24:27 Geplanter Prüfpunkt 04-07-2014 15:06:10 Geplanter Prüfpunkt 10-08-2014 17:27:39 Geplanter Prüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {071BF852-B9A7-4F26-9781-B7A0A8898DFF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {13256A05-582A-49DB-9D32-49F12927C5A6} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-11-17] () Task: {27A93F46-4AEC-47E4-9AFE-311C3436A82B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard) Task: {2D75B935-74E8-4CFB-A023-0A39CF60131B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2010-12-10] (CyberLink) Task: {372D33AE-7848-4A26-9866-92E1635AE9C6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Assistant Restart => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {6FBDDF0D-0597-45F0-B18B-35513B91C1D4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {73B2E243-F7CB-4E6B-BF6A-416F5BEA7B1A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2014-05-27] (Microsoft) Task: {7C8F402C-DC6F-4641-8983-E6DC743D3FAD} - System32\Tasks\HPCeeScheduleForMIKE-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) Task: {C7803C64-67C8-4C52-A5AF-F5687C73A3BB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3383338283-2784913959-1398910196-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {CDAE07DB-6CA4-4216-9A25-A4CA6411F397} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company) Task: {EFF2F478-DAEA-4BF9-B3CF-FAEDE9BE53B7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard) Task: {F8C6D223-A67B-426A-B4B5-50CD469BB3ED} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3383338283-2784913959-1398910196-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {F98919B4-0377-4894-9F24-69F88885CE49} - System32\Tasks\HPCeeScheduleForMike => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) Task: C:\Windows\Tasks\HPCeeScheduleForMIKE-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\HPCeeScheduleForMike.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2011-05-07 17:46 - 2010-12-17 02:37 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-07-29 19:39 - 2010-07-29 19:39 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2010-12-30 17:08 - 2010-12-30 17:08 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-12-02 10:09 - 2010-12-02 10:09 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-07-21 15:33 - 2010-07-21 15:33 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll 2010-07-21 15:33 - 2010-07-21 15:33 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll 2010-07-21 15:33 - 2010-07-21 15:33 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll 2010-11-22 14:00 - 2010-11-22 14:00 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2010-11-22 14:00 - 2010-11-22 14:00 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2010-11-22 14:00 - 2010-11-22 14:00 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2014-03-24 21:50 - 2010-11-18 12:57 - 12284984 _____ () C:\Users\Mike\AppData\Roaming\PictureMover\Bin\Core.dll 2009-07-13 23:03 - 2009-07-14 03:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll 2014-03-24 21:50 - 2010-11-18 13:07 - 01700920 _____ () C:\Users\Mike\AppData\Roaming\PictureMover\DE-DE\Presentation.dll 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2014-05-29 09:36 - 2014-05-29 09:36 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\aa739380ca2b2fc7366d464d2f2301ac\IsdiInterop.ni.dll 2011-05-07 17:41 - 2010-09-13 18:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/10/2014 06:54:16 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Volume "CANON_DC (G:)" wurde aufgrund eines Fehlers nicht defragmentiert: Der Datenträger wurde vom System getrennt. (0x89000011) Error: (08/10/2014 02:22:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Name des fehlerhaften Moduls: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000016d1 ID des fehlerhaften Prozesses: 0x92c Startzeit der fehlerhaften Anwendung: 0xHPWMISVC.exe0 Pfad der fehlerhaften Anwendung: HPWMISVC.exe1 Pfad des fehlerhaften Moduls: HPWMISVC.exe2 Berichtskennung: HPWMISVC.exe3 Error: (08/10/2014 02:20:58 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: Unbekannter Fehler bei der Systemwiederherstellung: (Geplanter Prüfpunkt). Zusätzliche Informationen: 0x80070057. Error: (08/10/2014 02:09:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Name des fehlerhaften Moduls: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000016d1 ID des fehlerhaften Prozesses: 0x9ac Startzeit der fehlerhaften Anwendung: 0xHPWMISVC.exe0 Pfad der fehlerhaften Anwendung: HPWMISVC.exe1 Pfad des fehlerhaften Moduls: HPWMISVC.exe2 Berichtskennung: HPWMISVC.exe3 Error: (08/10/2014 02:08:01 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: Unbekannter Fehler bei der Systemwiederherstellung: (Geplanter Prüfpunkt). Zusätzliche Informationen: 0x80070057. Error: (07/15/2014 09:14:34 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Name des fehlerhaften Moduls: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000016d1 ID des fehlerhaften Prozesses: 0xb10 Startzeit der fehlerhaften Anwendung: 0xHPWMISVC.exe0 Pfad der fehlerhaften Anwendung: HPWMISVC.exe1 Pfad des fehlerhaften Moduls: HPWMISVC.exe2 Berichtskennung: HPWMISVC.exe3 Error: (07/15/2014 09:04:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Name des fehlerhaften Moduls: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000016d1 ID des fehlerhaften Prozesses: 0xb9c Startzeit der fehlerhaften Anwendung: 0xHPWMISVC.exe0 Pfad der fehlerhaften Anwendung: HPWMISVC.exe1 Pfad des fehlerhaften Moduls: HPWMISVC.exe2 Berichtskennung: HPWMISVC.exe3 Error: (07/12/2014 11:08:05 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Name des fehlerhaften Moduls: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000016d1 ID des fehlerhaften Prozesses: 0x8f8 Startzeit der fehlerhaften Anwendung: 0xHPWMISVC.exe0 Pfad der fehlerhaften Anwendung: HPWMISVC.exe1 Pfad des fehlerhaften Moduls: HPWMISVC.exe2 Berichtskennung: HPWMISVC.exe3 Error: (07/12/2014 11:00:25 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Name des fehlerhaften Moduls: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000016d1 ID des fehlerhaften Prozesses: 0xc70 Startzeit der fehlerhaften Anwendung: 0xHPWMISVC.exe0 Pfad der fehlerhaften Anwendung: HPWMISVC.exe1 Pfad des fehlerhaften Moduls: HPWMISVC.exe2 Berichtskennung: HPWMISVC.exe3 Error: (07/12/2014 10:05:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Name des fehlerhaften Moduls: HPWMISVC.exe, Version: 2.3.1.0, Zeitstempel: 0x4cd8eed3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000016d1 ID des fehlerhaften Prozesses: 0x8a4 Startzeit der fehlerhaften Anwendung: 0xHPWMISVC.exe0 Pfad der fehlerhaften Anwendung: HPWMISVC.exe1 Pfad des fehlerhaften Moduls: HPWMISVC.exe2 Berichtskennung: HPWMISVC.exe3 System errors: ============= Error: (08/10/2014 06:36:29 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst HPWMISVC erreicht. Error: (08/10/2014 02:25:18 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: AFD DfsC discache KLIF KLIM6 klpd kltdi kneps NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf Error: (08/10/2014 02:25:18 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet: %%127 Error: (08/10/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NLA (Network Location Awareness)" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/10/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/10/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "SMB 1.x-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/10/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "SMB-Miniredirector-Wrapper und -Modul" ist vom Dienst "Umgeleitetes Puffersubsystem" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%31 Error: (08/10/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "IP-Hilfsdienst" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/10/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Arbeitsstationsdienst" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/10/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Netzwerkspeicher-Schnittstellendienst" ist vom Dienst "NSI proxy service driver." abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%31 Microsoft Office Sessions: ========================= Error: (08/10/2014 06:54:16 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: CANON_DC (G:)Der Datenträger wurde vom System getrennt. (0x89000011) Error: (08/10/2014 02:22:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: HPWMISVC.exe2.3.1.04cd8eed3HPWMISVC.exe2.3.1.04cd8eed3c0000005000016d192c01cfb49572abc090C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeff8d38d1-2088-11e4-bf3b-cc52af8f520e Error: (08/10/2014 02:20:58 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: Geplanter Prüfpunkt0x80070057 Error: (08/10/2014 02:09:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: HPWMISVC.exe2.3.1.04cd8eed3HPWMISVC.exe2.3.1.04cd8eed3c0000005000016d19ac01cfb493a2dcb4bfC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe3393b562-2087-11e4-a104-cc52af7139ab Error: (08/10/2014 02:08:01 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: Geplanter Prüfpunkt0x80070057 Error: (07/15/2014 09:14:34 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: HPWMISVC.exe2.3.1.04cd8eed3HPWMISVC.exe2.3.1.04cd8eed3c0000005000016d1b1001cfa060cb40fe33C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe40d4a91a-0c54-11e4-9010-cc52af7139ab Error: (07/15/2014 09:04:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: HPWMISVC.exe2.3.1.04cd8eed3HPWMISVC.exe2.3.1.04cd8eed3c0000005000016d1b9c01cfa05f4ecc5360C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exec77a60d1-0c52-11e4-8d21-cc52af8f520e Error: (07/12/2014 11:08:05 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: HPWMISVC.exe2.3.1.04cd8eed3HPWMISVC.exe2.3.1.04cd8eed3c0000005000016d18f801cf9db08c813467C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe08677968-09a4-11e4-8d3f-cc52af8f520e Error: (07/12/2014 11:00:25 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: HPWMISVC.exe2.3.1.04cd8eed3HPWMISVC.exe2.3.1.04cd8eed3c0000005000016d1c7001cf9daf5f72e48eC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exef5fe4b0e-09a2-11e4-b213-cc52af8f520e Error: (07/12/2014 10:05:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: HPWMISVC.exe2.3.1.04cd8eed3HPWMISVC.exe2.3.1.04cd8eed3c0000005000016d18a401cf9da7d617ea83C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe547b74e4-099b-11e4-aa5c-cc52af8f520e CodeIntegrity Errors: =================================== Date: 2014-08-10 18:56:21.532 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-10 18:56:21.530 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-10 18:56:21.528 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-10 18:56:21.503 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-10 18:56:21.500 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-10 18:56:21.497 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 25% Total physical RAM: 8139.86 MB Available physical RAM: 6085.59 MB Total Pagefile: 16277.9 MB Available Pagefile: 13762.66 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:914.56 GB) (Free:832.69 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: () (Fixed) (Total:931.51 GB) (Free:923.61 GB) NTFS Drive e: (RECOVERY) (Fixed) (Total:16.65 GB) (Free:2.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (KIS 2014) (CDROM) (Total:0.53 GB) (Free:0 GB) CDFS Drive g: (CANON_DC) (Removable) (Total:3.69 GB) (Free:3.5 GB) FAT32 Drive h: (USB DISK) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 067D8327) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=915 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=17 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 2CD2F13C) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 4 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 3 (Size: 2 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
10.08.2014, 19:29 | #8 |
/// TB-Ausbilder | Windows 7: Sperrbildschirm nach GVU Trojaner Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter reg: reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" /s Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
10.08.2014, 20:50 | #9 |
| Windows 7: Sperrbildschirm nach GVU TrojanerCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-08-2014 Ran by Mike at 2014-08-10 21:48:14 Run:2 Running from H:\ Boot Mode: Normal ============================================== Content of fixlist: ***************** reg: reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" /s ***************** ========= reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" /s ========= ========= End of Reg: ========= ==== End of Fixlog ==== |
11.08.2014, 07:41 | #10 |
/// TB-Ausbilder | Windows 7: Sperrbildschirm nach GVU Trojaner Ok, sieht gut aus. So gehts weiter: Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade Dir bitte Malwarebytes Anti-Malware
Starte noch einmal FRST.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
11.08.2014, 10:42 | #11 |
| Windows 7: Sperrbildschirm nach GVU Trojaner als erstes die adwcleaner-Datei: Code:
ATTFilter # AdwCleaner v3.304 - Bericht erstellt am 11/08/2014 um 11:10:39 # Aktualisiert 08/08/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Mike - MIKE-HP # Gestartet von : H:\adwcleaner_3.304.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Schlüssel Gelöscht : HKCU\Software\InstallCore ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 ************************* AdwCleaner[R0].txt - [3297 octets] - [11/08/2014 11:09:00] AdwCleaner[S0].txt - [2778 octets] - [11/08/2014 11:10:39] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2838 octets] ######## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Mike on 11.08.2014 at 11:16:47,12 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.08.2014 at 11:25:19,74 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 11.08.2014 Suchlauf-Zeit: 11:27:05 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.03.04.09 Rootkit Datenbank: v2014.02.20.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Mike Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 235868 Verstrichene Zeit: 7 Min, 2 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) und zu guter letzt die frst: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-08-2014 Ran by Mike (administrator) on MIKE-HP on 11-08-2014 11:37:20 Running from H:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (AMD) C:\Windows\System32\atieclxx.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Spotify Ltd) C:\Users\Mike\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Hewlett-Packard Company) C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [524800 2010-12-02] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2014-06-07] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2010-12-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2014-06-07] (Renesas Electronics Corporation) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-11-25] (cyberlink) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [976832 2010-06-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-06-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-12-13] (EasyBits Software AS) HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2010-12-13] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2014-03-26] (RealNetworks, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-05-27] (Microsoft Corporation) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-11-22] (Hewlett-Packard Company) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\Run: [Spotify] => C:\Users\Mike\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-24] (Spotify Ltd) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\Run: [Spotify Web Helper] => C:\Users\Mike\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-24] (Spotify Ltd) HKU\S-1-5-21-3383338283-2784913959-1398910196-1000\...\MountPoints2: {a149c82e-b38b-11e3-b45a-806e6f6e6963} - F:\autorun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish PictureMover.lnk ShortcutTarget: Snapfish PictureMover.lnk -> C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company) ShellIconOverlayIdentifiers: 00Zecter -> {D25B32FE-CB96-491A-98FF-AD59DA382D69} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 01Zecter -> {EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 02Zecter -> {B3C78E40-6B64-47C3-AE34-60B770881EB8} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 03Zecter -> {622AFE52-33F6-4D9F-9966-E0BC52D7D69D} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ShellIconOverlayIdentifiers: 04Zecter -> {855156F0-2A0F-11DE-8C30-0800200C9A66} => C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll (Versionate Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-01-27] (EasyBits Software Corp.) FireFox: ======== FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-05-07] FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-05-07] FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-05-07] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-07-15] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-07-15] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [nhfpefkeidlhbjljfdojcnngjbddgein] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2010-11-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2010-11-24] (CyberLink) R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed] R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-11-22] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-10-17] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620640 2013-10-17] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-11] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-11 11:26 - 2014-08-11 11:26 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-11 11:26 - 2014-08-11 11:26 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-11 11:26 - 2014-08-11 11:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-11 11:26 - 2014-08-11 11:26 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-11 11:26 - 2014-08-11 11:26 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-11 11:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-11 11:26 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-11 11:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-11 11:25 - 2014-08-11 11:25 - 00000624 _____ () C:\Users\Mike\Desktop\JRT.txt 2014-08-11 11:16 - 2014-08-11 11:16 - 00000000 ____D () C:\Windows\ERUNT 2014-08-11 11:08 - 2014-08-11 11:10 - 00000000 ____D () C:\AdwCleaner 2014-08-11 00:49 - 2014-08-11 11:37 - 00000000 ____D () C:\FRST 2014-08-10 14:07 - 2014-08-10 14:09 - 00000345 _____ () C:\ProgramData\RUNDLL32.EXE-2772-F.txt 2014-08-10 13:53 - 2014-08-10 13:54 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2752-F.txt 2014-07-15 21:29 - 2014-07-15 21:30 - 00000534 _____ () C:\ProgramData\RUNDLL32.EXE-3332-F.txt 2014-07-15 21:23 - 2014-07-15 21:23 - 00002334 _____ () C:\Users\Mike\Desktop\Sicherer Zahlungsverkehr.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00001124 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-07-15 21:23 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2014-07-15 21:21 - 2014-08-11 11:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-07-15 21:17 - 2013-10-17 15:47 - 00620640 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-07-15 21:17 - 2013-06-08 20:18 - 00112224 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-07-12 11:11 - 2014-07-12 11:11 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-3328-F.txt 2014-07-12 11:06 - 2014-07-12 11:09 - 00000458 _____ () C:\ProgramData\RUNDLL32.EXE-2800-F.txt 2014-07-12 11:04 - 2014-07-12 11:05 - 00000115 _____ () C:\ProgramData\RUNDLL32.EXE-2812-F.txt 2014-07-12 11:02 - 2014-07-12 11:02 - 00000169 _____ () C:\ProgramData\RUNDLL32.EXE-3044-F.txt 2014-07-12 10:57 - 2014-08-10 13:57 - 00000510 _____ () C:\ProgramData\RUNDLL32.EXE-2844-F.txt 2014-07-12 10:19 - 2014-07-12 10:20 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2832-F.txt 2014-07-12 10:04 - 2014-07-12 10:18 - 00001913 _____ () C:\ProgramData\RUNDLL32.EXE-2492-F.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-11 11:37 - 2014-08-11 00:49 - 00000000 ____D () C:\FRST 2014-08-11 11:26 - 2014-08-11 11:26 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-11 11:26 - 2014-08-11 11:26 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-11 11:26 - 2014-08-11 11:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-11 11:26 - 2014-08-11 11:26 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-11 11:26 - 2014-08-11 11:26 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-11 11:25 - 2014-08-11 11:25 - 00000624 _____ () C:\Users\Mike\Desktop\JRT.txt 2014-08-11 11:20 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-11 11:20 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-11 11:17 - 2014-05-24 17:41 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-08-11 11:17 - 2011-01-28 01:28 - 00698926 _____ () C:\Windows\system32\perfh007.dat 2014-08-11 11:17 - 2011-01-28 01:28 - 00149034 _____ () C:\Windows\system32\perfc007.dat 2014-08-11 11:17 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-11 11:16 - 2014-08-11 11:16 - 00000000 ____D () C:\Windows\ERUNT 2014-08-11 11:16 - 2011-05-07 17:38 - 01084810 _____ () C:\Windows\WindowsUpdate.log 2014-08-11 11:13 - 2014-05-24 18:28 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\Spotify 2014-08-11 11:12 - 2014-07-15 21:21 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-08-11 11:12 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-08-11 11:12 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-11 11:12 - 2009-07-14 06:51 - 00064647 _____ () C:\Windows\setupact.log 2014-08-11 11:11 - 2011-05-07 18:03 - 00248272 _____ () C:\Windows\PFRO.log 2014-08-11 11:10 - 2014-08-11 11:08 - 00000000 ____D () C:\AdwCleaner 2014-08-11 11:07 - 2014-03-24 21:42 - 00003704 _____ () C:\Windows\System32\Tasks\Registration 2014-08-10 22:19 - 2014-05-31 18:26 - 00003180 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForMike 2014-08-10 22:19 - 2014-05-31 18:26 - 00000328 _____ () C:\Windows\Tasks\HPCeeScheduleForMike.job 2014-08-10 22:19 - 2014-03-24 21:50 - 00003216 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForMIKE-HP$ 2014-08-10 22:19 - 2014-03-24 21:50 - 00000340 _____ () C:\Windows\Tasks\HPCeeScheduleForMIKE-HP$.job 2014-08-10 14:23 - 2014-06-17 09:03 - 00000505 _____ () C:\ProgramData\RUNDLL32.EXE-2756-F.txt 2014-08-10 14:09 - 2014-08-10 14:07 - 00000345 _____ () C:\ProgramData\RUNDLL32.EXE-2772-F.txt 2014-08-10 13:57 - 2014-07-12 10:57 - 00000510 _____ () C:\ProgramData\RUNDLL32.EXE-2844-F.txt 2014-08-10 13:54 - 2014-08-10 13:53 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2752-F.txt 2014-07-15 21:30 - 2014-07-15 21:29 - 00000534 _____ () C:\ProgramData\RUNDLL32.EXE-3332-F.txt 2014-07-15 21:30 - 2014-05-24 18:28 - 00000000 ____D () C:\Users\Mike\AppData\Local\Spotify 2014-07-15 21:23 - 2014-07-15 21:23 - 00002334 _____ () C:\Users\Mike\Desktop\Sicherer Zahlungsverkehr.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00001124 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-07-15 21:23 - 2014-07-15 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-07-15 21:21 - 2014-07-15 21:21 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-07-15 21:12 - 2011-05-07 18:09 - 00000000 ____D () C:\ProgramData\Norton 2014-07-12 11:11 - 2014-07-12 11:11 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-3328-F.txt 2014-07-12 11:09 - 2014-07-12 11:06 - 00000458 _____ () C:\ProgramData\RUNDLL32.EXE-2800-F.txt 2014-07-12 11:05 - 2014-07-12 11:04 - 00000115 _____ () C:\ProgramData\RUNDLL32.EXE-2812-F.txt 2014-07-12 11:02 - 2014-07-12 11:02 - 00000169 _____ () C:\ProgramData\RUNDLL32.EXE-3044-F.txt 2014-07-12 10:20 - 2014-07-12 10:19 - 00000114 _____ () C:\ProgramData\RUNDLL32.EXE-2832-F.txt 2014-07-12 10:18 - 2014-07-12 10:04 - 00001913 _____ () C:\ProgramData\RUNDLL32.EXE-2492-F.txt Some content of TEMP: ==================== C:\Users\Mike\AppData\Local\Temp\autorun.dll C:\Users\Mike\AppData\Local\Temp\Execute2App.exe C:\Users\Mike\AppData\Local\Temp\Extract.exe C:\Users\Mike\AppData\Local\Temp\lowproc.exe C:\Users\Mike\AppData\Local\Temp\msvcp90.dll C:\Users\Mike\AppData\Local\Temp\msvcr90.dll C:\Users\Mike\AppData\Local\Temp\Quarantine.exe C:\Users\Mike\AppData\Local\Temp\SP52503.exe C:\Users\Mike\AppData\Local\Temp\SP52509.exe C:\Users\Mike\AppData\Local\Temp\SP52898.exe C:\Users\Mike\AppData\Local\Temp\SP53998.exe C:\Users\Mike\AppData\Local\Temp\SP54714.exe C:\Users\Mike\AppData\Local\Temp\SP55068.exe C:\Users\Mike\AppData\Local\Temp\SP55094.exe C:\Users\Mike\AppData\Local\Temp\SP55101.exe C:\Users\Mike\AppData\Local\Temp\SP55102.exe C:\Users\Mike\AppData\Local\Temp\SP55107.exe C:\Users\Mike\AppData\Local\Temp\SP55109.exe C:\Users\Mike\AppData\Local\Temp\SP55150.exe C:\Users\Mike\AppData\Local\Temp\SP55152.exe C:\Users\Mike\AppData\Local\Temp\sp58915.exe C:\Users\Mike\AppData\Local\Temp\stubhelper.dll C:\Users\Mike\AppData\Local\Temp\UninstallHPSA.exe C:\Users\Mike\AppData\Local\Temp\UninstallHPTCA.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-10 18:54 ==================== End Of Log ============================ |
11.08.2014, 11:44 | #12 |
/// TB-Ausbilder | Windows 7: Sperrbildschirm nach GVU Trojaner Sieht sehr gut aus soweit. Achtung: ESET Scan dauert länger. ESET Online Scanner
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
11.08.2014, 13:29 | #13 |
| Windows 7: Sperrbildschirm nach GVU Trojaner Sorry hab ausversehen die Bedrohungen entfernen lassen. Kann sie aber wiederherstellen. Soll ich das tun? Aqnsonsten ist hier die log.txt: Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=1e1d3b96404edd41ae4547dbb7484813 # engine=19596 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-11 12:19:18 # local_time=2014-08-11 02:19:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Kaspersky Internet Security' # compatibility_mode=1292 16777214 100 99 11199 39237580 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 66 85 6413041 159389408 0 0 # scanned=190998 # found=3 # cleaned=3 # scan_time=5124 sh=16044F728654E8EBE6592A1066F894958A08E3B7 ft=1 fh=35e5f51864daae44 vn="Win32/Reveton.AJ Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\FRST\Quarantine\C\ProgramData\D250639581322285A2C4C66618854AE5\zy4j04.cpp.xBAD" sh=DCC2EB142E42A091827A8BE3363AF0D4871BAFEF ft=1 fh=ee8b1d76e6586962 vn="Variante von Win64/Kryptik.FZ Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\FRST\Quarantine\C\ProgramData\D250639581322285A2C4C66618854AE5\D250639581322285A2C4C66618854AE5\40j4yz.dot" sh=16044F728654E8EBE6592A1066F894958A08E3B7 ft=1 fh=35e5f51864daae44 vn="Win32/Reveton.AJ Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\Mike\AppData\Local\Temp\Low\0333.dll" |
11.08.2014, 14:10 | #14 |
/// TB-Ausbilder | Windows 7: Sperrbildschirm nach GVU Trojaner Ok nicht weiter schlimm. Soweit ist aber alles sauber ! Downloade Dir bitte SecurityCheck und:
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
11.08.2014, 15:22 | #15 |
| Windows 7: Sperrbildschirm nach GVU Trojaner Ich glaub so soll das nicht! Code:
ATTFilter UNSUPPORTED OPERATING SYSTEM! ABORTED! |
Themen zu Windows 7: Sperrbildschirm nach GVU Trojaner |
adobe, avp, computer, desktop, download, explorer, file, helper, home, kaspersky, kis, launch, microsoft, registry, rundll, scan, security, services.exe, software, spotify web helper, svchost.exe, system, temp, trojaner, usb, windows, winlogon.exe |